Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Enhancement of blockchainPublicAddress belongs to the user whose phoneNumber is indicated to set-up the binding relationship #52

Open
PedroDiez opened this issue May 2, 2024 · 3 comments
Labels
enhancement New feature or request

Comments

@PedroDiez
Copy link
Collaborator

Problem description
When generating a binding process bindBlockchainPublicAddress, Telco Operators have mechanism to enforce the phoneNumber indicated is the one that applied by means of AuthN/AuthZ (checking Access Token is issued for that phoneNumber). However, there is no enforcement about the blockchainPublicAddress indicated really belongs to the user (i.e. person) under such phoneNumber.

A solution is needed for this enforcement

Possible evolution
Discussed within the issue

Alternative solution
Not indicated

Additional context
Details to be discussed under this issue

@PedroDiez PedroDiez added the enhancement New feature or request label May 2, 2024
@PedroDiez
Copy link
Collaborator Author

2024-05-02:

@grgpapadopoulos
Copy link
Collaborator

Hi Pedro & team,
I propose a solution to ensure the owner of the blockchainPublicAddress is the user binding their MSISDN,
perform a verification, where it is required, the user to sign a message with their private key to verify control over the blockchain address.

@PedroDiez
Copy link
Collaborator Author

PedroDiez commented May 30, 2024

Summary about discussion so far:

  • Background topic is to ensure that the binding perfomed is trusted (MSISDN-Blockchain relation is verified)
  • In TEF there are currently solutions (applied at App/Service) on beforehand, previously to attempt binding registration
  • DT indicates a solution in CAMARA/OGW should consider a way to allow for such a process
  • Talking during the meeting, need to be discussed further, could be options like sending an SMS to the user in order to inform him to about such a binding so as her/him can confirm that association.
  • Also point out the relevance of a compliance of the procedure with legality/privacy

@PedroDiez PedroDiez changed the title Enhancement of blockchainPublicAddress belongs to the user whose phoneNumber is indicated to set-tp the binding relationship Enhancement of blockchainPublicAddress belongs to the user whose phoneNumber is indicated to set-up the binding relationship Nov 7, 2024
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
enhancement New feature or request
Projects
None yet
Development

No branches or pull requests

2 participants