SlideShare uma empresa Scribd logo
1 de 17
Baixar para ler offline
FIDO and Mobile Connect
FIDO Seminar, Barcelona
May 8th 2017
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
About the GSMA
The GSMA represents the interests of
mobile operators worldwide
Spanning more than 220 countries, the
GSMA unites nearly 800 of the world’s
mobile operators, as well as more than
230 companies in the broader mobile
ecosystem
Identity – Mobile Connect2
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.3
Introducing Mobile Connect, a mobile operator
facilitated digital identity solution
• Simple, secure and convenient access to
online services
• Enables users to:
• Authenticate online
• Authorise digital transactions
• Verify their identity
• …via their mobile device, anywhere
Convenient
via the device in
your pocket
Secure
using regulated
networks
Private
no data shared
without consent
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.4
Example use case: reducing user friction by
minimising steps to fulfil online commerce transaction
Select items; click
thru to checkout Form filling
Registration
complete
Select
payment type
Authorise
transaction
Username/
password
Without Mobile Connect
With Mobile Connect
Select
Select items; click
thru to checkout to checkout
Authenticate -> authorise
payment -> agree to share
name/address with merchant
via a single action
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Mobile Connect offers a range of services for digital transactions
Helping users manage their identity across their digital footprint
Authentication AttributesIdentityAuthorisation
Simple and globally
ubiquitous log-in
Insights about the user,
device or transaction
Assertion of user
identity
User authorisation of
SP requests
Identity – Mobile Connect5
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Mobile Connect and FIDO both seeking to replace passwords via
use of the mobile phone for authentication
6
Something I
Know
Something I
Have
Something I Have
+
Something I
Know
Something I Have
+
Something I Am
Or
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Mobile Connect leverages FIDO to expand
its set of Authenticators
7
Federation
Authentication
User Management
Physical-to-digital identity
Existing MNO
KYC
processes
Device-based authenticators
Existing MNO CRM databases
Network-based authenticators
(USSD, SIM applet etc.)
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
FIDO integrates into Mobile Connect as an optional
authenticator subsystem
8
FIDO UAF protocol
Mobilephone
with FIDO client AuthN server
MNO
Tablet/desktop
Service access request
Service Provider
Authentication
request
Identity GW
First mile
Second mileSIM applet protocol (CPAS8)
AuthN
server
SIM
applet
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.9
52 operators launched in 29 markets
3bn
…enabled users
world-wide
82m
…Mobile
Connect users…
17m
…monthly active
users
Correct as at April 2017
Cambodia
Italy
Bangladesh
Sri Lanka
Pakistan
India
China
Indonesia
South Korea
Australia
Thailand
Myanmar
Egypt
Turkey
Spain
Argentina
Peru
Mexico
Canada
Finland
France
Malaysia
Brazil
Switzerland
Jordan
Poland
Uruguay
Colombia
Ecuador
Morocco
UK
Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
• Mobile Connect and FIDO are complementary
providing a robust and extensible authentication framework
providing a federated digital identity framework leveraging FIDO to
deliver a range of services for facilitating secure digital transactions
• Both in combination help users transact more safely and conveniently online
Identity – Mobile Connect10
Take aways
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Mobile Connect API documentation & sandbox:
https://developer.mobileconnect.io
11 Identity – Mobile Connect
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
NSTIC (National Strategy for Trusted Identities in Cyberspace) pilot to enable a common
approach to enable consumers and businesses to use mobile devices for secure,
privacy-enhancing identity and access management.
By allowing relying parties (RPs) to more easily accept identity solutions from Mobile
Network Operators, the solution is intended to reduce a significant barrier to online
service providers accepting mobile-based credentials.
Identity – Mobile Connect12
Enabling Mobile-based Identity and Access Management
Technologies
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Overall Pilot Strategy – 3 Phased Approach
• Financial sector use case with VISAto demonstrate step up authentication at point of sale.
• Consumer goods use case with InterBev to demonstrate age verification on age-restricted websites.
• Healthcare use case with San Diego Health Connect to enable patient and doctor services through a Health Information
Exchange (HIE).
• eGovernment use case with the IRS to demonstrate the ability for citizens and non-citizens to file taxes within the US and
outside the US.
Personal Data – Mobile Connect13
Establish the
Foundation
Governance (US
MNOs, GSMA,
Technology Partners)
Technical
Infrastructure and
Authenticators
Proof of Concept
Financial Sector
(Visa)
Consumer Goods
(InterBev)
Healthcare
(SDHC)
eGovernment
(IRS)
Commercial
Exploration (Trust
Framework)
Legal Privacy Contracts Business model
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
• GSMA Mobile Connect architecture with multiple models for Mobile Connect
Accelerator (MCX) implementation and three Authenticator options.
• Implementation leveraging
a Hub integrated with the
different vendors per
Authenticator option
and MNOs.
Identity – Mobile Connect14
Pilot Architecture
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.Identity – Mobile Connect15
Pilot Partners
Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.
Visa – Step-up Authentication to reduce fraud.
• Demo: https://youtu.be/m8CID7VPr1I
InterBev – Age-verification when purchasing age-restricted
products from vending machine with mobile device.
• Demo: https://vimeo.com/204070861
Over 700 people experienced the demo.
Smartphone Application Authenticator with FIDO functionality were used
as well as SIM Application Authenticator.
• SIM Application Authenticator enables a very streamlined UX and
high security.
• Smartphone demonstrated the ability to partner with a third-party
technology partner.
Identity – Mobile Connect16
Mobile World Congress 2017
If you would like more information, please contact the GSMA via:
mobileconnect@gsma.com
+44 (0) 20 7356 0600
www.gsma.com/identity
Follow the GSMA on Twitter: @GSMA
GSMA London Office
The Walbrook Building, 25 Walbrook, London EC4N 8AF
Copyright © 2018 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.

