diff --git a/.harper-dictionary.txt b/.harper-dictionary.txt index 1ec81cf..c65042d 100644 --- a/.harper-dictionary.txt +++ b/.harper-dictionary.txt @@ -1,2 +1,15 @@ +Andi +B. +B.S. +BSc +Heijn +MSc +Noto +Q. bgcolor1 bgcolor2 +elsevier +mathblocks +textcolor1 +textcolor2 +vancouver diff --git a/poster/main.typ b/poster/main.typ index 48bd721..ef57302 100644 --- a/poster/main.typ +++ b/poster/main.typ @@ -1,9 +1,6 @@ #import "template.typ": * #import "colors.typ": base_colors, bold_color - - - #set page( width: 48in, height: 36in, @@ -53,57 +50,57 @@ [ // section 1 - #import "./sections/twizzler.typ": title; + #import "./sections/1_twizzler.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/twizzler.typ" + #include "./sections/1_twizzler.typ" ] // section 2 - #import "./sections/cap.typ": title; + #import "./sections/2_cap.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/cap.typ" + #include "./sections/2_cap.typ" ] ], [ // section 3 - #import "./sections/sec_ctx.typ": title; + #import "./sections/3_sec_ctx.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/sec_ctx.typ" + #include "./sections/3_sec_ctx.typ" ] // section 4 - #import "./sections/execution.typ": title; + #import "./sections/4_execution.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/execution.typ" + #include "./sections/4_execution.typ" ] ], [ // section 3 - #import "./sections/future.typ": title; + #import "./sections/5_future.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/future.typ" + #include "./sections/5_future.typ" ] // section 4 - #import "./sections/cited.typ": title; + #import "./sections/6_cited.typ": title; #colored_poster_section(fill: true)[ #title ][ - #include "./sections/cited.typ" + #include "./sections/6_cited.typ" ] diff --git a/poster/sections/1_twizzler.typ b/poster/sections/1_twizzler.typ new file mode 100644 index 0000000..f144392 --- /dev/null +++ b/poster/sections/1_twizzler.typ @@ -0,0 +1,19 @@ +#let title = "What is Twizzler?" + + +// the big idea is movign into a data centric operating system +// +// with that data centric operating system means that processes +// access data directly +// +// How do we ensure that data is only accessed by parties who +// are supposed to access that data, if the kernel isnt there +// to mediate data access? +// +// lead into capabilities... + +#lorem(200) + + + + diff --git a/poster/sections/2_cap.typ b/poster/sections/2_cap.typ new file mode 100644 index 0000000..3ffcb53 --- /dev/null +++ b/poster/sections/2_cap.typ @@ -0,0 +1,19 @@ +#let title = "Capabilities" + +// what is a capability in general? +// +// what is a twizzler capability? +// +// keypairs!? why?? +// (to ensure that noone can just tamper with a capability on disk and +// get away with it.) +// +// verifying key +// signing key +// +// +// figure of what a capability looks like + +#lorem(200) + + diff --git a/poster/sections/3_sec_ctx.typ b/poster/sections/3_sec_ctx.typ new file mode 100644 index 0000000..9c04869 --- /dev/null +++ b/poster/sections/3_sec_ctx.typ @@ -0,0 +1,10 @@ +#let title = "Security Contexts" + +// what is a security context +// +// figure of what a security context looks like... + + +#lorem(200) + + diff --git a/poster/sections/4_execution.typ b/poster/sections/4_execution.typ new file mode 100644 index 0000000..3a713fa --- /dev/null +++ b/poster/sections/4_execution.typ @@ -0,0 +1,13 @@ +#let title = "System At Work" + +// ok show an example of the system at work, what exactly is done +// to map it in, and then run... +// +// key point is that once access is set up, the process +// does not have to interact with the kernel to read/write to the file. + + +// THE main point is that there is no kernel involvement in the datapath, +// but we still uphold security!! + +#lorem(200) diff --git a/poster/sections/5_future.typ b/poster/sections/5_future.typ new file mode 100644 index 0000000..3f2ff7c --- /dev/null +++ b/poster/sections/5_future.typ @@ -0,0 +1,5 @@ +#let title = "Future Work" + +// dude just look at the fucking grant proposal lmfao + +#lorem(200) diff --git a/poster/sections/6_cited.typ b/poster/sections/6_cited.typ new file mode 100644 index 0000000..3d630b1 --- /dev/null +++ b/poster/sections/6_cited.typ @@ -0,0 +1,4 @@ +#let