Home > Mobile Computing Tips > Mobile Security > Understanding wireless security
Mobile Computing Tips:
EMAIL THIS
 TIPS & NEWSLETTERS TOPICS 

MOBILE SECURITY

Understanding wireless security


Craig J. Mathias, Contributor
04.19.2006
Rating: -4.50- (out of 5)


Mobile advice
Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google


Suppose I were to say to you that there's really no such thing as wireless security. That would sound pretty silly, especially since (a) data is clearly flying through the air, in range of anyone nearby with the right equipment, and (b) wireless security has historically been the number one concern of IT managers and often a roadblock to the deployment of mobile and wireless computing solutions. Silly, indeed.

And yet, when we look at wireless security as part of the overall value chain between client and server, the wireless part suddenly seems small and insignificant. This is because wireless deals only with that portion of the chain known as the airlink – the connection between a wireless client and (typically, in the case of wide-area mobility) a cellular base station. But consider all of the other connections between the cellular base station and your server -- a collection of equipment within the cellular network and the Internet or other wide-area connectivity -- and you'll see many points of vulnerability that far outweigh those of the airlink.

I am a big believer in end-to-end security. This means that, subject to a given enterprise's security policy, sensitive data is always stored securely and appears in the clear only to authorized users. And this doesn't just mean end-to-end over the airlink but rather end-to-end between the client device and the server that stores the data.

This further implies two key requirements:

  • Encryption: This means that all sensitive data is encoded while stored and during transmission, so it cannot be read by unauthorized users, legitimate or not.

  • Authentication: This means that users must identify themselves to their devices and the network before any access is allowed. Ideally, authentication is mutual, so a user cannot be fooled into sending sensitive data to a spoofed server.

    If we put this together, the core requirements are that all sensitive data must be stored encrypted on the server and the mobile client device (notebook computer, smartphone, memory key, etc.). It also means that authorized users must authenticate with the server before any data can be obtained. I recommend "two-factor authentication" using (typically) a hardware key and a password. That way, if one is lost or stolen, the data is still secure.

    Now comes the hard part.

    I also recommend that authorized users authenticate with their mobile device. This means at a minimum having to log in to one's notebook and use a PIN or similar mechanism on smartphones. Lots of users just hate this, but they need to understand enterprise security policies and also develop what we call a "culture of security" -- just as those "loose lips sink ships" posters used to remind everyone of the need for security during World War II.

    As it turns out, modern digital cellular networks include basic data security, and user traffic is by default encrypted over the air. I recommend, however, that enterprises use their own virtual private network (VPN) techniques on all wireless links; security really should be under the control of the enterprise, not the carrier.

    Basic security really isn't all that hard to plan, implement and manage. But again, it's not a matter of wireless security alone. Rather, it's end-to-end security across the entire network. Secure the whole value chain, and wireless security almost comes for free.

    Maybe there really is no such thing as wireless security after all.

    About the author: Craig Mathias is a principal with Farpoint Group, an advisory firm based in Ashland, Mass., specializing in wireless networking and mobile computing. The firm works with manufacturers, enterprises, carriers, government, and the financial community on all aspects of wireless and mobile. He can be reached at craig@farpointgroup.com.


    Rate this Tip
    To rate tips, you must be a member of SearchMobileComputing.com.
    Register now to start rating these tips. Log in if you are already a member.




    Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us    Add to Google



    RELATED CONTENT
    Mobile Security
    Mobile security threats
    Two-factor authentication: Mobile security at your fingertips
    Securing your Windows Mobile devices
    In-the-cloud defenses for mobile malware
    On-device defenses for mobile malware
    Is malware coming to a smartphone near you?
    Protecting data on your BlackBerry
    Defining your mobile security policy
    Government regulations and mobile security policies
    Symbian: Protect your data, not just your device

    Mobile Authentication and Encryption
    Sybase offers enterprise-ready iPhone solution on the App Store
    Two-factor authentication: Mobile security at your fingertips
    RIM makes hostile takeover bid for encryption vendor Certicom
    In-the-cloud defenses for mobile malware
    Podcast: The truth about network security and mobile device access
    iPhone encryption is a must for the security-conscious enterprise
    Sybase iAnywhere launches productivity suite that tunnels critical business apps through email
    Mobile voice encryption gets cheaper, easier to do
    Avoiding data breaches through mobile encryption
    Mobile device security: Improving mobile authentication
    Mobile Authentication and Encryption Research

    Mobile Device Security
    Fingerprint recognition and mobile security
    Traditional security threats coming soon to mobile device near you
    Securing your Windows Mobile devices
    Mobile security: Protecting your data, not just your devices
    Prevent mobile malware: Learn how to protect your enterprise and devices
    Podcast: The truth about network security and mobile device access
    Protecting data on your BlackBerry
    Going green: Recycling and energy saving tips for mobile devices -- podcast
    New challenges in mobile device discovery
    Quiz: Mobile Device Security -- Who else can hear me now?
    Mobile Device Security Research

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    CCMP  (SearchMobileComputing.com)
    drive-by spamming  (SearchMobileComputing.com)
    LEAP (Lightweight Extensible Authentication Protocol)  (SearchMobileComputing.com)
    Open System Authentication (OSA)  (SearchMobileComputing.com)
    SIM card  (SearchMobileComputing.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary

    DISCLAIMER: Our Tips Exchange is a forum for you to share technical advice and expertise with your peers and to learn from other enterprise IT professionals. TechTarget provides the infrastructure to facilitate this sharing of information. However, we cannot guarantee the accuracy or validity of the material submitted. You agree that your use of the Ask The Expert services and your reliance on any questions, answers, information or other materials received through this Web site is at your own risk.



  • Mobile Computing Security - Device Security, Mobile Authentication, Mobile Threats

    Notebook Deals at Notebook Review

    HomeNewsTopicsITKnowledge ExchangeTipsMultimediaWhite PapersProducts
    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides technology professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective purchase decisions and managing their organizations' technology projects - with its network of technology-specific websites, events and online magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2003 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts