On-Device Control Flow Verification For Java Programs

ESSoS'11: Proceedings of the Third international conference on Engineering secure software and systems(2011)

引用 3|浏览52
暂无评分
摘要
While mobile devices have become ubiquitous and generally multi-application capable, their operating systems provide few high level mechanisms to protect services offered by application vendors against; potentially hostile applications coexisting on the device. In this paper, we tackle the issue of controlling application interactions including collusion in Java-based systems running on open, constrained devices such as smart cards or mobile phones. We present; a model specially designed to be embedded in constrained devices to verify on-device at loading-time that interactions between applications abide by the security policies of each involved application without resulting in run-time computation overheads; this model deals with application (un)installations and policy changes in an incremental fashion. We sketch the application of our approach and its security enhancements on a multi-application use case for Global Platform/Java Card smart cards.
更多
查看译文
关键词
Smart Card, Security Policy, Java Program, Java Virtual Machine, Call Graph
AI 理解论文
溯源树
样例
生成溯源树,研究论文发展脉络
Chat Paper
正在生成论文摘要