Our research on smart and secure services and applications focuses on user guidance and contextual intelligence in mobile systems to keep up with continuously changing and augmenting demands of mobile communication environments. Core research targets are semantically well-founded personalization and service concepts with a universal serviceability. This includes context management, reasoning as well as service platform aspects. More specifically, the following items are part of our research agenda:
| • |
Platforms for Context Awareness and Context Management |
| • |
Semantic Web Technology to support mobile services and applications. |
| • |
Ontologies together with related knowledge representation and reasoning techniques. Advancement and application of the W3C Web Ontology Language (OWL). |
| • |
Emerging paradigms in Service-oriented Computing towards semantic service frameworks. Advancement and application of OWL-S and W3C SAWSDL. |
| • |
Convergence of established Web 2.0 paradigms such as community-based tagging, information mash-up and social networking towards mobile applications. |
| • |
Service deployment in ubiquitous computing environments. Smart Near Field Communications solutions to facilitate easy interaction with complex services. |
| • |
Development and support of IYOUIT – Share, Life, Blog, Play, an application for a digital mobile lifestyle and Web 2.0 |
Further, we perform research on the security technologies for the envisioned services and the security of mobile terminals. The security technologies research includes usage control, where usage control is an extension of access control and deals with what may happen to data when they have been released to a data consumer. Privacy consideration, intellectual property and public security suggest that data providers want to impose a certain amount of control on the data they release. If it comes to the deployment of services and applications onto mobile terminals, issues such as whether the downloading of code may harm the terminal become apparent. Thus, for the security of mobile terminals, our research activities are on securing the deployment and execution of services and applications. Currently, we are aiming at the security of managed code (e.g., Java® and .NET™ CLR) but extend this by looking into native code as well. However, our work as well considers the integration of security into services and application. For instance, we devised a non-repudiation service for trading digital resources in Near Field Communication and ad hoc networks. This service uses a novel authentication scheme tailored to the constraints found in ad hoc networks. Furthermore we built our expertise on secure mobile business application, context-aware security service and trust evaluation of context information. Thus, research topics of interest are:
| • |
Access and usage control with a focus on policies and policy enforcement. |
| • |
Privacy enhancing technologies, digital right management, control mechanism, their specification, analysis and implementation. |
| • |
Model checking, static analysis, code in-lining and runtime monitoring. |
| • |
Authentication, authorization and anonymity. |
| • |
Security framework for mobile services and applications, web services security, context-awareness and security. |
| |
|
|