Summary


X-TeeOS:双体系架构与Rust全栈构建可信执行环境 / Dual-system architecture with full-stack Rust for trusted execution environment | https://gitee.com/openkylin/community/tree/master/sig/X-TeeOS | https://www.openkylin.top/sig/sig_detail.html?sig_id=145

工作目标:X-TeeOS(Trusted Execution Environment OS)特别兴趣小组(SIG),致力于围绕“双体系架构 + Rust 全栈”构建下一代安全可信子系统。在当前操作系统可信化与软硬件协同可信的发展趋势下,X-TEEOS 旨在探索并落地一套面向关键业务场景的**轻量级、高可靠、可验证、永不中断(Never-Die)**的可信执行环境。具体包括:

1、打造双体系安全框架: 在原有主系统之上构建独立可信环境,通过隔离、监控与降级机制,为关键服务提供稳定执行底座。

2、推进 Rust 全栈可信实现: 以 Rust 语言为核心构建内核、运行时、驱动、系统服务,充分利用其内存安全特性,降低缺陷密度与攻击面。

3、构建可验证的安全子系统: 包括任务调度、资源隔离、状态持续记录、关键事件追踪,为安全场景提供高可信保障。

4、支持多场景的可信运行与实时监测: 为嵌入式、终端设备等不同形态的系统提供统一的可信组件。


Working Objective: The X-TeeOS (Trusted Execution Environment OS) Special Interest Group (SIG) is dedicated to building a next-generation secure and trustworthy subsystem based on a "dual-system architecture + full-stack Rust" approach. In alignment with the current trend toward trusted operating systems and hardware-software collaborative trust, X-TeeOS aims to explore and implement a lightweight, highly reliable, verifiable, and never-die trusted execution environment for critical business scenarios. Specifically, it includes:

  1. Establishing a dual-system security framework: Building an independent trusted environment atop the original main system, providing a stable execution foundation for critical services through isolation, monitoring, and fallback mechanisms.

  2. Advancing full-stack Rust-based trusted implementation: Utilizing Rust as the core language to develop the kernel, runtime, drivers, and system services, leveraging its memory safety features to reduce defect density and attack surface.

  3. Developing a verifiable security subsystem: Incorporating task scheduling, resource isolation, persistent state logging, and critical event tracing to deliver high-trust guarantees for security-critical scenarios.

  4. Enabling trusted execution and real-time monitoring across multiple scenarios: Providing unified trusted components for systems in various forms, such as embedded and edge devices.

发帖 / Post: x-tee-os@lists.openkylin.top

主页 / Home: https://gitee.com/openkylin/community/tree/master/sig/X-TeeOS

官网 SIG / Website: https://www.openkylin.top/sig/sig_detail.html?sig_id=145

列表页 / List: https://mailweb.openkylin.top/postorius/lists/x-tee-os.lists.openkylin.top/

归档 / Archives: https://mailweb.openkylin.top/hyperkitty/list/x-tee-os@lists.openkylin.top/

To contact the list owners, use the following email address: x-tee-os-owner@lists.openkylin.top

Archives

Archives


Subscription / Unsubscription

To subscribe or unsubscribe from this list, please log in first. If you have not previously logged in, you may need to set up an account with the appropriate email address.

Log In


You can also subscribe without creating an account. If you wish to do so, please use the form below.