Stateful Data Usage Control for Android Mobile Devices

被引:0
|
作者
Aliaksandr Lazouski
Fabio Martinelli
Paolo Mori
Andrea Saracino
机构
[1] Consiglio Nazionale delle Ricerche,Istituto di Informatica e Telematica
关键词
Usage control; Mobile devices; XACML; Android;
D O I
暂无
中图分类号
学科分类号
摘要
Modern mobile devices allow their users to download data from the network, such as documents or photos, to store local copies and to use them. Many real scenarios would benefit from this capability of mobile devices to easily and quickly share data among a set of users but, in case of critical data, the usage of these copies must be regulated by proper security policies. To this aim, we propose a framework for regulating the usage of data when they have been downloaded on mobile devices, i.e., they have been copied outside the producer’s domain. Our framework regulates the usage of the local copy by enforcing the Usage Control policy which has been embedded in the data by the producer. Such policy is written in UXACML, an extension of the XACML language for expressing Usage Control model-based policies, whose main feature is to include predicates which must be satisfied for the whole execution of the access to the data. Hence, the proposed framework goes beyond the traditional access control capabilities, being able to interrupt an ongoing access to the data as soon as the policy is no longer satisfied. This paper details the proposed approach, defines the architecture and the workflow of the main functionalities of the proposed framework, describes the implementation of a working prototype for Android devices, presents the related performance figures, and discusses the security of the prototype.
引用
收藏
页码:345 / 369
页数:24
相关论文
共 50 条
  • [1] Stateful Data Usage Control for Android Mobile Devices
    Lazouski, Aliaksandr
    Martinelli, Fabio
    Mori, Paolo
    Saracino, Andrea
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2017, 16 (04) : 345 - 369
  • [2] Stateful Usage Control for Android Mobile Devices
    Lazouski, Aliaksandr
    Martinelli, Fabio
    Mori, Paolo
    Saracino, Andrea
    SECURITY AND TRUST MANAGEMENT (STM 2014), 2014, 8743 : 97 - 112
  • [3] Stateful usage control for android mobile devices
    1600, Springer Verlag (8743):
  • [4] Data Security Evaluation for Mobile Android Devices
    Khokhlov, Igor
    Reznik, Leon
    PROCEEDINGS OF THE 20TH CONFERENCE OF OPEN INNOVATIONS ASSOCIATION (FRUCT 2017), 2017, : 154 - 160
  • [5] Architecture, Workflows, and Prototype for Stateful Data Usage Control in Cloud
    Lazouski, Aliaksandr
    Mancini, Gaetano
    Martinelli, Fabio
    Mori, Paolo
    2014 IEEE SECURITY AND PRIVACY WORKSHOPS (SPW 2014), 2014, : 23 - 30
  • [6] Android scraping: Accessing personal data on mobile devices
    Munro, Ken
    Network Security, 2014, 2014 (11) : 5 - 9
  • [7] Forensics of location data collected by Google Android mobile devices
    Kroeger, Knut
    Creutzburg, Reiner
    MULTIMEDIA ON MOBILE DEVICES 2012 AND MULTIMEDIA CONTENT ACCESS: ALGORITHMS AND SYSTEMS VI, 2012, 8304
  • [8] Logical acquisition and analysis of data from android mobile devices
    Srivastava, Himanshu
    Tapaswi, Shashikala
    INFORMATION AND COMPUTER SECURITY, 2015, 23 (05) : 450 - 475
  • [9] Remote control of model vehicles using Android mobile devices
    Vunderl, Bruno
    Zagar, Martin
    Basch, Danko
    2013 36TH INTERNATIONAL CONVENTION ON INFORMATION AND COMMUNICATION TECHNOLOGY, ELECTRONICS AND MICROELECTRONICS (MIPRO), 2013, : 901 - 906
  • [10] Development of an Application for Parental Control of WhatsApp on Android Mobile Devices
    Caizaluisa Moreno, Eduardo Francisco
    Cevallos Salazar, Gabriela Katherine
    2019 INTERNATIONAL CONFERENCE ON INFORMATION SYSTEMS AND SOFTWARE TECHNOLOGIES (ICI2ST), 2019, : 16 - 23