A Trusted Ecosystem For Android Applications Based On Context-Aware Access Control

AutorMarkus Herpich, Leonid Batyuk, Seyit Ahmet Camtepe, and Sahin Albayrak
Quelle7th International Conference on Malicious and Unwanted Software (Malware 2012) 

Private data stored on smartphones is a precious target for malware attacks. A constantly changing environment, e.g. switching network connections, can cause unpredictable threats, and require an adaptive approach to access control. Context-based access control is using dynamic environmental information, including it into access decisions. We propose an “ecosystem-in-an-ecosystem” which acts as a secure container for trusted software aiming at enterprise scenarios where users are allowed to use private devices. We have implemented a proof-of-concept prototype for an access control framework that processes changes to low-level sensors and semantically enriches them, adapting access control policies to the current context. This allows the user or the administrator to maintain fine-grained control over resource usage by compliant applications. Hence, resources local to the trusted container remain under control of the enterprise policy. Our results show that context-based access control can be done on smartphones without major performance impact.