Mais conteúdo relacionado

Mais procurados

FIDO Authentication in a Mobile Network
FIDO Authentication in a Mobile NetworkFIDO Authentication in a Mobile Network
FIDO Authentication in a Mobile NetworkFIDO Alliance
 
FIDO & GSMA Mobile Connect
FIDO & GSMA Mobile ConnectFIDO & GSMA Mobile Connect
FIDO & GSMA Mobile ConnectFIDO Alliance
 
Introduction to FIDO Biometric Authentication
Introduction to FIDO Biometric AuthenticationIntroduction to FIDO Biometric Authentication
Introduction to FIDO Biometric AuthenticationFIDO Alliance
 
Strong Authentication Trends in Government
Strong Authentication Trends in GovernmentStrong Authentication Trends in Government
Strong Authentication Trends in GovernmentFIDO Alliance
 
Technical Principles of FIDO Authentication
Technical Principles of FIDO AuthenticationTechnical Principles of FIDO Authentication
Technical Principles of FIDO AuthenticationFIDO Alliance
 
Integrating FIDO & Federation Protocols
Integrating FIDO & Federation ProtocolsIntegrating FIDO & Federation Protocols
Integrating FIDO & Federation ProtocolsFIDO Alliance
 
Beyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationBeyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationFIDO Alliance
 
Deploying FIDO Authentication - Business Considerations
Deploying FIDO Authentication  - Business ConsiderationsDeploying FIDO Authentication  - Business Considerations
Deploying FIDO Authentication - Business ConsiderationsFIDO Alliance
 
A First Step to a World without Passwords
A First Step to a World without PasswordsA First Step to a World without Passwords
A First Step to a World without PasswordsFIDO Alliance
 
FIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Alliance
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationFIDO Alliance
 
FIDO Authentication for Gaming Webinar
FIDO Authentication for Gaming WebinarFIDO Authentication for Gaming Webinar
FIDO Authentication for Gaming WebinarFIDO Alliance
 
