Zum Inhalt

Composable Operating Systems

We build secure operating systems based on a microkernel architecture to reduce complexity and improve component isolation. Following the principle of composability in hardware and software, our system consists of small building blocks that cooperate securely within a networked environment. In the Trustworthy Digital Architectures research area, we work closely with the Scalable Computing Hardware group to address security challenges at the chip and network levels. The Composable Operating Systems group provides the essential components that can be used to create customized systems for connected devices.

From Simulator to Hardware

Together with the Scalable Computing Hardware group, we bring our operating system from a software-based simulator to real hardware. To achieve this, we implement the hardware components on an FPGA chip, allowing us to evaluate the hardware design and test its interaction with our operating system. In the end, our operating system and the corresponding applications run on a system-on-chip (SoC) - a compact chip that integrates all essential components of a computer, such as the processor, memory, and accelerators, into a single unit.

Balancing Cost and Security

Security comes at a cost. For instance, additional resources are required to run components on separate processor cores. Therefore, we investigate how resources can be used both exclusively and shared, using the same mechanisms. This allows system designers to choose between maximum isolation (and thus maximum security) or minimal resource utilization in each individual case.

Component Updates and Attestation

For the overall system to be trustworthy, only the components required for a specific scenario should communicate with each other. To ensure this, we are researching how to securely attest the identity and integrity of all building blocks with minimal hardware and software overhead. This involves reliably verifying the authenticity and integrity of components. Such attestation is also essential for securely applying software updates.

M³ Operating System

M³ is a modular and secure operating system developed at the Barkhausen Institut for networked devices like IoT systems. It is built on a tiled hardware architecture, where each component - hardware or software - resides on its own tile, isolated from others by default. Only the operating system can grant communication channels between selected tiles via a dedicated Trusted Communication Unit

This ‘security-by-design’ approach is further enhanced by M³’s capability-based security model, which uses capabilities to authorize access between components; providing fine-grained control and limiting potential damage in case of a system intrusion. 

The M³ security architecture ensures the containment of malicious software and untrusted hardware components—increasing the trustworthiness in our connected world. 

The M³ framework is available as an open-source code base on GitHub.

Science Communication through film

We sometimes take unconventional paths to make our research accessible to a wider audience. One of our presentations was so well received by the audience that we turned it into an explanatory film on the topic of 'Data security by modularization.’ In the film, little animated robots illustrate how the software in smartphones works and how we can protect it. The smartphone also serves as a symbol for the digital infrastructure in the networked world of tomorrow.

Who we are

Dr.-Ing.  Michael Roitzsch Research Group Leader

Dr.-Ing.  Carsten Weinhold Associate Group Leader

Dr.-Ing.  Nils Asmussen Principal Researcher

M.Sc. Inf.  Matthias Hille Associate Researcher

Ph.D.  Nicholas Gordon Associate Researcher

Dipl.-Inf.  Till Miemietz Associate Researcher

M.Sc.  Per Natzschka Associate Researcher

M. Sc.  Viktor Reusch Associate Researcher

Prof. Dr.  Hermann Härtig BI Research Fellow

Prof. Dr.  Matthias Wählisch BI Research Fellow

Publications

Zum Seitenanfang