EDBT 2026 Demo / reviewers in the wild / expert
Michael D. Schroeder
dblp:s/MichaelDSchroeder · also Michael Schroeder 0002
· DBLP profile ↗
13ranked-venue papers
9as first author
0since 2021 · last 1991
0000-0003-2848-6949ORCID · corroborated
Domains — the database's venue-derived domains; a paper can count in several
Software engineering, systems software and programming languages · 8 · 6 first-authorSystems, architecture and hardware · 2 · 2 first-authorComputer networks · 1 · 1 first-authorSecurity and privacy · 1Applied, interdisciplinary, general and emerging computing · 1
Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.
| Computer architecture, parallel and distributed computing, and storage systems
7 papers |
Distributed systems · 50% Performance modeling and evaluation · 24% Memory systems · 13% | |
| Computer networks
3 papers |
Network management and operations · 37% Internet architecture and protocols · 35% Routing and switching · 23% | |
| Network and information security
4 papers |
Authentication and access control · 78% Systems and software security · 22% | |
| Software engineering, system software, and programming languages
5 papers |
Operating systems · 92% Programming languages and type systems · 8% |
Topics — the 24 heaviest of 31, each with the papers that count most for it
| Topic | Weight | Papers | Last | Evidence papers |
|---|---|---|---|---|
Distributed systems
remote procedure call |
0.0 | 2 | 1990 | Performance of Firefly RPC · ACM Trans. Comput. Syst. 1990 Performance of Firefly RPC · SOSP 1989 |
Network management and operations › fault management
fault monitoring |
0.0 | 1 | 1991 | Automatic Reconfiguration in Autonet · SOSP 1991 |
Internet architecture and protocols
local area network |
0.0 | 1 | 1991 | Autonet: A High-Speed, Self-Configuring Local Area Network Using Point-to-Point Links · IEEE J. Sel. Areas Commun. 1991 |
Network management and operations › network configuration
network reconfiguration |
0.0 | 1 | 1991 | Automatic Reconfiguration in Autonet · SOSP 1991 |
Internet architecture and protocols › network adaptation
self-configuring network |
0.0 | 1 | 1991 | Autonet: A High-Speed, Self-Configuring Local Area Network Using Point-to-Point Links · IEEE J. Sel. Areas Commun. 1991 |
Performance modeling and evaluation
benchmarking |
0.0 | 1 | 1990 | Performance of Firefly RPC · ACM Trans. Comput. Syst. 1990 |
Performance modeling and evaluation
delay analysis |
0.0 | 1 | 1989 | Performance of Firefly RPC · SOSP 1989 |
Distributed systems › replication
replicated system |
0.0 | 2 | 1984 | Experience with Grapevine: The Growth of a Distributed System · ACM Trans. Comput. Syst. 1984 Experience with Grapevine: The Growth of a Distributed System (Summary) · SOSP 1983 |
Authentication and access control › authentication
authentication protocols |
0.0 | 1 | 1986 | A Global Authentication Service without Global Trust · S&P 1986 |
Authentication and access control
distributed authentication |
0.0 | 1 | 1986 | A Global Authentication Service without Global Trust · S&P 1986 |
Parallel and multicore computing
multiprocessor system |
0.0 | 2 | 1990 | Performance of Firefly RPC · ACM Trans. Comput. Syst. 1990 Performance of Firefly RPC · SOSP 1989 |
Memory systems
cache |
0.0 | 1 | 1985 | A Caching File System For a Programmer's Workstation · SOSP 1985 |
Memory systems › cache management › storage caching
file cache |
0.0 | 1 | 1985 | A Caching File System For a Programmer's Workstation · SOSP 1985 |
Storage systems
file systems |
0.0 | 1 | 1985 | A Caching File System For a Programmer's Workstation · SOSP 1985 |
Distributed systems › distributed system architecture › distributed operating systems
naming |
0.0 | 1 | 1984 | Experience with Grapevine: The Growth of a Distributed System · ACM Trans. Comput. Syst. 1984 |
Routing and switching › routing
distributed routing |
0.0 | 1 | 1991 | Autonet: A High-Speed, Self-Configuring Local Area Network Using Point-to-Point Links · IEEE J. Sel. Areas Commun. 1991 |
Systems and software security
operating system security |
0.0 | 2 | 1977 | The Multics Kernel Design Project · SOSP 1977 Engineering a Security Kernel for Multics · SOSP 1975 |
Operating systems › kernel
kernel design |
0.0 | 2 | 1977 | The Multics Kernel Design Project · SOSP 1977 Engineering a Security Kernel for Multics · SOSP 1975 |
Authentication and access control
access control |
0.0 | 1 | 1975 | The protection of information in computer systems · Proc. IEEE 1975 |
Authentication and access control › access control › access control mechanisms
capability-based protection |
0.0 | 1 | 1975 | The protection of information in computer systems · Proc. IEEE 1975 |
Systems and software security › operating system security
security kernel |
0.0 | 1 | 1975 | Engineering a Security Kernel for Multics · SOSP 1975 |
Distributed systems
message delivery |
0.0 | 1 | 1984 | Experience with Grapevine: The Growth of a Distributed System · ACM Trans. Comput. Syst. 1984 |
Authentication and access control
authentication |
0.0 | 1 | 1975 | The protection of information in computer systems · Proc. IEEE 1975 |
Programming languages and type systems › type systems
extensible data types |
0.0 | 1 | 1977 | The Multics Kernel Design Project · SOSP 1977 |
Methods — techniques the papers use, named apart from their topics
latency measurement · 0.0operational measurement · 0.0topology acquisition · 0.0secure channel composition · 0.0fault monitoring · 0.0throughput measurement · 0.0performance analysis · 0.0caching · 0.0type extension · 0.0test implementation · 0.0kernel complexity analysis · 0.0capability-based access control · 0.0auditing · 0.0access control lists · 0.0
