Nomadic devices, the freedom to compute

February 22, 2008 Nomadic devices, the freedom to compute

Today's mobile phones and other nomadic devices have the computing power to offer users many more applications than currently available. However, security concerns and costs are holding back developments in this area. But ‘security-by-contract’ promises an effective solution.

There was a simpler time when a telephone was just a phone, and all you could do with it was call people. Nowadays, mobile phones come packed with more processing juice than a small country possessed not so long ago.

“If you go and buy a phone today, you will find it has more computing power than a PC in the late 1980s and even 1990s. But if you look at the third-party software available on the average mobile, it is almost non existent,” explains Fabio Massacci, a professor in security and computer engineering at the University of Trento in Italy.

“This is because the phone and PC markets are very different. Mobile operators are reluctant to allow third-software software on to their devices without certification, which is currently very costly and time-consuming. This discourages many software developers.”

But this is all set to change, if the project Massacci coordinates gains broad industry acceptance. “We have worked to reduce the threshold for certification without compromising security,” he says.

Certifiably safe

S3MS has developed a ‘security-by-contract’ technological solution which would allow users to download and use applications on a range of devices – from smart phones to personal digital assistants (PDAs) – without compromising their phone’s integrity or signing up to more than they bargained for. In contrast to the current e-signatures in place, users will be able to agree to, and even define, contracts that outline how and when an application is used.

“The current ‘sandbox’ security model is very simple: you either allow nothing or everything. With security-by-contract, you have more flexibility but also more complexity,” notes Massacci.

In practice, the new system will not prove that complex for end-users, developers and mobile operators. “Users will sign up to certain contractual agreements which specify such things as the number of SMSs an application can send, how many megabytes it can download, and even whether it can work when the power is low.”

Software developers will continue to develop code in the same way, except that they will have to “present an electronic contract and develop a verification process to the mobile operator”, according to Massacci.

This is a vast improvement on the current ‘trusted third-party’ certification which is complex and costly both for developers and operators, pushing it beyond the means of most companies.

“This means that operators will be able to formalise and streamline their third-party contracting process, generating a range of new business streams,” he elaborates.

Kaleidoscopic options

The beauty of the S3MS concept is that it is both flexible and scalable, which means that not all parties need to reach an accord for it to work. “In this model, we don’t assume that all partners – operators, developers and users – need to agree,” Massacci explains.

“The system allows operators to monitor for applications that violate its policies. It also allows the user to ‘inoculate’ applications that do not have a security policy. In addition, users and application providers can reach their own agreements without the operator.”

The EU-backed project insist that security-by-contract will not replace but enhance today’s security mechanism, and will provide a flexible, simple and scalable security and privacy protection for future mobile systems. The S3MS architecture provides an open platform for the development, loading and run-time execution of downloadable third-party applications on mobile platforms.

The project demonstrated a prototype of the system to some industry players in December 2007 and the final version of the prototype is due out in February 2008.

On the horizon

So, how likely are we to be using ‘security-by-contract’ in the future? Massacci is confident that it will be well received in the market. France telecom is a partner in S3MS and is finalising the commercial exploitation report. Japan’s DoCoMo is also a partner and Telecom Italia has expressed interest.

“We are in the process of trademarking ‘security-by-contract,” he says. “We will then discuss what to do after that and what kind of investments and investors we need to take the idea further.”

Source: ICT Results


print this article email this article download pdf blog this article bookmark this article     Stumble it Digg this share on Facebook retweet share on Reddit add to delicious
Rate this story - 4.7 /5 (6 votes)


February 22, 2008 all stories

Comments: 0

4.7 /5 (6 votes)
  • Stumble this up

  • Digg this

  • share this

  • hide
  • Related Stories

  • Trust Linux!
    created Nov 20, 2009 | popularity not rated yet | comments 0
  • FCC clears deep-sea fiber-optic cable linking Asia, California
    created Oct 09, 2009 | popularity not rated yet | comments 0
  • Rivals to form UK's top mobile operator
    created Sep 08, 2009 | popularity not rated yet | comments 0
  • As Internet turns 40, barriers threaten its growth
    created Aug 30, 2009 | popularity not rated yet | comments 0
  • U r pwned: text messaging paves way for hacking
    created Jul 30, 2009 | popularity not rated yet | comments 0



  • hide
  • Relevant PhysicsForums posts

  • Laser plasma emission
    created 4 hours ago
  • Achromat lens - magnifying LCD
    created Nov 25, 2009
  • Control System
    created Nov 24, 2009
  • Base Isolation Systems in Skyscrapers?
    created Nov 23, 2009
  • Need to interview a Computer Hardware Engineer for school project
    created Nov 23, 2009
  • transient heat transfer
    created Nov 23, 2009
  • More from Physics Forums - General Engineering

Other News

Building real security with virtual worlds

Technology / Computer Sciences

created 9 hours ago | popularity 4 / 5 (4) | comments 0

(PhysOrg.com) -- Advances in computerized modeling and prediction of group behavior, together with improvements in video game graphics, are making possible virtual worlds in which defense analysts can explore and predict ...


McKinnon, accused of hacking into US military and NASA computers, faces extradition to the United States

UFO-obsessed Briton loses bid to block US extradition

Technology / Other

created 5 hours ago | popularity 4 / 5 (2) | comments 0

A Briton accused of hacking into US military and NASA computers faces extradition to the United States after the British government Thursday rejected last-ditch requests to block the move.


Sony optimistic on 3-D TVs, in-house display (AP)

Sony optimistic on 3-D TVs, in-house display

Technology / Hi Tech

created 15 hours ago | popularity not rated yet | comments 0

(AP) -- A third to a half of the Sony Corp. TV sets sold annually will be packed with 3-D features by the year ending March 2013, a senior executive said Thursday.


Roku adds more 'channels' of video and other digital content

Technology / Telecom

created 9 hours ago | popularity not rated yet | comments 0

Owners of Roku's digital video player will soon have a bunch more channels to choose from.


A worman works on a computer

Half of Euro online travel purchases legally unsafe: EU

Technology / Internet

created 6 hours ago | popularity not rated yet | comments 0

More than half of all people who buy flights, hotel rooms and hire cars online risk being left without compensation if companies fail under outdated law, the EU said Thursday.