ISCAS OpenIR  > 2010软件所会议论文
model checking a secure hypervisor
Sunlv Wang; Jian Liu; Qiuping Yi; Xian Zhang
2010
Pages119-122
Conference PlaceWuhan
Indexed Typeieee
ISBN978-1-4244-9287-9
DepartmentInst. of Software, Chinese Acad. of Sci., Beijing, China
English AbstractHypervisor is a piece of platform-virtualization software that allows multiple operating systems to run on a host computer concurrently. CAS Monitor, short for CAS Virtual Monitor, is a secure, high-assurance hypervisor prototype, which aims to level B3 or higher of TCSEC standard. This paper reports our experience of employing model checking method to verify some design properties of CAS Monitor, such as isolation, mediated sharing, communication between separated virtual machines and source control policy. We show how to specify design architecture of CAS Monitor with Spin PROMELA language and verify the above important properties to meet system security request.
KeywordCas Monitor Spin Promela Language Model Checking Platform-virtualization Software Secure Hypervisor Formal Verification Operating Systems (Computers) Security Of Data Virtual Machines
Content Type会议论文
URIhttp://ir.iscas.ac.cn/handle/311060/8828
Collection2010软件所会议论文
Recommended Citation
GB/T 7714
Sunlv Wang,Jian Liu,Qiuping Yi,et al. model checking a secure hypervisor[C],2010:119-122.
Files in This Item:
File Name/Size DocType Version Access License
05718359.pdf(333KB) 限制开放--Application Full Text
Related Services
Recommend this item
Bookmark
Usage statistics
Export to Endnote
Google Scholar
Similar articles in Google Scholar
[Sunlv Wang]'s Articles
[Jian Liu]'s Articles
[Qiuping Yi]'s Articles
Baidu academic
Similar articles in Baidu academic
[Sunlv Wang]'s Articles
[Jian Liu]'s Articles
[Qiuping Yi]'s Articles
Bing Scholar
Similar articles in Bing Scholar
[Sunlv Wang]'s Articles
[Jian Liu]'s Articles
[Qiuping Yi]'s Articles
Terms of Use
No data!
Social Bookmark/Share
All comments (0)
No comment.
 

Items in the repository are protected by copyright, with all rights reserved, unless otherwise indicated.