loading...
 This Article 
   
 Share 
   
 Bibliographic References 
   
 Add to: 
 
Digg
Furl
Spurl
Blink
Simpy
Google
Del.icio.us
Y!MyWeb
 
 Search 
   
17th Annual Computer Security Applications Conference (ACSAC'01)
Verifiable Identifiers in Middleware Security
New Orleans, Lousiana
December 10-December 14
ISBN: 0-7695-1405-7
U. Lang, University of Cambridge
D. Gollmann, Microsoft Research
R. Schreiner, ObjectSecurity Ltd.
This paper discusses the difficulties of describing an appropriate notion of the security attributes "caller" and "target" in object-oriented middleware systems such as CORBA. Middleware security needs such security attributes in order to be able to express middleware layer security policies. Our analysis points out that, whilst there is no information available on the ORB layer to describe the caller and taryet, it is possible in practice to use descriptors from other layers. In CORBA security, the mechanism-specific identifiers on the caller side and the information from the object reference on the target side turn out to be most appropriate and trustworthy for describing caller and target application objects at the right granularity. As a proof of concept we mention our MICOSec CORBA security implementation which demonstrates the feasibility of our approach. Our paper shows that it is unrealistic to expect a security service layer to be able to abstract fully from the underlying security mechanisms without implications on granularity and semantic mismatches.
Citation:
U. Lang, D. Gollmann, R. Schreiner, "Verifiable Identifiers in Middleware Security," acsac, pp.0450, 17th Annual Computer Security Applications Conference (ACSAC'01), 2001
Usage of this product signifies your acceptance of the Terms of Use.