Next Article in Journal
An Anonymous Authenticated Key Agreement Scheme for Telecare Medical Information Systems
Previous Article in Journal
Quantum Security of a Compact Multi-Signature
 
 
Font Type:
Arial Georgia Verdana
Font Size:
Aa Aa Aa
Line Spacing:
Column Width:
Background:
Article

A Secure Approach Out-of-Band for e-Bank with Visual Two-Factor Authorization Protocol

by
Laerte Peotta de Melo
1,
Dino Macedo Amaral
1,
Robson de Oliveira Albuquerque
1,2,
Rafael Timóteo de Sousa Júnior
1,
Ana Lucila Sandoval Orozco
1,2 and
Luis Javier García Villalba
2,*
1
Department of Electrical Engineering, University of Brasília, Federal District, Brasília 70910-900, Brazil
2
Group of Analysis, Security and Systems (GASS), Department of Software Engineering and Artificial Intelligence (DISIA), Faculty of Computer Science and Engineering, Office 431, Universidad Complutense de Madrid (UCM), Calle Profesor José García Santesmases, 9, Ciudad Universitaria, 28040 Madrid, Spain
*
Author to whom correspondence should be addressed.
Cryptography 2024, 8(4), 51; https://doi.org/10.3390/cryptography8040051
Submission received: 17 September 2024 / Revised: 31 October 2024 / Accepted: 1 November 2024 / Published: 11 November 2024

Abstract

The article presents an innovative approach for secure authentication in internet banking transactions, utilizing an Out-of-Band visual two-factor authorization protocol. With the increasing rise of cyber attacks and fraud, new security models are needed that ensure the integrity, authenticity, and confidentiality of financial transactions. The identified gap lies in the inability of traditional authentication methods, such as TANs and tokens, to provide security in untrusted terminals. The proposed solution is the Dynamic Authorization Protocol (DAP), which uses mobile devices to validate transactions through visual codes, such as QR codes. Each transaction is assigned a unique associated code, and the challenge must be responded to within 120 s. The customer initiates the transaction on a computer and independently validates it on their mobile device using an out-of-band channel to prevent attacks such as phishing and man-in-the-middle. The methodology involves implementing a prototype in Java ME for Android devices and a Java application server, creating a practical, low-computational-cost system, accessible for use across different operating systems and devices. The protocol was tested in real-world scenarios, focusing on ensuring transaction integrity and authenticity. The results show a successful implementation at Banco do Brasil, with 3.6 million active users, demonstrating the efficiency of the model over 12 years of use without significant vulnerabilities. The DAP protocol provides a robust and effective solution for securing banking transactions and can be extended to other authentication environments, such as payment terminals and point of sale devices.
Keywords: online banking; cyber fraud; two-factor authentication; authorization online banking; cyber fraud; two-factor authentication; authorization

Share and Cite

MDPI and ACS Style

de Melo, L.P.; Macedo Amaral, D.; de Oliveira Albuquerque, R.; de Sousa Júnior, R.T.; Sandoval Orozco, A.L.; García Villalba, L.J. A Secure Approach Out-of-Band for e-Bank with Visual Two-Factor Authorization Protocol. Cryptography 2024, 8, 51. https://doi.org/10.3390/cryptography8040051

AMA Style

de Melo LP, Macedo Amaral D, de Oliveira Albuquerque R, de Sousa Júnior RT, Sandoval Orozco AL, García Villalba LJ. A Secure Approach Out-of-Band for e-Bank with Visual Two-Factor Authorization Protocol. Cryptography. 2024; 8(4):51. https://doi.org/10.3390/cryptography8040051

Chicago/Turabian Style

de Melo, Laerte Peotta, Dino Macedo Amaral, Robson de Oliveira Albuquerque, Rafael Timóteo de Sousa Júnior, Ana Lucila Sandoval Orozco, and Luis Javier García Villalba. 2024. "A Secure Approach Out-of-Band for e-Bank with Visual Two-Factor Authorization Protocol" Cryptography 8, no. 4: 51. https://doi.org/10.3390/cryptography8040051

APA Style

de Melo, L. P., Macedo Amaral, D., de Oliveira Albuquerque, R., de Sousa Júnior, R. T., Sandoval Orozco, A. L., & García Villalba, L. J. (2024). A Secure Approach Out-of-Band for e-Bank with Visual Two-Factor Authorization Protocol. Cryptography, 8(4), 51. https://doi.org/10.3390/cryptography8040051

Article Metrics

Back to TopTop