首页> 外文期刊>Information systems frontiers >A Formal Specification of Access Control in Android with URI Permissions
【24h】

A Formal Specification of Access Control in Android with URI Permissions

机译:使用URI权限的Android中访问控制的正式规范

获取原文
获取原文并翻译 | 示例
           

摘要

A formal specification of access control yields a deeper understanding of any operating system, and facilitates performing security analysis of the OS. In this paper, we provide a comprehensive formal specification of access control in Android (ACiA). Prior work is limited in scope, furthermore, recent developments in Android concerning dynamic runtime permissions require rethinking of its formalization. Our formal specification includes three parts, the user-initiated operations (UIOs) and app-initiated operations (AIOs) - which are distinguished based on the initiating entity, and the URI permissions which are utilized in sharing temporary access to data. We also studied the evolution of URI permissions from API 10 (Gingerbread) to API 22 (Lollipop), and a brief discussion on this is included in the paper. Formalizing ACiA allowed us to discover many peculiar behaviors pertaining to ACiA. In addition to that, we discovered two significant issues with permissions in Android which were reported to Google.
机译:对访问控制的正式规范产生了对任何操作系统的更深层次的理解,并有助于执行操作系统的安全性分析。在本文中,我们提供了Android(Acia)的全面正式的访问控制规范。此外,事先工作的范围有限,此外,Android关于动态运行时权限的最新进展需要重新思考其形式化。我们的形式规范包括三个部分,用户启动的操作(UIO)和应用程序发起的操作(AIO) - 基于启动实体,以及用于共享对数据的临时访问的URI权限。我们还研究了API 10(Gingerbread)的URI权限的演变为API 22(棒棒糖),并介绍了这一点。正式化ACIA使我们能够发现与ACIA有关的许多特殊行为。除此之外,我们还发现了两个具有Android权限的重要问题,该问题被报告给Google。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号