Path: EDN Asia >> News Centre >> Consumer Electronics >> Framework eases use of new Android security tools
Consumer Electronics Share print

Framework eases use of new Android security tools

22 Aug 2014

Share this page with your friends

A modified core Android operating system allows developers and users to plug in new security enhancements, thanks to the work of computer security researchers from Technische Universität Darmstadt/CASED in Germany and North Carolina State University.

The new Android Security Modules (ASM) framework aims to eliminate the bottleneck that prevents developers and users from taking advantage of new security tools.

"In the ongoing arms race between white hats and black hats, researchers and developers are constantly coming up with new security extensions," says Dr. William Enck, an assistant professor of computer science at NC State and a senior author of a paper describing the new framework. "But these new tools aren't getting into the hands of users because every new extension requires users to change their device's firmware, or operating system (OS).

"The ASM framework allows users to implement these new extensions without overhauling their firmware," Enck says. "The framework is available now for security enthusiasts. But for widespread adoption, either Google or one of the Android phone manufacturers will need to adopt the framework and incorporate it into the OS."

The ASM framework allows the creation of custom security control modules that better protect phones owned by consumers and businesses. The custom security modules receive "callbacks" for every security-sensitive operation in the Android OS. In this context, a callback means that Android is contacting the security module to determine whether an operation should proceed.

"Our ASM framework can be used in various personal and enterprise scenarios. For instance, security modules can implement dual persona: i.e., enable users to securely use their smartphones and tablets at home and at work while strictly separating private and enterprise data," says Enck.

"Security modules can also enhance consumer privacy. The framework provides callbacks that can filter, modify, or anonymise data before it is shared with third-party apps, in order to protect personal information," Enck says. "For instance consider an app like Whatsapp, which usually copies all your contacts to its server, which is not needed for it to function." With ASM, the user can make sure Whatsapp only gets the information it really needs.

"In addition, we designed the framework to allow apps to create their own hooks, which could be enforced by the security module," Enck says. "This increases flexibility for app developers and allows them to benefit from the security protections provided by the module."

The researchers also went to great lengths to ensure that the ASM framework complies with the security guarantees Google and others make with app developers. For example, the framework can only make data access more restrictive.




Want to more of this to be delivered to you for FREE?

Subscribe to EDN Asia alerts and receive the latest design ideas and product news in your inbox.

Got to make sure you're not a robot. Please enter the code displayed on the right.

Time to activate your subscription - it's easy!

We have sent an activate request to your registerd e-email. Simply click on the link to activate your subscription.

We're doing this to protect your privacy and ensure you successfully receive your e-mail alerts.


Add New Comment
Visitor (To avoid code verification, simply login or register with us. It is fast and free!)
*Verify code:
Tech Impact

Regional Roundup
Control this smart glass with the blink of an eye
K-Glass 2 detects users' eye movements to point the cursor to recognise computer icons or objects in the Internet, and uses winks for commands. The researchers call this interface the "i-Mouse."

GlobalFoundries extends grants to Singapore students
ARM, Tencent Games team up to improve mobile gaming


News | Products | Design Features | Regional Roundup | Tech Impact