English

ConstMig: Enabling Secure Live Migration of Large Intel SGX-based applications

Cryptography and Security 2026-01-21 v5

Abstract

Cloud service providers are adopting Trusted Execution Environments (TEEs) to provide hardware-guaranteed security to applications running on remote, untrusted data centers. However, migrating such applications still relies on the decade-old stop-and-copy method, which introduces large downtimes. Modern live-migration approaches such as pre-copy and post-copy do not work for TEE-based applications due to hardware-enforced restrictions. We propose ConstMig, a near-zero-downtime live-migration mechanism for large memory-footprint TEE-based applications. ConstMig is fully compatible with containers, virtual machines (VMs), and microVMs. Our prototype, built on Intel SGX, achieves near-zero downtime irrespective of enclave size and requires no additional hardware support. ConstMig reduces total downtime by 77 - 96% for a suite of SGX applications with multi-gigabyte memory footprints compared to state-of-the-art TEE-based migration solutions such as MigSGX.

Keywords

Cite

@article{arxiv.2311.06991,
  title  = {ConstMig: Enabling Secure Live Migration of Large Intel SGX-based applications},
  author = {Sandeep Kumar and Abhisek Panda and Smruti R. Sarangi},
  journal= {arXiv preprint arXiv:2311.06991},
  year   = {2026}
}
R2 v1 2026-06-28T13:18:46.046Z