{"id":{"repo_id":"uiuc","oai_identifier":"oai:www.ideals.illinois.edu:2142/16020"},"canonical_url":"https://search.dev.ndltd.org/etd/uiuc/oai:www.ideals.illinois.edu:2142/16020","repository":{"repo_id":"uiuc","name":"University of Illinois - Urbana-Champaign","base_url":"https://www.ideals.illinois.edu/oai-pmh"},"display":{"title":"Trusted and high assurance systems","abstract":"High assurance MILS (multiple independent levels of security) and MLS (multilevel security) systems require strict limitation of the interactions between different security compartments based on a security policy. Virtualization can be used to provide a high degree of separation in such systems. This work provides a study of commercial-off-the-shelf (COTS) products to support high assurance MLS systems and designs a candidate architecture based on virtualization and trusted execution to provide strong compartmentalization. We then identify three major security problems in the candidate architecture: the lack of trust in the network, the problem of patch management, and untrusted graphics. We study and solve each of the security gaps in detail. More specifically, we design and evaluate a trusted network architecture for high assurance applications, evaluate an optimal pre-deployment testing time for effective patch management, and finally design, implement, and formally evaluate a trusted graphics subsystem.","abstract_html":"High assurance MILS (multiple independent levels of security) and MLS (multilevel security) systems require strict limitation of the interactions between different security compartments based on a security policy. Virtualization can be used to provide a high degree of separation in such systems. This work provides a study of commercial-off-the-shelf (COTS) products to support high assurance MLS systems and designs a candidate architecture based on virtualization and trusted execution to provide strong compartmentalization. We then identify three major security problems in the candidate architecture: the lack of trust in the network, the problem of patch management, and untrusted graphics. We study and solve each of the security gaps in detail. More specifically, we design and evaluate a trusted network architecture for high assurance applications, evaluate an optimal pre-deployment testing time for effective patch management, and finally design, implement, and formally evaluate a trusted graphics subsystem.","abstract_has_math":false,"creators":["Okhravi, Hamed"],"institution":"University of Illinois at Urbana-Champaign","degree_name":"Ph.D.","degree_level":"Dissertation","degree_discipline":"Electrical & Computer Engr","degree_department":null,"school":null,"contributors":["Nicol, David M.","Sanders, William H.","Adve, Vikram S.","Vaidya, Nitin H."],"advisors":[],"committee_chairs":[],"committee_members":[],"year":2010,"date_issued":"2010-05-19T18:32:25Z","date_published":"2010-05-19T18:32:25Z","updated_at":"2026-07-22T22:25:08Z","subjects":["Trusted systems","High assurance systems","Multilevel security (MLS)","Virtualization","Trusted boot","Trusted networks","Patch management","Trusted graphics","Formal methods"],"languages":["en"],"rights":["Copyright 2010 Hamed Okhravi"],"rights_urls":[],"identifier_entries":[]},"links":{"outbound_url":"http://hdl.handle.net/2142/16020","outbound_label":"Handle","outbound_source":"dc:identifier"},"metadata_groups":[{"id":"people","label":"People","entries":[{"key":"dc:contributor","label":"Contributor","values":["Nicol, David M.","Sanders, William H.","Adve, Vikram S.","Vaidya, Nitin H."]},{"key":"dc:creator","label":"Author","values":["Okhravi, Hamed"]}]},{"id":"academic_context","label":"Academic Context","entries":[{"key":"dc:date","label":"Dc Date","values":["2010-05-19T18:32:25Z","2010-5"]},{"key":"thesis:degree_discipline","label":"Discipline","values":["Electrical & Computer Engr"]},{"key":"thesis:degree_level","label":"Degree Level","values":["Dissertation"]},{"key":"thesis:degree_name","label":"Degree Name","values":["Ph.D."]