Verifiable Identifiers in Middleware Security

  • Authors:
  • U. Lang;D. Gollmann;R. Schreiner

  • Affiliations:
  • -;-;-

  • Venue:
  • ACSAC '01 Proceedings of the 17th Annual Computer Security Applications Conference
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

This paper discusses the difficulties of describing anappropriate notion of the security attributes "caller"and "target" in object-oriented middleware systemssuch as CORBA. Middleware security needs such securityattributes in order to be able to express middlewarelayer security policies. Our analysis points outthat, whilst there is no information available on theORB layer to describe the caller and taryet, it is possiblein practice to use descriptors from other layers.In CORBA security, the mechanism-specific identifierson the caller side and the information from the objectreference on the target side turn out to be most appropriateand trustworthy for describing caller and targetapplication objects at the right granularity. As a proofof concept we mention our MICOSec CORBA securityimplementation which demonstrates the feasibilityof our approach. Our paper shows that it is unrealisticto expect a security service layer to be able to abstractfully from the underlying security mechanisms withoutimplications on granularity and semantic mismatches.