首页> 外文OA文献 >CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system
【2h】

CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system

机译:CA-ARBAC:在Android权限系统上使用基于上下文的基于角色的访问控制来保护隐私

代理获取
本网站仅为用户提供外文OA文献查询和代理获取服务,本网站没有原文。下单后我们将采用程序或人工为您竭诚获取高质量的原文,但由于OA文献来源多样且变更频繁,仍可能出现获取不到、文献不完整或与标题不符等情况,如果获取不到我们将提供退款服务。请知悉。

摘要

Existing mobile platforms are based on manual way of granting and revoking permissions to applications. Once the user grants a given permission to an application, the application can use it without limit, unless the user manually revokes the permission. This has become the reason for many privacy problems because of the fact that a permission that is harmless at some occasion may be very dangerous at another condition. One of the promising solutions for this problem is context-aware access control at permission level that allows dynamic granting and denying of permissions based on some predefined context. However, dealing with policy configuration at permission level becomes very complex for the user as the number of policies to configure will become very large. For instance, if there are A applications, P permissions, and C contexts, the user may have to deal with A × P × C number of policy configurations. Therefore, we propose a context-aware role-based access control model that can provide dynamic permission granting and revoking while keeping the number of policies as small as possible. Although our model can be used for all mobile platforms, we use Android platform to demonstrate our system. In our model, Android applications are assigned roles where roles contain a set of permissions and contexts are associated with permissions. Permissions are activated and deactivated for the containing role based on the associated contexts. Our approach is unique in that our system associates contexts with permissions as opposed to existing similar works that associate contexts with roles. As a proof of concept, we have developed a prototype application called context-aware Android role-based access control. We have also performed various tests using our application, and the result shows that our model is working as desired.
机译:现有的移动平台基于手动授予和撤消对应用程序的权限的方式。一旦用户向应用程序授予了给定的权限,该应用程序就可以无限制地使用它,除非用户手动撤消该权限。这成为许多隐私问题的原因,因为在某些情况下获得无害的许可在其他情况下可能非常危险。解决此问题的一种有希望的解决方案是权限级别的上下文感知访问控制,它允许基于某些预定义的上下文动态授予和拒绝权限。但是,由于要配置的策略数量将变得非常大,因此对于用户而言,在权限级别上处理策略配置变得非常复杂。例如,如果有A个应用程序,P个权限和C个上下文,则用户可能必须处理A×P×C个策略配置。因此,我们提出了一种基于上下文的基于角色的访问控制模型,该模型可以提供动态许可授予和吊销,同时保持尽可能少的策略数量。尽管我们的模型可以用于所有移动平台,但是我们使用Android平台来演示我们的系统。在我们的模型中,为Android应用程序分配了角色,其中角色包含一组权限,并且上下文与权限相关联。根据关联的上下文为包含角色激活和停用权限。我们的方法是独特的,因为我们的系统将上下文与权限相关联,而不是将上下文与角色相关联的现有类似作品。作为概念验证,我们开发了一个原型应用程序,称为基于上下文的Android基于角色的访问控制。我们还使用我们的应用程序执行了各种测试,结果表明我们的模型正在按预期工作。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
代理获取

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号