首页> 外文会议>International Conferece for Internet Technology and Secured Transactions >Role-based Privilege Isolation: A Novel Authorization Model for Android Smart Devices
【24h】

Role-based Privilege Isolation: A Novel Authorization Model for Android Smart Devices

机译:基于角色的特权隔离:Android智能设备的新颖授权模型

获取原文

摘要

Data ex-filtration is a major security concern in smart devices as they often store private and confidential data. Data ex-filtration can potentially lead to identity theft, financial and non-financial risks, and reputation damage for individuals and organizations. In Android smart devices, sandbox mechanism is not flexible enough to allow an application, such as webbrowser, to protect its own data against attacks such as cross-site request forgery, session or cookie hijacking that exploit application or platform vulnerabilities. These attacks in turn can lead to severe sensitive, private and confidential data ex-filtration. In this paper, we propose a novel authorization model for Android smart devices called Role Based Privilege Isolation (RBPI) which intends to mitigate data ex-filtration. This model achieves fine-grained privilege separation by creating roles based on application usage categories. By using roles, different instances of an application can be made to run with different data access privileges. Thus, the model protects sensitive data even in case where other instances of the same application are compromised. RBPI acts as an additional data security layer on top of the existing Android's security model without any performance overhead. Our proposed model is also applicable on any end-user computing system.
机译:数据前过滤是在智能设备的一个主要的安全问题,因为他们往往存储机密数据。数据前过滤有可能导致身份盗用,财务和非财务风险,以及个人和组织的声誉受损。在Android智能设备,沙箱机制不够灵活,允许应用程序,如网页浏览器,以保护自己的数据不受诸如跨站请求伪造,会话或饼干劫持是利用应用程序或平台漏洞的攻击。反过来,这些攻击可以导致严重的敏感,隐私和机密数据的前过滤。在本文中,我们提出了所谓的基于角色的权限隔离(的rBPI)的Android智能设备,其旨在减轻数据前过滤一个新的授权模型。这种模式实现了通过创建基于应用程序的使用类别角色的细粒度权限分离。通过使用角色,可以提出申请的不同情况用不同的数据访问权限运行。因此,该模型即使在同一应用程序的其他实例被损害的情况下可保护敏感的数据。的rBPI作为对现有的Android的安全模型之上的额外的数据安全层没有任何性能开销。我们提出的模型也适用任何最终用户计算系统上。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号