DocumentCode :
2529840
Title :
Distributed Secure Systems: Then and Now
Author :
Randell, Brian ; Rushby, John
Author_Institution :
Univ. of Newcastle upon Tyne, Newcastle upon Tyne
fYear :
2007
fDate :
10-14 Dec. 2007
Firstpage :
177
Lastpage :
199
Abstract :
The early 1980s saw the development of some rather sophisticated distributed systems. These were not merely networked file systems: rather, using remote procedure calls, hierarchical naming, and what would now be called middleware, they allowed a collection of systems to operate as a coherent whole. One such system in particular was developed at Newcastle that allowed pre-existing applications and (Unix) systems to be used, completely unchanged, as components of an apparently standard large (multiprocessor) Unix system. The distributed secure system (DSS) described in our 1983 paper proposed a new way to construct secure systems by exploiting the design freedom created by this form of distributed computing. The DSS separated the security concerns of policy enforcement from those due to resource sharing and used a variety of mechanisms (dedicated components, cryptography, periods processing, separation kernels) to manage resource sharing in ways that were simpler than before. In this retrospective, we provide the full original text of our DSS paper, prefaced by an introductory discussion of the DSS in the context of its time, and followed by an account of the subsequent implementation and deployment of an industrial prototype of DSS, and a description of its modern interpretation in the form of the MILS architecture. We conclude by outlining current opportunities and challenges presented by this approach to security.
Keywords :
distributed processing; security of data; distributed secure system; resource sharing; Cryptography; Decision support systems; Distributed computing; File systems; Kernel; Middleware; Prototypes; Resource management; Security; Standards development;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Computer Security Applications Conference, 2007. ACSAC 2007. Twenty-Third Annual
Conference_Location :
Miami Beach, FL
ISSN :
1063-9527
Print_ISBN :
978-0-7695-3060-4
Type :
conf
DOI :
10.1109/ACSAC.2007.48
Filename :
4412988
Link To Document :
بازگشت