HWMAC: Hardware-Enforced Fined-Grained Policy-Driven Security

A computer processing architecture with fine grain, programmable mandatory access control implemented in the processor hardware is presented. In this processing architecture, all processing contexts and all data are labeled. Depending on the instruction, and labels for the subjects and objects, the hardware enforces a loadable mandatory policy which specifies if the instruction is allowed access to the objects, and if so, also applies rules which may modify the context and output data labels.

By: W. Eric Hall, Guerney D. H. Hunt, Paul A. Karger, Mark F. Mergen, David R. Safford, David C. Toll

Published in: RC25155 in 2011

LIMITED DISTRIBUTION NOTICE:

This Research Report is available. This report has been submitted for publication outside of IBM and will probably be copyrighted if accepted for publication. It has been issued as a Research Report for early dissemination of its contents. In view of the transfer of copyright to the outside publisher, its distribution outside of IBM prior to publication should be limited to peer communications and specific requests. After outside publication, requests should be filled only by reprints or legally obtained copies of the article (e.g., payment of royalties). I have read and understand this notice and am a member of the scientific community outside or inside of IBM seeking a single copy only.

rc25155.pdf

Questions about this service can be mailed to reports@us.ibm.com .