Design of the EROS Trusted Window System (2004)
<p>Abstract: "Window systems are the primary mediator of user input and output in modern computing systems. They are also a commonly used interprocess communication mechanism. As a result, they play a key role in the enforcement of security policies and the protection of sensitive information. A user typing a password or passphrase must be assured that it is disclosed exclusively to the intended program. In highly secure systems, global policies concerning informaiton flow restrictions must be honored. Most window systems today, including X11 and Microsoft Windows, have carried forward the presumptive trust assumptions of the Xerox Alto from which they were conceptually derived. These assumptions are inappropriate for modern, computing environments.</p> <p>In this paper, we present the design of a new trusted window system for the EROS capability-based operating system. The EROS Window System (EWS) provides robust traceability of user volition and is capable (with extension) of enforcing mandatory access controls. The entire implementation of EWS is les than 4,500 lines, which is a factor of ten smaller than previous trusted window systems such as Trusted X, and well within the range of what can feasibly be evaluated for high assurance."</p>
Read the full article at srl.cs.jhu.edu →
Related stories
- Hacker News · 1 points · 5 days ago
- How to Sync a Design System with Claude Designnitayneeman.comHacker News · 1 points · 3 days ago
- Hacker News · 1 points · 7 days ago
- Forging 1024-bit RSA signatures in nearly SNFS timeeprint.iacr.orgLobsters · 7 points · 9 days ago
- Ars Technica · 0 points · 11 days ago
- System Designrye.wentcloud.comLobsters · 1 points · 10 months ago