TickTock: Verified Isolation in a Production Embedded OS
Vivien Rindisbacher, Evan Johnson, Nico Lehmann, Tyler Potyondy, Pat Pannuto, Stefan Savage, Deian Stefan, Ranjit Jhala
Abstract
We present a case study formally verifying process isolation in the Tock production microcontroller OS kernel. Tock combines hardware memory protection units and language-level techniques—by writing the kernel in Rust—to enforce isolation between user and kernel code. Our effort to verify Tock's process abstraction unearthed multiple, subtle bugs that broke isolation—many allowing malicious applications to compromise the whole OS. We describe this effort and TickTock, our fork of the Tock operating system kernel that eliminates isolation bugs by construction. TickTock uses Flux, an SMT-based Rust verifier, to formally specify and verify process isolation for all ARMv7-M platforms Tock supports and for three RISC-V 32-bit platforms. Our verification-guided design and implementation led to a new, granular process abstraction that is simpler than Tock's, has formal security guarantees (that are verified in half a minute), and outperforms Tock on certain critical code paths.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c1d8b01a-cbe0-4fad-8380-be7bbd8c01d5Cited by top-tier papers1
Ask how each one uses itBuilds on15
- Vale: Verifying High-Performance Cryptographic Assembly CodeBarry Bond, Chris Hawblitzel, Manos Kapritsos, K. Rustan M. Leino et al.USENIX Security 2017 · 147 citations
- Securing Real-Time Microcontroller Systems through Customized Memory View SwitchingChung Hwan Kim, Taegyu Kim, Hongjun Choi, Zhongshu Gu et al.NDSS 2018 · 127 citations
- Protecting Bare-Metal Embedded Systems with Privilege OverlaysAbraham A. Clements, Naif Saleh Almakhdhub, Khaled Saab, Prashast Srivastava et al.S&P 2017 · 122 citations
- ACES: Automatic Compartments for Embedded SystemsAbraham A. Clements, Naif Saleh Almakhdhub, Saurabh Bagchi, Mathias PayerUSENIX Security 2018 · 89 citations
- Verus: Verifying Rust Programs using Linear Ghost TypesAndrea Lattuada, Travis Hance, Chanhee Cho, Matthias Brun et al.OOPSLA 2023 · 86 citations
Related papers
- Atmosphere: Practical Verified Kernels with Rust and VerusXiangdong Chen, Zhaofeng Li, Jerry Zhang, Vikram Narayanan et al.SOSP 2025 · 1 citation
- Flux: Liquid Types for RustNico Lehmann, Adam T. Geller, Niki Vazou, Ranjit JhalaPLDI 2023 · 29 citations
- EC: Embedded Systems Compartmentalization via Intra-Kernel IsolationArslan Khan, Dongyan Xu, Dave Jing TianS&P 2023
- RedLeaf: Isolation and Communication in a Safe Operating SystemVikram Narayanan, Tianjiao Huang, David Detweiler, Dan Appel et al.OSDI 2020 · 86 citations
- End-to-End Mechanized Proof of an eBPF Virtual Machine for Micro-controllersShenghao Yuan, Frédéric Besson, Jean-Pierre Talpin, Samuel Hym et al.CAV 2022 · 13 citations
