• DocumentCode
    248734
  • Title

    StoreDroid: Sensor-based data protection framework for Android

  • Author

    Allalouf, Miriam ; Ben-Av, Radel ; Gerdov, Alex

  • Author_Institution
    Azrieli Coll. of Eng. (JCE), Jerusalem, Israel
  • fYear
    2014
  • fDate
    4-8 Aug. 2014
  • Firstpage
    511
  • Lastpage
    517
  • Abstract
    Android has become the most prevalent smartphone operating system. Despite its popularity, Android has a lot of flaws in security. In this research study we target a wide range of smartphone applications that share secret and local data with the service provider so that this data will not be leaked or accessed by other entities. The StoreDroid framework, described in this paper, addresses possible data violations that can occur in the current Android system by adding protection mechanisms in several layers as follows: (1) at the Linux level we use the security-enhanced Linux and security-enhanced Android plugins that prevent today´s privileged escalation data access; (2) StoreDroidApp is a generic sensor-based access control mechanism where the sensors (such as biometric sensors and GPS) and the rules to access the data are defined by the service provider for better protection - we took advantage of the fact that Android systems are usually integrated with various hardware sensors in order to protect the user as well as the service provider; and (3) a secured message passing protocol to ensure that sensitive data will not be compromised by unwanted applications. The StoreDroid framework makes the following contributions: (1) the generic StoreDroidApp stub that is installed when the ROM is built narrows possible illegal data access for assigned application by the set of semantic and limiting sensor-based access rules, and (2) on top of the regular Linux used in Android, the customized security-enhanced Linux ensures that the sensor-based application will keep the data isolated and secured.
  • Keywords
    Android (operating system); authorisation; cryptographic protocols; message passing; read-only storage; sensors; smart phones; Android system; GPS; ROM; StoreDroid framework; StoreDroidApp; biometric sensors; generic StoreDroidApp stub; generic sensor-based access control mechanism; hardware sensors; illegal data access; secured message passing protocol; security-enhanced Android plug-ins; security-enhanced Linux; sensor-based data protection framework; service provider; smartphone operating system; Access control; Androids; Humanoid robots; Linux; Sensors; Smart phones; Android; Data Security; Mobile Computing; Security-Enhanced Linux;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Wireless Communications and Mobile Computing Conference (IWCMC), 2014 International
  • Conference_Location
    Nicosia
  • Print_ISBN
    978-1-4799-7324-8
  • Type

    conf

  • DOI
    10.1109/IWCMC.2014.6906409
  • Filename
    6906409