Towards Dynamic Component Isolation in a Service Oriented Platform - ERODS Accéder directement au contenu
Communication Dans Un Congrès Année : 2009

Towards Dynamic Component Isolation in a Service Oriented Platform

Résumé

When dealing with dynamic component environments such as the OSGi Service Platform, where components can come from different sources and may be known only during runtime, evaluating third party components trustworthiness at runtime is difficult. The traditional namespace based isolation and the security mechanisms provided in the Java platform (the base platform for OSGi) can restrict the access of such components but can not provide fault isolation. In this paper we present a dynamic component isolation approach for the OSGi platform, based on a recently standardized Java mechanism. When an untrusted component is activated during runtime, it is isolated in a fault contained environment but it can still collaborate with the application. If it is observed that the untrusted code does not bring any threat to the application, at runtime it can be dynamically promoted to the safe environment. Tests have been performed in a controlled environment where misbehaving components hosted in the sandbox were not able to disturb the main application.

Dates et versions

hal-00941714 , version 1 (04-02-2014)

Identifiants

Citer

Kiev Gama, Didier Donsez. Towards Dynamic Component Isolation in a Service Oriented Platform. Component-Based Software Engineering - 12th International Symposium, CBSE 2009, Jun 2009, East Stroudsburg, PA, United States. pp.104-120, ⟨10.1007/978-3-642-02414-6_7⟩. ⟨hal-00941714⟩
69 Consultations
0 Téléchargements

Altmetric

Partager

Gmail Facebook X LinkedIn More