作者: John Rushby
DOI:
关键词:
摘要: The structure of many secure systems has been based on the idea a security kernel—an operating system nucleus that performs all trusted functions. diculty with this approach is kernel tends to be rather large, complex, and unstructured. This paper proposes an alternative for embedded systems. comprises three layers. At bottom Domain Separation Mechanism which responsible maintaining isolated “domains” (also known as “processes” or “virtual machines”) providing controlled channels their intercommunication. other resources (for example, devices more