Authentication of a user to a service in a communication system
By delegating user and subscription authentication to network operators and authentication service devices, combining SMS-based 2FA and FIDO authentication, the method addresses vulnerabilities in existing authentication methods, ensuring user and subscription authenticity and providing enhanced trust for service providers.
Patent Information
- Application Number
- PCT/EP2023/086509
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2023-12-19
- Publication Date
- 2025-06-26
AI Technical Summary
Existing user authentication methods, such as SMS-based 2FA and FIDO authentication, fail to ensure user authenticity, information authenticity, and subscription ownership, making them vulnerable to attacks like phishing and SIM swapping.
A method that combines the benefits of SMS-based 2FA and FIDO authentication by delegating user and subscription authentication to a network operator and an authentication service device, using SMS messages with authentication links and FIDO credentials to verify user authenticity.
This approach ensures the authenticity of users and their subscriptions, providing added trust to service providers and ensuring the authenticity of user information, while simplifying the authentication process for service providers.
Smart Images

Figure EP2023086509_26062025_PF_FP_ABST
Abstract
Description
[0001] AUTHENTICATION OF A USER TO A SERVICE IN A COMMUNICATION SYSTEM
[0002] TECHNICAL FIELD
[0003] Embodiments presented herein relate to methods, a service provider device, an authentication service device, a network operator device, computer programs, and a computer program product for authenticating a user to a service in a communication system.
[0004] BACKGROUND
[0005] In general terms, user authentication is a process that verifies a person's identity allowing them access to an online service, connected device, or other resource. There can be different ways to perform user authentication. Two non-limiting examples are short message service (SMS) based two-factor authentication (2FA) and Fast Identity Online (FIDO) authentication.
[0006] 2FA is a form of authentication that requires the user to provide two types of evidence to verify their identity. The first factor is typically password or a personal identification number (PIN) code, while the second factor typically is a one-time code sent via SMS to the user’s registered mobile phone number. The user needs to enter their one-time code to complete the authentication process. Typically, a service provider generates the one-time code, which is sent to the user via SMS using a mobile network. When the user enters this one-time code, the service provider verifies the code and thus grants the user access to the information. This approach is widely used because it is simple to use as it does not require any additional hardware or software (except for implementing the functionality itself). However, SMS based 2FA has been criticized for its vulnerability to so-called phishing attacks and SIM swapping.
[0007] FIDO (or FIDO2) is an authentication standard that supports password-less, second factor, and multi-factor user authentication via an authenticator. Unlike SMS-based authentication, FIDO requires a physical security key, either a separate FIDO authenticator or a communication device, such as a mobile phone, implementing it, and in addition (optionally) user verification (or at least acknowledgement) e.g., through a passcode or biometric authentication (such as facial recognition or fingerprint scanning) to authenticate the user, thereby making it a more robust form of 2FA. The FIDO authenticator can be either roaming (external) or a platform (embedded / bound) authenticator. The roaming authenticator connects to the client via some communications interface whereas the platform authenticator is built-in to the client platform. The authentication is initiated by the user by visiting a webpage provided by a web service (also referred to as relying party). The web service responses to the user with a CollectFromCredentialStore message comprising parameters such as origin (web service domain) and options which include challenge, identity of the relying party (rpid), credid (allowedCredentials.id), extensions. The user validates the origin with the originally requested web service origin, and if it does not match, the user rejects the connection, and the authentication is terminated. If the origin validation is ok, the user hashes the challenge and origin to create clientDataHash and sends parameters such as the rpid, clientDataHash and options to the authenticator. The authenticator prompts the user to validate their presence, using e.g., biometrics, an acknowledgement, as well as to get user consent to proceed the authentication, retrieves the private key (created during registration) from secure storage based on credid, and builds and signs the response with the credential private key. The authenticator sends the signed response to the user. The user adds clientData to the signed response and sends it to the web service. Finally, the web service verifies, origin, challenge, credid, and signature with the public key (stored during registration process) associated with the credential. If all verifications are ok, the user is authenticated.
[0008] As noted above, although SMS-based 2FA authentication is widely used, it is vulnerable to attacks such as phishing attacks and SIM swapping. Also, whilst the subscription is verified, the subscriber authenticity is ignored. FIDO authentication, on the other hand, assures subscriber authenticity, but is not as widely adopted as SMS and typically does not ensure the authenticity of the subscribers’ information. The subscriber, depending on their motivation, can easily provide falsified information to access services. As a non-limiting and illustrative example, if a service provider requires the subscriber to be over a certain age to access a given service, the subscriber can provide false data to access the service.
[0009] In view of the above, neither SMS-based 2FA authentication nor FIDO authentication ensures user authenticity, user information authenticity, and information whether the authenticating user is in possession of the subscription associated with the user at the service, which might be crucial for a service provider.
[0010] Hence, there is still a need for improved user authentication.
[0011] SUMMARY
[0012] An object of embodiments herein is to address the above issues to provide user authentication that does not suffer from the above issues, or where the above issues at least have been mitigated or reduced.
[0013] A particular object is to combine the benefits of SMS-based 2FA authentication and FIDO authentication but avoiding their disadvantages.
[0014] According to a first aspect there is presented a method for authenticating a user to a service in a communication system. The method is performed by a service provider device. The method comprises receiving an access request to a service from at least one user device of the user. The access request comprises an MSISDN of the at least one user device as identifier of the user. The method comprises providing an authentication request and an identifier of the service provider device to an authentication service device. The authentication request comprises the MSISDN. The method comprises receiving an authentication result from the authentication service device of authentication as performed by the authentication service device with the at least one user device. The method comprises enabling access to the service for the user via the at least one user device only when the authentication result indicates successful authentication of the at least one user device with the authentication service device.
[0015] According to a second aspect there is presented a service provider device for authenticating a user to a service in a communication system. The service provider device comprises processing circuitry. The processing circuitry is configured to cause the service provider device to receive an access request to a service from at least one user device of the user. The access request comprises an MSISDN of the at least one user device as identifier of the user. The processing circuitry is configured to cause the service provider device to provide an authentication request and an identifier of the service provider device to an authentication service device. The authentication request comprises the MSISDN. The processing circuitry is configured to cause the service provider device to receive an authentication result from the authentication service device of authentication as performed by the authentication service device with the at least one user device. The processing circuitry is configured to cause the service provider device to enable access to the service for the user via the at least one user device only when the authentication result indicates successful authentication of the at least one user device with the authentication service device.
[0016] According to a third aspect there is presented a computer program for authenticating a user to a service in a communication system, the computer program comprising computer program code which, when run on processing circuitry of a service provider device, causes the service provider device to perform actions. One action comprises the service provider device to receive an access request to a service from at least one user device of the user. The access request comprises an MSISDN of the at least one user device as identifier of the user. One action comprises the service provider device to provide an authentication request and an identifier of the service provider device to an authentication service device. The authentication request comprises the MSISDN. One action comprises the service provider device to receive an authentication result from the authentication service device of authentication as performed by the authentication service device with the at least one user device. One action comprises the service provider device to enable access to the service for the user via the at least one user device only when the authentication result indicates successful authentication of the at least one user device with the authentication service device.
[0017] According to a fourth aspect there is presented a method for authenticating a user to a service in a communication system. The method is performed by an authentication service device. The method comprises receiving an authentication request for the user from a service provider device and an identifier of the service provider device. The authentication request comprises an MSISDN of at least one user device of the user as identifier of the user. The method comprises identifying, based on the MSISDN, a home network operator device of the at least one user device. The method comprises triggering the home network operator device to send an SMS message to the at least one user device. The SMS message comprises the identifier of the service provider device, and a link to an authentication service for the user. The method comprises performing authentication with the at least one user device. The method comprises sending an authentication result of the authentication to the service provider device.
[0018] According to a fifth aspect there is presented an authentication service device for authenticating a user to a service in a communication system. The authentication service device comprises processing circuitry. The processing circuitry is configured to cause the authentication service device to receive an authentication request for the user from a service provider device and an identifier of the service provider device. The authentication request comprises an MSISDN of at least one user device of the user as identifier of the user. The processing circuitry is configured to cause the authentication service device to identify, based on the MSISDN, a home network operator device of the at least one user device. The processing circuitry is configured to cause the authentication service device to trigger the home network operator device to send an SMS message to the at least one user device. The SMS message comprises the identifier of the service provider device, and a link to an authentication service for the user. The processing circuitry is configured to cause the authentication service device to perform authentication with the at least one user device. The processing circuitry is configured to cause the authentication service device to send an authentication result of the authentication to the service provider device.
[0019] According to a sixth aspect there is presented a computer program for authenticating a user to a service in a communication system, the computer program comprising computer program code which, when run on processing circuitry of an authentication service device, causes the authentication service device to perform actions. One action comprises the authentication service device to receive an authentication request for the user from a service provider device and an identifier of the service provider device. The authentication request comprises an MSISDN of at least one user device of the user as identifier of the user. One action comprises the authentication service device to identify, based on the MSISDN, a home network operator device of the at least one user device. One action comprises the authentication service device to trigger the home network operator device to send an SMS message to the at least one user device. The SMS message comprises the identifier of the service provider device, and a link to an authentication service for the user. One action comprises the authentication service device to perform authentication with the at least one user device. One action comprises the authentication service device to send an authentication result of the authentication to the service provider device.
[0020] According to a seventh aspect there is presented a method for authenticating a user to a service in a communication system. The method is performed by a network operator device. The method comprises receiving triggering from an authentication service device for the network operator device to send an SMS message to at least one user device of the user. The SMS message comprises an identifier of the service provider device, and a link to an authentication service for the user. The method comprises sending the SMS message to the at least one user device.
[0021] According to an eighth aspect there is presented a network operator device for authenticating a user to a service in a communication system. The network operator device comprises processing circuitry. The processing circuitry is configured to cause the network operator device to receive triggering from an authentication service device for the network operator device to send an SMS message to at least one user device of the user. The SMS message comprises an identifier of the service provider device, and a link to an authentication service for the user. The processing circuitry is configured to cause the network operator device to send the SMS message to the at least one user device.
[0022] According to a ninth aspect there is presented a computer program for authenticating a user to a service in a communication system, the computer program comprising computer program code which, when run on processing circuitry of a network operator device, causes the network operator device to perform actions. One action comprises the network operator device to receive triggering from an authentication service device for the network operator device to send an SMS message to at least one user device of the user. The SMS message comprises an identifier of the service provider device, and a link to an authentication service for the user. One action comprises the network operator device to send the SMS message to the at least one user device.
[0023] According to a tenth aspect there is presented a computer program product comprising a computer program according to at least one of the third aspect, the sixth aspect, and the ninth aspect and a computer readable storage medium on which the computer program is stored. The computer readable storage medium can be a non- transitory computer readable storage medium.
[0024] Advantageously, these aspects provide user authentication that does not suffer from the above issues.
[0025] Advantageously, these aspects combine the benefits of SMS-based 2FA authentication and authentication by means of an authentications service device such as FIDO and avoid their disadvantages.
[0026] Advantageously, according to these aspects the service provider does not necessarily have to support the subscriber authentication as it is delegated to the network operator (or authentication service).
[0027] Advantageously, these aspects ensure the user and their subscription authenticity, which provides added trust to the service provider.
[0028] Advantageously, these aspects ensure the authenticity of information shared by the user.
[0029] Advantageously, these aspects enable the service provider to obtain subscriber information from a trustworthy source (namely the home network operator of the user).
[0030] Other objectives, features and advantages of the enclosed embodiments will be apparent from the following detailed disclosure, from the attached dependent claims as well as from the drawings.
[0031] Generally, all terms used in the claims are to be interpreted according to their ordinary meaning in the technical field, unless explicitly defined otherwise herein. All references to "a / an / the element, apparatus, component, means, module, step, etc." are to be interpreted openly as referring to at least one instance of the element, apparatus, component, means, module, step, etc., unless explicitly stated otherwise. The steps of any method disclosed herein do not have to be performed in the exact order disclosed, unless explicitly stated. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] The inventive concept is now described, by way of example, with reference to the accompanying drawings, in which:
[0033] Fig. 1 is a schematic diagram illustrating a communication system according to embodiments;
[0034] Figs. 2, 3, and 4 are flowcharts of methods for authenticating a user to a service in a communication system according to embodiments;
[0035] Figs. 5 and 7 are block diagrams of communication systems according to embodiments;
[0036] Figs. 6 and 8 are signaling diagrams of methods for registering a user and for authenticating the user to a service in a communication system according to embodiments;
[0037] Fig. 9 is a schematic diagram showing structural units of a service provider device according to an embodiment;
[0038] Fig. 10 is a schematic diagram showing structural units of an authentication service device according to an embodiment;
[0039] Fig. 11 is a schematic diagram showing structural units of a network operator device according to an embodiment; and
[0040] Fig. 12 shows one example of a computer program product comprising computer readable means according to an embodiment.
[0041] DETAILED DESCRIPTION
[0042] The inventive concept will now be described more fully hereinafter with reference to the accompanying drawings, in which certain embodiments of the inventive concept are shown. This inventive concept may, however, be embodied in many different forms and should not be construed as limited to the embodiments set forth herein; rather, these embodiments are provided by way of example so that this disclosure will be thorough and complete, and will fully convey the scope of the inventive concept to those skilled in the art. Like numbers refer to like elements throughout the description. Any step or feature illustrated by dashed lines should be regarded as optional.
[0043] Fig. 1 is a schematic diagram illustrating a communication system io where embodiments presented herein can be applied. The communication system io comprises a service provider device 100, an authentication service device 200, a network operator device 300, and at least one user device 400a, 400b. Each of the at least one user devices 400a, 400b could be a mobile phone, user equipment (UE), smartphone, laptop computer, tablet computer, or the like. The at least one user devices 400a, 400b belongs to a user 12. In some examples each of the at least one user devices 400a, 400b implements a FIDO client and / or a FIDO authenticator. In some examples the authentication service device 200 implements a FIDO authentication service. In some examples, as an alternative to FIDO authentication, also other types of authentication technologies could be used. One non-limiting example of such an authentication technology is Universal 2nd Factor (U2F), which a user 12 can use one key to authenticate to multiple services. Another non-limiting example of such an authentication technology is Decentralized Identifiers (DIDs) along with Verifiable Credentials (VCs). With DIDs, unique anonymous identifier can be created, and authentication to a service can be performed using public key cryptography. In some examples, the service provider device 100 comprises, or implements the functionality of, the authentication service device 200. For example, if the authentication service device 200 is co-located with the service provider device 100, the service provider device 100 does not necessarily need to establish a secure session between itself and the authentication service device 200, as it would be an internal service which is known and there is mutual trust between them. Likewise, the authentication service device 200 could be co-located with the network operator device 300. Then there would not be need for explicit authentication and secure session establishment between the authentication service device 200 and the network operator device 300, but instead internal security configuration of the network operator device 300 would take care of the securing of the interface between the two.
[0044] At least some of the herein disclosed embodiments are based on ensuring the service provider device 100 that the user 12 and their subscription are verified to access a requested service (as provided by the service provider device 100). This verification is by the service provider device 100 delegated to the network operator device 300 and the authentication service device 200.
[0045] Reference is now made to Fig. 2 illustrating a method for authenticating a user 12 to a service in a communication system 10 as performed by the service provider device 100 according to an embodiment.
[0046] S102: The service provider device 100 receives an access request to a service from at least one user device 400a (e.g., being a first user device 400a) of the user 12. The access request comprises an MSISDN of the at least one user device 400a, 400b (being either the first user device 400a or a second user device 400b) as identifier of the user 12.
[0047] Here, the first or second user device 400a, 400b is the user device which has the mobile subscription of the user 12 that will be used for communicating SMS messages to the user 12, and which might host, or has access to, (FIDO) authentication credentials. In this respect, SMS messages could be sent to one user device, and the (FIDO) authentication credentials could be provided on another user device.
[0048] S104: The service provider device 100 provides an authentication request and an identifier of the service provider device 100 to an authentication service device 200. The authentication request comprises the MSISDN.
[0049] S106: The service provider device 100 receives an authentication result from the authentication service device 200 of authentication as performed by the authentication service device 200 with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b).
[0050] S108: The service provider device 100 enables access to the service for the user 12 via the at least one user device 400a (being the first user device 400a) only when the authentication result indicates successful authentication of the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) with the authentication service device 200.
[0051] Embodiments relating to further details of authenticating a user 12 to a service in a communication system 10 as performed by the service provider device 100 will now be disclosed. In some embodiments, the authentication request as provided to the authentication service device 200 further comprises a request for information of the user 12. Examples of such information and how the information can be used by the service provider device 100 will be disclosed below. Such a request for information of the user 12 will hereinafter be referred to as a scope. In this way, the service provider device 100 can request information about the user 12 from the trustworthy source, such as the home network operator of the user 12, instead of from the user 120 themselves.
[0052] In some embodiments, the authentication result is of FIDO authentication as performed by the authentication service device 200 with the at least one user device 400a, 400b.
[0053] Reference is now made to Fig. 3 illustrating a method for authenticating a user 12 to a service in a communication system 10 as performed by the authentication service device 200 according to an embodiment.
[0054] S208: The authentication service device 200 receives an authentication request for the user 12 from a service provider device 100 and an identifier of the service provider device 100. The authentication request comprises an MSISDN of at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) of the user 12 as identifier of the user 12.
[0055] S210: The authentication service device 200 identifies, based on the MSISDN, a home network operator device 300 of the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b).
[0056] S218: The authentication service device 200 triggers the home network operator device 300 to send an SMS message to the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b). The SMS message comprises the identifier of the service provider device 100, and a link to an authentication service for the user 12.
[0057] S220: The authentication service device 200 performs authentication with the at least one user device 400a, 400b. S222: The authentication service device 200 sends an authentication result of the authentication to the service provider device 100.
[0058] Embodiments relating to further details of authenticating the user 12 to a service in a communication system 10 as performed by the authentication service device 200 will now be disclosed with continued reference to Fig. 3.
[0059] In some aspects, the authentication of the user 12 to the service is preceded by a registration of the user 12. Therefore, in some embodiments, the authentication service device 200 is configured to perform (optional) step S202.
[0060] S202: The authentication service device 200 receives a registration request from the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b). The registration request comprises the MSISDN of the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b).
[0061] Step S202 can thus be performed when registration of the user 12 precedes, or is part of, the authentication of the user 12. Step S202 does not need to be performed when such registration has already been performed.
[0062] In some embodiments, the SMS message in step S218 is a second SMS message, and, in case no registration information associated with the MSISDN is found, the authentication service device 200 is configured to perform (optional) step S204.
[0063] S204: The authentication service device 200 triggers the home network operator device 300 to send a first SMS message to the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b). The first SMS message is to comprise an identifier of the authentication service device 200, an indication that the first SMS message is for an authentication credential registration request, and a link for the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) to access for the registration to be performed.
[0064] As for step S202, since step S204 is performed as part of the registration of the user 12, step S204 can thus be performed when registration of the user 12 precedes, or is part of, the authentication of the user 12. Step S204 does not need to be performed when such registration has already been performed.
[0065] In some embodiments, the indication in the first SMS message in step S204 is that the first SMS message is for a FIDO authentication credential registration request, and the link is for the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) to access for FIDO registration to be performed.
[0066] Registration with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) can then be performed in accordance with the link in the first SMS message. Therefore, in some embodiments, the authentication service device 200 is configured to perform (optional) step S206.
