Delivering Attribute Certificates over GPRS

Attribute Certificates (ACs) have been developed and standardized by the ANSI X9 committee as an alternative and better approach, to X.509 public key certificates, for carrying authorization information. Attribute Authorities (AA) bind the characteristics of an entity (called attributes) to that entity by signing the appropriate AC. Therefore, ACs can be used for controlling access to system resources and employing role-based authorization and access controls policies accordingly. Although ACs are widely used and standardized, to the best of our knowledge, no mobile infrastructure or service currently utilizes them. In this paper, we first examine how basic Public Key Infrastructure (PKI) can be incorporated into mobile networks and especially the Universal Mobile Telecommunications System (UMTS). As a case study, we then experiment with ACs in the GPRS network, using a prototype implementation. In particular, we investigate and measure the performance in terms of service and transfer times when ACs are introduced in the mobile environment. Our measurements show that ACs technology not only is feasible to implement in present and future mobile networks, but at the same time can deliver flexible and relatively fast services to the subscribers, without compromising security.

[1]  Wael Hassan,et al.  Security Technologies for the World Wide Web , 2000 .

[2]  Andrei V. Gurtov,et al.  Measured performance of GSM, HSCSD and GPRS , 2001, ICC 2001. IEEE International Conference on Communications. Conference Record (Cat. No.01CH37240).

[3]  John Viega,et al.  Network Security with OpenSSL , 2002 .

[4]  Georgios Kambourakis,et al.  Introducing PKI to Enhance Security in Future Mobile Networks , 2003, SEC.

[5]  I. Nikolaidis Internet and intranet security, 2nd edition [Book Review] , 2002, IEEE Network.

[6]  Rajiv Chakravorty,et al.  Performance issues with general packet radio service , 2002, Journal of Communications and Networks.

[7]  Rolf Oppliger,et al.  Internet And Intranet Security , 1998 .

[8]  Joel Cartwright,et al.  Practical experience with TCP over GPRS , 2002, Global Telecommunications Conference, 2002. GLOBECOM '02. IEEE.

[9]  Rolf Oppliger Internet and Intranet Security, Second Edition , 2001 .

[10]  Rolf Oppliger,et al.  Using Attribute Certificates to Implement Role-based Authorization and Access Controls , 2000 .