Extending the Java']Java Virtual Machine to enforce fine-grained security policies in mobile devices

被引:6
|
作者
Ion, Iulia [1 ]
Dragovic, Boris [1 ]
Crispo, Bruno [2 ]
机构
[1] Create Net, Trento, Italy
[2] Univ Trent, I-38100 Trento, Italy
关键词
D O I
10.1109/ACSAC.2007.36
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
The growth of the applications and services market for mobile devices is currently slowed down by the lack of a flexible and reliable security infrastructure. The development and adoption of a new generation of mobile applications depends on the end user's ability to finely manage system security and control application's behavior The virtual execution environment for mobile software and services should support the security needs of users and applications. This paper proposes an extension to the security architecture of the Java Virtual Machine for mobile systems, to support fine-grained policy specification and run-time enforcement. Access control decisions are based on system state, application and system history data, as well as request specific parameters. The prototype implementation is running on desktops, as emulator and on mobile devices, proving the high level of flexibility and security, with excellent performance provided by the extended architecture.
引用
收藏
页码:233 / +
页数:2
相关论文
共 47 条
  • [1] Fine-grained information flow analysis and enforcement in a Java']Java virtual machine
    Chandra, Deepak
    Franz, Michael
    [J]. TWENTY-THIRD ANNUAL COMPUTER SECURITY APPLICATIONS CONFERENCE, PROCEEDINGS, 2007, : 463 - 474
  • [2] CONSCRIPT: Specifying and Enforcing Fine-Grained Security Policies for Java']JavaScript in the Browser
    Meyerovich, Leo A.
    Livshits, Benjamin
    [J]. 2010 IEEE SYMPOSIUM ON SECURITY AND PRIVACY, 2010, : SSS - +
  • [3] Coarse grained Java']Java security policies
    Jensen, T
    Le Métayer, D
    Thorn, T
    [J]. OBJECT-ORIENTED TECHNOLOGY: ECOOP'98 WORKSHOP READER, 1998, 1543 : 296 - 296
  • [4] Efficient support of fine-grained futures in Java']Java
    Zhang, Lingli
    Krintz, Chandra
    Soman, Sunil
    [J]. PROCEEDINGS OF THE 18TH IASTED INTERNATIONAL CONFERENCE ON PARALLEL AND DISTRIBUTED COMPUTING AND SYSTEMS, 2006, : 175 - +
  • [5] Fine-grained parallelism in probabilistic parsing with Habanero Java']Java
    Francis-Landau, Matthew
    Xue, Bing
    Eisner, Jason
    Sarkar, Vivek
    [J]. PROCEEDINGS OF 2016 6TH WORKSHOP ON IRREGULAR APPLICATIONS: ARCHITECTURE AND ALGORITHMS (IA3), 2016, : 78 - 81
  • [6] Providing fine-grained access control for Java']Java programs
    Pandey, R
    Hashii, B
    [J]. ECOOP'99 - OBJECT-ORIENTED PROGRAMMING, 1999, 1628 : 449 - 473
  • [7] Java']Java for mobile devices: A security study
    Debbabi, M
    Saleh, M
    Talhi, C
    Zhioua, S
    [J]. 21st Annual Computer Security Applications Conference, Proceedings, 2005, : 210 - 219
  • [8] Capturing policies for fine-grained access control on mobile devices
    Das, Prajit Kumar
    Joshi, Anupam
    Finin, Tim
    [J]. 2016 IEEE 2ND INTERNATIONAL CONFERENCE ON COLLABORATION AND INTERNET COMPUTING (IEEE CIC), 2016, : 54 - 63
  • [9] Consistency Validation Method for Java']Java Fine-Grained Lock Refactoring
    Zhang, Yang
    Li, Chunxia
    Bai, Yu
    [J]. IEEE ACCESS, 2021, 9 : 149287 - 149301
  • [10] Security Enhanced Java']Java: Mandatory Access Control for the Java']Java Virtual Machine
    Venelle, Benjamin
    Briffaut, Jeremy
    Clevy, Laurent
    Toinard, Christian
    [J]. 2013 IEEE 16TH INTERNATIONAL SYMPOSIUM ON OBJECT/COMPONENT/SERVICE-ORIENTED REAL-TIME DISTRIBUTED COMPUTING (ISORC), 2013,