Mobile Connect is a mobile phone-based strong authentication solution offered through mobile network operators (MNOs) including O2, Orange, Swisscom, Telefónica, Telia Carrier, and Vodafone, and is currently available in Finland, France, Italy, Spain, Switzerland, and the UK. It can be deployed relatively easily because it is based on open-standard SDKs, and it is positioned as a more secure, user-friendly alternative to weak passwords—an important point given that compromised passwords are a leading vector in data breaches.
The EU’s PSD2 directive takes effect in 2018 and requires strong customer authentication (SCA), defined as combining factors such as something you know, have, and are. PSD2 also creates new roles—Payment Initiation Service Providers (PISPs) and Account Information Service Providers (AISPs)—that can expand competition beyond traditional banks. As these entities increasingly deliver services via mobile apps, they will need strong, mobile-friendly SCA; many banks have reportedly not yet begun deploying solutions to meet this requirement.
Mobile Connect works by registering a user’s phone with the operator, creating a binding between identity and device to satisfy “something you have.” For higher assurance, users can set a device PIN; PIN validation occurs locally on the device and is not transmitted. With user consent, additional identity attributes (e.g., name, address, date of birth, national ID) can be shared. The system supports Levels of Assurance (LOA) 2 and 3 and provides passwordless access across compliant sites. It also includes recovery handling: if a phone is lost or replaced, the MNO deactivates the binding. Architecturally, it resembles OAuth2 and can use OpenID Connect structures, supports multiple authenticator classes (SMS+URL, USSD “mobile push,” SIM applet), and uses a challenge-response approach that limits attribute sharing and supports privacy and GDPR-aligned practices.
See All Locations
See All Locations