Application of the U(SIM) card as secure device for electronic signature Mr. Pedro Fuertes Head of Business Development and Innovation Vodafone Spain 8 th International Common Criteria Congress Rome, September, 26 th
Goals • To introduce the Mobile Digital Signature from Vodafone Spain • To show the business opportunities for secure SIM based products • To propose the CC world to develop a specific approach for SIM Certification 2 Mobile Electronic Signature 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0
Mobile Electronic Signature from Vodafone Spain • Signature of documents from the mobile How do you sign, pen or mobile? • Based on PKI, secure, robust • Under EU regulations • Multi CA • Allows: – Introduction of new services – Substitution of existing Authorization and Authentication methods • Easy to use • Large customer base • HW and Basic SW certified at EAL 4+ (1) Vodafone’s Mobile Digital Signature solution takes PKI security to the mobile world 3 Mobile Electronic Signature 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0 (1) (2) Certifications ID BSI-DSZ-CC-0353 -2005 And TUVIT-DSZ-CC-9253 -2006
Why the mobile, why in the SIM? - PC HANDSET WITH MOBILE ELECTRONIC SIGNATURE - INTERNET CONNECTION = - SCREEN - KEYBOARD - CARD + READER or - SW CERTIFICATE Directive 1999/93/CE 34/2002 IS Law RD 14/1999 59/2003 ES Law DNIe CA’s set up Apps without certificate Coordinates cards PIN as secure method Certificate’s usage 1999 4 Mono CA applications Mobile Multi CA applications Electronic Signature Mobile Electronic Signature 2001 2003 2005 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0 2007
Transaction flows • Certificate strength resides in the CA • Vodafone acts as a intermediate between the Service Provider and the CA, adding the mobility value • The Service Provider builds its own services on top of the Mobile Electronic Signature 5 Mobile Electronic Signature 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0
Is it worth to work on SIM Security? • High penetration (> 107% in Spain) • Intrinsically secure at Operator’s degree • Room for several certificates • Increasing processing capacity, Java Cards and crypto-coprocessors • Increasing importance for Operators – m-Payment – Mobile TV – Trusted applications – DRM – Access to other networks 6 Mobile Electronic Signature 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0
Proposals for Mobile Digital Signature ramp up • In order to realise the business opportunities for the Digital Signature in the mobile world, we recommend the Common Criteria Forum to work on: • Speed up the certification process and time • Adapt and make more flexible the certification process We propose the CC World to define a specific approach to the SIM Certification in order to realise all the business opportunities that are ahead 7 Mobile Electronic Signature 8 th ICCC, Rome, 26 th Sept 2007 Versión 1. 0
Thanks.