Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 1 MExE +44 (0) 777 55 8 22 88

Slides:



Advertisements
Similar presentations
Lemonade and Mobile e- mail Stéphane H. Maes – Lemonade Intermediate meeting Vancouver, BC October 2004.
Advertisements

EricssonT2#13, User Profile Description1 User Profile Description
17/11/99S3 and MExE1 S3 review of MExE release 99 security Tim Wright, Vodafone UK 3GPP SA3, ETSI SMG10
MExE - SMG4/3GPP T2 SWG1 - April Mobile Station Application Execution Environment (MExE) Java and WAP ETSI/SMG4 and 3GPP.
5.1 Overview of Network Access Protection What is Network Access Protection NAP Scenarios NAP Enforcement Methods NAP Platform Architecture NAP Architecture.
Microsoft Windows XP SP2 Urs P. Küderli Strategic Security Advisor Microsoft Schweiz GmbH.
Presents H.323 Forum ETSI TIPHON Presented by: Richard Brennan - Telxxis LLC Vice-Chair ETSI-TIPHON.
6 The IP Multimedia Subsystem Selected Topics in Information Security – Bazara Barry.
DESIGNING A PUBLIC KEY INFRASTRUCTURE
Figure 1: SDR / MExE Download Framework SDR Framework Network Server Gateway MExE Download + Verification Using MExE Repository (Java sandbox) MExE Applet.
LAB#2 JAVA SECURITY OVERVIEW Prepared by: I.Raniah Alghamdi.
Wireless Application Protocol and i-Mode By Sridevi Madduri Swetha Kucherlapati Sharrmila Jeyachandran.
Chapter 15 The Third Component: Powerful Networks.
V1.00 © 2009 Research In Motion Limited Introduction to Mobile Device Web Development Trainer name Date.
1 An overview Always Best Connected Networks Dênio Mariz Igor Chaves Thiago Souto Aug, 2004.
Cambodia-India Entrepreneurship Development Centre - : :.... :-:-
Software Distribution in Microsoft System Center Configuration Manager v.Next: Part 1.
Cloud Usability Framework
Installing software on personal computer
Broadband Forum Machine-to-Machine (M2M) Solutions Robin Mersh, CEO The information in this presentation is public.
Summary of 3GPP TR GPP2 TSG-S WG4 S Source: Qualcomm Incorporated Contact(s): Anand Palanigounder,
Creation of hybrid portlet application for file download using IBM Worklight and IBM Rational Application Developer v9 Gaurav Bhattacharjee Lakshmi Priya.
Operating Systems Chapter 4.
Managing Client Access
Module 4 Managing Client Access. Module Overview Configuring the Client Access Server Role Configuring Client Access Services for Outlook Clients Configuring.
Terminal Services in Windows Server ® 2008 Infrastructure Planning and Design.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
1 Remote Management of Wireless Gateway Student Name: Dinesh D N (BITS ID: 2004HZ12158) MphasiS Technologies Ltd, Bangalore March 2006.
Confidential and proprietary material for authorized Verizon Wireless personnel only. Use, disclosure or distribution of this material is not permitted.
Metadata in the Cloud Computing 07th June 2012 Baba Piprani Ewelina Szczekocka.
ATIS & TISPAN JOINT MEETING ON NGN Washington D.C., 1 April 2005 MEETING SUMMARY Draft v2 (4 April 2005) Based on Notes from David Boswarthick (ETSI),
PKI interoperability and policy in the wireless world.
M i SMob i S Mob i Store - Mobile i nternet File Storage Platform Chetna Kaur.
3GPP ”All-IP” vision Long and short term What do we want to obtain ? How to get there (phasing) ? What do 3GPP need to do ? Issues to be resolved.
Registration Processing for the Wireless Internet Ian Gordon Director, Market Development Entrust Technologies.
Key Technology Enablers for Mobile Value-Added and Content Services - MMS, Java and XHTML OFTA Hong Kong, Marko Keskinen Nokia Mobile Phones.
Best of Both Worlds: Information Management Solutions SmartCore Management Dashboards.
International Telecommunication Union Geneva, 9(pm)-10 February 2009 ITU-T Security Standardization on Mobile Web Services Lee, Jae Seung Special Fellow,
Java Security Pingping Ma Nov 2 nd, Overview Platform Security Cryptography Authentication and Access Control Public Key Infrastructure (PKI)
An Operators Input for oneM2M Baseline  Group name: TP#2/WG1  Source: DTAG, Vodafone Group  Meeting Date:  Agenda Item: WG1 agenda item.
Middleware for FIs Apeego House 4B, Tardeo Rd. Mumbai Tel: Fax:
1 Issues Degree to which standardisation is needed for IMS services, like for example video conferencing? Same service across different terminals Terminal.
Customer Interface for wuw.com 1.Context. Customer Interface for wuw.com 2. Content Our web-site can be classified as an service-dominant website. 3.
Android Security Model that Provide a Base Operating System Presented: Hayder Abdulhameed.
INTRODUCTION. 1.1 Why the Internet Protocol Multimedia Subsystem 1.2 Where did it come from?
07/09/04 Johan Muskens ( TU/e Computer Science, System Architecture and Networking.
Distribution and components. 2 What is the problem? Enterprise computing is Large scale & complex: It supports large scale and complex organisations Spanning.
Heidelberg, 25 February 1999 MTM’99 Workshop Terminal and Application Aspects of the Evolution of Broadband Mobile Services EURESCOM P809 Mobility in.
T Research Seminar on Telecommuncations Business II - Unified Interfaces for Messaging Services 1 T Research Seminar on Telecommuncations.
Doc.: IEEE /209r0 Submission 1 March GPP SA2Slide 1 3GPP System – WLAN Interworking Principles and Status From 3GPP SA2 Presented.
SIM application
verifone HQtm Estate Management Solution
Mobile Application Testing Mobile Application Testing.
Security-Enhanced Linux Stephanie Stelling Center for Information Security Department of Computer Science University of Tulsa, Tulsa, OK
J2EE Platform Overview (Application Architecture)
IP Multimedia Subsystem
Fundamentals of Information Systems, Sixth Edition
3GPP interworking in R3 Group Name: ARC
Bruno Chatras, ETSI TC TISPAN Vice-Chairman
EMV® 3-D Secure - High Level Overview
FTP - File Transfer Protocol
Lesson #8 MCTS Cert Guide Microsoft Windows 7, Configuring Chapter 8 Configuring Applications and Internet Explorer.
IIS.
Principles/Paradigms Of Pervasive Computing
Top Reasons to Choose Android Today. Over the years the Android OS has progressed largely by acquiring major percent of global market share. A number.
Top Reasons to Choose Android Today. Over the years the Android OS has progressed largely by acquiring major percent of global market share. A number.
Understanding Android Security
PLANNING A SECURE BASELINE INSTALLATION
SCCM in hybrid world Predrag Jelesijević Microsoft 7/6/ :17 AM
Remedy Integration Strategy Leverage the power of the industry’s leading service management solution via open APIs February 2018.
Presentation transcript:

