Skip to Main content Skip to Navigation
New interface
Conference papers

Supporting the Secure Deployment of OSGi Bundles

Pierre Parrend 1 Stéphane Frénot 1, 2 
1 ARES - Architectures of networks of services
Inria Grenoble - Rhône-Alpes, CITI - CITI Centre of Innovation in Telecommunications and Integration of services
Abstract : The OSGi platform is a lightweight management layer over a Java virtual machine that makes runtime extensi- bility and multi-application support possible in mobile and constraint environments. This powerfull capability opens a particular attack vector against mobile platforms: the in- stallation of malicious OSGi bundles. The first countermea- sure is the digital signature of the bundles. We developed a tool suite that supports the signature, the publication and the validation of the bundles in an OSGi framework. Our tools support the publication of bundles onto a remote bun- dle repository as well as the validation of the signature ac- cording to the OSGi R4 specifications. A comparison of ex- isting validation mechanisms shows that our security layer is the only one that is compliant with the specification.
Complete list of metadata

Cited literature [16 references]  Display  Hide  Download
Contributor : Pierre Parrend Connect in order to contact the contributor
Submitted on : Tuesday, April 22, 2008 - 4:34:06 PM
Last modification on : Friday, February 4, 2022 - 3:11:46 AM
Long-term archiving on: : Thursday, May 20, 2010 - 11:33:23 PM


Files produced by the author(s)


  • HAL Id : inria-00275186, version 1



Pierre Parrend, Stéphane Frénot. Supporting the Secure Deployment of OSGi Bundles. First IEEE WoWMoM Workshop on Adaptive and DependAble Mission- and bUsiness-critical mobile Systems, Jun 2007, Helsinki, Finland. ⟨inria-00275186⟩



Record views


Files downloads