A survey on multi-factor authentication for online banking in the wild

被引:32
|
作者
Sinigaglia, Federico [1 ,2 ]
Carbone, Roberto [2 ]
Costa, Gabriele [3 ]
Zannone, Nicola [4 ]
机构
[1] Univ Genoa, DIBRIS, Via Opera Pia 13, I-16145 Genoa, Italy
[2] Fdn Bruno Kessler, Secur & Trust Res Unit, Trento, Italy
[3] IMT Sch Adv Studies, SysMA Unit, Piazza S Francesco 19, I-55100 Lucca, Italy
[4] Eindhoven Univ Technol, Eindhoven, Netherlands
基金
欧盟地平线“2020”;
关键词
Multi-factor authentication; Online banking; Mobile banking; Remote payments; Legal compliance; Threat models; Field study; SECURITY;
D O I
10.1016/j.cose.2020.101745
中图分类号
TP [自动化技术、计算机技术];
学科分类号
0812 ;
摘要
In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges. (C) 2020 Elsevier Ltd. All rights reserved.
引用
收藏
页数:30
相关论文
共 50 条
  • [41] Secure Online Game Play with Token: A Case Study in the Design of Multi-factor Authentication Device
    Yamane, Shinji R.
    HUMAN CENTERED DESIGN (HCD), 2011, 6776 : 597 - 605
  • [42] A Multi-Factor Authentication Framework for Secure Access to Blockchain
    Sahan, Sercan
    Ekici, Adil Furkan
    Bahtiyar, Serif
    PROCEEDINGS OF THE 2019 5TH INTERNATIONAL CONFERENCE ON COMPUTER AND TECHNOLOGY APPLICATIONS (ICCTA 2019), 2019, : 160 - 164
  • [43] A PATTERN-BASED MULTI-FACTOR AUTHENTICATION SYSTEM
    Pankhuri
    Sinha, Akash
    Shrivastava, Gulshan
    Kumar, Prabhat
    SCALABLE COMPUTING-PRACTICE AND EXPERIENCE, 2019, 20 (01): : 101 - 112
  • [44] CCTV-Based Multi-Factor Authentication System
    Kwon, Byoung-Wook
    Sharma, Pradip Kumar
    Park, Jong-Hyuk
    JOURNAL OF INFORMATION PROCESSING SYSTEMS, 2019, 15 (04): : 904 - 919
  • [45] A review of multi-factor authentication in the Internet of Healthcare Things
    Suleski, Tance
    Ahmed, Mohiuddin
    Yang, Wencheng
    Wang, Eugene
    DIGITAL HEALTH, 2023, 9
  • [46] An Adaptive Approach Towards the Selection of Multi-factor Authentication
    Nag, Abhijit Kumar
    Roy, Arunava
    Dasgupta, Dipankar
    2015 IEEE SYMPOSIUM SERIES ON COMPUTATIONAL INTELLIGENCE (IEEE SSCI), 2015, : 463 - 472
  • [47] A Modular Framework for Multi-Factor Authentication and Key Exchange
    Fleischhacker, Nils
    Manulis, Mark
    Azodi, Amir
    SECURITY STANDARDISATION RESEARCH, SSR 2014, 2014, 8893 : 190 - 214
  • [48] Multi-factor EEG-based User Authentication
    Tien Pham
    Ma, Wanli
    Dat Tran
    Phuoc Nguyen
    Dinh Phung
    PROCEEDINGS OF THE 2014 INTERNATIONAL JOINT CONFERENCE ON NEURAL NETWORKS (IJCNN), 2014, : 4029 - 4034
  • [49] Biometric multi-factor authentication: On the usability of the FingerPIN scheme
    Marasco, Emanuela
    Albanese, Massimiliano
    Patibandla, Venkata Vamsi Ram
    Vurity, Anudeep
    Sriram, Sumanth Sai
    SECURITY AND PRIVACY, 2023, 6 (01)
  • [50] Framework for Multi-factor Authentication with Dynamically Generated Passwords
    Chenchev, Ivaylo
    ADVANCES IN INFORMATION AND COMMUNICATION, FICC, VOL 2, 2023, 652 : 563 - 576