Secure transactions
Making mobile phones more trustworthy
The mobile phone is the most deployed device for security tokens in the world. As mobile phones gain increasing acceptance as terminals for data communication, the ability to securely handle transactions is greater than ever. Mobile network operators can achieve acceptance of the mobile phone as a personal trusted device using the SIM card as the storage of keys and encryption engine.
With this, the operator is uniquely positioned to offer security schemes that leverage digital signatures and digital certificates for the secure signing of transactions and authentication of users. Enabling deployment of new security aware services can help reduce customer churn and increase loyalty. The process of certificate enrollment creates a closer bind between the operator and the subscriber.
Digital signatures for secure mobile transactions
With SIM Toolkit, the operator can reach all mobile phones. SmartTrust WibTM with plug-ins or the Java based client, SmartLicentio Client, provide WAP compliant SignText signatures. Our unique architecture enables handsets to interact with internet services whilst employing industry-standard security techniques for optimal security and ease of use. We handle a multi-browsing environment with the SIM as the core component for digital signatures in multiple use cases, including mobile banking, mobile commerce, VPN authentication, OpenID authentication, and Near Field Communication (NFC) based applications.
SmartLicentio Mobile Signature Services Platform
The SmartLicentio Mobile Signature Services Platform is a Java based signature, routing and verification server software supporting Signature Verification as per RFC3280 and PKCS#10. It is based on ETSI standards and provides SOAP interfaces for easy connectivity to service providers. It is successfully interoperability tested in an MSSP Mesh and supports RSA key lengths up to 2048 bits.
SmartLicentio runs on Sun Solaris and can be installed in the same environment as the SmartTrust DP OTA platform and SmartàLaCarte Universal Gateway. A Linux version is also available. SmartLicentio is connected to the SmartàLaCarte Universal Gateway to invoke the signature request on the user side. This requires that the SIM has SmartTrust Wib or SmartLicentio Client. A certificate for the user must be available in a LDAP repository.

Digital Signatures for mobile banking and secure transactions Read more