This article introduces a distributed model of trust for app developers in Android and iOS mobile ecosystems. The model aims to allow the co-existence of multiple app stores and distribution channels while retaining a high level of safety for mobile device users and minimum changes to current mobile operating systems. The Developers Certification Model (DCM) is a trust model for Android and iOS that aims to distinguish legit applications from security threats to user safeness by answering the question: "is the developer of this app trustable"? It proposes security by design, where safety relies on a chain of trust mapping real-world levels of trust across organizations. For the technical implementation, DCM is heavily inspired by SSL/TLS certification protocol, as a proven model that has been working for over 30 years.
翻译:摘要:本文介绍了一种面向安卓与iOS移动生态系统中应用开发者的分布式信任模型。该模型旨在允许多个应用商店与分发渠道共存,同时为移动设备用户维持高安全性,并对当前移动操作系统进行最小化改动。开发者认证模型(DCM)是一种针对安卓与iOS的信任模型,旨在通过回答“此应用的开发者是否可信?”这一问题,将合法应用与威胁用户安全的风险区分开来。该模型提出“安全通过设计”理念,其中安全性依赖于一条跨组织映射现实世界信任等级的信任链。在技术实现上,DCM深受SSL/TLS认证协议启发,该协议作为已被验证有效的模型已成功运行超过30年。