SecureSMS: A secure SMS protocol for VAS and other applications

•SecureSMS protects system from reply, MITM attack, SMS spoofing, SMS disclosure.•SecureSMS solves security issues related to OTA interface and SS7 signaling network.•It generates minimum computation & communication overhead compare to SMSSec, PK-SIM.•SecureSMS is also better in terms of bandwid...

Ausführliche Beschreibung

Gespeichert in:
Bibliographische Detailangaben
Veröffentlicht in:The Journal of systems and software 2014-04, Vol.90, p.138-150
Hauptverfasser: Saxena, Neetesh, Chaudhari, Narendra S.
Format: Artikel
Sprache:eng
Schlagworte:
Online-Zugang:Volltext
Tags: Tag hinzufügen
Keine Tags, Fügen Sie den ersten Tag hinzu!
Beschreibung
Zusammenfassung:•SecureSMS protects system from reply, MITM attack, SMS spoofing, SMS disclosure.•SecureSMS solves security issues related to OTA interface and SS7 signaling network.•It generates minimum computation & communication overhead compare to SMSSec, PK-SIM.•SecureSMS is also better in terms of bandwidth utilization compare to both protocols.•It provides authentication, confidentiality, integrity, non-repudiation. Nowadays, the SMS is a very popular communication channel for numerous value added services (VAS), business and commercial applications. Hence, the security of SMS is the most important aspect in such applications. Recently, the researchers have proposed approaches to provide end-to-end security for SMS during its transmission over the network. Thus, in this direction, many SMS-based frameworks and protocols like Marko's SMS framework, Songyang's SMS framework, Alfredo's SMS framework, SSMS protocol, and, Marko and Konstantin's protocol have been proposed but these frameworks/protocols do not justify themselves in terms of security analysis, communication and computation overheads, prevention from various threats and attacks, and the bandwidth utilization of these protocols. The two protocols SMSSec and PK-SIM have also been proposed to provide end-to-end security and seem to be little better in terms of security analysis as compared to the protocols/framework mentioned above. In this paper, we propose a new secure and optimal protocol called SecureSMS, which generates less communication and computation overheads. We also discuss the possible threats and attacks in the paper and provide the justified prevention against them. The proposed protocol is also better than the above two protocols in terms of the bandwidth utilization. On an average the SecureSMS protocol reduces 71% and 59% of the total bandwidth used in the authentication process as compared to the SMSSec and PK-SIM protocols respectively. Apart from this, the paper also proposes a scheme to store and implement the cryptographic algorithms onto the SIM card. The proposed scheme provides end-to-end SMS security with authentication (by the SecureSMS protocol), confidentiality (by encryption AES/Blowfish; preferred AES-CTR), integrity (SHA1/MD5; preferred SHA1) and non-repudiation (ECDSA/DSA; preferred ECDSA).
ISSN:0164-1212
1873-1228
DOI:10.1016/j.jss.2013.12.031