operatingsystem《操作系统》ch.ppt
《operatingsystem《操作系统》ch.ppt》由会员分享,可在线阅读,更多相关《operatingsystem《操作系统》ch.ppt(25页珍藏版)》请在三一办公上搜索。
1、Chapter 14:Protection,Chapter 14:Protection,Goals of Protection Principles of ProtectionDomain of Protection Access Matrix Implementation of Access Matrix Access ControlRevocation of Access Rights Capability-Based Systems Language-Based Protection,Objectives,Discuss the goals and principles of prote
2、ction in a modern computer systemExplain how protection domains combined with an access matrix are used to specify the resources a process may accessExamine capability and language-based protection systems,Goals of Protection,Operating system consists of a collection of objects,hardware or softwareE
3、ach object has a unique name and can be accessed through a well-defined set of operations.Protection problem-ensure that each object is accessed correctly and only by those processes that are allowed to do so.,Principles of Protection,Guiding principle principle of least privilegePrograms,users and
4、systems should be given just enough privileges to perform their tasks,Domain Structure,Access-right=where rights-set is a subset of all valid operations that can be performed on the object.Domain=set of access-rights,Domain Implementation(UNIX),System consists of 2 domains:UserSupervisorUNIX Domain=
5、user-idDomain switch accomplished via file system.Each file has associated with it a domain bit(setuid bit).When file is executed and setuid=on,then user-id is set to owner of the file being executed.When execution completes user-id is reset.,Domain Implementation(MULTICS),Let Di and Dj be any two d
6、omain rings.If j I Di Dj,Access Matrix,View protection as a matrix(access matrix)Rows represent domainsColumns represent objectsAccess(i,j)is the set of operations that a process executing in Domaini can invoke on Objectj,Access Matrix,Use of Access Matrix,If a process in Domain Di tries to do“op”on
7、 object Oj,then“op”must be in the access matrix.Can be expanded to dynamic protection.Operations to add,delete access rights.Special access rights:owner of Oicopy op from Oi to Ojcontrol Di can modify Dj access rightstransfer switch from domain Di to Dj,Use of Access Matrix(Cont.),Access matrix desi
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- 操作系统 operatingsystem ch
![提示](https://www.31ppt.com/images/bang_tan.gif)
链接地址:https://www.31ppt.com/p-6513279.html