This thesis reports on joint research with Michael Rabin. Issues of operating system security occupy a central role in applied computer science; yet there has been no satisfactory complete solution to the problem of computer security. In the Security Toolkit Project we have developed a number of novel interlocking techniques which can be combined in many ways to provide tremendously enhanced security. The security toolkit, ITOSS, uses little overhead and is flexible; a security engineer can tailor a particular configuration to exactly satisfy the security needs demanded by the organizational structure at the site. It opens the way for further experimental work, rapid development, and simulation of new security schemes. The project consists of four phases: creating a new model of security, implementing the model by modifying UNIX (4.2 BSD) on a SUN-2 computer, inventing new algorithmic fences to validate the software by insuring that security violations are computationally infeasible, and developing software to permit easy exploitation of ITOSS’s features.