- Resource accounting on SGX “enclaved” FaaS.
- Trusted timer: built using TSX + additional timer thread
- Model: function trusted by user, but not service provider(platform) => sandbox
- KMS, transitive attestation, encryption
- Implementation on Apache OpenWhisk