},{"key":"thesis:institution_name","label":"Thesis Institution Name","values":["University of Illinois at Urbana-Champaign"]}]},{"id":"subjects_keywords","label":"Subjects and Keywords","entries":[{"key":"dc:subject","label":"Dc Subject","values":["Trusted systems","High assurance systems","Multilevel security (MLS)","Virtualization","Trusted boot","Trusted networks","Patch management","Trusted graphics","Formal methods"]}]},{"id":"language_rights","label":"Language and Rights","entries":[{"key":"dc:language","label":"Dc Language","values":["en"]},{"key":"dc:rights","label":"Dc Rights","values":["Copyright 2010 Hamed Okhravi"]}]},{"id":"identifiers","label":"Identifiers","entries":[{"key":"dc:identifier","label":"Identifier","values":["http://hdl.handle.net/2142/16020"]}]},{"id":"additional","label":"Additional Metadata","entries":[{"key":"dc:description","label":"Description","values":["High assurance MILS (multiple independent levels of security) and MLS (multilevel security) systems require strict limitation of the interactions between different security compartments based on a security policy. Virtualization can be used to provide a high degree of separation in such systems. This work provides a study of commercial-off-the-shelf (COTS) products to support high assurance MLS systems and designs a candidate architecture based on virtualization and trusted execution to provide strong compartmentalization. We then identify three major security problems in the candidate architecture: the lack of trust in the network, the problem of patch management, and untrusted graphics. We study and solve each of the security gaps in detail. More specifically, we design and evaluate a trusted network architecture for high assurance applications, evaluate an optimal pre-deployment testing time for effective patch management, and finally design, implement, and formally evaluate a trusted graphics subsystem.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-01-28T14:51:27Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Okhravi_Hamed.pdf: 1948405 bytes, checksum: e9d866154680baf9d55139dc74869449 (MD5)","Made available in DSpace on 2010-05-19T18:32:25Z (GMT). No. of bitstreams: 2 Okhravi_Hamed.pdf: 1948405 bytes, checksum: e9d866154680baf9d55139dc74869449 (MD5) license.txt: 4063 bytes, checksum: 2a1c2d5f221359479fce282a77e75ea9 (MD5)"]},{"key":"dc:title","label":"Title","values":["Trusted and high assurance systems"]}]}],"canonical_facts":{"dc:contributor":["Nicol, David M.","Sanders, William H.","Adve, Vikram S.","Vaidya, Nitin H."],"dc:creator":["Okhravi, Hamed"],"dc:date":["2010-05-19T18:32:25Z","2010-5"],"dc:description":["High assurance MILS (multiple independent levels of security) and MLS (multilevel security) systems require strict limitation of the interactions between different security compartments based on a security policy. Virtualization can be used to provide a high degree of separation in such systems. This work provides a study of commercial-off-the-shelf (COTS) products to support high assurance MLS systems and designs a candidate architecture based on virtualization and trusted execution to provide strong compartmentalization. We then identify three major security problems in the candidate architecture: the lack of trust in the network, the problem of patch management, and untrusted graphics. We study and solve each of the security gaps in detail. More specifically, we design and evaluate a trusted network architecture for high assurance applications, evaluate an optimal pre-deployment testing time for effective patch management, and finally design, implement, and formally evaluate a trusted graphics subsystem.","Item withdrawn by Mark Zulauf (zulauf@illinois.edu) on 2010-01-28T14:51:27Z Item was in collections: University of Illinois Theses & Dissertations (ID: 1) No. of bitstreams: 1 Okhravi_Hamed.pdf: 1948405 bytes, checksum: e9d866154680baf9d55139dc74869449 (MD5)","Made available in DSpace on 2010-05-19T18:32:25Z (GMT). No. of bitstreams: 2 Okhravi_Hamed.pdf: 1948405 bytes, checksum: e9d866154680baf9d55139dc74869449 (MD5) license.txt: 4063 bytes, checksum: 2a1c2d5f221359479fce282a77e75ea9 (MD5)"],"dc:identifier":["http://hdl.handle.net/2142/16020"],"dc:language":["en"],"dc:rights":["Copyright 2010 Hamed Okhravi"],"dc:subject":["Trusted systems","High assurance systems","Multilevel security (MLS)","Virtualization","Trusted boot","Trusted networks","Patch management","Trusted graphics","Formal methods"],"dc:title":["Trusted and high assurance systems"],"thesis:degree_discipline":["Electrical & Computer Engr"],"thesis:degree_level":["Dissertation"],"thesis:degree_name":["Ph.D."],"thesis:institution_name":["University of Illinois at Urbana-Champaign"]},"updated_at":"2026-07-22T22:25:08Z"}