Affiliation:
1. Aarhus University, Denmark
Abstract
Thin hypervisors make it possible to isolate key security components like keychains, fingerprint readers, and digital wallets from the easily-compromised operating system.
To work together, virtual machines running on top of the hypervisor can make hypercalls to the hypervisor to share pages between each other in a controlled way.
However, the design of such hypercall ABIs remains a delicate balancing task between conflicting needs for expressivity, performance, and security.
In particular, it raises the question of what makes the specification of a hypervisor, and of its hypercall ABIs, good enough for the virtual machines.
In this paper, we validate the expressivity and security of the design of the hypercall ABIs of Arm's FF-A.
We formalise a substantial fragment of FF-A as a machine with a simplified ISA in which hypercalls are steps of the machine.
We then develop VMSL, a novel separation logic, which we prove sound with respect to the machine execution model, and use it to reason modularly about virtual machines which communicate through the hypercall ABIs, demonstrating the hypercall ABIs' expressivity.
Moreover, we use the logic to prove robust safety of communicating virtual machines, that is, the guarantee that even if some of the virtual machines are compromised and execute unknown code, they cannot break the safety properties of other virtual machines running known code.
This demonstrates the intended security guarantees of the hypercall ABIs.
All the results in the paper have been formalised in Coq using the Iris framework.
Publisher
Association for Computing Machinery (ACM)
Subject
Safety, Risk, Reliability and Quality,Software
Reference54 articles.
1. Foundational proof-carrying code
2. Position paper: the science of deep specification
3. Arm. 2021. Morello project. https://www.morello-project.org/ Arm. 2021. Morello project. https://www.morello-project.org/
4. Arm Ltd.. 2022. Arm Firmware Framework for Arm A-profile version 1.1 - DEN0077A. https://documentation-service.arm.com/static/624d5f52dc9d4f0e74a54e5f Arm Ltd.. 2022. Arm Firmware Framework for Arm A-profile version 1.1 - DEN0077A. https://documentation-service.arm.com/static/624d5f52dc9d4f0e74a54e5f
5. Isla: Integrating Full-Scale ISA Semantics and Axiomatic Concurrency Models
Cited by
1 articles.
订阅此论文施引文献
订阅此论文施引文献,注册后可以免费订阅5篇论文的施引文献,订阅后可以查看论文全部施引文献