Market Study on Mobile Authentication
Market Study on Mobile AuthenticationMarket Study on Mobile Authentication
Market Study on Mobile AuthenticationFIDO Alliance
 
FIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO Alliance
 
Fido Technical Overview
Fido Technical OverviewFido Technical Overview
Fido Technical OverviewFIDO Alliance
 
Deployment Case Study: Login.gov & FIDO2
Deployment Case Study: Login.gov & FIDO2Deployment Case Study: Login.gov & FIDO2
Deployment Case Study: Login.gov & FIDO2FIDO Alliance
 
Introduction to FIDO's Identity Verification & Binding Initiative
Introduction to FIDO's Identity Verification & Binding Initiative Introduction to FIDO's Identity Verification & Binding Initiative
Introduction to FIDO's Identity Verification & Binding Initiative FIDO Alliance
 
FIDO & Mobile Connect
FIDO & Mobile ConnectFIDO & Mobile Connect
FIDO & Mobile ConnectFIDO Alliance
 
The State of Strong Authentication
The State of Strong AuthenticationThe State of Strong Authentication
The State of Strong AuthenticationFIDO Alliance
 

Mais procurados (20)

FIDO Authentication in a Mobile Network
FIDO Authentication in a Mobile NetworkFIDO Authentication in a Mobile Network
FIDO Authentication in a Mobile Network
 
FIDO & GSMA Mobile Connect
FIDO & GSMA Mobile ConnectFIDO & GSMA Mobile Connect
FIDO & GSMA Mobile Connect
 
Introduction to FIDO Biometric Authentication
Introduction to FIDO Biometric AuthenticationIntroduction to FIDO Biometric Authentication
Introduction to FIDO Biometric Authentication
 
Strong Authentication Trends in Government
Strong Authentication Trends in GovernmentStrong Authentication Trends in Government
Strong Authentication Trends in Government
 
Technical Principles of FIDO Authentication
Technical Principles of FIDO AuthenticationTechnical Principles of FIDO Authentication
Technical Principles of FIDO Authentication
 
Integrating FIDO & Federation Protocols
Integrating FIDO & Federation ProtocolsIntegrating FIDO & Federation Protocols
Integrating FIDO & Federation Protocols
 
Beyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationBeyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer Authentication
 
FIDO Masterclass
FIDO MasterclassFIDO Masterclass
FIDO Masterclass
 
Deploying FIDO Authentication - Business Considerations
Deploying FIDO Authentication  - Business ConsiderationsDeploying FIDO Authentication  - Business Considerations
Deploying FIDO Authentication - Business Considerations
 
A First Step to a World without Passwords
A First Step to a World without PasswordsA First Step to a World without Passwords
A First Step to a World without Passwords
 
FIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Authentication in Hong Kong
FIDO Authentication in Hong Kong
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
 
FIDO Authentication for Gaming Webinar
FIDO Authentication for Gaming WebinarFIDO Authentication for Gaming Webinar
FIDO Authentication for Gaming Webinar
 
Market Study on Mobile Authentication
Market Study on Mobile AuthenticationMarket Study on Mobile Authentication
Market Study on Mobile Authentication
 
FIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong Kong
 
Fido Technical Overview
Fido Technical OverviewFido Technical Overview
Fido Technical Overview
 
Deployment Case Study: Login.gov & FIDO2
Deployment Case Study: Login.gov & FIDO2Deployment Case Study: Login.gov & FIDO2
Deployment Case Study: Login.gov & FIDO2
 
Introduction to FIDO's Identity Verification & Binding Initiative
Introduction to FIDO's Identity Verification & Binding Initiative Introduction to FIDO's Identity Verification & Binding Initiative
Introduction to FIDO's Identity Verification & Binding Initiative
 
FIDO & Mobile Connect
FIDO & Mobile ConnectFIDO & Mobile Connect
FIDO & Mobile Connect
 
