Symbian OS Platform Security: Software Development Using the Symbian OS Security Architecture (Paperback)

Craig Heath

  • 出版商: Wiley
  • 出版日期: 2006-04-01
  • 定價: $2,250
  • 售價: 1.8$399
  • 語言: 英文
  • 頁數: 274
  • 裝訂: Paperback
  • ISBN: 0470018828
  • ISBN-13: 9780470018828
  • 相關分類: 資訊安全
  • 立即出貨(限量) (庫存=4)

買這商品的人也買了...

商品描述

Description

Symbian OS is an advanced, customizable operating system, which is licensed by the world's leading mobile phone manufacturers. The latest versions incorporate an enhanced security architecture designed to protect the interests of consumers, network operators and software developers.

The new security architecture of Symbian OS v9 is relevant to all security practitioners and will influence the decisions made by every developer that uses Symbian OS in the creation of devices or add-on applications. Symbian OS Platform Security covers the essential concepts and presents the security features with accompanying code examples.

This introductory book highlights and explains:
* the benefits of platform security on mobile devices
* key concepts that underlie the architecture, such as the core principles of 'trust', 'capability' and data 'caging'
* how to develop on a secure platform using real-world examples
* an effective approach to writing secure applications, servers and plug-ins, using real-world examples
* how to receive the full benefit of sharing data safely between applications
* the importance of application certification and signing from the industry 'gatekeepers' of platform security
* a market-oriented discussion of possible future developments in the field of mobile device security

 

Table of Contents

About This Book.

Foreword.

About the Authors.

Author’s Acknowledgements.

Symbian Press Acknowledgements.

Part 1 Introduction to Symbian OS Platform Security.

1 Why a Secure Platform?

1.1 User Expectations of Mobile Phone Security.

1.2 What the Security Architecture Should Provide.

1.3 Challenges and Threats to Mobile Phone Security.

1.4 How Symbian OS Platform Security Fits into the Value Chain.

1.5 How Application Developers Benefit from the Security Architecture.

2 Platform Security Concepts.

2.1 Background Security Principles.

2.2 Architectural Goals.

2.3 Concept 1: The Process is the Unit of Trust.

2.4 Concept 2: Capabilities Determine Privilege.

2.5 Concept 3: Data Caging for File Access.

2.6 Summary.

viii CONTENTS

Part 2 Application Development for Platform Security.

3 The Platform Security Environment.

3.1 Building Your Application.

3.2 Developing on the Emulator.

3.3 Packaging Your Application.

3.4 Testing on Mobile Phone Hardware.

3.5 Summary.

4 How to Write Secure Applications.

4.1 What Is a Secure Application?

4.2 Analyzing the Threats.

4.3 What Countermeasures Can Be Taken?

4.4 Implementation Considerations.

4.5 Summary.

5 How to Write Secure Servers.

5.1 What Is a Secure Server?

5.2 Server Threat Modeling.

5.3 Designing Server Security Measures.

5.4 Server Implementation Considerations.

5.5 Summary.

6 How to Write Secure Plug-ins.

6.1 What Is a Secure Plug-In?

6.2 Writing Secure Plug-ins.

6.3 Plug-in Implementation Considerations.

6.4 Summary.

7 Sharing Data Safely.

7.1 Introduction to Sharing Data.

7.2 Categories of Data.

7.3 Deciding the Level of Trust.

7.4 Attacks on Data and Countermeasures.

7.5 Using System Services.

7.6 Summary.

Part 3 Managing Platform Security Attributes.

8 Native Software Installer.

8.1 Introduction to the Native Software Installer.

8.2 Validating Capabilities.

8.3 Identifiers, Upgrades, Removals and Special Files.

8.4 SIS File Changes for Platform Security.

8.5 Installing to and from Removable Media.

8.6 Summary.

9 Enabling Platform Security.

9.1 Responsibilities in Granting Capabilities.

9.2 Overview of the Signing Process.

9.3 Step-by-step Guide to Signing.

9.4 Revocation.

9.5 Summary.

Part 4 The Future of Mobile Device Security.

10 The Servant in Your Pocket.

10.1 Crystal-Ball Gazing.

10.2 Convergence, Content and Connectivity.

10.3 Enabling New Services.

10.4 New Security Technologies.

10.5 Summary.

Appendix A Capability Descriptions.

Appendix B Some Cryptography Basics.

Appendix C The Software Install API.

Glossary.

References.

Index.

商品描述(中文翻譯)

Symbian OS是一個先進且可定制的操作系統,由全球領先的手機製造商授權使用。最新版本包含了一個增強的安全架構,旨在保護消費者、網絡運營商和軟件開發人員的利益。

Symbian OS v9的新安全架構對所有安全從業人員都具有相關性,並將影響每個在設備或附加應用程序的創建中使用Symbian OS的開發人員的決策。Symbian OS平台安全涵蓋了基本概念並提供了相應的代碼示例。

這本入門書突出並解釋了以下內容:
- 移動設備平台安全的好處
- 架構的關鍵概念,如“信任”、“能力”和數據“囚禁”
- 如何使用真實世界的示例在安全平台上開發
- 使用真實世界的示例編寫安全應用程序、服務器和插件的有效方法
- 如何安全地在應用程序之間共享數據的重要性
- 應用程序認證和由平台安全的行業“門衛”簽署的重要性
- 關於移動設備安全領域可能的未來發展的市場導向討論

目錄:
- 關於本書
- 前言
- 關於作者
- 作者致謝
- Symbian Press致謝
- 第1部分 Symbian OS平台安全介紹
- 第1章 為什麼需要安全平台?
- 第2章 平台安全概念
- 第2部分 平台安全的應用開發
- 第3章 平台安全環境
- 第4章 如何編寫安全應用程序
- 第5章 如何編寫安全服務器
- 第6章 如何編寫安全插件

以上是對該段文字的翻譯,請注意,由於原文中包含HTML標籤,我已經移除了這些標籤,只提供了純文字的翻譯。