An abstract interpretation-based approach to mobile code safety


Autoria(s): Albert Albiol, Elvira; Puebla Sánchez, Alvaro Germán; Hermenegildo, Manuel V.
Data(s)

30/05/2005

Resumo

Recent approaches to mobile code safety, like proof- arrying code, involve associating safety information to programs. The code supplier provides a program and also includes with it a certifícate (or proof) whose validity entails compliance with a predefined safety policy. The intended benefit is that the program consumer can locally validate the certifícate w.r.t. the "untrusted" program by means of a certifícate checker—a process which should be much simpler, eflicient, and automatic than generating the original proof. We herein introduce a novel approach to mobile code safety which follows a similar scheme, but which is based throughout on the use of abstract interpretation techniques. In our framework the safety policy is specified by using an expressive assertion language defined over abstract domains. We identify a particular slice of the abstract interpretation-based static analysis results which is especially useful as a certifícate. We propose an algorithm for checking the validity of the certifícate on the consumer side which is itself in fact a very simplified and eflicient specialized abstract-interpreter. Our ideas are illustrated through an example implemented in the CiaoPP system. Though further experimentation is still required, we believe the proposed approach is of interest for bringing the automation and expressiveness which is inherent in the abstract interpretation techniques to the área of mobile code safety.

Formato

application/pdf

Identificador

http://oa.upm.es/14613/

Idioma(s)

eng

Publicador

Facultad de Informática (UPM)

Relação

http://oa.upm.es/14613/1/HERME_REFWORKS_2004-2.pdf

http://www.sciencedirect.com/science/article/pii/S1571066105050085

Direitos

http://creativecommons.org/licenses/by-nc-nd/3.0/es/

info:eu-repo/semantics/openAccess

Fonte

roceedings of the 3rd International Workshop on Compiler Optimization Meets Compiler Verification (COCV 2004) | 3rd International Workshop on Compiler Optimization Meets Compiler Verification (COCV 2004) | 3 April 2004 | Barcelona, Spain

Palavras-Chave #Informática
Tipo

info:eu-repo/semantics/conferenceObject

Ponencia en Congreso o Jornada

PeerReviewed