How to authenticate mobile devices in a web environment - the SIM-ID approach.

Florian Feldmann, Jörg Schwenk · 2013

Abstract: With the advent of the iPhone AppStore and Google Play, the ’walled gar-den ’ approach of telecommunication companies to supply content to their customers using standard GSM/UMTS/LTE authentication has failed: Neither Google nor Apple, nor any other content provider on the mobile internet, uses the SIM card for authen-tication. This is mainly due to the fact that mobile telecommunication and internet architectures differ substantially. In this paper, we propose several bridging technologies to fill this gap. We exem-plarily show how to use SIM authentication for web-based Single-Sign-On protocols. Starting from simple password replacement in the authentication between User Agent (UA) and Identity Provider (IdP), we show how we can achieve strong channel bind-ings between all TLS channels and SIM based authentication. 1

Read the paper · More papers on PaperTik