Protecting Mobile Service User Identity by Adding Additional Security Layer

dc.contributor.authorErdemir, Utku
dc.contributor.authorCoşkun, Vedat
dc.contributor.authorBuk, Onur
dc.contributor.authorMantar, Hacı Ali
dc.contributor.authorKöse, Büşra Özdenizci
dc.date.accessioned2024-03-13T09:49:59Z
dc.date.available2024-03-13T09:49:59Z
dc.date.issued2021
dc.departmentİstanbul Beykent Üniversitesien_US
dc.description.abstractToday, various common identity systems (e.g. Facebook Login, Google Connect, Apple ID) are used to improve operational efficiency for service providers and provide an easier authentication method in web or mobile services for users. Almost all common identity systems focus on delivering seamless user experience while proving user identity securely to the service provider. In particular, the use of common identity systems with a high security level is becoming a more important requirement on smartphones. In this context, MNOs (Mobile Network Operators) are considered as an important actor in providing common identity services, as they have strong GSM capabilities. Currently, it is possible to see many identity management solutions -based on OpenID Connect and Mobile Connect standards- from MNOs which are used for authentication in mobile applications of service providers. However, existing solutions generally does not provide very high level of assurance in the asserted digital identity. With advancements in value-added mobile services and increasing security requirements; there is a need for common identity systems that provide higher levels of assurance (i.e., particularly LoA4), strong authentication and non-repudiation services for service providers and users. This study presents the development and implementation of a multi-factor authentication method for mobile services based on Mobile Connect and OpenID Connect standards. The designed model includes the usage of three identity -knowledge, ownership, biometric- factors of user in order to access sensitive mobile services on the smartphone. The system development and testing studies were systematically presented based on the functional requirements. The realization and deployment of the proposed model by MNOs could play an important role in the development of mobile services that require a high level of assurance in the future.en_US
dc.identifier.doi10.31590/ejosat.833433
dc.identifier.endpage30en_US
dc.identifier.issn2148-2683
dc.identifier.issue23en_US
dc.identifier.startpage22en_US
dc.identifier.trdizinid1174746en_US
dc.identifier.urihttps://doi.org/10.31590/ejosat.833433
dc.identifier.urihttps://search.trdizin.gov.tr/yayin/detay/1174746
dc.identifier.urihttps://hdl.handle.net/20.500.12662/2376
dc.identifier.volume0en_US
dc.indekslendigikaynakTR-Dizinen_US
dc.language.isoenen_US
dc.relation.ispartofAvrupa Bilim ve Teknoloji Dergisien_US
dc.relation.publicationcategoryMakale - Ulusal Hakemli Dergi - Kurum Öğretim Elemanıen_US
dc.rightsinfo:eu-repo/semantics/openAccessen_US
dc.titleProtecting Mobile Service User Identity by Adding Additional Security Layeren_US
dc.typeArticleen_US

Dosyalar