Partitioning hypervisor solutions are becoming increasingly popular, to ensure stringent security and safety requirements related to isolation between co-hosted applications and to make more efficient use of available hardware resources. However, assessment and certification of isolation requirements remain a challenge and it is not trivial to understand what and how to test to validate these properties. Although the high-level requirements to be verified are mentioned in the different security- and safety-related standards, there is a lack of precise guidelines for the evaluator. This guidance should be comprehensive, generalizable to different products that implement partitioning, and tied specifically to lower-level requirements. The goal of this work is to provide a systematic framework that addresses this need.
翻译:分流高官解决方案越来越受欢迎,以确保与共同托管的应用程序之间隔离有关的严格的安保和安全要求,并更有效地利用现有硬件资源;然而,对隔离要求的评估与认证仍是一项挑战,了解什么和如何检验这些特性并非微不足道;虽然不同安保和安全相关标准都提到需要核实的高层次要求,但评价人员缺乏准确的准则;这一指导应全面,可普遍适用于实施分隔的不同产品,并特别与较低级别的要求挂钩;这项工作的目标是提供一个系统框架,满足这一需要。