Chapter 13
Proposed Runtime System Versus
Existing Approaches
Abstract In this chapter, we briefly compare our approach of a fault-tolerant
operating system with existing approaches. We use our own definition of fault
tolerance as a process that is required to support the implementation of all steps of
GAFT.
13.1 What Is Available?
Integrity OS: Integrity OS [1] is a commercial product by Green Hills Software. It
is the only Operating System available on the market, which is certified as Criteria
Evaluation Assurance Level (EAL) 6+. However, as the name of the OS indicates,
the focus lies on the integrity of the OS and the applications running on the OS, i.e.,
the tamper proof of the applications running on that platform.
However, as high as its certification level is, there is no fault tolerance in case of
malfunctions or permanent errors built in except for restart in case of a failed
application.
L4 Se: L4 Se [2] is a member of the L4 microkernel family and is the only
Operating System known to be formally verified and tested and thus certified by
EAL 7. The focus of this operating system lies on the correctness of the Operating
System implementation and the used compiler.
Although its certification level allows it to be used in safety-critical applications,
it has no built in means to deal with external radiation induces faults except for
restarting processes in case of failures. The microkernel model supports fault
containment as all processes and even drivers run in their own address space. The
support of a complex MMU is, of course, a strict requirement for these systems.
L4ReAnimator: L4ReAnimator [3] is a framework on the basis of L4 Re that uses
the Fiasco.OC [4] microkernel implementation as the basis. Fiasco.OC supports
so-called capabilities, which indirectly reference objects and act as communication
channels. As no single component in the system knows all capabilities, only the
application that uses the capability can detect failures.
© Springer Nature Switzerland AG 2020
I. Schagaev et al., Software Design for Resilient Computer Systems,
https://doi.org/10.1007/978-3-030-21244-5_13
193
Proposed Runtime System Versus
Existing Approaches
Abstract In this chapter, we briefly compare our approach of a fault-tolerant
operating system with existing approaches. We use our own definition of fault
tolerance as a process that is required to support the implementation of all steps of
GAFT.
13.1 What Is Available?
Integrity OS: Integrity OS [1] is a commercial product by Green Hills Software. It
is the only Operating System available on the market, which is certified as Criteria
Evaluation Assurance Level (EAL) 6+. However, as the name of the OS indicates,
the focus lies on the integrity of the OS and the applications running on the OS, i.e.,
the tamper proof of the applications running on that platform.
However, as high as its certification level is, there is no fault tolerance in case of
malfunctions or permanent errors built in except for restart in case of a failed
application.
L4 Se: L4 Se [2] is a member of the L4 microkernel family and is the only
Operating System known to be formally verified and tested and thus certified by
EAL 7. The focus of this operating system lies on the correctness of the Operating
System implementation and the used compiler.
Although its certification level allows it to be used in safety-critical applications,
it has no built in means to deal with external radiation induces faults except for
restarting processes in case of failures. The microkernel model supports fault
containment as all processes and even drivers run in their own address space. The
support of a complex MMU is, of course, a strict requirement for these systems.
L4ReAnimator: L4ReAnimator [3] is a framework on the basis of L4 Re that uses
the Fiasco.OC [4] microkernel implementation as the basis. Fiasco.OC supports
so-called capabilities, which indirectly reference objects and act as communication
channels. As no single component in the system knows all capabilities, only the
application that uses the capability can detect failures.
© Springer Nature Switzerland AG 2020
I. Schagaev et al., Software Design for Resilient Computer Systems,
https://doi.org/10.1007/978-3-030-21244-5_13
193
