+ All Categories
Home > Documents > Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Date post: 18-Jan-2016
Category:
Upload: avice-stone
View: 221 times
Download: 0 times
Share this document with a friend
Popular Tags:
21
Usably Secure, Low-Cost Usably Secure, Low-Cost Authentication for Mobile Authentication for Mobile Banking Banking Saurabh Gupta Sandeep Kumar Gupta
Transcript
Page 1: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Usably Secure, Low-Cost Usably Secure, Low-Cost Authentication for Mobile Authentication for Mobile BankingBanking

Saurabh GuptaSandeep Kumar Gupta

Page 2: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Need For Mobile BankingNeed For Mobile Banking

People need money on the run. Banks provide security, interest.

Page 3: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Use Cases – Buying Use Cases – Buying SomethingSomething

Page 4: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Use Case - Depositing Use Case - Depositing MoneyMoney

Page 5: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Use Case – Withdrawing Use Case – Withdrawing MoneyMoney

Page 6: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

What Security ?What Security ?

Page 7: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

How is it secured on How is it secured on Mars ?Mars ?

Application level encryption Typically have an application implementing the favorite encryption scheme. Provides end to end encryption.

Possible because Can ask people to install and use them. Phones are powerful enough to run them.

Page 8: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Challenges on EarthChallenges on Earth Fundamentally, GSM channel is weakly encrypted. Can not rely on network layer encryption. Need for end to end encryption Can not install applications on user ends.

Page 9: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Mobile Banking In GeneralMobile Banking In Generalo Cell Phoneo 2 factor authenticationo 4 digit pino A codebook with synchronized security tokens.

Page 10: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

 

Old Scheme New Scheme

Overview of 2 schemesOverview of 2 schemes

Both use 2 factor authentication schemes.

Page 11: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

 

Question: Impersonator?

1.                         2.                            3.

Security AnalysisSecurity Analysis4 different types of attacks considered.

• Pin Recovery• Type 0: Impersonator gets phone• Type 1: Impersonator gets phone and codebook• Type 2: Impersonator gets phone and PIN

Page 12: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Security AnalysisSecurity Analysis• Pin Recovery• Type 0: Impersonator gets phone• Type 1: Impersonator gets phone and codebook• Type 2: Impersonator gets phone and PIN

Page 13: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

User StudyUser Study Ethnography

15 people from Delhi

19 people from Bihar

Composition 8 agents 13 existing users 13 potential users

Tasks Plain PIN entry EKO signature formulation

New signature formulation

Page 14: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Parameters RecordedParameters Recorded

Page 15: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

ResultsResults

Page 16: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

ResultsResults

Page 17: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

ResultsResults

Page 18: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

DiscussionDiscussion Effect of increased cognitive effort. Effect of entering only 4 digits instead of 10. Statistical significance of results

Page 19: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

User Case StudiesUser Case Studies  What is required to validate your claim?

• from the perspective of paper publishing?o Novelty of the idea.  o Quick papers for promotion.

•  for proving soundly?o Acceptability of the idea.

Page 20: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

 Parameters studied in this paper:  1.                                       2.         

  

Parameters that should have been studied:

1.                                       2. 

Page 21: Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta.

Solutions:

• Submit an idea, verify later?• Get in touch with right kind of people to do social case

studies; sociologists?  Questions:• End product derived from user interaction?


Recommended