Security Issues in Mobile Commerce Using WAP

نویسندگان

  • Niels Jørgensen
  • Niels Christian Juul
چکیده

The Wireless Application Protocol (WAP) has been proposed as a way to get Internet (or a sort of Internet) to the small wireless and mobile devices, e.g. mobile phones, while accommodating for the special characteristics of such devices. Originally, WAP was designed with a gateway in the middle, acting as the interpreter between the Internet protocol stack and the Wireless Application Protocol stack. The WAP gateway forwards web content to the mobile phone in a way intended to accommodate the limited bandwidth of the mobile network and the mobile phone’s limited processing capability. However, the gateway introduces a security hole, which renders WAP unsuitable for any security-sensitive services. Through a set of standard releases, primarily version 1.2.1 (June 2000) and version 2.0 (July 2001), security issues have been addressed. We discuss the security hole and the gateway-based design that has led to it, including the business and architectural considerations underlying the design. A number of ways to correct the situation are discussed, including application level security, which still hasn’t been fixed in the WAP 2.0 standard of the July 2001 release. Finally we observe, that although version 2.0 allows skipping the gateway thereby tightening security, the added cost is not negligible.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Dynamic WAP (Wireless Application Protocol) Page Generation: A Proposed Solution for Small mobile Screen and Usability Issues

CONTEXT: Mobile commerce (M-Commerce) is a new commerce pattern in which the purchasing and vending of goods and services is completed through mobile apparatus. Or M-commerce is a business concept, which covering any practice of business transaction or information exchange using wireless and mobile technologies. WAP application is used In order to get access to the information and services in t...

متن کامل

Secure M-Commerce with WPKI

The huge success of mobile telephone is about to transform ebusiness and the Internet. As a Personal Trusted Device PTD, the mobile phone, will be able to handle secure transactions in a wireless world. The Wireless Application Protocol (WAP) suite enables secure e-commerce services and applications. This paper present an overview of the PKI and the WAP environments and their relation to the In...

متن کامل

M-Commerce-Issues and Challenges

|There has been a tremendous growth in wireless technology in the last decade. This advancement has changed how people do business in Mobile Commerce (M-Commerce) environment. For creating a more secure and exible m-commerce infrastructure so as to meet the new demands, we need to leverage new technologies like 3G/UMTS, Bluetooth, EDGE and at the same time utilize the older ones like WAP, GSM, ...

متن کامل

The Security Hole in WAP: An Analysis of the Network and Business Rationales Underlying a Failure

To succeed commercially, the Wireless Application Protocol (WAP), a protocol for the delivery of Internet-like services for mobile phones, had to dominate the market for mobile electronic commerce, but a security hole made it unsuitable for e-commerce transactions. The security hole was a byproduct of the so-called WAP-gateway. Mobile service providers offering WAP to their subscribers were sup...

متن کامل

WAP may Stumble over the Gateway (Security in WAP-based Mobile Commerce)

The key design idea underlying the Wireless Application Protocol (WAP) is to use a gateway at the intersection of the wireless mobile network and the traditional, wired network. The WAP gateway forwards web content to the mobile phone in a way intended to accommodate the limited bandwidth of the mobile network and the mobile phone’s limited processing capability. However, the gateway introduces...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2002