Imperial College London

Dr Lluis Vilanova

Faculty of EngineeringDepartment of Computing

Senior Lecturer
 
 
 
//

Contact

 

+44 (0)20 7594 8328vilanova Website

 
 
//

Location

 

556Huxley BuildingSouth Kensington Campus

//

Summary

 

Publications

Citation

BibTex format

@inproceedings{Hunger:2018:10.1145/3173162.3173213,
author = {Hunger, C and Vilanova, L and Papamanthou, C and Etsion, Y and Tiwari, M},
doi = {10.1145/3173162.3173213},
pages = {722--736},
publisher = {ACM},
title = {DATS - data containers for web applications},
url = {http://dx.doi.org/10.1145/3173162.3173213},
year = {2018}
}

RIS format (EndNote, RefMan)

TY  - CPAPER
AB - Data containers enable users to control access to their data while untrusted applications compute on it. However, they require replicating an application inside each container - compromising functionality, programmability, and performance. We propose DATS - a system to run web applications that retains application usability and efficiency through a mix of hardware capability enhanced containers and the introduction of two new primitives modeled after the popular model-view-controller (MVC) pattern. (1) DATS introduces a templating language to create views that compose data across data containers. (2) DATS uses authenticated storage and confinement to enable an untrusted storage service, such as memcached and deduplication, to operate on plain-text data across containers. These two primitives act as robust declassifiers that allow DATS to enforce non-interference across containers, taking large applications out of the trusted computing base (TCB). We showcase eight different web applications including Gitlab and a Slack-like chat, significantly improve the worst-case overheads due to application replication, and demonstrate usable performance for common-case usage.
AU - Hunger,C
AU - Vilanova,L
AU - Papamanthou,C
AU - Etsion,Y
AU - Tiwari,M
DO - 10.1145/3173162.3173213
EP - 736
PB - ACM
PY - 2018///
SP - 722
TI - DATS - data containers for web applications
UR - http://dx.doi.org/10.1145/3173162.3173213
UR - http://hdl.handle.net/10044/1/79660
ER -