›› 2008, Vol. 25 ›› Issue (4): 538-548.DOI: 10.7523/j.issn.2095-6134.2008.4.016
• 论文 • Previous Articles Next Articles
Gong Yu-chang, Tang Ling, Zhang Ye, Jia Yong-quan
Received:
Revised:
Online:
Abstract: Considering the limitations of current space isolation technique, a new security mechanism adopting function isolation is proposed in this paper. With the mechanism more delicate granularity of function can be used and different execution domains corresponding to different function requests may be isolated each other, so the safety of operating system can be improved. In the paper the principle and algorithm for function division are introduced in detail, and two kinds of isolating mechanisms PFI and ASFI are presented. Experiment results show that the overhead of function isolation wouldn’t reduce the system efficiency notably.
Key words: safety critical operating system, spatial isolation, function isolation, function dividing
Gong Yu-chang, Tang Ling, Zhang Ye, Jia Yong-quan. The function isolation mechanism in secure operating system[J]. , 2008, 25(4): 538-548.
0 / / Recommend
Add to citation manager EndNote|Ris|BibTeX
URL: http://journal.ucas.ac.cn/EN/10.7523/j.issn.2095-6134.2008.4.016
http://journal.ucas.ac.cn/EN/Y2008/V25/I4/538