Join GitHub today
GitHub is home to over 28 million developers working together to host and review code, manage projects, and build software together.
Sign upUse verified L4 kernel instead of Xen #3894
Comments
andrewdavidwong
added
enhancement
C: core
labels
May 12, 2018
andrewdavidwong
added this to the Far in the future milestone
May 12, 2018
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
GWeck commentedMay 12, 2018
•
edited
Edited 1 time
-
GWeck
edited May 12, 2018 (most recent)
Qubes OS version:
Far in the Future
Affected component(s):
mainly dom0
Steps to reproduce the behavior:
Expected behavior:
Actual behavior:
General notes:
The security of Qubes critically depends on strong isolation provided by Xen. Bugs in Xen endanger the security of Qubes significantly. Possibly the security kernel of L4 (os.inf.tu-dresden.de/L4/) might be used instead of Xen, if vchan and qrexec could be implemented in L4 without too much effort. As L4 is used in very security critical projects, e.g. a filter gateway connecting NATO secret systems to the outside world (https://www.infodas.de/wp-content/uploads/2016/11/SDoT_6.0i_eng_170530.pdf), it is to be expected that using L4 would significantly reduce the risks posed in Xen by bugs.
I think it would be worth while to contact the Technical University of Dresden on this issue. As far as I know, they are currently looking at Qubes and should be interested in a cooperation with the Qubes team. If interested, please contact Prof. Härtig (haertig@os.inf.tu-dresden.de).
Related issues: