Skip to Main Content (Press Enter)

Logo UNIBG
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze

UNI-FIND
Logo UNIBG

|

UNI-FIND

unibg.it
  • ×
  • Home
  • Corsi
  • Insegnamenti
  • Persone
  • Pubblicazioni
  • Strutture
  • Terza Missione
  • Attività
  • Competenze
  1. Pubblicazioni

Fine-grained Access Control Technologies to Protect Resources in Mobile and Cloud Applications

Libro
Data di Pubblicazione:
2025
Citazione:
(2025). Fine-grained Access Control Technologies to Protect Resources in Mobile and Cloud Applications . Retrieved from https://hdl.handle.net/10446/307914 Retrieved from http://dx.doi.org/10.13122/978-88-97253-25-9
Abstract:
Operating system security has evolved to address numerous threats. Mitigating
these threats is crucial for mobile operating systems given their widespread use
and the sensitive data they handle. In Android, application components share
access to internal storage and system services. While this may not be an issue
when the developer trusts all the code, it introduces significant risks with
third-party code. We address this by proposing SEApp, a mechanism for
isolating Android app components and managing their permissions, thereby
enhancing user privacy and data protection.

Securing cloud applications that interact with mobile devices is equally
important. Modern cloud applications often involve complex service
interactions, and existing technologies lack the granularity needed for
effective resource access control. We address this by proposing a
resource-based approach to restrict file system access. We also examine
WebAssembly runtimes (e.g., Wasmtime and WasmEdge), highlighting the security
implications of the WebAssembly System Interface (WASI) and identifying areas
for improvement.

Furthermore, we explore the use of JavaScript (JS) and TypeScript (TS) for cloud
applications, utilizing JS runtimes (Node.js, Deno, and Bun). While these
runtimes offer sandboxed JS code execution, access to system resources and
native code introduces security risks by compromising application isolation. To
mitigate these risks, we introduce NatiSand, a component for JavaScript
runtimes that controls file system, Inter-Process Communication (IPC), and
network resources for binary programs and shared libraries.

The technologies detailed in this book advance fine-grained resource protection
in both mobile and cloud applications. The open-source prototypes demonstrate
integration with existing systems, effectiveness, and efficiency.
Tipologia CRIS:
1.9.03 Collana della Scuola di Alta Formazione Dottorale
Elenco autori:
Rossi, Matthew
Autori di Ateneo:
ROSSI Matthew
Link alla scheda completa:
https://aisberg.unibg.it/handle/10446/307914
Link al Full Text:
https://aisberg.unibg.it/retrieve/handle/10446/307914/904373/CollanaSAFD_Volume83_2025.pdf
Pubblicato in:
COLLANA DELLA SCUOLA DI ALTA FORMAZIONE DOTTORALE
Series
  • Ricerca

Ricerca

Settori


Settore IINF-05/A - Sistemi di elaborazione delle informazioni
  • Utilizzo dei cookie

Realizzato con VIVO | Designed by Cineca | 26.5.1.0