Secure OTP and Biometric Verification Scheme for Mobile Banking

Chang-Lung Tsai, Chun-Jung Chen, Deng-Jie Zhuang
{"title":"Secure OTP and Biometric Verification Scheme for Mobile Banking","authors":"Chang-Lung Tsai, Chun-Jung Chen, Deng-Jie Zhuang","doi":"10.1109/MUSIC.2012.31","DOIUrl":null,"url":null,"abstract":"Recently, according to the emerging development of smart mobile phones and tablet PC, mobile e-commerce has dramatically increased due to the reason that the function of smart mobile phone and tablet PC are combined together. M-banking is thus become more convenient, effective and timely through the new mobile communication systems. In order to raise the security of M-banking, some banks adopt the one-time password (OTP) to remedy the possible M-banking stealing risk. In the past, the OTP is sent to personal mobile phone. But, currently most of the smart mobile phone can performing M-banking easily. Thus, it gains higher risk of information security due to mobile phone hacking. In order to provide a reliable and secure M-banking process without decrease the convenience concurrently, in the paper one-time password (OTP) and personal biometric have been combined with personal identification and password for verification while M-banking. As the client side initiates a request for M-banking to the server side of a bank that provides M-banking service, the server side will generate an OTP with limited period for registration the M-banking and transmit to the client side. After receiving the OTP message, the client side must verify if the OTP message is validation and provided by the desired real server side. After then, the client side will register the on-line M-banking with the OTP in the specified short period. After receiving the service request, the server side will then request the client side to capture personal biometric such as fingerprint, iris, photo, and etc. immediately for further verification with the existed data stored in the server side to prevent the M-banking embezzling. If the personal biometric has been verified as an old one, the M-banking will immediately terminated by the server side. As the verification is finally done by the server side, the client side then can perform transaction via M-banking smoothly. The proposed scheme not only can provide secure M-banking, but also can clearly define the process. Therefore, if there are any M-banking arguments occurred due to Internet hacking or mobile phone stealing for M-banking, both of the server side and client side could protect their rights and interests.","PeriodicalId":260515,"journal":{"name":"2012 Third FTRA International Conference on Mobile, Ubiquitous, and Intelligent Computing","volume":"39 1","pages":"0"},"PeriodicalIF":0.0000,"publicationDate":"2012-06-26","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"17","resultStr":null,"platform":"Semanticscholar","paperid":null,"PeriodicalName":"2012 Third FTRA International Conference on Mobile, Ubiquitous, and Intelligent Computing","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.1109/MUSIC.2012.31","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 17

Abstract

Recently, according to the emerging development of smart mobile phones and tablet PC, mobile e-commerce has dramatically increased due to the reason that the function of smart mobile phone and tablet PC are combined together. M-banking is thus become more convenient, effective and timely through the new mobile communication systems. In order to raise the security of M-banking, some banks adopt the one-time password (OTP) to remedy the possible M-banking stealing risk. In the past, the OTP is sent to personal mobile phone. But, currently most of the smart mobile phone can performing M-banking easily. Thus, it gains higher risk of information security due to mobile phone hacking. In order to provide a reliable and secure M-banking process without decrease the convenience concurrently, in the paper one-time password (OTP) and personal biometric have been combined with personal identification and password for verification while M-banking. As the client side initiates a request for M-banking to the server side of a bank that provides M-banking service, the server side will generate an OTP with limited period for registration the M-banking and transmit to the client side. After receiving the OTP message, the client side must verify if the OTP message is validation and provided by the desired real server side. After then, the client side will register the on-line M-banking with the OTP in the specified short period. After receiving the service request, the server side will then request the client side to capture personal biometric such as fingerprint, iris, photo, and etc. immediately for further verification with the existed data stored in the server side to prevent the M-banking embezzling. If the personal biometric has been verified as an old one, the M-banking will immediately terminated by the server side. As the verification is finally done by the server side, the client side then can perform transaction via M-banking smoothly. The proposed scheme not only can provide secure M-banking, but also can clearly define the process. Therefore, if there are any M-banking arguments occurred due to Internet hacking or mobile phone stealing for M-banking, both of the server side and client side could protect their rights and interests.
查看原文
分享 分享
微信好友 朋友圈 QQ好友 复制链接
本刊更多论文
移动银行的安全联机服务和生物识别验证方案
近年来,随着智能手机和平板电脑的新兴发展,由于智能手机和平板电脑的功能结合在一起,移动电子商务急剧增加。通过新的移动通信系统,手机银行变得更加方便、有效和及时。为了提高手机银行的安全性,一些银行采用一次性密码(OTP)来弥补手机银行可能存在的被盗风险。过去,OTP是发送到个人手机上的。但是,目前大多数智能手机都可以很容易地实现移动银行。因此,由于手机被黑客入侵,信息安全风险更高。为了在不降低便利性的前提下提供可靠、安全的移动银行业务流程,本文将一次性密码(OTP)和个人生物识别技术与个人身份识别和密码验证相结合,实现了移动银行业务的实名化。当客户端向提供移动银行服务的银行服务器端发起移动银行请求时,服务器端将生成一个有期限的OTP,用于注册移动银行并传输给客户端。在接收到OTP消息后,客户端必须验证该OTP消息是否由所需的实服务器端验证并提供。在此之后,客户将在规定的短时间内向网上银行网点注册网上银行。服务器端收到服务请求后,立即请求客户端采集指纹、虹膜、照片等个人生物特征信息,与服务器端存储的已有数据进行进一步验证,防止移动银行盗用。如果个人生物特征被验证为旧的,移动银行将立即被服务器端终止。由于验证最终由服务器端完成,因此客户端可以顺利地通过移动银行进行交易。该方案不仅可以提供安全的移动银行服务,而且可以清晰地定义移动银行服务的流程。因此,如果发生手机银行因网络黑客攻击或手机被盗而引起的手机银行纠纷,服务器端和客户端都可以维护自己的权益。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
求助全文
约1分钟内获得全文 去求助
来源期刊
自引率
0.00%
发文量
0
期刊最新文献
A Source-Based Share-Tree Like Multicast Routing in Satellite Constellation Networks An Empirical Case of a Context-Aware Mobile Recommender System in a Banking Environment Generating OWL Ontology from Relational Database Data Overhead Impact of Multipath Routing for Multicast in Wireless Mesh Networks UVote: A Ubiquitous E-voting System
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
现在去查看 取消
×
提示
确定
0
微信
客服QQ
Book学术公众号 扫码关注我们
反馈
×
意见反馈
请填写您的意见或建议
请填写您的手机或邮箱
已复制链接
已复制链接
快去分享给好友吧!
我知道了
×
扫码分享
扫码分享
Book学术官方微信
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术
文献互助 智能选刊 最新文献 互助须知 联系我们:info@booksci.cn
Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。
Copyright © 2023 Book学术 All rights reserved.
ghs 京公网安备 11010802042870号 京ICP备2023020795号-1