课题基金 / 基金详情

UniFaaS: A Unikernel-Based Serverless Operating System

UniFaaS: A Unikernel-Based Serverless Operating System
UniFaaS:基于Unikernel的无服务器操作系统
批准号:
EP/V012134/1
负责人:
Pierre Olivier
金额:
$34.05万
依托单位:
依托单位国家:
英国
项目类别:
Research Grant
财政年份:
2021
资助国家:
英国
项目状态:
未结题
起止时间:
2021 至 --

项目摘要

项目成果

Pierre Olivier的其他基金

相似基金

相关文献

中文摘要
翻译
点击翻译按钮获取中文摘要
英文摘要
Serverless computing, also know as Function as a Service (FaaS), is an emergingprogramming paradigm providing significant benefits for both the tenant (i.e.the application developer) and the provider in terms of costs reduction,data centre efficiency, scalability, etc. With its truly on-demand resourceconsumption and pricing model, as well as the fact that the tenant is relievedfrom any infrastructure management effort, serverless has the potential offully delivering on the core promises of cloud computing, and experts agreethat its usage will skyrocket in the years to come.Serverless computing is made possible by two crucial concepts implemented bythe systems software assuring the execution of functions and running in theprovider's infrastructure: (1) the isolation of the data and performance ofmutually untrusting functions running on the same physical host and (2) thelightweightness of the systems software supporting the execution of functions,i.e. the potential for low memory and disk footprint as well as fast invocationtimes for this software. The current serverless infrastructures are suboptimalregarding both concepts as they use a combination of virtual machines (wellisolated but heavyweight) and containers (lightweight but presenting someserious isolation concerns).The unikernel is a new Operating System (OS) model in which an application isexecuted with a very small custom operating system layer as minimal virtualmachine in the cloud. In effect, unikernels combine the strong isolation ofvirtual machines with a container-like level of lightweightness. Thesecharacteristics make that the unikernel is a uniquely fit candidate to run asserverless infrastructure systems software.We propose to explore the use of the unikernel OS model as the primary unit offunction execution in a serverless computing infrastructure. We note thatalthough it presents some fundamental benefits, the unikernel model needs toevolve to perfectly fit the serverless domain. The principal issue is the lackof support for important features, namely intra-unikernel isolation andmulti-processing. These shortcomings are not simply due to missingimplementations, but rather derive from fundamental design principles of theunikernel OS model. Hence, we propose to design and implement UniFaaS as an evolution of theunikernel OS model tailored for serverless computing. UniFaaS aims to supportthe aforementioned lacking features, while maintaining the isolation andlightweightness benefits that unikernels naturally offer. UniFaaS will be builton top of an existing unikernel, namely OSv. The design and development effortwill be made along 3 main avenues: (1) new functionalities development, inparticular multi-process support using threads as well as furtherspecialisation the towards serverless computing; (2) security enhancements, inparticular the introduction of low-overhead intra-unikernel isolation usingmodern hardware technologies; and (3) lightweightness optimisations to furtherreduce per-unikernels and per-function memory/disk footprints as well asboot/invocation time through various methods, in order to increase per-hostfunction density.Once UniFaaS is built, we will evaluate its security/isolation,lightweightness, and performance, by comparing it to traditional serverlessdeployments that use virtual machines and containers. Regarding security, wenote that the current metrics to assess isolation (such as counting the numberof lines of code of a software) are rather imprecise and we will develop anovel method based on the amount of trusted code (guest kernel and/orhypervisor/host) that can be reached from an untrusted component (applicationcode, network, etc.).
期刊论文(10)
专著(0)
科研奖励(0)
会议论文
EZIOTracer Unifying Kernel and User Space I/O Tracing for Data-Intensive Applications
EZIOTracer 统一数据密集型应用程序的内核和用户空间 I/O 跟踪
DOI: 10.1145/3469379.3469391
发表时间: 2021
期刊: ACM SIGOPS Operating Systems Review
影响因子: --
作者: [Islam Naas M]
通讯作者: Islam Naas M
DOI: 10.1109/secdev53368.2022.00020
发表时间: 2021-06
期刊: 2022 IEEE Secure Development Conference (SecDev)
影响因子: --
作者: [A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier]
通讯作者: A. Bhayat;L. Cordeiro;Giles Reger;F. Shmarov;Konstantin Korovin;T. Melham;Kaled Alshamrany;Mustafa A. Mustafa-Mustafa-A.-Mustafa-144411037;Pierre Olivier
DOI: 10.1145/3552326.3587452
发表时间: 2023-05
期刊: Proceedings of the Eighteenth European Conference on Computer Systems
影响因子: --
作者: [Ho-Ren Chuang;Karim Manaouil;Tong Xing;A. Barbalace;Pierre Olivier;Balvansh Heerekar;B. Ravindran-]
通讯作者: Ho-Ren Chuang;Karim Manaouil;Tong Xing;A. Barbalace;Pierre Olivier;Balvansh Heerekar;B. Ravindran-
DOI: 10.1145/3623759.3624550
发表时间: 2023
期刊:
影响因子: --
作者: [Kressel J]
通讯作者: Kressel J
9
    FlexCap: Exploring Hardware Capabilities in Unikernels and Flexible Isolation OSes
    • 批准号:
      EP/X015610/1
    • 项目类别:
      Research Grant
    • 资助金额:
      $33.65万
    • 财政年份:
      2022
    • 负责人:
      Pierre Olivier
    • 依托单位:
    海外基金