Mobile commerce is becoming more and more commonplace, but security is still a major concern. To provide security, the WAP
(Wireless Application Protocol) forum suggests the WAP security architecture. However, it needs the WAP gateway for intermediate
process between the WTLS (Wireless Transport Layer Security) and the SSL (Secure Socket Layer) protocol, and it does not guarantee
end-to-end security between the mobile devices and the WAP servers. In this paper, we propose a new authentication protocol
to solve this problem. Our solution is based on the design of a new network component that is called CRL-agent. Furthermore,
we also analyze and evaluate the security strength of the proposed protocol.