[0067] S206: The authentication service device 200 performs registration with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) in accordance with the link in the first SMS message. As part of performing the registration, the authentication service device 200 might registers an authentication credential, such as a public key of an asymmetric key pair for the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b).
[0068] As for steps S202 and S204, since step S206 is performed as part of the registration of the user 12, step S206 can thus be performed when registration of the user 12 precedes, or is part of, the authentication of the user 12. Step S206 does not need to be performed when such registration has already been performed.
[0069] In some embodiments, the registration performed with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) is FIDO registration.
[0070] As disclosed above, in some embodiments, the authentication request further comprises a request for information of the user 12. Examples of such information and how the information can be used by the service provider device 100 will be disclosed below. Such a request for information of the user 12 will hereinafter be referred to as a scope. In some aspects, the authentication service device 200 verifies the authentication request. In particular, in some embodiments, the authentication service device 200 is configured to perform (optional) step S212.
[0071] S212: The authentication service device 200 verifies that the authentication request is received from the service provider device 100 identified by the identifier before triggering the home network operator device 300 to send the SMS message.
[0072] Step S212 can thus be performed when the authentication request further comprises a request for information of the user 12. Step S212 does not need to be performed when the authentication request does not comprise any such request for information of the user 12.
[0073] In some aspects, the user 12 might have previously registered with the authentication service device 200, for example as in steps S202-S206. The authentication service device 200 might search for registration information to check if such a registration has taken place. In some embodiments, the authentication service device 200 is therefore configured to perform (optional) step S214.
[0074] S214: The authentication service device 200 searches for registration information associated with the MSISDN.
[0075] Step S214 can thus be performed to check if registration of the user 12 has already been performed. Step S212 does not need to be performed when the registration of the user 12 is performed as part of authenticating the user 12.
[0076] In case registration information associated with the MSISDN is found, the authentication service device 200 can use this registration information to see if it is associated with the service provider device 100 from which the authentication request was received. Therefore, in some embodiments, the authentication service device 200 is configured to perform (optional) step S216.
[0077] S216: The authentication service device 200 identifies whether the registration information is associated with the service provider device 100 from which the authentication request was received. As for step S214, since step S216 is performed as part of checking if registration of the user 12 has already been performed, step S216 does not need to be performed when the registration of the user 12 is performed as part of authenticating the user 12.
[0078] In other words, if the service provider device 100 is not registered with the credential of the user 12, this means that the user 12 has not (yet) given consent to use the credentials for authenticating to the service provider device 100. In this case, the (second) SMS might contain an indication to the user 12 that the credentials are not associated with the service provider device 100 and that if user 12 decides to go ahead and authenticate via the provided link, the service provider device 100 will be linked to the credential. That is, by authenticating, the user 12 gives consent to link the service provider device 100 to the credential). Therefore, in some embodiments, the (second) SMS message further indicates whether the service provider device 100 has been associated with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) or not.
[0079] In some embodiments, the authentication performed with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) is a FIDO authentication.
[0080] Reference is now made to Fig. 4 illustrating a method for authenticating a user 12 to a service in a communication system 10 as performed by the network operator device 300 according to an embodiment. In some aspects, the network operator device 300 is a home network operator device 300 of the at least one user device 400a, 400b of the user 12.
[0081] S306: The network operator device 300 receives triggering from an authentication service device 200 for the network operator device 300 to send an SMS message to at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) of the user 12. The SMS message is to comprise an identifier of the service provider device 100, and a link to an authentication service for the user 12.
[0082] S308: The network operator device 300 sends the SMS message to the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b). Embodiments relating to further details of authenticating a user 12 to a service in a communication system 10 as performed by the network operator device 300 will now be disclosed with continued reference to Fig. 4.
[0083] As disclosed above, in some embodiments, the SMS message further indicates whether the service provider device 100 has been associated with the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) or not.
[0084] As disclosed above, in some aspects, the authentication of the user 12 to the service is preceded by a registration of the user 12. Therefore, in some embodiments, the SMS message is a second SMS message, and the network operator device 300 is configured to perform (optional) steps S302 and S304.
[0085] S302: The network operator device 300 receives triggering from the authentication service device 200 for the network operator device 300 to send a first SMS message to the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b). The first SMS message comprises an identifier of the authentication service device 200, an indication that the first SMS message is for an authentication credential registration request, and a link for the user 12 to access for the registration to be performed.
[0086] S304: The network operator device 300 sends the first SMS message to the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b).
[0087] Steps S302 and S304 can thus be performed when registration of the user 12 precedes, or is part of, the authentication of the user 12. Steps S302 and S304 do not need to be performed when such registration has already been performed.
[0088] In some embodiments, the indication is that the first SMS message is for a FIDO authentication credential registration request, and the link is for the at least one user device 400a, 400b (being either the first user device 400a or the second user device 400b) to access for FIDO registration to be performed.
[0089] One particular embodiment for registering a user 12 to the authentication service device 200 based on at least some of the above disclosed embodiments will now be disclosed in detail with reference to the block diagram of Fig. 5 and the signaling diagram of Fig. 6.
[0090] The registration comprises generating and registering a credential, such as an asymmetric key pair, at the authentication service device 200, and associating the credential with the subscription of the user 12. This association can be made based on the MSISDN i.e., phone number, of the subscription.
[0091] S401: The user 12, via its user device 400a, accesses the authentication service device 200 and provides their MSISDN, thereby triggering the registration process.
[0092] S402: The authentication service device 200, based on the MSISDN, identifies the home network operator of the user 12 (i.e., of the user device 400a) and sends a trigger SMS message to the network operator device 300 of the home network operator. In addition to the target MSISDN, the message carries the service provider identifier (which is in this case the identifier of the authentication service device 200), a request type parameter indicating that this is a credential registration request, and a link (in terms of a uniform resource locator, URL) the user 12 is requested to access. The link could be a short-lived registration session specific link.
[0093] S403: The network operator device 300 uses the received information to send an SMS message for the user 12 and sends the SMS message to the user device 400a. The message contains the link received in step S402 as well as the identifier identifying the authentication service device 200 and information that the request is for registration of a credential with the authentication service device 200.
[0094] S404: The user can verify that the identifier and request type match the intent the user had at step S401 (namely to register the user 12 to the authentication service device 200), and then accesses the provided link, which results in registration being run between the user device 400a and the authentication service device 200.
