Enhancing Cross-Device Security with Fine-Grained Permission Control

被引:0
|
作者
Hu, Han [1 ]
Wang, Daibin [2 ]
Hong, Tailiang [2 ]
Zhang, Sheng [1 ]
机构
[1] Tsinghua Univ, Shenzhen Int Grad Sch, Key Lab Adv Sensor & Integrated Syst, Shenzhen 518055, Peoples R China
[2] Huawei Technol Co Ltd, Shenzhen, Peoples R China
关键词
Mobile device; Access control; Permission; Cross device; Operating system; ACCESS-CONTROL;
D O I
10.1007/978-3-031-64954-7_6
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
With the proliferation of smart devices in personal and home environments, there is a growing need for cross-device interaction. However, distributed scenarios that cross device boundaries pose unique security and privacy challenges. While existing cross-device security mechanisms focus primarily on authentication, there is little research on fine-grained permission control. Permission models, which are critical security mechanisms for single devices, do not adequately support cross-device access control. To address this gap, we proposed and implemented a distributed role and attribute hybrid-based access control (DHBAC) model to enhance the security of cross-device access. DHBAC extends the single-device permission system to cross-device access control, providing fine-grained control based on users, devices, and applications. This approach effectively eliminates the over-authorization problem and supports the principle of least privilege. In addition, DHBAC can dynamically adjust and assign permissions based on specific scenarios and user requirements, improving the flexibility and adaptability of the system. To evaluate DHBAC, we deployed it on Harmony Operating System and tested it in several real-world, cross-device scenarios. Our evaluation shows that DHBAC effectively blocked malicious cross-device access and mitigated the associated security risks with acceptable system overhead.
引用
收藏
页码:101 / 121
页数:21
相关论文
共 50 条
  • [21] Security-Aware Service Composition with Fine-Grained Information Flow Control
    She, Wei
    Yen, I-Ling
    Thuraisingham, Bhavani
    Bertino, Elisa
    IEEE TRANSACTIONS ON SERVICES COMPUTING, 2013, 6 (03) : 330 - 343
  • [22] A Lightweight Fine-Grained Access Control Scheme with Forward Security for Mobile Crowdsourcing
    Hong, Keyong
    Wang, Tao
    Wang, Zhichao
    Wang, Jintang
    2024 2ND INTERNATIONAL CONFERENCE ON MOBILE INTERNET, CLOUD COMPUTING AND INFORMATION SECURITY, MICCIS 2024, 2024, : 195 - 203
  • [23] Fine-Grained Access Control for Microservices
    Nehme, Antonio
    Jesus, Vitor
    Mahbub, Khaled
    Abdallah, Ali
    FOUNDATIONS AND PRACTICE OF SECURITY, FPS 2018, 2019, 11358 : 285 - 300
  • [24] A Fine-Grained Multi-Tenant Permission Management Framework for SDN and NFV
    Zou, Deqing
    Lu, Yu
    Yuan, Bin
    Chen, Haoyu
    Jin, Hai
    IEEE ACCESS, 2018, 6 : 25562 - 25572
  • [25] Fine-grained Device and Data Access Control of Community Medical Internet of Things
    Huang, Cheng
    Zhang, Ziyang
    Huang, Jing
    Chen, Fulong
    2020 16TH INTERNATIONAL CONFERENCE ON MOBILITY, SENSING AND NETWORKING (MSN 2020), 2020, : 236 - 243
  • [26] Enhancing Fine-Grained Classification for Low Resolution Images
    Singh, Maneet
    Nagpal, Shruti
    Vatsa, Mayank
    Singh, Richa
    2021 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2021,
  • [27] Enhancing knowledge tracing with fine-grained session modeling
    Wang, Jing
    Ma, Huifang
    Zhang, Mengyuan
    Li, Zhixin
    Chang, Liang
    INTERNATIONAL JOURNAL OF MACHINE LEARNING AND CYBERNETICS, 2025,
  • [28] Towards Enhancing Fine-grained Details for Image Matting
    Liu, Chang
    Ding, Henghui
    Jiang, Xudong
    2021 IEEE WINTER CONFERENCE ON APPLICATIONS OF COMPUTER VISION (WACV 2021), 2021, : 385 - 393
  • [29] Cryptographic pointers for fine-grained file access security
    Lopriore, Lanfranco
    INFORMATION SECURITY JOURNAL, 2022, 31 (03): : 359 - 375
  • [30] Fine-Grained In-Context Permission Classification for Android Apps using Control-Flow Graph Embedding
    Malviya, Vikas K.
    Tun, Yan Naing
    Leow, Chee Wei
    Xynyn, Ailys Tee
    Shar, Lwin Khin
    Jiang, Lingxiao
    2023 38TH IEEE/ACM INTERNATIONAL CONFERENCE ON AUTOMATED SOFTWARE ENGINEERING, ASE, 2023, : 1225 - 1237