2009/12/01 by Machigar Ongtang, Stephen McLaughlin, William Enck +1 · 1 voice · 1 citation
Computer Science · #Access control #Advanced Malware Detection Techniques #Android (operating system) #Architecture #Cloud computing #Cloud computing security #Computer science #Computer security #Computer security model #Enterprise information security architecture #Network Security and Intrusion Detection #Operating system #Permission #Security and Verification in Computing #Security information and event management #Security policy #Security testing
paper · doi:10.1109/acsac.2009.39
openalex publication_date 2009/12/01 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/29
Smartphones are now ubiquitous. However, the security requirements of these relatively new systems and the applications they support are still being understood. As a result, the security infrastructure available in current smartphone operating systems is largely underdeveloped. In this paper, we consider the security requirements of smartphone applications and augment the existing Android operating system with a framework to meet them. We present Secure Application INTeraction (Saint), a modified infrastructure that governs install-time permission assignment and their run-time use as dictated by application provider policy. An in-depth description of the semantics of application policy is presented. The architecture and technical detail of Saint is given, and areas for extension, optimization, and improvement explored. As we show through concrete example, Saint provides necessary utility for applications to assert and control the security decisions on the platform.