4 ms·
What IBM systems are you thinking of? System/360 had (and used) hardware privilege levels. Seems like few of your examples involve not using hardware for proc
by twtw 8y ago
What IBM systems are you thinking of?
System/360 had (and used) hardware privilege levels.
Seems like few of your examples involve not using hardware for process isolation. Java: no, except a few research OSes. Flash: no.
- monocasa 8y agoHe's probably talking about AS/400, and it's hardware/software codesigned VM. For some reason people call those mainframes. AS/400 though does use hardware heavily in it's isolation model, going so far as to have a custom PowerPC variant currently that adds tagged memory.
- pjmlp 8y agoBoth AS/400 and System/370 have a so called language environments. And yes I call them mainframes, because it is as I always heard people referring to them during my Summer job back in the day, so the name stuck with me even it isn't correct.
- monocasa 8y agoLanguage environment in IBM parlance is closer to "ABI" than "VM", or "sandbox" in the rest of the world. It's a common set of idioms to allow two languages (generally ASM and a higher level language like C) to call eachother and interoperate.
- nickpsecurity 8y agoThere's been quite a few of these systems over time. Especially sold commercially. IBM System/38, evolved into AS/400 and IBM i, is one of architectures described in this book: https://homes.cs.washington.edu/~levy/capabook/ https://homes.cs.washington.edu/~levy/capabook/ Far as language-based security, the first mainframe for businesses used a high-level language combined with a CPU that dynamically checked the programs. Still sold by Unisys but I doubt hardware checks still exist. http://www.smecc.org/The%20Architecture%20%20of%20the%20Burroughs%20B-5000.htm http://www.smecc.org/The%20Architecture%20%20of%20the%20Burr... The Flex Machine implemented capabilities and trusted procedures in the microcode: https://en.wikipedia.org/wiki/Flex_machine https://en.wikipedia.org/wiki/Flex_machine ASOS supported a mix of methods where each app was Ada for its safety features but a MLS kernel modeled in Gypsy separated various security levels: https://pdfs.semanticscholar.org/42a4/e6f812538c18461277c58a8464d2aa0c551f.pdf https://pdfs.semanticscholar.org/42a4/e6f812538c18461277c58a... SAFE explored tagging at CPU level which got commercialized as CoreGuard or Inherently Secure Processor: http://www.crash-safe.org/papers.html http://www.crash-safe.org/papers.html https://www.draper.com/explore-solutions/inherently-secure-processor https://www.draper.com/explore-solutions/inherently-secure-p... In embedded, there's Java processors that run bytecode natively with some support for separation. They blur the line between VM's and native apps: http://ajile.com/index.php?option=com_content&view=article&id=4&Itemid=5 http://ajile.com/index.php?option=com_content&view=article&i...