Security pipeline interface (SPI)

Lance J. Hoffman, Roger Davis · 2002

Proposes a new approach, security pipeline interface, for adding security to existing systems. Security functions are added in series to existing I/O paths without modification to the host system internals. The result is an I/O pipeline of security functions which is adaptable to both trusted and untrusted environments. Security of the physically separated SPI architecture is easier to analyze then other security products. Additionally, SPI requires no modification to the operating system. However, SPI is limited to the host processor interfaces. The SPI approach is compared with and contrasted to other ongoing security pipeline research. Examples of applications are presented which illustrate how security functions are added in a pipeline. These include a rogue program controller and intrusion detection systems.>

Read the paper · More papers on PaperTik