Trust More, Serverless

被引:27
作者
Brenner, Stefan [1 ]
Kapitza, Ruediger [1 ]
机构
[1] TU Braunschweig, Braunschweig, Germany
来源
SYSTOR '19: PROCEEDINGS OF THE 12TH ACM INTERNATIONAL SYSTEMS AND STORAGE CONFERENCE | 2019年
关键词
Trusted Function-as-a-Service; Intel SGX; Serverless Cloud;
D O I
10.1145/3319647.3325825
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
The increasingly popular and novel Function-as-a-Service ( FaaS) clouds allow users the deployment of single functions. Compared to Infrastructure-as-a-Service or Platform-as-a-Service, this enables providers even more aggressive and rigorous resource sharing and liberates customers from tedious maintenance tasks. However, as a crucial factor of cloud adoption, FaaS clouds need to provide security and privacy guarantees in order to allow sensitive data processing. In this paper, we investigate securing FaaS clouds for sensitive data processing, while respecting their new features, capabilities and benefits in a technology-aware manner. We start with the proposal of a generic approach for a JavaScript-based secure FaaS platform, then get more specific and discuss the implementation of two distinct approaches based on ( a) a lightweight and ( b) a high performance JavaScript engine. Our prototype implementation shows promising performance while efficiently utilising resources, thereby keeping the penalties of the added security low.
引用
收藏
页码:33 / 43
页数:11
相关论文
共 28 条
[1]  
Alder F., 2018, ARXIV181006080
[2]  
Anati I., 2013, P 2 INT WORKSH HARDW
[3]  
[Anonymous], 2019, IEEE S SEC PRIV S P
[4]  
[Anonymous], 2016, 12 USENIX S OP SYST
[5]  
[Anonymous], 2018, 27 USENIX SEC S USEN
[6]  
[Anonymous], P 12 EUR C COMP SYST
[7]  
[Anonymous], 2018, V8 DEV UNTRUSTED COD
[8]  
[Anonymous], 2017, INTRO CLOUDFLARE WOR
[9]  
[Anonymous], 2018, CLOUD COMPUTING CONT
[10]  
[Anonymous], 2017, SERVERLESS COMPUTING