Certificates for mobile code security

Hock Kim Tan, Luc Moreau · 2002

The problem of protecting mobile code from malicious hosts is an important security issue, for which many solutions have been proposed. We describe a method to adapt an existing technique, execution tracing, to enhance its flexibility in deployment for a large scale mobile agent system. This is achieved through the introduction of a trusted third party, the verification server, which undertakes the verification of execution traces on behalf of the platform launching the agent. The server constructs a certificate that testifies to the capability of a particular host platform to undertake the correct execution of a mobile agent. In this sense, the server assumes a role analogous of a Certificate Authority (CA) in a PKI. We briefly discuss the issues associated with such a framework.

Read the paper · More papers on PaperTik