Oct 2026· Proceedings on Privacy Enhancing Technologies· Vol 2026, pp. 232-247· 0 citations· 85 references
Computer Science
TL;DR
This work presents an addition to current permission systems that splits apps into multiple sandboxed processes to enforce fine-grained privacy and data-flow controls on smartphones, and implements a proof-of-concept based on the Android Open Source Project code base.
Abstract
One of the core privacy features of smartphone operating systems is a permission framework that requires explicit user consent before granting apps access to private data. Such systems are deeply integrated into Google's Android and Apple's iOS, which together account for the majority of the smartphone operating system market. While permission systems can be seen as milestones in user empowerment and privacy protection, they offer users only a binary choice: whether an app can access a specific resource or not. As soon as an app is allowed to read a resource, the operating system loses control over its further use. Most apps have Internet access and can send permission-protected data, like a user's location, over the Internet, which can harm user privacy. To solve this problem, we present an addition to current permission systems that splits apps into multiple sandboxed processes to enforce fine-grained privacy and data-flow controls on smartphones. By default, our design forces apps to process permission-protected data locally on the device, thereby eliminating the need for apps to request runtime permissions for local-only use cases. We implement a proof-of-concept based on the Android Open Source Project code base. We showcase our framework's practicability by adapting multiple app use cases to our system, benchmarking its computational overhead, and discussing the implications for platform operators, developers, and users.
Analysis of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasi...
Jyotirmay Chauhan, Kostas Solomos, Mir Masood Ali et al.· 0 citations
Kernel-level anti-cheats are effective against malicious player behavior in competitive video games, but raise significant user privacy concerns regarding installing unverifiable components at privileged modes (i.e., ring-0 in x86). While existing research has focused on improving the effectiveness of anti-cheats, the...
Santosh Gokul Narayanan, G. Paladino, Chu-Qi Zhang et al.· 0 citations
Android remains the world’s dominant mobile operating system with over 3.5 billion active devices, making it a prime target for increasingly sophisticated security threats and privacy violations. Traditional signature-based and rule-driven defenses are proving insufficient against polymorphic malware, zero-day exploits...
N. K. Yadati, Diwakar Reddy Peddinti, Saurabh Prakash Shetty· International Journal of Int...· 0 citations
Mobile operating systems provide runtime permission controls intended to improve user control over sensitive data. However, default or pre-installed applications are deeply integrated into the system, may operate with elevated privileges, and are difficult for users to scrutinize. Existing permission models generally g...
Asmau Yetunde Adeniran, A. Ademuwagun, Fatimah Adamu-Fika et al.· 0 citations
We use cookies to run the site and, with your consent, for analytics and to show ads.
See our Cookie Policy.