| Year | Publication | Venue | Position |
|---|---|---|---|
| 1991 | Automatic Reconfiguration in AutonetabstractAutonet is a switch-based local area network using 100 Mbit/s full-duplex point-to-point links. Crossbar switches are interconnected to other switches and to host controllers in an arbitrary pattern. Switch hardware uses the destination address in each packet to determine the proper outgoing link for the next step in the path from source to destination. Autonet automatically recalculates these forwarding paths in response to failures and additions of network components. This automatic reconfiguration allows the network to continue normal operation without need of human intervention. Reconfiguration occurs quickly enough that higher-level protocols are not disrupted. This paper describes the fault monitoring and topology acquisition mechanisms that are central to automatic reconfiguration in Autonet. Thomas L. Rodeheffer, Michael D. Schroeder |
SOSP | 2 |
| 1991 | Autonet: A High-Speed, Self-Configuring Local Area Network Using Point-to-Point LinksabstractAutonet is a self-configuring local area network composed of switches interconnected by 100 Mb/s, full-duplex, point-to-point links. The switches contain 12 ports that are internally connected by a full crossbar. Switches use cut-through to achieve a packet forwarding latency as low as 2 ms/switch. Any switch port can be cabled to any other switch port or to a host network controller. A processor in each switch monitors the network's physical configuration. A distributed algorithm running on the switch processor computes the routes packets are to follow and fills in the packet forwarding table in each switch. With Autonet, distinct paths through the set of network links can carry packets in parallel, allowing many pairs of hosts to communicate simultaneously at full link bandwidth. A 30-switch network with more than 100 hosts has been the service network for Digital's Systems Research Center since February 1990.> Michael D. Schroeder, Andrew Birrell, Michael Burrows, Hal Murray, Roger M. Needham, Thomas L. Rodeheffer, Edwin H. Satterthwaite, Charles P. Thacker |
IEEE J. Sel. Areas Commun. | 1 |
| 1990 | Performance of Firefly RPCabstractIn this paper we report on the performance of the remote procedure call (RPC) implementation for the Firefly multiprocessor and analyze the implementation to account precisely for all measured latency. From the analysis and measurements, we estimate how much faster RPC could be if certain improvements were made. The elapsed time for an intermachine call to a remote procedure that accepts no arguments and produces no results is 2.66 ms. The elapsed time for an RPC that has a single 1440-byte result (the maximum result that will fit in a single packet) is 6.35 ms. Maximum intermachine throughput of application program data using RPC is 4.65 Mbits/s, achieved with four threads making parallel RPCs that return the maximum-size result that fits in a single RPC result packet. CPU utilization at maximum throughput is about 1.2 CPU seconds per second on the calling machine and a little less on the server. These measurements are for RPCs from user space on one machine to user space on another, using the installed system and a 10 Mbit/s Ethernet. The RPC packet exchange protocol is built on IP/UDP, and the times include calculating and verifying UDP checksums. The Fireflies used in the tests had 5 MicroVAX II processors and a DEQNA Ethernet controller. Michael D. Schroeder, Michael Burrows |
ACM Trans. Comput. Syst. | 1 |
| 1989 | Performance of Firefly RPCabstractIn this paper, we report on the performance of the remote procedure call implementation for the Firefly multiprocessor and analyze the implementation to account precisely for all measured latency. From the analysis and measurements, we estimate how much faster RPC could be if certain improvements were made. Michael D. Schroeder, Michael Burrows |
SOSP | 1 |
| 1986 | A Global Authentication Service without Global TrustabstractThis paper describes a design for an authentication service for a very large scale, very long lifetime, distributed system. The paper introduces a methodology for describing authentication protocols that makes explicit the trust relationships amongst the participants. The authentication protocol is based on the primitive notion of composition of secure channels. The authentication model offered provides for the authentication of "roles", where a principal might exercise differing roles at differing times, whilst having only a single "identity". Roles are suitable for inclusion in access control lists. The naming of a role implies what entities are being trusted to authenticate the role. We provide a UID scheme that gives clients control over the time at which a name gets bound to a principal, thus controlling the effects of mutability of the name space. Andrew Birrell, Butler W. Lampson, Roger M. Needham, Michael D. Schroeder |
S&P | 4 |
| 1985 | A Caching File System For a Programmer's WorkstationabstractArticle Free Access Share on A caching file system for a programmer's workstation Authors: Michael D. Schroeder DEC Systems Research Center, Xerox Palo Alto Research Center, 130 Lytton Ave., Palo Alto, CA DEC Systems Research Center, Xerox Palo Alto Research Center, 130 Lytton Ave., Palo Alto, CAView Profile , David K. Gifford Laboratory for Computer Science, Xerox Palo Alto Research Center, 545 Technology Sq., Cambridge, MA Laboratory for Computer Science, Xerox Palo Alto Research Center, 545 Technology Sq., Cambridge, MAView Profile , Roger M. Needham Computer Laboratory, Xerox Palo Alto Research Center, Corn Exchange St., Cambridge CB2 3QG, UK Computer Laboratory, Xerox Palo Alto Research Center, Corn Exchange St., Cambridge CB2 3QG, UKView Profile Authors Info & Claims SOSP '85: Proceedings of the tenth ACM symposium on Operating systems principlesDecember 1985 Pages 25–34https://doi.org/10.1145/323647.323632Published:01 December 1985Publication History 86citation361DownloadsMetricsTotal Citations86Total Downloads361Last 12 Months63Last 6 weeks6 Get Citation AlertsNew Citation Alert added!This alert has been successfully added and will be sent to:You will be notified whenever a record that you have chosen has been cited.To manage your alert preferences, click on the button below.Manage my AlertsNew Citation Alert!Please log in to your account Save to BinderSave to BinderCreate a New BinderNameCancelCreateExport CitationPublisher SiteeReaderPDF Michael D. Schroeder, David K. Gifford, Roger M. Needham |
SOSP | 1 |
| 1984 | Experience with Grapevine: The Growth of a Distributed SystemabstractGrapevine is a distributed, replicated system that provides message delivery, naming, authentication, resource location, and access control services in an internet of computers.The system, described in a previous paper [1], was designed and implemented several years ago.We now have had operational experience with the system under substantial load.In this paper we report on what we have learned from using Grapevine. Michael D. Schroeder, Andrew Birrell, Roger M. Needham |
ACM Trans. Comput. Syst. | 1 |
| 1983 | Experience with Grapevine: The Growth of a Distributed System (Summary)abstractGrapevine is a distributed, replicated system that provides message delivery, naming, authentication, resource location, and access control services in an internet of computers. The system, described in a previous paper [1], was designed and implemented several years ago. We now have had operational experience with the system under substantial load. This experience has proved the original design sound in most aspects, but there also have been some surprises. In this paper we report what we have learned from using Grapevine. Our experience may offer some help to designers of new systems. Michael D. Schroeder, Andrew Birrell, Roger M. Needham |
SOSP | 1 |
| 1981 | Gravevine: An Exercise in Distributed Computing (summary)
Andrew Birrell, Roy Levin, Roger M. Needham, Michael D. Schroeder |
SOSP | 4 |
| 1977 | The Multics Kernel Design ProjectabstractWe describe a plan to create an auditable version of Multics. The engineering experiments of that plan are now complete. Type extension as a design discipline has been demonstrated feasible, even for the internal workings of an operating system, where many subtle intermodule dependencies were discovered and controlled. Insight was gained into several tradeoffs between kernel complexity and user semantics. The performance and size effects of this work are encouraging. We conclude that verifiable operating system kernels may someday be feasible. Michael D. Schroeder, David D. Clark, Jerome H. Saltzer |
SOSP | 1 |
| 1975 | Engineering a Security Kernel for MulticsabstractThis paper describes a research project to engineer a security kernel for Multics, a general-purpose, remotely accessed, multiuser computer system. The goals are to identify the minimum mechanism that must be correct to guarantee computer enforcement of desired constraints on information access, to simplify the structure of that minimum mechanism to make verification of correctness by auditing possible, and to demonstrate by test implementation that the security kernel so developed is capable of supporting the functionality of Multics completely and efficiently. The paper presents the overall viewpoint and plan for the project and discusses initial strategies being employed to define and structure the security kernel. Michael D. Schroeder |
SOSP | 1 |
| 1975 | The protection of information in computer systemsabstractThis tutorial paper explores the mechanics of protecting computer-stored information from unauthorized use or modification. It concentrates on those architectural structures-whether hardware or software-that are necessary to support information protection. The paper develops in three main sections. Section I describes desired functions, design principles, and examples of elementary protection and authentication mechanisms. Any reader familiar with computers should find the first section to be reasonably accessible. Section II requires some familiarity with descriptor-based computer architecture. It examines in depth the principles of modern protection architectures and the relation between capability systems and access control list systems, and ends with a brief analysts of protected subsystems and protected objects. The reader who is dismayed by either the prerequisites or the level of detail in the second section may wish to skip to Section III, which reviews the state of the art and current research projects and provides suggestions for further reading. Jerome H. Saltzer, Michael D. Schroeder |
Proc. IEEE | 2 |
| 1971 | A Hardware Architecture for Implementing Protection Rings (Abstract)abstractThis paper appears in the March, 1972, issue of the Communications of the ACM. Its abstract is reproduced below. Michael D. Schroeder, Jerome H. Saltzer |
SOSP | 1 |