DroidCap: OS Support for Capability-based Permissions in Android

Abdallah Dawoud, Sven Bugiel · 2019

We present DROIDCAP, a retrofitting of Android's central Binder IPC mechanism to change the way how permissions are being represented and managed in the system.In DROIDCAP, permissions are per-process Binder objectcapabilities.DROIDCAP's design removes Android's UID-based ambient authority and allows the delegation of capabilities between processes to create least-privileged protection domains efficiently.With DROIDCAP, we show that object-capabilities as underlying access control model integrates naturally and backward-compatible into Android's stock permission model and application management.Thus, our Binder capabilities provide app developers with a new path to gradually adopting app compartmentalization, which we showcase at two favorite examples from the literature, privilege separated advertisement libraries and least privileged app components.In this paper, we propose object-capabilities as a way to achieve per-process permissions together with the efficient delegation of privileges between processes.Drawing from past and current experiences on object-capability systems, we shift Android's permission model closer to an objectcapability system.Capability-based access control has been historically around [19], [23], [68], [37], [38], [49]-where it found use in high-assurance and distributed systems, such as EROS [58], IBM System/38 [28], iMAX 432 [33], CAP [48], or Amoeba [43]-and has recently been proposed for modern end-user systems, such as a new security feature for conventional systems like UNIX/Linux [65], [20], hybrid systems like CHERI [66], or new microkernel-based systems like Google's Fuchsia [24].Our solution adds to this recent developments.We show that an object-capability system not only fits well to Android's system model and realizing permissions, but also how such a model supports app developers in adopting privilege separation and fine-grained, dynamic permission management for least-privilege operation on Android more efficiently.At the heart of our paradigm shift for representing permissions in Android is an extension to Android's Binder IPC mechanism.Binder IPC is the primary IPC channel for communication among all apps and between system services

Read the paper · More papers on PaperTik