A survey on multi-factor authentication for online banking in the wild

被引:37
|
作者
Sinigaglia, Federico [1 ,2 ]
Carbone, Roberto [2 ]
Costa, Gabriele [3 ]
Zannone, Nicola [4 ]
机构
[1] Univ Genoa, DIBRIS, Via Opera Pia 13, I-16145 Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] IMT Sch Adv Studies, SysMA Unit, Piazza S Francesco 19, I-55100 Lucca, Italy
[4] Eindhoven Univ Technol, Eindhoven, Netherlands
基金
欧盟地平线“2020”;
关键词
Multi-factor authentication; Online banking; Mobile banking; Remote payments; Legal compliance; Threat models; Field study; SECURITY;
D O I
10.1016/j.cose.2020.101745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:30
相关论文
共 50 条
  • [41] Secure Online Game Play with Token: A Case Study in the Design of Multi-factor Authentication Device
    Yamane, Shinji R.
    HUMAN CENTERED DESIGN (HCD), 2011, 6776 : 597 - 605
  • [42] A Multi-Factor Authentication Framework for Secure Access to Blockchain
    Sahan, Sercan
    Ekici, Adil Furkan
    Bahtiyar, Serif
    PROCEEDINGS OF THE 2019 5TH INTERNATIONAL CONFERENCE ON COMPUTER AND TECHNOLOGY APPLICATIONS (ICCTA 2019), 2019, : 160 - 164
  • [43] A PATTERN-BASED MULTI-FACTOR AUTHENTICATION SYSTEM
    Pankhuri
    Sinha, Akash
    Shrivastava, Gulshan
    Kumar, Prabhat
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2019, 20 (01): : 101 - 112
  • [44] CCTV-Based Multi-Factor Authentication System
    Kwon, Byoung-Wook
    Sharma, Pradip Kumar
    Park, Jong-Hyuk
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2019, 15 (04): : 904 - 919
  • [45] Multi-Factor Biometrics for Authentication: A False Sense of Security
    Al-Assam, Hisham
    Sellahewa, Harin
    Jassim, Sabah
    MM&SEC 2010: 2010 ACM SIGMM MULTIMEDIA AND SECURITY WORKSHOP, PROCEEDINGS, 2010, : 81 - 87
  • [46] A lightweight multi-factor mobile user authentication scheme
    Sun, Jianguo
    Zhong, Qi
    Kou, Liang
    Wang, Wenshan
    Da, Qingan
    Lin, Yun
    IEEE INFOCOM 2018 - IEEE CONFERENCE ON COMPUTER COMMUNICATIONS WORKSHOPS (INFOCOM WKSHPS), 2018, : 831 - 836
  • [47] On the Security of Multi-Factor Authentication: Several Instructive Examples
    Huang, Yun
    Xue, Weijia
    Huang, Geshi
    Lai, Xuejia
    PROCEEDINGS OF THE 2013 INTERNATIONAL CONFERENCE ON ADVANCED COMPUTER SCIENCE AND ELECTRONICS INFORMATION (ICACSEI 2013), 2013, 41 : 685 - 687
  • [48] A review of multi-factor authentication in the Internet of Healthcare Things
    Suleski, Tance
    Ahmed, Mohiuddin
    Yang, Wencheng
    Wang, Eugene
    DIGITAL HEALTH, 2023, 9
  • [49] An Adaptive Approach Towards the Selection of Multi-factor Authentication
    Nag, Abhijit Kumar
    Roy, Arunava
    Dasgupta, Dipankar
    2015 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI), 2015, : 463 - 472
  • [50] A Modular Framework for Multi-Factor Authentication and Key Exchange
    Fleischhacker, Nils
    Manulis, Mark
    Azodi, Amir
    SECURITY STANDARDISATION RESEARCH, SSR 2014, 2014, 8893 : 190 - 214