首页> 外文会议>6th Symposium on usable privacy and security 2010 >Usably Secure, Low-Cost Authentication for Mobile Banking
【24h】

Usably Secure, Low-Cost Authentication for Mobile Banking

机译:适用于移动银行的安全,低成本身份验证

获取原文
获取原文并翻译 | 示例
获取外文期刊封面目录资料

摘要

This paper explores user authentication schemes for banking systems implemented over mobile phone networks in the developing world. We analyze an authentication scheme currently deployed by an Indian mobile banking service provider which uses a combination of PINs and printed codebooks for authenticating users. As a first step, we report security weaknesses in that scheme and show that it is susceptible to easy and efficient PIN recovery attacks. We then propose a new scheme which offers better secrecy of PINs, while still maintaining the simplicity and scalability advantages of the original scheme. Finally, we investigate the usability of the two schemes with a sample of 34 current and potential customers of the banking system. Our findings suggest that the new scheme is more efficient, less susceptible to human error and better preferred by the target consumers.
机译:本文探讨了在发展中国家通过移动电话网络实现的银行系统的用户身份验证方案。我们分析了印度移动银行服务提供商当前部署的认证方案,该方案使用PIN和印刷密码本的组合来认证用户。第一步,我们报告该方案中的安全漏洞,并表明该方案容易受到简单而有效的PIN恢复攻击。然后,我们提出了一种新的方案,该方案可提供更好的PIN保密性,同时仍保持原始方案的简单性和可伸缩性优势。最后,我们以银行系统的34位当前和潜在客户为样本,研究了这两种方案的可用性。我们的研究结果表明,新方案效率更高,不易受到人为错误的影响,并且受到目标消费者的青睐。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号