SlideShare a Scribd company logo
Mobile Network
Operators and
Identity – Crossing
the Chasm
Bjorn Hjelm
September 22, 2015
“Chasm crossing is
not the end, but rather
the beginning, of
mainstream market
development.”
- Geoffrey A. Moore, Crossing the Chasm: Marketing and Selling Disruptive
Products to Mainstream Customers
2
Leveraging
Open
Standards for
“Mainstream
Market”.
3
“Productivity improvement for existing
operations.”
“Evolution, not revolution.”
“Technology to enhance, not overthrow,
the established ways of doing
business.”
“Do not want to debug somebody else’s
product.“
- Geoffrey A. Moore, Crossing the Chasm: Marketing and
Selling Disruptive Products to Mainstream Customers
“When pragmatists buy,
they care about the
company they are
buying from, the quality
of the product they are
buying, the
infrastructure of
supporting products and
system interfaces, and
the reliability of the
service they are going to
get.”
- Geoffrey A. Moore, Crossing the
Chasm: Marketing and Selling
High-Tech Products to
Mainstream Customers
4
Authentication
and
Authorization
Framework
using Open
Standards
OAuth 2.0 and OpenID
Connect are two
authentication and
authorization standards
that promises to serve as
important tools.
OAuth 2.0
IETF standard for
securing Client
application delegated
access to server
resources on behalf of a
resource owner.
Useful for conveying
authorization decisions
across network of web-
enabled applications and
APIs.
Client authenticated to
the Resource Server (RS)
through the use of an
access token provided by
an Authorization Server
(AS).
OpenID Connect
OpenID Foundation
standard that extends
OAuth 2.0 adding an
identity layer to perform
user authentication.
OpenID Connect 1.0 adds
two identity constructs to the
token issuing model in
OAuth 2.0.
• Identity Token – Enables
a federated SSO user
experience for a user.
• Identity attribute API –
Allowing a Client to
retrieve the desired
identity attributes for the
a given user.
OpenID Foundation MODRNA WG
Developing a profile of
OpenID Connect for use
by Mobile Network
Operators providing
identity services.
Specifications divided into
three parts:
• Discovery
• Dynamic Registration
• Authentication
MODRNA Working Group
provides input to GSMA
on the technical
development of Mobile
Connect.
5
6
Discovery
Profile
Addition to OpenID
Connect Discovery
specification.
Specifies a way to
normalize a user identifier
to derive a resource and
especially a host for
OpenID Provider (OP)
Issuer Discovery.
Dynamic
Registration
Profile
Addition to OpenID
Connect Dynamic
Registration
specification.
Specifies how a Client
dynamically register with
multiple Mobile Network
Operators (MNOs) based
on information asserted by
a trusted entity.
Authentication
Profile
Addition to OpenID
Connect Core
specification.
Specifies the common
authentication contexts to
be used.
Discovery with
Account
Chooser.
7
Using Account Chooser to bypass
discovery to improve user experience.
Account Chooser is a OpenID Foundation
specification to help with the login process
to a website by leveraging an account
cashed.
Proposed enhancement to Account
Chooser specification to work with
MODRNA Discovery flow by allowing login
identifiers strings that are keyed on phone
numbers.
Service Providers will bring up Account
Chooser during login and MNO will
populate Account Chooser after successful
login the MNO calls
References for
more
information
8
OpenID Foundation MODRNA Working
Group
http://openid.net/wg/mobile/
OpenID Foundation Account Chooser
Working Group
http://openid.net/wg/ac/
Account Chooser
http://accountchooser.net/

More Related Content

PDF
What’s new in WSO2 Open Banking
WSO2
 
PDF
apidays LIVE Singapore - Engineering Open Banking with Singpass for Financial...
apidays
 
PDF
apidays LIVE India - The future of financial services is invisible by Bharat ...
apidays
 