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 1 MExE +44 (0) MExE Mobile Execution Environment …making the multimedia internet mobile… MExE Mobile Execution Environment …making the multimedia internet mobile…

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 2 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 3 MExE MExE Timetable  MExE (Release 98)  WAP and PersonalJava classmarks  approved 2Q99  MExE (Release 99)  SIM security enhancements  Quality of Service management  approved 4Q99  MExE (Release 4)  Java CLDC/MIDP classmark  other updates/additions  approved 4Q00

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 4 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 5 MExE 2G mobile services Service creation before Release 99Service creation before Release 99 Supplementary servicesSupplementary services limited, expensive to develop, difficult to deploy, limited uselimited, expensive to develop, difficult to deploy, limited use isolated from 3 rd party services developers, no internetisolated from 3 rd party services developers, no internet offered operators same bland services and no differentiationoffered operators same bland services and no differentiation Service creation since Release 99Service creation since Release 99 services as a general principle not standardisedservices as a general principle not standardised instead toolkits standardised, and services created using the toolkitsinstead toolkits standardised, and services created using the toolkits Seamless internet and intranet accessSeamless internet and intranet access compatibility with internet multimedia communicationscompatibility with internet multimedia communications

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 6 MExE 3G mobile multimedia services mobile phones fully internet integrated mobile phones fully internet integrated new operator/3 rd party IP multimedia services new operator/3 rd party IP multimedia services new personalised IP multimedia services rapidly developed to differentiate operators, reduce “churn” new personalised IP multimedia services rapidly developed to differentiate operators, reduce “churn” generally no services standardised, but enabled using 3GPP services toolkits (MExE, OSA, CAMEL, (U)SAT) and IP/IT toolkits generally no services standardised, but enabled using 3GPP services toolkits (MExE, OSA, CAMEL, (U)SAT) and IP/IT toolkits consistent “look’n’feel” of services within the VHE consistent “look’n’feel” of services within the VHE

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 7 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 8 MExE MExE Overview  standardised execution environments in mobile phone  WAP  PersonalJava  CLDC/MIDP Java  applicable to 3G, non-3G, cordless and fixed environments  IT/IP multimedia services on mobile phones/servers  write once, execute on many mobile phones  transfer of multimedia services  up/downloading, network/3rd party, MExE-to-MExE services  standardised negotiation of capabilities with servers

