EDBT 2026 Demo / reviewers in the wild / expert
Cynthia E. Irvine
dblp:31/5391
· DBLP profile ↗
32ranked-venue papers
9as first author
1since 2021 · last 2021
—ORCID · none
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 25 · 7 first-authorSystems, architecture and hardware · 4 · 1 first-authorHuman-computer interaction and ubiquitous computing · 2 · 1 since 2021Software engineering, systems software and programming languages · 1 · 1 first-authorGraphics, computer vision, multimedia, augmented reality and games · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer graphics and multimedia
1 paper |
Virtual and augmented reality · 50% Visualization and visual analytics · 50% | |
| Network and information security
8 papers |
Hardware security and side channels · 53% Systems and software security · 36% Privacy and data protection · 5% | |
| Computer architecture, parallel and distributed computing, and storage systems
5 papers |
Reconfigurable computing and FPGAs · 45% Integrated circuit design · 31% Embedded and real-time systems · 14% | |
| Human-computer interaction and pervasive computing
1 paper |
Collaborative and social computing · 100% | |
| Software engineering, system software, and programming languages
3 papers |
Operating systems · 100% |
Topics — the 20 heaviest of 25, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Visualization and visual analytics
graph visualization |
0.4 | 1 | 2020 | Peering Under the Hull: Enhanced Decision Making via an Augmented Environment · VR 2020 |
Hardware security and side channels › hardware obfuscation
split manufacturing |
0.2 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Systems and software security
supply chain security |
0.2 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Collaborative and social computing
team collaboration |
0.1 | 1 | 2020 | Peering Under the Hull: Enhanced Decision Making via an Augmented Environment · VR 2020 |
Hardware security and side channels › trusted execution environments
hardware isolation |
0.1 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Hardware security and side channels › trusted execution environments
trusted hardware |
0.1 | 1 | 2007 | Trusted Hardware: Can It Be Trustworthy? · DAC 2007 |
Reconfigurable computing and FPGAs
FPGA security |
0.1 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Operating systems › system security
operating system security |
0.1 | 3 | 1999 | A Multi-Threading Architecture for Multilevel Secure Transaction Processing · S&P 1999 Security in Innovative New Operating Systems · S&P 1997 A multilevel file system for high assurance · S&P 1995 |
Integrated circuit design
3d integration |
0.0 | 1 | 2013 | A 3-D Split Manufacturing Approach to Trustworthy System Development · IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. 2013 |
Cryptographic protocols and secure computation › key management
key storage |
0.0 | 1 | 2007 | Trusted Hardware: Can It Be Trustworthy? · DAC 2007 |
Embedded and real-time systems
reconfigurable embedded systems |
0.0 | 1 | 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based Systems · S&P 2007 |
Computing education › computer science curriculum
cybersecurity education |
0.0 | 1 | 1996 | Goals for Computer Security Education · S&P 1996 |
Operating systems › resource management › storage management
file systems |
0.0 | 1 | 1995 | A multilevel file system for high assurance · S&P 1995 |
Authentication and access control
access control |
0.0 | 2 | 1995 | A Formal Model for UNIX Setuid · S&P 1989 A multilevel file system for high assurance · S&P 1995 |
Processor architecture and microarchitecture › instruction set architecture
virtualization support |
0.0 | 1 | 2000 | Analysis of the Intel Pentium's Ability to Support a Secure Virtual Machine Monitor · USENIX Security Symposium 2000 |
Authentication and access control › access control models
discretionary access control |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security
operating system security |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security › operating system security
setuid |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Systems and software security › trusted computing
trusted computing base |
0.0 | 1 | 1995 | A multilevel file system for high assurance · S&P 1995 |
Systems and software security
formal security model |
0.0 | 1 | 1989 | A Formal Model for UNIX Setuid · S&P 1989 |
Methods — techniques the papers use, named apart from their topics
