An Efficient Security Verification Method for Programs with Stack Inspection
An Efficient Security Verification Method for Programs with Stack Inspection
复制标题
DOI:
10.11309/jssst.19.176
复制
发表时间:
2002
期刊:
影响因子:
--
通讯作者:
直也 新田;喜朗 高田;浩之 関
中科院分区:
文献类型:
--
作者:
直也 新田;喜朗 高田;浩之 関
Stack inspection is a simple but sufficiently practical access control technology, which is provided by Java development kit 1.2 (JDK1. 2)[10]. In the JDK1. 2 environment, every method belongs to one of the protection domains, and each protection domain is granted several permissions. If a method m belongs to a protection domain d and d is granted a permission p, then we simply say m has permission p. If the method checkPermission (p) with a permission p as an actual argument is invoked from a method m, then JDK1. 2 examines not only whether the method m has p but also whether every ancestor method which directly or indirectly invokes m have p. If all those methods have p, then the execution continues. Otherwise, the execution is aborted. The runtime control stack (or simply, stack) consists of frames for the active method and its ancestor methods. A frame for a method m contains the protection domain which m belongs to as well as actual arguments, local variables and the return address for m. The stack is inspected by checkPermission (p) from the top (the active method) to the bottom to examine whether the above mentioned condition is met; if a method which does not have p is encountered, then the execution is aborted. If the stack bottom or a method with a particular mode (called privileged) is encoun-