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 9 MExE MExE Overview  Manufacturer’s mobile phone unit Firmware  Manufacturer’s firmware OS  Mobile phone OS Telecomms  GMS/UMTS software APIs  APIs: manufacturer  MExE framework (MExE classmark 1, 2, 3) APIs, MExE classmark MExE  MExE executables, data and content AppContent DataApp ContentData Content The MExE framework sits in mobile phone architecture…  HTTP/WSP (with capability exchange)

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 10 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 11 MExE MExE functionality  standardised set of MExE classmarks  WAP, WAP/PersonalJava, CLDC/MIDP multimedia services  wide variety of multimedia services  with no standardised 3G services, MExE enables operator/3 rd party multimedia service delivery to users  multimedia services supported by all devices of a given classmark (CM)  CM1 devices support CM1 applications, CM2 devices support CM2 applications, CM3 devices support CM3 applications  sophisticated user interface  advanced services presentation  Graphical User Interface (GUI)

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 12 MExE MExE functionality  customisation and personalisation  services “look and feel” (user interface and services personalisation)  services communication with network/non-network nodes  operator branding and differentiation  enables the Virtual Home Environment  user services management  services download  services/data management  determine active services

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 13 MExE MExE functionality  re-use of existing technologies  software industry expertise, development tools  WAP, Internet and Intranet  existing APIs, (i.e. WAP, PersonalJava, Java MIDP/CLDC...)  capability negotiation  allows servers and MExE mobiles to determine the most suitable content format for the device (e.g. depending on screen size, memory, colour capabilities etc.)

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 14 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 15 MExE MExE Security Domains  secure environment for multimedia services  multiple Third Party domains permitted Third Party OperatorManufacturerThird Party  3 optional security domains (PKI certificates) optional Untrusted  1 “untrusted” area mandatory

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 16 MExE Operator’s Domain  only operator PKI authenticated multimedia services permitted  operators provide existing services and new multimedia services  branded services  franchised services  customer support  service personalisation  defined set of mandatory security restrictions on downloaded applications

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 17 MExE Handset Manufacturer’s Domain  permits mobile phone upgrades  “provisioned applications” upgrade  user interface upgrades  software updates  manufacturer’s multimedia services  defined set of mandatory security restrictions on downloaded applications  only manufacturer’s PKI authenticated multimedia services permitted

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 18 MExE Third Party Domain  “Administrator” determines whether Third Party domain is controlled by the operator or user  Operator controlled:  Operator controlled: operator decides which (if any) PKI authenticated third party services  User controlled:  User controlled: user decides which PKI authenticated third party services  defined set of mandatory security restrictions on downloaded applications

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 19 MExE Untrusted Area  user in control of the untrusted area  user downloads any multimedia service as desired  call origination  screen access  sending DTMF  add phonebook entry  downloaded multimedia services have limited permissions (only with explicit user authorisation)  defined set of mandatory security restrictions on downloaded applications

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 20 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 21 MExE Release 4 issues  explicitly defining the certificate verification process  need to clearly identify the process  need to define demotion of signed content to Untrusted Area  only in specifically defined cases  demoted content restricted to same basic functionality as untrusted applications  pre-launch verification of executables  applications require to be verified before being launched  clarify rules on operator applications

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 22 MExE Release 4 issues  administrator designation process  tidying up terminology  handling of operator applications on (U)SIM activity  operator executables currently have special handling  should operator executables be permitted to execute even if the (U)SIM is not available?  should operator executables also require pre-launch verification?  (U)SIM terminology  Replace terminology of “(U)SIM removal/insertion” with “accessing valid (U)SIM application”

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 23 MExE Agenda MExE timetable 2G and 3G Services MExE overview MExE functionality MExE domains and security MExE Release 4 issues MExE Release 5

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 24 MExE R5 Enhancements and Improvements WID  General enhancements and improvements  Investigate/identify VHE User Profile support  Investigate/identify USAT/OSA/CAMEL interaction  Investigate/identify new CLI classmark  Investigate/identify terminal management support  Investigate/identify AT commands support  Investigate/identify Push services support  Investigate/identify service provisioning support

Mark Cataldo / Louis Finkelstein 1 st March, 2001 Slide 25 MExE R5 Security Analysis Activity WID  Conduct a threat analysis of MExE to review the security features for effectiveness in countering those threats.  Perform a security analysis for the different releases of MExE and the associated classmarks  Identify issues in terms of security concepts and mechanisms for MExE  Identify potential threats, weaknesses and security shortfalls  Create policy as countermeasures for identifiable weaknesses  To map policies to the requirements within the specification  The output TR will be used as a basis to potentially agree CRs to S1's , T2's , and S3's and