VLDB 2026 Research / reviewers in the wild / expert
Hermann Härtig
dblp:h/HHartig · also Hermann Haertig
· DBLP profile ↗
58ranked-venue papers
7as first author
13since 2021 · last 2025
0000-0002-8357-2594ORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Systems, architecture and hardware · 25 · 3 first-author · 7 since 2021Software engineering, systems software and programming languages · 14 · 1 first-author · 6 since 2021Applied, interdisciplinary, general and emerging computing · 12 · 2 since 2021Databases, data management, data science and information retrieval · 3 · 1 since 2021Security and privacy · 2 · 1 first-authorArtificial intelligence and machine learning · 1 · 1 since 2021Human-computer interaction and ubiquitous computing · 1 · 1 first-authorTheory of computation · 1
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Enabling Efficient Mobile Tracing with BTraceabstractWith the growing complexity of smartphone systems, effective tracing becomes vital for enhancing their stability and optimizing the user experience. Unfortunately, existing tracing tools are inefficient in smartphone scenarios. Their distributed designs (with either per-core or per-thread buffers) prioritize performance but lead to missing crucial clues with high probability. While these problems can be overlooked in previous scenarios (e.g., servers), they drastically limit the usefulness of tracing on smartphones. Arnau Casadevall-Saiz, Diogo Behrens, Ming Fu, Ning Jia 0004, Hermann Härtig, Haibo Chen 0001 |
ASPLOS (2) | 8 |
| 2025 | CoRD: Converged RDMA DataplaneabstractHPC networking is often characterized by kernel bypass, which is considered mandatory for large parallel and distributed applications. However, kernel bypass comes at a price because it breaks the traditional OS architecture, requiring applications to use special APIs and limiting the OS's control over existing network connections. We make the case that kernel bypass is not mandatory. Rather, high-performance networking relies on multiple performance-improving techniques, with kernel bypass even being detrimental to performance under specific conditions. CoRD removes kernel bypass from RDMA networks, primarily to enable efficient OS-level control over the RDMA dataplane. This control can be used to enhance security or resource allocation policies, and, as we demonstrate in one of the use cases, can improve end-to-end application performance by up to 10%. This architecture can enable Cloud-based distributed RDMA applications and facilitate deployment of coupled HPC applications. Maksym Planeta, Jan Bierbaum, Michael Roitzsch, Hermann Härtig |
IPDPS | 4 |
| 2025 | HARP: Energy-Aware and Adaptive Management of Heterogeneous ProcessorsabstractEnergy efficiency has become a key concern in modern computing. Major processor vendors now offer single-ISA heterogeneous processors that combine powerful and energy-efficient cores, such as Arm's big.LITTLE CPUs, Apple's M-series chips, and Intel P/E systems. However, today's OS schedulers, relying on simple cost-based thread allocation strategies, fail to fully exploit their potential. Till Smejkal, Robert Khasanov, Jerónimo Castrillón, Hermann Härtig |
Middleware | 4 |
| 2025 | MettEagle: Costs and Benefits of Implementing Containers on Microkernels
Till Miemietz, Viktor Reusch, Matthias Hille, Lars Wrenger, Jana Eisoldt, Jan Klötzke, Max Kurze, Adam Lackorzynski, Michael Roitzsch, Hermann Härtig |
OSDI | 10 |
| 2024 | Brief Announcement: Work Stealing through Partial Asynchronous DelegationabstractWork stealing is a well-established technique in multi-core systems that aims to improve load balancing and task scheduling efficiency. Each processing unit maintains its own task queue, and when idle, it steals tasks from other units. Traditional work-stealing approaches face performance bottlenecks due to costly synchronization primitives and contention arising from concurrent access by both the queue owner and thieves. The state-of-the-art solution addresses these issues through coarse-grained synchronization; however, it restricts stealing in specific scenarios, thereby limiting parallelism. Ming Fu, Hermann Härtig, Haibo Chen 0001 |
SPAA | 4 |
| 2023 | AtoMig: Automatically Migrating Millions Lines of Code from TSO to WMMabstractCPUs with weak memory-consistency models (WMMs), such as Arm and RISC-V, are rapidly increasing their market share. Porting legacy x86 applications to such CPUs requires introducing extra synchronization to prevent WMM-related concurrency bugs---a task often left to human experts. Martin Beck, Koustubha Bhat, Lazar Stricevic, Diogo Behrens, Ming Fu, Viktor Vafeiadis, Haibo Chen 0001, Hermann Härtig |
ASPLOS (2) | 9 |
| 2023 | Sleep Well: Pragmatic Analysis of the Idle States of Intel ProcessorsabstractRising energy consumption is of growing concern for cloud data center providers. Modern processors try to counteract this problem through low-power idle states that save energy in phases with little demand for compute resources. Making proper use of this feature, however, requires knowledge about the properties of these states for the very processors used in a specific setup; most importantly, the energy consumed in each idle state and the latency for resuming normal operation. Unfortunately, hardware vendors usually do not provide this critical information. Till Smejkal, Jan Bierbaum, Thomas Oberhauser, Horst Schirmeier, Hermann Härtig |
BDCAT | 5 |
| 2023 | BWoS: Formally Verified Block-based Work Stealing for Parallel Processing
Bohdan Trach, Ming Fu, Diogo Behrens, Jonathan Schwender, Jitang Lei, Viktor Vafeiadis, Hermann Härtig, Haibo Chen 0001 |
OSDI | 9 |
