Enhancing Cross-Device Security with Fine-Grained Permission Control

被引:0
|
作者
Hu, Han [1 ]
Wang, Daibin [2 ]
Hong, Tailiang [2 ]
Zhang, Sheng [1 ]
机构
[1] Tsinghua Univ, Shenzhen Int Grad Sch, Key Lab Adv Sensor & Integrated Syst, Shenzhen 518055, Peoples R China
[2] Huawei Technol Co Ltd, Shenzhen, Peoples R China
关键词
Mobile device; Access control; Permission; Cross device; Operating system; ACCESS-CONTROL;
D O I
10.1007/978-3-031-64954-7_6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the proliferation of smart devices in personal and home environments, there is a growing need for cross-device interaction. However, distributed scenarios that cross device boundaries pose unique security and privacy challenges. While existing cross-device security mechanisms focus primarily on authentication, there is little research on fine-grained permission control. Permission models, which are critical security mechanisms for single devices, do not adequately support cross-device access control. To address this gap, we proposed and implemented a distributed role and attribute hybrid-based access control (DHBAC) model to enhance the security of cross-device access. DHBAC extends the single-device permission system to cross-device access control, providing fine-grained control based on users, devices, and applications. This approach effectively eliminates the over-authorization problem and supports the principle of least privilege. In addition, DHBAC can dynamically adjust and assign permissions based on specific scenarios and user requirements, improving the flexibility and adaptability of the system. To evaluate DHBAC, we deployed it on Harmony Operating System and tested it in several real-world, cross-device scenarios. Our evaluation shows that DHBAC effectively blocked malicious cross-device access and mitigated the associated security risks with acceptable system overhead.
引用
收藏
页码:101 / 121
页数:21
相关论文
共 50 条
  • [1] Vulture: Cross-Device Web Experience with Fine-Grained Graphical User Interface Distribution
    Park, Seonghoon
    Lee, Jeho
    Choi, Yonghun
    Cha, Hojung
    IEEE INFOCOM 2024-IEEE CONFERENCE ON COMPUTER COMMUNICATIONS, 2024, : 2478 - 2487
  • [2] A Fine-Grained Permission Control Mechanism for External Storage of Android
    Huang, Feiqiao
    Wu, Wenjia
    Yang, Ming
    Luo, Junzhou
    2016 IEEE INTERNATIONAL CONFERENCE ON SYSTEMS, MAN, AND CYBERNETICS (SMC), 2016, : 2911 - 2916
  • [3] Enhancing grid security by fine-grained behavioral control and negotiation-based authorization
    Hristo Koshutanski
    Aliaksandr Lazouski
    Fabio Martinelli
    Paolo Mori
    International Journal of Information Security, 2009, 8 : 291 - 314
  • [4] Enhancing grid security by fine-grained behavioral control and negotiation-based authorization
    Koshutanski, Hristo
    Lazouski, Aliaksandr
    Martinelli, Fabio
    Mori, Paolo
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2009, 8 (04) : 291 - 314
  • [5] Zero-Permission Acoustic Cross-Device Tracking
    Matyunin, Nikolay
    Szefer, Jakub
    Katzenbeisser, Stefan
    PROCEEDINGS OF THE 2018 IEEE INTERNATIONAL SYMPOSIUM ON HARDWARE ORIENTED SECURITY AND TRUST (HOST), 2018, : 25 - 32
  • [6] The Fine-Grained Security Access Control of Spatial Data
    Ma, Fuguang
    Gao, Yong
    Yan, Menglong
    Xu, Fuchun
    Liu, Ding
    2010 18TH INTERNATIONAL CONFERENCE ON GEOINFORMATICS, 2010,
  • [7] Perman: Fine-grained Permission Management for Android Applications
    Fu, Jiaojiao
    Zhou, Yangfan
    Liu, Huan
    Kang, Yu
    Wang, Xin
    2017 IEEE 28TH INTERNATIONAL SYMPOSIUM ON SOFTWARE RELIABILITY ENGINEERING (ISSRE), 2017, : 250 - 259
  • [8] Public Key Based Searchable Encryption with Fine-Grained Sender Permission Control
    Wang, Zhongming
    Chen, Biwen
    Xiang, Tao
    Zhou, Lu
    Yan, Hongyang
    Li, Jin
    PROVABLE AND PRACTICAL SECURITY, PROVSEC 2021, 2021, 13059 : 3 - 18
  • [9] Figment: Fine-grained Permission Management for Mobile Apps
    Gasparis, Ioannis
    Qian, Zhiyun
    Song, Chengyu
    Krishnamurthy, Srikanth V.
    Gupta, Rajiv
    Yu, Paul
    IEEE CONFERENCE ON COMPUTER COMMUNICATIONS (IEEE INFOCOM 2019), 2019, : 1405 - 1413
  • [10] Enhancing Efficiency and Fine-Grained Control in Redactable Blockchains with EPBCHF
    Ali, Shams Mhmood Abd
    Yusoff, Mohd Najwadi
    Hasan, Hasan Falah
    Iraqi Journal for Computer Science and Mathematics, 2024, 5 (03): : 194 - 212