Skip to main content


From a verified kernel towards verified systems


Gerwin Klein

NICTA, Sydney, Australia
UNSW, Australia


The L4.verified project has produced a formal, machine-checked Isabelle/HOL proof that the C code of the seL4 OS microkernel correctly implements its abstract implementation. This paper briefly summarises the proof, its main implications and assumptions, reports on the experience in conducting such a large-scale verification, and finally lays out a vision how this formally verified kernel may be used for gaining formal, code-level assurance about safety and security properties of systems on the order of a million lines of code.

BibTeX Entry

    publisher        = {Springer},
    series           = {Lecture Notes in Computer Science},
    author           = {Gerwin Klein},
    year             = {2010},
    month            = nov,
    volume           = {6461},
    editor           = {Kazunori Ueda},
    title            = {From a Verified Kernel towards Verified Systems},
    booktitle        = {Proceedings of the 8th Asian Symposium on Programming Languages and Systems (APLAS)},
    pages            = {21--33},
    address          = {Shanghai, China}


Served by Apache on Linux on seL4.
Served by Apache on Linux on seL4.