The Smartphone as Mobile Authorization Proxy
Luis Roalter, Matthias Kranz, Stefan Diewald, Andreas Möller · 2013
Abstract. We present a novel approach to use a mobile device for authentication and authorization purposes, where the user is able to authenticate and authorize himself for access on a public terminal. The concept is based on an extension of a Single-Sign On solution for mobile and public terminals. 1 Motivation for Intuitive Mobile SSO Internet services have become an integral element in daily activities. Cloud-based services like Google, Facebook or other social community platforms make use of a lot of personalized information of its users. It is essential for the users of these services to protect their data, their data’s integrity and their privacy by protecting the access to the account. As many users are using many different services, they usually have to use different logins for the different services – but, due to comfort reasons, often only have one password and probably only one login (typically the email address). Approaches like OAuth [1], OpenID [2], ‘Facebook Connect ‘ or Shibboleth [3] can reduce the duplicate usernames and thereby duplicate vulnerable passwords. The basic idea is to move the authentication to a trusted IDentity Provider (IDP). The user