Understanding Java stack inspection

Understanding Java stack inspection
复制标题

了解 Java 堆栈检查

DOI:
10.1109/secpri.1998.674823
复制
发表时间:
1998
期刊:
Proceedings. 1998 IEEE Symposium on Security and Privacy (Cat. No.98CB36186)
影响因子:
--
通讯作者:
E. Felten
E. Felten
中科院分区:
--
文献类型:
--
作者:
D. Wallach;E. Felten

文献摘要

被引文献

相似文献

Java的当前实现通过搜索运行时调用堆栈来做出安全决策。这些系统具有吸引人的安全属性,但它们被批评为依赖于Java实现的特定工件。本文模型的堆栈检查算法在一个很好理解的逻辑访问控制,并演示了堆栈检查是一个有用的工具,表达和管理复杂的信任关系。我们表明,基于堆栈检查的访问控制决策对应的逻辑证明的建设,我们提出了一个有效的决策过程中产生这些证明。通过研究决策过程,我们证明了逻辑中的许多语句是等价的,因此可以用更简单的形式表示。我们表明,有有限数量的这样的语句,使我们能够代表系统的安全状态作为下推自动机。我们还表明,这个自动机可以嵌入在Java中重写所有Java类传递一个额外的参数时,调用一个过程。我们称之为安全传递风格,并描述了它的好处,在以前的堆栈检查系统。最后,我们将展示如何的逻辑,使我们能够描述一个简单的设计扩展堆栈检查跨远程过程调用。
Current implementations of Java make security decisions by searching the runtime call stack. These systems have attractive security properties, but they have been criticized as being dependent on specific artifacts of the Java implementation. The paper models the stack inspection algorithm in terms of a well understood logic for access control and demonstrates how stack inspection is a useful tool for expressing and managing complex trust relationships. We show that an access control decision based on stack inspection corresponds to the construction of a proof in the logic, and we present an efficient decision procedure for generating these proofs. By examining the decision procedure, we demonstrate that many statements in the logic are equivalent and can thus be expressed in a simpler form. We show that there are a finite number of such statements, allowing us to represent the security state of the system as a pushdown automaton. We also show that this automaton may be embedded in Java by rewriting all Java classes to pass an additional argument when a procedure is invoked. We call this security passing style and describe its benefits over previous stack inspection systems. Finally, we show how the logic allows us to describe a straightforward design for extending stack inspection across remote procedure calls.