Android’s ubiquitous flexibility has helped it to become one of the most widely used mobile operating systems in the world. However, the convenient and extensive access to phone resources adopted by Android has revealed inefficiencies of its existing protections. Among these protections is application (app) signing. This process is intended to maintain the integrity of the app after it is released, and it provides users with confidence in the app’s authenticity. We analyze the functionality of Android signature verification and identify the logical gaps in the process that can be used to hide a malicious payload. We demonstrate the security implications of these gaps.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

More Than You Signed Up For: Exposing Gaps in the Validation of Android’s App Signing

  • Norah Ridley,
  • Enrico Branca,
  • Natalia Stakhanova

摘要

Android’s ubiquitous flexibility has helped it to become one of the most widely used mobile operating systems in the world. However, the convenient and extensive access to phone resources adopted by Android has revealed inefficiencies of its existing protections. Among these protections is application (app) signing. This process is intended to maintain the integrity of the app after it is released, and it provides users with confidence in the app’s authenticity. We analyze the functionality of Android signature verification and identify the logical gaps in the process that can be used to hide a malicious payload. We demonstrate the security implications of these gaps.