期刊文献+
共找到2篇文章
< 1 >
每页显示 20 50 100
An Access Control Framework for Reflective Middleware 被引量:1
1
作者 黄罡 孙连山 《Journal of Computer Science & Technology》 SCIE EI CSCD 2008年第6期895-904,共10页
Reflective middleware opens up the implementation details of middleware platform and applications at runtime for improving the adaptability of middleware-based systems. However, such openness brings new challenges to ... Reflective middleware opens up the implementation details of middleware platform and applications at runtime for improving the adaptability of middleware-based systems. However, such openness brings new challenges to access control of the middleware-based systems. Some users can access the system via reflective entities, which sometimes cannot be protected by access control mechanisms of traditional middleware. To deliver high adaptability securely, reflective middleware should be equipped with proper access control mechanisms for potential access control holes induced by reflection. One reason of integrating these mechanisms in reflective middleware is that one goal of reflective middleware is to equip applications with reflection capabilities as transparent as possible. This paper studies how to design a reflective J2EE middleware -- PKUAS with access control in mind. At first, a computation model of reflective system is built to identify all possible access control points induced by reflection. Then a set of access control mechanisms, including the wrapper of MBeans and a hierarchy of Java class loaders, are equipped for controlling the identified access control points. These mechanisms together with J2EE access control mechanism form the access control framework for PKUAS. The paper evaluates the security and the performance overheads of the framework in quality and quantity. 展开更多
关键词 reflective middleware access control j2ee
原文传递
构件运行支撑平台反射体系的安全框架设计与实现
2
作者 白佳 黄罡 +3 位作者 刘钊 刘天成 郑子瞻 梅宏 《电子学报》 EI CAS CSCD 北大核心 2004年第F12期207-210,共4页
反射式软件中间件改变了传统中间件纯粹的“黑盒复用”方式 ,以观测和控制基于中间件的软件系统的运行状态和行为 .作为主流的中间件产品 ,构件运行支撑平台有必要引入反射以适应动态开放的Internet环境 .但是 ,在带来更大开放性的同时 ... 反射式软件中间件改变了传统中间件纯粹的“黑盒复用”方式 ,以观测和控制基于中间件的软件系统的运行状态和行为 .作为主流的中间件产品 ,构件运行支撑平台有必要引入反射以适应动态开放的Internet环境 .但是 ,在带来更大开放性的同时 ,反射也给构件运行支撑平台带来安全隐患 .为此 ,针对反射体系的特点 ,本文逐层分析其中潜在的安全隐患 ,制定了一种特定于反射体系的安全框架 ,实现了四层安全访问控制机制 .该安全框架在反射式J2EE应用服务器PKUAS(PekingUniversityApplicationServer)中得到实现 ,并通过性能测试考察了安全框架对反射系统运行时刻性能的影响 . 展开更多
关键词 反射式中间件 构件运行支撑平台 安全 j2ee
下载PDF
上一页 1 下一页 到第
使用帮助 返回顶部