A survey on multi-factor authentication for online banking in the wild

被引:32
|
作者
Sinigaglia, Federico [1 ,2 ]
Carbone, Roberto [2 ]
Costa, Gabriele [3 ]
Zannone, Nicola [4 ]
机构
[1] Univ Genoa, DIBRIS, Via Opera Pia 13, I-16145 Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] IMT Sch Adv Studies, SysMA Unit, Piazza S Francesco 19, I-55100 Lucca, Italy
[4] Eindhoven Univ Technol, Eindhoven, Netherlands
基金
欧盟地平线“2020”;
关键词
Multi-factor authentication; Online banking; Mobile banking; Remote payments; Legal compliance; Threat models; Field study; SECURITY;
D O I
10.1016/j.cose.2020.101745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges. (C) 2020 Elsevier Ltd. All rights reserved.
引用
下载
收藏
页数:30
相关论文
共 50 条
  • [21] Multi-Factor Authentication to Systems Login
    ALSaleem, Bandar Omar
    Alshoshan, Abdullah, I
    2021 IEEE NATIONAL COMPUTING COLLEGES CONFERENCE (NCCC 2021), 2021, : 1092 - 1095
  • [22] Commentary: Multi-factor identification and authentication
    Morrison, Rodger
    INFORMATION SYSTEMS MANAGEMENT, 2007, 24 (04) : 331 - 332
  • [23] A Survey of Authentication and Communications Security in Online Banking
    Kiljan, Sven
    Simoens, Koen
    De Cock, Danny
    Van Eekelen, Marko
    Vranken, Harald
    ACM COMPUTING SURVEYS, 2017, 49 (04)
  • [24] Multi-factor Authentication: A Survey and Challenges in V2X Applications
    Ometov, Aleksandr
    Bezzateev, Sergey
    2017 9TH INTERNATIONAL CONGRESS ON ULTRA MODERN TELECOMMUNICATIONS AND CONTROL SYSTEMS AND WORKSHOPS (ICUMT), 2017, : 129 - 136
  • [25] Explaining the Workings Principle of Cloud-based Multi-factor Authentication Architecture on Banking Sectors
    Bose, Rajesh
    Chakraborty, Srabanti
    Roy, Sandip
    PROCEEDINGS 2019 AMITY INTERNATIONAL CONFERENCE ON ARTIFICIAL INTELLIGENCE (AICAI), 2019, : 764 - 768
  • [26] Database Multi-factor Authentication via Pluggable Authentication Modules
    Hamilton, Cameron
    Olmstead, Aspen
    2017 12TH INTERNATIONAL CONFERENCE FOR INTERNET TECHNOLOGY AND SECURED TRANSACTIONS (ICITST), 2017, : 367 - 368
  • [27] Multi-factor authentication using threshold cryptography
    1694, Institute of Electrical and Electronics Engineers Inc., United States
  • [28] Multi-Factor Authentication in Key Management Systems
    de Souza, Rick Lopes
    Lung, Lau Cheuk
    Custodio, Ricardo Felipe
    2013 12TH IEEE INTERNATIONAL CONFERENCE ON TRUST, SECURITY AND PRIVACY IN COMPUTING AND COMMUNICATIONS (TRUSTCOM 2013), 2013, : 746 - 752
  • [29] Multi-factor authentication model based on multipurpose speech watermarking and online speaker recognition
    Nematollahi, Mohammad Ali
    Gamboa-Rosales, Hamurabi
    Martinez-Ruiz, Francisco J.
    De la Rosa-Vargas, Jose I.
    Al-Haddad, S. A. R.
    Esmaeilpour, Mansour
    MULTIMEDIA TOOLS AND APPLICATIONS, 2017, 76 (05) : 7251 - 7281
  • [30] A Method of Risk Assessment for Multi-Factor Authentication
    Kim, Jae-Jung
    Hong, Seng-Phil
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2011, 7 (01): : 187 - 198