Keywords : resource analysis, access control, security model.

Access control model for interactive devices

Participants : Frédéric Besson, Thomas Jensen, David Pichardie.

The Lande groups continues its investigation of access control mechanisms by studying the security policy of mobile devices  [14] . We have designed a security model for programming applications in which the access control to resources can employ user interaction to obtain the necessary permissions. Our work is inspired by and improves on the current Java security architecture used in Java-enabled mobile smart phones. We consider access control permissions with multiplicities in order to allow to use a permission a certain number of times and reduce the number of user interactions. To support our security model, a static analysis is enforcing, at load-time, that resources are accessed correctly. This work extends a previous model proposed in [34] .


