10th IEEE International Symposium on Object and Component-Oriented Real-Time Distributed Computing (ISORC'07)
Security Analysis of the Utilization of Corba Object References as Authorization Tokens
Santorini Island, Greece
May 07-May 09
ISBN: 0-7695-2765-5
In object-oriented real-time computing scenarios, particularly where Corba is used in embedded systems with resource constraints, developers and system architects often utilize Corba object references as authorization tokens. This paper investigates the security of this method in principle, and it presents the results of the analysis of the work and computing effort necessary for a potential attacker to fabricate Corba object references to existing objects for the purpose of illegitimately gaining access to these objects at the instance of seven widely used Corba products.
Citation:
Christoph Becker, Sebastian Staamann, Ralf Salomon, "Security Analysis of the Utilization of Corba Object References as Authorization Tokens," isorc, pp.196-203, 10th IEEE International Symposium on Object and Component-Oriented Real-Time Distributed Computing (ISORC'07), 2007