首页> 外文会议>International Joint Conference on e-Business and Telecommunications >User-friendly Manual Transfer of Authenticated Online Banking Transaction Data - A Case Study that Applies the What You Enter Is What You Sign Transaction Authorization Information Scheme
【24h】

User-friendly Manual Transfer of Authenticated Online Banking Transaction Data - A Case Study that Applies the What You Enter Is What You Sign Transaction Authorization Information Scheme

机译:用户友好的手动传输经过身份验证的在线银行交易数据 - 一个案例研究,适用您输入的内容是您签署交易授权信息方案的内容

获取原文

摘要

Online banking relies on user-owned home computers and mobile devices, all vulnerable to man-in-the-middle attacks which are used to steal money from bank accounts. Banks mitigate this by letting users verify information that originates from these untrusted devices. This is not user-friendly since the user has to process the same information twice. It also makes the user an unnecessary critical factor and risk in the security process. This paper concerns a case study of an information scheme which allows the user to enter critical information in a trusted device, which adds data necessary for the recipient to verify its integrity and authenticity. The output of the device is a code that contains the information and the additional verification data, which the user enters in the computer used for online banking. With this, the bank receives the information in a secure manner without requiring an additional check by the user, since the data is protected from the moment the user entered it in the trusted device. This proposal shows that mundane tasks for the user in online banking can be automated, which improves both security and usability.
机译:网上银行依赖于用户拥有的家庭计算机和移动设备,所有人都容易受到中间人的攻击,这些攻击被用来窃取银行账户的资金。银行通过让用户验证源自这些不受信任的设备的信息来减轻这一点。这不是用户友好的,因为用户必须处理相同的信息两次。它还使用户成为安全过程中不必要的关键因素和风险。本文涉及一种信息方案的案例研究,该信息方案允许用户在可信设备中输入关键信息,这增加了收件人验证其完整性和真实性所需的数据。设备的输出是包含信息和附加验证数据的代码,该数据在用于在线银行的计算机中进入。由此,存储器以安全的方式接收信息而不需要用户额外的检查,因为数据受到用户在受信任设备中输入的那一刻受到保护。该提议表明,在线银行业务中的用户可以自动化,这提高了安全性和可用性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号