2019 IEEE International Symposium on Software Reliability Engineering Workshops (ISSREW) 2019
DOI: 10.1109/issrew.2019.00089
|View full text |Cite
|
Sign up to set email alerts
|

Isolating Real-Time Safety-Critical Embedded Systems via SGX-Based Lightweight Virtualization

Abstract: A promising approach for designing critical embedded systems is based on virtualization technologies and multicore platforms. These enable the deployment of both real-time and general-purpose systems with different criticalities in a single host. Integrating virtualization while also meeting the real-time and isolation requirements is non-trivial, and poses significant challenges especially in terms of certification. In recent years, researchers proposed hardware-assisted solutions to face issues coming from v… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1

Citation Types

0
2
0

Year Published

2021
2021
2024
2024

Publication Types

Select...
4
3

Relationship

1
6

Authors

Journals

citations
Cited by 8 publications
(3 citation statements)
references
References 29 publications
0
2
0
Order By: Relevance
“…To fulfill the need of safety-critical real-time systems and streamline the certification process, the authors in [40] examined the benefits of utilizing both SGX isolation and unikernel features. Another proposed framework for real-time orchestration introduces extensive modifications of the Kubernetes code-base and uses a unique patch for the Linux kernel to deploy best-effort and real-time tasks [41].…”
Section: Related Workmentioning
confidence: 99%
“…To fulfill the need of safety-critical real-time systems and streamline the certification process, the authors in [40] examined the benefits of utilizing both SGX isolation and unikernel features. Another proposed framework for real-time orchestration introduces extensive modifications of the Kubernetes code-base and uses a unique patch for the Linux kernel to deploy best-effort and real-time tasks [41].…”
Section: Related Workmentioning
confidence: 99%
“…236 This is enabled by the concept of hardware virtualization 237 supported by higher core processing power. 238 A partitioned OFP software design, as demonstrated by Lim et al, 2012, divided into core hardware interface and application modules with submodules for various avionics functions, provides a "separation of concerns," where a fault in one partition does not affect the other. Lim et al, 2012, concludes that "robust partitioning of software can easily and costeffectively obtain software safety assurance" (for the DO-178 B/C) " [and] each partition can be designed and developed by a specialized company reducing the cost."…”
Section: Timely and Cost-effective Software Safety Certificationmentioning
confidence: 99%
“…In literature, there were very few studies that leverage Intel SGX extensions to design real-time mixed-criticality systems. One study that is worth mentioning is provided with a positioning paper by De Simone et al [104], which explored the possibility of using the SGX to enforce the isolation among critical tasks running on top of unikernel-based hypervisor [105,106]. The most explored approach has been to use the security features of ARM TrustZone.…”
Section: Arm Trustzone-assisted Virtualizationmentioning
confidence: 99%