发表机构
New Jersey Institute of Technology; Hofstra University(新泽西理工学院; 霍夫斯特拉大学)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文通过实证研究,分析了机密虚拟机(CVM)中无服务器工作负载的内存效率与运行时开销,发现其存在内存和启动延迟问题,提出同一CVM内合并同函数多容器并选择性放松隔离机制的优化方法。
AI 中文摘要
机密无服务器计算正迅速成为医疗、金融、机器学习等需要强机密性保障的应用领域的关键范式。为在不可信云环境中实现该范式,机密虚拟机(Confidential Virtual Machines, CVM)通过加密整个客户机内存提供隔离,从而保护无服务器工作负载免受主机级访问和干扰。然而,人们对CVM对无服务器系统的影响仍了解不足。本文对CVM中的无服务器工作负载开展实证研究,系统覆盖了冷启动和热启动的内存效率与运行时开销。结果显示,CVM会产生大量内存开销,因为加密内存禁用了跨虚拟机页面重复数据删除并降低了内存可回收性,从而在固定内存预算下限制了热容器的容量。热启动中的运行时开销取决于工作负载,频繁出现VMEXIT的工作负载,尤其是空闲状态转换,会遭受严重减速。这种减速会被常见的无服务器部署实践进一步放大,该实践将vCPU分配与内存大小绑定,因为更高内存配置会提供比部分函数能有效使用的更多vCPU。对于冷启动,研究重点是容器创建,这是启动延迟的常见且主要的贡献因素。受内存效率结果的启发,本文考虑在同一CVM中合并同一函数的多个容器以提高效率的部署方式,并表明在此设置中有选择地放松某些隔离机制可大幅减少启动开销。这些结果阐明了机密无服务器计算的主要性能权衡,并提出了提高效率和降低延迟的实用方法。
英文摘要
Confidential serverless computing is rapidly emerg- ing as a critical paradigm for application domains requiring strong confidentiality guarantees, such as healthcare, finance, and machine learning. To enable this paradigm in untrusted cloud environments, Confidential Virtual Machines (CVMs) provide isolation by encrypting the entire guest memory, and thus securing serverless workloads against host-level access and inter- ference. However, the implications of CVMs for serverless systems remain insufficiently understood. This paper presents an empirical study of serverless work- loads in CVMs, systematically covering memory efficiency and runtime overhead on both warm-starts and cold-starts. Our results show that CVMs incur substantial memory overhead because encrypted memory disables cross-VM page deduplication and reduces memory reclaimability, thereby limiting warm- container capacity under a fixed memory budget. Runtime overhead in warm-starts is workload dependent. Workloads with frequent VMEXITs, particularly idle transitions, suffer substantial slowdowns. These slowdowns are further amplified by common serverless deployment practice that couples vCPU allocation to memory size, as higher-memory configurations expose more vCPUs than some functions can use effectively. For cold starts, the study focuses on container creation, a common and major contributor to startup latency. Motivated by the memory-efficiency results, we consider the deployments in which multiple containers of the same function are consolidated within the same CVM to improve efficiency, and show that selectively relaxing certain isolation mechanisms in this setting can substan- tially reduce startup overhead. These results clarify the main performance tradeoffs of confidential serverless computing and suggest practical ways to improve efficiency and latency.