usability study · 0.9simulator sickness questionnaire · 0.93d model visualization · 0.93d integration · 0.23-d integration · 0.2interconnect traceability · 0.1configuration scrubbing · 0.1scheduling policy design · 0.0hardware-assisted process isolation · 0.0security policy enforcement analysis · 0.0case study analysis · 0.0formal modeling · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2021 | Labtainers Cyber Exercises: Building and Deploying Fully Provisioned Cyber Labs that Run on a LaptopabstractLabtainers are fully provisioned Linux-based computer science lab exercises with an initial emphasis on cybersecurity. Consistent lab execution environments and automated provisioning are provided by Docker containers. With over 50 lab exercises including multi-component networks that all run on a modestly performing laptop computer., Labtainers supports exploratory learning for both local and remote learners. They offer automated assessment of student lab activity and progress as well as individualized lab exercises to discourage sharing solutions. Free and open at: https://nps.edu/web/c3o/labtainers, Labtainers is distributed as a single virtual machine for either VirtualBox or VMWare. On an exercise-specific basis, the framework leverages Docker containers to instantiate one or more networked computers within that single VM. This hands-on workshop covers the basics of creating Labtainer-based labs, whether for security, networking, operating systems, or other computer science classes. The workshop also introduces how this lab framework helps remove three barriers to CS lab exercises: 1) administrative setup and resulting divergent behavior between student environments; 2) sharing of solutions amongst students; 3) assessing student work. Participants should have a computer running either VMWare or VirtualBox, with the Labtainers VM appliance installed. Cynthia E. Irvine |
SIGCSE | 2 |
| 2020 | Peering Under the Hull: Enhanced Decision Making via an Augmented EnvironmentabstractDaily operation and management of complex systems typically include multiple working sessions during which a team presents a set of information and discusses issues relevant to their decision making. A complex set of operational technology (OT) networks installed onboard a Navy ship is an example of such a system. A crew’s ability to effectively communicate OT networks status to the ship commander, visualize, and discuss the options available in a given situation, has a significant impact on mission success. While the complexity of contemporary OT networks has dramatically increased, visualization tools have witnessed little improvement over several decades—they include sets of two-dimensional blueprints that are inherently hard to understand and conceptualize as three-dimensional (3D) information. To address this problem, we designed and implemented an augmented reality (AR) system that allowed a small team to visualize a 3D model of the ship with details of its computer networks. We recruited 30 individuals familiar with network management tasks central to our study and examined the usability of the tool on a set of real-world scenarios focused on network management. Analysis of objective and subjective data suggested that there was a general agreement among the participants that AR portrayal of the network was very supportive of their understanding of the physical-to-logical relationship within the network and that it fostered constructive collaboration among the team members. The reported levels of discomfort associated with oculomotor symptoms made the highest contribution to the total Simulator Sickness Questionnaire score; we believe that those symptoms should be given more attention in future studies with AR setups. The results provided in this empirical study offer early insights into the benefits and challenges of AR approaches applied to the decision making of small teams in high stakes scenarios and real-world situations. Matthew Timmerman, Amela Sadagic, Cynthia E. Irvine |
VR | 3 |
| 2013 | A 3-D Split Manufacturing Approach to Trustworthy System DevelopmentabstractSecuring the supply chain of integrated circuits is of utmost importance to computer security. In addition to counterfeit microelectronics, the theft or malicious modification of designs in the foundry can result in catastrophic damage to critical systems and large projects. In this letter, we describe a 3-D architecture that splits a design into two separate tiers: one tier that contains critical security functions is manufactured in a trusted foundry; another tier is manufactured in an unsecured foundry. We argue that a split manufacturing approach to hardware trust based on 3-D integration is viable and provides several advantages over other approaches. Jonathan Valamehr, Timothy Sherwood, Ryan Kastner, David Marangoni-Simonsen, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin |
IEEE Trans. Comput. Aided Des. Integr. Circuits Syst. | 6 |