PDF
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays
 
PDF
[WSO2 Open Banking & Security Forum Mexico 2019] API-Driven World
WSO2
 
PPTX
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
apidays
 
PDF
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
WSO2
 
PDF
Monage.io identity presentation 3.22.17 v3
Michael Queralt
 
What’s new in WSO2 Open Banking
WSO2
 
apidays LIVE Singapore - Engineering Open Banking with Singpass for Financial...
apidays
 
apidays LIVE India - The future of financial services is invisible by Bharat ...
apidays
 
apidays LIVE Australia 2021 - Empowering the fintech ecosystem with APIs by D...
apidays
 
[WSO2 Open Banking & Security Forum Mexico 2019] API-Driven World
WSO2
 
apidays LIVE Hong Kong 2021 - Digital Identity Centric Approach to Accelerate...
apidays
 
[APIdays INTERFACE 2021] The Evolution of API Security for Client-side Applic...
WSO2
 
Monage.io identity presentation 3.22.17 v3
Michael Queralt
 

What's hot (20)

PPTX
Identity Live London 2017 | Kenneth May
ForgeRock
 
PPTX
Digital authentication
allanh0526
 
PDF
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays
 
PPTX
Rubin Way - Blockchain Disruption in the Supply Chain
Rubin Way Ltd
 
PDF
Using Strong / Verified Identities
Ubisecure
 
PDF
OBIE Directory Integration - A Technical Deep Dive
WSO2
 
PDF
Authentication With Captive Portal
Wavecrest Computing
 
PPTX
Blockit Seed Round Pitch Deck
Jake McCarley
 
PPTX
Identity Live Paris 2017 | Ian Sorbello, HSBC
ForgeRock
 
PDF
Getting your API Management Strategy on Point for PSD2 Compliance
WSO2
 
PDF
Identity Platform Use Cases
Ubisecure
 
PPTX
OAuth and OpenID Connect for PSD2 and Third-Party Access
Nordic APIs
 
PDF
wso2 masterclass italia #13 - Open Healthcare: interoperabilità e sicurezza ...
Profesia Srl, Lynx Group
 
PDF
[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya
WSO2
 
PDF
Banking is Now More Open: Open Banking Update
MikeLeszcz
 
PPTX
Connected Identity : The Role of the Identity Bus
Prabath Siriwardena
 
PDF
[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...
WSO2
 
PPTX
Open Banking - Bringing Regulation and Technology together for Digital Trans...
WSO2
 
PDF
How to Use Actionable Insights to Increase Revenues
Allot Communications
 
PDF
[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...
WSO2
 
Identity Live London 2017 | Kenneth May
ForgeRock
 
Digital authentication
allanh0526
 
apidays LIVE India - Digital Trust Infrastructure - Key to digital transforma...
apidays
 
Rubin Way - Blockchain Disruption in the Supply Chain
Rubin Way Ltd
 
Using Strong / Verified Identities
Ubisecure
 
OBIE Directory Integration - A Technical Deep Dive
WSO2
 
Authentication With Captive Portal
Wavecrest Computing
 
Blockit Seed Round Pitch Deck
Jake McCarley
 
Identity Live Paris 2017 | Ian Sorbello, HSBC
ForgeRock
 
Getting your API Management Strategy on Point for PSD2 Compliance
WSO2
 
Identity Platform Use Cases
Ubisecure
 
OAuth and OpenID Connect for PSD2 and Third-Party Access
Nordic APIs
 
wso2 masterclass italia #13 - Open Healthcare: interoperabilità e sicurezza ...
Profesia Srl, Lynx Group
 
[WSO2 Integration Summit Nairobi 2019] Case Study - Telkom Kenya
WSO2
 
Banking is Now More Open: Open Banking Update
MikeLeszcz
 
Connected Identity : The Role of the Identity Bus
Prabath Siriwardena
 
[APIdays Singapore 2019] API Management in a Istio Service Mesh with WSO2 API...
WSO2
 
Open Banking - Bringing Regulation and Technology together for Digital Trans...
WSO2
 
How to Use Actionable Insights to Increase Revenues
Allot Communications
 
[APIdays Singapore 2019] Managing the API lifecycle with Open Source Technolo...
WSO2
 
