• DocumentCode
    2517749
  • Title

    Less is More -- A Secure Microkernel-Based Operating System

  • Author

    Lackorzynski, Adam ; Warg, Alexander

  • Author_Institution
    Oper. Syst. Group, Tech. Univ., Dresden, Germany
  • fYear
    2011
  • fDate
    6-6 July 2011
  • Firstpage
    103
  • Lastpage
    106
  • Abstract
    Micro kernel-based systems have gone through a steady development and current implementations have reached a new level of functionality. While the first systems started with the fundamental idea, latest systems offer a wide range of features. Experience showed that the most important feature, a secure system architecture, cannot be retrofitted into the system at a later stage but must be the core of it. A recent redesign of the architecture introduced capability-based access control on objects as the core mechanism upon which any functionality is built. Features of current systems include support for multi-cores, portability across different architectures, real-time execution and virtualization. Micro kernels are built with the goal of being sufficiently generic to host multiple subsystems with differing isolation and security requirements. Although putting functionality into many different components sounds appealing, it is a severe burden on the implementation side. It must be possible to reuse existing software, and with the help of virtualization techniques it is possible to find a better split of components. This way systems with a small trusted computing base can be built without reimple menting existing functionality. One of the open questions is how such a split must be designed and can be implemented and offered in a generic way, given all the options current modern systems offer. In this paper we report on the current state of the operating system developed at TU Dresden, focusing on its security mechanisms, and possible future direction that we envision with the ongoing changes in the hardware and software world.
  • Keywords
    authorisation; operating system kernels; virtualisation; capability-based access control; real-time execution; secure microkernel-based operating system; secure system architecture; security requirements; virtualization; Computer architecture; Conferences; Kernel; Linux; Real time systems; Security; design; operating systems; security; virtualization;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    SysSec Workshop (SysSec), 2011 First
  • Conference_Location
    Amsterdam
  • Print_ISBN
    978-1-4577-1528-0
  • Type

    conf

  • DOI
    10.1109/SysSec.2011.11
  • Filename
    6092777