Extensible Security Architectures for Java
Report ID:
TR-546-97
Authors:
Date:
March 1997
Pages:
16
Download Formats:
Abstract:
Mobile code technologies such as Java, JavaScript, and ActiveX
generally limit all programs to a single security policy. However,
software-based protection can allow for more flexible security models,
with potentially significant performance improvements over traditional
hardware-based solutions. We describe and analyze three
implementation strategies for interposing flexible security policies
in software-based security systems. Implementations exist for all
three strategies: several vendors have adapted capabilities to Java,
Netscape Communicator extended Java's stack introspection, and we
built a type-hiding system as an add-on to Microsoft Internet Explorer.