Where in the world is Gernot?

Where Has He Been?

SydneyAug. 15
Kuala LumpurAug. 12
SydneyAug. 11
San FranciscoAug. 04
AustraliaJul. 07
DresdenJul. 04
BerlinJun. 30
SydneyJun. 27
San DiegoJun. 19
Palo AltoJun. 18

About the Blog

 
OK Bloggers include:

Engineers,
Developers,
Academics,
Executives,
and a variety of voices from the OK team.

We hope you enjoy this glimpse into our culture...

If you have any questions or comments please email us:

blog@ok-labs.com

Open Kernel Labs Blog

February 13, 2008

Trusted vs trustworthy computer systems

What does the distinction between "trusted" and "trustworthy" mean for computer systems?


People tend to talk of a trusted computer system when they refer to a system that is trusted to perform security- or safety-critical operations. Unsurprisingly, the military and defence communities have worried about this for a while, and the term is explicilty used in the famous Orange Book, officially referred to the "Trusted Computer System Evaluation Criteria". It has now been replaced by the Common Criteria for IT Security Evaluation, or Common Criteria for short.

The Orange Book and the CC define an evaluation process that aims to ensure that the systems they trust to do their safety- or security-critical operations are actually trustworthy. The idea is that systems are subjected to a more-or-less thorough security evaluation, and if they meet certain criteria, they can then be certified as trustworthy to certain assurance level.

This is all fine for expensive military systems where the odd dozen millions for security evaluation doesn't matter that much. (And it is expensive, the industry estimate is that CC evaluation at the highest level, EAL7, cost $10k per line of code!) But for embedded systems, particularly consumer goods sold for not more than a few 100$, such as the ubiquitous mobile phones, this aproach isn't feasible.

Well, actually it isn't even good enough for what it's designed. The expensive evaluation certainly will make you sleep better if you subscribe to the theory that anything expensive must be good, so something very expensive must be very good, right? If you're a bit more of a sceptic, you might be interested in looking at what CC actually gives you. It turns out that besides a nice stamp of approval, it gives you no security guarantee whatsoever. It's a glorified ISO-9000 process. Even at the highest level. If you don't believe me, have a look at the relevant wikipedia article. Or my recent white paper "Your System is Secure? Prove it!"

At OK Labs we are going in a direction which makes much more sense. One the one hand, we are making systems more trustworthy by minimising their trusted computing base (TCB). If the security-critical code base is small (and with OKL4 it can be as small as 20,000 lines) then it is inherently less faulty than something that's hundreds of thousands of lines of code, even if they have gone through an expensive process producing reams of printed paper. This is achieved by our OKL4 microkernel technology, the hottest thing on the planet (but I may be a bit biased wink). The OKL4 microkernel provides a minimal basis for secure systems. And it supports virtualization, so you can run a complete operating system (such as Linux) in a virtual machine, without having to trust it. And all that at negligible performance overhead.

So, small is beautiful as far as security is concerned. But it goes further. As explained in another white paper, OKL4 is small enough that it is possible to prove that it is secure. Using sound and solid (but slightly non-trivial) maths—the next hottest thing on the planet. And we don't just prove things about some abstract model of the system, we prove the actual C/assembler code. Nothing short of this gives you a guarantee that your system is trustworthy. And you shouldn't have to rely on less.

Posted by Gernot Heiser on February 13 at 12:30 AM

Gernot Heiser's avatar

About Gernot Heiser:

Gernot Heiser, Chief Technology Officer, never thought he would be in the business world. Prior to NICTA's creation in 2003, Dr Heiser was a full-time faculty member at the University of New South Wales. However, this die-hard academic couldn’t pass up the opportunity to see the commercialization of this research. Gernot still loves teaching, almost as much as he loves good wine and good food. And anyone will tell you that Gernot knows his wine.

Email Gernot Heiser

Ask GernotPermalink

Back To Top