Skip to content
Open access

P-Box: Preventing Unwanted Data Flows using Permission Sandboxes on Android

Oct 2026 · Proceedings on Privacy Enhancing Technologies · Vol 2026, pp. 232-247 · 0 citations · 85 references
Computer Science

TL;DR

This work presents an addition to current permission systems that splits apps into multiple sandboxed processes to enforce fine-grained privacy and data-flow controls on smartphones, and implements a proof-of-concept based on the Android Open Source Project code base.

Abstract

One of the core privacy features of smartphone operating systems is a permission framework that requires explicit user consent before granting apps access to private data. Such systems are deeply integrated into Google's Android and Apple's iOS, which together account for the majority of the smartphone operating system market. While permission systems can be seen as milestones in user empowerment and privacy protection, they offer users only a binary choice: whether an app can access a specific resource or not. As soon as an app is allowed to read a resource, the operating system loses control over its further use. Most apps have Internet access and can send permission-protected data, like a user's location, over the Internet, which can harm user privacy. To solve this problem, we present an addition to current permission systems that splits apps into multiple sandboxed processes to enforce fine-grained privacy and data-flow controls on smartphones. By default, our design forces apps to process permission-protected data locally on the device, thereby eliminating the need for apps to request runtime permissions for local-only use cases. We implement a proof-of-concept based on the Android Open Source Project code base. We showcase our framework's practicability by adapting multiple app use cases to our system, benchmarking its computational overhead, and discussing the implications for platform operators, developers, and users.

Read PDF

Similar papers

Preprint Aug 2026

Exploring Privacy Leakage and Data Disclosure Violations in the MacOS Application Ecosystem

Analysis of the mechanisms designed to regulate and disclose data collection and sharing practices in the macOS ecosystem reveals how the macOS app ecosystem is comprised of disjoint mechanisms with divergent data abstractions, thus increasing complexity for developers while also facilitating undisclosed privacy-invasi...

Jyotirmay Chauhan, Kostas Solomos, Mir Masood Ali et al. · 0 citations

SURFACE at Syracuse University SURFACE at Syracuse University

Two essential pieces of the Web’s security infrastructure are weakened if Web-View and its APIs are used: the Trusted Computing Base at the client side, and the sandbox protection implemented by browsers.

Tongbo Luo, Hao Hao, Wenliang Du et al. · 0 citations
Preprint Sep 2026

You Shall Not Pass into Ring-0! A User Privacy-Friendly Anti-Cheat Architecture for Personal Computers

Kernel-level anti-cheats are effective against malicious player behavior in competitive video games, but raise significant user privacy concerns regarding installing unverifiable components at privileged modes (i.e., ring-0 in x86). While existing research has focused on improving the effectiveness of anti-cheats, the...

Santosh Gokul Narayanan, G. Paladino, Chu-Qi Zhang et al. · 0 citations
Review Open access Sep 2026

Security and Privacy in Android

GeminiShield is proposed, a layered security architecture that integrates Gemini AI across the Android software stack, and its efficacy is validated through comparative analysis against state-of-the-art approaches, demonstrating detection accuracy of 97.3%, outperforming prior approaches while maintaining acceptable co...

N. K. Yadati, Diwakar Reddy Peddinti, Saurabh Prakash Shetty · 0 citations
Review Aug 2026

A User-Centric Context-Aware Permission Governance Framework for Privacy Control in Default Mobile Applications

A feature-based authorization option, "Allow When Needed," is introduced that restricts access to the functionality requiring the data rather than the entire application session and provides preliminary evidence that context-aware permission governance can improve user understanding and decision clarity.

Asmau Yetunde Adeniran, A. Ademuwagun, F. Adamu-Fika et al. · 0 citations

We use cookies to run the site and, with your consent, for analytics and to show ads. See our Cookie Policy.