Nien-Chi Liu

dblp:150/4313 · DBLP profile ↗
← Back
1ranked-venue papers
0as first author
1since 2021 · last 2021
0000-0001-9921-4110ORCID · reported

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 1 · 1 since 2021

Expertise — from the expertise taxonomy: the topics of the expert's papers under the CCF categories. A weight counts papers with recency: 1 for a paper about the topic, 0.3 when the topic is its context, halved every five years.

Network and information security
1 paper
Web and mobile security · 50% Authentication and access control · 25% Privacy and data protection · 25%
Software engineering, system software, and programming languages
1 paper
Software maintenance and evolution · 100%

Topics — the 5 heaviest of 5, each with the papers that count most for it

TopicWeightPapersLastEvidence papers
Authentication and access control
access control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security › mobile security
android permission control
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Web and mobile security
mobile security
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Privacy and data protection › mobile privacy
runtime permission management
0.512021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021
Software maintenance and evolution › software ecosystems
third-party libraries
0.112021
DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries · IEEE Trans. Dependable Secur. Comput. 2021

Methods — techniques the papers use, named apart from their topics

dynamic permission API · 1.0android framework modification · 1.0
YearPublicationVenuePosition
2021 DPC: A Dynamic Permission Control Mechanism for Android Third-Party Libraries
abstract
Today's smartphone app stores are full of apps with diverse features. Many developers use third-party libraries to reduce the development time and cost, but developers often ignore the security problems of third-party libraries. A major security problem introduced by third-party libraries is that a third-party library has the same permissions as the apps, calledhost-appshereafter, that use it. According to previous research, having the same permissions as its host apps, a third-party library could have unauthorized access to user data, which poses a serious threat to app users. Therefore, how to prevent third-party libraries from abusing permissions has become an important issue. To solve this problem, this paper proposes a Dynamic Permission Control mechanism, calledDynamic Permission ControllerorDPChereafter, for app developers to prohibit third-party libraries from abusing host apps’ dangerous permissions. DPC modifies the permission control mechanism of Android framework to make apps have a more flexible permission management mechanism when they are running. DPC provides new APIs which allows an app to dynamically disable a granted dangerous permission before invoking an API of a third-party library and restore the dangerous permission after completing the API. Hence, DPC protects user's privacy by blocking unauthorized access from third-party libraries. Meanwhile, without the requirement that an app developer needs to know the detail of third-party libraries, the app still can use APIs of third-party libraries safely. Experimental results show that DPC works with many popular apps downloaded from Google Play well and DPC prohibits a third-party library from having the same dangerous permissions that its host apps have. Hence, unlike previous solutions, DPC does not have compatibility problems. The overhead introduced by DPC on an emulator and Nexus 7 are 1.8 and 0.3 percent respectively.
Fu-Hau Hsu, Nien-Chi Liu, Yanling Hwang, Che-Hao Liu, Chuan-Sheng Wang, Chang-Yi Chen
IEEE Trans. Dependable Secur. Comput.2