Tech-
invite
3GPP
space
IETF
space
21
22
23
24
25
26
27
28
29
31
32
33
34
35
36
37
38
4‑5x
Content for
TR 33.995
Word version: 18.0.0
1…
7…
7
Solutions for OpenID - 3GPP interworking
7.1
General
7.2
GBA Lite
7.3
Third Party IdP binding for two-factor authentication
7.4
Using user consent for GBA and SSO
7.5
3rd party SSO identity mapping
8
Conclusions
$
Change History
7
Solutions for OpenID - 3GPP interworking
p. 7
7.1
General
p. 7
7.2
GBA Lite
p. 7
7.2.1
Rationale for solution
p. 7
7.2.2
Solution description
p. 8
7.2.2.1
Architecture
p. 8
7.2.2.2
BSF Implementation optimizations
p. 8
7.2.2.3
Message Flow
p. 9
7.2.3
Evaluation against SA1 requirements
p. 10
7.3
Third Party IdP binding for two-factor authentication
p. 10
7.3.1
Rationale for solution
p. 10
7.3.3
Solution 1 description
p. 12
7.3.3.1
General
p. 12
7.3.3.2
Example solutions for two factor authentication
p. 14
7.3.4
Solution 2 description
p. 18
7.3.4.1
Solution based on OpenID-GBA interworking where OTT performs username/password authentication
p. 18
7.3.4.2
Solution based on OpenID-GBA interworking where MNO performs both GBA and username/password authentication
p. 19
7.3.5
Evaluation against SA1 requirements
p. 21
7.4
Using user consent for GBA and SSO
p. 23
7.4.1
Rationale for solution
p. 23
7.4.2
Solution description
p. 23
7.4.2.1
General
p. 23
7.4.2.2
GBA_ME-based solution
p. 24
7.4.2.3
GBA_U-based solution
p. 25
7.4.3
Functional Architecture
p. 27
7.4.4
Evaluation against SA1 requirements
p. 29
7.5
3rd party SSO identity mapping
p. 31
7.5.1
Rationale for solution
p. 31
7.5.2
Solution description
p. 31
7.5.3
Evaluation against SA1 requirements
p. 33
8
Conclusions
p. 35
$
Change History
p. 36