SECURE AUTHENTICATION AND SWITCHING TO ENCRYPTED DOMAINS
A device and method for switching to an encrypted domain requiring authentication in an operating system which implements a plurality of secure domains. An intermediate domain different from the encrypted domain and a current domain is provided. Upon receiving a request to switch to the encrypted domain, the system switches to the intermediate domain. An authentication challenge for access to the encrypted domain is displayed in the intermediate domain. Receiving authentication information is used to decrypt filesystem keys for providing access to the encrypted filesystem. The encrypted filesystem is then mounted, and the encrypted domain started.
1 . In a device comprising a processor and a memory storing instructions executable by the processor to implement an operating system providing a plurality of domains including a current domain and a target domain, wherein the target domain is stored at least in part in an encrypted filesystem, wherein access to the target domain requires authentication and access to the encrypted filesystem, a method of switching from the current domain to the target domain, the method comprising:
providing an intermediate domain different from the current domain and the target domain;
receiving a request to switch to the target domain;
determining that the target domain is not running, is stored at least in part in the encrypted filesystem, and requires authentication for access;
switching to the intermediate domain;
displaying in the intermediate domain an authentication challenge for access to the target domain;
receiving authentication information in response to the authentication challenge;
decrypting, based on the authentication information, filesystem keys for providing access to the encrypted filesystem;
providing access to the encrypted filesystem based on the filesystem keys, and mounting the encrypted filesystem; and
starting the target domain.
2 . The method according to claim 1 , wherein the target domain is not running when no process associated with the target domain is running.
3 . The method according to claim 1 , wherein at least some user interface elements associated with the target domain are stored in a filesystem different from the encrypted filesystem, the method further comprising displaying the user interface elements along with the authentication challenge.
4 . The method according to claim 1 further comprising displaying along with the authentication challenge a visual element which identifies the target domain.
5 . The method according to claim 4 , wherein the visual element is a wallpaper.
6 . The method according to claim 1 , wherein an input method editor associated with the target domain is stored in a filesystem different from the encrypted filesystem, and wherein receiving the authentication information in response to the authentication challenge comprises receiving the authentication information by means of the input method editor.
7 . The method according to claim 1 , wherein an input method editor associated with the target domain is stored in the encrypted filesystem, the method further comprising:
prior to receiving the authentication information, receiving a selection of an input method editor, wherein receiving the authentication information in response to the authentication challenge comprises receiving the authentication information by means of the input method editor.
8 . The method according to claim 1 , wherein the operating system comprises a Linux kernel, and wherein providing access to the encrypted filesystem based on the filesystem keys comprises storing the filesystem keys in a kernel keyring.
9 . The method according to claim 1 , wherein the encrypted filesystem is a cryptographic stacked filesystem.
10 . The method according to claim 1 , wherein the encrypted filesystem is an eCptFS filesystem.
11 . The method according to claim 1 , where an additional block level data encryption is applied to the encrypted filesystem.
12 . The method according to claim 1 , where an additional device level data encryption is applied to the encrypted filesystem.
13 . The method according to claim 1 further comprising, following mounting of the encrypted filesystem, dismissing a lock screen associated with the target domain.
14 . The method according to claim 1 , wherein the intermediate domain is configured to permit the launching only of processes from a predetermined set of applications or services.
15 . The method according to claim 1 , wherein a policy of the intermediate domain is configured to permit the launching only of a predetermined set of applications or services.
16 . The method according to claim 15 , wherein the operating system is an SEAndroid operating system, and wherein the policy of the intermediate domain comprises an SEAndroid policy.
17 . The method according to claim 1 , wherein providing the intermediate domain comprises creating the intermediate domain at start-up or initial configuration of the operating system.
18 . The method according to claim 1 , wherein providing the intermediate domain comprises creating the intermediate domain in response to creation of the target domain.
19 . The method according to claim 1 , wherein the operating system provides the plurality of domains by, for each domain:
(a) associating resources of the domain with a unique domain identifier, the resources comprising at least one data file or at least one application;
(b) storing a policy in association with the unique domain identifier, the policy comprising a rule set for controlling access to the resources; and
(c) controlling access to the domain resources based on the policy associated with the domain.
20 . The method according to claim 19 , wherein the operating system provides the plurality of domains by executing at least one service of the operating system at least partly outside of a kernel of the operating system.
21 . The method according to claim 20 , wherein the operating system provides the plurality of domains by executing at least one further service of the operating system within the kernel of the operating system.
22 . The method according to claim 19 , wherein the operating system implements a plurality of user accounts, and wherein the current domain and the target domain are commonly associated with one of the user accounts.
23 . The method according to claim 19 , wherein (c) comprises controlling access by a process to the target domain resources based on the policy associated with the target domain, wherein the process is associated with one of the other domains different from the target domain.
24 . The method according to claim 23 , wherein the process is associated with an execution context identifier based on the unique domain identifier of the other domain, and wherein (c) comprises controlling access by the process to the target domain resources based on the execution context identifier.
25 . The method according to claim 24 , wherein the resources of the other domain comprise the at least one application, and wherein the execution context identifier is based on the unique domain identifier of the other domain and a unique application identifier associated with the at least one application executed to generate the process.
26 . The method according to claim 25 , where the operating system is an Android operating system, the unique application identifier is a Unix-type user identifier (UID) assigned to the application on installation, the execution context identifier comprises the UID of the application, and the unique domain identifier is contained in reserved bits of the UID.
27 . The method according to any one of claims 1 to 26 , wherein the current domain and the target domain each comprise at least one application executable in the operating system without intermediation of another operating system.
28 . A computer-readable medium comprising instructions stored thereon that, when executed by a computer, perform the method of any one of claims 1 to 27 .
29 . A device comprising a processor and a memory storing instructions executable by the processor to implement an operating system providing a plurality of domains including a current domain and a target domain, wherein the target domain is stored at least in part in an encrypted filesystem, wherein access to the target domain requires authentication and access to the encrypted filesystem, wherein the instructions are further executable to perform a method of switching from the current domain to the target domain, the method comprising:
providing an intermediate domain different from the current domain and the target domain;
receiving a request to switch to the target domain;
determining that the target domain is not running, is stored at least in part in the encrypted filesystem, and requires authentication for access;
switching to the intermediate domain;
displaying in the intermediate domain an authentication challenge fo access to the target domain;
receiving authentication information in response to the authentication challenge;
decrypting, based on the authentication information, filesystem keys for providing access to the encrypted filesystem;
providing access to the encrypted filesystem based on the filesystem keys, and mounting the encrypted filesystem; and
starting the target domain.
30 . The device according to claim 29 , wherein the current domain and the target domain each comprise at least one application executable in the operating system without intermediation of another operating system.