An Efficient Security Verification Method for Programs with Stack Inspection

An Efficient Security Verification Method for Programs with Stack Inspection
复制标题

DOI:
10.11309/jssst.19.176
复制
发表时间:
2002
期刊:
--
影响因子:
--
通讯作者:
直也 新田;喜朗 高田;浩之 関
直也 新田;喜朗 高田;浩之 関
中科院分区:
其他
文献类型:
--
作者:
直也 新田;喜朗 高田;浩之 関

文献摘要

被引文献

相似文献

栈检查是一种简单但足够实用的访问控制技术,由Java开发工具包1.2 (JDK1)提供。2)[10]。在JDK1中。2 .环境中,每个方法属于一个保护域,每个保护域被授予若干权限。如果方法m属于保护域d,并且d被授予权限p,那么我们简单地说m具有权限p。如果从方法m调用具有权限p作为实际参数的方法checkPermission (p),则JDK1。2不仅检查方法m是否有p,而且检查每个直接或间接调用m的祖先方法是否有p。如果所有这些方法都有p,则继续执行。否则,中止执行。运行时控制堆栈(或简称为堆栈)由活动方法及其祖先方法的帧组成。方法m的帧包含m所属的保护域以及m的实际参数,局部变量和返回地址。checkPermission (p)从上到下检查堆栈是否满足上述条件(活动方法);如果遇到不包含p的方法,则中止执行。如果遇到堆栈底部或具有特定模式(称为特权模式)的方法-
Stack inspection is a simple but sufficiently practical access control technology, which is provided by Java development kit 1.2 (JDK1. 2)[10]. In the JDK1. 2 environment, every method belongs to one of the protection domains, and each protection domain is granted several permissions. If a method m belongs to a protection domain d and d is granted a permission p, then we simply say m has permission p. If the method checkPermission (p) with a permission p as an actual argument is invoked from a method m, then JDK1. 2 examines not only whether the method m has p but also whether every ancestor method which directly or indirectly invokes m have p. If all those methods have p, then the execution continues. Otherwise, the execution is aborted. The runtime control stack (or simply, stack) consists of frames for the active method and its ancestor methods. A frame for a method m contains the protection domain which m belongs to as well as actual arguments, local variables and the return address for m. The stack is inspected by checkPermission (p) from the top (the active method) to the bottom to examine whether the above mentioned condition is met; if a method which does not have p is encountered, then the execution is aborted. If the stack bottom or a method with a particular mode (called privileged) is encoun-