作者: Spencer E. Minear
DOI:
关键词:
摘要: In both secure and safety-critical systems it is desirable to have a very clear relationship between the system's mandatory security policy its proven operational semantics. This made clearer if system architecture provides strong separation enforcement mechanisms decisions, decision software clearly identifiable in architecture. This paper describes prototype Unix based on Mach which control over all kernel-supported operations. The work modified kernel by extending limited port right. extensions allow specify not only access an object via right, but individual services supported object. implemented external Security Server software. makes possible support wide range of policies with no change or applications.