The State of Strong Authentication
The State of Strong AuthenticationThe State of Strong Authentication
The State of Strong Authentication
 

Destaque

NIST 800-63 Guidance & FIDO Authentication
NIST 800-63 Guidance & FIDO AuthenticationNIST 800-63 Guidance & FIDO Authentication
NIST 800-63 Guidance & FIDO AuthenticationFIDO Alliance
 
Authentication and ID Proofing in Education
Authentication and ID Proofing in EducationAuthentication and ID Proofing in Education
Authentication and ID Proofing in EducationFIDO Alliance
 
FIDO Technical Specifications Overview
FIDO Technical Specifications OverviewFIDO Technical Specifications Overview
FIDO Technical Specifications OverviewFIDO Alliance
 
FIDO Authentication Opportunities in Healthcare
FIDO Authentication Opportunities in HealthcareFIDO Authentication Opportunities in Healthcare
FIDO Authentication Opportunities in HealthcareFIDO Alliance
 
FIDO Certified Program: Status & Futures
FIDO Certified Program: Status & FuturesFIDO Certified Program: Status & Futures
FIDO Certified Program: Status & FuturesFIDO Alliance
 
Strong Authentication and US Federal Digital Services
Strong Authentication and US Federal Digital ServicesStrong Authentication and US Federal Digital Services
Strong Authentication and US Federal Digital ServicesFIDO Alliance
 
FIDO Authentication & Blockchain
FIDO Authentication & BlockchainFIDO Authentication & Blockchain
FIDO Authentication & BlockchainFIDO Alliance
 
Introduction to FIDO Alliance
Introduction to FIDO AllianceIntroduction to FIDO Alliance
Introduction to FIDO AllianceFIDO Alliance
 
FIDO Authentication for Multifactor Payments
FIDO Authentication for Multifactor PaymentsFIDO Authentication for Multifactor Payments
FIDO Authentication for Multifactor PaymentsFIDO Alliance
 
Getting to Know the FIDO Specifications - Technical Tutorial
Getting to Know the FIDO Specifications - Technical TutorialGetting to Know the FIDO Specifications - Technical Tutorial
Getting to Know the FIDO Specifications - Technical TutorialFIDO Alliance
 
Javelin Research 2017 State of Authentication Report
Javelin Research 2017 State of Authentication ReportJavelin Research 2017 State of Authentication Report
Javelin Research 2017 State of Authentication ReportFIDO Alliance
 
FIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social LoginFIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social LoginFIDO Alliance
 
FIDO - The Value of Membership
FIDO -  The Value of Membership FIDO -  The Value of Membership
FIDO - The Value of Membership FIDO Alliance
 

Destaque (13)

NIST 800-63 Guidance & FIDO Authentication
NIST 800-63 Guidance & FIDO AuthenticationNIST 800-63 Guidance & FIDO Authentication
NIST 800-63 Guidance & FIDO Authentication
 
Authentication and ID Proofing in Education
Authentication and ID Proofing in EducationAuthentication and ID Proofing in Education
Authentication and ID Proofing in Education
 
FIDO Technical Specifications Overview
FIDO Technical Specifications OverviewFIDO Technical Specifications Overview
FIDO Technical Specifications Overview
 
FIDO Authentication Opportunities in Healthcare
FIDO Authentication Opportunities in HealthcareFIDO Authentication Opportunities in Healthcare
FIDO Authentication Opportunities in Healthcare
 
FIDO Certified Program: Status & Futures
FIDO Certified Program: Status & FuturesFIDO Certified Program: Status & Futures
FIDO Certified Program: Status & Futures
 
Strong Authentication and US Federal Digital Services
Strong Authentication and US Federal Digital ServicesStrong Authentication and US Federal Digital Services
Strong Authentication and US Federal Digital Services
 
FIDO Authentication & Blockchain
FIDO Authentication & BlockchainFIDO Authentication & Blockchain
FIDO Authentication & Blockchain
 
