Ca-Arbac: Privacy Preserving Using Context-Aware Role-Based Access Control on Android Permission System

dc.contributor.author Abdella, Juhar Ahmed
dc.contributor.author Özuysal, Mustafa
dc.contributor.author Tomur, Emrah
dc.coverage.doi 10.1002/sec.1750
dc.date.accessioned 2017-06-15T11:23:04Z
dc.date.available 2017-06-15T11:23:04Z
dc.date.issued 2016
dc.description.abstract Existing mobile platforms are based on manual way of granting and revoking permissions to applications. Once the user grants a given permission to an application, the application can use it without limit, unless the user manually revokes the permission. This has become the reason for many privacy problems because of the fact that a permission that is harmless at some occasion may be very dangerous at another condition. One of the promising solutions for this problem is context-aware access control at permission level that allows dynamic granting and denying of permissions based on some predefined context. However, dealing with policy configuration at permission level becomes very complex for the user as the number of policies to configure will become very large. For instance, if there are A applications, P permissions, and C contexts, the user may have to deal with A × P × C number of policy configurations. Therefore, we propose a context-aware role-based access control model that can provide dynamic permission granting and revoking while keeping the number of policies as small as possible. Although our model can be used for all mobile platforms, we use Android platform to demonstrate our system. In our model, Android applications are assigned roles where roles contain a set of permissions and contexts are associated with permissions. Permissions are activated and deactivated for the containing role based on the associated contexts. Our approach is unique in that our system associates contexts with permissions as opposed to existing similar works that associate contexts with roles. As a proof of concept, we have developed a prototype application called context-aware Android role-based access control. We have also performed various tests using our application, and the result shows that our model is working as desired. en_US
dc.identifier.citation Abdella, J. A., Özuysal, M., and Tomur, E. (2016). CA-ARBAC: privacy preserving using context-aware role-based access control on Android permission system. Security and Communication Networks, 9(18), 5977-5995. doi:10.1002/sec.1750 en_US
dc.identifier.doi 10.1002/sec.1750 en_US
dc.identifier.doi 10.1002/sec.1750
dc.identifier.issn 1939-0114
dc.identifier.issn 1939-0122
dc.identifier.scopus 2-s2.0-85016585170
dc.identifier.uri http://doi.org/10.1002/sec.1750
dc.identifier.uri https://hdl.handle.net/11147/5777
dc.language.iso en en_US
dc.publisher Hindawi Publishing Corporation en_US
dc.relation.ispartof Security and Communication Networks en_US
dc.rights info:eu-repo/semantics/openAccess en_US
dc.subject Access control en_US
dc.subject Context Aware Access Control en_US
dc.subject Permissions en_US
dc.subject Android permission system en_US
dc.subject Software prototyping en_US
dc.subject Mobile phones en_US
dc.title Ca-Arbac: Privacy Preserving Using Context-Aware Role-Based Access Control on Android Permission System en_US
dc.type Article en_US
dspace.entity.type Publication
gdc.author.institutional Abdella, Juhar Ahmed
gdc.author.institutional Özuysal, Mustafa
gdc.author.institutional Tomur, Emrah
gdc.author.yokid 21345
gdc.bip.impulseclass C4
gdc.bip.influenceclass C5
gdc.bip.popularityclass C4
gdc.coar.access open access
gdc.coar.type text::journal::journal article
gdc.collaboration.industrial false
gdc.description.department İzmir Institute of Technology. Computer Engineering en_US
gdc.description.endpage 5995 en_US
gdc.description.issue 18 en_US
gdc.description.publicationcategory Makale - Uluslararası Hakemli Dergi - Kurum Öğretim Elemanı en_US
gdc.description.scopusquality N/A
gdc.description.startpage 5977 en_US
gdc.description.volume 9 en_US
gdc.identifier.openalex W2580439803
gdc.identifier.wos WOS:000398221800084
gdc.index.type WoS
gdc.index.type Scopus
gdc.oaire.accesstype GOLD
gdc.oaire.diamondjournal false
gdc.oaire.impulse 5.0
gdc.oaire.influence 3.441326E-9
gdc.oaire.isgreen true
gdc.oaire.keywords Context Aware Access Control
gdc.oaire.keywords Android permission system
gdc.oaire.keywords Access control
gdc.oaire.keywords Permissions
gdc.oaire.keywords Mobile phones
gdc.oaire.keywords Software prototyping
gdc.oaire.keywords 004
gdc.oaire.popularity 5.109125E-9
gdc.oaire.publicfunded false
gdc.oaire.sciencefields 0202 electrical engineering, electronic engineering, information engineering
gdc.oaire.sciencefields 02 engineering and technology
gdc.openalex.collaboration National
gdc.openalex.fwci 1.19055526
gdc.openalex.normalizedpercentile 0.83
gdc.opencitations.count 10
gdc.plumx.crossrefcites 8
gdc.plumx.mendeley 22
gdc.plumx.scopuscites 11
gdc.scopus.citedcount 11
gdc.wos.citedcount 8
relation.isAuthorOfPublication.latestForDiscovery c5de0144-5a8c-4c0a-93b2-334507777064
relation.isOrgUnitOfPublication.latestForDiscovery 9af2b05f-28ac-4014-8abe-a4dfe192da5e

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Name:
5777.pdf
Size:
849.71 KB
Format:
Adobe Portable Document Format
Description:
Makale

License bundle

Now showing 1 - 1 of 1
Loading...
Name:
license.txt
Size:
1.71 KB
Format:
Item-specific license agreed upon to submission
Description: