Android Kernel Access Control Policy Configuration via Web Interface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users without expert knowledge find it difficult to set and manage access control policies for Android-based mobile terminals, especially in subdividing and specializing security settings to limit illegal access to applications and data, which is crucial as smartphones are increasingly used for work-related purposes.
Innovation Solution
A method and system for configuring a simple kernel access control policy using a web user interface on a management server, where a list of subjects and objects is created to formulate system and application policies, which are then combined into group policies and distributed to mobile terminals, allowing for flexible and efficient access control management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If detailed and strict access control policies are formulated to enhance security, then security levels are improved, but the complexity of policy formulation increases
Solution Approach 1:
The access control policy is segmented into multiple hierarchical levels: domain policies at the top level, subsystem policies in the middle, and object policies at the bottom level. This segmentation allows security to be implemented through manageable units rather than a single complex policy, resolving the contradiction between security enhancement and formulation complexity.
Solution Approach 2:
A policy manager component is introduced as an intermediary between administrators and the access control system. This mediator automatically handles policy formulation, translation, and distribution, reducing the complexity burden on users while maintaining strict security control through the hierarchical policy structure.
2Reliability
If access control policies are subdivided and specialized to limit illegal access to applications and data, then security control is improved, but the difficulty of policy setting increases
Solution Approach 1:
The policy structure is divided into domain, subsystem, and object levels, allowing specialized security control for different applications and data. Each level can be independently configured, making it easier to implement specialized access control without overwhelming the user with a single complex policy.
Solution Approach 2:
The system provides automatic policy translation and distribution through the policy manager, enabling users to define access control rules at high levels without manually configuring detailed subsystem and object policies. The system self-manages the complexity of policy translation and enforcement.
3Ease of operation
If a web user interface is used to simplify access control policy configuration, then ease of operation is improved, but system complexity increases
Solution Approach 1:
The web user interface acts as an intermediary layer that simplifies policy configuration for users while the backend policy manager handles the complex translation and distribution of these simplified inputs into enforceable access control policies. This separates the simplicity of the user interface from the complexity of the underlying system.
Solution Approach 2:
The complex mechanical process of manual access control policy configuration is replaced with an automated web-based interface and policy translation system. This substitution maintains or enhances ease of operation while managing system complexity through software-based automation rather than manual configuration.
Data Source
AI summary
A method of configuring a simple kernel access control policy for an Android-based mobile terminal includes: creating an entire list in a file system of a plurality of mobile terminals through a web user interface of a management server; creating a system policy set and an application policy set by recognizing in advance subjects and objects in the entire list by means of the management server; creating a group policy for each user group on the basis of the system policy set and the application policy set by means of the management server; distributing the group policies to the mobile terminals by means of the management server; and executing the group policies by means of the mobile terminals.


