Serveless computing running environment safety multiplexing

By compiling cloud functions into WebAssembly bytecode and encrypting it, and combining it with TEE to implement a secure channel and session ticket mechanism, the problem of weak operating environment isolation in serverless computing is solved, operational efficiency and security are improved, and privacy data leakage is prevented.

CN120658430APending Publication Date: 2025-09-16XIDIAN UNIV
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202510701802.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-28
Publication Date
2025-09-16

AI Technical Summary

Technical Problem

Existing serverless computing technologies have weak operating environment isolation capabilities, making them vulnerable to malicious attacks that can lead to privacy data leakage. Reusing runtimes also brings risks of user privacy data leakage and performance issues.

Method used

By compiling cloud functions into WebAssembly bytecode and encrypting it, storing it in the serverless computing platform database, distributing decryption keys only to authorized users, and using TEE to implement a secure channel and session ticket mechanism, cloud functions can be ensured to run securely in a trusted execution environment.

Benefits of technology

It enables the secure operation of cloud functions in a trusted execution environment, reduces the number of remote attestations, improves operational efficiency, prevents malicious attacks and privacy data leakage, and provides fine-grained access control.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120658430A_ABST
    Figure CN120658430A_ABST
Patent Text Reader

Abstract

The invention discloses a TEE-based server-free computing operation environment security multiplexing method and system, and solves the risk of user privacy data leakage caused by multiplexing operation and the performance problem caused by non-multiplexing operation in the prior art. The method comprises the following steps: a cloud function developer is used for compiling and encrypting a cloud function, storing an encrypted byte code into a database of a server-free computing platform, and sending a decryption key to an authorized user; the authorized user is used for sending a function call parameter, a remote attestation request and an input parameter to the server-free computing platform, and obtaining encrypted information of the server-free computing platform in response to the function call parameter and the remote attestation request and an operation result in response to the input parameter; according to the method, the operation environment is separated to avoid user privacy leakage, the number of times of remote attestation is reduced, and the cloud function in the same function call session can run more efficiently.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of serverless computing technology, and in particular to a method and system for securely reusing a serverless computing runtime environment based on a TEE (Trusted Execution Environment). Background Art

[0002] With the evolution of cloud computing technology, cloud vendors are constantly innovating their service offerings. Serverless computing, as an emerging cloud computing model, is gaining widespread attention across the industry. Serverless computing, centered around event-driven cloud functions, allows developers to focus solely on implementing the cloud function code for their business logic. Cloud resource management is fully handled by the cloud computing system software, transparent to developers. Serverless computing simplifies the process for developers to write and deploy cloud applications, automatically scales capacity based on application needs, and offers fine-grained billing, thereby reducing cloud service operating costs.

[0003] Serverless computing simplifies developers' work, but weak runtime environment isolation can easily lead to malicious users attacking legitimate users and leaking private data. This presents cloud vendors with challenges in isolating cloud function runtime environments. Faced with increasingly stringent privacy regulations, serverless computing customers are increasingly concerned about malicious runtime environments leaking private data during cloud function execution, leading to an urgent need for remote runtime environment verification technology. Traditional serverless computing solutions have assumed cloud vendors are secure and trustworthy, failing to consider the potential for malicious cloud vendors to steal user private data and interfere with cloud function execution.

[0004] Existing serverless computing architectures typically consist of two parts: a request gateway and a backend executor. The request gateway is responsible for distributing user requests to the backend executor, which is responsible for running cloud functions. There are typically multiple backend executors.

