Paper accepted at COSE

Published: Feb 2, 2020
The following paper has been accepted at the Computers & Security Journal (COSE):
  • Title: A Survey on Multi-Factor Authentication for Online Banking in the Wild
  • Authors: Federico Sinigaglia, Roberto Carbone, Gabriele Costa, Nicola Zannone
  • Abstract: In recent years, the usage of online banking services has considerably increased. To protect the sensitive resources managed by these services against attackers, banks have started adopting Multi-Factor Authentication (MFA). To date, a variety of MFA solutions have been implemented by banks, leveraging different designs and features and providing a non-homogeneous level of security and user experience. Public and private authorities have defined laws and guidelines to guide the design of more secure and usable MFA solutions, but their influence on existing MFA implementations remains unclear. In this work, we present a latitudinal study on the adoption of MFA and the design choices made by banks operating in different countries. In particular, we evaluate the MFA solutions currently adopted in the banking sector in terms of (i) compliance with laws and best practices, (ii) robustness against attacks and (iii) complexity. We also investigate possible correlations between these criteria. Based on this study, we identify a number of lessons learned and open challenges.
  • DOI: 10.1016/j.cose.2020.101745
  • Complementary Material: Link

About the journal

Involved People

Sinigaglia Federico

Federico Sinigaglia

Carbone Roberto

Roberto Carbone