KeyKOS architecture

Norman Hardy · ACM SIGOPS Operating Systems Review · 1985

IntroductionThis paper introduces the Architecture of KeyKOS ~M* , a capability-based operating system for the I B M System 13 70.We attempt to tel I enough so that certain arguments and conclusions about its properties can be formed.Our description attempts to be essentially complete concerning the function of the kernel** which comprises the privileged-mode code.Precision is attempted even while suppressing detail and omitting some unimportant architectural features.KeyKO,S was originally designed to solve the security, sharing, pricing, reliability, and extensibiIity requirements of a commercial computer service in a network environment.KeyK05 stands outside the conventional, 1960s-besed technology stream of IBM 370 operating system development.KeVK06 has been running on an IBM 4341 sincedanuary 1983 in support of a few production applications.. KeyK08 is also in the tradition of message-based systems.Messages are the primary interaction between components of the system.KeyKO,S supports object-style programming.Indeed, nearly all of the code written so far for KeyKO,S serves to define some particular type of object.Objects call upon the services of other objects by sending messaoes.For brevity we use "key" where most literature uses "capability"."Capability" has perfect connotations but tires the tongue.* Patent pending.* * Beid face is used to highlight terms at their point of inLroducUon or definition, Keys are tokens of authority.A program may only cause ~tions warranted by the keys it holds.Any action that a program causes is enabled by some key that it holds and explicitly identifies in an inyoc~t~on of that key.A key desionotes a specific object.The authority granted by a key is specific to just the object designated by that key.Different keys may designate the same object but convey different authority over that object.Exercising authority represented by a key is done by invoking the key.Some objects have state which may be modified by a holder of a Key that designates the object.Weaker keys to that object may only let the holder sense the state of the objectIn this paper "kernel cotmJIOr¥" refers to some class of keys known to the kernel.I1~solI~ are the principal signal by which one object influences another.The sender of a message must hold a kay designating the recipient object.The sender may include in a message keys that he holds, whereupon the recipient may also hold them.To send a message via a key is to invoke the key.

Read the paper · More papers on PaperTik