Secure Mobile Agent Digital Signatures with Proxy Certificates

  • Authors:
  • Artur Romão;Miguel Mira da Silva

  • Affiliations:
  • -;-

  • Venue:
  • E-Commerce Agents, Marketplace Solutions, Security Issues, and Supply and Demand
  • Year:
  • 2001

Quantified Score

Hi-index 0.00

Visualization

Abstract

Security issues related to the usage of mobile agents in performing operations to which their owners have to be bound, such as payments, are of utmost importance if this kind of agents are to be used in electronic commerce. If this binding is achieved by means of digital signature techniques, this means agents have to carry the owner's private key to the host where they sign documents. This exposes the key to attacks because it is copied outside a protected environment. In this paper, we present a mechanism, called proxy certificates, that avoids the need for the agent to have access to the user's private key for digitally signing documents, but still binds the owner to the contents of those documents. In order to support our claims, we apply the mechanism to SET/A, an agent-based payment system we proposed in previous work. We also analyze the emerging technology of attribute certificates and argue that it is appropriate to implement proxy certificates.