[0005] Some vendors choose virtual machines (VMs) as the runtime environment for their serverless computing platforms, leveraging hardware-assisted virtualization technology to achieve runtime environment isolation. Because they only focus on a single workload, cloud functions, lightweight VMs (microVMs) do not emulate full computer hardware and only implement the necessary runtime functionality. Therefore, these VMs are called lightweight VMs. After receiving the user function call parameters, the request gateway instructs the backend executor to launch a microVM, run the cloud function within it, return the results to the user, and then destroy the microVM. However, while microVMs are streamlined, each VM requires additional components, such as a Linux kernel, and resource sharing between VMs is difficult, resulting in higher resource usage compared to other solutions. Each microVM startup requires kernel initialization and then runtime environment initialization, a time-consuming process. Many vendors also choose to use containers as the runtime environment for their serverless computing platforms. Containers leverage the Linux kernel's control groups (cgroups) and namespaces to achieve isolation between containers. After receiving the user's function call parameters, the request gateway instructs the backend executor to start a container, run the cloud function in that container, return the results to the user, and then destroy the container. However, because containers share the host kernel, they are vulnerable to attacks such as container escape.

[0006] A small number of vendors choose to use a software runtime as the operating environment for their serverless computing platforms. This solution primarily relies on software technologies to achieve environmental isolation, such as the isolation technology provided by the JavaScript runtime V8. After receiving a user request, the request gateway instructs the backend executor to run the cloud function on its runtime and ultimately returns the results to the user. However, since the runtime primarily relies on software technology to achieve environmental isolation and multiple functions run on a single runtime, its isolation capabilities are weaker than other solutions. Furthermore, the programming languages ​​supported by this solution are limited to specific programming languages, as they are limited by the runtime.

[0007] Researchers have proposed some TEE-based serverless computing technology solutions, such as Clemmy and S-Faas, which implement runtime environment isolation based on TEE. TEE-based environment isolation can protect the runtime from attacks by malicious cloud vendors and provide remote runtime environment verification technology based on TEE remote attestation.

[0008] All of these solutions utilize Intel SGX technology. Intel SGX is a trusted execution environment (TEE) technology developed by Intel. SGX provides users with an application-level trusted execution environment (TEE). Users can deploy confidential program fragments in enclaves for execution. Enclaves are logically isolated from the external operating environment, and enclave memory is encrypted by the CPU's hardware encryption engine to prevent physical attacks. Intel SGX also provides remote attestation technology, which results in an enclave quote. This quote is a report containing various enclave information and a CPU digital signature. Users can use it to verify that the enclave is running on a trusted CPU and that the enclave's initial state is secure and trustworthy. Remote attestation can also be used to establish a secure session connection between the user and the enclave.

[0009] The backend executors in these solutions all choose to run a software runtime within the enclave. This software runtime is responsible for actually running the cloud function. The enclave protects the cloud function execution within the software runtime from external interference and uses remote attestation to verify the security and trustworthiness of the software runtime's initial state. Upon receiving a user request, the request gateway instructs the backend executor to run the cloud function on the enclave's runtime and ultimately returns the results to the user.

[0010] Existing solutions all have the risk of user privacy data leakage caused by reusing the runtime and performance issues caused by not reusing the runtime. Summary of the Invention

[0011] The present invention solves the risk of user privacy data leakage caused by reused runtime and the performance problem caused by non-reuse of runtime in the existing technology by providing a method and system for secure reuse of server-free computing runtime environment based on TEE. It realizes the separation of runtime environment to avoid user privacy leakage, reduces the number of remote proofs, and enables cloud functions in the same function call session to run more efficiently.

[0012] In a first aspect, the present invention provides a method for securely reusing a serverless computing runtime environment based on a TEE, the method comprising: The cloud function developer compiles the cloud function into WebAssembly bytecode, encrypts the WebAssembly bytecode, stores the encrypted bytecode in a database on the serverless computing platform, and sends the decryption key to the authorized user; An authorized user sends function call parameters, remote attestation requests and input parameters to a serverless computing platform, and obtains encrypted information of the serverless computing platform in response to the function call parameters and the remote attestation request, as well as the running result of the serverless computing platform in response to the input parameters; wherein the encrypted information includes: an encrypted session ticket, the encrypted session ticket corresponds one-to-one to the cloud function running instance; the running result is related to the encrypted bytecode.

