Show simple item record

dc.contributor.authorAbdella, Juhar Ahmed
dc.contributor.authorÖzuysal, Mustafa
dc.contributor.authorTomur, Emrah
dc.date.accessioned2017-06-15T11:23:04Z
dc.date.available2017-06-15T11:23:04Z
dc.date.issued2016-12
dc.identifier.citationAbdella, J. A., Özuysal, M., and Tomur, E. (2016). CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system. Security and Communication Networks, 9(18), 5977-5995. doi:10.1002/sec.1750en_US
dc.identifier.issn1939-0114
dc.identifier.urihttp://doi.org/10.1002/sec.1750
dc.identifier.urihttp://hdl.handle.net/11147/5777
dc.description.abstractExisting mobile platforms are based on manual way of granting and revoking permissions to applications. Once the user grants a given permission to an application, the application can use it without limit, unless the user manually revokes the permission. This has become the reason for many privacy problems because of the fact that a permission that is harmless at some occasion may be very dangerous at another condition. One of the promising solutions for this problem is context-aware access control at permission level that allows dynamic granting and denying of permissions based on some predefined context. However, dealing with policy configuration at permission level becomes very complex for the user as the number of policies to configure will become very large. For instance, if there are A applications, P permissions, and C contexts, the user may have to deal with A × P × C number of policy configurations. Therefore, we propose a context-aware role-based access control model that can provide dynamic permission granting and revoking while keeping the number of policies as small as possible. Although our model can be used for all mobile platforms, we use Android platform to demonstrate our system. In our model, Android applications are assigned roles where roles contain a set of permissions and contexts are associated with permissions. Permissions are activated and deactivated for the containing role based on the associated contexts. Our approach is unique in that our system associates contexts with permissions as opposed to existing similar works that associate contexts with roles. As a proof of concept, we have developed a prototype application called context-aware Android role-based access control. We have also performed various tests using our application, and the result shows that our model is working as desired.en_US
dc.language.isoengen_US
dc.publisherWileyen_US
dc.relation.isversionof10.1002/sec.1750en_US
dc.rightsinfo:eu-repo/semantics/openAccessen_US
dc.subjectAccess controlen_US
dc.subjectContext Aware Access Controlen_US
dc.subjectPermissionsen_US
dc.subjectAndroid permission systemen_US
dc.subjectSoftware prototypingen_US
dc.subjectMobile phonesen_US
dc.titleCA-ARBAC: privacy preserving using context-aware role-based access control on Android permission systemen_US
dc.typearticleen_US
dc.contributor.authorIDTR21345en_US
dc.contributor.iztechauthorAbdella, Juhar Ahmed
dc.contributor.iztechauthorÖzuysal, Mustafa
dc.contributor.iztechauthorTomur, Emrah
dc.relation.journalSecurity and Communication Networksen_US
dc.contributor.departmentİYTE, Mühendislik Fakültesi, Bilgisayar Mühendisliği Bölümüen_US
dc.identifier.volume9en_US
dc.identifier.issue18en_US
dc.identifier.startpage5977en_US
dc.identifier.endpage5995en_US
dc.identifier.wosWOS:000398221800084
dc.identifier.scopusSCOPUS:2-s2.0-85016585170
dc.relation.publicationcategoryMakale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanıen_US


Files in this item

Thumbnail

This item appears in the following Collection(s)

Show simple item record