Ad

Similar to Mobile Network Operators and Identity – Crossing the Chasm (20)

PPTX
OpenID Connect: The Mobile Profile
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG
Bjorn Hjelm
 
PPTX
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
MikeLeszcz
 
PPTX
OpenID Foundation MODRNA WG overview at EIC 2018
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Overview
Bjorn Hjelm
 
PPTX
Overview of the OpenID Foundation's Mobile Profile of OpenID Connect MODRNA WG
Bjorn Hjelm
 
PPTX
RSA Europe: Future of Cloud Identity
Mike Schwartz
 
PPTX
MODRNA WG Update - Apr. 2022
Bjorn Hjelm
 
PPTX
OpenID Foundation Workshop at EIC2017
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Overview (Apr. 2019)
Bjorn Hjelm
 
PPTX
MODRNA WG Overview - October 2020
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
PPTX
An Overview of the interface of MODRNA and GSMA Mobile Connect
Bjorn Hjelm
 
PPTX
MODRNA WG Update - Nov 2022
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
PDF
OpenID Connect "101" Introduction -- October 23, 2018
OpenIDFoundation
 
PPTX
MODRNA WG Update - April 2021
Bjorn Hjelm
 
OpenID Connect: The Mobile Profile
Bjorn Hjelm
 
OpenID Foundation MODRNA WG
Bjorn Hjelm
 
OpenID Foundation Workshop at EIC 2018 - MODRNA Working Group Update
MikeLeszcz
 
OpenID Foundation MODRNA WG overview at EIC 2018
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
OpenID Foundation MODRNA WG
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Overview
Bjorn Hjelm
 
Overview of the OpenID Foundation's Mobile Profile of OpenID Connect MODRNA WG
Bjorn Hjelm
 
RSA Europe: Future of Cloud Identity
Mike Schwartz
 
MODRNA WG Update - Apr. 2022
Bjorn Hjelm
 
OpenID Foundation Workshop at EIC2017
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Overview (Apr. 2019)
Bjorn Hjelm
 
MODRNA WG Overview - October 2020
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
An Overview of the interface of MODRNA and GSMA Mobile Connect
Bjorn Hjelm
 
MODRNA WG Update - Nov 2022
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
OpenID Foundation MODRNA WG Update
Bjorn Hjelm
 
OpenID Connect "101" Introduction -- October 23, 2018
OpenIDFoundation
 
MODRNA WG Update - April 2021
Bjorn Hjelm
 
Ad

More from Bjorn Hjelm (12)

PPTX
MODRNA WG Update - Oct 2023
Bjorn Hjelm
 
PPTX
MODRNA WG Update - Apr 2023
Bjorn Hjelm
 
PPTX
MODRNA WG update - OpenID Foundation Workshop at EIC 2022
Bjorn Hjelm
 
PPTX
MODRNA WG update - OpenID Foundation Workshop at EIC 2021
Bjorn Hjelm
 
PPTX
MODRNA WG Update - Dec 2021
Bjorn Hjelm
 
PPTX
Development of 5G IAM Architecture
Bjorn Hjelm
 
PPTX
OpenID Foundation MODRNA WG overview at EIC 2019
Bjorn Hjelm
 
PPTX
Development of 5G IAM Architecture
Bjorn Hjelm
 
PPTX
NSTIC Panel on Mobile-based Identity and Access Management
Bjorn Hjelm
 
PPTX
IIW 27 Wednesday Session 3
Bjorn Hjelm
 
PPTX
Integration of FIDO and Mobile Connect to deliver authentication globally wor...
Bjorn Hjelm
 
