Solved

Android Security Model

Posted on 2016-09-21
3
107 Views
Last Modified: 2016-09-30
Could someone please describe Android security model by explaining how it is enforced by Linux kernel and at the application layer?
0
Comment
Question by:K K
3 Comments
 
LVL 43

Expert Comment

by:Jackie Man
ID: 41810137
It is a tough question and you might need to read a chapter for a book to understand the concept.

First of all, you need to know about The Android architecture.
The Android architectureThe diagram above and the following extract are taken from a book called "Android Security Internals" by Nikolay Elenkov.

Android’s Security Model

Like the rest of the system, Android’s security model also takes advantage of the security features offered by the Linux kernel. Linux is a multiuser operating system and the kernel can isolate user resources from one another, just as it isolates processes. In a Linux system, one user cannot access another user’s files (unless explicitly granted permission) and each process runs with the identity (user and group ID, usually referred to as UID and GID) of the user that started it, unless the set-user-ID or set-group-ID (SUID and SGID) bits are set on the corresponding executable file.
Android takes advantage of this user isolation, but treats users differently than a traditional Linux system (desktop or server) does. In a traditional system, a UID is given either to a physical user that can log into the system and execute commands via the shell, or to a system service (daemon) that executes in the background (because system daemons are often accessible over the network, running each daemon with a dedicated UID can limit the damage if one is compromised). Android was originally designed for smartphones, and because mobile phones are personal devices, there was no need to register different physical users with the system. The physical user is implicit, and UIDs are used to distinguish applications instead. This forms the basis of Android’s application sandboxing.
0
 
LVL 62

Expert Comment

by:gheist
ID: 41810145
In short:
It is a Linux
Apps are users
Permissions are groups

Does the day look brighter now?
0
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 41810265
Android re-purpose the Linux system security controls to:
•Harden modular kernel (insecure modules removed/modified)
•Protect application and user data (e.g. User based permissions)
•Protect system resources (including the network)
•Provide application isolation from the system, other applications, and from the user (Process isolation, enforced oversight mechanisms for inter-process communication)

Besides those security enforcement through the Linux kernel, specific appl security can be look into in-depth to manage the access control and authorisation:
•Mandatory application sandbox for all applications
•Secure interprocess communication
•Application signing
•Application-defined and user-granted permissions

For more detailed information I'd suggest reading Android Security Overview
https://source.android.com/security/
A quick summary on the application secure exchanges
- http://www3.cs.stonybrook.edu/~rob/teaching/cse409-fa11/notes/09-19-alin-tomescu.pdf
0

Featured Post

Migrating Your Company's PCs

To keep pace with competitors, businesses must keep employees productive, and that means providing them with the latest technology. This document provides the tips and tricks you need to help you migrate an outdated PC fleet to new desktops, laptops, and tablets.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Samsung S5 - Bricked?? 5 47
reverse email lookup 8 55
How does Google Photos know what's in the photo? 9 25
sql server service accounts 4 22
How do we balance the user experience (UX) with reasonable security measures? It can be done, if you keep these fundamentals in mind.
Knowing where your website is hosted is as important as the features you receive, the monthly fee, and the support you receive. Due diligence should be done when choosing your next hosting provider.
Along with being a a promotional video for my three-day Annielytics Dashboard Seminor, this Micro Tutorial is an intro to Google Analytics API data.
Email security requires an ever evolving service that stays up to date with counter-evolving threats. The Email Laundry perform Research and Development to ensure their email security service evolves faster than cyber criminals. We apply our Threat…

776 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question