A Secure, Fast, and Resource-Efficient Serverless Platform with Function REWIND
Jaehyun Song, Bumsuk Kim, Minwoo Kwak, Byoungyoung Lee, Euiseong Seo, Jinkyu Jeong
Abstract
Serverless computing often utilizes the warm container technique to improve response times. However, this method, which allows the reuse of function containers across different function requests of the same type, creates persistent vulnerabilities in memory and file systems. These vulnerabilities can lead to security breaches such as data leaks. Traditional approaches to address these issues often suffer from performance drawbacks and high memory requirements due to the extensive use of user-level snapshots and complex restoration process.
The paper introduces REWIND, an innovative and efficient serverless function execution platform designed to address these security and efficiency concerns. REWIND ensures that after each function request, the container is reset to an initial state free of any sensitive data, including a thorough restoration of the file system to prevent data leakage. It incorporates a kernel-level memory snapshot management system, which significantly lowers memory usage and accelerates the rewind process. Additionally, REWIND optimizes runtime by reusing memory regions and leveraging the temporal locality of function executions, enhancing performance while maintaining strict data isolation between requests. The prototype of REWIND is implemented on OpenWhisk and Linux and evaluated with serverless benchmark workloads. The evaluation results have demonstrated that REWIND provides substantial memory savings while providing high function execution performance. Especially, the low memory usage makes more warm containers kept alive thereby improving the throughput as well as the latency of function executions while providing isolation between function requests.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e799dcf1-8389-440a-8f94-bd223e1a077aBuilds on13
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Catalyzer: Sub-millisecond Startup for Serverless Computing with Initialization-less BootingDong Du, Tianyi Yu, Yubin Xia, Binyu Zang et al.ASPLOS 2020 · 280 citations
- FaasCache: keeping serverless computing alive with greedy-dual cachingAlexander Fuerst, Prateek SharmaASPLOS 2021 · 223 citations
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
- Faster and Cheaper Serverless Computing on Harvested ResourcesYanqi Zhang, Iñigo Goiri, Gohar Irfan Chaudhry, Rodrigo Fonseca et al.SOSP 2021 · 131 citations
Related papers
- LeakLess: Selective Data Protection against Memory Leakage Attacks for Serverless PlatformsMaryam Rostamipoor, Seyedhamed Ghavamnia, Michalis PolychronakisNDSS 2025
- Fireworks: a fast, efficient, and safe serverless framework using VM-level post-JIT snapshotWonseok Shin, Wook-Hee Kim, Changwoo MinEuroSys 2022 · 20 citations
- TrEnv: Transparently Share Serverless Execution Environments Across Different Functions and NodesJialiang Huang, Mingxing Zhang, Teng Ma, Zheng Liu et al.SOSP 2024 · 14 citations
- Reusable Enclaves for Confidential Serverless ComputingShixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang et al.USENIX Security 2023
- Memory deduplication for serverless computing with MedesDivyanshu Saxena, Tao Ji, Arjun Singhvi, Junaid Khalid et al.EuroSys 2022 · 54 citations
