The Android Platform Security Model

04/11/2019
by   Rene Mayrhofer, et al.
0

Android is the most widely deployed end-user focused operating system. With its growing set of use cases encompassing communication, navigation, media consumption, entertainment, finance, health, and access to sensors, actuators, cameras, or microphones, its underlying security model needs to address a host of practical threats in a wide variety of scenarios while being useful to non-security experts. The model needs to strike a difficult balance between security, privacy, and usability for end users, assurances for app developers, and system performance under tight hardware constraints. While many of the underlying design principles have implicitly informed the overall system architecture, access control mechanisms, and mitigation techniques, the Android security model has previously not been formally published. This paper aims to both document the abstract model and discuss its implications. Based on a definition of the threat model and Android ecosystem context in which it operates, we analyze how the different security measures in past and current Android implementations work together to mitigate these threats. There are some special cases in applying the security model, and we discuss such deliberate deviations from the abstract model.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
03/13/2018

Android Inter-App Communication Threats, Solutions, and Challenges

Researchers and commercial companies have made a lot of efforts on detec...
research
03/18/2022

A Framework for Formal Specification and Verification of Security Properties of the Android Permissions System

Android is a widely deployed operating system that employs a permission-...
research
04/04/2022

SAUSAGE: Security Analysis of Unix domain Socket Usage in Android

The Android operating system is currently the most popular mobile operat...
research
02/24/2021

Analyzing Confidentiality and Privacy Concerns: Insights from Android Issue Logs

Context: Post-release user feedback plays an integral role in improving ...
research
08/10/2023

DCM: A Developers Certification Model for Mobile Ecosystems

This article introduces a distributed model of trust for app developers ...
research
09/02/2021

Brief View and Analysis to Latest Android Security Issues and Approaches

Due to the continuous improvement of performance and functions, Android ...
research
12/21/2017

An Economic Study of the Effect of Android Platform Fragmentation on Security Updates

Vendors in the Android ecosystem typically customize their devices by mo...

Please sign up or login with your details

Forgot password? Click here to reset