Towards Modular Specification and Verification of Concurrent Hypervisor-based Isolation
NOVA is a microhypervisor that executes in a privileged kernel mode and that provides only basic services for virtualization, isolation, scheduling and management of physical system resources. NOVA’s design goal is to reduce the critical code base, and to leave richer virtualization features to user applications, such as a Virtual Machine Monitor (VMM), that run in a less privileged mode (e.g. user mode). The size (about 17K lines of code and 15 hypercalls) makes it a suitable target for formal verification.
In the talk, we present our on-going effort in formally verifying the concurrent NOVA microhypervisor in a modular, tractable approach. We show how to decompose the specifications and proofs of NOVA’s hypercalls using concurrent separation logic, and discuss the (open) challenges.
Sat 20 JanDisplayed time zone: London change
16:00 - 17:30 | |||
16:00 22mTalk | Computational-Bounded Robust Compilation and Universally Composable Security PriSC Robert Künnemann CISPA Helmholtz Center for Information Security, Ethan Cecchetti University of Wisconsin-Madison File Attached | ||
16:22 22mTalk | Gradual Verification for Smart Contracts PriSC Haojia Sun Shanghai Jiao Tong University, Kunal Singh Carnegie Mellon University, Jan-Paul Ramos-Davila Cornell University, Jonathan Aldrich Carnegie Mellon University, Jenna DiVincenzo (Wise) Purdue University File Attached | ||
16:45 22mTalk | Towards Modular Specification and Verification of Concurrent Hypervisor-based Isolation PriSC File Attached | ||
17:07 8mDay closing | Closing Remarks PriSC Shweta Shinde ETH Zurich |