PE-TLBS: Secure Location Based Services Environment with Emphasis on Direct Anonymous Attestation Protocol

Hanunah Othman, Habibah Hashim, Jamalul‐lail Ab Manan · International Journal of Multimedia and Image Processing · 2011

Nowadays, an IT officer would normally use virtualization as a security mechanism to provide clandestine isolation environment and concurrently hope with optimism to secure the emerging of cloud computing.Indeed, virtualization offers some kind of computing defense from being attacked from the cloud infrastructure.Significantly, the proliferation of Location Based Services in mobile and wireless communication has also increased the need to address security, privacy and trust issues.Thus, this paper presents Privacy Enhanced-Trusted Location Based Services (PE-TLBS) framework which create more trusted and privacy preserving services on top of existing Mobile Location Protocol (MLP).The framework implements a simplified protocol based on Direct Anonymous Attestation (DAA) scheme supported by Trusted Platform Module (TPM) functionalities.A Trusted Group of users/clients is organized based on P2P communication concept and the trust-ability is measured by using RSA key pairs.A Privacy CA acts as an issuer organization which validates the embedded TPM before clients use an LBS service.TPM Emulator and TCG Software Stack simulate and make the accession to TPM much simpler while maintaining the functionality as well as providing Application Programming Interfaces (APIs).We have initiated a virtualized Proof of Concept (PoC) environment to validate the framework.We anticipate that the proposed framework would be able to mitigate threats, and strengthen customers' confidence on using LBSs.

Read the paper · More papers on PaperTik