[0095] The authentication service device 200 knows to expect the registration on the shortlived registration session specific link and having the user 12 accessing that link proves that the user 12 possesses the MSISDN provided in step S401. After successful registration, the authentication service device 200 has registered the credential of the user 12 and associated the credential with the MSISDN of the user 12. One particular embodiment for authenticating a user 12 to a service in a communication system 10 based on at least some of the above disclosed embodiments will now be disclosed in detail with reference to the block diagram of Fig. 7 and the signaling diagram of Fig. 8.
[0096] There are three different scenarios where the same authentication procedure can be used. According to a first scenario the user 12 is a new user 12 at the service provider device 100 and wants to access a service or open an account at the service provider device 100. Thus, the authentication can be used for proving ownership of the MSISDN, which later can be used to prove that it is still the same user 12 (or owner of subscription), i.e., that the MSISDN is used as e.g., account identifier for accessing the created account at a later stage. According to a second scenario the user 12 has already created an account at the service provider device 100, for example based on traditional credentials (e.g., a username and a password), and wants to add new credential to the account. The user 12 then first logs in to account using the traditional credentials, and then (as an authenticated user) issues a command to add new credentials to the account. According to a third scenario the user 12 has already created an account at the service provider device 100 and credentials according to the herein disclosed embodiments have already been associated with the account, and the user 12 uses the new credentials to access the service or account at the service provider device 100.
[0097] S501: The user 12, via the user device 400a, access the service provider device 100 and provides their MSISDN as account identifier to the service provider device 100.
[0098] S502: The service provider device 100 sends an authentication request to the authentication service device 200. The authentication request is sent over a mutually authenticated connection in case the service provider device 100 and the authentication service device 200 are not co-located.
[0099] S503: The authentication request carries the MSISDN, the identity of the service provider device 100, and, optionally a request from the service provider device 100 for scope regarding the user 12, i.e., information about the user 12 the service provider device 100 wants to obtain. S504: The authentication service device 200 verifies that the authentication request comes from the same service provider device 100 as indicated in the identifier in the authentication request. This could be achieved by the authentication service device 200 matching the identifier in the message with the credentials (e.g., certificate) used for establishing the secure connection over which the authentication request was received. Alternatively, the identifier is not sent in step S502, but instead the authentication service device 200 obtains the identifier based on the credentials used for establishing the secure session. The authentication service device 200 tries to locate a context for the MSISDN received from the service provider device 100. If the user 12 has previously registered with the authentication service device 200 there will be a context for the MSISDN, where the MSISDN is associated with credentials of the user 12. The authentication service device 200 identifies whether the context is already associated with the specific service provider device 100, i.e., that the user 12 has authorized the use of the credential towards the service provider device 100.
[0100] S505: The authentication service device 200, based on the MSISDN, identifies the home network operator of the user 12 and sends a trigger SMS message to the network operator device 300 of the home network operator. In addition to the target MSISDN, the message carries the identifier of the service provider device 100, the link the user 12 is requested to access, and a request type parameter indicating the type of request. The request type can indicate whether this is an authentication request of a known service provider device 100 (i.e., a service provider device 100 already authorized for the credentials) or an authentication request of a new service provider device 100, and thus also an authorization request to associate the service provider device 100 with the credential. The link could be a short-lived authentication session specific link.
[0101] S506: The network operator device 300 of the user 12 uses the received information to send an SMS message for the user 12 and sends the SMS to the user device 400a. The SMS message comprises the link received in step S504 as well as the identifier of the service provider device 100 and the request type identifying if the service provider device 100 is previously known, or associated, with the subscription.
[0102] S507: The user 12 can verify that the identifier of the service provider device 100 matches the intent the user had at step S501, and also make a decision of potentially wanting to add the service provider device 100 as an associated service provider device 100 for the service, and then (wanting to proceed) accesses the provided link. This results in authentication being run between the user device 400a (or another user device 400b) and the authentication service device 200, and the service provider device 100 (optionally) being added to the list of authorized service provider devices 100 for the credentials. In this way, the service provider device 100 might only be added to the list of authorized service provider devices 100 for the credentials when the identifier of the service provider device 100 matches the intent the user had at step S501. In turn, this prevents the credentials from being used for any intent the user 12 has not verified.
[0103] The authentication service device 200 knows to expect the authentication on the short-lived session specific link and having the user 12 accessing that link proves that the user 12 possesses the MSISDN obtained in step S502.
[0104] 5508 (optional): If the service provider device 100 requested a scope in step S502, the authentication service device 200 provides the user 12, via the user device 400a, 400b used for authentication towards the authentication service device 200, the possibility to see and affect what information about the user 12 should be made available to the service provider device 100. This could be in the form of a web service based on the scope request, where the user 12 can, for each piece of information, select whether the authentication service device 200 is allowed to share the information with the service provider device 100, and if the information should be obtained from the home network operator of the user 12 or alternatively, if the user themselves should enter the information. The user 12 then submits the authorization for sharing information requested by the service provider device 100. Step S508 is thus only performed when the service provider device 100 requested a scope in step S502.
[0105] 5509 (optional): Based on the authorization provided by the user 12, the authentication service device 200 fetches the indicated information from the home network operator of the user 12. Step S509 is thus only performed when step S598 was performed, and when having received authorization from the user 12 (as in step S508). S510: The authentication service device 200 provides an authentication result to the service provider device 100, telling whether the entity possessing the MSISDN has indeed managed to authenticate to the authentication service device 200. Optionally, if the service provider device 100 requested scope information, the authentication service device 200 provides information based on the user authorization in step S507.
[0106] The scope information can for each data element have an indication whether the data was obtained from the home network operator of the user 12 or if the user 12 themselves has provided the information. One example of user information that could be requested in the scope is whether the user 12 is over some age limit. This would be useful for services providing age restricted content. For example, the service provider device 100 could request a scope where one piece of information is whether the user is over a certain age, i.e., a true / false attribute. The home network operator of the user 12 might know the date of birth of the subscription owner and can based on that information deduce if the user 12 is over the indicated age limit and respond accordingly.
[0107] If the user 12 accessing the service provider device 100 has not yet register themselves at the authentication service device 200, i.e., the user 12 does not have credentials, registration at the authentication service device 200 can either be required to be done separately as described with reference to Figs. 5 and 6, or it can also be triggered by the user 12 accessing the service provider device 100 as in Figs. 7 and 8 with some modifications as will be disclosed next.
[0108] In step S503, if the authentication service device 200 finds that there are not any credentials registered for the MSISDN the authentication request from the service provider device 100 in step S502 acts as an implicit registration request from the user 12. This corresponds to step S401 in Fig. 6.
[0109] In step S504, the authentication service device 200 could use a special registration type code in the message indicating both that this relates to authentication (to the service provider device 100 identified by the identifier) and registration of credentials. The link provided by the authentication service device 200 to the network operator device 300 is to a registration interface at the authentication service device 200, similar to as in the registration described with reference to Figs. 5 and 6. In Step S505, the network operator device 300 includes the same code, or indication, as received from the authentication service device 200 that this relates to both authentication and registration. In addition to the identifier of the service provider device 100, the authentication service device 200 can (optionally) also include an additional parameter providing the identifier of the authentication service device 200 (similar to how the identifier of the service provider device 100 is provided during the registration).
[0110] In Step S506, instead of running authentication, registration is run. This also includes verifying that the user device 400a owns the private key corresponding to the public key being registered. Thus, the registration can act as the authentication. Alternatively, an additional authentication exchange can be performed after the registration.
[0111] In summary, according to at least some of the herein disclosed embodiments, instead of SMS-based 2FA, the service provider device 100 uses FIDO-SMS based 2FA to verify not only the subscription of the user 12, but the user 12 and the information shared by the user 12 too. This is achieved by the service provider device 100 delegating the authentication of the user 12 and their subscription to the network operator device 300 and the authentication service device 200, where the network operator device 300 sends an SMS message with authentication link to the user 12. With the link, the user 12 proves their authenticity via e.g., biometrics (using the FIDO protocol) and via an SMS message prove the ownership of the subscription. Additionally, the service provider device 100 can request for specific subscriber information, which the network operator device 300, could provide to the service provider device 100, with the user’s 12 consent.
[0112] According to at least some of the herein disclosed embodiments, FIDO and SMS 2FA are merged into one process, whereby both SMS messages and FIDO credentials are verified each time the user 12 is authenticated. One benefit is that the service provider device 100 does not need to support or even implement FIDO itself as it is the authentication service device 200 that handles the FIDO based authentication. This simplifies the service provider device 100.
[0113] It is possible to perform the authentication of the user 12 also without SMS messages. This would appear as using OpenlD merged with FIDO, i.e., with OpenlD using FIDO as authentication mechanism. With OpenlD the service provider device 100 would redirect the user 12 to the authentication service device 200 for authentication, and after FIDO based authentication has been performed by the authentication service device 200, the user 12 returns to the service provider device 100 with information that the service provider device 100 can use (by interacting with the authentication service device 200 before or after the authentication) for verifying that the authentication service device 200 indeed has authenticated the user 12.
[0114] Fig. 9 schematically illustrates, in terms of a number of structural units, the components of a service provider device 100 according to an embodiment. Processing circuitry 210 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210a (as in Fig. 12), e.g. in the form of a storage medium 230. The processing circuitry 210 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0115] Particularly, the processing circuitry 210 is configured to cause the service provider device 100 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 230 may store the set of operations, and the processing circuitry 210 maybe configured to retrieve the set of operations from the storage medium 230 to cause the service provider device 100 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus the processing circuitry 210 is thereby arranged to execute methods as herein disclosed.
[0116] The storage medium 230 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0117] The service provider device 100 may further comprise a communications (comm.) interface 220 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 220 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0118] The processing circuitry 210 controls the general operation of the service provider device 100 e.g. by sending data and control signals to the communications interface 220 and the storage medium 230, by receiving data and reports from the communications interface 220, and by retrieving data and instructions from the storage medium 230. Other components, as well as the related functionality, of the service provider device 100 are omitted in order not to obscure the concepts presented herein.
[0119] Fig. 10 schematically illustrates, in terms of a number of structural units, the components of an authentication service device 200 according to an embodiment. Processing circuitry 310 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210b (as in Fig. 12), e.g. in the form of a storage medium 330. The processing circuitry 310 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0120] Particularly, the processing circuitry 310 is configured to cause the authentication service device 200 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 330 may store the set of operations, and the processing circuitry 310 maybe configured to retrieve the set of operations from the storage medium 330 to cause the authentication service device 200 to perform the set of operations. The set of operations maybe provided as a set of executable instructions. Thus the processing circuitry 310 is thereby arranged to execute methods as herein disclosed.
[0121] The storage medium 330 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0122] The authentication service device 200 may further comprise a communications interface 320 for communications with other entities, functions, nodes, and devices, as in Fig. 1. As such the communications interface 320 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0123] The processing circuitry 310 controls the general operation of the authentication service device 200 e.g. by sending data and control signals to the communications interface 320 and the storage medium 330, by receiving data and reports from the communications interface 320, and by retrieving data and instructions from the storage medium 330. Other components, as well as the related functionality, of the authentication service device 200 are omitted in order not to obscure the concepts presented herein.
[0124] Fig. 11 schematically illustrates, in terms of a number of structural units, the components of a network operator device 300 according to an embodiment. Processing circuitry 410 is provided using any combination of one or more of a suitable central processing unit (CPU), multiprocessor, microcontroller, digital signal processor (DSP), etc., capable of executing software instructions stored in a computer program product 1210c (as in Fig. 12), e.g. in the form of a storage medium 430. The processing circuitry 410 may further be provided as at least one application specific integrated circuit (ASIC), or field programmable gate array (FPGA).
[0125] Particularly, the processing circuitry 410 is configured to cause the network operator device 300 to perform a set of operations, or steps, as disclosed above. For example, the storage medium 430 may store the set of operations, and the processing circuitry 410 may be configured to retrieve the set of operations from the storage medium 430 to cause the network operator device 300 to perform the set of operations. The set of operations may be provided as a set of executable instructions. Thus the processing circuitry 410 is thereby arranged to execute methods as herein disclosed.
[0126] The storage medium 430 may also comprise persistent storage, which, for example, can be any single one or combination of magnetic memory, optical memory, solid state memory or even remotely mounted memory.
[0127] The network operator device 300 may further comprise a communications interface 420 for communications with other entities, functions, nodes, and devices, as in Fig.
[0128] 1. As such the communications interface 420 may comprise one or more transmitters and receivers, comprising analogue and digital components.
[0129] The processing circuitry 410 controls the general operation of the network operator device 300 e.g. by sending data and control signals to the communications interface 420 and the storage medium 430, by receiving data and reports from the communications interface 420, and by retrieving data and instructions from the storage medium 430. Other components, as well as the related functionality, of the network operator device 300 are omitted in order not to obscure the concepts presented herein.
