• DocumentCode
    2360179
  • Title

    Verifiable identifiers in middleware security

  • Author

    Lang, Ulrich ; Gollmann, Dieter ; Schreiner, Rudolf

  • Author_Institution
    Comput. Lab., Cambridge Univ., UK
  • fYear
    2001
  • fDate
    10-14 Dec. 2001
  • Firstpage
    450
  • Lastpage
    459
  • Abstract
    This paper discusses the difficulties of describing an appropriate notion of the security attributes "caller" and "target" in object-oriented middleware systems such as CORBA. Middleware security needs such security attributes in order to be able to express middleware layer security policies. Our analysis points out that, whilst there is no information available on the ORB layer to describe the caller and target, it is possible in practice to use descriptors from other layers. In CORBA security, the mechanism-specific identifiers on the caller side and the information from the object reference on the target side turn out to be most appropriate and trustworthy for describing caller and target application objects at the right granularity. As a proof of concept we mention our MICOSec CORBA security implementation which demonstrates the feasibility of our approach. Our paper shows that it is unrealistic to expect a security service layer to be able to abstract fully from the underlying security mechanisms without implications on granularity and semantic mismatches.
  • Keywords
    distributed object management; security of data; telecommunication security; CORBA; MICOSec; caller security attribute; middleware security; object reference; object-oriented middleware systems; security service layer; target security attribute; verifiable identifiers; Application software; Computer architecture; Computer security; Hardware; Information analysis; Information security; Laboratories; Middleware; Object oriented programming; Terminology;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Computer Security Applications Conference, 2001. ACSAC 2001. Proceedings 17th Annual
  • Print_ISBN
    0-7695-1405-7
  • Type

    conf

  • DOI
    10.1109/ACSAC.2001.991562
  • Filename
    991562