DocumentCode :
683995
Title :
Toward active and efficient privacy protection for Android
Author :
Yuhao Luo ; Dawu Gu ; Juanru Li
Author_Institution :
Dept. of Comput. Sci. & Eng., Shanghai Jiao Tong Univ., Shanghai, China
fYear :
2013
fDate :
23-25 March 2013
Firstpage :
924
Lastpage :
929
Abstract :
Although Android has introduced many security mechanisms, users often expose privacy information to attacker due to the system´s defensive privacy protecting policy. The problem is that for most inexperienced users, no mandatory protection is provided. To address this issue, we propose a data-centric privacy enhancement design to actively restrict privacy violation on Android. The main idea is to first build trusted database by introducing secure enhanced kernel and data-at-rest encryption. Then, the system enforces an isolation of applications with privacy data access privilege mode. The design focuses on data protection and keeps persistent mandatory access control model from kernel to application layer, and could resist most common privacy leakage attacks. Compared with other heavyweight isolation scheme, the overhead is also controlled into an acceptable range due to our lightweight design principle.
Keywords :
Android (operating system); authorisation; cryptography; data privacy; trusted computing; Android; data protection; data-at-rest encryption; data-centric privacy enhancement design; defensive privacy protecting policy; kernel encryption; lightweight design principle; persistent mandatory access control model; privacy data access privilege mode; privacy leakage attacks; privacy protection; privacy violation; security mechanisms; trusted database; Data privacy; Databases; Encryption; Kernel; Smart phones;
fLanguage :
English
Publisher :
ieee
Conference_Titel :
Information Science and Technology (ICIST), 2013 International Conference on
Conference_Location :
Yangzhou
Print_ISBN :
978-1-4673-5137-9
Type :
conf
DOI :
10.1109/ICIST.2013.6747691
Filename :
6747691
Link To Document :
بازگشت