Supporting these options complicates the design of Graphene and loading
logic significantly, providing little useful functionality:
- loader.exec:
- the main user of it were our tests
- worked only for the first process spawned inside Graphene, as it
was a unidirectional manifest->binary mapping, so the child
process didn't know about the corresponding manifest.
- sgx.sigfile:
- probably all existing usages of it were completely redundant
- was resolved relatively to CWD instead of the executable location,
which made it mostly useless
From now on, the correct location of the files is:
- either place the manifest and sigfile next to the binary, with a
matching name, or
- create a symlink to the binary in the folder where manifests are
stored and launch it through this symlink
OpenVINO
This directory contains a Makefile and a template manifest for the most recent version of OpenVINO toolkit (as of this writing, version 2020.4). We use the "Object Detection C++ Sample SSD" (object_detection_sample_ssd) example from the OpenVINO distribution as a concrete application running under Graphene-SGX. We test only the CPU backend (i.e., no GPU or FPGA). This was tested on a machine with SGX v1 and Ubuntu 18.04.
The Makefile and the template manifest contain extensive comments. Please review them to understand the requirements for OpenVINO/object_detection_sample_ssd running under Graphene-SGX.
We build OpenVINO from the source code instead of using an existing installation. Note: the build process requires ~1.1GB of disk space and takes ~20 minutes.
We also download the Open Model Zoo repository and use the SSD300 pre-trained model from it. Note: the model zoo requires ~350MB of disk space.
Prerequisites
For Ubuntu 18.04, install the following prerequisite packages:
-
Install CMake version >= 3.11 (on Ubuntu 18.04, this may require installing Cmake from a non-official APT repository like Kitware).
-
Install libusb version >= 1.0.0.
-
Install libtbb-dev
-
Install packages for Python3:
pip3 install pyyaml numpy networkx test-generator defusedxml protobuf>=3.6.1
Quick Start
# build OpenVINO together with object_detection_sample_ssd and the final manifest;
# note that it also downloads the SSD300 model and transforms it from the Caffe
# format to an optimized Intermediate Representation (IR)
make SGX=1
# run original OpenVINO/object_detection_sample_ssd
# note that this assumes the Release build of OpenVINO (no DEBUG=1)
./openvino/bin/intel64/Release/object_detection_sample_ssd -i images/horses.jpg \
-m model/VGG_VOC0712Plus_SSD_300x300_ft_iter_160000.xml -d CPU
# run OpenVINO/object_detection_sample_ssd in non-SGX Graphene
./pal_loader object_detection_sample_ssd.manifest -i images/horses.jpg \
-m model/VGG_VOC0712Plus_SSD_300x300_ft_iter_160000.xml -d CPU
# run OpenVINO/object_detection_sample_ssd in Graphene-SGX
SGX=1 ./pal_loader object_detection_sample_ssd.manifest.sgx -i images/horses.jpg \
-m model/VGG_VOC0712Plus_SSD_300x300_ft_iter_160000.xml -d CPU
# Each of these commands produces an image out_0.bmp with detected objects
xxd out_0.bmp # or open in any image editor