arrow
Return

seL4: Formal Verification of an Operating-System Kernel

delete2010-06-01
delete161
PRE
AI
G
Gerwin Klein *
J
June Andronick
K
Kevin Elphinstone
G
Gernot Heiser
D
David Cock
P
Philip Derrin
D
Dhammika Elkaduwe
K
Kai Engelhardt
R
Rafal Kolanski
M
Michael Norrish
T
Thomas Sewell
H
Harvey Tuch
S
Simon Winwood
DOI:10.1145/1743546.1743574delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
We report on the formal, machine-checked verification of the seL4 microkernel from an abstract specification down to its C implementation. We assume correctness of compiler, assembly code, hardware, and boot code. seL4 is a third-generation microkernel of L4 provenance, comprising 8700 lines of C and 600 lines of assembler. Its performance is comparable to other high-performance L4 kernels. We prove that the implementation always strictly follows our high-level abstract specification of kernel behavior. This encompasses traditional design and implementation safety properties such as that the kernel will never crash, and it will never perform an unsafe operation. It also implies much more: we can predict precisely how the kernel will behave in every possible situation.
Keywords:
PROTECTION
AI Summary

AI Summary

Key information extracted from the uploaded paper, including a brief overview, abstract, background, key highlights, visual analysis, and future outlook.

Journal

Communications of the ACM cover
Communications of the ACM
IF:
12.2
Papers:
1.2W
Citations:
3.7W

Organization

N
nicta
Scholars:
191
Papers: 167
Citations: 0