DocumentCode
2554512
Title
Sharing Mobile Code Securely with Information Flow Control
Author
Arden, O. ; George, M.D. ; Liu, Jiangchuan ; Vikram, K. ; Askarov, Aslan ; Myers, A.C.
fYear
2012
fDate
20-23 May 2012
Firstpage
191
Lastpage
205
Abstract
Mobile code is now a nearly inescapable component of modern computing, thanks to client-side code that runs within web browsers. The usual tension between security and functionality is particularly acute in a mobile-code setting, and current platforms disappoint on both dimensions. We introduce a new architecture for secure mobile code, with which developers can use, publish, and share mobile code securely across trust domains. This architecture enables new kinds of distributed applications, and makes it easier to reuse and evolve code from untrusted providers. The architecture gives mobile code considerable expressive power: it can securely access distributed, persistent, shared information from multiple trust domains, unlike web applications bound by the same-origin policy. The core of our approach is analyzing how flows of information within mobile code affect confidentiality and integrity. Because mobile code is untrusted, this analysis requires novel constraints on information flow and authority. We show that these constraints offer principled enforcement of strong security while avoiding the limitations of current mobile-code security mechanisms. We evaluate our approach by demonstrating a variety of mobile-code applications, showing that new functionality can be offered along with strong security.
Keywords
Internet; codes; mobile computing; security of data; trusted computing; Web applications; Web browsers; information flow control; mobile code sharing; mobile-code security mechanisms; mobile-code setting; modern computing; same-origin policy; secure mobile code; trust domains; Authorization; Computer architecture; Fabrics; Libraries; Mobile communication; Social network services; distributed systems; evolution; information flow; mobile code; programming languages; security;
fLanguage
English
Publisher
ieee
Conference_Titel
Security and Privacy (SP), 2012 IEEE Symposium on
Conference_Location
San Francisco, CA
ISSN
1081-6011
Print_ISBN
978-1-4673-1244-8
Electronic_ISBN
1081-6011
Type
conf
DOI
10.1109/SP.2012.22
Filename
6234413
Link To Document