Device & Service
Security
- Solutions for an Increasingly Open Environment
Key Objective: To innovate security approaches appropriate to the increasingly open nature of networks – Public, Enterprise and Ad Hoc.
Activities:
  • Simple and Transparent Identity Management and User Privacy
  • Establishing Dynamic Trust Relationships between User Devices
  • Adaptive Protection of increasingly open Enterprise Environments

Research Priorities and Topics:

Telecom operators, broadcasters and service providers increasingly need to deliver services over not only their own infrastructure, but also over that owned by partners, over which they have little if any control. Users’ devices increasingly interoperate over multiple networks and are increasingly ‘open’, in terms of operating system and the ability to host user-deployed applications. The consequent evolution of the security threat to public networks, enterprise networks and user-owned devices means that existing centralised solutions are no longer tenable – innovative and robust approaches appropriate to this new environment are required.

Priorities in this research theme therefore include:

• Overcoming the obstacles preventing the full realisation of the possibilities of wireless systems, including user privacy concerns, corporate security concerns, and regulatory issues

• Enabling mobile users to enjoy the benefits of ubiquitous services, whilst controlling access to information concerning their behaviour through their use of wireless interfaces

• Developing architectures for enterprises to detect and respond to new security threats arising from mobile device access

• Addressing the security and privacy issue arising from ad hoc relationships (peer-to-peer and client-server)

Approach:

These priorities will be addressed as three broad topics – Identity Management & User Privacy, Enterprise Security and Trust Models within the scope of an exemplar application, reflecting the interwoven of service & security.

Technical approaches adopted include:

• Practical and pragmatic Privacy and security management solutions – ie ones that are simple and transparent to the user – eg using existing configuration information held in the network

• Distributed adaptive processes, based on adaptive learning, targeted initially at the enterprise environment

• On-device dynamic behaviour monitoring with adaptive response, to protect the user’s device, service and identity which leverage anticipated developments in handset technology

• Trust models for client-server, peer-to-peer and ad-hoc secure wireless communications that are context aware, time varying and able to provide for varying balances between reliance on central authorities and ‘webs of trust’

 

9 October 2007 MobileVCE Home Copyright © 2007 Mobile VCE.