| 2010 | Hardware assistance for trustworthy systems through 3-D integrationabstractHardware resources are abundant; state-of-the-art processors have over one billion transistors. Yet for a variety of reasons, specialized hardware functions for high assurance processing are seldom (i.e., a couple of features per vendor over twenty years) integrated into these commodity processors, despite a small flurry of late (e.g., ARM TrustZone, Intel VT-x/VT-d and AMD-V/AMD-Vi, Intel TXT and AMD SVM, and Intel AES-NI). Furthermore, as chips increase in complexity, trustworthy processing of sensitive information can become increasingly difficult to achieve due to extensive on-chip resource sharing and the lack of corresponding protection mechanisms. In this paper, we introduce a method to enhance the security of commodity integrated circuits, using minor modifications, in conjunction with a separate integrated circuit that can provide monitoring, access control, and other useful security functions. We introduce a new architecture using a separate control plane, stacked using 3D integration, that allows for the function and economics of specialized security mechanisms, not available from a co-processor alone, to be integrated with the underlying commodity computing hardware. We first describe a general methodology to modify the host computation plane by attaching an optional control plane using 3-D integration. In a developed example we show how this approach can increase system trustworthiness, through mitigating the cache-based side channel problem by routing signals from the computation plane through a cache monitor in the 3-D control plane. We show that the overhead of our example application, in terms of area, delay and performance impact, is negligible. Jonathan Valamehr, Mohit Tiwari, Timothy Sherwood, Ryan Kastner, Ted Huffmire, Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 6 |
| 2010 | Security Primitives for Reconfigurable Hardware-Based SystemsabstractComputing systems designed using reconfigurable hardware are increasingly composed using a number of different Intellectual Property (IP) cores, which are often provided by third-party vendors that may have different levels of trust. Unlike traditional software where hardware resources are mediated using an operating system, IP cores have fine-grain control over the underlying reconfigurable hardware. To address this problem, the embedded systems community requires novel security primitives that address the realities of modern reconfigurable hardware. In this work, we propose security primitives using ideas centered around the notion of “moats and drawbridges.” The primitives encompass four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet they map cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads of the security techniques on modern FPGA architectures across a number of different applications. Ted Huffmire, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner |
ACM Trans. Reconfigurable Technol. Syst. | 4 |
| 2008 | An Ontological Approach to Secure MANET ManagementabstractMobile ad hoc networks (MANETs) rely on dynamic configuration decisions to efficiently operate in a rapidly changing environment of limited resources. The ability of a MANET to make decisions that accurately reflect the real environment depends on the quality of the input to those decisions. However, collecting and processing of the multitudinous factors related to the operation of a MANET is a significant challenge. Equally significant in current approaches to dynamic MANET management is the lack of consideration given to security factors. We show how our ontology of MANET attributes including device security and performance characteristics can be leveraged to efficiently and effectively make dynamic configuration decisions for managing a MANET. Mark E. Orwat, Timothy E. Levin, Cynthia E. Irvine |
ARES | 3 |
| 2007 | Toward a Medium-Robustness Separation Kernel Protection ProfileabstractA protection profile for high-robustness separation kernels has recently been validated and several implementations are under development. However, medium-robustness separation kernel development efforts have no protection profile, although the US Government has published guidance for authoring such a profile. As a step toward a protection profile, a set of security requirements for medium-robustness separation kernels is proposed. These requirements result from an informal, yet principled, approach. By bracketing the problem with appropriate reference points and elaborating a method for interpolating the requirements both a measure of uniformity and a basis for further discussion are achieved. Our reference points include the high robustness protection profile, the existing medium robustness consistency instruction, and our familiarity with the nuances of separation kernels. This practitioner-oriented study is intended to advance the prevailing practices for commercial software development, which presently falls far short of the rigor needed for either high-robustness or medium-robustness systems. These requirements represent an incremental improvement in the pursuit of secure software - and is intended to be a step forward on the road to higher assurance. Rance J. DeLong, Thuy D. Nguyen, Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 3 |
