Roger Schell and Steve Lipner
Abstract
Two men who met over the security of Multics in the early 1970s went on to represent the two answers computer security has produced to the question of how to make software trustworthy. Roger Schell, an Air Force officer with an MIT doctorate, led the 1974 evaluation that broke Multics, championed the security kernel, was the founding deputy director of the National Computer Security Center and the principal author of its Orange Book (1983), which defined the classes from C1 to A1 and demanded mathematical proof for the top one; he then built an A1 system, GEMSOS, that almost nobody bought. Steve Lipner, a MITRE analyst who ran Digital’s A1 kernel project until it was cancelled in 1990, concluded that assurance had to be built into how ordinary products were made, and at Microsoft after 2002 created the Security Development Lifecycle, the process behind every Windows release since. Schell’s approach produced systems that were provably secure and commercially dead; Lipner’s produced systems that were commercially alive and measurably less broken. The field runs on the second and still cites the first.
Multics
Schell was born in Richey, Montana, took an electrical-engineering degree at Montana State through the ROTC, a master’s at Washington State in 1963, and, sent by the Air Force to MIT, a doctorate in 1971 with a thesis on dynamic reconfiguration in Multics, the time-sharing system that was the era’s most serious attempt at a secure operating system (see The Multics Story). Back at the Electronic Systems Division at Hanscom Field he was given a second lieutenant named Paul Karger and a dispute: the Air Force wanted Multics hardened before it ran the Pentagon’s data centre, and Honeywell said it was secure enough. Karger and Schell’s Multics Security Evaluation: Vulnerability Analysis (1974) found ways through the hardware, the software and the procedures, and, in an appendix, described a compiler that inserted a trapdoor into itself, the idea Ken Thompson rebuilt for his 1984 Turing lecture. The report’s other conclusion became Schell’s career: a system could be trusted only if the part that enforced security was small enough to be verified. That part was the security kernel, and the design principle of a reference monitor that mediates every access, tamper-proof, always invoked and small enough to check, is the one he has argued for since.
Lipner took bachelor’s and master’s degrees at MIT and joined MITRE, the Air Force’s systems contractor, where he worked on the same problems from the other side of the table, and where he remembered Karger arriving as a young officer. In 1981, the night after the IEEE security symposium, he and Karger conceived in a Palo Alto restaurant the project Lipner would run at Digital Equipment for the rest of the decade.
The Orange Book
Work on a standard for evaluating secure systems began at the Department of Defense in 1979, and Schell, by then a colonel, was the founding deputy director of the National Computer Security Center at the NSA when it published the Trusted Computer System Evaluation Criteria on August 15, 1983, orange-covered, and reissued as a DoD standard in December 1985. It sorted systems into divisions: D for those that failed, C1 and C2 for discretionary access control and audit, B1 to B3 for mandatory labels and a structured kernel, and A1, which required the B3 design plus a formal top-level specification and a mathematical proof that it satisfied the security model. The classes became the vocabulary of the field and of procurement; Multics with mandatory controls was rated B2 in 1985, Windows NT reached C2 in the 1990s, and three systems ever reached A1. Schell is called the father of the Orange Book. He left the Air Force in 1984 and co-founded Gemini Computers, whose GEMSOS kernel on Intel hardware was one of the A1 systems, evaluated in 1994 after ten years; he later managed security development at Novell and founded Aesec, which still sells GEMSOS. He taught at the Naval Postgraduate School and the University of Southern California, and was inducted into the Cyber Security Hall of Fame in 2012.
The VAX Kernel
Lipner joined Digital in 1981 and for eleven years ran security products, above all the VAX Security Kernel: a virtual-machine monitor on the VAX built to the A1 standard, with Karger as its technical authority, that ran unmodified VMS and Ultrix in labelled virtual machines and stayed up for weeks in customer field tests. Digital cancelled it on March 1, 1990, before evaluation, for reasons it never published; the technical story is in Paul Karger: Mr High Assurance. Lipner’s conclusion was the one the cancellation taught: a decade of proof-grade engineering had produced a product the market would not wait for, and the systems people actually ran, which were none of the evaluated ones, needed a different kind of help. He served on the government’s Computer System Security and Privacy Advisory Board from its creation in 1989, ran the Gauntlet firewall business at Trusted Information Systems through its 1996 IPO, and spent the late 1990s at Mitretek.
The Security Development Lifecycle
He joined Microsoft in 1999 to run the Microsoft Security Response Center, the group that handled reported vulnerabilities, at the moment the company’s software became the most attacked in the world. The worms of 2001, Code Red and Nimda, and Bill Gates’s Trustworthy Computing memo of January 15, 2002, gave him the mandate; his answer was the security push, in which the Windows Server 2003 team, about 8,000 engineers, stopped feature work for two months, was trained in secure coding, and audited its own code. The push became a process. The Security Development Lifecycle, mandatory for Microsoft products from 2004, put security into every phase: threat modelling of the design, banned functions and static analysis in the code, fuzzing in test, a final security review before release, and a plan for the response afterwards. Lipner and Michael Howard published it as a book in 2006, and it became the template that other vendors, and eventually regulators, copied; the measurable result was that the number of vulnerabilities in each Windows release fell while the number of attackers rose. The larger history is in Secure by Design.
He retired from Microsoft in 2015 as partner director of software security, became executive director of SAFECode, the industry group for software assurance, and was elected to the National Academy of Engineering in 2017 and to the National Cybersecurity Hall of Fame in 2015. He is named on twelve US patents.
Two Answers
Schell’s position, stated in papers and talks for fifty years, is that everything since the Orange Book has been a retreat: that “secure by design” without a verified kernel is a slogan, that the Common Criteria which replaced the TCSEC in 2005 let vendors choose what to be evaluated against, and that the industry knows how to build systems that cannot be subverted and chooses not to. Lipner’s position is that the systems people use will be large, will be written by ordinary engineers, and will ship on a schedule, and that the job is to make those systems as secure as that permits, which turns out to be a great deal more than anyone had managed before. Karger and Schell’s 2002 retrospective, Thirty Years Later, found that the vulnerabilities of 1974 were all still present in 2002; the SDL was the industry’s answer to the same finding. The argument between the two views is the argument of the field.
📚 Sources
- Roger R. Schell — Wikipedia
- Karger, Paul A. and Roger R. Schell — Multics Security Evaluation: Vulnerability Analysis, ESD-TR-74-193 Vol. II, June 1974
- Karger, Paul A. and Roger R. Schell — “Thirty Years Later: Lessons from the Multics Security Evaluation”, ACSAC 2002
- Trusted Computer System Evaluation Criteria — Wikipedia (the 1983 and 1985 dates, the divisions, the A1 systems, the Common Criteria replacement)
- Steven B. Lipner — ACSAC 2004 Distinguished Practitioner biography (MIT degrees, the advisory board from 1989, TIS and the 1996 IPO, the 8,000-engineer Windows security review)
- Steven B. Lipner — biography, NIST Information Security and Privacy Advisory Board (retirement from Microsoft in 2015, SAFECode, the NAE in 2017, the Cybersecurity Hall of Fame in 2015, twelve patents)
- Howard, Michael and Steve Lipner — The Security Development Lifecycle, Microsoft Press, 2006
- Karger, Paul A. et al. — “A Retrospective on the VAX VMM Security Kernel”, IEEE Transactions on Software Engineering 17(11), November 1991
- Oral history interview with Roger R. Schell — Charles Babbage Institute, May 1, 2012, interviewed by Jeffrey R. Yost