[Top][All Lists]
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Amoeba's approach to capabilities
From: |
Ludovic Courtès |
Subject: |
Amoeba's approach to capabilities |
Date: |
Fri, 07 Oct 2005 14:02:43 +0200 |
User-agent: |
Gnus/5.110004 (No Gnus v0.4) Emacs/21.4 (gnu/linux) |
Hi Bas,
Bas Wijnen <address@hidden> writes:
> I think anything protected by sparsity is fundamentally flawed and
> unacceptable, especially for something as critical as the kernel.
I think I understand what you mean. The problem is that I don't
understand how it relates to Amoeba's capability implementation,
summarized like this:
A capability typically consists of four fields as illustrated in Fig. 2.
1. The put-port of the server that manages the object
2. An object number meaningful only to the server managing the object
3. A rights field, containing a 1 bit for each permitted operation
4. A random number, for protecting each object
(1) is a globally-unique identifier returned by the kernel, (2) is
computed by the server managing the object, and (4) is computed using a
secret random number known only to the server (the random number itself
is not part of the capability, unlike one might think from the above
description).
How _this_ is protected by sparsity? Perhaps this is just a matter of
vocabulary. However, my understanding of this is that capabilities are
computed using information known only to the server implementing them,
which makes it "hard" to forge new capabilities.
Maybe the whole difference is here: I consider that "hard" means "next
to impossible" (if you know that a given server implements an object on
a given port, you still have to guess 80 bits, which is not something
that can reasonably be performed by brute force), but you seem to
believe that it's not that hard. Is that correct?
Thanks,
Ludovic.
- Re: problems with hierarchy: L4 pagers, (continued)
Re: capability interface for idl4, Ludovic Courtès, 2005/10/06
- Re: capability interface for idl4, Bas Wijnen, 2005/10/07
- Re: capability interface for idl4, Simon Nieuviarts, 2005/10/07
- Re: capability interface for idl4, Jonathan S. Shapiro, 2005/10/07
- Re: capability interface for idl4, Simon Nieuviarts, 2005/10/07
- Re: capability interface for idl4, Jonathan S. Shapiro, 2005/10/07
Amoeba's approach to capabilities,
Ludovic Courtès <=
Re: Amoeba's approach to capabilities, Jonathan S. Shapiro, 2005/10/07
Re: Amoeba's approach to capabilities, Ludovic Courtès, 2005/10/07
Re: Amoeba's approach to capabilities, Jonathan S. Shapiro, 2005/10/07
Re: Amoeba's approach to capabilities, Ludovic Courtès, 2005/10/10
Re: Amoeba's approach to capabilities, Jonathan S. Shapiro, 2005/10/10
[OT] Trusted hardware, Ludovic Courtès, 2005/10/10
Re: [OT] Trusted hardware, Jonathan S. Shapiro, 2005/10/10
Re: [OT] Trusted hardware, Udo A. Steinberg, 2005/10/10
Re: [OT] Trusted hardware, Jonathan S. Shapiro, 2005/10/10
Re: [OT] Trusted hardware, Udo A. Steinberg, 2005/10/10