On security in capability-based systems

Li Jing Gong · ACM SIGOPS Operating Systems Review · 1989

Introduction Hogan in her recent paper [4] presented the requirements and the characteristics of operating systems to realize the principle of complete mediation. She states "the principle of complete mediation requires that every access to every object be checked for authority. This implies that a secure system must utilize a foolproof method of identifying the source of every request". Wells argues in a later paper [13] that Hogan's discussion "does not apply to contemporary capability-based system technology", and her statement is not true in such systems. Wells used the KeyKOS system [3,11] as an example. In our opinion, Wells's argument holds for at most one special type of capability systems, which we refer as fully armed systems. In fact, one can argue that in KeyKOS the utilization of a foolproof mechanism for identifying the source is implicitly embedded throughout the system design, which is mixed with other issues and would naturally

Read the paper · More papers on PaperTik