Title
Flexible Access Control using IPC Redirection
Abstract
We present a mechanism for inter-process communication (IPC) redirection that enables efficient and flexible access control for micro-kernel systems. In such systems, services are implemented at user-level, so IPC is the only means of communication between them. Thus, the system must be able to mediate IPCs to enforce its access control policy. Such mediation must enable enforcement of security policy with as little performance overhead as possible, but current mechanisms either: (1) place significant access control functionality in the kernel which increases IPC cost or (2) are static and require more IPCs than necessary to enforce access control. We define an IPC redirection mechanism that makes two improvements: (1) it removes the management of redirection policy from the kernel, so access control enforcement can be implemented outside the kernel and (2) it separates the notion of who controls the redirection policy from the redirections themselves, so redirections can be configured arbitrarily and dynamically. In this paper, we define our redirection mechanism, demonstrate its use, and examine possible, efficient implementations.
Year
DOI
Venue
1999
10.1109/HOTOS.1999.798399
Workshop on Hot Topics in Operating Systems
Keywords
Field
DocType
redirection policy,significant access control functionality,ipc cost,access control,access control enforcement,ipc redirection,security policy,ipc redirection mechanism,access control policy,flexible access control,redirection mechanism,inter process communication,authorization,authorisation,message passing,control systems,security,read only memory,operating systems,ipc,kernel
Kernel (linear algebra),Computer security,Computer science,Authorization,Implementation,Access control,Enforcement,Security policy,Message passing
Conference
ISBN
Citations 
PageRank 
0-7695-0237-7
7
1.10
References 
Authors
4
5
Name
Order
Citations
PageRank
T Jaeger12635255.67
K. Elphinstone2119065.76
Jochen Liedtke365385.61
Vsevolod Panteleenko4264.40
Yoonho Park535035.57