Wallet: Confidential Serverless Computing
Patrick Sabanic, Masanori Misono, Teofil Bodea, Julian Pritzi, Michael Hackl, Dimitrios Stavrakakis, Pramod Bhatotia
Abstract
Although serverless computing offers compelling cost and deployment simplicity advantages, a significant challenge remains in securely managing sensitive data as it flows through the network of ephemeral function executions in serverless computing environments within untrusted clouds. While Confidential Virtual Machines (CVMs) offer a promising secure execution environment, their integration with serverless architectures currently faces fundamental limitations in key areas: security, performance, and resource efficiency.
We present Wallet, a lightweight confidential computing system for secure serverless deployments. By employing nested confidential execution and a decoupled guest OS within CVMs, Wallet runs each function in a minimal "trustlet", significantly improving security through a reduced Trusted Computing Base (TCB). Furthermore, by leveraging a data-centric I/O architecture built upon a lightweight LibOS, Wallet optimizes network communication to address performance and resource efficiency challenges.
Our evaluation shows that compared to CVM-based deployments,Wallet has a 4.3× smallerTCB,improves end-to-end latency (15-93%), achieves higher function density (up to 907×), and reduces inter-function communication (up to 27×) and function chaining latency (16.7-30.2×); thus, Wallet offers a practical system design for confidential serverless computing.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext ccc65047-8215-48e5-9abb-613b820e4ef2Builds on55
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Faasm: Lightweight Isolation for Efficient Stateful Serverless ComputingSimon Shillaker, Peter R. PietzuchUSENIX ATC 2020 · 382 citations
- Keystone: an open framework for architecting trusted execution environmentsDayeol Lee, David Kohlbrenner, Shweta Shinde, Krste Asanovic et al.EuroSys 2020 · 381 citations
- Catalyzer: Sub-millisecond Startup for Serverless Computing with Initialization-less BootingDong Du, Tianyi Yu, Yubin Xia, Binyu Zang et al.ASPLOS 2020 · 280 citations
- Nightcore: efficient and scalable serverless computing for latency-sensitive, interactive microservicesZhipeng Jia, Emmett WitchelASPLOS 2021 · 218 citations
Related papers
- Serverless Functions Made Confidential and Efficient with Split ContainersJiacheng Shi, Jinyu Gu, Yubin Xia, Haibo ChenUSENIX Security 2025
- Reusable Enclaves for Confidential Serverless ComputingShixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang et al.USENIX Security 2023
- SeSeMI: Secure Serverless Model Inference on Sensitive DataGuoyu Hu, Yuncheng Wu, Gang Chen, Tien Tuan Anh Dinh et al.ICDE 2025 · 1 citation
- SEVeriFast: Minimizing the root of trust for fast startup of SEV microVMsBenjamin Holmes, Jason Waterman, Dan WilliamsASPLOS 2024 · 14 citations
- WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave RestoreXiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian et al.ASPLOS 2026