| 2022 | Slashing the disaggregation tax in heterogeneous data centers with FractOSabstractDisaggregated heterogeneous data centers promise higher efficiency, lower total costs of ownership, and more flexibility for data-center operators. However, current software stacks can levy a high tax on application performance. Applications and OSes are designed for systems where local PCIe-connected devices are centrally managed by CPUs, but this centralization introduces unnecessary messages through the shared data-center network in a disaggregated system. Lluís Vilanova, Lina Maudlej, Shai Bergman, Till Miemietz, Matthias Hille, Nils Asmussen, Michael Roitzsch, Hermann Härtig, Mark Silberstein |
EuroSys | 8 |
| 2022 | BBQ: A Block-based Bounded Queue for Exchanging Data and Profiling
Diogo Behrens, Ming Fu, Lilith Oberhauser, Jonas Oberhauser, Jitang Lei, Hermann Härtig, Haibo Chen 0001 |
USENIX ATC | 8 |
| 2021 | CLoF: A Compositional Lock Framework for Multi-level NUMA SystemsabstractEfficient locking mechanisms are extremely important to support large-scale concurrency and exploit the performance promises of many-core servers. Implementing an efficient, generic, and correct lock is very challenging due to the differences between various NUMA architectures. The performance impact of architectural/NUMA hierarchy differences between x86 and Armv8 are not yet fully explored, leading to unexpected performance when simply porting NUMA-aware locks from x86 to Armv8. Moreover, due to the Armv8 Weak Memory Model (WMM), correctly implementing complicated NUMA-aware locks is very difficult. Rafael Lourenco de Lima Chehab, Antonio Paolillo, Diogo Behrens, Ming Fu, Hermann Härtig, Haibo Chen 0001 |
SOSP | 5 |
| 2021 | MigrOS: Transparent Live-Migration Support for Containerised RDMA Applications
Maksym Planeta, Jan Bierbaum, Leo Sahaya Daphne Antony, Torsten Hoefler, Hermann Härtig |
USENIX ATC | 5 |
| 2021 | Enabling and Optimizing MACsec for Industrial EnvironmentsabstractIndustry 4.0 will revolutionize industrial automation. Yet, future smart factories will not be created from scratch. They will rather evolve from existing legacy installations. Consequently, also industrial networks will evolve and the result will be a mixture of new and legacy components. This will make new security mechanisms necessary, that are specifically designed for this industrial use case. This work proposes modifications for MACsec [1], a new security protocol for protecting communication traffic. These modifications enable MACsec to work within future industrial settings, circumventing drawbacks introduced by legacy networking technologies. Furthermore, we managed to significantly increase the performance of MACsec. Tim Lackorzynski, Gregor Garten, Jan Sönke Huster, Stefan Köpsell, Hermann Härtig |
IEEE Trans. Ind. Informatics | 5 |
| 2020 | Enabling and Optimizing MACsec for Industrial Environments (Extended Abstract)abstractThe specifics of industrial networks make security mechanisms necessary, that are specifically designed for them. This work proposes two modifications for MACsec, a new security protocol for protecting layer 2 traffic: a new fragmentation mechanism enabling MACsec to work within future industrial networks, and the use of ciphers currently not standardised for MACsec, leading to a significant increase in the performance of MACsec. Tim Lackorzynski, Gregor Garten, Jan Sönke Huster, Stefan Köpsell, Hermann Härtig |
WFCS | 5 |
| 2019 | Corrected trees for reliable group communicationabstractDriven by ever increasing performance demands of compute-intensive applications, supercomputing systems comprise more and more nodes. This growth is a significant burden for fast group communication primitives and also makes those systems more susceptible to failures of individual nodes. In this paper we present a two-phase fault-tolerant scheme for group communication. Using broadcast as an example, we provide a full-spectrum discussion of our approach --- from a formal analysis to LogP-based simulations to a message-passing-based implementation running on a large cluster. Ultimately, we are able to reduce the complex problem of reliable and fault-tolerant collective group communication to a graph theoretical renumbering problem. Both, simulations and measurements, show our solution to achieve a latency reduction of 50% with up to six times fewer messages sent in comparison to existing schemes. Martin Küttler, Maksym Planeta, Jan Bierbaum, Carsten Weinhold, Hermann Härtig, Amnon Barak, Torsten Hoefler |
PPoPP | 5 |
| 2019 | K2: Work-Constraining Scheduling of NVMe-Attached StorageabstractFor data-driven cyber-physical systems, timely access to storage is an important building block of real-time guarantees. At the same time, storage technology undergoes continued technological advancements. The introduction of NVMe fundamentally changes the interface to the drive by exposing request parallelism available at the flash package level to the storage stack, allowing to extract higher throughput and lower latencies from the drive. The resulting architectural changes within the operating system render many historical designs and results obsolete, requiring a fresh look at the I/O scheduling landscape. In this paper, we conduct a comprehensive survey of the existing NVMe-compatible I/O schedulers in Linux regarding their suitability for real-time applications. We find all schedulers severely lacking in terms of performance isolation and tail latencies. Therefore, we propose K2, a new I/O scheduler specifically designed to reduce latency at the 99.9th percentile, while maintaining the throughput gains promised by NVMe. By limiting the length of NVMe device queues, K2 reduces read latencies up to 10× and write latencies up to 6.8×, while penalizing throughput for non-real-time background load by at most 2.7×. Till Miemietz, Hannes Weisbach, Michael Roitzsch, Hermann Härtig |
RTSS | 4 |
| 2019 | M³x: Autonomous Accelerators via Context-Enabled Fast-Path Communication
Nils Asmussen, Michael Roitzsch, Hermann Härtig |
USENIX ATC | 3 |
| 2019 | SemperOS: A Distributed Capability System
Matthias Hille, Nils Asmussen, Pramod Bhatotia, Hermann Härtig |
USENIX ATC | 4 |
| 2019 | Architecture and Advanced Electronics Pathways Toward Highly Adaptive Energy- Efficient ComputingabstractWith the explosion of the number of compute nodes, the bottleneck of future computing systems lies in the network architecture connecting the nodes. Addressing the bottleneck requires replacing current backplane-based network topologies. We propose to revolutionize computing electronics by realizing embedded optical waveguides for onboard networking and wireless chip-to-chip links at 200-GHz carrier frequency connecting neighboring boards in a rack. The control of novel rate-adaptive optical and mm-wave transceivers needs tight interlinking with the system software for runtime resource management. Gerhard P. Fettweis, Meik Dörpinghaus, Jerónimo Castrillón, Akash Kumar 0001, Christel Baier, Karlheinz Bock, Frank Ellinger, Andreas Fery, Frank H. P. Fitzek, Hermann Härtig, Kambiz Jamshidi, Thomas Kissinger, Wolfgang Lehner, Michael Mertig, Wolfgang E. Nagel, Giang T. Nguyen 0002, Dirk Plettemeier, Michael Schröter, Thorsten Strufe |
Proc. IEEE | 10 |
| 2019 | Configuration of inter-process communication with probabilistic model checking
Linda Herrmann, Martin Küttler, Tobias Stumpf, Christel Baier, Hermann Härtig, Sascha Klüppelholz |
Int. J. Softw. Tools Technol. Transf. | 5 |
| 2018 | Energy-Utility Function-Based Resource Control for In-Memory Database Systems LIVEabstractThe ever-increasing demand for scalable database systems is limited by their energy consumption, which is one of the major challenges in research today. While existing approaches mainly focused on transaction-oriented disk-based database systems, we are investigating and optimizing the energy consumption and performance of data-oriented scale-up in-memory database systems that make heavy use of the main power consumers, which are processors and main memory. In this demo, we present energy-utility functions as an approach for enabling the operating system to improve the energy efficiency of scalable in-memory database systems. Our highly interactive demo setup mainly allows attendees to switch between multiple DBMS workloads and watch in detail how the system responds by adapting the hardware configuration appropriately. Thomas Kissinger, Marcus Hähnel, Till Smejkal, Dirk Habich, Hermann Härtig, Wolfgang Lehner |
SIGMOD Conference | 5 |
| 2017 | Towards Automated Configuration of Systems with Non-Functional ConstraintsabstractThe paper reports on first steps towards a systematic design process that ensures quantitative stochastic requirements like requirements on the expected energy consumption or resilience requirements by construction. The idea is to automatically extract a formal model from a configurable system and to use formal analysis techniques to automatically determine a configuration such that the system meets the quantitative requirements. As a proof of concept we present a tool that supports the automated synthesis of protocol parameters for IPC (interprocess communication). The tool takes as input a Lua script describing the communication structure of several processes. This script is annotated with quantitative information such as error probabilities and timing information. The output is a Markov chain specified in the input language of the prominent probabilistic model checker PRISM. This Markov chain yields the basis for quantitative formal analysis of failure scenarios caused by hardware faults in IPC channels. The results yield the basis for finding optimal values for protocol parameters that tune, e.g., the level of resiliency. As an initial demonstration of the tool, we analyze and adjust system parameters of a simple scenario with a few communicating processes and report on results. Though achieved under simplified assumptions, the results presented here are a proof-of-concept towards the vision of automated system configuration. Linda Herrmann, Martin Küttler, Tobias Stumpf, Christel Baier, Hermann Härtig, Sascha Klüppelholz |
HotOS | 5 |
| 2017 | Lateral Thinking for Trustworthy AppsabstractThe growing computerization of critical infrastructure as well as the pervasiveness of computing in everyday life has led to increased interest in secure application development. We observe a flurry of new security technologies like ARM TrustZone and Intel SGX, but a lack of a corresponding architectural vision. We are convinced that point solutions are not sufficient to address the overall challenge of secure system design. In this paper, we outline our take on a trusted component ecosystem of small individual building blocks with strong isolation. In our view, applications should no longer be designed as massive stacks of vertically layered frameworks, but instead as horizontal aggregates of mutually isolated components that collaborate across machine boundaries to provide a service. Lateral thinking is needed to make secure systems going forward. Hermann Härtig, Michael Roitzsch, Carsten Weinhold, Adam Lackorzynski |
ICDCS | 1 |
