Kernel isolation of a Capability-based security Operating System

More Info
expand_more

Abstract

Providing more confidentiality by extending a capability-based OS trough a hardware enforced isolation between the memory of the kernel and other memory. By employing memory tagging and hardware based Inter Process Communication (IPC) this defense gives an overhead of 26 percent.