Header
Home | Sitemap Set as homepage | Add to favorites
  Search the Site     » Advanced Search
Sections



Assumptions

by

image

Assumptions

The following assumptions contributed to the design of the security mechanism and ensured ample flexibility in its implementation:

  • MIDlets do not need to be aware of the security policy except for security exceptions that may occur when using APIs.

  • A MIDlet suite is subject to a single protection domain and its permissible actions. (See Section 18.3.3, "Protection Domain," for an explanation of protection domains.)

  • The internal representation of protection domains and permissions is implementation specific. (See Section 18.3.1, "Permissions," for an explanation of permissions.)

  • The user interface for presenting configuration settings and the results of authentication attempts to the user is implementation-dependent and outside the scope of the MIDP Specification version 2.0.

  • The device must protect its security policy and its information on protection domains so that they are safe from viewing or modification except by authorized parties.

  • If the security policy for a device is static and disallows use of some functions of the security framework, then the implementation of unused and inaccessible security functions may be removed.

  • Security policy allows an implementation to restrict access but must not be used to avoid implementing security-sensitive functionality. For example, unimplemented protocols under the Generic Connection framework must throw a ConnectionNotFoundException, not a security-related exception


396 times read

Related news

» Trusted MIDlet Suite Security Model
by admin posted on Jul 08,2007
» Recommended Security Policy for GSM/UMTS Devices
by admin posted on Jul 08,2007
» Permissions for Network Connections
by admin posted on Nov 17,2006
» Security of the Push Registry
by admin posted on Jul 08,2007


More Top News
Cisco Wireless Networking
Most Popular
Featured Author