| 2017 | TETRiS: a Multi-Application Run-Time System for Predictable Execution of Static MappingsabstractFor embedded system software, it is common to use static mappings of tasks to cores. This becomes considerably more challenging in multi-application scenarios. In this paper, we propose TETRiS, a multi-application run-time system for static mappings for heterogeneous system-on-chip architectures. It leverages compile-time information to map and migrate tasks in a fashion that preserves the predictable performance of using static mappings, allowing the system to accommodate multiple applications. TETRiS runs on off-the-shelf embedded systems and is Linux-compatible. We embed our approach in a state-of-the-art compiler for multicore systems and evaluate the proposed run-time system in a modern heterogeneous platform using realistic benchmarks. We present two experiments whose execution time and energy consumptions are comparable to those obtained by the highly-optimized Linux scheduler CFS, and where execution time variance is reduced by a factor of 510, and energy consumption variance by a factor of 83. Andres Goens, Robert Khasanov, Jerónimo Castrillón, Marcus Hähnel, Till Smejkal, Hermann Härtig |
SCOPES | 6 |
| 2017 | Sandcrust: Automatic Sandboxing of Unsafe Components in RustabstractSystem-level development has been dominated by traditional programming languages such as C and C++ for decades. These languages are inherently unsafe regarding memory management. Even experienced developers make mistakes that open up security holes or compromise the safety properties of software. The Rust programming language is targeted at the systems domain and aims to eliminate memory-related programming errors by enforcing a strict memory model at the language and compiler level. Unfortunately, these compile-time guarantees no longer hold when a Rust program is linked against a library written in unsafe C, which is commonly required for functionality where an implementation in Rust is not yet available. Benjamin Lamowski, Carsten Weinhold, Adam Lackorzynski, Hermann Härtig |
PLOS@SOSP | 4 |
| 2017 | E-Team: Practical Energy Accounting for Multi-Core Systems
Till Smejkal, Marcus Hähnel, Thomas Ilsche, Michael Roitzsch, Wolfgang E. Nagel, Hermann Härtig |
USENIX ATC | 6 |
| 2016 | M3: A Hardware/Operating-System Co-Design to Tame Heterogeneous ManycoresabstractIn the last decade, the number of available cores increased and heterogeneity grew. In this work, we ask the question whether the design of the current operating systems (OSes) is still appropriate if these trends continue and lead to abundantly available but heterogeneous cores, or whether it forces a fundamental rethinking of how systems are designed. We argue that: 1. hiding heterogeneity behind a common hardware interface unifies, to a large extent, the control and coordination of cores and accelerators in the OS, 2. isolating at the network-on-chip rather than with processor features (like privileged mode, memory management unit, ...), allows running untrusted code on arbitrary cores, and 3. providing OS services via protocols over the network-on-chip, instead of via system calls, makes them accessible to arbitrary types of cores as well. Nils Asmussen, Marcus Völp, Benedikt Noethen, Hermann Härtig, Gerhard P. Fettweis |
ASPLOS | 4 |
| 2015 | Towards dependable CPS infrastructures: Architectural and operating-system challengesabstractCyber-physical systems (CPSs), due to their direct influence on the physical world, have to meet extended security and dependability requirements. This is particularly true for CPS that operate in close proximity to humans or that control resources that, when tampered with, put all our lives at stake. In this paper, we review the challenges and some early solutions that arise at the architectural and operating-system level when we require cyber-physical systems and CPS infrastructure to withstand advanced and persistent threats. We found that although some of the challenges we identified are already matched by rudimentary solutions, further research is required to ensure sustainable and dependable operation of physically exposed CPS infrastructure and, more importantly, to guarantee graceful degradation in case of malfunction or attack. Marcus Völp, Nils Asmussen, Hermann Härtig, Benedikt Noethen, Gerhard P. Fettweis |
ETFA | 3 |
| 2015 | Demo abstract: An energy/utility demo - Energy-aware resource scheduling under utility considerationsabstractOur works on energy/utility present an approach for energy-efficient resource management that considers the utility requirements of users and the energy restriction that are set by them. In this demo, we show an initial prototype of our approach, demonstrating energy/utility trade-offs in an example application and how modeling individual components and their interaction can simplify the scheduling of resources. Marcus Hähnel, Hermann Härtig |
RTAS | 2 |
| 2015 | Locks: Picking key methods for a scalable quantitative analysis
Christel Baier, Marcus Daum, Benjamin Engel, Hermann Härtig, Joachim Klein 0001, Sascha Klüppelholz, Steffen Märcker, Hendrik Tews, Marcus Völp |
J. Comput. Syst. Sci. | 4 |
| 2014 | Can we put concurrency back into redundant multithreading?abstractSoftware-implemented fault tolerance (SIFT) mechanisms allow to tolerate transient hardware faults in commercial off-the-shelf (COTS) systems without using specialized resilient hardware. Unfortunately, existing SIFT methods at both the compiler and the operating system levels are often restricted to single-threaded applications and hence do not apply to multithreaded software on modern multicore platforms. Björn Döbel, Hermann Härtig |
EMSOFT | 2 |
| 2013 | Response-Time Analysis of Parallel Fork-Join Workloads with Real-Time ConstraintsabstractThe advent of multi- and many-core processors comes with new challenges and opportunities for the designer of embedded real-time applications. By using parallel programming techniques (e.g. OpenMP) software engineers can leverage from the available hardware parallelism and speed up the algorithms. The inherent redundancy of multi-core architectures can also be used to implement fault-tolerance by executing code redundantly on multiple cores in parallel. Parallel programming and redundant execution are typical examples for fork-join tasks in which the program is partially parallelized. However, complex synchronization of parallel segments across multiple cores can cause unanticipated effects. This is especially problematic in hard real-time applications where data must be available in bounded time (e.g. stereo vision for pedestrian detection). The contribution of this work is a novel worst-case response time analysis which accounts for synchronization of fork-join tasks with arbitrary deadlines. We apply the analysis to the Romain framework which extends the L4 micro kernel by redundant multithreading targeted towards fault-tolerant embedded systems. By using formal analysis, we show that parallelizing workloads can lead to drastic performance impairments compared to traditional sequential execution if not done carefully. Philip Axer, Sophie Quinton, Moritz Neukirchner, Rolf Ernst, Björn Döbel, Hermann Härtig |
ECRTS | 6 |
| 2013 | Atlas: Look-ahead scheduling using workload metricsabstractFrom video and music to user interface animations, a lot of real-time workloads run on today's desktops and mobile devices, yet commodity operating systems offer scheduling interfaces like nice-levels, priorities or shares that do not adequately convey timing requirements. Real-time research offers many solutions with strong timeliness guarantees, but they often require a periodic task model and ask the developer for information that is hard to obtain like execution times or reservation budgets. Within this design space of easy programming, but weak guarantees on one hand and strong guarantees, but harder development on the other, we propose Atlas, the Auto-Training Look-Ahead Scheduler. With a simple yet powerful interface it relies exclusively on data from the application domain: It uses deadlines to express timing requirements and workload metrics to express resource requirements. It replaces implicit knowledge of future job releases as provided by periodic tasks with explicit job submission to enable look-ahead scheduling. Using video playback as a dynamic high-throughput load, we show that the proposed workload metrics are sufficient for Atlas to know an application's execution time behavior ahead of time. Atlas' predictions have a typical relative error below 10%. Michael Roitzsch, Stefan Wachtler, Hermann Härtig |
IEEE Real-Time and Embedded Technology and Applications Symposium | 3 |
| 2013 | On confidentiality-preserving real-time locking protocolsabstractCoordinating access to shared resources is a challenging task, in particular if real-time and security aspects have to be integrated into the same system. However, rather than exacerbating the problem, we found that considering real-time guarantees actually simplifies the security problem of preventing information leakage over shared-resource covert channels. We introduce a transformation for standard real-time resource locking protocols and show that protocols transformed in this way preserve the confidentiality guarantees of the schedulers on which they are based. Through this transformation, we were able to prove that four out of the seven investigated protocols are information-flow secure. Marcus Völp, Benjamin Engel, Claude-Joachim Hamann, Hermann Härtig |
IEEE Real-Time and Embedded Technology and Applications Symposium | 4 |
| 2013 | The case for practical multi-resource and multi-level scheduling based on Energy/UtilityabstractEnergy has become the dominating concern for resource management. We advocate an energy-centered design approach for resource-management systems. To this end, we structure systems in layers, where layers implement higher-level resources using lower-level ones. For each layer, we describe the relation of the performance delivered for the higher layer to its demands on the lower layer and refer to that relation as demand/performance function. The lowest layers are rooted in hardware and express demand in terms of energy, the highest layers provide performance in terms of user-specific utility, thus leading to an Energy/Utility characterization of a complete system. We describe the overall approach, some research challenges and few initial results on the representation of demand/performance functions. Hermann Härtig, Marcus Völp, Marcus Hähnel |
RTCSA | 1 |
| 2012 | Operating system support for redundant multithreadingabstractIn modern commodity operating systems, core functionality is usually designed assuming that the underlying processor hardware always functions correctly. Shrinking hardware feature sizes break this assumption. Existing approaches to cope with these issues either use hardware functionality that is not available in commercial-off-the-shelf (COTS) systems or poses additional requirements on the software development side, making reuse of existing software hard, if not impossible. Björn Döbel, Hermann Härtig, Michael Engel |
EMSOFT | 2 |
| 2012 | Flattening hierarchical schedulingabstractRecently, the application of virtual-machine technology to integrate real-time systems into a single host has received significant attention and caused controversy. Drawing two examples from mixed-criticality systems, we demonstrate that current virtualization technology, which handles guest scheduling as a black box, is incompatible with this modern scheduling discipline. However, there is a simple solution by exporting sufficient information for the host scheduler to overcome this problem. We describe the problem, the modification required on the guest and show on the example of two practical real-time operating systems how flattening the hierarchical scheduling problem resolves the issue. We conclude by showing the limitations of our technique at the current state of our research. Adam Lackorzynski, Alexander Warg, Marcus Völp, Hermann Härtig |
EMSOFT | 4 |
| 2012 | Waiting for Locks: How Long Does It Usually Take?
