首页> 外文会议>International Symposium on Software Reliability Engineering Workshops >Isolating Real-Time Safety-Critical Embedded Systems via SGX-Based Lightweight Virtualization
【24h】

Isolating Real-Time Safety-Critical Embedded Systems via SGX-Based Lightweight Virtualization

机译:通过基于SGX的轻量级虚拟化隔离实时的安全关键嵌入式系统

获取原文

摘要

A promising approach for designing critical embedded systems is based on virtualization technologies and multi-core platforms. These enable the deployment of both real-time and general-purpose systems with different criticalities in a single host. Integrating virtualization while also meeting the real-time and isolation requirements is non-trivial, and poses significant challenges especially in terms of certification. In recent years, researchers proposed hardware-assisted solutions to face issues coming from virtualization, and recently the use of Operating System (OS) virtualization as a more lightweight approach. Industries are hampered in leveraging this latter type of virtualization despite the clear benefits it introduces, such as reduced overhead, higher scalability, and effortless certification since there is still lack of approaches to address drawbacks. In this position paper, we propose the usage of Intel's CPU security extension, namely SGX, to enable the adoption of enclaves based on unikernel, a flavor of OS-level virtualization, in the context of real-time systems. We present the advantages of leveraging both the SGX isolation and the unikernel features in order to meet the requirements of safety-critical real-time systems and ease the certification process.
机译:一种用于设计关键嵌入式系统的有前途的方法是基于虚拟化技术和多核平台的。这些功能可以在单个主机中部署具有不同关键性的实时系统和通用系统。在满足实时性和隔离性要求的同时集成虚拟化并非易事,特别是在认证方面提出了巨大的挑战。近年来,研究人员提出了硬件辅助解决方案,以应对虚拟化带来的问题,最近还提出了使用操作系统(OS)虚拟化作为一种​​更轻量级的方法。尽管它带来了明显的好处,例如减少的开销,更高的可伸缩性和轻松的认证,但由于仍然缺乏解决缺点的方法,因此行业在利用后者的虚拟化方面受到了阻碍。在本立场文件中,我们建议使用Intel的CPU安全扩展,即SGX,以在实时系统的情况下采用基于unikernel的安全区域,这是一种OS级虚拟化。我们展示了利用SGX隔离和Unikernel功能的优势,以满足对安全至关重要的实时系统的要求并简化了认证过程。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号