• DocumentCode
    2960436
  • Title

    Cross-Platform Access Control for Mobile Web Applications

  • Author

    Lyle, John ; Monteleone, Salvatore ; Faily, Shamal ; Patti, Davide ; Ricciato, Fabio

  • fYear
    2012
  • fDate
    16-18 July 2012
  • Firstpage
    37
  • Lastpage
    44
  • Abstract
    Web browsers are a common platform for delivering cross-platform applications. However, they currently fail to provide consistent access control for security and privacy sensitive JavaScript APIs, such as geolocation and local storage. This problem is exacerbated by new HTML5 APIs and the increasing number of personal devices people own and use. In this paper we present the webinos platform which aims to provide a single, cross-device policy system for web applications on a wide range of web-enabled devices including TVs, smartphones, in-car systems and PCs. webinos solves the existing deficiencies in web authorisation by introducing the concept of a personal zone, the set of all devices and services owned by a particular user. All devices in this zone can synchronize their access control policies through interoperable middleware and can create flexible rules which may refer to an individual user, device or the entire zone. We provide details of the architecture and explain how our experience during design highlighted several conceptual challenges.
  • Keywords
    Internet; Java; application program interfaces; authorisation; data privacy; mobile computing; online front-ends; smart phones; HTML5 API; PC; TV; Web browsers; Web-enabled devices; cross-device policy system; cross-platform access control; cross-platform applications; in-car systems; interoperable middleware; mobile Web applications; personal devices; personal zone; privacy sensitive JavaScript API; security sensitive JavaScript API; smartphones; web authorisation; webinos platform; Access control; Browsers; Context; Geology; Mobile communication; Smart phones; access control; api; middleware; policy; synchronization; web applications; webinos;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Policies for Distributed Systems and Networks (POLICY), 2012 IEEE International Symposium on
  • Conference_Location
    Chapel Hill, NC
  • Print_ISBN
    978-1-4673-1993-5
  • Type

    conf

  • DOI
    10.1109/POLICY.2012.9
  • Filename
    6267999