Research Article

Protecting Mobile Service User Identity by Adding Additional Security Layer

Number: 23 April 30, 2021
TR EN

Protecting Mobile Service User Identity by Adding Additional Security Layer

Abstract

Today, various common identity systems (eg Facebook Login, Google Connect, Apple ID) are used to improvee operational efficiency for service providers and provide an easier authentication method in web or mobile services for users. Almost all common identity systems focus on delivering seamless user experience while proving user identity securely to the service provider. In particular, the use of common identity systems with a high security level is becoming a more important requirement on smartphones. In this context, MNOs (Mobile Network Operators) are considered as an important actor in providing common identity services, as they have strong GSM capabilities. Currently, it is possible to see many identity management solutions -based on OpenID Connect and Mobile Connect standards- from MNOs which are used for authentication in mobile applications of service providers. However, recent solutions generally provide low level of assurance (i.e., LoA2 or LoA3). With advancements in value-added mobile services and increasing security requirements; there is a need for common identity systems that provide higher levels of assurance (i.e., LoA4), strong authentication and non-repudiation services for service providers and users. This study presents the development and implementation of a multi-factor authentication method for mobile services based on Mobile Connect and OpenID Connect standards. The designed model includes the usage of three identity -knowledge, ownership, biometric- factors of the user in order to access sensitive mobile services on the smartphone. The system development and testing studies were systematically presented based on the functional requirements. The realization and deployment of the proposed model by MNOs could play an important role in the development of mobile services that require a high level of assurance in the future.

Keywords

Supporting Institution

Turkcell Technology A.S. and TUBITAK (The Scientific and Technological Research Council of Turkey)

Project Number

1505-5190045

Thanks

This work is funded by Turkcell Technology A.S. and TUBITAK (The Scientific and Technological Research Council of Turkey) under 1505 Program, Project no 5190045.

References

  1. Apple Sign-In (2020). https://developer.apple.com/sign-in-with-apple/
  2. Facebook Login (2020). https://developers.facebook.com/docs/facebook-login/
  3. Turkcell (2020). Fast Login. https://hizligiris.turkcell.com.tr/en/fast-login/what-is-fast-login
  4. Google Sign-In (2020). https://developers.google.com/identity
  5. GSMA (2020). Mobile Connect, https://www.gsma.com/identity/mobile-connect.
  6. Harini, N., & Padmanabhan, T. R. (2013). 2CAuth: A new two factor authentication scheme using QR-code. International Journal of Engineering and Technology, 5(2), 1087-1094.
  7. ISO/IEC 29115 (2013). Information technology-Security techniques-Entity authentication assurance framework.
  8. Ozdenizci Kose, B., Buk, O., Mantar, H. A., & Coskun, V. (2020, October). TrustedID: An Identity Management System based on OpenID Connect Protocol. In 2020 4th International Symposium on Multidisciplinary Studies and Innovative Technologies (ISMSIT) (pp. 1-6). IEEE.

Details

Primary Language

English

Subjects

Engineering

Journal Section

Research Article

Publication Date

April 30, 2021

Submission Date

November 30, 2020

Acceptance Date

February 26, 2021

Published in Issue

Year 2021 Number: 23

APA
Özdenizci Köse, B., Bük, O., Mantar, H. A., Coskun, V., & Erdemir, U. (2021). Protecting Mobile Service User Identity by Adding Additional Security Layer. Avrupa Bilim Ve Teknoloji Dergisi, 23, 22-30. https://doi.org/10.31590/ejosat.833433

Cited By