Establishment of a secure networking between Secure OSs

  • Lim, Jae-Deok (Network Security Department, Information Security Research Division, Electronics and Telecommunications Research Institute(ETRI)) ;
  • Yu, Joon-Suk (Network Security Department, Information Security Research Division, Electronics and Telecommunications Research Institute(ETRI)) ;
  • Kim, Jeong-Nyeo (Network Security Department, Information Security Research Division, Electronics and Telecommunications Research Institute(ETRI))
  • Published : 2003.10.22

Abstract

Many studies have been done on secure operating system using secure kernel that has various access control policies for system security. Secure kernel can protect user or system data from unauthorized and/or illegal accesses by applying various access control policies like DAC(Discretionary Access Control), MAC(Mandatory Access Control), RBAC(Role Based Access Control), and so on. But, even if secure operating system is running under various access control policies, network traffic among these secure operating systems can be captured and exposed easily by network monitoring tools like packet sniffer if there is no protection policy for network traffic among secure operating systems. For this reason, protection for data within network traffic is as important as protection for data within local system. In this paper, we propose a secure operating system trusted channel, SOSTC, as a prototype of a simple secure network protocol that can protect network traffic among secure operating systems and can transfer security information of the subject. It is significant that SOSTC can be used to extend a security range of secure operating system to the network environment.

Keywords