Studying the Implementation and Security of the Signature Authentication Mechanism in Android
Lei Wang · Xinxi wangluo anquan · 2012
In this paper, the author provided a thorough analysis of the signature authentication mechanism in Android, via statically analyzing the Android source code and dynamically monitoring the executing of the signature authentication mechanism during the process of application installation and executing. Through the analysis, the author finds that Android applications are authenticated only at the installation, but not at the execution. Every time the applications are executed, only the applications’ timestamps and file paths are verified. The security risk makes it possible for the attack codes to bypass the signature authentication mechanism, and launch attacks successfully.