Istituto di Informatica e Telematica     
Martinelli F., Matteucci I., Saracino A., Sgandurra D. Remote Policy Enforcement for Trusted Application Execution in Mobile Environments. In: InTrust 2013 (Graz, Austria, 2013). Proceedings, pp. 70 - 84. Springer, 2013.
Both in the cloud and mobile environments, a large number of online services is daily accessed through smartphones and tablets. Since several security, safety and trust concerns may arise when using these services, providers may require a usage policy to be enforced on the devices while accessing these services. This kind of policy enforcements enables service providers to have assurance that remote devices are in an acceptable state when using the provided service, according to their terms and conditions. In this paper, we propose a framework which allows service providers to have assurance about the enforcement of some functional policies directly on the device. The proposed framework inserts an enforcer into the client?s device, which is responsible for enforcing the provider?s policy to abide by the terms and conditions of the service. To assure the integrity of the enforcer and of the policy, the framework exploits Trusted Computing techniques to remotely attest the enforcer?s measurements. Preliminary experiments and a first prototype implementation for Android-based smartphones suggest that the approach is both viable and effective.
Subject Systems and Data Security
D.4.6 Security and Protection (K.6.5) Access controls

Icona documento 1) Download Document PDF

Icona documento Open access Icona documento Restricted Icona documento Private


Per ulteriori informazioni, contattare: Librarian http://puma.isti.cnr.it

Valid HTML 4.0 Transitional