Security Kernel
Roger R. Schell, Donald L. Brinkley · Encyclopedia of Software Engineering · 2002
Abstract Information is a valuable and vital asset that requires security against unwanted modification and disclosure. The security kernel concept provides highly effective controls, internal to a computer system, to mediate access of people to information, thereby preventing unwanted modification and disclosure. The need for such internal security controls has grown with the need to share computing resources and information. The security kernel is designed to meet three engineering principles: (1) completeness‐all accesses to information must go through the kernel; (2) isolation—the kernel must be protected from unauthorized alteration; and (3) verifiability—the kernel must be small, well‐structured, and understandable enough to be completely analyzed and verified to perform its functions properly.