Adapting Public Key Infrastructures to the Mobile Environment
N. T. Trask, Semia Jaweed · Institution of Engineering and Technology eBooks · 2002
A prerequisite for many commercially attractive services is the deployment of a secure infrastructure protecting the interests of all the parties. For many of the mobile operators and service providers the PKI model is of particular interest, offering the authentication, integrity, non-repudiation and confidentiality requirements demanded by many application providers. Financial institutions, for example, need to offer their customers the ability to bank on-line or trade in shares using their mobile devices, while retaining the same level of transaction security available in the 'wired world'. Currently under GSM, there are two common approaches to providing value added services on top of bearer services - via SIM Toolkit (STK) or via the use of wireless application protocol (WAP). There are already a number of STK-based PKI solutions available from vendors today, but while they may offer early-to-market advantage, they are typically proprietary, 'walled-garden' solutions. The remainder of this chapter focuses on WAP, and discusses the WAP Forum's standards-based approach to implementing a wireless PKI - an initiative that is proving attractive to many operators.