USENIX Security Symposium · 2016 · 41 citations · 30 references
Secure Difc EnforcementInformation Flow ControlEngineeringMobile SecurityInformation SecurityCloud ComputingSmartphone UsersData PrivacySecure By DesignMobile MalwareTrusted Execution EnvironmentSecure ComputingMobile ComputingComputer ScienceData SecurityCryptography
Smartphone users often use private and enterprise data with untrusted third party applications. The fundamental lack of secrecy guarantees in smartphone OSes, such as Android, exposes this data to the risk of unauthorized exfiltration. A natural solution is the integration of secrecy guarantees into the OS. In this paper, we describe the challenges for decentralized information flow control (DIFC) enforcement on Android. We propose contextsensitive DIFC enforcement via lazy polyinstantiation and practical and secure network export through domain declassification. Our DIFC system, Weir, is backwards compatible by design, and incurs less than 4 ms overhead for component startup. With Weir, we demonstrate practical and secure DIFC enforcement on Android.
30
A lattice model of secure information flow
Dorothy E. Denning · Communications of the ACM · 1976 · 1.9K citations · Full text
Andrew C. Myers · 1999 · 1K citations · Full text