ETRI-Knowledge Sharing Plaform

KOREAN
논문 검색
Type SCI
Year ~ Keyword

Detail

Conference Paper User-Defined Privilege Restriction Mechanism for Secure Execution Environments on Android
Cited 1 time in scopus Share share facebook twitter linkedin kakaostory
Authors
Boheung Chung, Youngsung Jeon, Jeongnyeo Kim
Issue Date
2014-10
Citation
International Conference on Information and Communication Technology Convergence (ICTC) 2014, pp.815-816
Publisher
IEEE
Language
English
Type
Conference Paper
DOI
https://dx.doi.org/10.1109/ICTC.2014.6983299
Abstract
Recently emerging mobile devices have powerful capabilities and access personal and private data ever than before. Whenever we want to use various services, we would encounter unexpected security problems unless we carefully approve and manage app's permissions. To make secure execution environment for users or apps, we propose strict and light-weight privilege restriction mechanism. For this purpose, we strictly distinguish app's priority more than that of Android and validate their permissions at run-time. As all apps must be a secure or a non-secure one according to their priority at run-time, Android doesn't need to statically analyze in its database for all installed apps to validate and permit apps' privilege. Providing secure environment for secure one, we dynamically constrain the others privileges by deleting some of its permissions temporarily. With the help of our proposed method, users can easily identify the most privileged app among all others and they could efficiently prohibit unintended app's behavior to attain higher privilege without theirs acknowledgement.
KSP Keywords
Light-weight, Mobile devices, Private data, Restriction mechanism, Run-Time, Secure Execution Environment, Security problems, privilege restriction, user-defined