More Patterns for Operating System Access Control.
Eduardo B. Fernández, John Sinibaldi · European Conference on Pattern Languages of Programs · 2003
We present architectural patterns for access control in operating systems. These complement the patterns that we introduced in a previous paper. The patterns control access to resources represented as objects and include patterns for authentication, process creation, object creation, and object access. Introduction We present architectural patterns for access control in operating systems. These complement the patterns that we introduced in [Fer02]. That paper presented the following patterns: • File access control. How do you control access to files in an operating system? Apply the Authorization pattern to describe access to files by subjects. The protection object is now a file component that may be a directory or a file. • Controlled Virtual Address Space. How to control access by processes to specific areas of their virtual address space (VAS) according to a set of predefined access types? Divide the VAS into segments that correspond to logical units in the programs. Use special words (descriptors) to represent access rights for these segments. • Reference Monitor. How to enforce authorizations when a process requests access to an object? Define an abstract process that intercepts all requests for resources and checks them for compliance with authorizations. • Controlled Execution Environment. How to define an execution environment for processes? Attach to each process a set of descriptors that represent the rights of the process. Use the Reference Monitor to enforce access. Here we add the following patterns: • Authenticator. How to verify that a subject is who it says it is? Use a single point of access to receive the interactions of a subject with the system and apply a protocol to verify the identity of the subject. • Controlled-Process Creator. How to define the rights to be given to a new process? Define their rights as part of their creation. • Controlled-Object Factory. How to specify rights of processes with respect to a new object? When a process creates a new object through a Factory, the request includes the features of the new object. Among these features include a list of rights to access the object. • Controlled-Object Monitor. How to control access by a subject to an object? Use a reference monitor to intercept access requests from processes. The reference monitor checks if the process has the requested type of access to the object. Assume here that resources are represented as objects, as it is common in modern operating systems. Figure 1 shows how these patterns are organized into a pattern language. For example, Authentication is needed for file access and for controlled object access, a subject must be authorized to access some object in a specific way and we need to make sure that the requestor is not an impostor. The other three patterns complete the definition of the Controlled Execution Environment, where now the creation and access to objects are controlled. The language also shows that access to files is controlled by a Reference Monitor. Background Operating systems are fundamental to provide security to computing systems. The operating system supports the execution of applications and any security constraints defined at that level must be enforced by the operating system. The operating system must also protect itself because compromise would give access to all the user accounts and all the data in their files. A weak operating system would allow hackers access not only to data in the operating system files but data in database systems that use the services of the operating system. The operating system performs this protection by protecting processes from each other and protecting the permanent data stored in its files [Sil03]. For this purpose, the operating system controls access to resources such as memory address spaces and I/O devices. Most operating systems use the access matrix as security model. An access matrix defines which processes (subjects in general) have what types of access to specific resources (resources are represented as objects in modern operating systems). To apply this model we need to make sure that subjects are authenticated before they perform any access (using the Authenticator), we need to control the rights given to each process when created (Controlled-Process Creator), and to let processes execute in a controlled environment where they cannot exceed their rights (Controlled Execution Environment). We also need to define access rights to access new objects (Controlled-Object Factory) , and to control access to objects at execution time (Controlled-Object Monitor). This latter performs access control by intercepting requests and checking them for authorization. All these functions are the purpose of the patterns presented in these two papers. Operating systems authenticate users when they first login and maybe again when they access specific resources. A user then executes an application composed of several concurrent processes. Processes are usually created through system calls to the operating system. A process that needs to create a new process gets the operating system to create a child process that is given access to some resources. Executing applications need to create objects for their work. Some objects are created at program initialization while others are created dynamically during execution. The access rights of processes with respect to objects must be defined when these processes are created. Applications also ControlledObject Factory ControlledProcess Creator Authenticator File Access ControlledObject Monitor Controlled Execution Environment Reference Monitor Controlled VAS Uses Uses