Please use this identifier to cite or link to this item: https://hdl.handle.net/11147/5777
Title: CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system
Authors: Abdella, Juhar Ahmed
Özuysal, Mustafa
Tomur, Emrah
Abdella, Juhar Ahmed
Özuysal, Mustafa
Tomur, Emrah
Izmir Institute of Technology. Computer Engineering
Keywords: Access control
Context Aware Access Control
Permissions
Android permission system
Software prototyping
Mobile phones
Issue Date: Dec-2016
Publisher: Hindawi Publishing Corporation
Source: Abdella, J. A., Özuysal, M., and Tomur, E. (2016). CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system. Security and Communication Networks, 9(18), 5977-5995. doi:10.1002/sec.1750
Abstract: Existing mobile platforms are based on manual way of granting and revoking permissions to applications. Once the user grants a given permission to an application, the application can use it without limit, unless the user manually revokes the permission. This has become the reason for many privacy problems because of the fact that a permission that is harmless at some occasion may be very dangerous at another condition. One of the promising solutions for this problem is context-aware access control at permission level that allows dynamic granting and denying of permissions based on some predefined context. However, dealing with policy configuration at permission level becomes very complex for the user as the number of policies to configure will become very large. For instance, if there are A applications, P permissions, and C contexts, the user may have to deal with A × P × C number of policy configurations. Therefore, we propose a context-aware role-based access control model that can provide dynamic permission granting and revoking while keeping the number of policies as small as possible. Although our model can be used for all mobile platforms, we use Android platform to demonstrate our system. In our model, Android applications are assigned roles where roles contain a set of permissions and contexts are associated with permissions. Permissions are activated and deactivated for the containing role based on the associated contexts. Our approach is unique in that our system associates contexts with permissions as opposed to existing similar works that associate contexts with roles. As a proof of concept, we have developed a prototype application called context-aware Android role-based access control. We have also performed various tests using our application, and the result shows that our model is working as desired.
URI: http://doi.org/10.1002/sec.1750
http://hdl.handle.net/11147/5777
ISSN: 1939-0114
1939-0122
Appears in Collections:Computer Engineering / Bilgisayar Mühendisliği
Scopus İndeksli Yayınlar Koleksiyonu / Scopus Indexed Publications Collection
WoS İndeksli Yayınlar Koleksiyonu / WoS Indexed Publications Collection

Files in This Item:
File Description SizeFormat 
5777.pdfMakale849.71 kBAdobe PDFThumbnail
View/Open
Show full item record

CORE Recommender

SCOPUSTM   
Citations

6
checked on Sep 18, 2021

WEB OF SCIENCETM
Citations

5
checked on Sep 18, 2021

Page view(s)

46
checked on Sep 21, 2021

Download(s)

30
checked on Sep 21, 2021

Google ScholarTM

Check

Altmetric


Items in GCRIS Repository are protected by copyright, with all rights reserved, unless otherwise indicated.