Ericsson Mobile digital identity (Views on delivering solutions and the Business case for the banking and finance community) pedro calderon head of Product line Authentication & digital identity
Ericsson s identity Vision Every mobile phone number can be a Trusted digital ID Every mobile device is a Digital Wallet and ey part in the Networked Society Vision We must enable Simple & secure access to the largest possible set of services Pedro Calderon Ericsson Confidential 2014-11-05 Page 2
What is Ericsson MDI? Pedro Calderon A solution to converts every mobile device into a mobile digital ID Mobile Operators validate credentials and protect identity Simplifies access from any device to online resources Anywhere, anytime, any device Converts operators into Trusted Identity Providers Different levels of assurance (LoA1 to LoA4) for both SIM & non SIM-based services Pedro Calderon Ericsson Confidential 2014-11-05 Page 3
What are the use cases? Pedro Calderon Ericsson Confidential 2014-11-05 Page 4
Architecture for MCX Accelerator E-Gov Banks MDI Cloud based components User Portal SP Portal Discovery & Resolution MDI Cloud Gateway E/// API MDI Operator Cloud Components DB App. Server. MCXP / MCXS DB App. Server MCXP / MCXS Operator Authenticators SMS-C USSD BIOMETRICS SMS-C USSD BIOMETRICS AFG AFG Pedro Calderon Ericsson Confidential 2014-11-05 Page 5
identity players today Google + 300M MAU Facebook 1,35B MAU Mobile Operators 4.65B MAU Pedro Ericsson Calderon AB 2014 Ericsson 2014-09-04 Confidential Page 2014-11-05 6 Page 6
Identity model Who are you claiming to be? Can I trust this claim? Do you have a physical key? Prove to me the key isn t stolen! Smart card/reader BankID Bank / Gov Validated ID SIM PKI Mobile ID Facebook ID Google ID Twitter ID Open ID Connect O A U T H MNO validated against UDM Data MNO validated at Point of Sale GBA 2FA SMS challenge Location Challenge Notification SMS Setup SMS challenge Biometrics PKI password password Manual entry form NO NO Pedro Calderon Ericsson Confidential 2014-11-05 Page 7
99% of services Who are you claiming to be? Can I trust this claim? Do you have a physical key? Prove to me the key isn t stolen! Smart card/reader BankID Bank / Gov Validated ID SIM PKI Mobile ID Facebook ID Google ID Twitter ID Open ID Connect O A U T H MNO validated against UDM Data MNO validated at Point of Sale GBA 2FA SMS challenge Location Challenge Notification SMS Setup SMS challenge Biometrics PKI password password Manual entry form NO NO Pedro Calderon Ericsson Confidential 2014-11-05 Page 8
Gsma mobile connect Who are you claiming to be? Can I trust this claim? Do you have a physical key? Prove to me the key isn t stolen! Smart card/reader BankID Bank / Gov Validated ID SIM PKI Mobile ID Facebook ID Google ID Twitter ID Open ID Connect O A U T H MNO validated against UDM Data MNO validated at Point of Sale GBA 2FA SMS challenge Location Challenge Notification SMS Setup SMS challenge Biometrics PKI password password Manual entry form NO NO Pedro Calderon Ericsson Confidential 2014-11-05 Page 9
Bank and gov id Who are you claiming to be? Can I trust this claim? Do you have a physical key? Prove to me the key isn t stolen! Smart card/reader BankID Bank / Gov Validated ID SIM PKI Mobile ID Facebook ID Google ID Twitter ID Open ID Connect O A U T H MNO validated against UDM Data MNO validated at Point of Sale GBA 2FA SMS challenge Location Challenge Notification SMS Setup SMS challenge Biometrics PKI password password Manual entry form NO NO Pedro Calderon Ericsson Confidential 2014-11-05 Page 10
Mobile digital identity supported cases Who are you claiming to be? Can I trust this claim? Do you have a physical key? Prove to me the key isn t stolen! Smart card/reader BankID Bank / Gov Validated ID SIM PKI Mobile ID Facebook ID Google ID Twitter ID Open ID Connec t O A U T H MNO validated against UDM Data MNO validated at Point of Sale GBA 2FA SMS challenge Location Challenge Notification SMS Setup SMS challenge Biometrics PKI password password Manual entry form NO NO Pedro Calderon Ericsson Confidential 2014-11-05 Page 11
Business, trust & simplicity MDI and the Mobile connect move Simple User Interface Pedro Calderon End-User Profile Management MNO LOGO Branding Space Featured Applications Connected Applications Permissions Management per App Pedro Calderon Ericsson Confidential 2014-11-05 Page 12
WherE is the business case For MOBIle ID & eid?
Pedro Calderon Ericsson Confidential 2014-11-05 Page 14
3 elements for a strong BC Paid authentication Attribute Brokerage Promote Own Services Pedro Calderon Ericsson Confidential 2014-11-05 Page 15
authentication Paid authentication Provide Attribute Brokerage Promote Own Services Pedro Calderon Ericsson Confidential 2014-11-05 Page 16
levels of assurance Level of Assuran ce Confidence in Asserted Identity Authentication Factors LoA1 Little or no confidence Single Factor Authentication Something I Know Options for Authentication N/A MDI leverages on the possession of a mobile device Social Apps LoA2 Some confidence Single Factor Authentication Something I Have LoA3 High confidence Multi-Factor Authentication: Something I Have Something I Know SMS + URL USSD Smartphone App Idem on LoA2 plus PIN or Password MDI 1.X LoA4 Very high confidence Multi-Factor Authentication: Something I Have Something I Know + PKI for Digital Signature Idem on LOA3 plus PKI MDI 2,x Pedro Calderon Ericsson Confidential 2014-11-05 Page 17
Pedro Calderon Ericsson Confidential 2014-11-05 Page 18
Freemium model High volume (above threshold) Low volume (below threshold) paid free paid free paid LOA2 LOA3 LOA4 Pedro Calderon Ericsson Confidential 2014-11-05 Page 19
Promoting services Paid authentication Provide Attribute Brokerage Promote Own Services Pedro Calderon Ericsson Confidential 2014-11-05 Page 20
Key Take-Aways MDI leverages on the possession of a mobile device to provide multi-factor authentication What I have (Mobile device) What I know (Password, PIN, etc..) What I am (Biometrics and more on research) Offers a Full range of Authentication, Identification and Authorization levels MDI 1.0 is 1 st Global GSMA Mobile Operator Compliant solution in the market Pedro Calderon Ericsson Confidential 2014-11-05 Page 21
Promote your own services fast development of ecosystem Pedro Calderon Ericsson Confidential 2014-11-05 Page 23
From Discovery to Recommendations Pedro Calderon Ericsson Confidential 2014-11-05 Page 24
Attribute brokerage Paid authentication Provide Attribute Brokerage Promote Own Services Pedro Calderon Ericsson Confidential 2014-11-05 Page 25
Attribute brokerage Seamlessly needed when there is 1 to Many relationships (e.g. Between an app and identity sources) website or app Company A user database Company B user database Company C user database Pedro Calderon Ericsson Confidential 2014-11-05 Page 26
examples MCX Pedro Calderon Ericsson Confidential 2014-11-05 Page 27
Pedro Calderon Ericsson Confidential 2014-11-05 Page 28
Mobile apps & MOBIle connect Pedro Calderon Ericsson Confidential 2014-11-05 Page 29
Pedro Calderon Ericsson Confidential 2014-11-05 Page 30
Pedro Calderon Ericsson Confidential 2014-11-05 Page 31