首页> 外文会议>Future Internet Symposium >Security-By-Contract for the Future Internet
【24h】

Security-By-Contract for the Future Internet

机译:对未来互联网的安全性

获取原文

摘要

With the advent of the next generation java servlet on the smartcard, the Future Internet will be composed by web servers and clients silently yet busily running on high end smart cards in our phones and our wallets. In this brave new world we can no longer accept the current security model where programs can be downloaded on our machines just because they are vaguely "trusted". We want to know what they do in more precise details. We claim that the Future Internet needs the notion of security-by-contract: In a nutshell, a contract describes the security relevant interactions that the smart internet application could have with the smart devices hosting them. Compliance with contracts should verified at development time, checked at depolyment time and contracts should be accepted by the platform before deployment and possibly their enforcement guaranteed, for instance by in-line monitoring. In this paper we describe the challenges that must be met in order to develop a security-by-contract framework for the Future Internet and how security research can be changed by it.
机译:随着智能卡上的下一代Java Servlet的出现,未来的互联网将由Web服务器和客户端默默地繁忙,但在我们的手机和我们的钱包中的高端智能卡上繁忙地运行。在这个勇敢的新世界中,我们无法再接受目前可以在我们的机器上下载计划的安全模型,因为它们是模糊的“可信赖”。我们想知道他们在更精确的细节中做了什么。我们声称未来的互联网需要签订安全的概念:简而言之,合同描述了智能互联网应用程序可能拥有托管它们的智能设备的安全相关交互。应在开发时间核对合同,在呼吸时间和合同应在部署前应接受合同,并且可能在线监测担保,可能是其执法。在本文中,我们描述了必须满足的挑战,以便为未来的互联网制定一份备份框架以及如何改变安全性研究。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号