Context-Based Access Control Systems for Mobile Devices

被引:54
|
作者
Shebaro, Bilal [1 ,2 ]
Oluwatimi, Oyindamola [1 ,2 ]
Bertino, Elisa [1 ,2 ]
机构
[1] Purdue Univ, Dept Comp Sci, Cyber Ctr, W Lafayette, IN 47907 USA
[2] Purdue Univ, CERIAS, W Lafayette, IN 47907 USA
关键词
Context-based access control; smartphone devices; security and privacy; policies; mobile applications;
D O I
10.1109/TDSC.2014.2320731
中图分类号
TP3 [计算技术、计算机技术];
学科分类号
0812 ;
摘要
Mobile Android applications often have access to sensitive data and resources on the user device. Misuse of this data by malicious applications may result in privacy breaches and sensitive data leakage. An example would be a malicious application surreptitiously recording a confidential business conversation. The problem arises from the fact that Android users do not have control over the application capabilities once the applications have been granted the requested privileges upon installation. In many cases, however, whether an application may get a privilege depends on the specific user context and thus we need a context-based access control mechanism by which privileges can be dynamically granted or revoked to applications based on the specific context of the user. In this paper we propose such an access control mechanism. Our implementation of context differentiates between closely located subareas within the same location. We have modified the Android operating system so that context-based access control restrictions can be specified and enforced. We have performed several experiments to assess the efficiency of our access control mechanism and the accuracy of context detection.
引用
收藏
页码:150 / 163
页数:14
相关论文
共 50 条
  • [1] Exploring a Context-based Network Access Control for Mobile Devices
    Mowafi, Yaser
    Abou-Tair, Dhiah el Diehn I.
    Zmily, Ahmad
    Al-Aqarbeh, Tareq
    Abilov, Marat
    Dmitriyevr, Viktor
    [J]. PROCEEDINGS OF THE 2015 INTERNATIONAL CONFERENCE ON SOFT COMPUTING AND SOFTWARE ENGINEERING (SCSE'15), 2015, 62 : 547 - 554
  • [2] A Context-Based Personalization for Mobile Applications' Network Access
    Mowafi, Yaser
    Alaqarbeh, Tareq
    Alazrai, Rami
    [J]. MOBILE WEB AND INTELLIGENT INFORMATION SYSTEMS, (MOBIWIS 2016), 2016, 9847 : 406 - 415
  • [3] Context-Based Access Control for Ridesharing Service
    Teslya, Nikolay
    Kashevnik, Alexey
    Pashkin, Michael
    [J]. 2013 14TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT), 2013, : 156 - 163
  • [4] A Semantic-Aware Context-Based Access Control Framework for Mobile Web Services
    Shen, Haibo
    Cheng, Yu
    [J]. MECHANICAL ENGINEERING AND INTELLIGENT SYSTEMS, PTS 1 AND 2, 2012, 195-196 : 498 - 503
  • [5] Model for adaptable context-based biometric authentication for mobile devices
    Adam Wójtowicz
    Krzysztof Joachimiak
    [J]. Personal and Ubiquitous Computing, 2016, 20 : 195 - 207
  • [6] Model for adaptable context-based biometric authentication for mobile devices
    Wojtowicz, Adam
    Joachimiak, Krzysztof
    [J]. PERSONAL AND UBIQUITOUS COMPUTING, 2016, 20 (02) : 195 - 207
  • [7] Context-based access control management in ubiquitous environments
    Corradi, A
    Montanari, R
    Tibaldi, D
    [J]. THIRD IEEE INTERNATIONAL SYMPOSIUM ON NETWORK COMPUTING AND APPLICATIONS, PROCEEDINGS, 2004, : 253 - 260
  • [8] Context-based Access Control Model for Smart Space
    Smirnov, Alexander
    Kashevnik, Alexey
    Shilov, Nikolay
    Teslya, Nikolay
    [J]. 2013 5TH INTERNATIONAL CONFERENCE ON CYBER CONFLICT (CYCON), 2013,
  • [9] Context-based evaluation of mobile knowledge management systems
    Ben Ayed, Emna
    Kolski, Christophe
    Ezzedine, Houcine
    [J]. 2016 IEEE/ACS 13TH INTERNATIONAL CONFERENCE OF COMPUTER SYSTEMS AND APPLICATIONS (AICCSA), 2016,
  • [10] Semantic-based Obligation for Context-Based Access Control
    Al-Wahah, Mouiad
    Saaudi, Ahmed
    Farkas, Csilla
    [J]. PROCEEDINGS OF THE 16TH INTERNATIONAL JOINT CONFERENCE ON E-BUSINESS AND TELECOMMUNICATIONS, VOL 2: SECRYPT, 2019, : 535 - 540