5 CONCLUSIONS
The paper summarizes our comprehensive study on
analyzing the security for mobile web services
provisioning. In this paper we included our analysis
of adapting the wired web service security
specifications to the cellular world, with
performance statistics. The results of our study are
welcoming and the mobile web service messages of
reasonable size, approximately 2-5kb, can be
secured with standard specifications. But based on
our till-date realization of security awareness in
cellular networks, we conclude that secure web
service provisioning in mobile networks is still a
great challenge. The mechanisms developed for
traditional networks are not always appropriate for
the mobile environment and support at hardware like
adding an encryption chipset is recommended.
Our future research in this domain includes
providing proper end-point security for the Mobile
Host with federated identity and appropriate SSO
strategy, using SAML and LA standards. We also
want to have a detailed performance analysis of the
Mobile Host with full security features through real-
time applications. We are also looking for
alternatives, to reduce the security processing load
on the Mobile Host using Enterprise Service Bus
(ESB) (Borck, 2005) based mediation framework for
maintaining the QoS of the Mobile Host.
The increase in size of the message with the
security headers is also quite daunting. We are
currently focusing at XML compression and SOAP
optimization techniques, to reduce the size of the
message, there by improving the scalability of the
Mobile Host. The scalability can also be maintained
as part of QoS at the mediation framework.
ACKNOWLEDGEMENTS
The work is supported by German Research
Foundation (DFG) as part of the Graduate School
”Software for Mobile Communication Systems” at
RWTH Aachen University. The authors also thank
R. Levenshteyn and M. Gerdes of Ericsson Research
and K. Pendyala for their help and support.
REFERENCES
3GPP, 2006. Third Generation Partnership Project.
http://www.3gpp.org/
4GPress, 2005. World's First 2.5Gbps Packet
Transmission in 4G Field Experiment.
http://www.4g.co.uk/PR2006/2056.htm
Booth, D.,Haas, H., McCabe, F. and etc., 2004. Web
Service Architecture. W3C Working group note.
http://www.w3.org/TR/ws-arch/
Borck, J.R., 2005. Enterprise service buses hit the road.
Infoworld journal. pp 26-40.
www.infoworld.com/article/05/07/22/30FEesb_1.html
BouncyCastle, 2006. Bouncy Castle Crypto APIs. The
Legion of the Bouncy Castle.
http://www.bouncycastle.org/
Christensen, E., Curbera, F., Meredith, G. and etc., 2001.
Web Services Description Language (WSDL) 1.1.
W3C Working group note.
http://www.w3.org/TR/wsdl
Eastlake, D., Reagle, J., Solo, D., 2002. XML-Signature
Syntax and Processing.
http://www.w3.org/TR/xmldsig-core/
GSMWorld, 2006. General Packet Radio Service
www.gsmworld.com/technology/gprs/index.shtml
IBM, 2002. Security in a Web Services world: A Proposed
Architecture and Roadmap. IBM Developerworks.
JSR 118, 2002. Mobile Information Device Profile
(MIDP) v2.0. Java Community process.
http://java.sun.com/products/midp/
JSR 139, 2002. Connected Limited Device Configuration
(CLDC). Java Community process.
http://java.sun.com/products/cldc/
KSOAP2, 2006. kSOAP 2. http://ksoap2.sourceforge.net/
LA, 2006. The Liberty Alliance Project.
http://www.projectliberty.org/
Lawrence, K., Kaler, C., 2004. Web Services Security:
SOAP Message Security 1.1 (WS-Security 2004).
OASIS Standard Specification.
Mishra, P., Lockhart, H., 2005. SAML V2.0 OASIS
Standard specification set. OASIS Standard.
Reagle, J., 2001. XML Encryption. W3C Working group
note. http://www.w3.org/Encryption/2001/
RSA Labs., 2006. Cryptographic technologies,
http://www.rsasecurity.com/rsalabs/node.asp?id=2212
Srirama, S., Jarke, M., Prinz, W, 2006. Mobile Web
Service Provisioning. Int. Conf. on Internet and Web
Applications and Services, ICIW06, IEEE Computer
Society. pp. 120-125.
Srirama, S., Jarke, M., Prinz, W., Pendyala, K., 2006.
Security Aware Mobile Web Service Provisioning. In
Proceedings of the International Conference for
Internet Technology and Secured Transactions,
ICITST’06. London, UK, ISBN 0-9546628-2-2, e-
Centre for Infonomics, pp. 48-56.
Thomas, K., 1999. Fourth Generation (4G) wireless
communications, http://www.4g.co.uk/
Umtsworld, 2002. Overview of the Universal Mobile
Telecommunication System.
http://www.umtsworld.com/technology/overview.htm
W3C, 2003. SOAP Version 1.2. W3C Working group
note. http://www.w3.org/TR/soap/
WEBIST 2007 - International Conference on Web Information Systems and Technologies
392