Christel Baier, Marcus Daum, Benjamin Engel, Hermann Härtig, Joachim Klein 0001, Sascha Klüppelholz, Steffen Märcker, Hendrik Tews, Marcus Völp |
FMICS | 4 |
| 2010 | Capability wrangling made easy: debugging on a microkernel with valgrindabstractNot all operating systems are created equal. Contrasting traditional monolithic kernels, there is a class of systems called microkernels more prevalent in embedded systems like cellphones, chip cards or real-time controllers. These kernels offer an abstraction very different from the classical POSIX interface. The resulting unfamiliarity for programmers complicates development and debugging. Valgrind is a well-known debugging tool that virtualizes execution to perform dynamic binary analysis. However, it assumes to run on a POSIX-like kernel and closely interacts with the system to control execution. In this paper we analyze how to adapt Valgrind to a non-POSIX environment and describe our port to the Fiasco.OC microkernel. Additionally, we analyze bug classes that are indigenous to capability systems and show how Valgrind's flexibility can be leveraged to create custom debugging tools detecting these errors. Aaron Pohle, Björn Döbel, Michael Roitzsch, Hermann Härtig |
VEE | 4 |
| 2008 | Avoiding timing channels in fixed-priority schedulersabstractA practically feasible modification to fixed-priority schedulers allows to avoid timing channels despite threads having access to precise clocks. This modification is rather simple: we compute at admission time a static predicate that states whether a thread may possibly leak information; if such a thread blocks we switch to the idle thread instead. We describe the modified scheduler, provide a mechanical PVS-based proof of noninterference and show how common admission algorithms can be reused to give real-time guarantees for this modified scheduler. While providing similar isolation guarantees, our approach outperforms timepartitioning schedulers in terms of achieved real-time guarantees. Marcus Völp, Claude-Joachim Hamann, Hermann Härtig |
AsiaCCS | 3 |
| 2008 | VPFS: building a virtual private file system with a small trusted computing baseabstractIn this paper we present the lessons we learned when developing VPFS, a virtual private file system that is based on both a small amount of trusted storage and an untrusted legacy file system residing on the same machine. VPFS' purpose is to provide secure and reliable storage to highly sensitive applications running on top of a microkernel, which may concurrently execute untrusted software. The confidentiality and integrity guarantees of VPFS do not only apply to file contents, but also to all meta data including integrity of the directory structure. Carsten Weinhold, Hermann Härtig |
EuroSys | 2 |
| 2007 | Probabilistic Admission Control to Govern Real-Time Systems under OverloadabstractExisting real-time research focuses on how to formulate. model and enforce timeliness guarantees for task sets whose correctness has a temporal aspect. However; the resulting systems often exhibit poor resource utilization due to the resource scheduler reserving more resources than required in order to ensure that admitted schedules can be satisfied under worst case conditions. Weakening the guarantees leads to the known concepts of firm and soft real-time tasks, butt we think the paradigm needs to be shifted further,: reifying efficient utilization. With Quality-Assuring Scheduling (QAS) we presented such an algorithm. However: its practical applicability is restricted to uniform and harmonic periods, due to its complexity for arbitrary periods. To overcome this limitation, we introduce Quality-Rate-Monotonic Scheduling (QRMS), which, although slightly more pessimistic, is less complex compared to QAS. Thee admission control is again based on a probabilistic model to ensure that a requested fraction of jobs is successfully executed. Thus the amount of missed deadlines can be externally controlled, even in sustained overload situations. Claude-Joachim Hamann, Michael Roitzsch, Lars Reuther, Jean Wolter, Hermann Härtig |
ECRTS | 5 |
| 2007 | Enforceable component-based realtime contracts
Hermann Härtig, Steffen Zschaler, Martin Pohlack, Ronald Aigner, Steffen Göbel 0001, Christoph Pohl, Simone Röttger |
Real Time Syst. | 1 |
| 2006 | Reducing TCB complexity for security-sensitive applications: three case studiesabstractThe large size and high complexity of security-sensitive applications and systems software is a primary cause for their poor testability and high vulnerability. One approach to alleviate this problem is to extract the security-sensitive parts of application and systems software, thereby reducing the size and complexity of software that needs to be trusted. At the system software level, we use the Nizza architecture which relies on a kernelized trusted computing base (TCB) and on the reuse of legacy code using trusted wrappers to minimize the size of the TCB. At the application level, we extract the security-sensitive portions of an already existing application into an AppCore. The AppCore is executed as a trusted process in the Nizza architecture while the rest of the application executes on a virtualized, untrusted legacy operating system. In three case studies of real-world applications (e-commerce transaction client, VPN gateway and digital signatures in an e-mail client), we achieved a considerable reduction in code size and complexity. In contrast to the few hundred thousand lines of current application software code running on millions of lines of systems software code, we have AppCores with tens of thousands of lines of code running on a hundred thousand lines of systems software code. We also show the performance penalty of AppCores to be modest (a few percent) compared to current software. Lenin Singaravelu, Calton Pu, Hermann Härtig, Christian Helmuth |
