[logo]

High Assurance Architecture for High Integrity Internets

University of Arizona
Department of Computer Science

Principal Investigators

Sean O'Malley
Hilarie Orman
Larry Peterson











DARPA OS/Security PI Meeting
May 22-23, 1996






Next
Top


[logo]

Goals


















Next
Previous
Top

[logo]




Enabling Concepts
















Next
Previous
Top

[logo]




Why Modular, Flexible, etc?



Must be able to respond rapidly and accurately to changes







Next
Previous
Top

[logo]

Accomplishments




Next
Previous
Top

[logo]

Software Architecture















Next
Previous
Top

[logo]



In progress

Public key signatures in IP security framework

New key exchange protocol

OSPF link state signatures

Integration of IP security in Linux kernel

xKernel security code used directly

Mix-match user/kernel security processing in Linux

xKernel in Linux kernel and in user space

Omnipresent policy modules









Next
Previous
Top




[logo]

OAKLEY key exchange






Next
Previous
Top

[logo] Protocols

Crypto Subsystem








Next
Previous
Top

[logo] More Protocols, Higher-Level Semantics


Policy Enforcement Auxiliary Systems Applications





Next
Previous
Top

[logo] Linux Integration



xKernel simulator over native UDP

Packet Intercept/Insert

xKernel uniform interface user/kernel?






Next
Previous
Top

[logo]



Scorecard



Very successful Moderately successful

Less successful

Previous
Top