Both DDA and OBS states that the client should be authenticated via a Client certs. This may be ok for a web based clients, but probably quickly gets out of control if the client is a mobile app. You probably do not to want to manage billions of certificates.