PPTX
FIDO and Mobile Connect
Bjorn Hjelm
 
MODRNA WG Update - Oct 2023
Bjorn Hjelm
 
MODRNA WG Update - Apr 2023
Bjorn Hjelm
 
MODRNA WG update - OpenID Foundation Workshop at EIC 2022
Bjorn Hjelm
 
MODRNA WG update - OpenID Foundation Workshop at EIC 2021
Bjorn Hjelm
 
MODRNA WG Update - Dec 2021
Bjorn Hjelm
 
Development of 5G IAM Architecture
Bjorn Hjelm
 
OpenID Foundation MODRNA WG overview at EIC 2019
Bjorn Hjelm
 
Development of 5G IAM Architecture
Bjorn Hjelm
 
NSTIC Panel on Mobile-based Identity and Access Management
Bjorn Hjelm
 
IIW 27 Wednesday Session 3
Bjorn Hjelm
 
Integration of FIDO and Mobile Connect to deliver authentication globally wor...
Bjorn Hjelm
 
FIDO and Mobile Connect
Bjorn Hjelm
 

Mobile Network Operators and Identity – Crossing the Chasm

  • 1. Mobile Network Operators and Identity – Crossing the Chasm Bjorn Hjelm September 22, 2015
  • 2. “Chasm crossing is not the end, but rather the beginning, of mainstream market development.” - Geoffrey A. Moore, Crossing the Chasm: Marketing and Selling Disruptive Products to Mainstream Customers 2
  • 3. Leveraging Open Standards for “Mainstream Market”. 3 “Productivity improvement for existing operations.” “Evolution, not revolution.” “Technology to enhance, not overthrow, the established ways of doing business.” “Do not want to debug somebody else’s product.“ - Geoffrey A. Moore, Crossing the Chasm: Marketing and Selling Disruptive Products to Mainstream Customers “When pragmatists buy, they care about the company they are buying from, the quality of the product they are buying, the infrastructure of supporting products and system interfaces, and the reliability of the service they are going to get.” - Geoffrey A. Moore, Crossing the Chasm: Marketing and Selling High-Tech Products to Mainstream Customers
  • 4. 4 Authentication and Authorization Framework using Open Standards OAuth 2.0 and OpenID Connect are two authentication and authorization standards that promises to serve as important tools. OAuth 2.0 IETF standard for securing Client application delegated access to server resources on behalf of a resource owner. Useful for conveying authorization decisions across network of web- enabled applications and APIs. Client authenticated to the Resource Server (RS) through the use of an access token provided by an Authorization Server (AS). OpenID Connect OpenID Foundation standard that extends OAuth 2.0 adding an identity layer to perform user authentication. OpenID Connect 1.0 adds two identity constructs to the token issuing model in OAuth 2.0. • Identity Token – Enables a federated SSO user experience for a user. • Identity attribute API – Allowing a Client to retrieve the desired identity attributes for the a given user.
  • 5. OpenID Foundation MODRNA WG Developing a profile of OpenID Connect for use by Mobile Network Operators providing identity services. Specifications divided into three parts: • Discovery • Dynamic Registration • Authentication MODRNA Working Group provides input to GSMA on the technical development of Mobile Connect. 5
  • 6. 6 Discovery Profile Addition to OpenID Connect Discovery specification. Specifies a way to normalize a user identifier to derive a resource and especially a host for OpenID Provider (OP) Issuer Discovery. Dynamic Registration Profile Addition to OpenID Connect Dynamic Registration specification. Specifies how a Client dynamically register with multiple Mobile Network Operators (MNOs) based on information asserted by a trusted entity. Authentication Profile Addition to OpenID Connect Core specification. Specifies the common authentication contexts to be used.
  • 7. Discovery with Account Chooser. 7 Using Account Chooser to bypass discovery to improve user experience. Account Chooser is a OpenID Foundation specification to help with the login process to a website by leveraging an account cashed. Proposed enhancement to Account Chooser specification to work with MODRNA Discovery flow by allowing login identifiers strings that are keyed on phone numbers. Service Providers will bring up Account Chooser during login and MNO will populate Account Chooser after successful login the MNO calls
  • 8. References for more information 8 OpenID Foundation MODRNA Working Group http://openid.net/wg/mobile/ OpenID Foundation Account Chooser Working Group http://openid.net/wg/ac/ Account Chooser http://accountchooser.net/