- 1、原创力文档(book118)网站文档一经付费(服务费),不意味着购买了该文档的版权,仅供个人/单位学习、研究之用,不得用于商业用途,未经授权,严禁复制、发行、汇编、翻译或者网络传播等,侵权必究。。
- 2、本站所有内容均由合作方或网友上传,本站不对文档的完整性、权威性及其观点立场正确性做任何保证或承诺!文档内容仅供研究参考,付费前请自行鉴别。如您付费,意味着您自己接受本站规则且自行承担风险,本站不退款、不进行额外附加服务;查看《如何避免下载的几个坑》。如果您已付费下载过本站文档,您可以点击 这里二次下载。
- 3、如文档侵犯商业秘密、侵犯著作权、侵犯人身权等,请点击“版权申诉”(推荐),也可以打举报电话:400-050-0827(电话支持时间:9:00-18:30)。
查看更多
Module 18 Protection.ppt
Module 18: Protection Goals of Protection Domain of Protection Access Matrix Implementation of Access Matrix Revocation of Access Rights Capability-Based Systems Language-Based Protection Protection Operating system consists of a collection of objects, hardware or software Each object has a unique name and can be accessed through a well-defined set of operations. Protection problem - ensure that each object is accessed correctly and only by those processes that are allowed to do so. Domain Structure Access-right = object-name, rights-setwhere rights-set is a subset of all valid operations that can be performed on the object. Domain = set of access-rights Domain Implementation (UNIX) System consists of 2 domains: User Supervisor UNIX Domain = user-id Domain switch accomplished via file system. Each file has associated with it a domain bit (setuid bit). When file is executed and setuid = on, then user-id is set to owner of the file being executed. When execution completes user-id is reset. Domain Implementation (Multics) Let Di and Dj be any two domain rings. If j I ? Di ? Dj Access Matrix View protection as a matrix (access matrix) Rows represent domains Columns represent objects Access(i, j) is the set of operations that a process executing in Domaini can invoke on Objectj Access Matrix Use of Access Matrix If a process in Domain Di tries to do “op” on object Oj, then “op” must be in the access matrix. Can be expanded to dynamic protection. Operations to add, delete access rights. Special access rights: owner of Oi copy op from Oi to Oj control – Di can modify Dj access rights transfer – switch from domain Di to Dj Use of Access Matrix (Cont.) Access matrix design separates mechanism from policy. Mechanism Operating system provides access-matrix + rules. If ensures that the matrix is only manipulated by authorized agents and that rules are strictly enforced. Policy User dictates policy. Who can access what object and in what mode. Implemen
您可能关注的文档
- FGCS MeetingDenver, ColoradoJune 13, 2007.ppt
- FIDIC 2005 BeijingWorkshop 14.ppt
- Figure 13. Significant growing season correlations for segment .ppt
- Flow Cytometry (FCM).ppt
- Food Security in Complex Emergencies.ppt
- FOODWORLD INDIA 2008November 13 – 14, 2008, Mumbai.ppt
- Footstep Planning Among Obstacles for Biped Robots.ppt
- Forensics Tripwire Project Report.ppt
- Formatting Scientific Documents.ppt
- Fundamentals of air Pollution – Air Quality Management.ppt
- 2025年氢能产业技术创新中心建设与运营模式研究报告.docx
- 情感化表达赋能2025年智能语音合成技术在智能电网行业的创新实践.docx
- 2025年电网升级核心——智能电网柔性直流输电技术创新报告.docx
- 2025年智能仓储机器人路径避障技术创新,引领仓储物流行业智能化潮流.docx
- 2025年电网稳定控制技术创新与电力系统稳定运行保障.docx
- 八大特殊作业安全知识题目测试卷附答案.docx
- 2025年机器人协作作业控制技术在环保设备制造中的应用研究.docx
- 2025年锂电池正极材料表面包覆技术在储能系统中的应用.docx
- 2021-2025年高考生物试题知识点分类汇编之群落及其演替(三).pdf
- 2025年度弹性备考计划(备考技巧).pptx
最近下载
- 2024年琼海市菜篮子市场开发有限责任公司招聘真题 .pdf VIP
- 2025海南琼海市菜篮子市场开发有限责任公司招聘10人(第1号)备考练习题库及答案解析.docx VIP
- 2025海南琼海市菜篮子市场开发有限责任公司招聘10人(第1号)笔试备考题库及答案解析.docx VIP
- 2025海南琼海市菜篮子市场开发有限责任公司招聘10人(第1号)笔试参考题库附答案解析.docx VIP
- GB∕T 39758-2021 无障碍设计 盲文在标志、设备和器具上的应用.pdf
- 2025海南琼海市菜篮子市场开发有限责任公司招聘10人(第1号)笔试模拟试题及答案解析.docx VIP
- 法哲学原理第二讲导论-公开课件.ppt VIP
- 法哲学原理课件.pptx
- 轻型卒中临床诊疗中国专家共识(2024版).pptx VIP
- 广告语言的语用分析.docx VIP
文档评论(0)