Introduction to FIDO Alliance
Introduction to FIDO AllianceIntroduction to FIDO Alliance
Introduction to FIDO Alliance
 
FIDO Authentication for Multifactor Payments
FIDO Authentication for Multifactor PaymentsFIDO Authentication for Multifactor Payments
FIDO Authentication for Multifactor Payments
 
Getting to Know the FIDO Specifications - Technical Tutorial
Getting to Know the FIDO Specifications - Technical TutorialGetting to Know the FIDO Specifications - Technical Tutorial
Getting to Know the FIDO Specifications - Technical Tutorial
 
Javelin Research 2017 State of Authentication Report
Javelin Research 2017 State of Authentication ReportJavelin Research 2017 State of Authentication Report
Javelin Research 2017 State of Authentication Report
 
FIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social LoginFIDO, Federation & Facebook Social Login
FIDO, Federation & Facebook Social Login
 
FIDO - The Value of Membership
FIDO -  The Value of Membership FIDO -  The Value of Membership
FIDO - The Value of Membership
 

Semelhante a FIDO Authentication and GSMA Mobile Connect

[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy
[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy
[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital EconomyWSO2
 
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...Ubisecure
 
case-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_encase-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_enAlix Murphy
 
Mobile Connect and the FIDO standards
Mobile Connect and the FIDO standardsMobile Connect and the FIDO standards
Mobile Connect and the FIDO standardsFIDO Alliance
 
FIDO and Mobile Connect
FIDO and Mobile ConnectFIDO and Mobile Connect
FIDO and Mobile ConnectFIDO Alliance
 
Introduction to Mobile Connect
Introduction to Mobile ConnectIntroduction to Mobile Connect
Introduction to Mobile ConnectUbisecure
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb
 
Mobile Connections – FIDO Alliance and GSMA Presentation
Mobile Connections – FIDO Alliance and GSMA PresentationMobile Connections – FIDO Alliance and GSMA Presentation
Mobile Connections – FIDO Alliance and GSMA PresentationFIDO Alliance
 
7.2 gsm-association-fraud-forum
7.2 gsm-association-fraud-forum7.2 gsm-association-fraud-forum
7.2 gsm-association-fraud-forumkkvences
 
Biometrics for Payment Authentication
Biometrics for Payment AuthenticationBiometrics for Payment Authentication
Biometrics for Payment AuthenticationFIDO Alliance
 
How we do monotize SaaS as a VAS in India?
How we do monotize SaaS as a VAS in India?   How we do monotize SaaS as a VAS in India?
How we do monotize SaaS as a VAS in India? Ranjit Kumar
 
Managing & Securing the Online and Mobile banking - Chew Chee Seng
Managing & Securing the Online and Mobile banking - Chew Chee SengManaging & Securing the Online and Mobile banking - Chew Chee Seng
Managing & Securing the Online and Mobile banking - Chew Chee SengKnowledge Group
 
CIS 2015-Putting Control Back in the Users’ Hands- David Pollington
CIS 2015-Putting Control Back in the Users’ Hands- David PollingtonCIS 2015-Putting Control Back in the Users’ Hands- David Pollington
CIS 2015-Putting Control Back in the Users’ Hands- David PollingtonCloudIDSummit
 
Introduction to Aradiom's Key Products
Introduction to Aradiom's Key ProductsIntroduction to Aradiom's Key Products
Introduction to Aradiom's Key ProductsRegAradiom
 
Cidway Securing POS Transactions
Cidway Securing POS TransactionsCidway Securing POS Transactions
Cidway Securing POS Transactionslfilliat
 
Optimising mobile signature v4
Optimising mobile signature v4Optimising mobile signature v4
Optimising mobile signature v4moldovaictsummit
 
m-commerce Applications
m-commerce Applicationsm-commerce Applications
m-commerce ApplicationsHimanshu Arya
 

Semelhante a FIDO Authentication and GSMA Mobile Connect (20)