[0013] In conjunction with the first aspect, in one possible implementation, the serverless computing platform responds to the encrypted information of the function call parameters and the remote attestation request, and the serverless computing platform responds to the execution result of the input parameters, including: Determining whether the function call parameters include an encrypted session ticket; if no encrypted session ticket is present, generating a cloud function running instance and an encrypted session ticket corresponding to the remote attestation request according to a new function call session method, and sending encrypted information and a running result responsive to the input parameters to the authorized user; If there is an encrypted session ticket, the session method is called according to the reuse function, the cloud function running instance corresponding to the encrypted session ticket is reused, and the running result in response to the input parameters is sent to the authorized user.

[0014] In conjunction with the first aspect, in one possible implementation, generating a cloud function running instance and an encrypted session ticket corresponding to the remote attestation request according to the new function call session method, and sending encrypted information and a running result responsive to input parameters to the authorized user, includes: The execution environment scheduler in the serverless computing platform generates first attestation information Q1 related to the execution environment scheduler according to the remote attestation request, and at the same time, the execution environment scheduler requests the backend execution program to create a cloud function running instance; wherein the first attestation information Q1 includes: first signature information, first metric value and first identity information; The execution environment scheduler sends the remote attestation request to the cloud function running instance and obtains second attestation information Q2 as a response; wherein the second attestation information Q2 is generated by the cloud function running instance according to the remote attestation request; the second attestation information Q2 includes: second signature information, second metric value, and second identity information; The execution environment scheduler performs credibility verification on the second proof information Q2, establishes a secure channel between the execution environment scheduler and the cloud function running instance according to the verification result, and generates a session ticket. The execution environment scheduler generates an encrypted session ticket for the session ticket based on the symmetric key generated during its initialization, and sends the encrypted information and the running results in response to the input parameters to the authorized user; wherein, the encrypted information includes: the encrypted session ticket, the first proof information Q1 and the second proof information Q2.

[0015] In conjunction with the first aspect, in one possible implementation, calling the session method according to the reused function, reusing the cloud function running instance corresponding to the encrypted session ticket, and sending the running result responsive to the input parameters to the authorized user, includes: The execution environment scheduler obtains the encrypted session ticket in the encrypted information; The execution environment scheduler decrypts the encrypted session ticket according to the symmetric key to obtain the session ticket, and then obtains the corresponding cloud function running instance according to the session ticket; Determine whether the session ticket is within the validity period. If not, return an error message and require the authorized user to re-create the cloud function running instance according to the new function call session method, generate the cloud function running instance and encrypted session ticket corresponding to the remote attestation request, and send encrypted information and the running result in response to the input parameters to the authorized user; If it is within the validity period, the cloud function running instance is made to load the encrypted bytecode corresponding to the function call parameters in the database, and the encrypted bytecode is decrypted according to the decryption key in the function call parameters to obtain the cloud function running instance that loads the WebAssembly bytecode, and then respond to the function input parameters according to the cloud function running instance that loads the WebAssembly bytecode.

[0016] In conjunction with the first aspect, in one possible implementation, the execution environment scheduler performs credibility verification on the second proof information Q2, establishes a secure channel between the execution environment scheduler and the cloud function running instance based on the verification result, and generates a session ticket, including: The execution environment scheduler verifies the second signature information in the second certification information Q2. If the signature information verification fails, the current session is terminated. If the signature information verification is successful, the second measurement value and the second identity information will be verified again; if the secondary verification is successful, a secure channel will be established between the execution environment scheduler and the cloud function running instance, and a session ticket will be generated; if the secondary verification fails, the current session will be terminated.

[0017] In combination with the first aspect, in one possible implementation, the symmetric key is only stored in the execution environment scheduler, and the validity period of the session ticket is consistent with the life cycle of the cloud function running instance.

[0018] In combination with the first aspect, in one possible implementation, the cloud function running instance is automatically destroyed after its life cycle expires, and the encrypted session ticket automatically becomes invalid after its validity period expires.

