【24h】

JCCAP: CAPABILITY-BASED ACCESS CONTROL FOR JAVA CARD

机译:JCCAP:Java卡的基于能力的访问控制

获取原文
获取外文期刊封面目录资料

摘要

This paper describes JCCap, a protection facility for cooperating applications in the context of Java Card. It enables the control of access rights between mutually suspicious applications, either between one terminal application and one Java Card applet or between two applets hosted inside the same Java Card. Using JCCap, access to objects is controlled by means of software capabilities that can be exchanged between mutually suspicious applications. An important advantage of JCCap is that the definition of the protection policy of an application (i.e., how access rights are granted to other applications) is completely separated from the application code. The protection policy is described in an extended Interface Definition Language (IDL) at the interface level, thus enhancing modularity, separation of concerns, and ease of expression in the design of the overall security architecture. Each application can define its own protection policy independently from the other applications, thus enabling the expression of mutual suspicion without any prior knowledge about the policies of other applications. Every protection policy is then applied when applications interact with each other. This paper describes the implementation of a prototype of JCCap. It shows the feasibility and applicability of this technique in today's Java Card and outline its advantages.
机译:本文介绍了JCCAP,一种用于在Java卡的上下文中协作应用程序的保护设备。它可以控制相互可疑应用程序之间的访问权限,无论是在一个终端应用程序和一个Java卡小程序之间还是在同一Java卡内托管的两个小程序之间。使用JCCAP,通过可以在相互可疑的应用程序之间交换的软件功能来控制对对象的访问。 JCCAP的一个重要优势是应用程序的保护策略的定义(即,访问权限被授予其他应用程序)的定义是完全与应用程序代码分开的。在接口级别的扩展接口定义语言(IDL)中描述了保护策略,从而提高了整体安全架构设计中的模块化,分离和易于表达式。每个应用程序都可以独立地定义自己的保护策略,从其他应用程序中,可以表达相互怀疑,而无需任何关于其他应用程序的政策的先验知识。然后,当应用程序互相交互时,然后应用每个保护策略。本文介绍了JCCAP的原型的实现。它显示了这种技术在当今的Java卡中的可行性和适用性,并概述了其优势。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号