DocumentCode
693662
Title
A professional view on ebanking authentication: Challenges and recommendations
Author
Aguila Vila, Jorge ; Serna-Olvera, Jetzabel ; Fernandez, Luis ; Medina, Manel ; Sfakianakis, Andreas
Author_Institution
CSRIT, CaixaBank, Barcelona, Spain
fYear
2013
fDate
4-6 Dec. 2013
Firstpage
43
Lastpage
48
Abstract
In current e-banking systems, millions of consumers are now able to conduct financial transactions using a wide range of mobile devices; this growth exposes the system not only to the set of known threats that are now migrating from traditional PC-based e-banking to the mobile-based scenario, but, to emerging threats specifically targeting mobile devices. Considering the sensitive nature of the financial information managed, security in mobile devices has become a major issue. Thus, to be able to provide transaction security, and minimize the potential threats, e-banking systems must implement robust identification and authentication systems (eIDAS). Therefore, this paper analyzes current threats in e-banking. It presents a brief review on the current state of the art analyzing the most popular eIDAS implemented in Europe, through a survey launched by ENISA addressed to security professionals of the financial sector. The most common eIDAS approaches for e-banking, and their suitability against the known threats in terms of related incidents and financial loss, are therefore assessed. Finally, a set of challenges and recommendations to be considered in any eIDAS implementation is introduced.
Keywords
authorisation; bank data processing; electronic commerce; mobile computing; transaction processing; ENISA; Europe; PC-based e-banking; authentication system; e-banking systems; eIDAS; ebanking authentication; financial information management; financial loss; financial sector; financial transactions; mobile device security; mobile-based e-banking; potential threat minimization; robust identification system; security professionals; security threats; transaction security; Cryptography; Europe; Mobile communication; authentication; best practices; e-banking authentication; financial sector; online banking security;
fLanguage
English
Publisher
ieee
Conference_Titel
Information Assurance and Security (IAS), 2013 9th International Conference on
Conference_Location
Gammarth
Print_ISBN
978-1-4799-2989-4
Type
conf
DOI
10.1109/ISIAS.2013.6947731
Filename
6947731
Link To Document