题名 | Reusable Enclaves for Confidential Serverless Computing |
作者 | |
发表日期 | 2023
|
会议名称 | 32nd USENIX Security Symposium
|
会议录名称 | |
会议日期 | AUG 09-11, 2023
|
会议地点 | null,Anaheim,CA
|
出版地 | SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA
|
出版者 | |
摘要 | The recent development of Trusted Execution Environment has brought unprecedented opportunities for confidential computing within cloud-based systems. Among various popular cloud business models, serverless computing has gained dominance since its emergence, leading to a high demand for confidential serverless computing services based on trusted enclaves. However, the issue of cold start overhead significantly hinders its performance, as new enclaves need to be created to ensure a clean and verifiable execution environment. In this paper, we propose a novel approach for constructing reusable enclaves that enable rapid enclave reset and robust security with three key enabling techniques: enclave snapshot and rewinding, nested attestation, and multi-layer intra-enclave compartmentalisation. We have built a prototype system for confidential serverless computing, integrating OpenWhisk and a WebAssembly runtime, which significantly reduces the cold start overhead in an end-to-end serverless setting while imposing a reasonable performance impact on standard execution. |
学校署名 | 其他
|
语种 | 英语
|
相关链接 | [来源记录] |
收录类别 | |
资助项目 | NSF["2112471","2207202"]
; NSFC[62102254]
; Shanghai Pujiang Program[21PJ1404900]
|
WOS研究方向 | Computer Science
|
WOS类目 | Computer Science, Information Systems
; Computer Science, Interdisciplinary Applications
; Computer Science, Theory & Methods
|
WOS记录号 | WOS:001066451504011
|
来源库 | Web of Science
|
引用统计 |
被引频次[WOS]:3
|
成果类型 | 会议论文 |
条目标识符 | http://sustech.caswiz.com/handle/2SGJ60CL/673956 |
专题 | 南方科技大学 |
作者单位 | 1.The Ohio State University, United States 2.Southern University of Science and Technology, China 3.Shanghai Jiaotong University, China |
推荐引用方式 GB/T 7714 |
Zhao, Shixuan,Xu, Pinshen,Chen, Guoxing,et al. Reusable Enclaves for Confidential Serverless Computing[C]. SUITE 215, 2560 NINTH ST, BERKELEY, CA 94710 USA:USENIX ASSOC,2023.
|
条目包含的文件 | 条目无相关文件。 |
|
除非特别说明,本系统中所有内容都受版权保护,并保留所有权利。
修改评论