Forum Moderators: buckworks

Message Too Old, No Replies

I got question to ask

m-commerce concerns

         

resiler

4:51 pm on Aug 31, 2005 (gmt 0)

10+ Year Member



Hello everyone, im a foreigner who study in Aus now.

I got a problem about my essay, the subject is"security issues in mobile commerce", i don not exactly know how to handle it? Could u guys tell me how to write this essay? I did do a research over internet, but i found nearly nothing. Is it the same as"WAP security"or"wireless security"? Could i carry on this subject from these two directions? How should i do?

Thanks u guys, i really appreciate your help”«”«”«

Plus,could someone explain these two paragraph to me?

We make the simplifying assumption that the client device C is identified with the user of this device. At the application level, the authentication mechanisms for use in transactions will be different from those used at the link level to obtain services such as data transport. In some applications, this distinction will blur such as when the user uses the link level authentication and authorization mechanisms to participate in transactions.

Physical security of the client device is a very useful property for the user to participate in protocols that can be proven, with high assurance, to be secure.While we do not assume that inexpensive devices such as current off-the-shelf cell phones or PDAs (or, for that matter, desktop machines) other suffciently high resistance to physical attacks, we identify security exposures in protocols which could be avoided if C or K had these properties. With care, physical security can be imported into the client device via a secure hardware token
such as a smart card or a smart button. Although the physical security of such devices is still in question , some smart buttons have had physical security independently evaluated at FIPS 140{1 Level 3 [15]. Physical security can be imported into desktops via a high-end, FIPS Level 4 secure coprocessor

Cheers again!

Morgenhund

8:22 am on Sep 1, 2005 (gmt 0)

10+ Year Member



Hi resiler,

and welcome to WebMasterWorld!

The known security issues regarding mobile commerce might be the same, as in "usual" e-commerce, with protocols- and hardware-related specific issues:

1. Data privacy/integrity. Is it possible to intercept/change data between mobile device and service provider? Or hack a server of service provider? What protocols are used, how secure they are?
2. Spoofing -- how easy is it for one owner of a mobile device to pretend to be an another, or for a service provider? Study protocols again.
3. Hardware-specific virus issues.

The two other paragraphs seems to be completely unreadable. Try to split them in small chunks and re-write in a human language, and most probably you will not need another explanation :)