Skip to main content

Strong Authentication for Web Services with Mobile Universal Identity

  • Conference paper
  • First Online:
Book cover Mobile Web and Intelligent Information Systems (MobiWIS 2015)

Part of the book series: Lecture Notes in Computer Science ((LNISA,volume 9228))

Included in the following conference series:

Abstract

To access services on the Web, users need quite often to have accounts, i.e. user names and passwords. This becomes a problem when the number of accounts keeps increasing at the same time password is a very weak form of authentication exposing the users to fraud and abuses. To address both mentioned issues we propose a Mobile Universal identity, which by combining Internet identifiers with mobile identifiers is capable of delivering strong authentication for Internet services. By introducing an identity provider, the solution enables the user to employ the Mobile Universal identity for multiple service providers. By federation with other identities, Mobile Universal identity can be used with service providers worldwide.

This is a preview of subscription content, log in via an institution to check access.

Access this chapter

Chapter
USD 29.95
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
eBook
USD 39.99
Price excludes VAT (USA)
  • Available as PDF
  • Read on any device
  • Instant download
  • Own it forever
Softcover Book
USD 54.99
Price excludes VAT (USA)
  • Compact, lightweight edition
  • Dispatched in 3 to 5 business days
  • Free shipping worldwide - see info

Tax calculation will be finalised at checkout

Purchases are for personal use only

Institutional subscriptions

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

References

  1. 3rd Generation Partnership Project: 3GPP TS 33.220 V8.2.0 (2007-12) Technical Specification Group Services and System Aspects; Generic Authentication Architecture (GAA) Generic bootstrapping architecture (Release 8)

    Google Scholar 

  2. Van Thanh, D., Jønvik, T., Van Thuan, D., Jørstad, I.: Enhancing internet service security using GSM SIM authentication. In: Proceedings of the IEEE Globecom 2006 Conference, San Francisco, USA, November 27, December 1, 2006. ISBN 1-4244-0357-X

    Google Scholar 

  3. Van Thanh, D., Jønvik, T., Feng, B., Van Thuan, D., Jørstad, I.: Simple strong authentication for internet applications using mobile phones. In: Proceedings of IEEE Global Communications Conference (IEEE GLOBECOM 2008), New Orleans, LA, USA, November 30, December 4, 2008. ISBN 978-1-4244-2324-8

    Google Scholar 

  4. Facebook Inc.: Facebook login. https://developers.facebook.com/docs/facebook-login/

  5. Google: Google account. https://developers.google.com/+/features/sign-in

  6. Twitter. https://twitter.com/

  7. EMC2. http://www.emc.com/security/rsa-securid/rsa-securid-software-authenticators.htm

  8. 3rd Generation Partnership Project: 3GPP TS 11.11 V6.0.0 (1998-04); Specification of the Subscriber Identity Module - Mobile Equipment (SIM-ME) Interface (Release 97)

    Google Scholar 

  9. NIST: National Institute of Standards and Technology. Special Publication 800-63 Version 1.0.2 Electronic Authentication Guideline, April 2006

    Google Scholar 

  10. T. Wason, et al., Liberty ID-FF Architecture Overview: Version: 1.2-errata-v1.0. Liberty Alliance Project (2005)

    Google Scholar 

  11. OpenId. http://openid.net/

  12. oAuth. http://oauth.net/

  13. The Internet Engineering Task Force: Network Working Group, Haverinen, H., Salowey, J.: EAP-SIM Authentication. RFC 4186, IETF, January 2006

    Google Scholar 

  14. The Internet Engineering Task Force: Network Working Group. RFC 4187 Extensible Authentication Protocol Method for 3rd Generation Authentication and Key Agreement (EAP-AKA)

    Google Scholar 

  15. ETSI TS 100 974 V7.15.0 (2004-03). Digital cellular telecommunications system (Phase 2+); Mobile Application Part (MAP) specification - (3GPP TS 09.02 version 7.15.0 Release 1998

    Google Scholar 

  16. Open Mobile Alliance (OMA): Wireless Application Protocol Architecture Specification - WAP Architecture Version, April 30, 1998

    Google Scholar 

Download references

Author information

Authors and Affiliations

Authors

Corresponding author

Correspondence to Do van Thanhe .

Editor information

Editors and Affiliations

Rights and permissions

Reprints and permissions

Copyright information

© 2015 Springer International Publishing Switzerland

About this paper

Cite this paper

van Thanhe, D., Jørstad, I., van Thuan, D. (2015). Strong Authentication for Web Services with Mobile Universal Identity. In: Younas, M., Awan, I., Mecella, M. (eds) Mobile Web and Intelligent Information Systems. MobiWIS 2015. Lecture Notes in Computer Science(), vol 9228. Springer, Cham. https://doi.org/10.1007/978-3-319-23144-0_3

Download citation

  • DOI: https://doi.org/10.1007/978-3-319-23144-0_3

  • Published:

  • Publisher Name: Springer, Cham

  • Print ISBN: 978-3-319-23143-3

  • Online ISBN: 978-3-319-23144-0

  • eBook Packages: Computer ScienceComputer Science (R0)

Publish with us

Policies and ethics