A Survey of WAP Security Architecture.ppt
《A Survey of WAP Security Architecture.ppt》由会员分享,可在线阅读,更多相关《A Survey of WAP Security Architecture.ppt(27页珍藏版)》请在麦多课文档分享上搜索。
1、A Survey of WAP Security Architecture,Neil Daswani ,December 3, 2000,Neil Daswani, ,Overview,Security Basics Wireless Security WTLS & SSL WAP Security Models WIM, WMLScript, Access Control Summary References,December 3, 2000,Neil Daswani, ,Security Basics,Security Goals Authentication Confidentialit
2、y Integrity Authorization Non-Repudiation,December 3, 2000,Neil Daswani, ,Security Basics,Cryptography Symmetric: 3DES, RC4, etc. Asymmetric: RSA, ECC Key Exchange Digital Signature Certificates PKI,December 3, 2000,Neil Daswani, ,Wireless Security,Link Layer Security GSM CDMA CDPD Application Layer
3、 Security WAP: WTLS, WML, WMLScript, & SSL iMode: N/A SMS: N/A,December 3, 2000,Neil Daswani, ,Need for App Level Security,Bearer Independence Security out to Gateway Advanced Security Goals (ie. Non-Repudiation),December 3, 2000,Neil Daswani, ,Basic WAP Architecture,Internet,Gateway,Web Server,WTLS
4、,SSL,December 3, 2000,Neil Daswani, ,WTLS & SSL,WTLS Goals Authentication: Asymmetric Key Crypto Class 1: No Authentication Class 2: Server Authentication Class 3: Mutual Authentication Privacy: Symmetric Key Crypto Data Integrity: MACs,December 3, 2000,Neil Daswani, ,WTLS: Class 1,No Authentication
5、,ClientHello -ServerHelloApplication Data,December 3, 2000,Neil Daswani, ,WTLS: Class 2,Server-Authentication Only,ClientHello -ServerHelloCertificateApplication Data,1. Verify Server Certificate,2. Establish Session Key,December 3, 2000,Neil Daswani, ,WTLS: Class 3,Client Hello - ServerHelloCertifi
6、cateCertificateRequestApplication Data,1. Verify Server Certificate,2. Establish Session Key,3. Generate Signature,Mutual-Authentication,December 3, 2000,Neil Daswani, ,TLS/SSL vs. WTLS,WTLS supports ECC WTLS over WDP TLS over TCP Premaster secret is 20 bytes (vs. 48 in TLS/SSL),December 3, 2000,Nei
7、l Daswani, ,WAP Security Models,Operator Hosts Gateway Without PKI With PKI Content Provider Hosts Gateway Static Gateway Connection Dynamic Gateway Connection,December 3, 2000,Neil Daswani, ,Operator Hosts Gateway,Without PKI,Operator,Content Provider,December 3, 2000,Neil Daswani, ,Operator Hosts
8、Gateway,Without PKI: Advantages No extra work for Content Provider No extra work for user System only requires one logical gateway Disadvantages Content Provider must trust Operator (NDA) Operator can control home deck Operator can introduce advertising,December 3, 2000,Neil Daswani, ,Operator Hosts
9、 Gateway,With PKI,December 3, 2000,Neil Daswani, ,Operator Hosts Gateway,With PKI: Advantages Content providers does not need to trust Operator. Disadvantages PKI Infrastructure must be in place.,December 3, 2000,Neil Daswani, ,Content Provider Hosts Gateway,Static Gateway Connection,WAPGateway,Web
- 1.请仔细阅读文档,确保文档完整性,对于不预览、不比对内容而直接下载带来的问题本站不予受理。
- 2.下载的文档,不会出现我们的网址水印。
- 3、该文档所得收入(下载+内容+预览)归上传者、原创作者;如果您是本文档原作者,请点此认领!既往收益都归您。
下载文档到电脑,查找使用更方便
2000 积分 0人已下载
下载 | 加入VIP,交流精品资源 |
- 配套讲稿:
如PPT文件的首页显示word图标,表示该PPT已包含配套word讲稿。双击word图标可打开word文档。
- 特殊限制:
部分文档作品中含有的国旗、国徽等图片,仅作为作品整体效果示例展示,禁止商用。设计者仅对作品中独创性部分享有著作权。
- 关 键 词:
- ASURVEYOFWAPSECURITYARCHITECTUREPPT
