The Android platform stores basic telephony data such as contacts, call logs, schedules, and SMS messages. These basic telephony data are managed by ContentProvider, which is one of the core components of Android applications along with Activities, Services, and BroadcastReceivers. If an Android application requires basic telephony data, it requests queries such as query, insert, update, and delete operations to ContentProvider. In the Android platform, every operation for which there is a possibility of misuse is protected by permissions. Generally, every application with proper permissions can request a protected operation from the Android platform. Database operations which access a database through ContentProvider are also protected by READ and WRITE permissions. However, this security policy has a critical flaw: it is impossible to differentiate the permissions of individual contacts in the Android Platform. If one application has READ permission for contacts, it can read every contact stored on an Android device. When the entities are not equal value, this flaw becomes a critical flaw. In the particular case of SMS, the problem is more serious because SMS messages can include financial information, authentication tokens, or privacy information. To address this security problem, we have designed and implemented a privacy-enhanced SMS provider. In this paper, we show how to hide sensitive SMS data from untrusted applications.
목차
Abstract 1. Introduction 2. Security Model and Limitations of the Android Platform 2.1. Security Model of the Android Platform 2.2. Limitations of the Security Model 3. Privacy-enhanced SMS Provider 3.1. SMS_RECEIVED Action in the Android Platform 3.2. Function of Privacy-enhanced SMS Provider 3.3. Design and Implementation 4. Demonstration of Privacy-enhanced SMS Provider 5. Conclusion References
Min-woo Park [ Department of Electrical and Computer Engineering, Sungkyunkwan University, Chunchun-dong 300,Jangan-gu, Suwon, Kyunggi-do, Republic of Korea ]
Jung ho Eom [ Military Studies, Daejeon University, 62 Daehakro, Dong-Gu, Daejeon, ]
Corresponding author
Tai-Myoung Chung [ Department of Electrical and Computer Engineering, Sungkyunkwan University, Chunchun-dong 300,Jangan-gu, Suwon, Kyunggi-do, Republic of Korea ]
보안공학연구지원센터(IJSIA) [Science & Engineering Research Support Center, Republic of Korea(IJSIA)]
설립연도
2006
분야
공학>컴퓨터학
소개
1. 보안공학에 대한 각종 조사 및 연구
2. 보안공학에 대한 응용기술 연구 및 발표
3. 보안공학에 관한 각종 학술 발표회 및 전시회 개최
4. 보안공학 기술의 상호 협조 및 정보교환
5. 보안공학에 관한 표준화 사업 및 규격의 제정
6. 보안공학에 관한 산학연 협동의 증진
7. 국제적 학술 교류 및 기술 협력
8. 보안공학에 관한 논문지 발간
9. 기타 본 회 목적 달성에 필요한 사업
간행물
간행물명
International Journal of Security and Its Applications
간기
격월간
pISSN
1738-9976
수록기간
2008~2016
등재여부
SCOPUS
십진분류
KDC 505DDC 605
이 권호 내 다른 논문 / International Journal of Security and Its Applications Vol.9 No.5