{"bundle_type":"pith_open_graph_bundle","bundle_version":"1.0","pith_number":"pith:2019:4VV4IJ7WQW6NE43XJ2BRJDQTFU","short_pith_number":"pith:4VV4IJ7W","canonical_record":{"source":{"id":"1908.08707","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-23T08:00:38Z","cross_cats_sorted":[],"title_canon_sha256":"8efff987b1e287b307df3f3be1146fcefa7b28174cc1b932c17e15180c051008","abstract_canon_sha256":"a875de0dd15d377d620f91da7404f4ba520284bf7f1321a119e337c8addcfec3"},"schema_version":"1.0"},"canonical_sha256":"e56bc427f685bcd273774e83148e132d29f3e9f9376902848500fd6fe7f2bae6","source":{"kind":"arxiv","id":"1908.08707","version":1},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1908.08707","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"arxiv_version","alias_value":"1908.08707v1","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1908.08707","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_12","alias_value":"4VV4IJ7WQW6N","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_16","alias_value":"4VV4IJ7WQW6NE43X","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_8","alias_value":"4VV4IJ7W","created_at":"2026-07-04T23:59:17Z"}],"events":[{"event_type":"record_created","subject_pith_number":"pith:2019:4VV4IJ7WQW6NE43XJ2BRJDQTFU","target":"record","payload":{"canonical_record":{"source":{"id":"1908.08707","kind":"arxiv","version":1},"metadata":{"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-23T08:00:38Z","cross_cats_sorted":[],"title_canon_sha256":"8efff987b1e287b307df3f3be1146fcefa7b28174cc1b932c17e15180c051008","abstract_canon_sha256":"a875de0dd15d377d620f91da7404f4ba520284bf7f1321a119e337c8addcfec3"},"schema_version":"1.0"},"canonical_sha256":"e56bc427f685bcd273774e83148e132d29f3e9f9376902848500fd6fe7f2bae6","receipt":{"kind":"pith_receipt","key_id":"pith-v1-2026-05","algorithm":"ed25519","signed_at":"2026-07-04T23:59:17.013680Z","signature_b64":"YHJkdWc2vQzBoEiiams9+ULzt56kecSMt7otz5Z3W7Y84eIz0aRgOWWqPDO96oWxWcCsIuLWORGNoElDPjOqCA==","signed_message":"canonical_sha256_bytes","builder_version":"pith-number-builder-2026-05-17-v1","receipt_version":"0.3","canonical_sha256":"e56bc427f685bcd273774e83148e132d29f3e9f9376902848500fd6fe7f2bae6","last_reissued_at":"2026-07-04T23:59:17.013224Z","signature_status":"signed_v1","first_computed_at":"2026-07-04T23:59:17.013224Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"source_kind":"arxiv","source_id":"1908.08707","source_version":1,"attestation_state":"computed"},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-04T23:59:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"iIsqE0ju8ZtZMgtXNiH0f2nlVuacGIjRaCxIqA5vVm0LNSNtiEBmN0BmLl+GR6MD3U846VtJM2a9PATrydwLBg==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-18T08:03:26.258447Z"},"content_sha256":"560e5a74499b00354aee7360eac80ff8dcf75ed19850ecb77b3119d927ded117","schema_version":"1.0","event_id":"sha256:560e5a74499b00354aee7360eac80ff8dcf75ed19850ecb77b3119d927ded117"},{"event_type":"graph_snapshot","subject_pith_number":"pith:2019:4VV4IJ7WQW6NE43XJ2BRJDQTFU","target":"graph","payload":{"graph_snapshot":{"paper":{"title":"A Least-Privilege Memory Protection Model for Modern Hardware","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","headline":"","cross_cats":[],"primary_cat":"cs.OS","authors_text":"Daniel Schwyn, David Cock, Lukas Humbel, Nora Hossle, Reto Achermann, Timothy Roscoe","submitted_at":"2019-08-23T08:00:38Z","abstract_excerpt":"We present a new least-privilege-based model of addressing on which to base memory management functionality in an OS for modern computers like phones or server-based accelerators. Existing software assumptions do not account for heterogeneous cores with different views of the address space, leading to the related problems of numerous security bugs in memory management code (for example programming IOMMUs), and an inability of mainstream OSes to securely manage the complete set of hardware resources on, say, a phone System-on-Chip.