[0019] In combination with the first aspect, in one possible implementation, the serverless computing platform includes a backend executor and a request gateway; wherein, multiple cloud function running instances are deployed in the backend executor, and each cloud function running instance is used to load and execute encrypted WebAssembly bytecode; an execution environment scheduler is set in the request gateway, and a secure channel is established between the cloud function running instance and the execution environment scheduler through a remote attestation mechanism.

[0020] In combination with the first aspect, in one possible implementation, the cloud function running instance and the execution environment scheduler run in an independent trusted execution environment.

[0021] In a second aspect, the present invention provides a secure reuse system for a serverless computing runtime environment based on TEE, the system comprising: a cloud function developer, a serverless computing platform, and an authorized user; The cloud function developer compiles the cloud function into WebAssembly bytecode, encrypts the WebAssembly bytecode, stores the encrypted bytecode in a database, and sends the decryption key to authorized users; The serverless computing platform is configured to respond to function call parameters, remote attestation requests, and input parameters sent by an authorized user, and obtain encrypted information and an execution result; wherein the encrypted information includes an encrypted session ticket, which corresponds one-to-one to a cloud function execution instance; and the execution result is associated with the encrypted bytecode. Authorized users are used to send function call parameters, remote proof requests, and input parameters to the serverless computing platform, and obtain encrypted information and running results.

[0022] One or more technical solutions provided in the present invention have at least the following technical effects or advantages: The present invention is used by cloud function developers to compile cloud functions into WebAssembly bytecode, encrypt the WebAssembly bytecode, store the encrypted bytecode in the database of the serverless computing platform, and send the decryption key to authorized users; cloud functions are encrypted and stored after being compiled into WebAssembly bytecode, and the decryption key is only distributed to authorized users. This "code encryption + key isolation" mechanism effectively prevents platform administrators or third parties from directly stealing or tampering with the original code, protecting the developer's intellectual property and sensitive logic; authorized users are used to send function call parameters, remote proof requests, and input to the serverless computing platform. Input parameters and obtain the encrypted information of the serverless computing platform in response to the function call parameters and remote attestation request, as well as the running results in response to the input parameters; wherein, the encrypted information includes: encrypted session tickets, which correspond one-to-one to the cloud function running instance; authorized users can verify the credibility of the cloud function running environment through remote attestation requests; the encrypted session tickets returned by the platform are bound to the cloud function running instance to ensure that the function is only decrypted and executed in a verified secure environment, preventing malicious nodes or man-in-the-middle attacks; the decryption key is only distributed to authorized users, not stored in the platform; authorized users need to provide legal keys to trigger function execution, thus achieving fine-grained access control. BRIEF DESCRIPTION OF THE DRAWINGS

[0023] Figure 1 A flowchart of the steps for a secure and efficient reuse method for a serverless computing runtime environment based on TEE provided in an embodiment of the present invention; Figure 2 A schematic diagram of a process flow for creating a function call session provided by an embodiment of the present invention; Figure 3 A schematic diagram of a multiplexing function call session method provided in an embodiment of the present invention. DETAILED DESCRIPTION

[0024] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts are within the scope of protection of the present invention.

[0025] The present invention provides a method for secure reuse of a serverless computing runtime environment based on TEE, see Figure 1 , including the following steps S101 to S102.

[0026] S101, cloud function developers compile cloud functions into WebAssembly bytecode, encrypt the WebAssembly bytecode, store the encrypted bytecode in the database of the serverless computing platform, and send the decryption key to authorized users.

[0027] Here, the serverless computing platform includes a backend executor and a request gateway; wherein, multiple cloud function running instances (FE instances) are deployed in the backend executor, and the cloud function running instances all run in a trusted execution environment. Each cloud function instance is used to load and execute encrypted WebAssembly bytecode; an execution environment scheduler (DE) is deployed in the request gateway, and a secure channel is established between the FE instance and the DE through a remote attestation mechanism. It can be understood that both the FE instance and the DE run in an independent trusted execution environment.

[0028] For example, developers write cloud functions in a high-level programming language and compile them into WebAssembly bytecode. The WebAssembly runtime in the backend FE instance that executes the program can load and run the WebAssembly bytecode. The developer generates a key and encrypts the bytecode using symmetric encryption. The encrypted bytecode is then stored in the serverless computing platform's database.

