Solved

Android Security Model

Posted on 2016-09-21
3
92 Views
Last Modified: 2016-09-30
Could someone please describe Android security model by explaining how it is enforced by Linux kernel and at the application layer?
0
Comment
Question by:K K
3 Comments
 
LVL 42

Expert Comment

by:Jackie Man
ID: 41810137
It is a tough question and you might need to read a chapter for a book to understand the concept.

First of all, you need to know about The Android architecture.
The Android architectureThe diagram above and the following extract are taken from a book called "Android Security Internals" by Nikolay Elenkov.

Android’s Security Model

Like the rest of the system, Android’s security model also takes advantage of the security features offered by the Linux kernel. Linux is a multiuser operating system and the kernel can isolate user resources from one another, just as it isolates processes. In a Linux system, one user cannot access another user’s files (unless explicitly granted permission) and each process runs with the identity (user and group ID, usually referred to as UID and GID) of the user that started it, unless the set-user-ID or set-group-ID (SUID and SGID) bits are set on the corresponding executable file.
Android takes advantage of this user isolation, but treats users differently than a traditional Linux system (desktop or server) does. In a traditional system, a UID is given either to a physical user that can log into the system and execute commands via the shell, or to a system service (daemon) that executes in the background (because system daemons are often accessible over the network, running each daemon with a dedicated UID can limit the damage if one is compromised). Android was originally designed for smartphones, and because mobile phones are personal devices, there was no need to register different physical users with the system. The physical user is implicit, and UIDs are used to distinguish applications instead. This forms the basis of Android’s application sandboxing.
0
 
LVL 61

Expert Comment

by:gheist
ID: 41810145
In short:
It is a Linux
Apps are users
Permissions are groups

Does the day look brighter now?
0
 
LVL 62

Accepted Solution

by:
btan earned 500 total points
ID: 41810265
Android re-purpose the Linux system security controls to:
•Harden modular kernel (insecure modules removed/modified)
•Protect application and user data (e.g. User based permissions)
•Protect system resources (including the network)
•Provide application isolation from the system, other applications, and from the user (Process isolation, enforced oversight mechanisms for inter-process communication)

Besides those security enforcement through the Linux kernel, specific appl security can be look into in-depth to manage the access control and authorisation:
•Mandatory application sandbox for all applications
•Secure interprocess communication
•Application signing
•Application-defined and user-granted permissions

For more detailed information I'd suggest reading Android Security Overview
https://source.android.com/security/
A quick summary on the application secure exchanges
- http://www3.cs.stonybrook.edu/~rob/teaching/cse409-fa11/notes/09-19-alin-tomescu.pdf
0

Featured Post

VMware Disaster Recovery and Data Protection

In this expert guide, you’ll learn about the components of a Modern Data Center. You will use cases for the value-added capabilities of Veeam®, including combining backup and replication for VMware disaster recovery and using replication for data center migration.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Title # Comments Views Activity
Account Lockouts 25 147
change password links 7 72
Error Message during CentOS 7 Minimal Install 3 34
Changing Antivirus for Corporatre Network 11 6
You may have a outside contractor who comes in once a week or seasonal to do some work in your office but you only want to give him access to the programs and files he needs and keep privet all other documents and programs, can you do this on a loca…
Big data transfers via information superhighways require special attention and protection. Learn more about the IT-regulations of the country where your server is located. Analyze cloud providers and their encryption systems for safe data transit. S…
This Micro Tutorial will demonstrate importing calendar invites from events such as webinars into your Google Calendar.
Shows how to create a shortcut to site-search Experts Exchange using Google in the Chrome browser. This eliminates the need to type out site:experts-exchange.com whenever you want to search the site. Launch the Search Engine Menu: In chrome, via you…

912 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now