The mCommerce and secure mobile payments in WAP E C C E - 11 & S A F E C O M P 2 0 0 2 Joint P a n el on H u m a n - M a c hine S y stem D e p e n d a bility Catania, Septe m b er 11th, 2 0 0 2 Dino D e L u c a, Marcello Salemi N o kia, M obile S oftware I ntegration S o uth Europe hub 1 © NOKIA 2002 SAFECOMP, 11 Sept 2002 / Dino De Luca, Marcello Salemi M o bile C o m merce By 2002, one billion consumers globally will have a mobile phone M o bile C o m merce buying and paying using a mobile phone digital content (ringing tones, games, cartoons) physical goods (books, roses, gifts) tickets (movies, ski lifts), etc. using a mobile terminal Mobile phones evolve towards Personal Trusted Devices 2 © NOKIA 2002 SAFECOMP, 11 Sept 2002 / Dino De Luca, Marcello Salemi S e c ure Mobile Payments Consumer can buy any goods Consumer and the service must fully trust each other PKI application needed to secure transactions (based on RSA or ECC algorithms) •“mobility” increases architecture complexity due to • More complex client authentication • Storing and managing certificates (CA and user certificates) because of PKI 3 © NOKIA 2002 SAFECOMP, 11 Sept 2002 / Dino De Luca, Marcello Salemi T h e role of Mobile Device s • The mobile phone acts as a Personal Trusted Device (PTD) • PTD contains the security features for accessing information in the network very securely and easily • Customer certification needed to access the services. • Solution is based on “Smart Card”, the Wireless Identity Module (WIM) • Standardized by OMA group (former WAP forum) • WAP-260-WIM-20010712-a • WAP-217_103-WPKI-20011102-a 4 © NOKIA 2002 SAFECOMP, 11 Sept 2002 / Dino De Luca, Marcello Salemi Important Features in modern and future m C o m merce • The notion of Trust still remains vaguely understood and defined • M o bility and L o c ality are converging to Global • Human Perspective: • PDTs are main actors in the mCommerce scenario; Human are associated with PDTs • Service-Of-The-Shelf (Related Issues: Integration of different services/devises; Dependencies, Conflicting Services, etc.) • Human - PDTs interaction is important to access remote services in a mobile evolving scenario 5 © NOKIA 2002 SAFECOMP, 11 Sept 2002 / Dino De Luca, Marcello Salemi