SlideShare a Scribd company logo
MODRNA WG
The interface of MODRNA (Mobile Profile of OpenID Connect) and GSMA Mobile
Connect
May 15, 2018
Bjorn Hjelm
Verizon
John Bradley
Yubico
http://openid.net/wg/mobile/
Purpose
• Support GSMA technical development of
Mobile Connect
• Enable Mobile Network Operators (MNOs) to
become Identity Providers
• Developing (1) a profile of and (2) an
extension to OpenID Connect for use by MNOs
providing identity services.
Participants
What is Mobile Connect?
• Mobile phone number as user identifier
• Mobile phone as authenticator
• MNO as authentication/identity provider
• Replace passwords and hardware security
tokens
Example Use Case
Towards Mobile Connect
Services Enabler Model
• The aim of the Service Enabler model
is to enhance the modularity of the
Mobile Connect framework by
defining it as a set of Service Enablers
that can be used (and re-used) for
supporting Global Products as well as
Local Products devised by MNOs to
meet their local market needs.
– In R2, each Product was defined and
specified individually.
– In R3. with the Service Enabler model,
each of these Products can be
implemented using a common service
enabler.
Mobile Connect
Reference Architecture
2. The service provider requests the
authenticating operator from the API
Exchange.
3. The service provider makes a
request for authentication.
4. The operator selects the appropriate
authenticator depending on the request for
assurance and capabilities
1. The user clicks on a Mobile
Connect button to access a
service.
• SIM Applet
• USSD
• SMS
• Smartphone App
• FIDO
MNO
Service access request
Authentication
Service Provider
Authentication
request
Authentication
server
Identity
Gateway
MNO Discovery
MODRNA WG
2. The service provider requests the
authenticating operator from the API
Exchange.
3. The service provider makes a
request for authentication.
4. The operator selects the appropriate
authenticator depending on the request for
assurance and capabilities
1. The user clicks on a Mobile
Connect button to access a
service.
• SIM Applet
• USSD
• SMS
• Smartphone App
• FIDO
MNO
Service access request
Authentication
Service Provider
Authentication
request
Authentication
server
Identity
Gateway
MNO Discovery
1
2 3
Set up
credentials
MODRNA Specifications
• Discovery
– http://openid.net/specs/openid-connect-modrna-authentication-1_0.html
– Dedicated discovery service
– Account Chooser integration
• Client Registration
– http://openid.net/wordpress-content/uploads/2014/04/draft-mobile-registration-01.html
– OIDC Dynamic Client Registration with software statements (RFC 7591)
– Mandatory claims in the statements
– Signature algorithms
– Lifecycle management, e.g. revocation of statements/blocking of RPs
• Authentication
– http://openid.net/wordpress-content/uploads/2014/04/draft-mobile-discovery-01.html
– ACR values
– Additional parameters
Auxiliary MODRNA Work
• Client Initiated Backchannel Authentication
– http://openid.net/specs/openid-connect-modrna-client-initiated-backchannel-authentication-
1_0.html
– Mechanism to perform authentication (out-of-band) when there is no user agent available and
the authentication process needs to initiated via server-to-server communication
• User Questioning API
– http://openid.net/specs/openid-connect-user-questioning-api-1_0.html
– Mechanism to perform transaction authorizations. Define additional OpenID Connect
endpoint (Resource Server) that RP would use (server-to-server) to initiate transaction
authorization processes
• Account Porting
– http://openid.net/specs/openid-connect-account-porting-1_0.html
– Mechanism to allow the migration of user account from old to new OP
– Protocol allowing new OP to obtain the necessary user data from the old OP and provide every
RP with the necessary data to migrate the RP's local user account data in a secure way
MODRNA WG Status
• Active progress to close all open issues for the four specifications
approved as Implementer’s Draft (May 2017).
– MODRNA Authentication Profile
– Account Porting
– User Questioning API
– Client Initiated Backchannel Authentication (CIBA)
• Collaboration with Financial API (FAPI) WG on use cases, Mobile Connect,
Backchannel Authentication, and Dynamic Client Registration.
• Still planning on collaboration with International Government Assurance
(iGov) WG on Attribute Exchange using NIST IR 8112 Attribute Metadata as
guideline.
MODRNA - GSMA CPAS
Status
• Mobile Connect enhanced to support back-channel authentication based on
MODRNA WG work on CIBA specification.
– Mobile Connect already adopted OpenID Connect Account Porting specification and aligning
with MODRNA Authentication Profile.
• User Questioning API being adopted by Mobile Connect based on product
definition proposed by Orange.
• Active work on aligning priorities and roadmap between both organizations and
following the Governance Process for how Mobile Connect will reference and
adopt MODRNA specifications.
– Process outlines how Mobile Connect specifications handle Implementer’s Draft and
Published specifications.
– Next joint MODRNA – GSMA CPAS technical workshop possibly 2H 2018 based on Mobile
Connect roadmap.
• GSMA interested in adopting output from FAPI WG to support financial sector.
Thank you
http://openid.net/wg/mobile/

