← Latest briefing

Technology

Proofcraft completes formal seL4 security proofs for AArch64

A newly established confidentiality proof finishes the formal mathematical verification suite for the seL4 microkernel on AArch64 architecture.

The short version

  • Proofcraft completed the final remaining security proof for the seL4 microkernel on AArch64, establishing kernel enforcement of confidentiality.
  • Supported by the NCSC, the formal mathematical proof verifies that seL4 isolates applications and prevents unauthorized data leaks.
  • The isolation ensures that security compromises in non-critical applications cannot propagate to critical ones.

Key facts

  • Proofcraft finalized the seL4 security proofs on the AArch64 architecture by completing the confidentiality proof.[Hacker News]
  • The confidentiality proof provides a mathematical guarantee that the kernel prevents unauthorized information retrieval between applications.[Hacker News]
  • The project received funding and support from the NCSC.[Hacker News]
  • With this milestone, seL4 on AArch64 has completed formal proofs for functional correctness, integrity, and confidentiality.[Hacker News]

What remains uncertain

  • The mathematical guarantees depend on a specific set of underlying platform and implementation assumptions documented by the project.[Hacker News]

Sources