Banking and Mobile Identity
Banking and Mobile IdentityBanking and Mobile Identity
Banking and Mobile Identity
 
[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy
[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy
[WSO2Con EU 2017] Keynote: Mobile Identity in the Digital Economy
 
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...
GSMA - How To Combine Cross-border eID Recognition With Convenience For Users...
 
case-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_encase-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_en
 
Mobile Connect and the FIDO standards
Mobile Connect and the FIDO standardsMobile Connect and the FIDO standards
Mobile Connect and the FIDO standards
 
FIDO and Mobile Connect
FIDO and Mobile ConnectFIDO and Mobile Connect
FIDO and Mobile Connect
 
Introduction to Mobile Connect
Introduction to Mobile ConnectIntroduction to Mobile Connect
Introduction to Mobile Connect
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor Authentication
 
otp-sms-two-factor-authentication
otp-sms-two-factor-authenticationotp-sms-two-factor-authentication
otp-sms-two-factor-authentication
 
Mobile Connections – FIDO Alliance and GSMA Presentation
Mobile Connections – FIDO Alliance and GSMA PresentationMobile Connections – FIDO Alliance and GSMA Presentation
Mobile Connections – FIDO Alliance and GSMA Presentation
 
7.2 gsm-association-fraud-forum
7.2 gsm-association-fraud-forum7.2 gsm-association-fraud-forum
7.2 gsm-association-fraud-forum
 
Biometrics for Payment Authentication
Biometrics for Payment AuthenticationBiometrics for Payment Authentication
Biometrics for Payment Authentication
 
How we do monotize SaaS as a VAS in India?
How we do monotize SaaS as a VAS in India?   How we do monotize SaaS as a VAS in India?
How we do monotize SaaS as a VAS in India?
 
Managing & Securing the Online and Mobile banking - Chew Chee Seng
Managing & Securing the Online and Mobile banking - Chew Chee SengManaging & Securing the Online and Mobile banking - Chew Chee Seng
Managing & Securing the Online and Mobile banking - Chew Chee Seng
 
CIS 2015-Putting Control Back in the Users’ Hands- David Pollington
CIS 2015-Putting Control Back in the Users’ Hands- David PollingtonCIS 2015-Putting Control Back in the Users’ Hands- David Pollington
CIS 2015-Putting Control Back in the Users’ Hands- David Pollington
 
Introduction to Aradiom's Key Products
Introduction to Aradiom's Key ProductsIntroduction to Aradiom's Key Products
Introduction to Aradiom's Key Products
 
Cidway Securing POS Transactions
Cidway Securing POS TransactionsCidway Securing POS Transactions
Cidway Securing POS Transactions
 
Optimising mobile signature v4
Optimising mobile signature v4Optimising mobile signature v4
Optimising mobile signature v4
 
m-commerce
m-commercem-commerce
m-commerce
 
m-commerce Applications
m-commerce Applicationsm-commerce Applications
m-commerce Applications
 

Mais de FIDO Alliance

FIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance
 
IBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxIBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxFIDO Alliance
 
OTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxOTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxFIDO Alliance
 
FIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptxFIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptxFIDO Alliance
 
CISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxCISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxFIDO Alliance
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Alliance
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)FIDO Alliance
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance
 
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comFIDO Alliance
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向FIDO Alliance
 
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想FIDO Alliance
 
Introduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesIntroduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesFIDO Alliance
 
富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案FIDO Alliance
 
テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察FIDO Alliance
 
「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへFIDO Alliance
 
YubiOnが目指す未来
YubiOnが目指す未来YubiOnが目指す未来
YubiOnが目指す未来FIDO Alliance
 
FIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO Alliance
 
中小企業によるFIDO導入事例
中小企業によるFIDO導入事例中小企業によるFIDO導入事例
中小企業によるFIDO導入事例FIDO Alliance
 
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスVPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスFIDO Alliance
 
CloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークCloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークFIDO Alliance
 

