Screen Version
School of Computer Science & Engineering
University of New South Wales

 Advanced Operating Systems 
 COMP9242 2002/S2 
next up previous
Next: Password capabilities Up: 03-caps Previous: Partitioned Capabilities

Subsections

Sparse Capabilities

Basic idea similar to encryption:

Example: Signature capabilities


``First Migration Scheme''[GL79], designed to allow migration of tagged capabilities in distributed systems.

cap-m1
+
tamper proof via encryption with secret kernel key
+
can freely be passed around
-
need to decrypt on each validation
-
users do not know which object capability refers to



``Second Migration Scheme''[GL79]

cap-m2

Object ID visible, yet still tamper proof.

Amoeba's capabilities

cap-a1

Appropriate for user-level servers [MT86].

Properties of Amoeba capabilities


Amoeba rights restriction

cap-a2

Improved version (not implemented)

Server authentication: F-boxes


next up previous
Next: Password capabilities Up: 03-caps Previous: Partitioned Capabilities
Gernot Heiser 2002-08-15