EuroSys | 3 |
| 2005 | The Nizza secure-system architectureabstractThe trusted computing bases (TCBs) of applications running on today's commodity operating systems have become extremely large. This paper presents an architecture that allows to build applications with a much smaller TCB. It is based on a kernelized architecture and on the reuse of legacy software using trusted wrappers. We discuss the design principles, the architecture and some components, and a number of usage examples. Hermann Härtig, Michael Hohmuth, Norman Feske, Christian Helmuth, Adam Lackorzynski, Frank Mehnert, Michael Peter |
CollaborateCom | 1 |
| 2005 | Fast Component Interaction for Real-Time SystemsabstractOpen real-time systems provide for co-hosting hard-, soft- and non-real-time applications. Microkernel-based designs in addition allow for these applications to be mutually protected. Thus, trusted servers can coexist next to untrusted applications. These systems place a heavy burden on the performance of the message-passing mechanism, especially when based on microkernel-like inter-process communication. In this paper we introduce capacity-reserve donation (in short Credo), a mechanism for the fast interaction of interdependent components, which is applicable to common real-time resource-access models. We implemented Credo by extending L4's message-passing mechanism to provide proper resource accounting and time-donation control, thereby preserving desired real-time properties. We were able to achieve priority inheritance and stack-based priority-ceiling resource sharing with virtually no overhead added to L4's message-passing implementation. By providing a. mechanism that does not impose performance penalties, while still guaranteeing correct real-time behaviour, Credo allows for the usage of microkernels in general-purpose but also in specialized systems. Udo Steinberg, Jean Wolter, Hermann Härtig |
ECRTS | 3 |
| 2004 | Low-Latency Hard Real-Time Communication over Switched EthernetabstractA number of algorithms have been presented for handling software decoding of MPEG-2 streams based on buffering or rate adjustment focusing on providing good average quality. The potentially arising drops in quality are tolerated, e.g., in transmissions over the Internet; they cannot be accepted in high quality consumer products: these mandate real-time methods. When resources, such as processing power or network bandwidth, are limited and not all frames can be handled, best effort decoders incur unnecessary quality decrease while wasting resources. In this paper, we present a method for quality aware frame selection for MPEG decoding under limited resources, based on realistic timing constraints for the decoding of MPEG streams. Given that not all frames can be processed, it selects those which provide the best picture quality while matching the available resources, starting only such decoding, which is guaranteed to be completed. We formulate the method as real-time scheduling problem and present its application in an example scheduling algorithm. Results from study based on realistic MPEG-2 video underline the effectiveness of our approach. Jork Löser, Hermann Härtig |
ECRTS | 2 |
| 2003 | DOpE - a Window Server for Real-Time and Embedded SystemsabstractA window server used in real-time applications should be able to assure previously agreed-upon redrawing rates for a subset of windows while providing best-effort services to the remaining windows and operations such as moving windows. A window server used in embedded systems should be small and require only minimal operating system support, for example just threads and address spaces as provided by microkernels. In this paper, we present the design and an implementation of the DOpE window server. The key techniques used are to move redrawing responsibility from client applications to the window server and to devise a simple scheduling discipline for the redrawing subtasks. Norman Feske, Hermann Härtig |
RTSS | 2 |
| 2002 | Cost and Benefit of Separate Address Spaces in Real-Time Operating SystemsabstractThe combination of a real-time executive and an off-the-shelf time-sharing operating system has the potential of providing both predictability and the comfort of a large application base. To isolate the real-time section from a significant class of faults in the (ever-growing) time-sharing operating system, address spaces can be used to encapsulate the time-sharing subsystem. However, in practice, designers seldom use address spaces for this purpose, fearing that the extra cost induced limits the system's predictability. To analyze this cost, we compared in detail two systems with almost identical interfaces-both are a combination of the Linux operating system and a small real-time executive. Our analysis revealed that for interrupt-response times, the delay and jitter caused by address spaces are similar to or even smaller than those caused by caches and blocked interrupts. As a side effect of our analysis, we observed that published figures on predictability must be carefully checked whether or not such hardware features are included in the analysis. This paper is a follow-up of an earlier publication at the 3rd Real-Time Linux workshop. It is different in that we have further optimized our microkernel and examined more hardware. Frank Mehnert, Michael Hohmuth, Hermann Härtig |
RTSS | 3 |
| 2001 | A Streaming Interface for Real-Time Interprocess CommunicationabstractTimely transfer of long, continuous data streams and handling data omission are stringent requirements of multimedia applications. To cope with these requirements, we extend well known mechanisms for inter-address-space data transmission, such as zero-copy and fast IPC, by the notion of time. Therefore, we add a time track to data streams and add mechanisms to limit the validity of data. For cases of overload we add notification and revocation techniques. Jork Löser, Hermann Härtig, Lars Reuther |
