WAVEN: WebAssembly Memory Virtualization for Enclaves

Weili Wang

Network and Distributed System Security (NDSS) Symposium 2025 · Day 3 · Confidential Computing 2

Overview

The talk "WAVEN: WebAssembly Memory Virtualization for Enclaves" by Weili Wang introduces a novel memory virtualization scheme designed to enhance the capabilities of WebAssembly (Wasm) within trusted execution environments (TEEs), particularly Intel SGX enclaves. Wang, a researcher from Southern University of Science and Technology, presents WAVEN as a solution to critical limitations of Wasm's inherent linear memory model when applied to multi-tenant confidential computing scenarios. The core problem addressed is the inefficient memory sharing and the complete lack of fine-grained memory access control, which are essential for secure data sharing in platforms like confidential data markets and secure federated learning.

Watch on YouTube · Slides

Key moments

  1. 0:00 Introduction and WebAssembly's enclave memory problem
  2. 2:00 Inefficient memory sharing and access control limitations
  3. 4:00 WAVEN: WebAssembly memory virtualization scheme overview
  4. 5:00 Enforcing memory isolation with execution pages
  5. 6:00 Secure data sharing and access control with dual page tables
  6. 7:00 WAVEN implementation and performance overhead
  7. 8:00 Memory sharing effectiveness and significant speedup

WAVEN: WebAssembly Memory Virtualization for Enclaves

Speakers: Weili Wang

Conference: NDSS Symposium

YouTube: https://www.youtube.com/watch?v=LyuKEk9LOFk

Overview

The talk "WAVEN: WebAssembly Memory Virtualization for Enclaves" by Weili Wang introduces a novel memory virtualization scheme designed to enhance the capabilities of WebAssembly (Wasm) within trusted execution environments (TEEs), particularly Intel SGX enclaves. Wang, a researcher from Southern University of Science and Technology, presents WAVEN as a solution to critical limitations of Wasm's inherent linear memory model when applied to multi-tenant confidential computing scenarios. The core problem addressed is the inefficient memory sharing and the complete lack of fine-grained memory access control, which are essential for secure data sharing in platforms like confidential data markets and secure federated learning.

The significance of WAVEN lies in its ability to bridge the gap between the isolated, high-integrity execution offered by enclaves and the flexible, secure data management required by modern confidential applications. By implementing a software-defined Memory Management Unit (MMU) for Wasm modules, WAVEN enables granular memory sharing and access control, akin to how operating systems provide virtual memory for processes. This innovation is crucial for the widespread adoption of WebAssembly in confidential computing, where multiple mutually distrustful workloads need to run securely within a single enclave, optimizing resource utilization and reducing overhead associated with enclave creation and switching.

Background

▶ Watch: Introduction and WebAssembly's enclave memory problem (0:00)

Trusted Execution Environments (TEEs) are a cornerstone of confidential computing, designed to protect sensitive code and data from attacks originating from privileged software, including the operating system and hypervisor. TEEs come in various forms: VM-based TEEs like Intel TDX provide a VM-level abstraction, while enclave-based TEEs such as Intel SGX and Keystone run programs within isolated enclaves, characterized by a significantly smaller Trusted Computing Base (TCB). The inherent security advantages of enclave-based TEEs, particularly their reduced attack surface, position them as a foundational technology for future confidential computing platforms.

A key challenge in these environments, especially for multi-tenancy scenarios, is enabling mutually distrustful workloads to coexist within a single enclave without compromising security or efficiency. Intel SGX, by default, does not support this feature. WebAssembly (Wasm) emerges as a promising solution. Wasm is a novel, portable binary format designed for high-performance execution on the web, but its utility extends to server-side and confidential computing contexts. Languages like C and Rust can be compiled to Wasm, which then runs within a Wasm runtime. These runtimes enforce memory isolation among Wasm modules, making Wasm a popular choice for enhancing SGX capabilities, as demonstrated by multiple prior works.

The security of Wasm relies heavily on its linear memory model, which treats memory as a contiguous byte array allocated by the runtime. Modules access this memory using 32-bit addresses, and the Wasm runtime enforces isolation through either hardware or software-based boundary checks. However, this linear memory model presents two significant limitations in confidential computing:

  1. Inefficient Memory Sharing: Each Wasm module typically has only one linear memory. Sharing data requires exporting the entire memory, which is both inflexible and impractical for fine-grained sharing. While the "Multi-memory proposal" aims to address this by allowing multiple memories, it is still immature, lacks compiler support, and still necessitates sharing entire memory regions.
  2. Lack of Memory Access Control: In the default linear memory model, all partitions are generally writable. This poses a severe security risk when sharing data, as shared data can be easily tampered with by other modules. Secure data sharing, where data consumers can read but not modify sensitive data, is a highly desired feature for practical applications like confidential stable-fast platforms and secure data marketplaces. These applications often involve multiple modules concurrently accessing the same data, underscoring the critical need for a more robust memory management solution within Wasm enclaves.

