Second European Symposium on Research in Computer Security (ESORICS 92)

M2S: A Machine for Multilevel Security

Bruno d'Ausbourg, Jean-Henri Llareus

Abstract : In this paper we describe the architecture of a computer machine ensuring a protection for data and processes of various classification levels, concurrently running on behalf of various cleared users. The security, enforced by a hardware security subsystem, is based on an internal information flow control that prevents building any illicit channel. Mechanisms and services of standard operating systems may be built on this machine. It permits also to build and manage multilevel data structures and multilevel computations which are able to satisfy the highest security requirement of new applications.

(Pages 373-391)

