A framework for cryptography algorithms on mobile devices

dc.contributor.advisorBishop, Judithen
dc.contributor.emailjlo@cs.up.ac.zaen
dc.contributor.postgraduateLo, Johnny Li-Changen
dc.date.accessioned2013-09-07T14:22:21Z
dc.date.available2007-11-08en
dc.date.available2013-09-07T14:22:21Z
dc.date.created2007-04-25en
dc.date.issued2007-11-08en
dc.date.submitted2007-10-19en
dc.descriptionDissertation (MSc (Computer Science))--University of Pretoria, 2007.en
dc.description.abstractMobile communication devices have become a popular tool for gathering and disseminating information and data. With the evidence of the growth of wireless technology and a need for more flexible, customizable and better-optimised security schemes, it is evident that connection-based security such as HTTPS may not be sufficient. In order to provide sufficient security at the application layer, developers need access to a cryptography package. Such packages are available as third party mobile cryptographic toolkits or are supported natively on the mobile device. Typically mobile cryptographic packages have reduced their number of API methods to keep the package lightweight in size, but consequently making it quite complex to use. As a result developers could easily misuse a method which can weaken the entire security of a system without knowing it. Aside from the complexities in the API, mobile cryptography packages often do not apply sound cryptography within the implementation of the algorithms thus causing vulnerabilities in its utilization and initialization. Although FIPS 140-2 and CAPI suggest guidelines on how cryptographic algorithms should be implemented, they do not define the guidelines for implementing and using cryptography in a mobile environment. In our study, we do not define new cryptographic algorithms, instead, we investigate how sound cryptography can be applied practically in a mobile application environment and developed a framework called Linca (which stands for Logical Integration of Cryptographic Architectures) that can be used as a mobile cryptographic package to demonstrate our findings. The benefit that Linca has is that it hides the complexity of making incorrect cryptographic algorithm decisions, cryptographic algorithm initialization and utilization and key management, while maintaining a small size. Linca also applies sound cryptographic fundamentals internally within the framework, which radiates these benefits outwards at the API. Because Linca is a framework, certain architecture and design patterns are applied internally so that the cryptographic mechanisms and algorithms can be easily maintained. Linca showed better results when evaluated against two mobile cryptography API packages namely Bouncy Castle API and Secure and Trust Service API in terms of security and design. We demonstrate the applicability of Linca on using two realistic examples that cover securing network channels and on-device data.en
dc.description.availabilityunrestricteden
dc.description.degreeMSc
dc.description.departmentComputer Scienceen
dc.identifier.citationLo, JL 2007, A framework for cryptography algorithms on mobile devices, MSc Dissertation, University of Pretoria, Pretoria, viewed yymmdd <http://hdl.handle.net/2263/28849>
dc.identifier.otherPretoriaen
dc.identifier.upetdurlhttp://upetd.up.ac.za/thesis/available/etd-10192007-155921/en
dc.identifier.urihttp://hdl.handle.net/2263/28849
dc.language.isoen
dc.publisherUniversity of Pretoriaen_ZA
dc.rights© University of Pretoren
dc.subjectCryptographyen
dc.subjectSoftware componentsen
dc.subjectFrameworksen
dc.subjectSmall message service (SMS)en
dc.subjectEntropyen
dc.subjectStandardsen
dc.subjectProtocolen
dc.subjectSoftware application.en
dc.subjectServeren
dc.subjectClienten
dc.subjectMobile devicesen
dc.subjectProtocolen
dc.subjectCryptographic packagesen
dc.subjectUCTDen_US
dc.titleA framework for cryptography algorithms on mobile devicesen
dc.typeDissertationen

Files

Original bundle

Now showing 1 - 1 of 1
Loading...
Thumbnail Image
Name:
dissertation.pdf
Size:
3.47 MB
Format:
Adobe Portable Document Format