Skip to main navigation Skip to search Skip to main content

Comparison of two context allocation approaches for fast protected calls

  • State University of New York Binghamton University

Research output: Contribution to conferencePaperpeer-review

3 Scopus citations

Abstract

Secure computing systems require the implementation of protection domains and a safe way of transferring control across such domains. Isolating the contexts (activation stacks) of the caller and the callee, to avoid unintended information flow, is a fundamental requirement for implementing cross-domain transfers. We present and evaluate two approaches for implementing contexts for cross-domain calls in a conventional pipelined architecture retrofitted with a simple capability mechanism. The first and the more traditional approach is to use separate context segments for the caller and the callee. The second is to use a unified context segment supported by some modest hardware for avoiding unintended information flow. Simulation results indicate that the unified context solution performs markedly better than the separate context solution. Also, the overall overhead of the protected call mechanism using the unified context is about 10-30% - a price that may be worth paying for the resulting security.

Original languageEnglish
Pages16-21
Number of pages6
StatePublished - 1997
EventProceedings of the 1997 4th International Conference on High Performance Computing, HiPC - Bangalore, India
Duration: Dec 18 1997Dec 21 1997

Conference

ConferenceProceedings of the 1997 4th International Conference on High Performance Computing, HiPC
CityBangalore, India
Period12/18/9712/21/97

Fingerprint

Dive into the research topics of 'Comparison of two context allocation approaches for fast protected calls'. Together they form a unique fingerprint.

Cite this