| 2007 | Trusted Hardware: Can It Be Trustworthy?abstractProcessing and storage of confidential or critical information is an every day occurrence in computing systems. The trustworthiness of computing devices has become an important consideration during hardware design and fabrication. For instance, devices are increasingly required to store confidential information. This includes data such as cryptographic keys, personal information, and the intellectual property (IP) in the device's design. Furthermore, computing systems in critical applications must work as specified. Therefore it is important that hardware be designed and fabricated to be trustworthy. Cynthia E. Irvine, Karl N. Levitt |
DAC | 1 |
| 2007 | Moats and Drawbridges: An Isolation Primitive for Reconfigurable Hardware Based SystemsabstractBlurring the line between software and hardware, reconfigurable devices strike a balance between the raw high speed of custom silicon and the post-fabrication flexibility of general-purpose processors. While this flexibility is a boon for embedded system developers, who can now rapidly prototype and deploy solutions with performance approaching custom designs, this results in a system development methodology where functionality is stitched together from a variety of "soft IP cores," often provided by multiple vendors with different levels of trust. Unlike traditional software where resources are managed by an operating system, soft IP cores necessarily have very fine grain control over the underlying hardware. To address this problem, the embedded systems community requires novel security primitives which address the realities of modern reconfigurable hardware. We propose an isolation primitive, moats and drawbridges, that are built around four design properties: logical isolation, interconnect traceability, secure reconfigurable broadcast, and configuration scrubbing. Each of these is a fundamental operation with easily understood formal properties, yet maps cleanly and efficiently to a wide variety of reconfigurable devices. We carefully quantify the required overheads on real FPGAs and demonstrate the utility of our methods by applying them to the practical problem of memory protection. Ted Huffmire, Brett Brotherton, Gang Wang 0015, Timothy Sherwood, Ryan Kastner, Timothy E. Levin, Thuy D. Nguyen, Cynthia E. Irvine |
S&P | 8 |
| 2007 | A video game for cyber security training and awareness
Benjamin D. Cone, Cynthia E. Irvine, Michael F. Thompson, Thuy D. Nguyen |
Comput. Secur. | 2 |
| 2006 | Cyber Security Training and Awareness Through Game Play
Benjamin D. Cone, Michael F. Thompson, Cynthia E. Irvine, Thuy D. Nguyen |
SEC | 3 |
| 2006 | Utilizing the Common Criteria for Advanced Student Research Projects
Thuy D. Nguyen, Cynthia E. Irvine |
SEC | 2 |
| 2006 | Least Privilege in Separation Kernels
Timothy E. Levin, Cynthia E. Irvine, Thuy D. Nguyen |
SECRYPT | 2 |
| 2003 | An Editor for Adaptive XML-Based Policy Management of IPsecabstractThe IPsec protocol provides a mechanism to enforce a range of security services for both confidentiality and integrity, enabling secure transmission of information across networks. Dynamic parameterization of IPsec, via the KeyNote trust management system, further enables security mechanisms to adjust the level of security service "on-the-fly" to respond to changing network and operational conditions. However KeyNote requires that an IPsec policy be defined in the KeyNote specification syntax. Defining such a dynamic security policy in the KeyNote policy specification language is complicated and can lead to incorrect specification of the desired policy, thus degrading the security of the network. We present an alternative XML representation of this language and a graphical user interface to create and manage a consistent and correct security policy. The interface has the simplicity of a simple menu-driven editor that not only provides KeyNote with a policy in the specified syntax but also integrates techniques to support administrative policy verification. Raj Mohan, Timothy E. Levin, Cynthia E. Irvine |
ACSAC | 3 |
| 2002 | Cool security trendsabstractTrent Jarger will discuss ongoing work in the verification of authorization hook placement in Linux. The idea is that we can develop tools to check that all security-sensitive kernel operations can be mediated properly. Dawson Engler will discuss ongoing work in static checking for kernal and driver bugs, including security bugs, based on his meta-complier xgcc. The idea is that reguirements can be expressed in a high-level language that the xgcc can check.David Wagner will discuss using formal modeling to guide the identifcation of security bugs. The idea is that a formal model generated fromteh source code can be more easily analyzed to find bugs.Cynthia Irvine will discuss security quality-of-service. The idea is that the cost of security in terms of performance and resource usage can be compared with the security benefits in such a way that decisions about security improvements can be made. Dawson R. Engler, Cynthia E. Irvine, Trent Jaeger, David A. Wagner 0001 |
SACMAT | 2 |
| 2002 | An Approach to Security Requirements Engineering for a High Assurance System
Cynthia E. Irvine, Timothy E. Levin, Jeffery D. Wilson, David J. Shifflett, Barbara Pereira |
Requir. Eng. | 1 |
