Elective Mobile Application Development

Mobile Application DevelopmentUnit 610 min read

Wireless Networks, Protocols & Mobile App Integration

Unit 6 of Mobile Application Development explores wireless communication technologies (Wi-Fi, Bluetooth, cellular networks), their protocols (TCP/IP, HTTP/HTTPS, MQTT), security mechanisms (WPA3, TLS), and how mobile apps interact with these systems. Covers real-world implementations like eSewa’s secure transactions, P

TAKEAWAYS:

  • Wireless connectivity relies on radio waves (Wi-Fi), microwaves (cellular), or infrared/Bluetooth (short-range), each with distinct speed, range, and power constraints.
  • TCP/IP and HTTP/HTTPS are the backbone of mobile app communication, while MQTT enables lightweight IoT/mobile messaging.
  • Security protocols (WPA3, TLS) protect data in transit, but mobile apps must handle offline scenarios and reconnection logic.
  • Latency and bandwidth directly impact app performance (e.g., video streaming vs. chat apps).
  • Nepali examples: eSewa uses HTTPS + OAuth for secure payments; Pathao relies on GPS + cellular data for ride tracking; Ncell’s 4G/LTE network manages voice/data traffic via SIP for VoIP.
  • Exam focus: Compare protocols (Wi-Fi vs. Bluetooth vs. cellular), trace packet flows, and explain how apps handle disconnections/reconnections.

Wireless Communication Technologies

Wireless connectivity enables mobile apps to interact with networks without physical cables. The three primary technologies are:

1. Wi-Fi (IEEE 802.11 Standards)

  • Uses radio waves (2.4 GHz or 5 GHz) for short-to-medium range (up to 100 meters indoors).
  • Standards:
    • 802.11n (Wi-Fi 4): Up to 600 Mbps, MIMO technology.
    • 802.11ac (Wi-Fi 5): Up to 3.5 Gbps, wider channels.
    • 802.11ax (Wi-Fi 6): Improved efficiency in crowded networks (e.g., airports).
  • Security: WPA3 (replaces WPA2) uses SAE (Simultaneous Authentication of Equals) to prevent brute-force attacks.
  • Use in Nepal:
    • eSewa app uses Wi-Fi for secure transactions when users are at home/businesses.
    • NTC’s public Wi-Fi hotspots (e.g., in Kathmandu) rely on 802.11ac for high-speed internet.
Wi-Fi Signal (802.11ac)InternetDataResponseUser DeviceRouter (AP)ISPServer
Wi-Fi data flow in Nepal (eSewa/NTC hotspots)

Figure 1: Wi-Fi communication flow (eSewa transaction example).

2. Bluetooth (IEEE 802.15.1)

  • Uses short-range radio waves (2.4 GHz), ideal for device pairing (e.g., headphones, printers).
  • Versions:
    • Bluetooth Classic: Low speed (up to 24 Mbps), used in audio devices.
    • Bluetooth Low Energy (BLE): Optimized for low power (e.g., fitness trackers, beacons).
  • Use in Nepal:
    • Khalti’s POS machines use BLE for contactless payments.
    • Health apps (e.g., pulse oximeters) connect via BLE to smartphones.
BLE PairingEncrypted PaymentKhalti POSUser PhoneMerchant Terminal
Bluetooth Low Energy (BLE) payment flow (Khalti)

Figure 2: BLE connection steps (Khalti POS example).

3. Cellular Networks (3G/4G/5G)

  • Uses microwaves for long-range communication via base stations (cell towers).
  • Generations:
    • 3G: Up to 42 Mbps (e.g., Ncell’s early 3G).
    • 4G/LTE: Up to 1 Gbps (Nepal’s current standard).
    • 5G: Ultra-low latency (<1 ms), higher bandwidth (Ncell testing in Kathmandu).
  • Protocols:
    • SIP (Session Initiation Protocol): Used for VoIP (e.g., Ncell’s internet calling).
    • MQTT: Lightweight protocol for IoT/mobile messaging (e.g., Daraz’s inventory updates).
InternetResponseMobile PhoneCell Tower (eNodeB)MMEVoIP Server
5G VoIP call flow (Ncell example)

Figure 3: 4G VoIP call flow (Ncell internet calling).


Wireless Protocols for Mobile Apps

Mobile apps use protocols to communicate over wireless networks. Key protocols include:

1. TCP/IP Suite

  • TCP (Transmission Control Protocol): Reliable, connection-oriented (e.g., web browsing, emails).
  • UDP (User Datagram Protocol): Faster, connectionless (e.g., video streaming, online games).
  • IP (Internet Protocol): Addresses packets for routing (IPv4 vs. IPv6).

Comparison Table:

Feature TCP UDP
Reliability Guaranteed delivery No guarantee
Speed Slower (handshakes) Faster
Use Case Web (HTTP), emails Video calls, gaming
Header Size 20 bytes 8 bytes

Example: eSewa uses TCP for secure transactions (reliable data transfer) but may use UDP for real-time chat notifications.

2. HTTP/HTTPS

  • HTTP (Hypertext Transfer Protocol): Stateless protocol for web requests (e.g., loading Daraz product pages).
  • HTTPS: Secure HTTP with TLS/SSL encryption (used by all banking apps like NMB Bank).
  • Methods:
    • GET: Retrieve data (e.g., fetching stock prices from NEPSE).
    • POST: Send data (e.g., submitting a Pathao ride request).
    • PUT/DELETE: Update/delete resources.
sequenceDiagram
  participant User
  participant App
  participant Server
  User->>App: Clicks "Book Ride" (Pathao)
  App->>Server: POST /rides (HTTPS)
  Server-->>App: 201 Created (Ride ID)
  App-->>User: Displays "Ride Confirmed"

Figure 4: HTTPS request flow (Pathao ride booking).

