Demonstration venue · read-only. Every page can be browsed; the buttons that would change it are switched off. Create an account to run TaxoReview on your own data.

G.-L. Grenier

dblp:86/34 · DBLP profile ↗
← Back
1ranked-venue papers
1as first author
0since 2021 · last 1989
—ORCID · none

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 first-author

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Software engineering, system software, and programming languages
1 paper
Operating systems · 100%
Network and information security
1 paper
Systems and software security · 100%

Topics — the 4 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Operating systems › operating system design
policy-mechanism separation
0.011989
Policy vs. Mechanism in the Secure TUNIS Operating System · S&P 1989
Operating systems › system security › operating system security
secure operating system
0.011989
Policy vs. Mechanism in the Secure TUNIS Operating System · S&P 1989
Operating systems › system security › operating system security
trusted computing base
0.011989
Policy vs. Mechanism in the Secure TUNIS Operating System · S&P 1989
Systems and software security › operating system security
security kernel
0.011989
Policy vs. Mechanism in the Secure TUNIS Operating System · S&P 1989

Methods — techniques the papers use, named apart from their topics

formal verification · 0.0
YearPublicationVenuePosition
1989 Policy vs. Mechanism in the Secure TUNIS Operating System
abstract
The trusted computing base (TCB) of a secure operating system can have its security policy enforced by a small, provably correct security manager. The design of the Secure TUNIS (Toronto University system) operating system divides security concerns into policy (implemented by its security manager) and mechanism (implemented by the rest of the operating system). It is shown that this separation is a key concept in allowing Secure TUNIS to be validated, due to the isolation of security critical code and data in a small module. This design provides the basis of an implementation of a POSIX (Unix) kernel that can be certified at security levels of B3 and above. The security policy, as implemented by Secure TUNIS, is given.>
G.-L. Grenier, Richard C. Holt, M. Funkenhauser
S&P1