\n  Our new work is based on a recent formal model of address tra"},"claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1908.08707","kind":"arxiv","version":1},"verdict":{"id":null,"model_set":{},"created_at":null,"strongest_claim":"","one_line_summary":"","pipeline_version":null,"weakest_assumption":"","pith_extraction_headline":""},"integrity":{"clean":true,"summary":{"advisory":0,"critical":0,"by_detector":{},"informational":0},"endpoint":"/pith/1908.08707/integrity.json","findings":[],"available":true,"detectors_run":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938"},"references":{"count":0,"sample":[],"resolved_work":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","internal_anchors":0},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"author_claims":{"count":0,"strong_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"builder_version":"pith-number-builder-2026-05-17-v1"},"verdict_id":null},"signer":{"signer_id":"pith.science","signer_type":"pith_registry","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54"},"created_at":"2026-07-04T23:59:17Z","supersedes":[],"prev_event":null,"signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"8bUWoODzqsGbyDiLMK5O02TujNQve9yIfCLPw5F5ICb7+/uHAx2JW4EEv52XliRoxkBl0jJkKRJGQgZczm7PDQ==","signed_message":"open_graph_event_sha256_bytes","signed_at":"2026-08-18T08:03:26.259077Z"},"content_sha256":"dc3f119c93ef76298604f251f3d85762a8c1ba5949112ec5d0d33fc3ff865f9a","schema_version":"1.0","event_id":"sha256:dc3f119c93ef76298604f251f3d85762a8c1ba5949112ec5d0d33fc3ff865f9a"}],"timestamp_proofs":[],"mirror_hints":[{"mirror_type":"https","name":"Pith Resolver","base_url":"https://pith.science","bundle_url":"https://pith.science/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/bundle.json","state_url":"https://pith.science/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/state.json","well_known_bundle_url":"https://pith.science/.well-known/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/bundle.json","status":"primary"}],"public_keys":[{"key_id":"pith-v1-2026-05","algorithm":"ed25519","format":"raw","public_key_b64":"stVStoiQhXFxp4s2pdzPNoqVNBMojDU/fJ2db5S3CbM=","public_key_hex":"b2d552b68890857171a78b36a5dccf368a953413288c353f7c9d9d6f94b709b3","fingerprint_sha256_b32_first128bits":"RVFV5Z2OI2J3ZUO7ERDEBCYNKS","fingerprint_sha256_hex":"8d4b5ee74e4693bcd1df2446408b0d54","rotates_at":null,"url":"https://pith.science/pith-signing-key.json","notes":"Pith uses this Ed25519 key to sign canonical record SHA-256 digests. Verify with: ed25519_verify(public_key, message=canonical_sha256_bytes, signature=base64decode(signature_b64))."}],"merge_version":"pith-open-graph-merge-v1","built_at":"2026-08-18T08:03:26Z","links":{"resolver":"https://pith.science/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU","bundle":"https://pith.science/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/bundle.json","state":"https://pith.science/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/state.json","well_known_bundle":"https://pith.science/.well-known/pith/4VV4IJ7WQW6NE43XJ2BRJDQTFU/bundle.json"},"state":{"state_type":"pith_open_graph_state","state_version":"1.0","pith_number":"pith:2019:4VV4IJ7WQW6NE43XJ2BRJDQTFU","merge_version":"pith-open-graph-merge-v1","event_count":2,"valid_event_count":2,"invalid_event_count":0,"equivocation_count":0,"current":{"canonical_record":{"metadata":{"abstract_canon_sha256":"a875de0dd15d377d620f91da7404f4ba520284bf7f1321a119e337c8addcfec3","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-23T08:00:38Z","title_canon_sha256":"8efff987b1e287b307df3f3be1146fcefa7b28174cc1b932c17e15180c051008"},"schema_version":"1.0","source":{"id":"1908.08707","kind":"arxiv","version":1}},"source_aliases":[{"alias_kind":"arxiv","alias_value":"1908.08707","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"arxiv_version","alias_value":"1908.08707v1","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"doi","alias_value":"10.48550/arxiv.1908.08707","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_12","alias_value":"4VV4IJ7WQW6N","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_16","alias_value":"4VV4IJ7WQW6NE43X","created_at":"2026-07-04T23:59:17Z"},{"alias_kind":"pith_short_8","alias_value":"4VV4IJ7W","created_at":"2026-07-04T23:59:17Z"}],"graph_snapshots":[{"event_id":"sha256:dc3f119c93ef76298604f251f3d85762a8c1ba5949112ec5d0d33fc3ff865f9a","target":"graph","created_at":"2026-07-04T23:59:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"graph_snapshot":{"author_claims":{"count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57","strong_count":0},"builder_version":"pith-number-builder-2026-05-17-v1","claims":{"count":0,"items":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"formal_canon":{"evidence_count":0,"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"integrity":{"available":true,"clean":true,"detectors_run":[],"endpoint":"/pith/1908.08707/integrity.json","findings":[],"snapshot_sha256":"c28c3603d3b5d939e8dc4c7e95fa8dfce3d595e45f758748cecf8e644a296938","summary":{"advisory":0,"by_detector":{},"critical":0,"informational":0}},"paper":{"abstract_excerpt":"We