Security Scheme for Mobile Agent System in E- Commerce Scenario
نویسنده
چکیده
Mobile agents are software program that can autonomously migrate from a platform to another platform to accomplish their tasks and it is believed that they will play an important role in future ecommerce system, offering higher flexibility and improved performance. In spite of those benefits from mobile agent system, security in mobile agent system is especially hard to achieve when a mobile agent is executed on remote platform that may behave maliciously or mobile agent may behave maliciously on the remote platform. There has been a lot of work done in the area of mobile agent’s security. Recently, Bae et al. proposed a security scheme for mobile agent system using an IDENTITYBASED digital signature scheme and claimed that their scheme provided complete security to mobile agent system. However, in this paper, we show that their security scheme still suffers from some security weakness such as man in middle attack and previous agent platform can forge the signature. And then we further propose a new security scheme for secure mobile agent system that solves the weakness of their protocol using dynamic generated partial multi signature with message flexibility and provides the security services such as mutual authentication, confidentiality, integrity, nonrepudiation and the prevention of replay and exclude attack. The propose scheme is suitable and practical for protecting mobile agent from malicious platform in e-commerce scenario over the Internet.
منابع مشابه
The Presentation of an Ideal Safe SMS based model in mobile Electronic commerce using Encryption hybrid algorithms AES and ECC
Mobile commerce is whatever electronic transfer or transaction via a mobile modem through a mobile net in which the true value or advance payment is done for goods, services or information. A mobile payment system should be beneficial for all related persons. For a payment system to be a Successful system, End-user, seller, exporter and operators should see a additional value in it. End-user ...
متن کاملA Pairing-Based Authentication Scheme for Protecting Multiple Mobile Agent Hosts
A mobile agent is an autonomous software program, which can be executed in different agent platforms for a specific task on behalf of a customer. Security is one of the key issues for mobile agent technology while the mobile agents are applied to the developments of e-commerce. Therefore, this paper focuses on a mobile agent authentication scheme for safeguarding mobile agent platforms or hosts...
متن کاملSecure e-commerce using mobile agents on untrusted hosts
This paper investigates how mobile agents can securely collect information, protect the collected information against untrusted hosts, and how they can digitally sign transactions in an untrusted environment. We present an agent-based scenario for mobile commerce and discuss techniques using multiple agents that have been implemented to provide security in this scenario. The underlying techniqu...
متن کاملSecure brokerage mechanisms for mobile electronic commerce
The possibility of making the Internet accessible via mobile devices has generated an important opportunity for electronic commerce. Nevertheless, some deficiencies deter a massive use of m-commerce applications. Security and easiness of use are unavoidable conditions. The use of brokerage systems constitutes an interesting solution to speed up the information delivery to the users. Moreover, b...
متن کاملRole-Based Access Control for E-commerce Sea-of-Data Applications
Sea-of-Data (SoD) applications (those that need to process huge quantities of distributed data) present specific restrictions, which make mobile agent systems one of the most feasible technologies to implement them. On the other hand mobile agent technologies are in a hot research state, specially concerning security. We present an access control method for mobile agent systems. It is based on ...
متن کامل