[0029] Cloud function developers typically distribute decryption keys to trusted authorized users. Often, the cloud function developer and authorized user are the same entity, eliminating the need for key distribution. If the cloud function developer believes WebAssembly bytecode encryption is unnecessary, they can upload the plaintext WebAssembly bytecode directly without encrypting the function.

[0030] S102, the authorized user sends function call parameters, remote proof request and input parameters to the serverless computing platform, and obtains the encrypted information of the serverless computing platform in response to the function call parameters and remote proof request, as well as the running results of the serverless computing platform in response to the input parameters; wherein the encrypted information includes: encrypted session tickets, the encrypted session tickets correspond one-to-one to the FE instances; the running results are related to the encrypted bytecode.

[0031] Specifically, in step S102, the serverless computing platform responds to the encrypted information of the function call parameters and the remote attestation request, and the operation result of the serverless computing platform in response to the input parameters, including: (1) Determine whether the function call parameters include an encrypted session ticket. If there is no encrypted session ticket, generate an FE instance and an encrypted session ticket corresponding to the remote attestation request according to the new function call session method, and send encrypted information and the operation results in response to the input parameters to the authorized user.

[0032] Specifically, according to the new function call session method, an FE instance and an encrypted session ticket corresponding to the remote attestation request are generated, and encrypted information and the operation results in response to the input parameters are sent to the authorized user, including: (1.1) The execution environment scheduler in the serverless computing platform generates first attestation information Q1 related to the execution environment scheduler based on the remote attestation request, and simultaneously requests the backend execution program to create an FE instance; wherein the first attestation information Q1 includes: first signature information, first metric value, and first identity information; (1.2) The execution environment scheduler sends a remote attestation request to the FE instance and obtains second attestation information Q2 in response. The second attestation information Q2 is generated by the FE instance in response to the remote attestation request and includes: second signature information, second metric value, and second identity information. (1.3) The execution environment scheduler verifies the credibility of the second proof information Q2, establishes a secure channel between the execution environment scheduler and the FE instance based on the verification result, and generates a session ticket; Specifically, in (1.3), the execution environment scheduler verifies the credibility of the second proof information Q2, establishes a secure channel between the execution environment scheduler and the FE instance based on the verification result, and generates a session ticket, including: (1.3.1) The execution environment scheduler verifies the second signature information in the second proof information Q2. If the signature information verification fails, the current session is terminated. (1.3.2) If the signature information verification passes, the second metric value and second identity information are verified again. If the second verification passes, a secure channel is established between the execution environment scheduler and the FE instance, and a session ticket is generated. If the second verification fails, the current session is terminated.

[0033] The symmetric key here is generated when the execution environment scheduler is initialized, and the validity period of the session ticket is consistent with the life cycle of the FE instance.

[0034] (1.4) The execution environment scheduler generates an encrypted session ticket based on the symmetric key for the session ticket, and sends the encrypted information and the running result in response to the input parameters to the authorized user; wherein the encrypted information includes: the encrypted session ticket, the first proof information Q1 and the second proof information Q2.

[0035] It can be understood that the above process is the initial cloud function call and the new function call session process.

[0036] For example, see Figure 2 Diagram of calling the session method for a new function.

[0037] ① The authorized user initiates a cloud function call request to the request gateway and simultaneously initiates a remote proof request to the DE; ②DE generates the first attestation information (denoted as Q1) based on the remote attestation request, and requests the backend execution program to create an FE instance. After the requested FE instance is created, DE initiates a remote attestation request to the FE instance. Here, Q1 is usually digitally signed by the CPU's built-in security key, which contains DE's first signature information, first measurement value and first identity information.

[0038] ③ The FE instance generates the second proof information (denoted as Q2) according to the remote proof request and sends Q2 to the DE; here, Q2 is digitally signed by the CPU's built-in security key, which contains the FE instance's second signature information, second measurement value and second identity information.

