Nokia 8910 User Manual page 54

Hide thumbs Also See for 8910:
Table of Contents

Advertisement

M e n u f u n c t i o n s
Security module
The security module provides
security services for WAP- related
applications and enables digital
signing. If present, the security
module is in the SIM card as an
optional service of your service
provider. The security module helps
to prevent the card content from
being maliciously read or modified.
(It can contain certificates, as well
as private and public keys to operate
the certificates. The certificates are
stored in the security module by the
SIM card issuer or the service
provider.)
Digital signature
You can sign, for example, a bill or a
financial contract digitally while
using WAP. Note that the signature
can be traced back to you via the
private key and the associated
certificate that was used to perform
the signature, so signing using the
digital signature is the same as
signing your name to a paper bill,
contract or other document.
When you select a link, for example,
the title of the book you want to buy
and its price, the digital signature
procedure starts and shows the text
to be signed. At this point the header
text is
Read
and the digital signature
icon
is shown.
42
Copyright © 2004 Nokia. All rights reserved.
Note: If the digital
signature icon does not
appear, this means that
there is a security breach,
and you should not enter
any personal data such as
your signing PIN.
To sign the displayed text, select
Sign, after you have read all of the
text.
Note: The text may not fit
within a single screen.
Therefore, make sure to
scroll through and read all
of the text before signing.
Select the user certificate you want
to use in the signing. Key in the
signing PIN (supplied by the service
provider) and press OK. Since the
PIN code will not be sent outside the
phone, it will remain secret. The
phone shows a confirmation of your
purchase, the digital signature icon
will disappear, and you can continue
browsing or end the WAP
connection.
Certificates
There are three kinds of certificates:
• Server certificates
A server certificate is sent from
the server to the phone and its
validity is checked using the
authority certificates stored in
the phone or the security module.
This process helps to determine
whether a WAP gateway or a

Advertisement

Table of Contents
loading

Table of Contents