Personal trusted devices for web services: revisiting multilevel security

  • Authors:
  • Edgar Weippl;Wolfgang Essmayr

  • Affiliations:
  • Software Competence Center Hagenberg, www.scch.at, Hauptstr. 99, A-4232 Hagenberg, Austria;Software Competence Center Hagenberg, www.scch.at, Hauptstr. 99, A-4232 Hagenberg, Austria

  • Venue:
  • Mobile Networks and Applications - Security in mobile computing environments
  • Year:
  • 2003

Quantified Score

Hi-index 0.00

Visualization

Abstract

In this paper we revisit the concept of mandatory access control and investigate its potential with personal digital assistants (PDA). Only if applications are clearly separated and Trojans cannot leak personal information can these PDAs become personal trusted devices. Limited processing power and memory can be overcome by using Web services instead of full-fledged applications - a trend also in non-mobile computing. Web services, however, introduce additional security risks, some of them specific for mobile users. We propose an identification scheme that can be effectively used to protect privacy and show how this system builds upon a light-weight version of mandatory access control.