[0039] ④DE determines whether the FE instance is secure and trustworthy based on the FE instance measurement value and signature contained in Q2. If the FE instance is secure and trustworthy, DE establishes a secure session with the FE instance; ⑤DE generates a symmetrically encrypted ticket (the encryption key of the ticket is randomly generated when DE is initialized). The ticket stores the correspondence between the function call session and the FE, returns encrypted information to the authorized user, and encrypts the session ticket (session ticket), the first proof information Q1 and the second proof information Q2.

[0040] ⑥ The authorized user verifies the DE and FE instances according to Q1 and Q2. The verification process is the same as the Q2 verification process in (1.3). If both are verified, the function input and bytecode decryption key are sent to the DE and the function call session ticket is stored. Otherwise, the request is terminated. ⑦After receiving the function input and decryption key, DE forwards it to the FE instance and asks it to load the WebAssembly bytecode corresponding to the user request; ⑧The FE instance loads and decrypts the bytecode, runs the cloud function bytecode using the user's function input in the WebAssembly runtime, and returns the results to the DE after the execution is completed; ⑨DE returns the running results to the authorized user.

[0041] (2) If there is an encrypted session ticket, the session method is called according to the reuse function, the FE running instance corresponding to the encrypted session ticket is reused, and the running result in response to the input parameters is sent to the authorized user.

[0042] Here, the session method is called according to the reuse function, the FE running instance corresponding to the encrypted session ticket is reused, and the running result corresponding to the input parameters is sent to the authorized user, including: (2.1) The execution environment scheduler obtains the encrypted session ticket in the encrypted information; (2.2) The execution environment scheduler decrypts the encrypted session ticket according to the symmetric key to obtain the session ticket, and then obtains the corresponding FE instance according to the session ticket pair; The FE instance here is automatically destroyed after exceeding its life cycle, and the encrypted session ticket automatically becomes invalid after exceeding its validity period.

[0043] (2.3) Determine whether the session ticket is within the validity period. If not, return an error message and require the authorized user to re-create the cloud function running instance according to the new function call session method, generate the cloud function running instance and encrypted session ticket corresponding to the remote attestation request, and send the encrypted information and the running result in response to the input parameters to the authorized user; (2.4) If it is within the validity period, the FE instance is instructed to load the encrypted bytecode corresponding to the function call parameters into the database, and the encrypted bytecode is decrypted according to the decryption key in the function call parameters to obtain the FE instance that loads the WebAssembly bytecode. The FE instance that loads the WebAssembly bytecode then responds to the function input parameters according to the FE instance that loads the WebAssembly bytecode.

[0044] For example, see Figure 3 Diagram of calling session method for reused functions.

[0045] ① The authorized user initiates a cloud function call request to the request gateway again. The request includes function call parameters such as the encrypted session ticket, the cloud function corresponding bytecode decryption key, and the function input parameters; ②DE decrypts the function call session ticket, obtains the FE corresponding to the current function call session, and transmits the function input and decryption key to the corresponding FE instance; ③ The FE instance loads and decrypts the cloud function bytecode corresponding to the request, runs the cloud function bytecode using the authorized user's function input in the WebAssembly runtime, and returns the result to the DE after the execution is completed; ④DE returns the running results to the authorized user.

[0046] A function call session ticket has a validity period, and the corresponding FE has a similar lifespan. Upon expiration, the FE instance is destroyed. Users can decide whether to upload a function call session ticket based on the confidentiality of the data they are processing. If an invalid session ticket is uploaded, the request gateway will return an error message and require the cloud function to be re-invoked as a new function call.

[0047] Compared with the existing non-reusing TEE solution, the present invention is more efficient. Compared with the existing reusing TEE solution, the present invention is more secure. Since the present invention reuses the trusted execution environment for only one function call session of one user, the cloud function operation between different users and different sessions still uses the trusted execution environment to separate the operating environment to avoid user privacy leakage. Even if the operating environment of the current session is attacked, it will not affect the cloud function operation and privacy data security of other users and other sessions. Compared with the existing non-reusing TEE solution, since all function requests in a function call session of one user of the present invention reuse the same trusted execution environment, the time and resource consumption caused by repeatedly creating a trusted execution environment is eliminated, the number of remote attestations is reduced, and the cloud functions in the same function call session can run more efficiently. Users can choose whether to reuse the trusted execution environment (whether to include a session ticket in the request) based on the confidentiality of their own data to be processed, giving users room for choice.

[0048] In a second aspect, the present invention provides a secure reuse system for a serverless computing runtime environment based on TEE, the system comprising: a cloud function developer, a serverless computing platform, and an authorized user; Cloud function developers compile cloud functions into WebAssembly bytecode, encrypt the WebAssembly bytecode, store the encrypted bytecode in a database, and send the decryption key to authorized users. The serverless computing platform is used to respond to function call parameters, remote attestation requests, and input parameters sent by authorized users, and obtain encrypted information and execution results. The encrypted information includes: encrypted session tickets, which correspond one-to-one to FE instances; the execution results are related to the encrypted bytecode; Authorized users are used to send function call parameters, remote proof requests, and input parameters to the serverless computing platform, and obtain encrypted information and running results.

[0049] The various embodiments in this specification are described in a progressive manner. References to the same or similar parts between the various embodiments are sufficient. Each embodiment focuses on the differences from other embodiments. All or part of the present invention can be used in a variety of general or specialized computer system environments or configurations. For example, personal computers, server computers, handheld or portable devices, tablet devices, mobile communication terminals, multiprocessor systems, microprocessor-based systems, programmable electronic devices, network PCs, minicomputers, mainframe computers, and distributed computing environments that include any of the above systems or devices.

[0050] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit the present invention. Although the present invention has been described in detail with reference to the aforementioned embodiments, it should be understood by those skilled in the art that the technical solutions described in the aforementioned embodiments may still be modified, or some or all of the technical features thereof may be replaced by equivalents. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the scope of the technical solutions of the present invention.

Claims

1. A method for secure reuse of a serverless computing runtime environment based on TEE, characterized in that: include: The cloud function developer compiles the cloud function into WebAssembly bytecode, encrypts the WebAssembly bytecode, stores the encrypted bytecode in a database on the serverless computing platform, and sends the decryption key to the authorized user; An authorized user sends function call parameters, remote attestation requests and input parameters to a serverless computing platform, and obtains encrypted information of the serverless computing platform in response to the function call parameters and the remote attestation request, as well as the running result of the serverless computing platform in response to the input parameters; wherein the encrypted information includes: an encrypted session ticket, the encrypted session ticket corresponds one-to-one to the cloud function running instance; the running result is related to the encrypted bytecode.

2. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 1, characterized in that: The serverless computing platform responds to the function call parameters and the encrypted information of the remote attestation request, and the execution result of the serverless computing platform responding to the input parameters, including: Determining whether the function call parameters include an encrypted session ticket; if no encrypted session ticket is present, generating a cloud function running instance and an encrypted session ticket corresponding to the remote attestation request according to a new function call session method, and sending encrypted information and a running result responsive to the input parameters to the authorized user; If there is an encrypted session ticket, the session method is called according to the reuse function, the cloud function running instance corresponding to the encrypted session ticket is reused, and the running result in response to the input parameters is sent to the authorized user.

3. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 2, characterized in that: The method of creating a new function call session generates a cloud function running instance and an encrypted session ticket corresponding to the remote attestation request, and sends encrypted information and a running result in response to the input parameters to the authorized user, including: The execution environment scheduler in the serverless computing platform generates first attestation information Q1 related to the execution environment scheduler according to the remote attestation request, and at the same time, the execution environment scheduler requests the backend execution program to create a cloud function running instance; wherein the first attestation information Q1 includes: first signature information, first metric value and first identity information; The execution environment scheduler sends the remote attestation request to the cloud function running instance and obtains second attestation information Q2 as a response; wherein the second attestation information Q2 is generated by the cloud function running instance according to the remote attestation request; the second attestation information Q2 includes: second signature information, second metric value, and second identity information; The execution environment scheduler performs credibility verification on the second proof information Q2, establishes a secure channel between the execution environment scheduler and the cloud function running instance according to the verification result, and generates a session ticket. The execution environment scheduler generates an encrypted session ticket for the session ticket based on the symmetric key generated during its initialization, and sends the encrypted information and the running results in response to the input parameters to the authorized user; wherein, the encrypted information includes: the encrypted session ticket, the first proof information Q1 and the second proof information Q2.

4. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 3, characterized in that: The method of calling the session method according to the reuse function, reusing the cloud function running instance corresponding to the encrypted session ticket, and sending the running result in response to the input parameters to the authorized user, includes: The execution environment scheduler obtains the encrypted session ticket in the encrypted information; The execution environment scheduler decrypts the encrypted session ticket according to the symmetric key to obtain the session ticket, and then obtains the corresponding cloud function running instance according to the session ticket; Determine whether the session ticket is within the validity period. If not, return an error message and require the authorized user to re-create the cloud function running instance according to the new function call session method, generate the cloud function instance and encrypted session ticket corresponding to the remote attestation request, and send the encrypted information and the running result in response to the input parameters to the authorized user; If it is within the validity period, the cloud function running instance is made to load the encrypted bytecode corresponding to the function call parameters in the database, and the encrypted bytecode is decrypted according to the decryption key in the function call parameters to obtain the cloud function running instance that loads the WebAssembly bytecode, and then respond to the function input parameters according to the cloud function running instance that loads the WebAssembly bytecode.

5. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 3, characterized in that: The execution environment scheduler performs credibility verification on the second proof information Q2, establishes a secure channel between the execution environment scheduler and the cloud function running instance based on the verification result, and generates a session ticket, including: The execution environment scheduler verifies the second signature information in the second certification information Q2. If the signature information verification fails, the current session is terminated. If the signature information verification is successful, the second measurement value and the second identity information will be verified again; if the secondary verification is successful, a secure channel will be established between the execution environment scheduler and the cloud function running instance, and a session ticket will be generated; if the secondary verification fails, the current session will be terminated.

6. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 3, characterized in that: The symmetric key is only stored in the execution environment scheduler, and the validity period of the session ticket is consistent with the life cycle of the cloud function running instance.

7. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 3, characterized in that: The cloud function running instance is automatically destroyed after its life cycle expires, and the encrypted session ticket automatically becomes invalid after its validity period expires.

8. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 1, characterized in that: The serverless computing platform includes a backend execution program and a request gateway; wherein: Multiple cloud function running instances can be deployed in the backend execution program, and each cloud function running instance is used to load and execute encrypted WebAssembly bytecode; An execution environment scheduler is set in the request gateway, and a secure channel is established between the cloud function running instance and the execution environment scheduler through a remote certification mechanism.

9. The method for secure reuse of a serverless computing runtime environment based on TEE according to claim 1, characterized in that: The cloud function running instance and execution environment scheduler run in an independent trusted execution environment.

10. A secure reuse system for serverless computing runtime environments based on TEE, characterized in that: The system includes: cloud function developers, serverless computing platforms, and authorized users; The cloud function developer compiles the cloud function into WebAssembly bytecode, encrypts the WebAssembly bytecode, stores the encrypted bytecode in a database, and sends the decryption key to authorized users; The serverless computing platform is configured to respond to function call parameters, remote attestation requests, and input parameters sent by an authorized user, and obtain encrypted information and an execution result; wherein the encrypted information includes an encrypted session ticket, which corresponds one-to-one to a cloud function execution instance; and the execution result is associated with the encrypted bytecode. Authorized users are used to send function call parameters, remote proof requests, and input parameters to the serverless computing platform, and obtain encrypted information and running results.

Citation Information

Cited By

  • Method and device for hierarchical decryption of fine-tuned LoRA model by computing power of intelligent computing cloud platform

    CN122475864A