Key Findings

▶ Watch: WAVEN: WebAssembly memory virtualization scheme overview (4:00)

WAVEN introduces a novel WebAssembly memory virtualization scheme that directly addresses the limitations of Wasm's linear memory model within enclave environments. The primary findings and contributions are:

  1. WebAssembly Paging and Software MMU: WAVEN implements a software-defined Memory Management Unit (MMU) for Wasm modules, drawing inspiration from operating system memory management. This introduces a WebAssembly paging mechanism, mapping Wasm virtual addresses to runtime-managed physical addresses via a single-level page table. This design minimizes the overhead associated with page table lookups while providing the necessary abstraction for virtualization.
  1. Efficient Memory Isolation without Boundary Checks: To overcome the performance penalties of expensive software boundary checks, WAVEN proposes an optimized address translation mechanism. It utilizes execution pages and page paddings. Unallocated Wasm pages are mapped to a dedicated execution page, and each allocated page is padded with extra bytes. This approach prevents out-of-page boundary accesses and enforces memory isolation with minimal overhead, significantly improving efficiency compared to traditional Wasm runtime checks within SGX.
  1. Fine-Grained Memory Sharing: WAVEN enables flexible and fine-grained memory sharing among Wasm modules. By allowing the runtime to modify page table entries, different modules can map their respective Wasm pages to the same underlying virtual page, facilitating secure and efficient data exchange. This is a significant improvement over the all-or-nothing approach of exporting entire linear memories.
  1. Robust Memory Access Control via Dual Page Tables: To enforce granular access control (e.g., read-only access), WAVEN introduces a dual page table design. One page table is dedicated to memory reads, and another for memory writes. Any unauthorized write attempt is redirected to an execution page, effectively preventing tampering. This software-based approach avoids reliance on untrusted OS components or slow software permission checks, making it suitable for enclave usage.
  1. Practicality and Performance: Implemented on WAMR, a popular Wasm runtime with native SGX support, WAVEN demonstrates practical viability. Evaluation results show a moderate performance overhead of 10.42% on PolyBench benchmarks compared to a standard WAMR setup. Crucially, in confidential computing workloads like confidential databases and privacy-preserving MR inferences, WAVEN introduces a small overhead (e.g., 6.14% for MR inference), highlighting its practicality. For scenarios involving memory sharing, WAVEN significantly outperforms WAMR, achieving peak speedups of 2.4 to 2.5 times in multi-read settings, demonstrating the effectiveness of its sharing mechanism.

Technical Deep Dive

▶ Watch: Enforcing memory isolation with execution pages (5:00)

WAVEN's core innovation lies in establishing a software-defined Memory Management Unit (MMU) within the WebAssembly runtime operating inside an enclave. This addresses the fundamental incompatibility between Wasm's rigid linear memory model and the dynamic, secure memory requirements of multi-tenant confidential computing.

WebAssembly Paging

At the heart of WAVEN is its WebAssembly paging mechanism. Similar to how operating systems manage virtual memory for processes, WAVEN virtualizes memory for Wasm modules. Each Wasm module operates with its own virtual address space. When a module attempts to access memory, the Wasm runtime performs an address translation. The Wasm address is treated as a virtual address, which the runtime then translates into a physical address within the enclave's memory. This mapping is stored and managed in a page table.

WAVEN employs a single-level page table design to minimize the overhead associated with page table lookups. The 32-bit Wasm virtual address is divided: the higher 16 bits are used as the page index to locate the corresponding entry in the page table, and the lower 16 bits represent the page offset within that physical page. This allows for addressing up to 65,536 pages, each of 64KB (2^16 bytes), totaling 4GB of virtual memory per module, consistent with Wasm's 32-bit addressing.

Memory Isolation without Boundary Checks

Traditional Wasm runtimes enforce memory isolation using boundary checks, which can be computationally expensive, especially when implemented purely in software within an SGX enclave. WAVEN optimizes this by enforcing isolation during address translation rather than through explicit checks. It achieves this using two key mechanisms:

  1. Execution Pages: Each Wasm module is allocated a special execution page. All unallocated Wasm pages in a module's virtual address space are mapped to this execution page in the page table. If a module attempts to access an address within an unallocated page, the address translation will direct it to the execution page. This acts as a trap, preventing unauthorized access to unallocated or sensitive memory regions.
  2. Page Paddings: To prevent out-of-page boundary accesses – where a module might try to read or write slightly beyond the intended end of an allocated page – each page is padded with a few extra bytes. This padding ensures that any access that falls just outside the logical bounds of a page will still be contained within the physical memory allocated for that page, or immediately trigger a fault if it goes beyond the padded region, preventing memory corruption or information leakage to adjacent pages.

