USENIX Security2023Top-tier venue
Reusable Enclaves for Confidential Serverless Computing
Shixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang, Yinqian Zhang, Zhiqiang Lin
Abstract
The recent development of Trusted Execution Environment has brought unprecedented opportunities for confidential computing within cloud-based systems. Among various popular cloud business models, serverless computing has gained dominance since its emergence, leading to a high demand for confidential serverless computing services based on trusted enclaves. However, the issue of cold start overhead significantly hinders its performance, as new enclaves need to be created to ensure a clean and verifiable execution environment. In this paper, we propose a novel approach for constructing reusable enclaves that enable rapid enclave reset and robust security with three key enabling techniques: enclave snapshot and rewinding, nested attestation, and multi-layer intra-enclave compartmentalisation. We have built a prototype system for confidential serverless computing, integrating OpenWhisk and a WebAssembly runtime, which significantly reduces the cold start overhead in an end-to-end serverless setting while imposing a reasonable performance impact on standard execution.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext a4decf9b-d50d-42c5-b470-38083b23017cCited by top-tier papers11
- A Secure, Fast, and Resource-Efficient Serverless Platform with Function REWINDJaehyun Song, Bumsuk Kim, Minwoo Kwak, Byoungyoung Lee et al.USENIX ATC 2024 · 5 citations
- The HitchHiker's Guide to High-Assurance System Observability Protection with Efficient Permission SwitchesChuqi Zhang, Jun Zeng, Yiming Zhang, Adil Ahmad et al.CCS 2024 · 4 citations
- Erebor: A Drop-In Sandbox Solution for Private Data Processing in Untrusted Confidential Virtual MachinesChuqi Zhang, Rahul Priolkar, Yuancheng Jiang, Yuan Xiao et al.EuroSys 2025 · 4 citations
- SeSeMI: Secure Serverless Model Inference on Sensitive DataGuoyu Hu, Yuncheng Wu, Gang Chen, Tien Tuan Anh Dinh et al.ICDE 2025 · 1 citation
- Characterizing Trust Boundary Vulnerabilities in TEE Container Systems: An Empirical StudyWeijie Liu, Hongbo Chen, Shuo Huai, Zhen Xu et al.FSE 2026
Builds on12
- Spectre Attacks: Exploiting Speculative ExecutionPaul Kocher, Jann Horn, Anders Fogh, Daniel Genkin et al.S&P 2019 · 2,435 citations
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- SGX-Shield: Enabling Address Space Layout Randomization for SGX ProgramsJaebaek Seo, Byoungyoung Lee, Seong-Min Kim, Ming-Wei Shih et al.NDSS 2017 · 227 citations
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGXYouren Shen, Hongliang Tian, Yu Chen, Kang Chen et al.ASPLOS 2020 · 144 citations
- Twine: An Embedded Trusted Runtime for WebAssemblyJämes Ménétrey, Marcelo Pasin, Pascal Felber, Valerio SchiavoniICDE 2021 · 58 citations
Related papers
- WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave RestoreXiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian et al.ASPLOS 2026
- EnTurbo: Accelerate Confidential Serverless Computing via Parallelizing Enclave Startup ProcedureYifan Zhu, Peinan Li, Yunkai Bai, Yubiao Huang et al.DAC 2024 · 2 citations
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 32 citations
- Wallet: Confidential Serverless ComputingPatrick Sabanic, Masanori Misono, Teofil Bodea, Julian Pritzi et al.NSDI 2026
- SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMsBenjamin Holmes, Jason Waterman, Dan WilliamsASPLOS 2024 · 14 citations
