Partitioning Kernel With Capability Controlled Temporal and Spatial Partitioning
Henrik A. Karlsson, Roberto Guanciale
Abstract
Partitioning kernels often face challenges such as static resource allocation and insufficient temporal protection, limiting their applicability in dynamic and mixed-criticality systems where resource needs and security boundaries evolve over time. To address these limitations, we present S3K, a capability-based multicore partitioning kernel for embedded RISC-V systems. S3K provides robust spatial and temporal isolation, time protection, and dynamic resource reconfiguration, enabling flexible adaptation to changing operational requirements while maintaining strong safety and security guarantees. Its capability-based model ensures secure and efficient resource management, while in-kernel data partitioning prevents information leakage and mitigates side-channel attacks. Additionally, S3K's scheduler guarantees deterministic process dispatch, free from microarchitectural interference. Evaluation results demonstrate S3K's effectiveness, showing the absence of scheduling jitter, resistance to intra-core side-channels, and efficient interprocess communication. These results highlight S3K's suitability for safety-critical and security-critical applications in dynamic, resource-constrained environments.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Your agent calls
Lunesearch_papers
Free to start. No credit card required.
Terminal
Install the CLIlune papers get 85b76f6b-c20b-4993-8fe8-5538553a27f3Cited by top-tier papers1
Ask how each one uses itRelated papers
- EKC: A Portable and Extensible Kernel Compartment for De-Privileging Commodity OSJiaqin Yan, Qiujiang Chen, Shuai Zhou, Yuke Peng et al.USENIX Security 2025
- EC: Embedded Systems Compartmentalization via Intra-Kernel IsolationArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- HybCache: Hybrid Side-Channel-Resilient Caches for Trusted Execution EnvironmentsGhada Dessouky, Tommaso Frassetto, Ahmad-Reza SadeghiUSENIX Security 2020
- CHERIoT: Complete Memory Safety for Embedded DevicesSaar Amar, David Chisnall, Tony Chen, Nathaniel Wesley Filardo et al.MICRO 2023 · 22 citations
- ChaosINTC: A Secure Interrupt Management Mechanism against Interrupt-based Attacks on TEEYifan Zhu, Peinan Li, Lutan Zhao, Dan Meng et al.DAC 2023 · 2 citations