By combining these techniques, WAVEN ensures that memory isolation is enforced implicitly through the address translation process, reducing the need for costly runtime boundary checks and improving performance within the enclave.

Fine-Grained Memory Sharing

One of the primary motivations for WAVEN is to enable flexible and secure memory sharing. In the Wasm paging model, sharing memory becomes straightforward. To allow two modules (e.g., Module 1 and Module 2) to share a specific region of data, the Wasm runtime simply modifies their respective page table entries. For instance, if Wasm Page 2 of Module 1 and Wasm Page 4 of Module 2 are intended to share data, the runtime configures their page table entries to both point to the same underlying physical page. This allows both modules to access the same data region, with the runtime mediating and enforcing access policies.

Dual Page Table for Memory Access Control

Achieving fine-grained memory access control (e.g., read-only access for data consumers) is critical for secure data sharing. Hardware primitives like Memory Protection Keys (MPK) require a trusted OS, which is not suitable for enclaves. Software permission checks, while possible, are notoriously slow. WAVEN innovates here with a dual page table design:

  1. Read Page Table: This page table governs all memory read operations.
  2. Write Page Table: This separate page table governs all memory write operations.

When a module attempts to read from memory, the runtime consults the Read Page Table for address translation. When a module attempts to write, the runtime consults the Write Page Table. If a specific page (e.g., Page 3) is designated as read-only for a module, its entry in that module's Write Page Table will be configured to point to the execution page instead of the actual data page. Consequently, any attempt by the module to write to Page 3 will be redirected to the execution page, effectively trapping the unauthorized write and preventing data tampering. This design provides a robust and efficient mechanism for enforcing read/write permissions at the page level within the enclave.

Implementation Details

WAVEN is implemented on top of WAMR, a popular WebAssembly runtime known for its native SGX support. The implementation involved two main modifications:

  • Compiler Modifications: The Ahead-Of-Time (AOT) compiler for WAMR was modified to support the address translation logic, ensuring that Wasm modules compiled for WAVEN correctly interact with the virtualized memory system.
  • Runtime Support: The WAMR runtime itself was extended to include functionalities for page table management (creation, modification, lookup) and shared memory management, allowing it to dynamically allocate, map, and control access to memory pages for different Wasm modules.

Demo / Proof of Concept

▶ Watch: WAVEN implementation and performance overhead (7:00)

While the talk did not feature a live, interactive demo, the speaker presented comprehensive evaluation results that serve as a robust proof of concept for WAVEN's practicality, security, and performance. The evaluations were conducted across different settings to assess WAVEN's overhead and the effectiveness of its memory sharing capabilities.

Performance Overhead

To quantify the performance overhead, WAVEN was evaluated using 30 PolyBench benchmarks. These benchmarks cover a wide range of computational patterns, providing a good measure of general-purpose performance. The results showed that WAVEN incurs a moderate overhead of 10.42% compared to a standard WAMR setup. This overhead is attributed to the extra memory read required for page table lookups during each memory access. However, this overhead is partially offset by WAVEN saving the cost of traditional boundary checks. The speaker highlighted that this 10.42% overhead is acceptable, demonstrating the practicality of the approach.

Furthermore, WAVEN's performance was assessed in more specific confidential computing workloads:

  • Confidential Database: While specific numbers weren't detailed for this, it was mentioned as a scenario where WAVEN's features are beneficial.
  • Privacy-Preserving MR Inferences: In this critical application, WAVEN introduced a very small overhead of just 6.14%. This low overhead in real-world confidential computing workloads further underscores WAVEN's viability and efficiency for practical deployment.

Effectiveness of Memory Sharing

The effectiveness of WAVEN's memory sharing mechanism was evaluated in two typical scenarios relevant to confidential computing applications:

  1. Multi-Write/Multi-Read Scenario: This setting is characteristic of confidential stable-fast platforms, where multiple modules might both read from and write to shared data concurrently.
  2. Multi-Read Scenario: This scenario is typical of secure data marketplaces, where multiple consumers (modules) need to read sensitive data from a provider (another module) but are restricted from modifying it.

In both scenarios, WAVEN consistently outperformed the baseline WAMR runtime. The evaluations involved testing with different numbers of concurrent users/modules and measuring the total execution time. Notably, in the multi-read setting, WAVEN achieved a peak speedup of 2.4 to 2.5 times. This significant performance improvement clearly demonstrates the utility and efficiency of WAVEN's fine-grained memory sharing capabilities, especially when multiple modules need to access shared data without incurring the overheads of data duplication or inefficient full-memory exports. The results confirm that WAVEN's ability to manage shared memory effectively translates into tangible performance benefits for multi-tenant enclave applications.

