Manage your own security domain on your smartphone

Arne Munch-Ellingsen, Anders Andersen, S. Akselsen
{"title":"Manage your own security domain on your smartphone","authors":"Arne Munch-Ellingsen, Anders Andersen, S. Akselsen","doi":"10.1109/MOBISECSERV.2015.7072869","DOIUrl":null,"url":null,"abstract":"Mobile network operators' role as keystone players in the smartphone ecosystem is challenged by other actors and technologies that aim to reduce the importance of the Universal Integrated Circuit Card (also known as SIM card). Modern Universal Integrated Circuit Cards are Java Cards that also include a Global Platform conformant Secure Element, usually under the mobile operator's control. We argue that mobile operators still have the opportunity to defend their role by offering easy access for customers and service providers to the Secure Element on the Universal Integrated Circuit Card for storing data and executing applications with high demands for security. The mobile operators could let the customers or service providers own and manage their private Global Platform specified supplementary security domain on the Secure Element. Such access to supplementary security domains on the Universal Integrated Circuit Card can enable new ecosystems and new business models created around this asset. This paper describes a novel smartphone, customer and service provider oriented, technical approach to management of the secure element. We have designed and implemented SecurePlay, a client side, proxy based \"lightweight\" Trusted Service Manager prototype and have successfully used it to manage Secure Elements on Universal Integrated Circuit Cards in the Telenor operated mobile phone network in Norway. SecurePlay allow operators to cost efficiently enable end users' ownership and operation of their own private security. Implementation details of a proof-of-concept prototype are presented.","PeriodicalId":164383,"journal":{"name":"2015 First Conference on Mobile and Secure Services (MOBISECSERV)","volume":"161 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2015-04-02","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"3","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2015 First Conference on Mobile and Secure Services (MOBISECSERV)","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MOBISECSERV.2015.7072869","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 3

Abstract

Mobile network operators' role as keystone players in the smartphone ecosystem is challenged by other actors and technologies that aim to reduce the importance of the Universal Integrated Circuit Card (also known as SIM card). Modern Universal Integrated Circuit Cards are Java Cards that also include a Global Platform conformant Secure Element, usually under the mobile operator's control. We argue that mobile operators still have the opportunity to defend their role by offering easy access for customers and service providers to the Secure Element on the Universal Integrated Circuit Card for storing data and executing applications with high demands for security. The mobile operators could let the customers or service providers own and manage their private Global Platform specified supplementary security domain on the Secure Element. Such access to supplementary security domains on the Universal Integrated Circuit Card can enable new ecosystems and new business models created around this asset. This paper describes a novel smartphone, customer and service provider oriented, technical approach to management of the secure element. We have designed and implemented SecurePlay, a client side, proxy based "lightweight" Trusted Service Manager prototype and have successfully used it to manage Secure Elements on Universal Integrated Circuit Cards in the Telenor operated mobile phone network in Norway. SecurePlay allow operators to cost efficiently enable end users' ownership and operation of their own private security. Implementation details of a proof-of-concept prototype are presented.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
在智能手机上管理自己的安全域
移动网络运营商在智能手机生态系统中的关键角色受到了其他参与者和技术的挑战,这些参与者和技术旨在降低通用集成电路卡(也称为SIM卡)的重要性。现代通用集成电路卡是Java卡,它还包括一个符合全球平台的安全元素,通常在移动运营商的控制之下。我们认为,移动运营商仍然有机会通过为客户和服务提供商提供对通用集成电路卡上的安全元件的方便访问来保护他们的角色,以存储数据和执行对安全性要求很高的应用程序。移动运营商可以让客户或服务提供商在安全元素上拥有和管理他们的私有全球平台指定的补充安全域。这种对通用集成电路卡上补充安全域的访问可以使围绕该资产创建的新生态系统和新商业模式成为可能。本文描述了一种新颖的智能手机、面向客户和服务提供商的安全元件管理技术方法。我们设计并实现了SecurePlay,这是一个基于客户端代理的“轻量级”可信服务管理器原型,并成功地将其用于管理挪威Telenor运营的移动电话网络中通用集成电路卡上的安全元素。SecurePlay允许运营商以经济高效的方式使最终用户拥有和运营自己的私人安全。介绍了概念验证原型的实现细节。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
Over-the-internet: efficient remote content management for secure elements in mobile devices Performance variation in host-based card emulation compared to a hardware security element An authentication architecture for cloud-based firewalling service Leveraging COBIT5 in NFC-based payment technology: challenges and opportunities for security risk mitigation and audit Two-factor authentication for android host card emulated contactless cards
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1