[论文解读] SoK: Decoding the Super App Enigma: The Security Mechanisms, Threats, and Trade-offs in OS-alike Apps
对在类似微信、支付宝等类操作系统平台内运行的超级应用(小程序)的安全机制、威胁及权衡的系统性研究。
The super app paradigm, exemplified by platforms such as WeChat and AliPay, has revolutionized the mobile app landscape by enabling third-party developers to deploy add-ons within these apps. These add-ons, known as miniapps, leverage user data hosted by the super app platforms to provide a wide range of services, such as shopping and gaming. With the rise of miniapps, super apps have transformed into "operating systems", offering encapsulated APIs to miniapp developers as well as in-app miniapp stores for users to explore and download miniapps. In this paper, we provide the first systematic study to consolidate the current state of knowledge in this field from the security perspective: the security measures, threats, and trade-offs of this paradigm. Specifically, we summarize 13 security mechanisms and 10 security threats in super app platforms, followed by a root cause analysis revealing that the security assumptions still may be violated due to issues in underlying systems, implementation of isolation, and vetting. Additionally, we also systematize open problems and trade-offs that need to be addressed by future works to help enhance the security and privacy of this new paradigm.
研究动机与目标
- 总结超级应用生态系统与小程序的演变与架构。
- 编目并分析实施隔离、访问控制与审核的安全机制。
- 识别由底层系统、实现与审核引发的安全威胁及根本原因。
- 综合经验教训并勾勒待解决的问题,以指导未来的安全研究。
提出的方法
- 对前端与后端组件的13项安全机制进行透彻的文献与平台特定分析。
- 将机制与潜在违规(如隔离、审核漏洞、平台信任)之间的根本原因进行关联分析。
- 对超级应用与网页及原生应用范式进行分类学比较,识别独特的安全挑战。

实验结果
研究问题
- RQ1超级应用为保护资源与数据而实现了哪些安全机制?
- RQ2哪些威胁影响超级应用,哪些根本原因使这些威胁成为可能?
- RQ3在提升小程序生态系统的安全与隐私方面,有哪些经验教训与待解决的问题?
主要发现
- 在超级应用中,前端与后端组件共存在13项安全机制。
- 识别出有根本原因的安全威胁共10项,原因包括底层系统问题、隔离性、审核漏洞。
- 分析给出5条经验教训和4个待解决的问题,以指导未来在自动化分析、标准化、开发者教育和语义审核方面的工作。

更好的研究,从现在开始
从论文设计到论文写作,大幅缩短您的研究时间。
无需绑定信用卡
本解读由 AI 生成,并经人工编辑审核。