Advanced security of two-factor authentication system using stego QR code. (22nd April 2020)
- Record Type:
- Journal Article
- Title:
- Advanced security of two-factor authentication system using stego QR code. (22nd April 2020)
- Main Title:
- Advanced security of two-factor authentication system using stego QR code
- Authors:
- Kouraogo, Yacouba
Orhanou, Ghizlane
Elhajji, Said - Abstract:
- Many financial institutions are trying to protect their customers by offering improved and more secure technologies for authentication. One of the most common is two-factor authentication (2FA), which presents many vulnerabilities that allow attackers to retrieve confidential information such as mobile transaction authentication (mTAN). Thus, according to NIST (National Institute of Standards and Technology), 2FA based on SMS is deprecated and aims to find a secure communication channel other than SMS. Therefore in this paper, we propose a 2FA communication channel based on steganography in the QR-code. So, the mTAN can only be read by a specific scanner that implements the technique of extracting the hidden information while having the shared key and the public information in the QR-code readable by the standard scanners. Finally, we implement our proposed method and then do the test by simulating a line banking service.
- Is Part Of:
- International journal of information and computer security. Volume 12:Number 4(2020)
- Journal:
- International journal of information and computer security
- Issue:
- Volume 12:Number 4(2020)
- Issue Display:
- Volume 12, Issue 4 (2020)
- Year:
- 2020
- Volume:
- 12
- Issue:
- 4
- Issue Sort Value:
- 2020-0012-0004-0000
- Page Start:
- 436
- Page End:
- 449
- Publication Date:
- 2020-04-22
- Subjects:
- steganography -- QR code -- two-factor authentication -- 2FA -- mobile transaction authentication number -- mTAN -- mobile security
Computer security -- Periodicals
Information systems management -- Security measures -- Periodicals
Computer networks -- Security measures -- Periodicals
Information technology -- Security measures -- Periodicals
005.805 - Journal URLs:
- http://www.inderscience.com/browse/index.php?journalCODE=ijics ↗
http://www.inderscience.com/ ↗ - Languages:
- English
- ISSNs:
- 1744-1765
- Deposit Type:
- Legaldeposit
- View Content:
- Available online (eLD content is only available in our Reading Rooms) ↗
- Physical Locations:
- British Library DSC - BLDSS-3PM
British Library STI - ELD Digital store - Ingest File:
- 12938.xml