| 2001 | Collective Value of QoS: A Performance Measure Framework for Distributed Heterogeneous NetworksabstractWhen user's tasks in a distributed heterogeneous computing environment are allocated resources, and the total demand placed on system resources by the tasks, for a given interval of time, exceeds the resources available, some tasks will receive degraded service, receive no service at all, or may be dropped from the system. One part of a measure to quantify the success of a resource management system (RMS) in such an environment is the collective value of the tasks completed during an interval of time, as perceived by the user, the application, or the policy maker. For the case where a task may be a data communication request, the collective value of data communication requests that are satisfied during an interval of time is measured. The Flexible Integrated System Capability (FISC) measure defined here is one way of obtaining a multi-dimensional measure for quantifying this collective value. While the FISC measure itself is not sufficient for scheduling purposes, it can be a critical part of a scheduler or a scheduling heuristic. The primary contribution of this work is providing a way to measure the collective value accrued by an RMS using a broad range of attributes and to construct a flexible framework that can be extended for particular problem domains. Jong-Kook Kim, Taylor Kidd, Howard Jay Siegel, Cynthia E. Irvine, Timothy E. Levin, Debra A. Hensgen, David St. John, Viktor Prasanna 0001, Richard F. Freund, N. Wayne Porter |
IPDPS | 4 |
| 2000 | Calculating Costs for Quality of Security ServiceabstractPresents a quality-of-security-service (QoSS) costing framework and a demonstration of it. A method for quantifying costs related to the security service and for storing and retrieving security information is illustrated. We describe a security model for tasks, which incorporates the ideas of variant security services invoked by the task, dynamic network modes, abstract security level choices and resource utilization costs. The estimated costs can be fed into a resource management system to facilitate the process of estimating efficient task schedules. Integration and scalability issues have been taken into account during the design of the QoSS costing demonstration, which we believe is suitable for incorporation into a resource management system research prototype. E. Spyropoulou, Timothy E. Levin, Cynthia E. Irvine |
ACSAC | 3 |
| 2000 | Quality of security serviceabstractAbstract 1. We examine the concept of security as a dimension of Quality of Service in distributed systems. Implicit to the concept of Quality of Service is the notion of choice or variation. Security services also offer a range of choice both from the user perspective and among the underlying resources. We provide a discussion and examples of user-specified security variables and show how the range of service levels associated with these variables can support the provision of Quality of Security Service, whereby security is a constructive network management tool rather than a performance obstacle. We also discuss various design implications regarding security ranges provided in a QoS-aware distributed system. Cynthia E. Irvine, Timothy E. Levin |
NSPW | 1 |
| 2000 | Is Electronic Privacy Achievable?
Cynthia E. Irvine, Timothy E. Levin |
S&P | 1 |
| 2000 | Analysis of the Intel Pentium's Ability to Support a Secure Virtual Machine Monitor
John Scott Robin, Cynthia E. Irvine |
USENIX Security Symposium | 2 |
| 1999 | Information Security Education for the Next Millennium: Building the Next Generation of Practitioners (Forum)
Ron Ross, Cynthia E. Irvine, Charles Reynolds, Ravi S. Sandhu, Blaine Burnham, Rayford B. Vaughn |
ACSAC | 2 |
| 1999 | Toward a Taxonomy and Costing Method for Security ServicesabstractA wide range of security services may be available to applications in a heterogeneous computer network environment. Resource management systems (RMSs) responsible for assigning computing and network resources to tasks need to know the resource-utilization costs associated with the various network security services. In order to understand the range of security services all RMS needs to manage, a preliminary security service taxonomy is defined. The taxonomy is used as a framework for defining the costs associated with network security services. Cynthia E. Irvine, Timothy E. Levin |
ACSAC | 1 |
| 1999 | A Multi-Threading Architecture for Multilevel Secure Transaction ProcessingabstractA TCB and security kernel architecture for supporting multi-threaded, queue-driven transaction processing applications in a multilevel secure environment is presented. Our design exploits hardware security features of the Intel 80/spl times/86 processor family. Intel's CPU architecture provides hardware with two distinct descriptor tables. We use one of these in the usual way for process isolation. For each process, the descriptor table holds the descriptors of "system-low" segments, such as code segments, used by every thread in a process. We use the second table to hold descriptors for segments known to individual threads within the process. This allocation, together with an appropriately designed scheduling policy, permits us to avoid the full cost of process creation when only switching between threads of different security classes in the same process. Where large numbers of transactions are encountered on transaction queues, this approach has benefits over traditional multilevel systems. Haruna R. Isa, William R. Shockley, Cynthia E. Irvine |
