Screen Version
School of Computer Science & Engineering
University of New South Wales

 Advanced Operating Systems 
 COMP9242 2002/S2 
next up previous
Next: Protection Domain Manipulation: Up: 12-mungi Previous: Discretionary Access Control in

Protected Procedure Calls


  • Object can have (PDX) type:
    • has PDX capabilities,
    • registered set of entry points,
    • an associated PDX clist.

  • Owner's APD changes for the duration of the call

  • Allows secure invocation of an object in a PD different from caller's

  • Discretionary access control validates entry points and invocation right

PDX



Gernot Heiser 2002-10-24