发明名称 Efficient security kernel for the 80960 extended architecture
摘要 A computer security mechanism including an access control table specifying the predetermined access rights of each of a plurality of predetermined security subjects relative to predetermined security objects; a collection of mutually exclusive execution domains for each of the security subjects so that the executing processes of a security subject can only directly access code and data contained within the collection of domains of such security subject; a collection of mutually exclusive domains for a plurality of security object type managers, each of which is the sole owner of the right and ability to create and control access to security objects of a predetermined type, such that the only interaction between the execution environment of a security subject and the execution environment of another security subject is through operations on security objects performed through the services of the type managers; an object table for storing entries identifying the nature and location of security objects; and unforgeable access descriptors created by the security type managers by reference to the access control table for validation of access rights and utilized to allow access by security subjects to security objects via the object table, each access descriptor containing an index to the object table entry for the associated security object and identification of the access rights of the security subject with which the access descriptor is associated, whereby use of an access descriptor allows for efficient validation and mechanization of a requested access.
申请公布号 US5504814(A) 申请公布日期 1996.04.02
申请号 US19940185728 申请日期 1994.01.24
申请人 HUGHES AIRCRAFT COMPANY 发明人 MIYAHARA, GARY K.
分类号 G06F1/00;G06F21/00;(IPC1-7):H04L9/00 主分类号 G06F1/00
代理机构 代理人
主权项
地址