seL4: Formal Verification of an OS Kernel

The work

TitleseL4: Formal Verification of an OS Kernel
AuthorsGerwin Klein; Kevin Elphinstone; Gernot Heiser; June Andronick; David Cock; Philip Derrin; Dhammika Elkaduwe; Kai Engelhardt; Rafal Kolanski; Michael Norrish; Thomas Sewell; Harvey Tuch; Simon Winwood
Typeconference paper
Year2009
Citekeyklein2009sel4

Where it appeared

Published inProceedings of the ACM SIGOPS 22nd symposium on Operating systems principles
PublisherAssociation for Computing Machinery
Pages207--220

Identifiers

DOI10.1145/1629575.1629596

Access

Landing pagehttps://doi.org/10.1145/1629575.1629596

Abstract

Complete formal verification is the only known way to guarantee that a system is free of programming errors. We present our experience in performing the formal, machine-checked verification of the seL4 microkernel from an abstract specification down to its C implementation. We assume correctness of compiler, assembly code, and hardware, and we used a unique design approach that fuses formal and operating systems techniques. To our knowledge, this is the first formal proof of functional correctness of a complete, general-purpose operating-system kernel. Functional correctness means here that the implementation always strictly follows our high-level abstract specification of kernel behaviour. This encompasses traditional design and implementation safety properties such as the kernel will never crash, and it will never perform an unsafe operation. It also proves much more: we can predict precisely how the kernel will behave in every possible situation. seL4, a third-generation microkernel of L4 provenance, comprises 8,700 lines of C code and 600 lines of assembler. Its performance is comparable to other high-performance L4 kernels.

Copy held

KindPDF, 735.6 kB
Retrieved2026-08-08
Heldlocal, for personal reference
Where it came fromhttps://trustworthy.systems/publications/nicta_full_text/1852.pdf

Where this came from

How it got herethe agent went looking · found via crossref
First seen2026-08-05
Recordreviewed by a person
Approved2026-08-16

Cite it as

@inproceedings{klein2009sel4,
  title = {seL4: Formal Verification of an OS Kernel},
  author = {Gerwin Klein and Kevin Elphinstone and Gernot Heiser and June Andronick and David Cock and Philip Derrin and Dhammika Elkaduwe and Kai Engelhardt and Rafal Kolanski and Michael Norrish and Thomas Sewell and Harvey Tuch and Simon Winwood},
  year = {2009},
  booktitle = {Proceedings of the ACM SIGOPS 22nd symposium on Operating systems principles},
  pages = {207--220},
  publisher = {Association for Computing Machinery},
  doi = {10.1145/1629575.1629596},
  url = {https://doi.org/10.1145/1629575.1629596},
}

This record lives at https://refs.drheap.org/klein2009sel4/ and will keep doing so.