DocumentCode :
2217681
Title :
A fine-grained protection mechanism in object-based operating systems
Author :
Shigeta, Soichi ; Tanimori, Toru ; Shimizu, Kentaro ; Ashihara, Hyo
Author_Institution :
Dept. of Comput. Sci., Univ. of Electro-Commun., Tokyo, Japan
fYear :
1996
fDate :
27-28 Oct 1996
Firstpage :
156
Lastpage :
160
Abstract :
The paper describes the design and implementation of a flexible, fine-grained protection mechanism for operating systems based on an object/thread model. The mechanism has the following features: (1) it provides fine-grained protection: each thread has a list of keys (capabilities) and inherits object´s keys when it invokes an abject. (2) The mechanism is very flexible: a combination of multiple keys are used to represent various conditions for accessing objects. (3) It allows a group of keys to be defined as key group, which realizes hierarchical, integrated key processing and management. (4) Users can specify an SCL (subject control list), which defines a list of objects that a subject can invoke. This is used to restrict subjects; suspected subjects are only allowed to access the objects specified in the SCL. The proposed mechanism is being implemented in an object-based operating system which the authors are developing. Implementation techniques to improve efficiency are also described
Keywords :
object-oriented methods; object-oriented programming; operating systems (computers); protection; security of data; software engineering; efficiency; flexible fine-grained protection mechanism; hierarchical key management; hierarchical key processing; integrated key management; integrated key processing; key group; multiple keys; object access; object keys; object model; object-based operating systems; subject control list; suspected subjects; thread model; Access control; Computer science; Data structures; Design methodology; Mechanical factors; Operating systems; Permission; Protection; Switches; Yarn;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Object-Orientation in Operating Systems, 1996., Proceedings of the Fifth International Workshop on
Conference_Location :
Seattle, WA
ISSN :
1063-5351
Print_ISBN :
0-8186-7692-2
Type :
conf
DOI :
10.1109/IWOOOS.1996.557911
Filename :
557911
Link To Document :
بازگشت