MULTI-LEVEL, HARDWARE-ENFORCED DOMAIN SEPARATION USING A SEPARATION KERNEL ON A MULTICORE PROCESSOR WITH A SHARED CACHE
摘要:
A separation kernel isolating memory domains within a shared system memory (103, 301, 401) is executed on the cores (202) of a multicore processor (101, 201a-201h) having hardware security enforcement for static virtual address mappings, to implement an efficient embedded multi-level security system (100). Shared caches (208, 209) are disabled to isolate domains accessible to select cores and reduce security risks from data co-mingling.
信息查询
0/0