Title: IIAC Briefing
1Hongkong Post
Hongkong Post e-Courier Service The Use of
PKI in Mobile Services
20 June 2000
2Hongkong Post e-Courier Service
Websenger - the Secure Digital Delivery Service
3Websenger
- Jointly launched with Cable Wireless
- HKT on 17 May 2000
4Websenger
Secure Digital Delivery Service
- - Hong Kongs first e-Cert enabled application
- - The first PKI based secure digital delivery
service - - Support SSL connection
- - Support Password-based authentication
- - Support e-Cert end-to-end encryption
5Websenger
- Features
- - Document tracking
- - Trusted time stamping
- - Scheduled delivery
- - Manual cancellation
- of documents
6Websenger
- Three packaged prices are offered -
Plan A Plan B Plan C Monthly
HK65 HK180 HK700 subscription
fee (5 items) (20 items) (100
items) Charges for HK11 HK8
HK6 additional items
7Websenger
- On-line registration
- at www.websenger.com
8Websenger
Notification appears in the recipients email box
(URL only)
Recipient access URL to read message
Customer access Websenger website
www.websenger.com and send message to recipient
Secure Connection (Secured Socket Layer)
Websenger Server at CA Centre
9Login www.websenger.com
10Easy way to send with different security levels
11Other security options
Secure Socket Layer protection Require
recipients account password to receive Require
pre-agreed password to receive
12 Sending Encrypted Signed Package
13Signing from desktop certificate store
14Other security options
15Schedule delivery / Expiration setting etc
16Status checking
17More detail status checking
18The recipient will receive a notification
19Click the URL to get the package
20Open the incoming message
21Verify the e-Cert of sender by a click
22View the senders e-Cert
23Account Information
24Billing information
25Maintain multiple address books
26Hongkong Post CA Services
Use of PKI in Mobile Services by Hongkong Post
27Use of PKI in Mobile Services
- Background
- over 4m mobile phones
- A joint Forum was set up on 26.4.00 by Hutchison
Telecom, CWHKT and SmarTone to establish a common
security platform for mobile certificate - New World, Sunday and People joined the Forum on
24.5.00
28Use of PKI in Mobile Services
- Background
- To support the strong demand for secure
electronic transactions, digital certificates
have to be in different forms and stored in
different devices such as Hongkong e- Cert in
Personal Computers and Mobile Certificate on GSM
SIM cards.
29Use of PKI in Mobile Services
- The major mobile technologies are
- Sonera Smartrust for GSM SIM cards
- Baltimore Telepathy for WAP enabled devices, and
- Eliptic Curve Crytography for PDA devices
30Use of PKI in Mobile Services
- HKP strategy toward m-Cert
- A generic m-cert may not be possible in the short
term because several technologies are available - Each mobile phone operator will bear the cost of
developing its own m-Cert with HKP - All operators will be treated on a non-exclusive
basis
31Use of PKI in Mobile Services
- MOU Signed with New World Mobility on 15.5.2000
32Use of PKI in Mobile Services
- NW PCS Ltd. has selected Sonera technology as the
technical platform for secure mobile
transactions. -
33Use of PKI in Mobile Services
- The Stock Exchange of Hong Kong has agreed to
integrate the New World Mobile Cert with the
Stock Exchange AMS/3 platform, enabling secure
mobile stock trading service in Oct 2000
34M-Cert Operation Model
Consumer
Mobile Phone Operator as Registration Authority
(RA)
2
Mobile Phone Operator
- SIM Management
- Public Key/NID pairs
- management
- Registration Authority
1
Purchase order for SIMs
HKP CA
4
SIM Manufacturer
SIMs (NID, PriKey) (PubKey, NID)
- Generates NIDs for
- SIMs
- Generates key pairs
- for associated NIDs
- Embeds Private Key
- NID in SIM
- Certificate Issuance Authority
- Certificate Management
Cert. Requests approved by MO NID, HKID, PubKey
M-Cert
SIM (NID, Prikey)
3
5
Identity Verification (NID, HKID)
Place order to Merchant
6
Consumer
Merchant
Delivery of goods/ services
7
35Hongkong Post
Thank You