Microsoft formed the first release of the Litebox project, which develops a security-focused operating system implemented in the form of a library (Library OS). With this approach, operating system services are directly built into the application instead of accessing the external OS kernel using system calls. Litebox can be used in programs or kernels as an additional layer of isolation, blocking access to unnecessary kernel functionality or APIs. The project code is written in Rust and is open under the MIT license.
Litebox provides an application-connected library with an isolation layer that translates requests to external program interfaces. Such external interfaces can be the Linux kernel, protected isolated environments OP-TEE (Open Portable Trusted Execution Environment), Webassembly environments or the standard RustStd library.
The minimal platform formed via Litebox is applicable for running Linux and Windows applications, nested Linux kernels and LVBS (Linux Virtualization Based Security). Possible applications for Litebox include ensuring that unmodified Linux programs run on Windows, isolating the execution of Linux applications on systems running the Linux kernel, running programs on top of AMD SEV SNP for memory encryption, running OP-TEE programs on Linux, and isolation using the LVBS concept (using hardware virtualization to protect individual components of the Linux kernel, for example, used to control the authenticity of modules and access control).
