Reusable Enclaves for Confidential Serverless Computing

Reusable Enclaves for Confidential Serverless Computing
复制标题

DOI:
--
复制
发表时间:
2023
期刊:
--
影响因子:
--
通讯作者:
Shixuan Zhao;Pinshen Xu;Guoxing Chen;Mengya Zhang;Yinqian Zhang;Zhiqiang Lin
Shixuan Zhao;Pinshen Xu;Guoxing Chen;Mengya Zhang;Yinqian Zhang;Zhiqiang Lin
中科院分区:
其他
文献类型:
--
作者:
Shixuan Zhao;Pinshen Xu;Guoxing Chen;Mengya Zhang;Yinqian Zhang;Zhiqiang Lin

文献摘要

相似文献

可信赖的执行环境的最新发展为基于云的系统中的机密计算带来了前所未有的机会。自出现以来,在各种流行的云业务模型中,无服务器的计算已经获得了优势,从而导致基于信任的飞地对机密无服务器计算服务的需求很高。但是,由于需要创建新的飞地以确保清洁可验证的执行环境,因此冷启动开销的问题极大地阻碍了其性能。在本文中,我们提出了一种构建可重复使用的飞地的新方法,该方法可以通过三种关键的启用技术来快速地重置和稳健的安全性:飞地快照和重新启动,嵌套身定义,以及多层内部内腔室内剖分。我们已经构建了一个用于无服务器计算的原型系统,集成了OpenWhisk和一个WebAssembly运行时,该系统在无端到端无服务器设置中大大降低了冷启动开销,同时对标准执行产生了合理的性能影响。
The recent development of Trusted Execution Environment has brought unprecedented opportunities for confidential computing within cloud-based systems. Among various popular cloud business models, serverless computing has gained dominance since its emergence, leading to a high demand for confidential serverless computing services based on trusted enclaves. However, the issue of cold start overhead significantly hinders its performance, as new enclaves need to be created to ensure a clean and verifiable execution environment. In this paper, we propose a novel approach for constructing reusable enclaves that enable rapid enclave reset and robust security with three key enabling techniques: enclave snapshot and rewinding , nested attestation , and multi-layer intra-enclave compartmentalisation . We have built a prototype system for confidential serverless computing, integrating OpenWhisk and a WebAssembly runtime, which significantly reduces the cold start overhead in an end-to-end serverless setting while imposing a reasonable performance impact on standard execution.