...
首页> 外文期刊>Information Security Technical Report >Secure Mobile Business Applications - Framework, Architecture and Implementation
【24h】

Secure Mobile Business Applications - Framework, Architecture and Implementation

机译:安全的移动业务应用程序-框架,体系结构和实施

获取原文
获取原文并翻译 | 示例

摘要

Emerging mobile technologies such as PDAs, laptops and smart phones together with wireless networking technologies such as WLAN and UMTS promise to empower mobile employees to become better integrated into their companies' business processes. However, the actual uptake of these technologies is still to come; one hindrance is security of mobile devices and applications. In this contribution we present an in-depth analysis of the current situation enterprises are faced with in the mobile arena, both from a security and a management perspective. We argue that the currently predominant model of perimeter security will not scale for future mobile business applications that will require appropriate application-level security mechanisms to be in place. We present a framework offering solutions for the development of secure mobile business applications that takes into account the need for strong security credentials, e.g. based on smart cards. This framework consists of software and abstractions that allow for the separation of the core business logic from the security logic in applications. Security management instruments in the form of enforceable enterprise policies are defined which target the security and trust-related deployment and configuration of mobile devices and business applications. The presented architecture is open, in the sense that the actual mobile business application can span over heterogeneous client devices, forming a so-called federation.
机译:PDA,笔记本电脑和智能手机等新兴移动技术以及WLAN和UMTS等无线网络技术有望使移动员工能够更好地融入其公司的业务流程中。但是,这些技术的实际应用仍将继续。一个障碍是移动设备和应用程序的安全性。在此贡献中,我们从安全和管理的角度对企业在移动领域面临的现状进行了深入分析。我们认为,当前占主导地位的外围安全模型无法扩展到将来的移动业务应用程序中,而未来的移动业务应用程序将需要适当的应用程序级安全机制。我们提出了一个框架,该框架提供了用于开发安全移动业务应用程序的解决方案,其中考虑了对强大安全凭证的需求,例如基于智能卡。该框架由软件和抽象组成,这些软件和抽象允许将核心业务逻辑与应用程序中的安全逻辑分开。定义了可强制执行的企业策略形式的安全管理工具,这些工具针对移动设备和业务应用程序的安全性和与信任相关的部署和配置。在实际的移动业务应用程序可以跨越异构客户端设备的意义上,所形成的架构是开放的,形成了所谓的联合。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号