[0130] The service provider device 100, authentication service device 200, or network operator device 300 maybe provided as a respective standalone device or as a part of at least one further device. For example, the service provider device 100, authentication service device 200, or network operator device 300 maybe provided in a node of a radio access network or in a node of a core network. Alternatively, functionality of the service provider device 100, authentication service device 200, or network operator device 300 maybe distributed between at least two devices, or nodes. These at least two nodes, or devices, may either be part of the same network part (such as the radio access network or the core network) or may be spread between at least two such network parts. In general terms, instructions that are required to be performed in real time may be performed in a device, or node, operatively closer to the cell than instructions that are not required to be performed in real time. Thus, a first portion of the instructions performed by the service provider device 100, authentication service device 200, or network operator device 300 maybe executed in a respective first device, and a second portion of the of the instructions performed by the service provider device 100, authentication service device 200, or network operator device 300 maybe executed in a respective second device, and so on; the herein disclosed embodiments are not limited to any particular number of devices on which the instructions performed by the service provider device 100, authentication service device 200, or network operator device 300 maybe executed. Hence, the methods according to the herein disclosed embodiments are suitable to be performed by a service provider device 100, authentication service device 200, or network operator device 300 residing in a cloud computational environment. Therefore, although a single processing circuitry no, 210, 310 is illustrated in Figs. 9, 10, and 11 the processing circuitry no, 210, 310 maybe distributed among a plurality of devices, or nodes. The same applies to the computer programs 1220a, 1220b, 1220c of Fig. 12.
[0131] Fig. 12 shows one example of a computer program product 1210a, 1210b, 1210c comprising computer readable means 1230. On this computer readable means 1230, a computer program 1220a can be stored, which computer program 1220a can cause the processing circuitry 210 and thereto operatively coupled entities and devices, such as the communications interface 220 and the storage medium 230, to execute methods according to embodiments described herein. The computer program 1220a and / or computer program product 1210a may thus provide means for performing any steps of the service provider device 100 as herein disclosed. On this computer readable means 1230, a computer program 1220b can be stored, which computer program 1220b can cause the processing circuitry 310 and thereto operatively coupled entities and devices, such as the communications interface 320 and the storage medium 330, to execute methods according to embodiments described herein. The computer program 1220b and / or computer program product 1210b may thus provide means for performing any steps of the authentication service device 200 as herein disclosed. On this computer readable means 1230, a computer program 1220c can be stored, which computer program 1220c can cause the processing circuitry 410 and thereto operatively coupled entities and devices, such as the communications interface 420 and the storage medium 430, to execute methods according to embodiments described herein. The computer program 1220c and / or computer program product 1210c may thus provide means for performing any steps of the network operator device 300 as herein disclosed.
[0132] In the example of Fig. 12, the computer program product 1210a, 1210b, 1210c is illustrated as an optical disc, such as a CD (compact disc) or a DVD (digital versatile disc) or a Blu-Ray disc. The computer program product 1210a, 1210b, 1210c could also be embodied as a memory, such as a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM), or an electrically erasable programmable read-only memory (EEPROM) and more particularly as a non-volatile storage medium of a device in an external memory such as a USB (Universal Serial Bus) memory or a Flash memory, such as a compact Flash memory. Thus, while the computer program 1220a, 1220b, 1220c is here schematically shown as a track on the depicted optical disk, the computer program 1220a, 1220b, 1220c can be stored in any way which is suitable for the computer program product 1210a, 1210b, 1210c.
[0133] The inventive concept has mainly been described above with reference to a few embodiments. However, as is readily appreciated by a person skilled in the art, other embodiments than the ones disclosed above are equally possible within the scope of the inventive concept, as defined by the appended patent claims.
Claims
CLAIMS1. A method for authenticating a user (12) to a service in a communication system (10), wherein the method is performed by a service provider device (100), and wherein the method comprises: receiving (S102) an access request to a service from at least one user device (400a, 400b) of the user (12), the access request comprising an MSISDN of the at least one user device (400a, 400b) as identifier of the user (12); providing (S104) an authentication request and an identifier of the service provider device (100) to an authentication service device (200), the authentication request comprising the MSISDN; receiving (S106) an authentication result from the authentication service device (200) of authentication as performed by the authentication service device (200) with the at least one user device (400a, 400b); and enabling (S108) access to the service for the user (12) via the at least one user device (400a, 400b) only when the authentication result indicates successful authentication of the at least one user device (400a, 400b) with the authentication service device (200).
2. The method according to claim 1, wherein the authentication request as provided to the authentication service device (200) further comprises a request for information of the user (12).
3. The method according to claim 1 or 2, wherein the authentication result is of Fast Identity Online, FIDO, authentication as performed by the authentication service device (200) with the at least one user device (400a, 400b).
4. A method for authenticating a user (12) to a service in a communication system (10), wherein the method is performed by an authentication service device (200), and wherein the method comprises: receiving (S208) an authentication request for the user (12) from a service provider device (100) and an identifier of the service provider device (100), theauthentication request comprising an MSISDN of at least one user device (400a, 400b) of the user (12) as identifier of the user (12); identifying (S210), based on the MSISDN, a home network operator device (300) of the at least one user device (400a, 400b); triggering (S218) the home network operator device (300) to send a short text message service, SMS, message to the at least one user device (400a, 400b), the SMS message comprising the identifier of the service provider device (100), and a link to an authentication service for the user (12); performing (S220) authentication with the at least one user device (400a, 400b); and sending (S222) an authentication result of the authentication to the service provider device (100).
5. The method according to claim 4, wherein the authentication request further comprises a request for information of the user (12).
6. The method according to claim 4 or 5, wherein the method further comprises: verifying (S212) that the authentication request is received from the service provider device (100) identified by the identifier before triggering the home network operator device (300) to send the SMS message.
7. The method according to any of claims 4 to 6, wherein the method further comprises: searching (S214) for registration information associated with the MSISDN.
8. The method according to claim 7, wherein the method further comprises: identifying (S216) whether the registration information is associated with the service provider device (100) from which the authentication request was received.
9. The method according to any of claims 4 to 8, wherein the SMS message further indicates whether the service provider device (100) has been associated with the at least one user device (400a, 400b) or not.io. The method according to any of claims 4 to 9, wherein the method further comprises: receiving (S202) a registration request from the at least one user device (400a, 400b), the registration request comprising the MSISDN of the at least one user device (400a, 400b).
11. The method according to a combination of claim 7 and claim 10, wherein the SMS message is a second SMS message, and wherein, in case no registration information associated with the MSISDN is found, the method further comprises: triggering (S204) the home network operator device (300) to send a first SMS message to the at least one user device (400a, 400b), the first SMS message comprising an identifier of the authentication service device (200), an indication that the first SMS message is for an authentication credential registration request, and a link for the at least one user device (400a, 400b) to access for the registration to be performed.
12. The method according to claim 11, wherein the indication is that the first SMS message is for a Fast Identity Online, FIDO, authentication credential registration request, and the link is for the at least one user device (400a, 400b) to access for FIDO registration to be performed.
