210 likes | 226 Views
Usably Secure, Low-Cost Authentication for Mobile Banking. Saurabh Gupta Sandeep Kumar Gupta. Need For Mobile Banking. People need money on the run. Banks provide security, interest. Use Cases – Buying Something. Use Case - Depositing Money. Use Case – Withdrawing Money.
E N D
Usably Secure, Low-Cost Authentication for Mobile Banking Saurabh Gupta Sandeep Kumar Gupta
Need For Mobile Banking • People need money on the run. • Banks provide security, interest.
How is it secured on Mars ? Application level encryption • Typically have an application implementing the favorite encryption scheme. • Provides end to end encryption. Possible because • Can ask people to install and use them. • Phones are powerful enough to run them.
Challenges on Earth • Fundamentally, GSM channel is weakly encrypted. • Can not rely on network layer encryption. • Need for end to end encryption • Can not install applications on user ends.
Mobile Banking In General • Cell Phone • 2 factor authentication • 4 digit pin • A codebook with synchronized security tokens.
Overview of 2 schemes • Both use 2 factor authentication schemes. New Scheme Old Scheme
Security Analysis • 4 different types of attacks considered. • Pin Recovery • Type 0: Impersonator gets phone • Type 1: Impersonator gets phone and codebook • Type 2: Impersonator gets phone and PIN Question: Impersonator? 1. 2. 3.
Security Analysis • Pin Recovery • Type 0: Impersonator gets phone • Type 1: Impersonator gets phone and codebook • Type 2: Impersonator gets phone and PIN
User Study • Ethnography • 15 people from Delhi • 19 people from Bihar • Composition • 8 agents • 13 existing users • 13 potential users • Tasks • Plain PIN entry • EKO signature formulation • New signature formulation
Discussion • Effect of increased cognitive effort. • Effect of entering only 4 digits instead of 10. • Statistical significance of results
User Case Studies • What is required to validate your claim? • from the perspective of paper publishing? • Novelty of the idea. • Quick papers for promotion. • for proving soundly? • Acceptability of the idea.
Parameters studied in this paper: 1. 2. Parameters that should have been studied: 1. 2.
Solutions: • Submit an idea, verify later? • Get in touch with right kind of people to do social case studies; sociologists? • Questions: • End product derived from user interaction?