TY - JOUR
T1 - A root privilege management scheme with revocable authorization for Android devices
AU - Tan, Yu an
AU - Xue, Yuan
AU - Liang, Chen
AU - Zheng, Jun
AU - Zhang, Quanxin
AU - Zheng, Jiamin
AU - Li, Yuanzhang
N1 - Publisher Copyright:
© 2018 Elsevier Ltd
PY - 2018/4/1
Y1 - 2018/4/1
N2 - As a critical part in mobile cloud computing, the vulnerability of Android devices can directly affect the security of the mobile cloud. The unsecured Android can be potentially exploited by malwares to obtain the root privilege. Root privilege misuse is the critical issue for Android security, which breaks the integrity of Android security and rises the risk of permission escalation from malwares. The existing solutions still fail to balance the trade-off between the users desires on using root privilege and the Android security, which lays risks in leading to the root privilege misuse. To address this issue, a root privilege management scheme named Root Privilege Manager (RPM) is proposed, which adopts the root privilege access control to guarantee the exclusive root access opportunity of the authenticated apps. RPM verifies the authorization and integrity of root requesting apps based on the extracted authorization files during app installation, and then root access management controls the granting of root privilege based on the authenticated results. In this way, the end users are free from the embarrassment of appropriate decision-making while confront root access management. The prototype of RPM is implemented to evaluate its effectiveness, efficiency and performance. The experiments show RPM can effectively control the granting of root privilege and the time consumption in root access management is increased by 0.21%–0.94% respectively compared with the user management.
AB - As a critical part in mobile cloud computing, the vulnerability of Android devices can directly affect the security of the mobile cloud. The unsecured Android can be potentially exploited by malwares to obtain the root privilege. Root privilege misuse is the critical issue for Android security, which breaks the integrity of Android security and rises the risk of permission escalation from malwares. The existing solutions still fail to balance the trade-off between the users desires on using root privilege and the Android security, which lays risks in leading to the root privilege misuse. To address this issue, a root privilege management scheme named Root Privilege Manager (RPM) is proposed, which adopts the root privilege access control to guarantee the exclusive root access opportunity of the authenticated apps. RPM verifies the authorization and integrity of root requesting apps based on the extracted authorization files during app installation, and then root access management controls the granting of root privilege based on the authenticated results. In this way, the end users are free from the embarrassment of appropriate decision-making while confront root access management. The prototype of RPM is implemented to evaluate its effectiveness, efficiency and performance. The experiments show RPM can effectively control the granting of root privilege and the time consumption in root access management is increased by 0.21%–0.94% respectively compared with the user management.
KW - Android security
KW - Mobile cloud computing
KW - Revocable authorization
KW - Root privilege management
UR - http://www.scopus.com/inward/record.url?scp=85042118238&partnerID=8YFLogxK
U2 - 10.1016/j.jnca.2018.01.011
DO - 10.1016/j.jnca.2018.01.011
M3 - Article
AN - SCOPUS:85042118238
SN - 1084-8045
VL - 107
SP - 69
EP - 82
JO - Journal of Network and Computer Applications
JF - Journal of Network and Computer Applications
ER -