Mais de FIDO Alliance (20)

FIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptx
 
IBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxIBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptx
 
OTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxOTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptx
 
FIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptxFIDO Workshop-Demo Breakdown.pptx
FIDO Workshop-Demo Breakdown.pptx
 
CISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxCISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptx
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for All
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDO
 
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向
 
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
 
Introduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesIntroduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS Services
 
富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案
 
テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察
 
「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ
 
YubiOnが目指す未来
YubiOnが目指す未来YubiOnが目指す未来
YubiOnが目指す未来
 
FIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみた
 
中小企業によるFIDO導入事例
中小企業によるFIDO導入事例中小企業によるFIDO導入事例
中小企業によるFIDO導入事例
 
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスVPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
 
CloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークCloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワーク
 

Último

Android Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesAndroid Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesChandrakantDivate1
 
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...nishasame66
 
Mobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsMobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsChandrakantDivate1
 
Mobile App Penetration Testing Bsides312
Mobile App Penetration Testing Bsides312Mobile App Penetration Testing Bsides312
Mobile App Penetration Testing Bsides312wphillips114
 
Mobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsMobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsChandrakantDivate1
 

Último (6)

Android Application Components with Implementation & Examples
Android Application Components with Implementation & ExamplesAndroid Application Components with Implementation & Examples
Android Application Components with Implementation & Examples
 
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
Obat Penggugur Kandungan Di Apotik Kimia Farma (087776558899)
 
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...
Satara Call girl escort *74796//13122* Call me punam call girls 24*7hour avai...
 
Mobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s ToolsMobile Application Development-Android and It’s Tools
Mobile Application Development-Android and It’s Tools
 
Mobile App Penetration Testing Bsides312
Mobile App Penetration Testing Bsides312Mobile App Penetration Testing Bsides312
Mobile App Penetration Testing Bsides312
 
Mobile Application Development-Components and Layouts
Mobile Application Development-Components and LayoutsMobile Application Development-Components and Layouts
Mobile Application Development-Components and Layouts
 

