You are here: silicon.com > Software > Security Strategy

Security Strategy

Experts applaud move to close WAP security hole

European experts today welcomed news that US authorities have finally standardised an encryption algorithm, saying that it will help close a security hole in WAP gateways.

By Pia Heikkila

Published: 4 October 2000 18:05 BST

According to cryptography experts, current encryption techniques leave wireless transactions open to fraud, but the Advanced Encryption Algorithm (AES) standard, now clears the way for the development of far more secure applications.

Guy Tweedale, EMEA director at Extensity, wireless software developer, said: "There has been a well known security hole with public WAP gateways, therefore any standard which will allow the development of more secure technology is welcome."

William Whyte, senior cryptographer at Baltimore Technologies, added: "The point of vulnerability lies at the gateway of a WAP server which potentially could allow anyone to read that message. The universal adoption of AES should make it possible for people to encrypt directly from the wireless device to any web server and it will subsequently remove the point of vulnerability."

Stuart Hillston, chief technology officer at business campaign group Interforum, said the standard will create the much-needed confidence in the m-commerce arena.

He said: "The creation of algorithm standard itself is a step forward. Customers just want to know whether they can interact safely over the internet and mobiles and if the vendors can come up with the goods, it can only have a positive effect."

The AES standard was agreed last Monday by the National Institute of Standards and Technology (NIST) - an arm of the US government's commerce department.

Algorithms based on the AES standard can be used to develop applications that allow sending encrypted information from a mobile device to a website without the need to decrypt and re-encrypt the message at the WAP gateway level.

  1. Zones
  2. Management
  3. Networks
  4. Software
  5. IT Services
  6. Hardware
  1. Verticals
  2. Public Sector
  3. Financial Services
  4. Retail & Leisure

  • Jobs
E-Commerce Analyst - Data & Statistics - Glasgow Area - Up to 35K

E-Commerce Analyst Exciting times ahead for my client, a well know fashion retailer. As they develop their e-commerce team, the core responsibilities ...

Mobile device management - EMEA handset management & vendor liaison

Looking after 3000 devices globally you will be responsible for best practice, vendor liaison and, in future projects, ensuring device integration ...

Senior Software Validation Bedford Bedfordshire CFR ISO Medical Device

Senior Software Validation Bedford Bedfordshire CFR ISO Medical Device Basic Requirements The job holder will be able to demonstrate expert knowledge ...

CIO50 2008
The silicon.com CIO50 2008 profiles the most influential and innovative tech chiefs in the UK across all industries and organisation size, from the biggest FTSE100 companies to high growth dot-com start ups and the public sector. The list was voted on by the UK CIO community and a panel of experts. Find out more in our latest special report.





Quick Sitemap Links: