Businesses and government agencies have longed for an easy-to-use, trusted operating system that's extremely difficult for hackers to crack and limits the damage if they do break in. However, security managers say existing trusted operating systems such as Trusted Solaris and Hewlett-Packard's Virtual Vault are too expensive and often fail to run many applications properly.
"What's unique here is that Palladium won't change the existing Windows environment," says project manager Mario Juarez. Palladium will provide a fenced-off area in which applications can run and documents can be stored without being affected by viruses or hackers. In effect, Microsoft is creating an operating system that's part trusted and part Windows. "There will be a new space for protecting the run-time environment, and security for secure processing, the storing of secrets, and the safe isolation of memory," Juarez says. "Palladium will enable new kinds of security and integrity side by side with Windows."
Juarez says Palladium will create "chains of trust" between Palladium software, a PC's hardware, applications, and documents. Only "trusted" applications, specifically written to take advantage of Palladium's security features, will be permitted to access Palladium applications or documents. As a result, Juarez says, users will be assured that their applications and data won't be destroyed by viruses or their credit-card and personal information hijacked by fraudulent Web sites. In addition, content developers will produce movies, books, and music protected by Palladium.
Palladium won't affect the market for many years. Microsoft must work with hardware developers such as Intel to design the required hardware and convince application developers to start writing software that utilizes Palladium.
Return to main story, "Future Security"
Stay connected and informed by visiting the CA Solutions Center Community!

Become a member today for instant access to free InformationWeek research, expert advice, peer perspectives, and more on the following topics:
- Application Performance Management (APM)
- Security Management
- Mainframe 2.0
- IT Automation
- Service Assurance
Also, visit our Government and Financial Services groups to see how these technologies apply specifically to those industries.
NOTE: Offer valid for U.S., U.S. possessions, & Canada only.