2015
DOI: 10.1007/978-3-319-27659-5_22
|View full text |Cite
|
Sign up to set email alerts
|

Fine-Grained Access Control for HTML5-Based Mobile Applications in Android

Abstract: HTML5-based mobile applications are becoming more and more popular because they can run on different platforms. Several newly introduced mobile OS natively support HTML5-based applications. For those that do not provide native support, such as Android, iOS, and Windows Phone, developers can develop HTML5-based applications using middlewares, such as PhoneGap [17]. In these platforms, programs are loaded into a web component, called WebView, which can render HTML5 pages and execute JavaScript code. In order for… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
2
2
1

Citation Types

0
21
0

Year Published

2016
2016
2020
2020

Publication Types

Select...
4
2
1

Relationship

0
7

Authors

Journals

citations
Cited by 27 publications
(21 citation statements)
references
References 14 publications
0
21
0
Order By: Relevance
“…Jin et al [8] addressed the security problems encountered due the existence of bridges between PhoneGap and Android, those bridges break the protection that was already implemented in the WebView because they create holes in the sandbox of the WebView usage architecture. They study the reduction of the permission reachability without effecting business model so they designed a permission based access control model to control permission usage based on frames, it allow developers to assign different permissions to different frames.…”
Section: Related Workmentioning
confidence: 99%
See 1 more Smart Citation
“…Jin et al [8] addressed the security problems encountered due the existence of bridges between PhoneGap and Android, those bridges break the protection that was already implemented in the WebView because they create holes in the sandbox of the WebView usage architecture. They study the reduction of the permission reachability without effecting business model so they designed a permission based access control model to control permission usage based on frames, it allow developers to assign different permissions to different frames.…”
Section: Related Workmentioning
confidence: 99%
“…This study is based on current implementation of the latest Apache Cordova version (3.5.0) released on (June 12, 2014). Security of such platforms has recently gained the attention, several studies [1,4,8] have analyzed possible security threats and have proposed possible solutions. In this paper, our study focuses on the plugin access model implemented by Cordova framework, which to the best of our knowledge has not been addressed nor analyzed in previous studies.…”
Section: Introductionmentioning
confidence: 99%
“…There have been several works introducing more fine-grained access control mechanism for the cross-language interface in hybrid mobile apps, particularly Cordova, such as NoFrak [10], MobileIFC [22], and others [12,21]. They all identified the breach of the sandbox security and that Cordova fails to restrict access to plugins by untrusted JavaScript code as the major security and privacy concern.…”
Section: Security Considerations For Cordova Appsmentioning
confidence: 99%
“…Recent works applied the access control and the privilege separation mechanisms in JavaScript and presented several sandbox mechanisms to protect its users from the malicious scripts in the traditional web applications and the HTML5 applications.…”
Section: Related Workmentioning
confidence: 99%