Authors
Wook Shin, Shinsaku Kiyomoto, Kazuhide Fukushima, Toshiaki Tanaka
Publication date
2010/8/20
Conference
2010 IEEE Second International Conference on Social Computing
Pages
944-951
Publisher
IEEE
Description
This paper proposes a formal model of the Android permission scheme. We describe the scheme specifying entities and relationships, and provide a state-based model which includes the behavior specification of permission authorization and the interactions between application components. We also show how we can logically confirm the security of the specified system. Utilizing a theorem prover, we can verify security with given security requirements based on mechanically checked proofs. The proposed model can be used as a reference model when the scheme is implemented in a different embedded platform, or when we extend the current scheme with additional constraints or elements. We demonstrate the use of the verifiable specification through finding a security vulnerability in the Android system. To our knowledge, this is the first formalization of the permission scheme enforced by the Android framework.
Total citations
20092010201120122013201420152016201720182019202020212022202312915151810915753112
Scholar articles
W Shin, S Kiyomoto, K Fukushima, T Tanaka - 2010 IEEE Second International Conference on Social …, 2010