Providing policy control over object operations in a mach based system
Spencer E. Minear · 1995
In both secure and safety-critical systems it is desirable to have a very clear relationship between the system's mandatory security pol-icy and its proven operational semantics. This relationship is made clearer if the system ar-chitecture provides strong separation between the enforcement mechanisms and the policy decisions, and if the policy decision software is clearly identi®able in the system's architec-ture. This paper describes a prototype Unix sys-tem based on Mach which provides manda-tory control over all kernel-supported opera-tions. The prototype work modi®ed the Mach kernel by extending its limited control mech-anisms based on the Mach port right. The control extensions allow a mandatory control policy to specify control over not only access to an object via a port right, but over the indi-vidual services supported by the object. The mandatory security policy is implemented in an external Security Server which provides very strong separation between policy enforce-ment and policy decision software. This makes it possible to support a wide range of security policies with no change to the kernel or appli-cations. 1