Design and Verification of Microprocessor Systems for High-Assurance Applications 2010
DOI: 10.1007/978-1-4419-1539-9_6
|View full text |Cite
|
Sign up to set email alerts
|

Formal Verification of Partition Management for the AAMP7G Microprocessor

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
4
1

Citation Types

2
17
0

Year Published

2010
2010
2021
2021

Publication Types

Select...
6
1
1

Relationship

1
7

Authors

Journals

citations
Cited by 34 publications
(19 citation statements)
references
References 6 publications
2
17
0
Order By: Relevance
“…In Heitmeyer et al [12], for instance, partitions have explicit input and output buffers, but communication is delegated to external agents, in this way allowing properties like absence of infiltration (roughly: direct flows) and exfiltration (indirect flows) to be proved. Similar results are reported in [23,4] and in [30] at the firmware level. Murray et al [20] considers noninterference in presence of a dynamic scheduler and uses a version of intransitive noninterference [24] (actually, NI) to allow a scheduler to influence which partition is scheduled, without permitting the scheduler to be used as a covert channel, as discussed briefly in the introduction.…”
Section: Related Worksupporting
confidence: 88%
See 2 more Smart Citations
“…In Heitmeyer et al [12], for instance, partitions have explicit input and output buffers, but communication is delegated to external agents, in this way allowing properties like absence of infiltration (roughly: direct flows) and exfiltration (indirect flows) to be proved. Similar results are reported in [23,4] and in [30] at the firmware level. Murray et al [20] considers noninterference in presence of a dynamic scheduler and uses a version of intransitive noninterference [24] (actually, NI) to allow a scheduler to influence which partition is scheduled, without permitting the scheduler to be used as a covert channel, as discussed briefly in the introduction.…”
Section: Related Worksupporting
confidence: 88%
“…Due to our use of memory protection, this is really a noninterference-like property of the ARMv7-A architecture rather than a property of the separation kernel. This property is similar to the partition management result reported in [30].…”
Section: Introductionsupporting
confidence: 89%
See 1 more Smart Citation
“…Nevertheless, both mechanisms are generally not equipped with the functionality needed to host a commodity OS. Conversely, formally verified processor architectures specifically designed with a focus on logical partitioning [51] and information flow control [6] can be used to achieve isolation.…”
Section: Related Workmentioning
confidence: 99%
“…Noninterference Verication for Separation Hardware Wilding et al [24] verify noninterference for the partitioning system of the AAMP7G microprocessor. The processor can be seen as a separation kernel in hardware, but lacks for example user-visible registers.…”
Section: Related Workmentioning
confidence: 99%