{"id":"https://openalex.org/W2136310957","doi":"https://doi.org/10.1145/1629575.1629596","title":"seL4","display_name":"seL4","publication_year":2009,"publication_date":"2009-10-11","ids":{"openalex":"https://openalex.org/W2136310957","doi":"https://doi.org/10.1145/1629575.1629596","mag":"2136310957"},"language":"en","primary_location":{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1629575.1629596","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false},"type":"article","type_crossref":"proceedings-article","indexed_in":["crossref"],"open_access":{"is_oa":false,"oa_status":"closed","oa_url":null,"any_repository_has_fulltext":false},"authorships":[{"author_position":"first","author":{"id":"https://openalex.org/A5056561099","display_name":"Gerwin Klein","orcid":"https://orcid.org/0000-0001-8883-0559"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Gerwin Klein","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5073718932","display_name":"Kevin Elphinstone","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Kevin Elphinstone","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5025750562","display_name":"Gernot Heiser","orcid":"https://orcid.org/0000-0002-7069-0831"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Gernot Heiser","raw_affiliation_strings":["NICTA, UNSW & Open Kernel Labs, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA, UNSW & Open Kernel Labs, Sydney, Australia","institution_ids":["https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5069964343","display_name":"June Andronick","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"June Andronick","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5070060979","display_name":"David Cock","orcid":"https://orcid.org/0000-0003-2997-6560"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"David Cock","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5020803298","display_name":"Philip Derrin","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Philip Derrin","raw_affiliation_strings":["NICTA, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA, Sydney, Australia","institution_ids":["https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5081797820","display_name":"Dhammika Elkaduwe","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Dhammika Elkaduwe","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5112018592","display_name":"Kai Engelhardt","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Kai Engelhardt","raw_affiliation_strings":["UNSW & NICTA, Sydney, Australia#TAB#"],"affiliations":[{"raw_affiliation_string":"UNSW & NICTA, Sydney, Australia#TAB#","institution_ids":["https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5034161278","display_name":"Rafal Kolanski","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Rafal Kolanski","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5056365707","display_name":"Michael Norrish","orcid":"https://orcid.org/0000-0003-1163-8467"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Michael Norrish","raw_affiliation_strings":["NICTA & ANU, Canberra, Australia#TAB#"],"affiliations":[{"raw_affiliation_string":"NICTA & ANU, Canberra, Australia#TAB#","institution_ids":["https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5036639723","display_name":"Thomas Sewell","orcid":"https://orcid.org/0000-0002-4891-0797"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Thomas Sewell","raw_affiliation_strings":["NICTA, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA, Sydney, Australia","institution_ids":["https://openalex.org/I42894916"]}]},{"author_position":"middle","author":{"id":"https://openalex.org/A5008383684","display_name":"Harvey Tuch","orcid":null},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Harvey Tuch","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]},{"author_position":"last","author":{"id":"https://openalex.org/A5012139430","display_name":"Simon Winwood","orcid":"https://orcid.org/0009-0005-6133-0147"},"institutions":[{"id":"https://openalex.org/I42894916","display_name":"Data61","ror":"https://ror.org/03q397159","country_code":"AU","type":"other","lineage":["https://openalex.org/I1292875679","https://openalex.org/I2801453606","https://openalex.org/I42894916","https://openalex.org/I4387156119"]},{"id":"https://openalex.org/I31746571","display_name":"UNSW Sydney","ror":"https://ror.org/03r8z3t63","country_code":"AU","type":"education","lineage":["https://openalex.org/I31746571"]}],"countries":["AU"],"is_corresponding":false,"raw_author_name":"Simon Winwood","raw_affiliation_strings":["NICTA & UNSW, Sydney, Australia"],"affiliations":[{"raw_affiliation_string":"NICTA & UNSW, Sydney, Australia","institution_ids":["https://openalex.org/I42894916","https://openalex.org/I31746571"]}]}],"institution_assertions":[],"countries_distinct_count":1,"institutions_distinct_count":2,"corresponding_author_ids":[],"corresponding_institution_ids":[],"apc_list":null,"apc_paid":null,"fwci":68.17,"has_fulltext":false,"cited_by_count":1470,"citation_normalized_percentile":{"value":0.999884,"is_in_top_1_percent":true,"is_in_top_10_percent":true},"cited_by_percentile_year":{"min":99,"max":100},"biblio":{"volume":null,"issue":null,"first_page":null,"last_page":null},"is_retracted":false,"is_paratext":false,"primary_topic":{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},"topics":[{"id":"https://openalex.org/T11424","display_name":"Security and Verification in Computing","score":0.9999,"subfield":{"id":"https://openalex.org/subfields/1702","display_name":"Artificial Intelligence"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10054","display_name":"Parallel Computing and Optimization Techniques","score":0.9977,"subfield":{"id":"https://openalex.org/subfields/1708","display_name":"Hardware and Architecture"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}},{"id":"https://openalex.org/T10772","display_name":"Distributed systems and fault tolerance","score":0.9964,"subfield":{"id":"https://openalex.org/subfields/1705","display_name":"Computer Networks and Communications"},"field":{"id":"https://openalex.org/fields/17","display_name":"Computer Science"},"domain":{"id":"https://openalex.org/domains/3","display_name":"Physical Sciences"}}],"keywords":[],"concepts":[{"id":"https://openalex.org/C41008148","wikidata":"https://www.wikidata.org/wiki/Q21198","display_name":"Computer science","level":0,"score":0.4923371}],"mesh":[],"locations_count":1,"locations":[{"is_oa":false,"landing_page_url":"https://doi.org/10.1145/1629575.1629596","pdf_url":null,"source":null,"license":null,"license_id":null,"version":null,"is_accepted":false,"is_published":false}],"best_oa_location":null,"sustainable_development_goals":[],"grants":[],"datasets":[],"versions":[],"referenced_works_count":63,"referenced_works":["https://openalex.org/W1476411550","https://openalex.org/W1494673397","https://openalex.org/W1523275077","https://openalex.org/W1525928249","https://openalex.org/W1533238174","https://openalex.org/W1568755417","https://openalex.org/W1596552075","https://openalex.org/W1607932714","https://openalex.org/W1888392380","https://openalex.org/W1937179622","https://openalex.org/W1957415375","https://openalex.org/W1980491540","https://openalex.org/W19830081","https://openalex.org/W2014942166","https://openalex.org/W201784039","https://openalex.org/W2019404692","https://openalex.org/W2021994557","https://openalex.org/W2027168655","https://openalex.org/W2029030698","https://openalex.org/W2029224396","https://openalex.org/W2039804807","https://openalex.org/W2048500751","https://openalex.org/W2053262709","https://openalex.org/W2071542068","https://openalex.org/W2083469471","https://openalex.org/W2087832144","https://openalex.org/W2089661946","https://openalex.org/W2093852121","https://openalex.org/W2095954493","https://openalex.org/W2098592421","https://openalex.org/W2104634303","https://openalex.org/W2106115112","https://openalex.org/W2106192381","https://openalex.org/W2106211802","https://openalex.org/W2106412703","https://openalex.org/W2115696550","https://openalex.org/W2116860113","https://openalex.org/W2117181435","https://openalex.org/W2118341398","https://openalex.org/W2129695855","https://openalex.org/W2130970533","https://openalex.org/W2137186143","https://openalex.org/W2138662592","https://openalex.org/W2140508184","https://openalex.org/W2142286787","https://openalex.org/W2146530476","https://openalex.org/W2147448476","https://openalex.org/W2150210903","https://openalex.org/W2160022481","https://openalex.org/W2162553649","https://openalex.org/W2163117779","https://openalex.org/W2166004296","https://openalex.org/W2167800525","https://openalex.org/W2167911131","https://openalex.org/W2171069290","https://openalex.org/W2491926874","https://openalex.org/W2987803397","https://openalex.org/W30213274","https://openalex.org/W3160870209","https://openalex.org/W4206796831","https://openalex.org/W4232666937","https://openalex.org/W4246472322","https://openalex.org/W4247564898"],"related_works":["https://openalex.org/W2899084033","https://openalex.org/W2748952813","https://openalex.org/W2530322880","https://openalex.org/W2390279801","https://openalex.org/W2382290278","https://openalex.org/W2376932109","https://openalex.org/W2358668433","https://openalex.org/W2350741829","https://openalex.org/W2130043461","https://openalex.org/W1596801655"],"abstract_inverted_index":{"Complete":[0],"formal":[1,58,70],"verification":[2,26],"is":[3,13,67,158],"the":[4,23,28,68,86,108,131],"only":[5],"known":[6],"way":[7],"to":[8,36,160],"guarantee":[9],"that":[10,56,85],"a":[11,52,76,139],"system":[12],"free":[14],"of":[15,27,43,72,75,95,142,148,154],"programming":[16],"errors.We":[17],"present":[18],"our":[19,64,91],"experience":[20],"in":[21,135],"performing":[22],"formal,":[24],"machine-checked":[25],"seL4":[29],"microkernel":[30,141],"from":[31],"an":[32,118],"abstract":[33,93],"specification":[34,94],"down":[35],"its":[37],"C":[38,149],"implementation.":[39],"We":[40],"assume":[41],"correctness":[42,74,82],"compiler,":[44],"assembly":[45],"code,":[46],"and":[47,49,59,102,113,151],"hardware,":[48],"we":[50,126],"used":[51],"unique":[53],"design":[54,101],"approach":[55],"fuses":[57],"operating":[60],"systems":[61],"techniques.":[62],"To":[63],"knowledge,":[65],"this":[66],"first":[69],"proof":[71],"functional":[73],"complete,":[77],"general-purpose":[78],"operating-system":[79],"kernel.":[80],"Functional":[81],"means":[83],"here":[84],"implementation":[87,103],"always":[88],"strictly":[89],"follows":[90],"high-level":[92],"kernel":[96,109,132],"behaviour.":[97],"This":[98],"encompasses":[99],"traditional":[100],"safety":[104],"properties":[105],"such":[106],"as":[107],"will":[110,115,133],"never":[111,116],"crash,":[112],"it":[114],"perform":[117],"unsafe":[119],"operation.":[120],"It":[121],"also":[122],"proves":[123],"much":[124],"more:":[125],"can":[127],"predict":[128],"precisely":[129],"how":[130],"behave":[134],"every":[136],"possible":[137],"situation.seL4,":[138],"third-generation":[140],"L4":[143,163],"provenance,":[144],"comprises":[145],"8,700":[146],"lines":[147,153],"code":[150],"600":[152],"assembler.":[155],"Its":[156],"performance":[157],"comparable":[159],"other":[161],"high-performance":[162],"kernels.":[164]},"cited_by_api_url":"https://api.openalex.org/works?filter=cites:W2136310957","counts_by_year":[{"year":2024,"cited_by_count":64},{"year":2023,"cited_by_count":78},{"year":2022,"cited_by_count":63},{"year":2021,"cited_by_count":103},{"year":2020,"cited_by_count":90},{"year":2019,"cited_by_count":98},{"year":2018,"cited_by_count":81},{"year":2017,"cited_by_count":108},{"year":2016,"cited_by_count":104},{"year":2015,"cited_by_count":114},{"year":2014,"cited_by_count":127},{"year":2013,"cited_by_count":121},{"year":2012,"cited_by_count":118}],"updated_date":"2025-01-04T16:00:59.270844","created_date":"2016-06-24"}