Certificates for mobile code security

  • Authors:
  • Hock Kim Tan;Luc Moreau

  • Affiliations:
  • University of Southampton, Southampton SO17 1BJ, UK;University of Southampton, Southampton SO17 1BJ, UK

  • Venue:
  • Proceedings of the 2002 ACM symposium on Applied computing
  • Year:
  • 2002

Quantified Score

Hi-index 0.00

Visualization

Abstract

The problem of protecting mobile code from malicious hosts is an important security issue, for which many solutions have been proposed. We describe a method to adapt an existing technique, execution tracing, to enhance its flexibility in deployment for a large scale mobile agent system. This is achieved through the introduction of a trusted third party, the verification server, which undertakes the verification of execution traces on behalf of the platform launching the agent. The server constructs a certificate that testifies to the capability of a particular host platform to undertake the correct execution of a mobile agent. In this sense, the server assumes a role analogous of a Certificate Authority (CA) in a PKI. We briefly discuss the issues associated with such a framework.