Namespaces
Variants
Actions

Record store vulnerability in Series 40 (Known Issue)

Jump to: navigation, search
Article Metadata

Tested with
Devices(s): Series 40 devices

Compatibility
Platform(s): Series 40

Article
Created: User:Technical writer 1 (29 May 2008)
Last edited: hamishwillee (05 Jul 2012)

Overview

In Series 40 devices using MIDP 2.0, files stored in Record Management System can be accessed via external tools, such as a PC.

Description

In MIDP 2.0, the RMS record stores were designed to be robust/secure from a MIDlet-to-MIDlet perspective. Using authorization mode it is possible to determine whether other MIDlet suites have access to the record store.

However, the defined security design does not make RMS record stores safe against other forms of external access. RMS uses file store and was not designed to be secure against access tools which can be used via PC to access files containing discreet data, such as DRM keys.

Solution

Avoid using RMS record stores for storing sensitive data, such as DRM keys, with Series 40 devices using MIDP 2.0 and 2.1.

To improve the described RMS security deficiency with MIDP 2.0, the upcoming MIDP 3.0 specifies RMS encryption control.

This page was last modified on 5 July 2012, at 09:19.
68 page views in the last 30 days.
Nokia Developer aims to help you create apps and publish them so you can connect with users around the world.

京ICP备05048969号  © Copyright Nokia 2013 All rights reserved