A VMM security kernel for the VAX architecture
- 1 January 1990
- conference paper
- Published by Institute of Electrical and Electronics Engineers (IEEE)
Abstract
The development of a virtual-machine monitor (VMM) security kernel for the VAX architecture is described. Particular focus is on how the system's hardware, microcode, and software are aimed at meeting A1-level security requirements while maintaining the standard interfaces and applications of the VMS and ULTRIX-32 operating systems. The VAX security kernel supports multiple concurrent virtual machines on a single VAX system, providing isolation and controlled sharing of sensitive data. Rigorous engineering standards were applied during development to comply with the assurance requirements for verification and configuration management. The VAX security kernel was developed with a heavy emphasis on performance and on system management tools. The kernel performs sufficiently well that all of its development can be now carried out in virtual machines running on the kernel itself, rather than in a conventional time-sharing system.Keywords
This publication has 11 references indexed in Scilit:
- The auditing facility for a VMM security kernelPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1990
- KVM/370 in RetrospectPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1984
- Scomp: A Solution to the Multilevel Security ProblemComputer, 1983
- A Practical Approach to Identifying Storage and Timing ChannelsPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1982
- The Structure of a Security Kernel for the Z8000 MultiprocessorPublished by Institute of Electrical and Electronics Engineers (IEEE) ,1981
- Synchronization with eventcounts and sequencersCommunications of the ACM, 1979
- The PDP-11 virtual machine architectureACM SIGOPS Operating Systems Review, 1975
- Formal requirements for virtualizable third generation architecturesCommunications of the ACM, 1974
- Design for Multics Security EnhancementsPublished by Defense Technical Information Center (DTIC) ,1973
- The structure of the “THE”-multiprogramming systemCommunications of the ACM, 1968