Flexible Access Control using IPC Redirection

نویسندگان

  • Trent Jaeger
  • Kevin Elphinstone
  • Jochen Liedtke
  • Vsevolod Panteleenko
  • Yoonho Park
چکیده

We present a mechanism for inter-process communication (IPC) redirection that enables efficient and flexible access control for micro-kernel systems. In such systems, services are implemented at user-level, so IPC is the only means of communication between them. Thus, the system must be able to mediate IPCs to enforce its access control policy. Such mediation must enable enforcement of security policy with as little performance overhead as possible, but current mechanisms either: (1) place significant access control functionality in the kernel which increases IPC cost or (2) are static and require more IPCs than necessary to enforce access control. We define an IPC redirection mechanism that makes two improvements: (1) it removes the management of redirection policy from the kernel, so access control enforcement can be implemented outside the kernel and (2) it separates the notion of who controls the redirection policy from the redirections themselves, so redirections can be configured arbitrarily and dynamically. In this paper, we define our redirection mechanism, demonstrate its use, and examine possible, efficient implementations.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Ubiquitous Redirection as Access Control Response

Rule-based access control mechanisms, network firewalls and application input validation all serve to enforce security policy. When violating the acceptable conditions these defenses mandate, an unauthorized requester is generally turned away. We make an argument for a modification to traditional access limitation through redirection and deceptive completion across many layers of data communica...

متن کامل

A semantic-aware role-based access control model for pervasive computing environments

Access control in open and dynamic Pervasive Computing Environments (PCEs) is a very complex mechanism and encompasses various new requirements. In fact, in such environments, context information should be used in access control decision process; however, it is not applicable to gather all context information completely and accurately all the time. Thus, a suitable access control model for PCEs...

متن کامل

Intentio Ex Machina: Android Intent Access Control via an Extensible Application Hook

Android's intent framework serves as the primary method for interprocess communication (IPC) among apps. The increased volume of intent IPC present in Android devices, coupled with intent's ability to implicitly nd valid receivers for IPC, bring about new security challenges. We propose Intentio Ex Machina (IEM), an access control solution for Android intent security. IEM separates the logic fo...

متن کامل

A Technique for User Specific Request Redirection in a Content Delivery Network

This paper presents a technique for user specific request redirection for personalizing responses to user requests in Content Delivery Networks. Current schemes for redirecting user requests to a content delivery server in a Content Delivery Network are either based on the authoritative DNS model or the URL rewrite model. The authoritative DNS model is not flexible to support user specific redi...

متن کامل

Personalized Redirection of Communication

Universal access to information and data is an important goal of current research. Previously different forms of information and data, captured by different devices or held on different systems, were isolated. However, the development of different networks has created the “glue” by which the overall goal of universal access can be achieved. Another important goal is the development of personali...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 1999