HotOS | 2 |
| 2001 | Quality-Assuring Scheduling-Using Stochastic Behavior to Improve Resource UtilizationabstractWe present a unified model for admission and scheduling, applicable for various active resources such as CPU or disk to assure a requested quality in situations of temporary overload. The model allows us to predict and control the behavior of applications based on given quality requirements. It uses the variations in the execution time, i.e., the time any active resource is needed We split resource requirements into a mandatory part which must be available and an optional part which should be available as often as possible but at least with a certain percentage. In combination with a given distribution for the execution time we can move away from worst-case reservations and drastically reduce the amount of reserved resources for applications which can tolerate occasional deadline misses. This increases the number of admittable applications. For example, with negligible loss of quality our system can admit more than two times the disk bandwidth than a system based on the worst-case. Finally, we validated the predictions of our model by measurements using a prototype real-time system and observed a high accuracy between predicted and measured values. Claude-Joachim Hamann, Lars Reuther, Jork Wolter, Hermann Härtig, Jork Löser, Sebastian Schönberg |
RTSS | 4 |
| 2001 | Pragmatic Nonblocking Synchronization for Real-Time Systems
Michael Hohmuth, Hermann Härtig |
USENIX ATC, General Track | 2 |
| 1998 | Design and Implementation of a Real-Time ATM-Based Protocol ServerabstractThe paper describes the design and implementation of L/sup 4/ATM, an ATM (asynchronous transfer mode) based networking server. While ATM emphasizes deterministic high speed communication, applications can not yet fully utilize its potential. We demonstrate an architecture-and a corresponding implementation-to resolve this dilemma by developing implementable resource quantification techniques and QoS (Quality Of Service) management algorithms for host resources. L/sup 4/ATM has been built in the context of DROPS (Dresden Real-Time Operating System). DROPS supports coexisting real time and time sharing applications in a /spl mu/kernel environment. Evaluating L/sup 4/ATM's implementation in a real world environment, we show that: (i) performance guarantees are maintained under heavy time sharing load, and (ii) the implementation outperforms a standard OS significantly. Martin Borriss, Hermann Härtig |
RTSS | 2 |
| 1997 | Encapsulating Mobile ObjectsabstractThis paper describes a technique to effectively isolate mobile objects or processes that execute downloaded, potentially suspicious programs. It relies on wish lists, trust lists and capability lists. Wish lists are carried along with programs or mobile objects and denote the resources requested by the program to do what it claims to do. Wish lists are transformed into capability lists when downloaded programs are started. Trust lists reside on stations and are used to determine which members of wish lists are taken over into capability lists. The capability lists are enforced during the execution of programs. All lists are symbolic to enable their interpretation in heterogeneous environments. The paper describes the technique, its integration in a Linux environment and first experiences. Hermann Härtig, Lars Reuther |
ICDCS | 1 |
| 1997 | The Performance of µKernel-Based Systemsabstractarticle The performance of μ-kernel-based systems Share on Authors: Hermann Härtig Dresden University of Technology, Department of Computer Science, D-01062 Dresden, Germany Dresden University of Technology, Department of Computer Science, D-01062 Dresden, GermanyView Profile , Michael Hohmuth Dresden University of Technology, Department of Computer Science, D-01062 Dresden, Germany Dresden University of Technology, Department of Computer Science, D-01062 Dresden, GermanyView Profile , Jochen Liedtke IBM T. J. Watson Research Center, 30 Saw Mill River Road, Hawthorne, NY IBM T. J. Watson Research Center, 30 Saw Mill River Road, Hawthorne, NYView Profile , Sebastian Schönberg Dresden University of Technology, Department of Computer Science, D-01062 Dresden, Germany Dresden University of Technology, Department of Computer Science, D-01062 Dresden, GermanyView Profile , Jean Wolter Dresden University of Technology, Department of Computer Science, D-01062 Dresden, Germany Dresden University of Technology, Department of Computer Science, D-01062 Dresden, GermanyView Profile Authors Info & Claims ACM SIGOPS Operating Systems ReviewVolume 31Issue 5Dec. 1997 pp 66–77https://doi.org/10.1145/269005.266660Online:01 October 1997Publication History 177citation6,894DownloadsMetricsTotal Citations177Total Downloads6,894Last 12 Months272Last 6 weeks40 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteGet Access Hermann Härtig, Michael Hohmuth, Jochen Liedtke, Sebastian Schönberg, Jean Wolter |
SOSP | 1 |
| 1993 | The BirliX Security Architecture
Hermann Härtig, Oliver C. Kowalski, Winfried E. Kühnhauser |
J. Comput. Secur. | 1 |
| 1990 | Software Configuration Management for Medium-Size Systems
W. Reck, Hermann Härtig |
CAiSE | 2 |
| 1990 | Protection in the BirliX Operating SystemabstractThe user-interface-level and implementation-level protection mechanisms of the BirliX operating system are described and motivated. Descriptions are provided of subject restriction and object protection as complementary user-interface-level mechanisms for enforcing security policies by building small domains of protection. Traceability is used as a basis for tracing back violations of policies to answerable humans.> Oliver C. Kowalski, Hermann Härtig |
ICDCS | 2 |