计算机应用 ›› 2005, Vol. 25 ›› Issue (05): 1163-1165.DOI: 10.3724/SP.J.1087.2005.1163

• 信息安全 • 上一篇    下一篇

一种新的移动Agent保护方案研究与设计

杨欣,沈建京,王世军   

  1. 信息工程大学理学院
  • 出版日期:2005-05-01 发布日期:2005-05-25

Research and design of a new mobile agent protection scheme

YANG Xin, SHEN Jian-jing, WANG Shi-jun   

  1. Institute of Science, Information Engineering University, Zhengzhou Henan 450001, China
  • Online:2005-05-01 Published:2005-05-25

摘要: 随着移动Agent技术在分布式计算中的应用,移动Agent系统在安全和软件工程两方面面临着巨大的挑战。为了防止恶意或未授权的第三方实体的攻击,研究了保护移动Agent数据和代码的方法。设计了一种全新的移动Agent结构,由封装了所有要在特定主机平台上执行的代码的数据和负责传送并处理这些数据的显示代码构成,这种数据代码分离结构与其他已有的移动Agent结构互不影响,因而提高了移动Agent平台之间的互操作性。同时描述了公钥解密和Agent验证机制,实现了保护数据免受篡改代码引起的攻击,以及通过进一步改进数据的结构,实现了保护代码免受注入恶意数据引起的攻击。

关键词:  , 移动Agent, 安全, 互操作, 密码服务

Abstract: With the application of mobile agent technology in distributed computing, mobile agent systems encounter numerous security and software engineering challenges. To prevent malicious or unauthorized attacks from the third party entities, the method of protection of agent’s data and code was investigated, and a new mobile agent’s architecture was designed, which was composed of data wrapping all executable code intended for a given platform and explicit agent code in charge of transporting and handling the above data. The data-code split could co-exist with other architectures already proposed to improve platform interoperability. Finally, to protect data from agent’s code modification, public key decryption mechanism and agent authentication mechanism was analyzed. To protect code from injection of malicious data, data protection mechanism was proposed by improving the structure of data.

Key words: mobile agent, security, interoperability, cryptography service

中图分类号: