Where are we with time protection? Verification and cross-domain communication update
Authors
School of Computer Science and Engineering
UNSW,
Sydney 2052, Australia
Abstract
This talk will give an update on the past two years' advances at Trustworthy Systems in (1) our ongoing efforts to verify time protection for seL4, as well as (2) our implementation in seL4 of new time-protected cross-domain communication mechanisms on RISC-V Cheshire. On the formal verification front, I will present our results so far, thanks to a crucial rethink of our approach to verifying a key aspect of time protection for seL4 down to its C implementation, which has eliminated the main cause of the project's previously large number of breakages to seL4's existing correctness proofs. On the OS kernel design and development front, I will present both legacy and hardware-supported implementation options we evaluated for seL4 to support cross-domain shared memory and notification mechanisms that ensure one-way communications are truly one way, without permitting any timing channels in either (but most importantly, the backwards) direction. I will also remark on where we stand and next steps forward to formalise and verify that time protection is enforced by these new mechanisms.
BibTeX Entry
@misc{Sison_26:sel4s,
author = {Rob Sison},
location = {Vancouver, BC, Canada},
month = sep,
note = {Talk at the 8th {seL4} {Summit}},
title = {Where are we with Time Protection? Verification and Cross-domain Communication Update},
url = {https://sel4summit2026.sched.com/event/2Prqx},
year = {2026}
}
Slides
BibTeX