An Extensible Framework for Efficient Secure SMS

被引:26
|
作者
De Santis, Alfredo [1 ]
Castiglione, Aniello [1 ]
Cattaneo, Giuseppe [1 ]
Cembalo, Maurizio [1 ]
Petagna, Fabio [1 ]
Petrillo, Umberto Ferraro [2 ]
机构
[1] Univ Salerno, Dip Informat Applicaz RM Capocelli, Via Ponte don Melillo, I-84084 Fisciano, SA, Italy
[2] Univ Roma Sapienza, Dip Stat Probabil & Stat Appl, I-00185 Rome, Italy
关键词
Elliptic curve cryptography; mobile secure communications; SMS security; power consumption analysis; performance analysis;
D O I
10.1109/CISIS.2010.81
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
Nowadays, Short Message Service (SMS) still represents the most used mobile messaging service. SMS messages are used in many different application fields, even in cases where security features, such as authentication and confidentiality between the communicators, must be ensured. Unfortunately, the SMS technology does not provide a built-in support for any security feature. This work presents SEESMS (Secure Extensible and Efficient SMS), a software framework written in Java which allows two peers to exchange encrypted and digitally signed SMS messages. The communication between peers is secured by using public-key cryptography. The key-exchange process is implemented by using a novel and simple security protocol which minimizes the number of SMS messages to use. SEESMS supports the encryption of a communication channel through the ECIES and the RSA algorithms. The identity validation of the contacts involved in the communication is implemented through the RSA, DSA and ECDSA signature schemes. SEESMS is able to certify the phone number of the peers using the framework. Additional cryptosystems can be coded and added to SEESMS as plug-ins. Special attention has been devoted to the implementation of an efficient framework in terms of energy consumption and execution time. This efficiency is obtained in two steps. First, all the cryptosystems available in the framework are implemented using mature and fully optimized cryptographic libraries. Second, an experimental analysis was conducted to determine which combination of cryptosystems and security parameters were able to provide a better trade-off in terms of speed/security and energy consumption. This experimental analysis has also been useful to expose some serious performance issues affecting the cryptographic libraries which are commonly used to implement security features on mobile devices.
引用
收藏
页码:843 / 850
页数:8
相关论文
共 50 条
  • [1] TinyVisor: An extensible secure framework on android platforms
    Shen, Dong
    Li, Zhoujun
    Su, Xiaojing
    Ma, Jinxin
    Deng, Robert
    COMPUTERS & SECURITY, 2018, 72 : 145 - 162
  • [3] HARDSHEAP: A Universal and Extensible Framework for Evaluating Secure Allocators
    Yun, Insu
    Song, Woosun
    Min, Seunggi
    Kim, Taesoo
    CCS '21: PROCEEDINGS OF THE 2021 ACM SIGSAC CONFERENCE ON COMPUTER AND COMMUNICATIONS SECURITY, 2021, : 379 - 392
  • [4] SMSCrypto: A lightweight cryptographic framework for secure SMS transmission
    Pereira, Geovandro C. C. F.
    Santos, Mateus A. S.
    de Oliveira, Bruno T.
    Simplicio, Marcos A., Jr.
    Barreto, Paulo S. L. M.
    Margi, Cintia B.
    Ruggiero, Wilson V.
    JOURNAL OF SYSTEMS AND SOFTWARE, 2013, 86 (03) : 698 - 706
  • [5] FCPP: an efficient and extensible Field Calculus framework
    Audrito, Giorgio
    2020 IEEE INTERNATIONAL CONFERENCE ON AUTONOMIC COMPUTING AND SELF-ORGANIZING SYSTEMS (ACSOS 2020), 2020, : 153 - 159
  • [6] MetaData for efficient, secure and extensible access to data in a medical grid
    Pierson, JM
    Seitz, L
    Duque, H
    Montagnat, J
    15TH INTERNATIONAL WORKSHOP ON DATABASE AND EXPERT SYSTEMS APPLICATIONS, PROCEEDINGS, 2004, : 562 - 566
  • [7] Frigate: A Validated, Extensible, and Efficient Compiler and Interpreter for Secure Computation
    Mood, Benjamin
    Gupta, Debayan
    Carter, Henry
    Butler, Kevin R. B.
    Traynor, Patrick
    1ST IEEE EUROPEAN SYMPOSIUM ON SECURITY AND PRIVACY, 2016, : 112 - 127
  • [8] An extensible framework for practical secure component composition in a ubiquitous computing environment
    Llewellyn-Jones, D
    Merabti, M
    Shi, Q
    Askwith, B
    ITCC 2004: INTERNATIONAL CONFERENCE ON INFORMATION TECHNOLOGY: CODING AND COMPUTING, VOL 1, PROCEEDINGS, 2004, : 112 - 117
  • [9] SECTET: an extensible framework for the realization of secure inter-organizational workflows
    Hafner, Michael
    Breu, Ruth
    Agreiter, Berthold
    Nowak, Andrea
    INTERNET RESEARCH, 2006, 16 (05) : 491 - 506
  • [10] A framework for secure message transmission using SMS-Based VPN
    Gholami, MohammadReza
    Hashemi, Seyyed Mohsen
    Teshnelab, Mohammad
    RESEARCH AND PRACTICAL ISSUES OF ENTERPRISE INFORMATION SYSTEMS II, VOL 1, 2008, 254 : 503 - +