Enhancing the security of FinTech applications with map-based graphical password authentication

被引:23
|
作者
Meng, Weizhi [1 ]
Zhu, Liqiu [3 ]
Li, Wenjuan [2 ,4 ]
Han, Jinguang [5 ]
Li, Yan [6 ]
机构
[1] Tech Univ Denmark, Dept Appl Math & Comp Sci, Cyber Secur Sect, Lyngby, Denmark
[2] Tech Univ Denmark, Dept Appl Math & Comp Sci, Lyngby, Denmark
[3] FinTech Startup, Macau, Peoples R China
[4] City Univ Hong Kong, Dept Comp Sci, Hong Kong, Peoples R China
[5] Queens Univ Belfast, Sch Elect Elect Engn & Comp Sci, Belfast, Antrim, North Ireland
[6] Singapore Management Univ, Sch Informat Syst, Singapore, Singapore
关键词
FinTech application; User authentication; Multiple password inference; Graphical passwords; Map passwords; Security and usability; MEMORABILITY; DESIGN;
D O I
10.1016/j.future.2019.07.038
中图分类号
TP301 [理论、方法];
学科分类号
081202 ;
摘要
With the rapid development of information technology (IT) in financial industry, financial technology (FinTech) has become an emerging area for enterprises and organizations. Due to the wide adoption of IT, various FinTech applications are used by financial industry to help process information and offer financial services. Traditionally, textual passwords are the most widely deployed authentication mechanism, while having many known limitations. As a result, there is a need to enhance the security of FinTech authentication against cyber-criminals. As an alternative, graphical passwords (GPs) are considered as one promising solution to complement traditional password-based systems. In the literature, various GP schemes were proposed such as PassPoints, DAS, Cued Click Points, GeoPass, etc. In this work, we identify that multiple password inference has become a challenge for most GP schemes, and thus design RouteMap, a map-and route-based GP to further improve the security of FinTech applications. This scheme requires users to create a route on a world map as their credentials. In the evaluation, we involved a total of 120 participants, among which 60 of them have financial (FinTech) background, and investigated the performance of RouteMap by comparing it with two similar schemes. Our results demonstrate that participants can achieve better performance using RouteMap in the aspects of both authentication accuracy and multiple password memory. Our effort attempts to complement existing studies and stimulate more research on the combination of GP and FinTech. (C) 2019 Elsevier B.V. All rights reserved.
引用
收藏
页码:1018 / 1027
页数:10
相关论文
共 50 条
  • [1] Exploring Effect of Location Number on Map-Based Graphical Password Authentication
    Meng, Weizhi
    Lee, Wang Hao
    Au, Man Ho
    Liu, Zhe
    INFORMATION SECURITY AND PRIVACY, ACISP 2017, PT II, 2017, 10343 : 301 - 313
  • [2] PassMap: A Map Based Graphical-Password Authentication System
    Sun, Hung-Min
    Chen, Yao-Hsin
    Fang, Chiung-Cheng
    Chang, Shih-Ying
    7TH ACM SYMPOSIUM ON INFORMATION, COMPUTER AND COMMUNICATIONS SECURITY (ASIACCS 2012), 2012,
  • [3] Security Attacks and Enhancements to Chaotic Map-Based RFID Authentication Protocols
    Kardas, Suleyman
    Genc, Ziya Alper
    WIRELESS PERSONAL COMMUNICATIONS, 2018, 98 (01) : 1135 - 1154
  • [4] Security Attacks and Enhancements to Chaotic Map-Based RFID Authentication Protocols
    Süleyman Kardaş
    Ziya Alper Genç
    Wireless Personal Communications, 2018, 98 : 1135 - 1154
  • [5] Token-based graphical password authentication
    Gyorffy, John Charles
    Tappenden, Andrew F.
    Miller, James
    INTERNATIONAL JOURNAL OF INFORMATION SECURITY, 2011, 10 (06) : 321 - 336
  • [6] Token-based graphical password authentication
    John Charles Gyorffy
    Andrew F. Tappenden
    James Miller
    International Journal of Information Security, 2011, 10 : 321 - 336
  • [7] Alignment based graphical password authentication system
    Danish, Abutalha
    Sharma, Labhya
    Varshney, Harshit
    Khan, Asad Mohammed
    PROCEEDINGS OF THE 10TH INDIACOM - 2016 3RD INTERNATIONAL CONFERENCE ON COMPUTING FOR SUSTAINABLE GLOBAL DEVELOPMENT, 2016, : 2950 - 2954
  • [8] Conformal Chebyshev chaotic map-based remote user password authentication protocol using smart card
    Chandrashekhar Meshram
    Sarita Gajbhiye Meshram
    Rabha W. Ibrahim
    Hamid A. Jalab
    Sajjad Shaukat Jamal
    Sharad Kumar Barve
    Complex & Intelligent Systems, 2022, 8 : 973 - 987
  • [9] Conformal Chebyshev chaotic map-based remote user password authentication protocol using smart card
    Meshram, Chandrashekhar
    Meshram, Sarita Gajbhiye
    Ibrahim, Rabha W.
    Jalab, Hamid A.
    Jamal, Sajjad Shaukat
    Barve, Sharad Kumar
    COMPLEX & INTELLIGENT SYSTEMS, 2022, 8 (02) : 973 - 987
  • [10] Enhancing graphical password authentication system with deep learning-based arabic digit recognition
    Rasheed A.F.
    Zarkoosh M.
    Elia F.R.
    International Journal of Information Technology, 2024, 16 (3) : 1419 - 1427