title = "Works Cited" + +#bibliography("../../refs.bib", full: true, title: none) + diff --git a/poster/sections/cap.typ b/poster/sections/cap.typ deleted file mode 100644 index 0f918fc..0000000 --- a/poster/sections/cap.typ +++ /dev/null @@ -1,5 +0,0 @@ -#let title = "Capabilities" - -#lorem(200) - - diff --git a/poster/sections/cited.typ b/poster/sections/cited.typ deleted file mode 100644 index 032caf1..0000000 --- a/poster/sections/cited.typ +++ /dev/null @@ -1,2 +0,0 @@ -#let title = "Works Cited" -#lorem(200) diff --git a/poster/sections/execution.typ b/poster/sections/execution.typ deleted file mode 100644 index 09079bf..0000000 --- a/poster/sections/execution.typ +++ /dev/null @@ -1,2 +0,0 @@ -#let title = "System At Work" -#lorem(200) diff --git a/poster/sections/future.typ b/poster/sections/future.typ deleted file mode 100644 index 9bbf068..0000000 --- a/poster/sections/future.typ +++ /dev/null @@ -1,2 +0,0 @@ -#let title = "Future Work" -#lorem(200) diff --git a/poster/sections/sec_ctx.typ b/poster/sections/sec_ctx.typ deleted file mode 100644 index e124a3d..0000000 --- a/poster/sections/sec_ctx.typ +++ /dev/null @@ -1,2 +0,0 @@ -#let title = "Security Contexts" -#lorem(200) diff --git a/poster/sections/twizzler.typ b/poster/sections/twizzler.typ deleted file mode 100644 index 436e9bc..0000000 --- a/poster/sections/twizzler.typ +++ /dev/null @@ -1,4 +0,0 @@ -#let title = "What is Twizzler?" -#lorem(200) - - diff --git a/thesis/main.typ b/thesis/main.typ index 81d353d..f4f9377 100644 --- a/thesis/main.typ +++ b/thesis/main.typ @@ -2,8 +2,6 @@ #show: mol-thesis - - #mol-titlepage( // title: "Design, Implementation, and Verification of a Security System for Data-Centric Operating Systems", title: "Twizzler-Security\nA Capability-Based Security System for Twizzler", @@ -13,13 +11,13 @@ birth-place: "Alice Springs, Australia", defence-date: "August 28, 2005", /* Only one supervisor? The singleton array ("Dr Jack Smith",) needs the - trailing comma. */ + trailing comma. */ supervisors: ("Owen B. Arden",), committee: ( "Dr. Peter Alvaro", "Dr. Andi Quinn", ), - degree: "Computer Engineering B.S." + degree: "Computer Engineering B.S.", ) // DANIEL feedback @@ -31,19 +29,16 @@ // more feedback throughout, feel free to take or ignore #mol-abstract[ -Traditional operating systems permit data access through the kernel, applying -security policy as a part of that pipeline. The Twizzler operating system flips -that relationship on its head, focusing on an approach where data access is a -first-class citizen, getting rid of the kernel as a middleman. This -data-centric approach requires us to rethink how security policy interacts with -users and the kernel. In this thesis, I present the design and implementation of -core security primitives in Twizzler. Then I evaluate the security model with -microbenchmarks of core security operations, and ways to increase performace. -Lastly, I discuss a few things we plan to do in the continuation of this work, as -its not conplete by any means. -// Lastly, I discuss future work built -// off this thesis, such as the incorporation of Decentralized Information Flow -// Control. + Traditional operating systems permit data access through the kernel, applying + security policy as a part of that pipeline. The Twizzler operating system flips + that relationship on its head, focusing on an approach where data access is a + first-class citizen, getting rid of the kernel as a middleman. This + data-centric approach requires us to rethink how security policy interacts with + users and the kernel. In this thesis, I present the design and implementation of + core security primitives in Twizzler. Then I evaluate the security model with + micro benchmarks of core security operations, and ways to increase performance. + Lastly, I discuss a few things we plan to do in the continuation of this work, as + its not complete by any means. ] diff --git a/thesis/template.typ b/thesis/template.typ index 7b47776..97d501e 100644 --- a/thesis/template.typ +++ b/thesis/template.typ @@ -30,7 +30,7 @@ #set heading(numbering: "1.1.1.1") #set outline.entry(fill: repeat(". ")) #show outline.entry.where( - level: 1 + level: 1, ): set block(above: 1.5em) #show