A PK-SIM card based end-to-end security framework for SMS

  • Authors:
  • He Rongyu;Zhao Guolei;Chang Chaowen;Xie Hui;Qin Xi;Qin Zheng

  • Affiliations:
  • School of Electronic and Information Engineering, Xi'an Jiaotong University, Xi'an 710049, PR China and School of Electronic Technology, Information Engineering University, Zhengzhou 450004, PR Ch ...;School of Electronic Technology, Information Engineering University, Zhengzhou 450004, PR China;School of Electronic and Information Engineering, Xi'an Jiaotong University, Xi'an 710049, PR China and School of Electronic Technology, Information Engineering University, Zhengzhou 450004, PR Ch ...;School of Electronic Technology, Information Engineering University, Zhengzhou 450004, PR China;School of Electronic Technology, Information Engineering University, Zhengzhou 450004, PR China;School of Electronic and Information Engineering, Xi'an Jiaotong University, Xi'an 710049, PR China

  • Venue:
  • Computer Standards & Interfaces
  • Year:
  • 2009

Quantified Score

Hi-index 0.01

Visualization

Abstract

Since the first SMS (Short Message Services) message was sent in the UK in 1992, the SMS has become a mass communication tool and has been broadly used in mobile business applications. But the security issue of the SMS has often been considered as a crucial barrier to its application in many fields that need strong authentication and confidentiality, such as mobile-commerce. The Subscriber Identity Module (SIM) inside mobile phones is a tamper resistant device which contains strong authentication mechanism and has been used in remote user authentication system, e.g. WIM card in Wireless Application Protocol (WAP). In this contribution, we design and realize a secure SIM card, named PK-SIM card, which is a standard SIM card with additional PKI functionality; based on the PK-SIM card, we present a security framework offering solutions for the development of secure mobile business applications using SMS as bearer. The security framework consists of a client device, in which a PK-SIM card is used to store security credentials, a Secure Access Gateway (SAG) which is used to receive and send secure SMS messages, a trusted third-party, Certification Authority (CA), which provides a public-key certification service and a Mobile Operator which provides the communication infrastructure for the SMS. Then we propose an authentication and session key distribution protocol which provides end-to-end security between the PK-SIM card and the SAG, and give a formal security analysis to the proposed protocol based on BAN authentication logic. Lastly, we provide a typical application of the security framework in Mobile Police Information System. The evaluations of the system have proved that the security framework is suitable for actual needs both in speed and security.