A survey on multi-factor authentication for online banking in the wild

被引:32
|
作者
Sinigaglia, Federico [1 ,2 ]
Carbone, Roberto [2 ]
Costa, Gabriele [3 ]
Zannone, Nicola [4 ]
机构
[1] Univ Genoa, DIBRIS, Via Opera Pia 13, I-16145 Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] IMT Sch Adv Studies, SysMA Unit, Piazza S Francesco 19, I-55100 Lucca, Italy
[4] Eindhoven Univ Technol, Eindhoven, Netherlands
基金
欧盟地平线“2020”;
关键词
Multi-factor authentication; Online banking; Mobile banking; Remote payments; Legal compliance; Threat models; Field study; SECURITY;
D O I
10.1016/j.cose.2020.101745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges. (C) 2020 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:30
相关论文
共 50 条
  • [1] Multi-Factor Authentication Method for Online Banking Services in South Africa
    Moepi, Glen L.
    Mathonsi, Topside E.
    INTERNATIONAL CONFERENCE ON ELECTRICAL, COMPUTER AND ENERGY TECHNOLOGIES (ICECET 2021), 2021, : 146 - 150
  • [2] Multi-Factor Authentication: A Survey
    Ometov, Aleksandr
    Bezzateev, Sergey
    Makitalo, Niko
    Andreev, Sergey
    Mikkonen, Tommi
    Koucheryavy, Yevgeni
    CRYPTOGRAPHY, 2018, 2 (01) : 1 - 31
  • [3] Internet Banking Login with Multi-Factor Authentication
    Boonkrong, Sirapat
    KSII TRANSACTIONS ON INTERNET AND INFORMATION SYSTEMS, 2017, 11 (01): : 511 - 535
  • [4] Trusted framework for online banking in public cloud using multi-factor authentication and privacy protection gateway
    Nagaraju, Sabout
    Parthiban, Latha
    JOURNAL OF CLOUD COMPUTING-ADVANCES SYSTEMS AND APPLICATIONS, 2015, 4 : 1 - 23
  • [5] A Systematic Survey of Multi-Factor Authentication for Cloud Infrastructure
    Otta, Soumya Prakash
    Panda, Subhrakanta
    Gupta, Maanak
    Hota, Chittaranjan
    FUTURE INTERNET, 2023, 15 (04):
  • [6] Multi-observed Multi-factor Authentication: A Multi-factor Authentication Using Single Credential
    Nozaki, Shinnosuke
    Serizawa, Ayumi
    Yoshihira, Mizuho
    Fujita, Masahiro
    Shibata, Yoichi
    Yamanaka, Tadakazu
    Matsuda, Nori
    Ohki, Tetsushi
    Nishigaki, Masakatsu
    ADVANCES IN NETWORK-BASED INFORMATION SYSTEMS, NBIS-2022, 2022, 526 : 201 - 211
  • [7] A Survey on the Security in Cyber Physical System with Multi-Factor Authentication
    Sain, Mangal
    Normurodov, Oloviddin
    Hong, Chen
    Hui, Kueh Lee
    2021 23RD INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT 2021): ON-LINE SECURITY IN PANDEMIC ERA, 2021, : 1322 - +
  • [8] A Survey on the Security in Cyber Physical System with Multi-Factor Authentication
    Sain, Mangal
    Normurodov, Oloviddin
    Hong, Chen
    Hui, Kueh Lee
    2022 24TH INTERNATIONAL CONFERENCE ON ADVANCED COMMUNICATION TECHNOLOGY (ICACT): ARITIFLCIAL INTELLIGENCE TECHNOLOGIES TOWARD CYBERSECURITY, 2022, : 1322 - +
  • [9] Multi-Factor Authentication as a Service
    Shah, Yogendra
    Choyi, Vinod
    Schmidt, Andreas U.
    Subramanian, Lakshmi
    2015 3RD IEEE INTERNATIONAL CONFERENCE ON MOBILE CLOUD COMPUTING, SERVICES, AND ENGINEERING (MOBILECLOUD 2015), 2015, : 144 - 150
  • [10] MULTI-FACTOR AUTHENTICATION MODELLING
    Dostalek, L.
    Safarik, J.
    RADIO ELECTRONICS COMPUTER SCIENCE CONTROL, 2020, (02) : 106 - 116