S&P | 3 |
| 1998 | Security Architecture for a Virtual Heterogeneous MachineabstractWe describe security for a virtual heterogeneous machine (VHM). Our security architecture is based upon separation of services into four distinct domains. It is designed to take advantage of operating system support for domains, where available. We have chosen to use emerging public key technology as an interim solution to provide domain separation. A prototype demonstration of our architecture has been developed. Roger Wright, David J. Shifflett, Cynthia E. Irvine |
ACSAC | 3 |
| 1997 | Security in Innovative New Operating SystemsabstractA principal criterion by which new operating systems are judged is the level of performance that they provide for applications. To this end, new operating systems have sought novel approaches to performance enhancement. A theme common to many of these initiatives is that of specialization. Instead of an operating system designed to serve all applications (either equally well or equally badly), the operating system is adapted to serve the needs of the application. The intent is not to provide a different static operating system for each application but to allow the operating system to be dynamically modified or specialized to best serve each application. The five operating system efforts presented are: the Exokernel Project, the Fluke Project, the Fox Project, the Scout Project, and the SPIN Project. The authors hope to give an overview of the innovative techniques being used to enhance performance in these systems and to discuss the effect of those enhancements on one's ability to reason about the security properties of systems. Cynthia E. Irvine |
S&P | 1 |
| 1997 | Secure flow typing
Dennis M. Volpano, Cynthia E. Irvine |
Comput. Secur. | 2 |
| 1996 | Goals for Computer Security Education
Cynthia E. Irvine |
S&P | 1 |
| 1996 | A Sound Type System for Secure Flow AnalysisabstractEnsuring secure information flow within programs in the context of multiple sensitivity levels has been widely studied. Especially noteworthy is Denning's work in secure flow analysis and the lattice model [6,7]. Until now, however, the soundness of Dennis M. Volpano, Cynthia E. Irvine, Geoffrey Smith 0001 |
J. Comput. Secur. | 2 |
| 1995 | A multilevel file system for high assuranceabstractThe designs of applications for multilevel systems cannot merely duplicate those of the untrusted world. When applications are built on a high assurance base, they will be constrained by the underlying policy enforcement mechanism. Consideration must be given to the creation and management of multilevel data structures by untrusted subjects. Applications should be designed to rely upon the TCB's security policy enforcement services rather than build new access control services beyond the TCB perimeter. The results of an analysis of the design of a general purpose file system developed to execute as an untrusted application on a high assurance TCB are presented. The design illustrates a number of solutions to problems resulting from a high assurance environment.> Cynthia E. Irvine |
S&P | 1 |
| 1990 | Architecture for an embedded secure data base management systemabstractThe architecture for an embedded secure database management system (ESDBMS) applicable to C/sup 3/ environments is presented. The ESDBMS design consists of three major components: the GEMSOS tamperproof security kernel, an embedded system run-time executive and the trusted ORACLE RDBMS. The ESDBMS is designed to support a fully-functional DBMS while meeting high assurance requirements. Future enhancements to the basic version of the ESDBMS are identified which will broaden its applicability.> Cynthia E. Irvine, Roger R. Schell, Linda L. Vetter |
ACSAC | 1 |
| 1989 | A Formal Model for UNIX SetuidabstractThe Unix setuid (set user identification) mechanism is described in the context of the GEMSOS architecture. Motivation for modeling setuid is given, and modeling and policy requirements for the control of the setuid mechanism are presented. The GEMSOS formal security policy model is compared with the Bell and LaPadula model. The Bell and LaPadula model is shown not to admit the actions of a setuid mechanism. Features of the GEMSOS DAC (discretionary access control) model are described that represent the actions of the Unix setuid mechanism while limiting their negative effect on the DAC policy.> Timothy E. Levin, S. J. Padilla, Cynthia E. Irvine |
S&P | 3 |