Defensive Implications

▶ Watch: Memory sharing effectiveness and significant speedup (8:00)

WAVEN presents significant defensive implications for the design and deployment of confidential computing applications, particularly those leveraging WebAssembly within enclaves. By addressing critical limitations of Wasm's native memory model, WAVEN empowers defenders to build more secure, efficient, and flexible confidential platforms.

Firstly, WAVEN provides a robust foundation for multi-tenant enclaves. Traditionally, hosting multiple mutually distrustful workloads within a single SGX enclave was challenging due to the lack of strong isolation and access control between Wasm modules. WAVEN's software MMU, with its WebAssembly paging and dual page table design, enables true isolation and fine-grained access control. This means a platform owner can safely deploy multiple applications or user-provided Wasm modules within a single enclave, reducing the overhead of context switching and enclave creation, while maintaining strong security guarantees.

Secondly, the introduction of fine-grained memory access control is a game-changer for secure data sharing. In scenarios like secure data marketplaces or federated learning, data providers can share sensitive datasets with data consumers (Wasm modules) with confidence that their data will not be tampered with. WAVEN's dual page table design ensures that even if a malicious Wasm module attempts an unauthorized write, it will be redirected to a dummy execution page, preventing any modification of the genuine shared data. This strengthens data integrity and confidentiality, addressing a critical need highlighted by applications that require controlled access to sensitive information.

Thirdly, WAVEN's optimized memory isolation mechanism, which relies on execution pages and page paddings rather than expensive software boundary checks, contributes to a more performant defense. By integrating isolation directly into the address translation process, it reduces the computational overhead typically associated with secure memory management in software-only TEEs. This efficiency means that security does not come at an unacceptable performance cost, making WAVEN a practical solution for high-throughput confidential workloads.

Finally, WAVEN's design aligns with the broader trend of adopting WebAssembly in TEEs. As Intel continues to support SGX, solutions like WAVEN provide a pathway for developers to leverage the portability and safety features of Wasm while overcoming its inherent limitations in a confidential setting. Defenders can now architect systems where Wasm modules can securely collaborate on sensitive data, unlocking new possibilities for privacy-preserving computation without compromising the integrity or confidentiality of the underlying data.

Key Takeaways

  • WAVEN virtualizes WebAssembly memory within enclaves: It introduces a software-defined Memory Management Unit (MMU) for Wasm modules, bringing OS-like memory management capabilities to confidential computing.
  • Enables fine-grained memory sharing and access control: WAVEN overcomes the limitations of Wasm's linear memory model, allowing modules to share specific memory regions and enforce read/write permissions via a dual page table design.
  • Optimized for performance in TEEs: By using WebAssembly paging with execution pages and page paddings, WAVEN achieves memory isolation with minimal overhead, avoiding expensive software boundary checks.
  • Demonstrates practical performance: Evaluation shows a moderate 10.42% overhead on PolyBench and a low 6.14% overhead in privacy-preserving MR inference, proving its viability for real-world confidential computing workloads.
  • Achieves significant speedups for shared memory: In multi-read scenarios, WAVEN delivers peak speedups of 2.4 to 2.5 times, highlighting the efficiency of its memory sharing mechanism for multi-tenant applications.
  • Enhances security for multi-tenant enclaves: WAVEN provides a robust solution for running mutually distrustful Wasm modules securely within a single enclave, crucial for confidential data markets and other privacy-preserving platforms.

About the Speaker(s)

Weili Wang is a researcher at Southern University of Science and Technology, where he presented the paper "WAVEN: WebAssembly Memory Virtualization for Enclaves." His work focuses on enhancing the capabilities of WebAssembly within trusted execution environments. The research for WAVEN was a joint effort with fellow researchers Hungi Patient, Dr. Yao Jan, and Dr. Yu, and was supervised by his master advisor, Dr. Injang, also from Southern University of Science and Technology.

Reviews

Dr. Zero (Offensive Security Researcher) — SOLID

Legitimate systems security research solving a real problem — Wasm's flat linear memory model is genuinely broken for multi-tenant enclave workloads, and the software MMU approach with dual page tables is a clean, well-reasoned solution. Competent academic work that will matter to the narrow audience building confidential computing platforms, but it's not going to reshape anyone's threat model or make a practitioner rethink their architecture tomorrow.

Heather Calloway (CISO) — PASS

Technically rigorous systems research on Wasm memory virtualization inside SGX enclaves. Entirely outside my lane — no governance angle, no operator takeaway, no institutional accountability dimension. This is route to zero on relevance, not quality.

→ Top-rated talks at Network and Distributed System Security (NDSS) Symposium 2025

All talks from Network and Distributed System Security (NDSS) Symposium 2025