seL4 Microkernel for virtualization use-cases: Potential directions towards a standard VMM

10/09/2022
by   Everton de Matos, et al.
0

Virtualization plays an essential role in providing security to computational systems by isolating execution environments. Many software solutions, called hypervisors, have been proposed to provide virtualization capabilities. However, only a few were designed for being deployed at the edge of the network, in devices with fewer computation resources when compared with servers in the Cloud. Among the few lightweight software that can play the hypervisor role, seL4 stands out by providing a small Trusted Computing Base and formally verified components, enhancing its security. Despite today being more than a decade with seL4 microkernel technology, its existing userland and tools are still scarce and not very mature. Over the last few years, the main effort has been put into increasing the maturity of the kernel itself and not the tools and applications that can be hosted on top. Therefore, it currently lacks proper support for a full-featured userland Virtual Machine Monitor, and the existing one is quite fragmented. This article discusses the potential directions to a standard VMM by presenting our view of design principles and feature set needed. This article does not intend to define a standard VMM, we intend to instigate this discussion through the seL4 community.

READ FULL TEXT

page 11

page 14

research
08/20/2023

Towards a Formally Verified Security Monitor for VM-based Confidential Computing

Confidential computing is a key technology for isolating high-assurance ...
research
04/12/2023

CoVE: Towards Confidential Computing on RISC-V Platforms

Multi-tenant computing platforms are typically comprised of several soft...
research
07/01/2021

A Review on Edge Analytics: Issues, Challenges, Opportunities, Promises, Future Directions, and Applications

Edge technology aims to bring Cloud resources (specifically, the compute...
research
06/26/2022

WebAssembly as a Common Layer for the Cloud-edge Continuum

Over the last decade, the cloud computing landscape has transformed from...
research
02/06/2023

Decentralized Zero-Trust Framework for Digital Twin-based 6G

The Sixth Generation (6G) network is a platform for the fusion of the ph...
research
05/12/2022

IVOIRE Deliverable 1.1: Classification of existing VOs tools and Formalization of VOs semantics

This report discusses the foundations of the VO approach. Then, it explo...
research
10/25/2014

The Karlskrona manifesto for sustainability design

Sustainability is a central concern for our society, and software system...

Please sign up or login with your details

Forgot password? Click here to reset