STOVEPipe: Observable Access Control of User Data for Untrusted Applications on Mobile Devices

Jiaqi Tan, Utsav Drolia, Rolando Martins, R. Gandhi, P. Narasimhan
{"title":"STOVEPipe: Observable Access Control of User Data for Untrusted Applications on Mobile Devices","authors":"Jiaqi Tan, Utsav Drolia, Rolando Martins, R. Gandhi, P. Narasimhan","doi":"10.1109/CloudCom.2014.118","DOIUrl":null,"url":null,"abstract":"The rapid growth in mobile devices will give rise to the trend of the leasing out of compute and data resources on mobile devices to third-parties for applications to be run on multiple mobile devices. However, these third-party applications running on leased mobile devices are typically written by unknown entities, and cannot be trusted by mobile device owners. Current mobile device platforms (e.g. Android) have permissions and access control systems designed for mobile apps that are written by reputable developers and vetted by authoritative app stores, and they are not suitable for untrusted apps. We propose STOVEPipe, an observable access control system for user data on mobile devices for untrusted third-party applications. STOVEPipe ensures that untrusted code is isolated and cannot directly access system data, and performs all data accesses on behalf of untrusted apps. This enables STOVEPipe to observe all data accessed by untrusted apps, implement content-based access control, perform accounting and auditing on accessed data easily, and perform privacy-preserving data transformations.","PeriodicalId":249306,"journal":{"name":"2014 IEEE 6th International Conference on Cloud Computing Technology and Science","volume":"1 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2014-12-15","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"2","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2014 IEEE 6th International Conference on Cloud Computing Technology and Science","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/CloudCom.2014.118","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 2

Abstract

The rapid growth in mobile devices will give rise to the trend of the leasing out of compute and data resources on mobile devices to third-parties for applications to be run on multiple mobile devices. However, these third-party applications running on leased mobile devices are typically written by unknown entities, and cannot be trusted by mobile device owners. Current mobile device platforms (e.g. Android) have permissions and access control systems designed for mobile apps that are written by reputable developers and vetted by authoritative app stores, and they are not suitable for untrusted apps. We propose STOVEPipe, an observable access control system for user data on mobile devices for untrusted third-party applications. STOVEPipe ensures that untrusted code is isolated and cannot directly access system data, and performs all data accesses on behalf of untrusted apps. This enables STOVEPipe to observe all data accessed by untrusted apps, implement content-based access control, perform accounting and auditing on accessed data easily, and perform privacy-preserving data transformations.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
STOVEPipe:移动设备上不受信任应用的用户数据的可观察访问控制
随着移动设备的快速增长,移动设备上的计算和数据资源将被出租给第三方,以供应用程序在多个移动设备上运行。但是,在租用的移动设备上运行的这些第三方应用程序通常是由未知实体编写的,移动设备所有者不能信任它们。当前的移动设备平台(如Android)拥有专为知名开发者编写并经过权威应用商店审核的移动应用设计的权限和访问控制系统,不适合不受信任的应用。我们提出STOVEPipe,一个可观察的访问控制系统,用于不受信任的第三方应用程序的移动设备上的用户数据。STOVEPipe确保不受信任的代码被隔离,不能直接访问系统数据,并代表不受信任的应用程序执行所有数据访问。这使STOVEPipe能够观察不受信任的应用程序访问的所有数据,实现基于内容的访问控制,轻松地对访问的数据执行会计和审计,并执行保护隐私的数据转换。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Exploring the Performance Impact of Virtualization on an HPC Cloud Performance Study of Spindle, A Web Analytics Query Engine Implemented in Spark Role of System Modeling for Audit of QoS Provisioning in Cloud Services Dependability Analysis on Open Stack IaaS Cloud: Bug Anaysis and Fault Injection Delegated Access for Hadoop Clusters in the Cloud
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1