INDIA SP BranchlessBanking 2013

March 1, 2018 | Penulis: Rick Yuen | Kategori: Short Message Service, Authentication, Wire Transfer, Communications Protocols, Banks
Share Embed


Deskripsi Singkat

Description: Although branchless banking systems have spread to di erent parts of the developing world, methods to ensu...

Deskripsi

Although branchless banking systems have spread to di erent parts of the developing world, methods to ensure transactional security in these systems have seen slower adoption because of a variety of operational constraints. A basic requirement from such systems is the provision of secure and reliable receipts to users during transactions, and recent attacks have demonstrated that existing systems fall short of ful lling this requirement in practice. In this paper, we propose a simple and practical protocol to enable users to authenticate transaction receipts in branchless banking systems. Our protocol makes novel use of missed calls (sent from users to the bank) to help distinguish real receipts from spoofed ones and can be implemented on any mobile phone, without software installation. Besides preventing spoo ng attacks, the protocol enjoys signi cant advantages of usability, eciency and cost, which make it a more practical choice than other schemes. We also discuss ways to use missed calls to mitigate man-in-the-middle attacks on branchless banking systems.
Lihat lebih banyak...

Komentar

Hak Cipta © 2017 PDFDOKUMEN Inc.