UIDroid: User-Driven Based Hierarchical Access Control for Sensitive Information
Luping Ma, Dali Zhu, Shunliang Zhang, Xiaohui Zhang, Shumin Peng, Ya Li · 2020
Nowadays, increasing Android applications attempt to obtain a large number of sensitive user information such as Contacts, SMS, Call logs, IMEI, IMSI without rational necessity, which has seriously threatened the privacy of users. However, the existing Android cannot effectively prevent the above risks. To solve this problem, this paper proposes a novel, user-driven sensitive information management model-UIDroid. UIDroid redefines the subject, object, definition of security level, legitimacy of operations, and system security status. With UIDroid, users could authorize the sub-functions of an application to access sensitive information with rational security levels based on essential requirements on the accuracy of the sensitive data. The prototype of UIDroid is developed to verify the feasibility of the UIDroid and compatibility with existing applications. Extensive experiments show that UIDroid can effectively prevent malicious applications from getting unnecessary sensitive user information with unnecessary accuracy. Meanwhile, the overall performance overhead introduced by UIDroid is less than 4.8%.