More Related Content

PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
PPTX
OpenID Foundation FastFed Working Group Update - 2017-10-16
PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
PDF
OpenID Certification Program Update - 2018-04-02
PDF
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
PPTX
OpenID Foundation MODRNA WG Update
PDF
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Certification Program U...
OpenID Foundation Workshop at EIC 2018 - OpenID Connect Working Group Update
OpenID Foundation FastFed Working Group Update - 2017-10-16
OpenID Foundation Workshop at EIC 2018 - OpenID Certification Update
OpenID Certification Program Update - 2018-04-02
OIDF Workshop at European Identity Conference 2019 -- 5/14/2019 -- OpenID Cer...
OpenID Foundation MODRNA WG Update
OpenID Foundation Workshop at EIC 2018 - OpenID Enhanced Authentication Profi...

What's hot (20)

PDF
OIDF Workshop 4/29/2019 -- OpenID Certification Update
PPTX
OpenID Foundation iGov Working Group Update - October 22, 2018
PDF
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
PDF
OpenID Foundation RISC WG Update - 2017-10-16
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
PDF
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
PDF
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
PPTX
MODRNA WG Update - April 2021
PDF
Strong Customer Authentication - All Your Questions Answered
PPTX
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
PDF
CIS 2015 Easy Federation in Cloud and on Premises - Ian Jaffe
PDF
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
PDF
Enterprise Security Requirements
PPTX
WEB API Gateway
PDF
OBIE Directory Integration - A Technical Deep Dive
PDF
Gateway deepdive
PDF
FIDO Certification Program Updates
OIDF Workshop 4/29/2019 -- OpenID Certification Update
OpenID Foundation iGov Working Group Update - October 22, 2018
OpenID Foundation Workshop at EIC 2018 - Mobile Driver's License Presentantion
OIDF Workshop at Verizon Media -- 9/30/2019 -- Continuous Access Evaluation P...
OIDF Workshop at Verizon Media -- 9/30/2019 -- FastFed Working Group Update
OpenID Foundation RISC WG Update - 2017-10-16
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Federation Update
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect for Identity As...
OIDF Workshop at Verizon Media -- 9/30/2019 -- Browser Changes Impacting Iden...
OpenID Foundation/Open Banking Workshop - OpenID Foundation Overview
MODRNA WG Update - April 2021
Strong Customer Authentication - All Your Questions Answered
OpenID Connect - a simple[sic] single sign-on & identity layer on top of OAut...
CIS 2015 Easy Federation in Cloud and on Premises - Ian Jaffe
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
Enterprise Security Requirements
WEB API Gateway
OBIE Directory Integration - A Technical Deep Dive
Gateway deepdive
FIDO Certification Program Updates
Ad

Similar to OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update (20)

PPTX
An Overview of the interface of MODRNA and GSMA Mobile Connect
PPTX
OpenID Foundation Workshop at EIC2017
PPTX
OpenID Foundation MODRNA WG
PPTX
OpenID Foundation MODRNA WG Update
PPTX
OpenID Foundation MODRNA WG
PPTX
OpenID Foundation MODRNA WG Overview (Apr. 2019)
PPTX
OpenID Connect: The Mobile Profile
PPTX
OpenID Foundation MODRNA WG Overview
PPTX
Overview of the OpenID Foundation's Mobile Profile of OpenID Connect MODRNA WG
PPTX
OpenID Foundation MODRNA WG overview at EIC 2019
PPTX
MODRNA WG Overview - October 2020
PPTX
MODRNA WG update - OpenID Foundation Workshop at EIC 2022
PPTX
OpenID Foundation MODRNA WG Update
PPTX
MODRNA WG update - OpenID Foundation Workshop at EIC 2021
PPTX
MODRNA WG Update - Dec 2021
PPTX
MODRNA WG Update - Nov 2022
PPTX
MODRNA WG Update - Apr. 2022
PPTX
MODRNA WG Update - Apr 2023
PPTX
Mobile Network Operators and Identity – Crossing the Chasm
PPTX
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
An Overview of the interface of MODRNA and GSMA Mobile Connect
OpenID Foundation Workshop at EIC2017
OpenID Foundation MODRNA WG
OpenID Foundation MODRNA WG Update
OpenID Foundation MODRNA WG
OpenID Foundation MODRNA WG Overview (Apr. 2019)
OpenID Connect: The Mobile Profile
OpenID Foundation MODRNA WG Overview
Overview of the OpenID Foundation's Mobile Profile of OpenID Connect MODRNA WG
OpenID Foundation MODRNA WG overview at EIC 2019
MODRNA WG Overview - October 2020
MODRNA WG update - OpenID Foundation Workshop at EIC 2022
OpenID Foundation MODRNA WG Update
MODRNA WG update - OpenID Foundation Workshop at EIC 2021
MODRNA WG Update - Dec 2021
MODRNA WG Update - Nov 2022
MODRNA WG Update - Apr. 2022
MODRNA WG Update - Apr 2023
Mobile Network Operators and Identity – Crossing the Chasm
OIDF Workshop at Verizon Media -- 9/30/2019 -- OpenID Connect Working Group U...
Ad

More from MikeLeszcz (8)

PDF
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
PDF
OpenID Foundation Workshop at EIC 2018 - HEART Working Group Update
PDF
CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018
PDF
OpenID Foundation RISC WG Update - 2018-04-02
PDF
OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...
PDF
OpenID Foundation/Open Banking Workshop - Open Banking Update
PDF
OpenID Certification Program Update - 2017-10-16
PDF
Banking is Now More Open: Open Banking Update
OpenID Foundation Workshop at EIC 2018 - Introduction to the FAPI Read & Writ...
OpenID Foundation Workshop at EIC 2018 - HEART Working Group Update
CIBA Profile Overview - OpenID Foundation/Open Banking Workshop - March 21, 2018
OpenID Foundation RISC WG Update - 2018-04-02
OpenID Foundation's Risk Incident and Sharing Communication (RISC) Work Group...
OpenID Foundation/Open Banking Workshop - Open Banking Update
OpenID Certification Program Update - 2017-10-16
Banking is Now More Open: Open Banking Update

Recently uploaded (20)

PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Programs and apps: productivity, graphics, security and other tools
PDF
cuic standard and advanced reporting.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PPT
“AI and Expert System Decision Support & Business Intelligence Systems”
PPTX
Machine Learning_overview_presentation.pptx
PPT
Teaching material agriculture food technology
PDF
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PDF
Empathic Computing: Creating Shared Understanding
PDF
Per capita expenditure prediction using model stacking based on satellite ima...
PDF
Machine learning based COVID-19 study performance prediction
PDF
Getting Started with Data Integration: FME Form 101
PPTX
MYSQL Presentation for SQL database connectivity
PDF
Encapsulation theory and applications.pdf
PDF
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
Advanced methodologies resolving dimensionality complications for autism neur...
Programs and apps: productivity, graphics, security and other tools
cuic standard and advanced reporting.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
“AI and Expert System Decision Support & Business Intelligence Systems”
Machine Learning_overview_presentation.pptx
Teaching material agriculture food technology
Build a system with the filesystem maintained by OSTree @ COSCUP 2025
Group 1 Presentation -Planning and Decision Making .pptx
A comparative analysis of optical character recognition models for extracting...
MIND Revenue Release Quarter 2 2025 Press Release
Empathic Computing: Creating Shared Understanding
Per capita expenditure prediction using model stacking based on satellite ima...
Machine learning based COVID-19 study performance prediction
Getting Started with Data Integration: FME Form 101
MYSQL Presentation for SQL database connectivity
Encapsulation theory and applications.pdf
Blue Purple Modern Animated Computer Science Presentation.pdf.pdf
Digital-Transformation-Roadmap-for-Companies.pptx
Agricultural_Statistics_at_a_Glance_2022_0.pdf

OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update

  • 1. MODRNA WG The interface of MODRNA (Mobile Profile of OpenID Connect) and GSMA Mobile Connect May 15, 2018 Bjorn Hjelm Verizon John Bradley Yubico http://openid.net/wg/mobile/
  • 2. Purpose • Support GSMA technical development of Mobile Connect • Enable Mobile Network Operators (MNOs) to become Identity Providers • Developing (1) a profile of and (2) an extension to OpenID Connect for use by MNOs providing identity services.
  • 4. What is Mobile Connect? • Mobile phone number as user identifier • Mobile phone as authenticator • MNO as authentication/identity provider • Replace passwords and hardware security tokens
  • 6. Towards Mobile Connect Services Enabler Model • The aim of the Service Enabler model is to enhance the modularity of the Mobile Connect framework by defining it as a set of Service Enablers that can be used (and re-used) for supporting Global Products as well as Local Products devised by MNOs to meet their local market needs. – In R2, each Product was defined and specified individually. – In R3. with the Service Enabler model, each of these Products can be implemented using a common service enabler.
  • 7. Mobile Connect Reference Architecture 2. The service provider requests the authenticating operator from the API Exchange. 3. The service provider makes a request for authentication. 4. The operator selects the appropriate authenticator depending on the request for assurance and capabilities 1. The user clicks on a Mobile Connect button to access a service. • SIM Applet • USSD • SMS • Smartphone App • FIDO MNO Service access request Authentication Service Provider Authentication request Authentication server Identity Gateway MNO Discovery
  • 8. MODRNA WG 2. The service provider requests the authenticating operator from the API Exchange. 3. The service provider makes a request for authentication. 4. The operator selects the appropriate authenticator depending on the request for assurance and capabilities 1. The user clicks on a Mobile Connect button to access a service. • SIM Applet • USSD • SMS • Smartphone App • FIDO MNO Service access request Authentication Service Provider Authentication request Authentication server Identity Gateway MNO Discovery 1 2 3 Set up credentials
  • 9. MODRNA Specifications • Discovery – http://openid.net/specs/openid-connect-modrna-authentication-1_0.html – Dedicated discovery service – Account Chooser integration • Client Registration – http://openid.net/wordpress-content/uploads/2014/04/draft-mobile-registration-01.html – OIDC Dynamic Client Registration with software statements (RFC 7591) – Mandatory claims in the statements – Signature algorithms – Lifecycle management, e.g. revocation of statements/blocking of RPs • Authentication – http://openid.net/wordpress-content/uploads/2014/04/draft-mobile-discovery-01.html – ACR values – Additional parameters
  • 10. Auxiliary MODRNA Work • Client Initiated Backchannel Authentication – http://openid.net/specs/openid-connect-modrna-client-initiated-backchannel-authentication- 1_0.html – Mechanism to perform authentication (out-of-band) when there is no user agent available and the authentication process needs to initiated via server-to-server communication • User Questioning API – http://openid.net/specs/openid-connect-user-questioning-api-1_0.html – Mechanism to perform transaction authorizations. Define additional OpenID Connect endpoint (Resource Server) that RP would use (server-to-server) to initiate transaction authorization processes • Account Porting – http://openid.net/specs/openid-connect-account-porting-1_0.html – Mechanism to allow the migration of user account from old to new OP – Protocol allowing new OP to obtain the necessary user data from the old OP and provide every RP with the necessary data to migrate the RP's local user account data in a secure way
  • 11. MODRNA WG Status • Active progress to close all open issues for the four specifications approved as Implementer’s Draft (May 2017). – MODRNA Authentication Profile – Account Porting – User Questioning API – Client Initiated Backchannel Authentication (CIBA) • Collaboration with Financial API (FAPI) WG on use cases, Mobile Connect, Backchannel Authentication, and Dynamic Client Registration. • Still planning on collaboration with International Government Assurance (iGov) WG on Attribute Exchange using NIST IR 8112 Attribute Metadata as guideline.
  • 12. MODRNA - GSMA CPAS Status • Mobile Connect enhanced to support back-channel authentication based on MODRNA WG work on CIBA specification. – Mobile Connect already adopted OpenID Connect Account Porting specification and aligning with MODRNA Authentication Profile. • User Questioning API being adopted by Mobile Connect based on product definition proposed by Orange. • Active work on aligning priorities and roadmap between both organizations and following the Governance Process for how Mobile Connect will reference and adopt MODRNA specifications. – Process outlines how Mobile Connect specifications handle Implementer’s Draft and Published specifications. – Next joint MODRNA – GSMA CPAS technical workshop possibly 2H 2018 based on Mobile Connect roadmap. • GSMA interested in adopting output from FAPI WG to support financial sector.