Re: To Jonathan [readonly?]

Pierre THIERRY <[email protected]>
Newsgroups gmane.os.hurd.l4
Message-ID <[email protected]>
Scribit Anton Tagunov dies 09/01/2007 hora 05:38:
> Can we design capabilities in such a way that reading a memory region
> holding them would give no benefit to the reader?

Not per se.

> Can they somehow be "tied" to the process holding them?
> 
> For instance the process would have an int key known only to kernel
> and the capability would include a XOR of main part of it with this
> key?

You can achieve this reliably with the help of a reference monitor, if I
understand correctly your goal.

There is a very short and clear description of it's principle in some
documentation about KeyKOS:

http://www.cis.upenn.edu/~KeyKOS/Security.html

> P.S. Sorry for spawning 2 threads of discussion.  I think both of my
> "To Jonathan" threads are promising avenues for thinking.

You sould probably try to use more specific subjects for your emails.

Quickly,
Pierre
-- 
[email protected]
OpenPGP 0xD9D50D8A

_______________________________________________
L4-hurd mailing list
[email protected]
http://lists.gnu.org/mailman/listinfo/l4-hurd
signature.asc (application/pgp-signature, 189 B)
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.6 (GNU/Linux)

iD8DBQFFowrjxe13INnVDYoRAokEAJ9S1K3QI03F6H7Y9g9ZPdq7BIRGhACgtXvk
hkEKkpWwJmNaBKQczp2yo1w=
=Poep
-----END PGP SIGNATURE-----
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.