13. The method according to claim 11 or 12, wherein the method further comprises: performing (S206) registration with the at least one user device (400a, 400b) in accordance with the link in the first SMS message, wherein as part of performing the registration, the authentication service device (200) registers a public key of an asymmetric key pair for the at least one user device (400a, 400b).
14. The method according to claim 13, wherein the registration performed with the at least one user device (400a, 400b) is a Fast Identity Online, FIDO, registration.
15. The method according to any of claims 4 to 14, wherein the authentication performed with the at least one user device (400a, 400b) is a Fast Identity Online, FIDO, authentication.
16. A method for authenticating a user (12) to a service in a communication system (10), wherein the method is performed by a network operator device (300), and wherein the method comprises: receiving (S306) triggering from an authentication service device (200) for the network operator device (300) to send a short text message service, SMS, message to at least one user device (400a, 400b) of the user (12), the SMS message comprising an identifier of the service provider device (100), and a link to an authentication service for the user (12); and sending (S308) the SMS message to the at least one user device (400a, 400b).
17. The method according to claim 12, wherein the SMS message further indicates whether the service provider device (100) has been associated with the at least one user device (400a, 400b) or not.
18. The method according to claim 16 or 17, wherein the SMS message is a second SMS message, and wherein the method further comprises: receiving (S302) triggering from the authentication service device (200) for the network operator device (300) to send a first SMS message to the at least one user device (400a, 400b), the first SMS message comprising an identifier of the authentication service device (200), an indication that the first SMS message is for an authentication credential registration request, and a link for the user (12) to access for the registration to be performed; and sending (S304) the first SMS message to the at least one user device (400a, 400b).
19. The method according to claim 18, wherein the indication is that the first SMS message is for a Fast Identity Online, FIDO, authentication credential registration request, and the link is for the at least one user device (400a, 400b) to access for FIDO registration to be performed.
20. A service provider device (100) for authenticating a user (12) to a service in a communication system (10), the service provider device (100) comprising processingcircuitry (210), the processing circuitry being configured to cause the service provider device (100) to: receive an access request to a service from at least one user device (400a, 400b) of the user (12), the access request comprising an MSISDN of the at least one user device (400a, 400b) as identifier of the user (12); provide an authentication request and an identifier of the service provider device (100) to an authentication service device (200), the authentication request comprising the MSISDN; receive an authentication result from the authentication service device (200) of authentication as performed by the authentication service device (200) with the at least one user device (400a, 400b); and enable access to the service for the user (12) via the at least one user device (400a, 400b) only when the authentication result indicates successful authentication of the at least one user device (400a, 400b) with the authentication service device (200).
21. An authentication service device (200) for authenticating a user (12) to a service in a communication system (10), the authentication service device (200) comprising processing circuitry (310), the processing circuitry being configured to cause the authentication service device (200) to: receive an authentication request for the user (12) from a service provider device (100) and an identifier of the service provider device (100), the authentication request comprising an MSISDN of at least one user device (400a, 400b) of the user (12) as identifier of the user (12); identify, based on the MSISDN, a home network operator device (300) of the at least one user device (400a, 400b); trigger the home network operator device (300) to send a short text message service, SMS, message to the at least one user device (400a, 400b), the SMS message comprising the identifier of the service provider device (100), and a link to an authentication service for the user (12);perform authentication with the at least one user device (400a, 400b); and send an authentication result of the authentication to the service provider device (100).
22. A network operator device (300) for authenticating a user (12) to a service in a communication system (10), the network operator device (300) comprising processing circuitry (410), the processing circuitry being configured to cause the network operator device (300) to: receive triggering from an authentication service device (200) for the network operator device (300) to send a short text message service, SMS, message to at least one user device (400a, 400b) of the user (12), the SMS message comprising an identifier of the service provider device (100), and a link to an authentication service for the user (12); and send the SMS message to the at least one user device (400a, 400b).
23. A computer program (1220a) for authenticating a user (12) to a service in a communication system (10), the computer program comprising computer code which, when run on processing circuitry (210) of a service provider device (100), causes the service provider device (100) to: receive (S102) an access request to a service from at least one user device (400a, 400b) of the user (12), the access request comprising an MSISDN of the at least one user device (400a, 400b) as identifier of the user (12); provide (S104) an authentication request and an identifier of the service provider device (100) to an authentication service device (200), the authentication request comprising the MSISDN; receive (S106) an authentication result from the authentication service device (200) of authentication as performed by the authentication service device (200) with the at least one user device (400a, 400b); and enable (S108) access to the service for the user (12) via the at least one user device (400a, 400b) only when the authentication result indicates successfulauthentication of the at least one user device (400a, 400b) with the authentication service device (200).
24. A computer program (1220b) for authenticating a user (12) to a service in a communication system (10), the computer program comprising computer code which, when run on processing circuitry (310) of an authentication service device (200), causes the authentication service device (200) to: receive (S208) an authentication request for the user (12) from a service provider device (100) and an identifier of the service provider device (100), the authentication request comprising an MSISDN of at least one user device (400a, 400b) of the user (12) as identifier of the user (12); identify (S210), based on the MSISDN, a home network operator device (300) of the at least one user device (400a, 400b); trigger (S218) the home network operator device (300) to send a short text message service, SMS, message to the at least one user device (400a, 400b), the SMS message comprising the identifier of the service provider device (100), and a link to an authentication service for the user (12); perform (S220) authentication with the at least one user device (400a, 400b); and send (S222) an authentication result of the authentication to the service provider device (100).
25. A computer program (1220c) for authenticating a user (12) to a service in a communication system (10), the computer program comprising computer code which, when run on processing circuitry (410) of a network operator device (300), causes the network operator device (300) to: receive (S306) triggering from an authentication service device (200) for the network operator device (300) to send a short text message service, SMS, message to at least one user device (400a, 400b) of the user (12), the SMS message comprising an identifier of the service provider device (100), and a link to an authentication service for the user (12); andsend (S308) the SMS message to the at least one user device (400a, 400b).
26. A computer program product (1210a, 1210b, 1210c) comprising a computer program (1220a, 1220b, 1220c) according to at least one of claims 23, 24 and 25, and a computer readable storage medium (1230) on which the computer program is stored.
Citation Information
Patent Citations
FIDO remote controller, television payment system and television payment method
CN105657468A
Apparatus, method and computer program product for use in authenticating a user
GB2547231A
System and method for authentication of a mobile device
US20200210988A1
Systems and methods for authenticating access to a service by a mobile device
US20230254306A1