{"title":"Using GSM/UMTS for single sign-on","authors":"A. Pashalidis, C. Mitchell","doi":"10.1109/TIC.2003.1249107","DOIUrl":null,"url":null,"abstract":"At present, network users have to remember a user-name and a corresponding password for every service with which they are registered. Single sign-on (SSO) has been proposed as a solution to the usability, security and management implications of this situation. Under SSO, users authenticate themselves only once to an entity termed the 'authentication service provider' (ASP) and subsequently use disparate service providers (SPs) without re-authenticating. The information about the user's authentication status is handled between the ASP and the desired SP in a manner transparent to the user. We propose an SSO protocol where a GSM or UMTS operator plays the role of the ASP and by which its subscribers can be authenticated to SPs without any user interaction and in a way that preserves the user's privacy and mobility. The protocol requires only minimal changes to the deployed GSM infrastructure.","PeriodicalId":177770,"journal":{"name":"SympoTIC'03. Joint 1st Workshop on Mobile Future and Symposium on Trends in Communications","volume":"70 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2003-12-03","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"11","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"SympoTIC'03. Joint 1st Workshop on Mobile Future and Symposium on Trends in Communications","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/TIC.2003.1249107","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 11
Abstract
At present, network users have to remember a user-name and a corresponding password for every service with which they are registered. Single sign-on (SSO) has been proposed as a solution to the usability, security and management implications of this situation. Under SSO, users authenticate themselves only once to an entity termed the 'authentication service provider' (ASP) and subsequently use disparate service providers (SPs) without re-authenticating. The information about the user's authentication status is handled between the ASP and the desired SP in a manner transparent to the user. We propose an SSO protocol where a GSM or UMTS operator plays the role of the ASP and by which its subscribers can be authenticated to SPs without any user interaction and in a way that preserves the user's privacy and mobility. The protocol requires only minimal changes to the deployed GSM infrastructure.