|
|
|
Design of a Micro-kernel Based Secure System ArchitectureJianjun ShenThe 7th IEEE Information Assurance Workshop (IAWorkshop 2006)West Point, New York, USA, June 21-23, 2006
AbstractWe describe the Trium secure system architecture. It is based on the Fiasco microkernel – an implementation of L4 microkernel interface. Compared to previous work on microkernel based secure systems, Trium tries to minimize the trusted computing base (TCB) of a secure system by moving most functions of an operating system out of the TCB, and it emphasizes on the reuse of legacy software. Compared to conventional virtual machine monitor solutions, Trium needs not to add complexities to the TCB for virtualization. We also try to achieve better isolation, privilege control and flexible configuration of system components, taking advantage of the specific features of the L4 microkernel as a second generation microkernel. An example application of Trium in multi-level secure networks is shown.
|
|