標題: | WAP憑證轉換工具設計與實作 Design and Implementation of WAP Certificate Converter Toolkit |
作者: | 顏志明 袁賢銘 資訊科學與工程研究所 |
關鍵字: | 無線運用協定;X.509憑證;行動安全;WAP憑證;無線公開金鑰架構;無線身份模組;WAP(Wireless Application Protocol);X.509 Certificate;Mobile Security;WAP Certificate;WPKI;WTLS;WIM;WMLScript Crypto Library |
公開日期: | 2004 |
摘要: | 行動安全(mobile security)一直是在手持裝置上開發行動商務(m-commerce)程式的一項重要議題。對此,無線運用協定(Wireless Application Protocol, WAP)已訂製一系列規範標準,包括WTLS (Wireless Transport Layer Security), WPKI (Wireless Public-Key Infrastructure), WIM (Wireless Identity Module), and WMLScript Crypto Library. 在這些標準中,一項重要的組件就是憑證(certificate)的使用。然而,為了符合無線環境的限制,WAP重新定義了數種憑證格式,同時既有網際網路上通用的X.509憑證,也無法在未經修改情況下,直接下載到支援WAP的行動裝置上使用。
在本篇論文中,我們設計和實作出一個WAP憑證轉換工具,提供方便的程式及操作介面,可以將網際網路上通用的X.509憑證轉換成WAP相容憑證格式,並套用在支援WAP的行動裝置上。我們所開發的這個WAP憑證轉換工具,可以用來協助目前網際網路上發行X.509憑證的憑證中心(Certification Authority, CA),將他們發出的憑證,根據使用者的需要,動態且容易地轉換成WAP憑證。就增進行動安全和考慮現行X.509憑證轉換成本而言,這套工具提供了相當程度的便利性與經濟性,可以用來幫助行動商務程式之開發。 Mobile security has been a key factor for development of m-commerce applications on hand-held devices. To enhance the mobile security, WAP (Wireless Application Protocol) has defined several standards such as WTLS (Wireless Transport Layer Security), WPKI (Wireless Public-Key Infrastructure), WIM (Wireless Identity Module), and WMLScript Crypto Library to regulate it. One important component of those standards is the use of certificate. However, for fitting the limitations in the wireless environment, WAP introduces several certificate formats in those specifications and the existing Internet X.509 certificates can not download directly to WAP-enabled handsets without any modification. In this paper, we design and implement a WAP Certificate Converter Toolkit to provide the convenient interfaces for doing the conversion from the existing Internet X.509 certificates to WAP compatible certificates that can be deployed in WAP-enabled mobile devices. The toolkit we provide can be used by the Internet CA’s (Certification Authority) to dynamically and easily transform their issued certificates into WAP certificates by the need of users. As far as enhancement of mobile security and conversion cost from Internet X.509 certificates are concerned, this toolkit is convenient and economic to a large extent and can be used to help the development of m-commerce applications. |
URI: | http://140.113.39.130/cdrfb3/record/nctu/#GT009223620 http://hdl.handle.net/11536/76670 |
顯示於類別: | 畢業論文 |