Mandatory Enforcement of Geofenced Security in Android
Prateek Pande, Amit Kumar Medatiya, Kurra Mallaiah, Rishi Kumar Gandhi, S Srinivasachary · 2021
Android applications are today driving most of the aspects of business. But corresponding threats of information breach through a malware or naive users are also increasing many folds. It becomes extremely difficult for any organisation to allow employees to seamlessly use android based smartphones within office premises while keeping the related threats at bay. Situation is even more difficult for an organisation related to finance, defence, medicine, reasearch etc., where employees handle sensitive and confidential data. Usually, these threats are ignored else employers try to impose various physical restrictions which incur huge costs and inconvenience. In this regard, this paper proposes a novel scheme to enforce constraints on android based smartphones to mitigate above threats. It provides kernel level restriction on existing Android applications from accessing various smartphone resources whenever host device enters a predefined geographical boundary of an enterprise. This is achieved by dynamic security policies in SEAndroid. It utilises Android source from AOSP ported on Google Pixel2 XL device to demonstrate nuances of practicality.