DocumentCode
2939477
Title
A Multi-Layer Mandatory Access Control Mechanism for Mobile Devices Based on Virtualization
Author
Sung-Min Lee ; Sang-bum Suh ; Bokdeuk Jeong ; Sangdok Mo
Author_Institution
SAMSUNG ELECTRON. CO. LTD., Suwon
fYear
2008
fDate
10-12 Jan. 2008
Firstpage
251
Lastpage
256
Abstract
In this paper we present a multi-layer mandatory access control mechanism (ACM) for mobile devices based on system virtualization technology. We discuss a detailed threat model to mobile devices in the real world to develop an ACM fitted to mobile devices. Then, we propose a novel multi-layer access control mechanism for mobile devices, which provides strong protection against the identified mobile threats as well as performance efficiency. Our Virtual Machine Monitor (VMM) and secure domain have independent access control modules to effectively control mobile device´s resources. Access control module at VMM controls access requests from a domain to physical/virtual resources in order to confine sharing resources among domains for confidentiality. It also protects a mobile device against DoS attacks draining limited system resources such as battery and memory to guarantee availability. In addition, access control at secure domain enforces fine-grained control of resources (e.g., file system access control) in upper layer without degrading performance of a mobile device due to additional hypercall invocations. Furthermore, there is no bypass of our access control since our ACM is placed inside VMM which is simple and small enough to verify its safety and we eliminated the chance of VMM corruption by checking integrity of VMM including ACM during bootstrap time.
Keywords
authorisation; mobile computing; monitoring; virtual machines; DoS attacks; mobile devices; mobile threats; multilayer mandatory access control mechanism; system virtualization technology; virtual machine monitor; Access control; Availability; Batteries; Computer crime; Control systems; Degradation; File systems; Protection; Safety; Virtual machine monitors;
fLanguage
English
Publisher
ieee
Conference_Titel
Consumer Communications and Networking Conference, 2008. CCNC 2008. 5th IEEE
Conference_Location
Las Vegas, NV
Print_ISBN
978-1-4244-1456-7
Electronic_ISBN
978-1-4244-1457-4
Type
conf
DOI
10.1109/ccnc08.2007.63
Filename
4446361
Link To Document