Fine-Grained Isolation for Scalable, Dynamic, Multi-tenant Edge Clouds

Fine-Grained Isolation for Scalable, Dynamic, Multi-tenant Edge Clouds
复制标题

DOI:
--
复制
发表时间:
2020-07
期刊:
--
影响因子:
--
通讯作者:
Yuxin Ren;Guyue Liu;Vlad Nitu;Wenyuan Shao;Riley Kennedy;Gabriel Parmer;Timothy Wood;A. Tchana
Yuxin Ren;Guyue Liu;Vlad Nitu;Wenyuan Shao;Riley Kennedy;Gabriel Parmer;Timothy Wood;A. Tchana
中科院分区:
其他
文献类型:
--
作者:
Yuxin Ren;Guyue Liu;Vlad Nitu;Wenyuan Shao;Riley Kennedy;Gabriel Parmer;Timothy Wood;A. Tchana

文献摘要

相似文献

5G边缘云有望在短网络跳距内实现普遍的计算基础设施,从而实现新型智能设备,实时响应其物理环境。不幸的是,今天的操作系统设计无法满足这些应用程序所需的可伸缩隔离、密集多租户和高性能的目标。在本文中,我们介绍了EdgeOS,它强调系统范围的隔离,就像每个客户端一样细粒度。我们提出了一种新的内存移动加速器架构,采用数据复制,以执行强隔离,而不会带来性能损失。为了支持可扩展的隔离,我们引入了一个新的保护域实现,即使在高流失情况下也能提供轻量级隔离、快速启动和低延迟。我们在基于微内核的操作系统中实现EdgeOS,并使用Click软件路由器和端点应用程序(如memcached,TLS代理和神经网络推理)演示运行高规模网络中间盒。与Linux进程相比,我们将启动延迟降低了170倍,并且在一台服务器上运行300到1000个边缘云memcached实例时,延迟提高了三个数量级。
5G edge clouds promise a pervasive computational infrastructure a short network hop away, enabling a new breed of smart devices that respond in real-time to their physical surroundings. Unfortunately, today’s operating system designs fail to meet the goals of scalable isolation, dense multi-tenancy, and high performance needed for such applications. In this paper we introduce EdgeOS that emphasizes system-wide isolation as fine-grained as per-client. We propose a novel memory movement accelerator architecture that employs data copying to enforce strong isolation without performance penalties. To support scalable isolation, we introduce a new protection domain implementation that offers lightweight isolation, fast startup and low latency even under high churn. We implement EdgeOS in a microkernel based OS and demonstrate running high scale network middleboxes using the Click software router and endpoint applications such as memcached, a TLS proxy, and neural network inference. We reduce startup latency by 170X compared to Linux processes, and improve latency by three orders of magnitude when running 300 to 1000 edge-cloud memcached instances on one server.