1 of 50

Lambada: Autoscaling Confidential Function Chains without Centralized Trust

Aashutosh Poudel, Matthew Berthoud, and Stephen Herwig

William & Mary

2 of 50

Function, Function as a Service (FaaS), Function Chains

  • Functions are small, modular pieces of code

2

3 of 50

Function, Function as a Service (FaaS), Function Chains

  • Functions are small, modular pieces of code
  • Cloud-based solution for running functions

3

Google Cloud Function

AWS Lambda

4 of 50

Function, Function as a Service (FaaS), Function Chains

  • Functions are small, modular pieces of code
  • Cloud-based solution for running functions
  • Logical (ordered) grouping of Functions
  • Example: A function chain to process loan applications

4

Google Cloud Function

AWS Lambda

Bank function to process applications

Function to verify applicant’s identity

Function to retrieve applicant’s credit score

5 of 50

Threat Landscape

  • Infrastructure bugs and insider threats
  • Data disclosures to law enforcement
  • Data flow manipulation attacks can steal sensitive information

5

6 of 50

Research Question

Is it possible for a FaaS platform to guarantee the confidentiality and integrity of function chains without resorting to centralized trusted services?

6

7 of 50

Threat Model

7

8 of 50

Threat Model

8

9 of 50

Threat Model + Security Goals

9

10 of 50

Existing Solutions

  • Trusted Execution Environments (TEEs), e.g. Intel SGX, provide data confidentiality and integrity
  • Act as a reverse sandbox (enclave) — protecting code inside from privileged attackers like the OS or hypervisor

  • Sealing — lets an enclave persist secrets to untrusted storage across restarts
  • Attestation — an authenticated assertion of the platform's identity and of the enclave's code and data

10

11 of 50

Existing Solutions

  • Central Key Distribution Server to provision identical keying material

11

Intel SGX

Shared Key

Key Distribution Server (KDS)

Key Escrow

KDS Bugs

12 of 50

Our Approach

  • Remove the central Key Distribution Server
  • TEEs provide confidentiality and integrity

12

13 of 50

Our Approach

  • Functions create their own keys

13

14 of 50

Our Approach

  • There’s usually multiple copies (replicas) of functions scaled according to incoming requests

14

15 of 50

Our Approach

  • AFGH05 Proxy Re-encryption Scheme (Section 6.4)

15

16 of 50

Proxy Re-encryption

16

17 of 50

Proxy Re-encryption

17

18 of 50

Proxy Re-encryption

18

19 of 50

Proxy Re-encryption

19

20 of 50

Proxy Re-encryption in Functions

20

21 of 50

Proxy Re-encryption in Functions

21

22 of 50

Proxy Re-encryption in Functions

22

23 of 50

Path Integrity

  • BGLS03 Aggregate Signature Scheme (Section 6.4)

23

24 of 50

Request Flow in Lambada

24

25 of 50

Request Flow in Lambada

25

26 of 50

Request Flow in Lambada

26

27 of 50

Request Flow in Lambada

27

28 of 50

Replay Detection

28

29 of 50

Tamper-evident log

29

30 of 50

Key Rotation

30

31 of 50

End-to-end Design

31

32 of 50

End-to-end Design

32

33 of 50

End-to-end Design

33

34 of 50

End-to-end Design

34

35 of 50

End-to-end Design

35

36 of 50

Implementation: Knative

36

37 of 50

Implementation: Knative

37

38 of 50

Implementation: Knative

38

39 of 50

Implementation: Knative

39

40 of 50

Evaluation: Startup delay

40

41 of 50

Evaluation: Startup delay

41

42 of 50

Evaluation: Startup delay

42

43 of 50

Evaluation: Startup delay

43

44 of 50

Evaluation: Function Invocation

  • Request decryption & Response encryption on request path
  • 250 to 1250 (in increments of 250) and run each strategy for five minutes

44

45 of 50

Evaluation: Application Macrobenchmark

  • Four-node Azure Kubernetes Service (AKS)
  • Avg. time each request spends on a function (1% of 100 rps for 5 minutes)
  • Emojivoto microservice: validate votes, record vote, count vote, display

45

46 of 50

Evaluation: Application Macrobenchmark

46

47 of 50

Evaluation: Application Macrobenchmark

47

48 of 50

Evaluation: Application Macrobenchmark

48

49 of 50

Summary

  • Compose Intel SGX and proxy re-encryption to protect function I/O while preserving horizontal trust scaling.
  • Implement a prototype in a popular FaaS framework (Knative), integrating transparently with FaaS workflows.
  • Evaluate our prototype on a real system, showing modest overhead of 1.55–1.83× that of a function using shared RSA keys.

49

50 of 50

Lambada: Autoscaling Confidential Function Chains without Centralized Trust

Aashutosh Poudel, Matthew Berthoud, and Stephen Herwig

William & Mary

GitHub

Paper