信息安全研究 ›› 2022, Vol. 8 ›› Issue (10): 984-.

• 数据安全与隐私计算专题 • 上一篇    下一篇

基于安全容器的券商APP用户隐私威胁行为管控技术研究

宋士明
  

  1. (南京证券股份有限公司南京210019)
  • 出版日期:2022-10-25 发布日期:2022-10-24
  • 通讯作者: 宋士明 硕士,高级工程师.主要研究方向为信息安全技术和架构、安全管理与运营. smsong1120@126.com
  • 作者简介:宋士明 硕士,高级工程师.主要研究方向为信息安全技术和架构、安全管理与运营. smsong1120@126.com

Research on User Privacy Threat Behavior Management and Control  Technology of Brokerage APP Based on Security Container

  • Online:2022-10-25 Published:2022-10-24

摘要: 为解决券商APP中第三方SDK可能侵犯用户隐私的问题,在研究Android安全沙箱技术基础上,提出了一种移动端安全沙箱技术,通过结合安全沙箱管控策略,在APP用户侧运行态下,实现对隐私采集、通信外发、组件热更新3类APP隐私威胁行为的全面监测与阻断能力,进而实现对由第三方SDK产生的超出APP隐私政策的隐私威胁行为的管控,提升券商APP的整体隐私威胁管控能力和个人信息保护水平.

关键词: 券商APP, 用户隐私, 第三方SDK, Android安全沙箱, 隐私威胁管控

Abstract: In order to solve the problem that thirdparty SDKs in brokerage APPs may violate user privacy, this paper proposes a mobile terminal security sandbox technology based on the research of Android security sandbox technology. By combining the security sandbox management and control strategy, it runs on the APP user side. In this state, it realizes comprehensive monitoring and blocking capabilities for three types of APP privacy threat behaviors, such as privacy collection, communication outbound, and component hot update, so as to realize the management and control of privacy threat behaviors generated by thirdparty SDKs that exceed the APP privacy policy, and improve the overall privacy threat management capability and personal information protection level of the brokerage APP.

Key words: brokerage APP, user privacy, thirdparty SDK, Android security sandbox, privacy threat management and control