...
首页> 外文期刊>Dependable and Secure Computing, IEEE Transactions on >Context-Based Access Control Systems for Mobile Devices
【24h】

Context-Based Access Control Systems for Mobile Devices

机译:移动设备的基于上下文的访问控制系统

获取原文
获取原文并翻译 | 示例
           

摘要

Mobile Android applications often have access to sensitive data and resources on the user device. Misuse of this data by malicious applications may result in privacy breaches and sensitive data leakage. An example would be a malicious application surreptitiously recording a confidential business conversation. The problem arises from the fact that Android users do not have control over the application capabilities once the applications have been granted the requested privileges upon installation. In many cases, however, whether an application may get a privilege depends on the specific user context and thus we need a context-based access control mechanism by which privileges can be dynamically granted or revoked to applications based on the specific context of the user. In this paper we propose such an access control mechanism. Our implementation of context differentiates between closely located sub-areas within the same location. We have modified the Android operating system so that context-based access control restrictions can be specified and enforced. We have performed several experiments to assess the efficiency of our access control mechanism and the accuracy of context detection.
机译:移动Android应用程序通常可以访问用户设备上的敏感数据和资源。恶意应用程序滥用此数据可能会导致隐私泄露和敏感数据泄漏。一个例子就是恶意应用程序秘密记录了机密的商业对话。问题来自以下事实:一旦在安装时向应用程序授予了请求的特权,Android用户就无法控制应用程序功能。但是,在许多情况下,应用程序是否可以获取特权取决于特定的用户上下文,因此我们需要基于上下文的访问控制机制,通过该机制,可以基于用户的特定上下文将特权动态授予或撤销给应用程序。在本文中,我们提出了这样一种访问控制机制。我们对上下文的实现区分了同一位置内位置较近的子区域。我们已经修改了Android操作系统,以便可以指定和实施基于上下文的访问控制限制。我们已经进行了几次实验,以评估我们的访问控制机制的效率和上下文检测的准确性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号