Scientific Annals of Computer Science · 2016 · 17 citations · 17 references
In this work we present a comprehensive formal specification of an idealized formulation of Android's permission model. Permissions in Android are basically tags that developers declare in their applications, more precisely in the so-called application manifest, to gain access to sensitive resources. Several analyses have recently been carried out concerning the security of the Android system. Few of them, however, pay attention to the formal aspects of the permission enforcing framework. We provide a complete and uniform formulation of several security properties using the higher order logic of the Calculus of Inductive Constructions and sketch the proofs that have been developed and verified using the Coq proof assistant. We also analyze how the changes introduced in the latest version of Android, that allows to manage permissions at runtime, impact the presented model.
17
Android permissions demystified
Adrienne Porter Felt, Erika Chin, Steve Hanna et al. · 2011 · 1.3K citations
Formal verification of a realistic compiler
Xavier Leroy · Communications of the ACM · 2009 · 1.1K citations · Full text
Thierry Coquand, Gérard Huet · Information and Computation · 1988 · 1.1K citations