Supporting the Secure Deployment of OSGi Bundles - Inria - Institut national de recherche en sciences et technologies du numérique Accéder directement au contenu
Communication Dans Un Congrès Année : 2007

Supporting the Secure Deployment of OSGi Bundles

Résumé

The OSGi platform is a lightweight management layer over a Java virtual machine that makes runtime extensi- bility and multi-application support possible in mobile and constraint environments. This powerfull capability opens a particular attack vector against mobile platforms: the in- stallation of malicious OSGi bundles. The first countermea- sure is the digital signature of the bundles. We developed a tool suite that supports the signature, the publication and the validation of the bundles in an OSGi framework. Our tools support the publication of bundles onto a remote bun- dle repository as well as the validation of the signature ac- cording to the OSGi R4 specifications. A comparison of ex- isting validation mechanisms shows that our security layer is the only one that is compliant with the specification.
Fichier principal
Vignette du fichier
parrend07adamus.pdf (267.89 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)
Loading...

Dates et versions

inria-00275186 , version 1 (22-04-2008)

Identifiants

  • HAL Id : inria-00275186 , version 1

Citer

Pierre Parrend, Stéphane Frénot. Supporting the Secure Deployment of OSGi Bundles. First IEEE WoWMoM Workshop on Adaptive and DependAble Mission- and bUsiness-critical mobile Systems, Jun 2007, Helsinki, Finland. ⟨inria-00275186⟩
104 Consultations
328 Téléchargements

Partager

Gmail Facebook X LinkedIn More