A survey on multi-factor authentication for online banking in the wild

被引:32
|
作者
Sinigaglia, Federico [1 ,2 ]
Carbone, Roberto [2 ]
Costa, Gabriele [3 ]
Zannone, Nicola [4 ]
机构
[1] Univ Genoa, DIBRIS, Via Opera Pia 13, I-16145 Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] IMT Sch Adv Studies, SysMA Unit, Piazza S Francesco 19, I-55100 Lucca, Italy
[4] Eindhoven Univ Technol, Eindhoven, Netherlands
基金
欧盟地平线“2020”;
关键词
Multi-factor authentication; Online banking; Mobile banking; Remote payments; Legal compliance; Threat models; Field study; SECURITY;
D O I
10.1016/j.cose.2020.101745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:30
相关论文
共 50 条
  • [31] A Systematic Review on Multi-Factor Authentication Framework
    Syahreen, Muhammad
    Hafizah, Noor
    Maarop, Nurazean
    Maslinan, Mayasarah
    INTERNATIONAL JOURNAL OF ADVANCED COMPUTER SCIENCE AND APPLICATIONS, 2024, 15 (05) : 1043 - 1050
  • [32] Multi-Factor Authentication Using Threshold Cryptography
    Venukumar, Vishnu
    Pathari, Vinod
    2016 INTERNATIONAL CONFERENCE ON ADVANCES IN COMPUTING, COMMUNICATIONS AND INFORMATICS (ICACCI), 2016, : 1694 - 1698
  • [33] Privacy preserving multi-factor authentication with biometrics
    Bhargav-Spantzel, Abhilasha
    Squicciarini, Anna
    Modi, Shimon
    Young, Matthew
    Bertino, Elisa
    Elliott, Stephen
    JOURNAL OF COMPUTER SECURITY, 2007, 15 (05) : 529 - 560
  • [34] Multi-factor authentication for shibboleth identity providers
    de Mello, Emerson Ribeiro
    Wangham, Michelle Silva
    Loli, Samuel Bristot
    da Silva, Carlos Eduardo
    da Silva, Gabriela Cavalcanti
    de Chaves, Shirlei Aparecida
    Loli, Bruno Bristot
    JOURNAL OF INTERNET SERVICES AND APPLICATIONS, 2020, 11 (01)
  • [35] Using Multi-Factor Authentication for Online Account Security: Examining the Influence of Anticipated Regret
    Ogbanufe, Obi M.
    Baham, Corey
    INFORMATION SYSTEMS FRONTIERS, 2023, 25 (02) : 897 - 916
  • [36] Using Multi-Factor Authentication for Online Account Security: Examining the Influence of Anticipated Regret
    Obi M. Ogbanufe
    Corey Baham
    Information Systems Frontiers, 2023, 25 : 897 - 916
  • [37] Multi-channel Authentication for Online Banking
    AlFairuz, Mohamed
    SUSTAINABLE ECONOMIC GROWTH, EDUCATION EXCELLENCE, AND INNOVATION MANAGEMENT THROUGH VISION 2020, VOLS I-VII, 2017, : 1959 - 1968
  • [38] Multi-Factor Authentication with OpenId in Virtualized Environments
    Alves, J. M.
    Rodrigues, T. G.
    Beserra, D. W.
    Fonseca, J. C.
    Endo, P. T.
    Kelner, J.
    IEEE LATIN AMERICA TRANSACTIONS, 2017, 15 (03) : 528 - 533
  • [39] Robust Multi-Factor Authentication for Fragile Communications
    Huang, Xinyi
    Xiang, Yang
    Bertino, Elisa
    Zhou, Jianying
    Xu, Li
    IEEE TRANSACTIONS ON DEPENDABLE AND SECURE COMPUTING, 2014, 11 (06) : 568 - 581
  • [40] Multi-factor authentication model based on multipurpose speech watermarking and online speaker recognition
    Mohammad Ali Nematollahi
    Hamurabi Gamboa-Rosales
    Francisco J. Martinez-Ruiz
    Jose I. De la Rosa-Vargas
    S. A. R. Al-Haddad
    Mansour Esmaeilpour
    Multimedia Tools and Applications, 2017, 76 : 7251 - 7281