Designing new low-level systems programming languages suitable for verification - pKVM
Designing new low-level systems programming languages suitable for verification - pKVM
批准号:
2744391
负责人:
金额:
$0.0万
依托单位:
依托单位国家:
英国
项目类别:
Studentship
财政年份:
2020
资助国家:
英国
项目状态:
已结题
起止时间:
2020 至 --
中文摘要
点击翻译按钮获取中文摘要
英文摘要
pKVM (protected KVM) is an ongoing project to enable KVM on Google's Android mobile operating system. It has specific goals which make it a challenging, but worthwhile target for formal verification. A hypervisor is a piece of software that creates and manages virtual machines. Though most users are likely to have come across examples such as VirtualBox, VMWare or Parallels Desktop for Mac, this proposal is concerned with a different kind of hypervisor.Bare-metal (also known as Type-1 ) hypervisors run directly on hardware (as opposed to the Type-2 examples given earlier, which require an operating system torun on). KVM (kernel-based virtual machine) is a Linux kernel module which allows the Linux kernel to run as a bare-metal hypervisor.pKVM (protected KVM) is an ongoing project to enable KVM on Google's Android mobile operating system (or more specifically, the Android fork of Linux).Its main, high-level goal is to support Android's security model: "guest data remains private even if the host kernel has been compromised". Expressed another way, pKVM needs to "de-privilege third party code and provide a portable environment in which services are isolated from one another and also from the rest of Android". Achieving this would allow Google to provide a single, extensible kernel binary to platform vendors (such as phone manufacturers), who can then link it (via a small ABI which Google guarantees will be stable across updates) with software to support their particular hardware platform. There are two advantages to doing so: security and functionality.Currently, each hardware platform has its own kernel, which makes delivering security patches for Android difficult, since each vendor needs to update their version of the kernel. A single, extensible binary would eliminate duplication of effort and reduce delays and fragmentation in the dispersion of security updates. It also has a similar effect with regards to exposing new hardware features quickly and at the correct level of abstraction across many different hardware platforms.However, there is an important trade-off here: any vulnerabilities and errors in pKVM itself could undermine the security and functionality benefits mentioned above. As such, it becomes important to gain a higher level of confidence in the correctness of the design and implementation.One way to increase the confidence in both is to keep them very simple, and this is feasible because the features pKVM needs to support are also (relatively) simple (for example, message passing, context switching, and page-table set-up and translations). Another way to do so is to formally reason and prove aspects of (if not the whole) program correct.
期刊论文(0)
专著(0)
科研奖励(0)
会议论文
国内基金
海外基金
登录
查看更多内容
脊髓新鉴定SNAPR神经元相关环路介导SCS电刺激抑制恶性瘙痒
-
批准号:82371478
-
项目类别:面上项目
-
资助金额:48.00万元
-
批准年份:2023
-
负责人:焦英甫
-
依托单位:
tau轻子衰变与新物理模型唯象研究
-
批准号:11005033
-
项目类别:青年科学基金项目
-
资助金额:18.0万元
-
批准年份:2010
-
负责人:李文君
-
依托单位:
HIV gp41的NHR区新靶点的确证及高效干预
-
批准号:81072676
-
项目类别:面上项目
-
资助金额:33.0万元
-
批准年份:2010
-
负责人:戴秋云
-
依托单位:
强子对撞机上新物理信号的多轻子末态研究
-
批准号:10675110
-
项目类别:面上项目
-
资助金额:36.0万元
-
批准年份:2006
-
负责人:蒋一
-
依托单位: