login

A security kernel based on the lambda-calculus

DSpace@MIT (Massachusetts Institute of Technology)Published 1 January 1995Open access
Jonathan Rees
Citations44
View PDF

TL;DR

Experience with Scheme 48 is described that shows how it serves as a robust and flexible experimental platform and two successful applications of Scheme 48 are the programming environment for the Cornell mobile robots; and a secure multi-user environment that runs on workstations.

Abstract

Cooperation between independent agents depends upon establishing a degree of security. Each of the cooperating agents needs assurance that the cooperation will not endanger resources of value to that agent. In a computer system, a computational mechanism can assure safe cooperation among the system's users by mediating resource access according to desired security policy. Such a mechanism, which is called a security kernel , lies at the heart of many operating systems and programming environments. This report describes Scheme 48, a programming environment whose design is guided by established principles of operating system security. Scheme 48's security kernel is small, consisting of the call-by-value -calculus with a few simple extensions to support abstract data types, object mutation, and access to hardware resources. Each agent (user or subsystem) has a separate evaluation environment that holds objects representing privileges granted to that agent. Because environments ultimatel...

Keywords

Computer Science