3. MQTT (Message Queuing Telemetry Transport)

  • Lightweight protocol for IoT/mobile messaging (e.g., Daraz’s warehouse inventory updates).
  • Uses publish-subscribe model:
    • Broker: Middleman (e.g., Mosquitto).
    • Topics: Channels (e.g., daraz/inventory/books).
  • QoS Levels:
    • 0: Fire-and-forget (e.g., sensor data).
    • 1: At least once delivery (e.g., order confirmations).
    • 2: Exactly once (critical updates).
Publish (Topic: stock)Subscribe (Topic: stock)Daraz ServerMobile AppInventory Sensor
MQTT publish-subscribe for Daraz inventory updates

Example: A Daraz app subscribes to daraz/inventory/books to update stock levels in real time.


Security in Wireless Communication

Wireless networks are vulnerable to attacks (e.g., man-in-the-middle, eavesdropping). Security measures include:

1. Wi-Fi Security: WPA3

  • Replaces WPA2 with stronger encryption (SAE instead of PSK).
  • Features:
    • Forward Secrecy: Past sessions can’t be decrypted if a key is stolen.
    • Protected Management Frames: Prevents deauthentication attacks.
  • Use in Nepal: NTC’s public Wi-Fi now uses WPA3 in major cities.

2. TLS/SSL for HTTPS

  • Encrypts data between app and server (e.g., Khalti payments).
  • Handshake Process:
    1. Client sends supported cipher suites.
    2. Server responds with its digital certificate.
    3. Client verifies certificate (via CA like Let’s Encrypt).
    4. Symmetric key exchange (e.g., AES).
flowchart TD
  A["Client"] -->|"Hello"| B["Server"]
  B -->|"Certificate"| A
  A -->|"Key Exchange"| B
  B -->|"Encrypted Data"| A

Figure 5: TLS handshake (Khalti payment example).

3. Mobile App Security Best Practices

  • Certificate Pinning: Bind app to a specific server certificate (prevents MITM).
  • Data Encryption: Use SQLCipher for local databases (e.g., eSewa’s offline transactions).
  • Secure Authentication: OAuth 2.0 (e.g., eSewa login via Facebook/Google).

Handling Network Disconnections in Mobile Apps

Mobile networks are unreliable (e.g., Kathmandu traffic jams drop 4G signals). Apps must handle:

  1. Offline-First Design:

    • Store data locally (e.g., Room Database in Android) and sync later.
    • Example: Pathao app caches ride history for offline access.
  2. Reconnection Logic:

    • Use exponential backoff to retry failed requests.
    • Example: Daraz app retries failed order placements every 5 seconds (then 10, 20, etc.).
  3. Conflict Resolution:

    • Last-write-wins: For non-critical data (e.g., chat messages).
    • Merge strategies: For critical data (e.g., banking transactions).
    // Pseudocode for offline-first sync (Android)
    public void syncData() {
        if (isOnline()) {
            uploadLocalChanges();
        } else {
            scheduleRetry(); // Exponential backoff
        }
    }
    

    Trace:

    Step Network Status Action
    1 Online Uploads 3 pending orders
    2 Offline Schedules retry in 5 seconds
    3 Online (later) Retries, uploads remaining 1

Real-World Applications in Nepal

  1. eSewa App:

    • Technology: HTTPS (TLS 1.3) + OAuth for authentication.
    • Wireless Use: Wi-Fi for home transactions, 4G for mobile payments.
    • Challenge: Handles disconnections by caching transactions and syncing later.
  2. Pathao Ride-Hailing:

    • Technology: GPS (via cellular data) + WebSockets for real-time driver tracking.
    • Protocol: MQTT for lightweight driver location updates.
    • Example: When a user books a ride, the app:
      1. Sends a POST /rides request (HTTPS).
      2. Subscribes to pathao/ride/{id}/updates (MQTT) for ETA changes.
  3. Ncell’s 4G Network:

    • Protocol: SIP for VoIP calls (e.g., Ncell’s internet calling).
    • Optimization: Uses load balancing to distribute traffic across cell towers during peak hours (e.g., 7–9 PM in Kathmandu).
  4. Daraz Marketplace:

    • Wireless Stack: HTTP/2 for product pages, MQTT for inventory updates.
    • Offline Handling: Caches product listings; syncs when back online.

Exam Tip

  1. Diagrams Are Key:
    • Draw OSI vs. TCP/IP model comparisons.
    • Trace TLS handshake or MQTT publish-subscribe flows.
  2. Compare Protocols:
    • Wi-Fi vs. Bluetooth vs. Cellular (speed, range, power).
    • TCP vs. UDP (reliability vs. speed).
  3. Real-World Scenarios:
    • Explain how eSewa uses HTTPS + OAuth or Pathao uses MQTT for GPS.
    • Describe offline-first sync with a trace table.
  4. Security Focus:
    • Differentiate WPA2 vs. WPA3 and TLS 1.2 vs. 1.3.
    • Mention certificate pinning and OAuth 2.0 in app security.
  5. Common Pitfalls:
    • Don’t confuse HTTP (stateless) with WebSockets (persistent).
    • Remember: MQTT is for IoT/mobile messaging, not general web requests.

Visual Summary:

Based on the TU BIT syllabus for Mobile Application Development, unit 6.

Discussion

Loading…