Bring Your Own Device, Securely
A. Armando, G. Costa, A. Merlo, L. Verderame
28th Symposium On Applied Computing (SAC 2013)
Security Track
Agenda
I
BYOD paradigm, Android and Users;
I
Formal reasoning about Android;
I
Type and Effect System for Mobile Apps;
I
Writing and verifying BYOD policies;
The BYOD paradigm on mobile
I
The Bring Your Own Device paradigm pushes the use of
personal devices inside organizations.
I
BYOD solutions must both
1.
allow users to freely personalize devices outside the
organization;
2.
grant the security of corporate data accessed by personal
devices inside the organization.
I
Mobile OSes do not have the sufficient level of protection
Android, Security and Users
Device owner Personal Device A1, A2, , AN App market - Internet - Access SD card Manifest of AX - Access SD card Manifest of AYManifests and Apps
I
Android applications come up
with a manifest file, containing
required permissions.
I
Users must accept at install time
all the required permissions.
I
Do users understand both the
meaning and the impact of such
permissions on their
Android and BYOD
Device owner
Personal Device
BYOD Policy:
« devices cannot access the network after accessing local file system in the same session»
A1, A2, , AN Corporation App market - Internet - Access SD card Manifest of AX - Access SD card Manifest of AY
BYOD through secure meta-markets
Personal Device A1, A2, , AN Corporation App market Secure Meta-marketManifests and Apps
BYOD Policy Require AY