outline.entry.where(level: 1): it => [ #set block(above: 1.5em) @@ -57,8 +57,9 @@ "Dr Jack Smith", "Prof Dr Jane Williams", "Dr Jill Jones", - "Dr Albert Heijn"), - degree: "MSc in Logic" + "Dr Albert Heijn", + ), + degree: "MSc in Logic", ) = align(alignment.center)[ // Size of the thesis's title #let title-size = 17pt @@ -81,11 +82,10 @@ *#author* - under the supervision of #supervisors.map(x => [*#x*]).join(", ", last: - " and "), and submitted to the + under the supervision of #supervisors.map(x => [*#x*]).join(", ", last: " and"), and submitted to the - Examinations Board in partial fulfilment of the requirements for the - degree of + Examinations Board in partial fulfillment of the requirements for the + degree of #text([*#degree*], size: subtitle-size) @@ -93,23 +93,19 @@ #v(50pt) - #box(width: 75%, - columns(2, gutter: -10%, - align(alignment.left, [ - #set par(first-line-indent: 0em) + #box(width: 75%, columns(2, gutter: -10%, align(alignment.left, [ + #set par(first-line-indent: 0em) - // *Date of the public defence:* + // *Date of the public defence:* - // _#defence-date _ + // _#defence-date _ - #colbreak() + #colbreak() - *Members of the Thesis Committee:* + *Members of the Thesis Committee:* - #committee.join("\n") - ]) - ) - ) + #committee.join("\n") + ]))) // #align(bottom, image("../img/illclogo.svg", alt: "ILLC Logo. A 3-by-3 jigsaw puzzle. The // center piece is white, while the surrounding pieces are black. The text @@ -122,7 +118,11 @@ // A non-numbered page dedicated to the thesis abstract. #let mol-abstract(body) = [ #set page(numbering: none) - #align(center+horizon, heading("Abstract", numbering: none, outlined: false)) + #align(center + horizon, heading( + "Abstract", + numbering: none, + outlined: false, + )) #body #pagebreak() #counter(page).update(1) @@ -132,10 +132,7 @@ #let mol-chapter(body) = [ #pagebreak() #hide( - heading(body, - hanging-indent: 0pt, - level: 1, - supplement: [Chapter]) + heading(body, hanging-indent: 0pt, level: 1, supplement: [Chapter]), ) #text(size: 28pt, weight: "bold")[ #set par(first-line-indent: 0pt) @@ -147,49 +144,49 @@ // A counter for mathematical blocks #let mathcounter = rich-counter( identifier: "mathblocks", - inherited_levels: 1 + inherited_levels: 1, ) // A block for mathematical definitions #let definition = mathblock( blocktitle: "Definition", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical theorems #let theorem = mathblock( blocktitle: "Theorem", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical examples #let example = mathblock( blocktitle: "Example", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical propositions #let proposition = mathblock( blocktitle: "Proposition", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical lemmas #let lemma = mathblock( blocktitle: "Lemma", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical corollaries #let corollary = mathblock( blocktitle: "Corollary", - counter: mathcounter + counter: mathcounter, ) // A block for mathematical remarks #let remark = mathblock( blocktitle: "Remark", - prefix: [_Remark._] + prefix: [_Remark._], ) // A block for mathematical proofs @@ -199,20 +196,20 @@ // This allows you to invoke it once per file in your thesis. This is important, // because Typst would otherwise raise an error if you were to cite a source in // a file with no bibliography. -// +// // https://forum.typst.app/t/how-to-share-bibliography-in-a-multi-file-setup/1605/9 -// +// // If invoked with "true", it actually displays the bibliography. -// +// // ```typst // // main.typ // #include "chapter-1.typ" // #load-bib(read("works.bib"), main: true) // ``` -// +// // Otherwise, it still makes the sources citable in the current file. Should be // invoked with "true" at most once. -// +// // ```typst // // chapter-1.typ // We build on the work of @Author_2025. @@ -222,8 +219,10 @@ counter("illc-mol-thesis-bibs").step() context if main { [#bibliography(bytes(sources)) ] - } else if (counter("illc-mol-thesis-bibs").get().first() == 1 and - query() == ()) { + } else if ( + counter("illc-mol-thesis-bibs").get().first() == 1 + and query() == () + ) { // This is the first bibliography, and there is no main bibliography bibliography(bytes(sources)) }