WorksetEnclave: Towards Optimizing Cold Starts in Confidential Serverless with Workset-Based Enclave Restore
Xiaolong Yan, Qihang Zhou, Zisen Wan, Feifan Qian, Wentao Yao, Weijuan Zhang, Xiaoqi Jia
摘要
Serverless computing has become a popular cloud computing paradigm. However, the increasing demand for data security in serverless applications necessitates the use of Trusted Execution Environments (TEEs) such as Intel Software Guard Extensions (SGX). Despite the promise of SGX for secure computation, its adoption in serverless environments is hindered by high startup latencies and excessive Enclave Page Cache (EPC) consumption, particularly during cold starts. This paper identifies the key challenges of SGX in serverless workloads and proposes WorksetEnclave, an efficient optimization method designed to address these issues. WorksetEnclave leverages a snapshot-based approach to optimize both startup time and enclave memory usage. By tracking workset pages used during execution, WorksetEnclave minimizes enclave memory footprints and significantly accelerates enclave restore time during secure checkpointing and recovery. We have implemented two separate prototypes, each based on a different LibOS: Gramine and Occlum. Our evaluation shows that WorksetEnclave accelerates cold start times by 1.9--54× and reduces enclave memory consumption by 13.37--94.87%. Our findings demonstrate that WorksetEnclave significantly improves the performance of confidential serverless.
问问这篇 Paper
问问你的智能体。
Lune 读过与它相关的顶会 Paper,每个回答都会注明依据哪几篇。
相关 Paper
- Reusable Enclaves for Confidential Serverless ComputingShixuan Zhao, Pinshen Xu, Guoxing Chen, Mengya Zhang 等USENIX Security 2023
- EnTurbo: Accelerate Confidential Serverless Computing via Parallelizing Enclave Startup ProcedureYifan Zhu, Peinan Li, Yunkai Bai, Yubiao Huang 等DAC 2024 · 被引用 2 次
- Confidential Serverless Made Efficient with Plug-In EnclavesMingyu Li, Yubin Xia, Haibo ChenISCA 2021 · 被引用 32 次
- Occlum: Secure and Efficient Multitasking Inside a Single Enclave of Intel SGXYouren Shen, Hongliang Tian, Yu Chen, Kang Chen 等ASPLOS 2020 · 被引用 144 次
- Klotski: Efficient Obfuscated Execution against Controlled-Channel AttacksPan Zhang, Chengyu Song, Heng Yin, Deqing Zou 等ASPLOS 2020 · 被引用 14 次
