【24h】

Short Paper: How to Attack PSD2 Internet Banking

机译:简短论文:如何攻击PSD2网上银行

获取原文

摘要

Internet banking security is set to take a major step forward: On September 14, 2019, the Regulatory Technical Standards of the Revised Payment Service Directive (PSD2) are going to be effective within the European Union and the European Economic Area. This regulation makes two widely demanded transaction security properties mandatory: two-factor authentication, and the dynamic linking of the authentication code to the transaction's beneficiary and amount (full transaction authentication). Even though the regulation is undoubtedly a positive development from a security perspective, it does not account for all the technical and human weak points involved in the transaction process. In this paper, we look at a series of attacks targeting online and mobile banking that are possible even in a post-PSD2 era. Despite the regulatory motivation of this work, the presented issues and suggestions to address them are likely to be universal for internet banking in general.
机译:互联网银行的安全性将迈出重要的一步:2019年9月14日,修订后的支付服务指令(PSD2)的监管技术标准将在欧盟和欧洲经济区生效。该规定使两个广泛要求的交易安全属性成为强制性:两要素身份验证,以及身份验证代码与交易的受益人和金额的动态链接(完全交易身份验证)。即使从安全的角度来看,该法规无疑是积极的发展,但它并不能解决交易过程中涉及的所有技术和人员薄弱环节。在本文中,我们研究了一系列针对在线和移动银行的攻击,这些攻击甚至在后PSD2时代也可能发生。尽管有这项工作的监管动机,但提出的问题和解决这些问题的建议对于整个互联网银行来说可能是普遍的。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号