SEPIA: Secure-PIN-Authentication-as-a-Service for ATM using Mobile and Wearable Devices

被引:14
作者
Khan, Rasib [1 ]
Hasan, Ragib [1 ]
Xu, Jinfang [1 ]
机构
[1] Univ Alabama Birmingham, SECRETLab, Dept Comp & Informat Sci, Birmingham, AL 35294 USA
来源
2015 3RD IEEE INTERNATIONAL CONFERENCE ON MOBILE CLOUD COMPUTING, SERVICES, AND ENGINEERING (MOBILECLOUD 2015) | 2015年
关键词
ATM; Authentication; Credit/Debit Card; Google Glass; Obfuscated PIN; PIN Template; Point-of-Service; Security;
D O I
10.1109/MobileCloud.2015.16
中图分类号
TP31 [计算机软件];
学科分类号
081202 ; 0835 ;
摘要
Credit card fraud is a common problem in today's world. Financial institutions have registered major loses till today due to users being exposed of their credit card information. Shoulder-surfing or observation attacks, including card skimming and video recording with hidden cameras while users perform PIN-based authentication at ATM terminals is one of the common threats for common users. Researchers have struggled to come up with secure solutions for secure PIN authentication. However, modern day ubiquitous wearable devices, such as the Google Glass have presented us with newer opportunities in this research area. In this paper, we propose Secure-PIN-Authentication-as-a-Service (SEPIA), a secure obfuscated PIN authentication protocol for ATM and other point-of-service terminals using cloud-connected personal mobile and wearable devices. Our approach protects the user from shoulder-surfers and partial observation attacks, and is also resistant to relay, replay, and intermediate transaction attacks. A SEPIA user utilizes a Google Glass or a mobile device for scanning a QR code on the terminal screen to prove co-location to the cloud-based server and obtain a secure PIN template for point-of-service authentication. SEPIA ensures minimal task overhead on the user's device with maximal computation offloaded to the cloud. We have implemented a proof-of-concept prototype to perform experimental analysis and a usability study for the SEPIA architecture.
引用
收藏
页码:41 / 50
页数:10
相关论文
共 29 条
[1]   EMV: Why Payment Systems Fail [J].
Anderson, Ross ;
Murdoch, Steven J. .
COMMUNICATIONS OF THE ACM, 2014, 57 (06) :24-28
[2]  
[Anonymous], 2008, RESTFUL WEB SERVICES
[3]  
[Anonymous], 1993, P 1 ACM C COMPUTER C, DOI [10.1145/168588.168615, DOI 10.1145/168588.168615]
[4]  
[Anonymous], P 6 S US PRIV SEC
[5]  
[Anonymous], 2014, IEEE SPECTRUM
[6]   Authenticating public terminals [J].
Asokan, N ;
Debar, H ;
Steiner, M ;
Waidner, M .
COMPUTER NETWORKS-THE INTERNATIONAL JOURNAL OF COMPUTER AND TELECOMMUNICATIONS NETWORKING, 1999, 31 (08) :861-870
[7]  
Benson Edwin Raj S., 2011, 2011 Proceedings of International Conference on Computer, Communication and Electrical Technology (ICCCET 2011), P152, DOI 10.1109/ICCCET.2011.5762457
[8]  
Bhatla T.P., 2003, CARDS BUS REV, V1, P1
[9]  
Bureau of Justice Statistics, ID THFT SUPPL ITS NA
[10]  
Coventry L., 2003, Proceedings of the SIGCHI conference on Human factors in computing systems, P153, DOI DOI 10.1145/642637.642639