FIDO Authentication and GSMA Mobile Connect

  • 1. FIDO and Mobile Connect FIDO Seminar, Barcelona May 8th 2017
  • 2. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. About the GSMA The GSMA represents the interests of mobile operators worldwide Spanning more than 220 countries, the GSMA unites nearly 800 of the world’s mobile operators, as well as more than 230 companies in the broader mobile ecosystem Identity – Mobile Connect2
  • 3. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.3 Introducing Mobile Connect, a mobile operator facilitated digital identity solution • Simple, secure and convenient access to online services • Enables users to: • Authenticate online • Authorise digital transactions • Verify their identity • …via their mobile device, anywhere Convenient via the device in your pocket Secure using regulated networks Private no data shared without consent Identity – Mobile Connect
  • 4. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.4 Example use case: reducing user friction by minimising steps to fulfil online commerce transaction Select items; click thru to checkout Form filling Registration complete Select payment type Authorise transaction Username/ password Without Mobile Connect With Mobile Connect Select Select items; click thru to checkout to checkout Authenticate -> authorise payment -> agree to share name/address with merchant via a single action Identity – Mobile Connect
  • 5. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Mobile Connect offers a range of services for digital transactions Helping users manage their identity across their digital footprint Authentication AttributesIdentityAuthorisation Simple and globally ubiquitous log-in Insights about the user, device or transaction Assertion of user identity User authorisation of SP requests Identity – Mobile Connect5
  • 6. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Mobile Connect and FIDO both seeking to replace passwords via use of the mobile phone for authentication 6 Something I Know Something I Have Something I Have + Something I Know Something I Have + Something I Am Or Identity – Mobile Connect
  • 7. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Mobile Connect leverages FIDO to expand its set of Authenticators 7 Federation Authentication User Management Physical-to-digital identity Existing MNO KYC processes Device-based authenticators Existing MNO CRM databases Network-based authenticators (USSD, SIM applet etc.) Identity – Mobile Connect
  • 8. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. FIDO integrates into Mobile Connect as an optional authenticator subsystem 8 FIDO UAF protocol Mobilephone with FIDO client AuthN server MNO Tablet/desktop Service access request Service Provider Authentication request Identity GW First mile Second mileSIM applet protocol (CPAS8) AuthN server SIM applet Identity – Mobile Connect
  • 9. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.9 52 operators launched in 29 markets 3bn …enabled users world-wide 82m …Mobile Connect users… 17m …monthly active users Correct as at April 2017 Cambodia Italy Bangladesh Sri Lanka Pakistan India China Indonesia South Korea Australia Thailand Myanmar Egypt Turkey Spain Argentina Peru Mexico Canada Finland France Malaysia Brazil Switzerland Jordan Poland Uruguay Colombia Ecuador Morocco UK Identity – Mobile Connect
  • 10. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. • Mobile Connect and FIDO are complementary providing a robust and extensible authentication framework providing a federated digital identity framework leveraging FIDO to deliver a range of services for facilitating secure digital transactions • Both in combination help users transact more safely and conveniently online Identity – Mobile Connect10 Take aways
  • 11. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Mobile Connect API documentation & sandbox: https://developer.mobileconnect.io 11 Identity – Mobile Connect
  • 12. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. NSTIC (National Strategy for Trusted Identities in Cyberspace) pilot to enable a common approach to enable consumers and businesses to use mobile devices for secure, privacy-enhancing identity and access management. By allowing relying parties (RPs) to more easily accept identity solutions from Mobile Network Operators, the solution is intended to reduce a significant barrier to online service providers accepting mobile-based credentials. Identity – Mobile Connect12 Enabling Mobile-based Identity and Access Management Technologies
  • 13. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Overall Pilot Strategy – 3 Phased Approach • Financial sector use case with VISAto demonstrate step up authentication at point of sale. • Consumer goods use case with InterBev to demonstrate age verification on age-restricted websites. • Healthcare use case with San Diego Health Connect to enable patient and doctor services through a Health Information Exchange (HIE). • eGovernment use case with the IRS to demonstrate the ability for citizens and non-citizens to file taxes within the US and outside the US. Personal Data – Mobile Connect13 Establish the Foundation Governance (US MNOs, GSMA, Technology Partners) Technical Infrastructure and Authenticators Proof of Concept Financial Sector (Visa) Consumer Goods (InterBev) Healthcare (SDHC) eGovernment (IRS) Commercial Exploration (Trust Framework) Legal Privacy Contracts Business model
  • 14. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. • GSMA Mobile Connect architecture with multiple models for Mobile Connect Accelerator (MCX) implementation and three Authenticator options. • Implementation leveraging a Hub integrated with the different vendors per Authenticator option and MNOs. Identity – Mobile Connect14 Pilot Architecture
  • 15. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.Identity – Mobile Connect15 Pilot Partners
  • 16. Copyright © 2017 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA. Visa – Step-up Authentication to reduce fraud. • Demo: https://youtu.be/m8CID7VPr1I InterBev – Age-verification when purchasing age-restricted products from vending machine with mobile device. • Demo: https://vimeo.com/204070861 Over 700 people experienced the demo. Smartphone Application Authenticator with FIDO functionality were used as well as SIM Application Authenticator. • SIM Application Authenticator enables a very streamlined UX and high security. • Smartphone demonstrated the ability to partner with a third-party technology partner. Identity – Mobile Connect16 Mobile World Congress 2017
  • 17. If you would like more information, please contact the GSMA via: mobileconnect@gsma.com +44 (0) 20 7356 0600 www.gsma.com/identity Follow the GSMA on Twitter: @GSMA GSMA London Office The Walbrook Building, 25 Walbrook, London EC4N 8AF Copyright © 2018 GSMA. The Mobile Connect logo is a trade mark registered and owned by the GSMA.