20.08.2015 Views

SELinux in Android Lollipop and M

lss2015_selinuxinandroidlollipopandm_smalley

lss2015_selinuxinandroidlollipopandm_smalley

SHOW MORE
SHOW LESS

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Service-specific Protection via <strong>SEL<strong>in</strong>ux</strong>• <strong>Android</strong> keystore– Provides secure storage of keys.• <strong>SEL<strong>in</strong>ux</strong> kernel-enforced guarantees:– Noth<strong>in</strong>g can ptrace the keystore.– Noth<strong>in</strong>g else can open /data/misc/keystore files.• <strong>SEL<strong>in</strong>ux</strong> userspace access control:– Keystore checks <strong>SEL<strong>in</strong>ux</strong> policy for client requests.– Sensitive operations restricted via policy.7

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!