• DocumentCode
    3452668
  • Title

    Vulnerabilities in synchronous IPC designs

  • Author

    Shapiro, Jonathan S.

  • Author_Institution
    Dept. of Comput. Sci., Johns Hopkins Univ., MD, USA
  • fYear
    2003
  • fDate
    11-14 May 2003
  • Firstpage
    251
  • Lastpage
    262
  • Abstract
    Recent advances in interprocess communication (IPC) performance have been exclusively based on thread-migrating IPC designs. Thread-migrating designs assume that IPC interactions are synchronous, and that user-level execution will usually resume with the invoked process (modulo preemption). This IPC design approach offers shorter instruction path lengths, requires fewer locks, has smaller instruction and data cache footprints, dramatically reduces TLB overheads, and consequently offers higher performance and lower timing variance than previous IPC designs. With care, it can be performed as an atomic unit of operation. While the performance of thread-migrating IPC has been examined in detail, the vulnerabilities implicit in synchronous IPC designs have not been examined in depth in the archival literature, and their implications for IPC design have been actively misunderstood in at least one recent publication. In addition to performance, a sound IPC design must address concerns of asymmetric trust and reproducibility and provide support for dynamic payload lengths. Previous IPC designs, including those of EROS, Mach, L4, Flask, and Pebble, satisfy only two of these three requirements. In this paper, we show how these three design objectives can be met simultaneously. We identify the conflict of requirements and illustrate how their collision arises in two well-documented IPC architectures: L4 and EROS. We then show how all three design objectives are simultaneously met in the next generation EROS IPC system.
  • Keywords
    multi-threading; operating system kernels; performance evaluation; security of data; EROS; L4; asymmetric trust; capability systems; dynamic payload lengths; interprocess communication; operating systems; performance; reproducibility; synchronous IPC designs; thread-migrating designs; vulnerabilities; Communication system security; Computer science; Operating systems; Payloads; Performance analysis; Protection; Reproducibility of results; Resumes; Testing; Timing;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Security and Privacy, 2003. Proceedings. 2003 Symposium on
  • ISSN
    1081-6011
  • Print_ISBN
    0-7695-1940-7
  • Type

    conf

  • DOI
    10.1109/SECPRI.2003.1199341
  • Filename
    1199341