MPhil Thesis Defence "A PKI-based Secure Infrastructure for Mobile Electronic Commerce" By Mr. Tin-Wo Cheung Abstract Electronic commerce is gaining in popularity in recent years. The high penetration rate of the mobile handset, evolving technology on handheld mobile devices and deployment of the public key infrastructure in many parts of the world have led to the development of electronic commerce on mobile devices. However, a PKI-based end-to-end secure and open infrastructure for supporting electronic transactions on mobile is still absent. This is hampering the public's adoption of mobile commerce. The main challenge is the limited computing capacity on these devices for PKI operations which are CPU intensive and requires much more memory space compared to symmetric key operations. This is especially true for the mobile phone in which the only accessible processor and memory is the SIM card in GSM phones. In this thesis, we present a new architecture and protocol for authentication and key exchange as well as the supporting infrastructure that is suitable and optimised for the mobile phone environment. The system and security requirements and our solutions in addressing these requirements in the restrictive environment are discussed. An evaluation of the system performance is also included. The system has been implemented and is supporting some real-life applications. Date: Monday, 20 August 2001 Time: 3:00p.m.-5:00p.m. Venue: Room 3006 Lift 4 Committee Members: Prof. Samuel Chanson (Supervisor) Dr. Dit-Yan Yeung (Chairman) Dr. Man-Hoi Choy **** ALL are Welcome ****