present a new least-privilege-based model of addressing on which to base memory management functionality in an OS for modern computers like phones or server-based accelerators. Existing software assumptions do not account for heterogeneous cores with different views of the address space, leading to the related problems of numerous security bugs in memory management code (for example programming IOMMUs), and an inability of mainstream OSes to securely manage the complete set of hardware resources on, say, a phone System-on-Chip.\n  Our new work is based on a recent formal model of address tra","authors_text":"Daniel Schwyn, David Cock, Lukas Humbel, Nora Hossle, Reto Achermann, Timothy Roscoe","cross_cats":[],"headline":"","license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-23T08:00:38Z","title":"A Least-Privilege Memory Protection Model for Modern Hardware"},"references":{"count":0,"internal_anchors":0,"resolved_work":0,"sample":[],"snapshot_sha256":"258153158e38e3291e3d48162225fcdb2d5a3ed65a07baac614ab91432fd4f57"},"source":{"id":"1908.08707","kind":"arxiv","version":1},"verdict":{"created_at":null,"id":null,"model_set":{},"one_line_summary":"","pipeline_version":null,"pith_extraction_headline":"","strongest_claim":"","weakest_assumption":""}},"verdict_id":null}}],"author_attestations":[],"timestamp_anchors":[],"storage_attestations":[],"citation_signatures":[],"replication_records":[],"corrections":[],"mirror_hints":[],"record_created":{"event_id":"sha256:560e5a74499b00354aee7360eac80ff8dcf75ed19850ecb77b3119d927ded117","target":"record","created_at":"2026-07-04T23:59:17Z","signer":{"key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signer_id":"pith.science","signer_type":"pith_registry"},"payload":{"attestation_state":"computed","canonical_record":{"metadata":{"abstract_canon_sha256":"a875de0dd15d377d620f91da7404f4ba520284bf7f1321a119e337c8addcfec3","cross_cats_sorted":[],"license":"http://arxiv.org/licenses/nonexclusive-distrib/1.0/","primary_cat":"cs.OS","submitted_at":"2019-08-23T08:00:38Z","title_canon_sha256":"8efff987b1e287b307df3f3be1146fcefa7b28174cc1b932c17e15180c051008"},"schema_version":"1.0","source":{"id":"1908.08707","kind":"arxiv","version":1}},"canonical_sha256":"e56bc427f685bcd273774e83148e132d29f3e9f9376902848500fd6fe7f2bae6","receipt":{"algorithm":"ed25519","builder_version":"pith-number-builder-2026-05-17-v1","canonical_sha256":"e56bc427f685bcd273774e83148e132d29f3e9f9376902848500fd6fe7f2bae6","first_computed_at":"2026-07-04T23:59:17.013224Z","key_id":"pith-v1-2026-05","kind":"pith_receipt","last_reissued_at":"2026-07-04T23:59:17.013224Z","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","receipt_version":"0.3","signature_b64":"YHJkdWc2vQzBoEiiams9+ULzt56kecSMt7otz5Z3W7Y84eIz0aRgOWWqPDO96oWxWcCsIuLWORGNoElDPjOqCA==","signature_status":"signed_v1","signed_at":"2026-07-04T23:59:17.013680Z","signed_message":"canonical_sha256_bytes"},"source_id":"1908.08707","source_kind":"arxiv","source_version":1}}},"equivocations":[],"invalid_events":[],"applied_event_ids":["sha256:560e5a74499b00354aee7360eac80ff8dcf75ed19850ecb77b3119d927ded117","sha256:dc3f119c93ef76298604f251f3d85762a8c1ba5949112ec5d0d33fc3ff865f9a"],"state_sha256":"6705af9a140eb2be7e6ff5c69cf0bf489ffd08fe4b444d48b2f56a78ffe77cf4"},"bundle_signature":{"signature_status":"signed_v1","algorithm":"ed25519","key_id":"pith-v1-2026-05","public_key_fingerprint":"8d4b5ee74e4693bcd1df2446408b0d54","signature_b64":"FiMy1V8r1q4D+ajj8AEjpG+J9YVUeqURBe9Lw2HBzdGGQr89nwUXQe1z27lkyr2mSttN3mTFMLrZieoCmAmJCg==","signed_message":"bundle_sha256_bytes","signed_at":"2026-08-18T08:03:26.262413Z","bundle_sha256":"f4d0cd10aac0e775c0dc4ae72dc179b0f8c0d81a5657099425e96e99c5d264f7"}}