Electronic Thesis/Dissertation
 

Efficient and Predictable Protection Domains on Resource-Constrained Embedded Systems

Open Access

The goal to facilitate multi-tenancy and increase functionality integration on resource-constrained embedded systems calls for protection domains. However, providing protection domains that offer all of efficiency, security, predictability and flexibility is challenging. Unlike traditional embedded systems, current ones must efficiently perform a collection of potentially untrusted tasks that may require different predictability guarantees. A lack of spatial and temporal isolation negatively impacts the reliability and security of the system by allowing faults and compromises to propagate between software components. With the advent of the Internet-of-Things (IoT), embedded systems are increasingly connected to the network, exposing attack surfaces that traditional off-line systems do not face. Traditional programming styles that ignore isolation fail to address these concerns, and an efficient, secure, flexible yet predictable protection domain mechanism is required. However, only limited hardware facilities for memory isolation are available on these resource-constrained embedded systems. These facilities often lack flexibility in that they pose restrictions on the base, size and number of the memory regions to protect, and do not offer memory address virtualization. These shortcomings render setting up protection domains on them challenging. In this thesis, we propose mechanisms to implement efficient, secure, predictable and flexible system-level protection domain isolation mechanisms on resource-constrained em- bedded systems. Firstly, we introduce an unified and principled system abstraction and design for programming efficient, predictable and secure protection domains on these sys- tems. Then, we propose an interrupt acceleration infrastructure leveraging security monitors, further reducing interrupt latency of these protection domains. Finally, we extend such system abstraction by adding temporal specifications to memory access control, boosting flexibility and portability of these protection domains.

Author Language Keyword Date created Type of Work License
  • All rights reserved
Rights statement GW Unit Degree Advisor Committee Member(s) Persistent URL

Notice to Authors

If you are the author of this work and you have any questions about the information on this page, please use the Contact form to get in touch with us.

Thumbnail Title Date Uploaded Visibility Actions
Preview of Pan_gwu_0075A_15587.pdf Pan_gwu_0075A_15587.pdf 2021-05-10 Open Access