调整用户界面设计以减少 USSD 频道中的 "肩膊冲浪 "攻击

Binitie A. P., Babatunde J. O.
{"title":"调整用户界面设计以减少 USSD 频道中的 \"肩膊冲浪 \"攻击","authors":"Binitie A. P., Babatunde J. O.","doi":"10.52589/ajensr-dpcgwn0x","DOIUrl":null,"url":null,"abstract":"The most widely accepted authentication method involves the use of a personal identification number (PIN). This method is applicable across many technologies, of which one of them is Unstructured Supplementary Service Data (USSD). USSD is a capability built into the Global System for Mobile Communication (GSM). In some developing countries like Nigeria, USSD is used in carrying out financial transactions. It has been observed that while carrying out banking transactions using this technology, users' personal identification number (PIN) entered for authentication appears in plain text on the mobile interface, thereby subjecting it to shoulder surfing attacks. Findings revealed that users' PIN appears in plain text because USSD technology is designed to convey only textual data. That is why many existing authentication methods against Human shoulder surfing attacks which contain features like images, colors, or graphical password, that can provide security to users' PIN on mobile interface are not implemented on the USSD channel. This is one of the reasons why many existing authentication methods, which are designed with features such as images, colors or graphical passwords to prevent shoulder surfing attack, are not implemented on the USSD channel. This research is, therefore, on the design of a new authentication method that can provide security to users’ PIN at the mobile interface of the USSD channel and secure the users’ transaction against shoulder surfing attacks. In this method, the challenge response approach is adopted to provide a secure PIN entry method in the presence of a human shoulder surfer, using the randomization obfuscation method that randomly places the user's chosen PIN within randomly generated 10-digit numbers, in Left to Right order. For further security, the designed model includes features like Bag of Soft Biometrics (BoSB) details and one-time password (OTP).","PeriodicalId":404388,"journal":{"name":"African Journal of Environment and Natural Science Research","volume":"89 3","pages":""},"PeriodicalIF":0.0000,"publicationDate":"2024-01-24","publicationTypes":"Journal Article","fieldsOfStudy":null,"isOpenAccess":false,"openAccessPdf":"","citationCount":"0","resultStr":"{\"title\":\"Adapting User Interface Design to Mitigate Shoulder Surfing Attacks in USSD Channel\",\"authors\":\"Binitie A. P., Babatunde J. O.\",\"doi\":\"10.52589/ajensr-dpcgwn0x\",\"DOIUrl\":null,\"url\":null,\"abstract\":\"The most widely accepted authentication method involves the use of a personal identification number (PIN). This method is applicable across many technologies, of which one of them is Unstructured Supplementary Service Data (USSD). USSD is a capability built into the Global System for Mobile Communication (GSM). In some developing countries like Nigeria, USSD is used in carrying out financial transactions. It has been observed that while carrying out banking transactions using this technology, users' personal identification number (PIN) entered for authentication appears in plain text on the mobile interface, thereby subjecting it to shoulder surfing attacks. Findings revealed that users' PIN appears in plain text because USSD technology is designed to convey only textual data. That is why many existing authentication methods against Human shoulder surfing attacks which contain features like images, colors, or graphical password, that can provide security to users' PIN on mobile interface are not implemented on the USSD channel. This is one of the reasons why many existing authentication methods, which are designed with features such as images, colors or graphical passwords to prevent shoulder surfing attack, are not implemented on the USSD channel. This research is, therefore, on the design of a new authentication method that can provide security to users’ PIN at the mobile interface of the USSD channel and secure the users’ transaction against shoulder surfing attacks. In this method, the challenge response approach is adopted to provide a secure PIN entry method in the presence of a human shoulder surfer, using the randomization obfuscation method that randomly places the user's chosen PIN within randomly generated 10-digit numbers, in Left to Right order. For further security, the designed model includes features like Bag of Soft Biometrics (BoSB) details and one-time password (OTP).\",\"PeriodicalId\":404388,\"journal\":{\"name\":\"African Journal of Environment and Natural Science Research\",\"volume\":\"89 3\",\"pages\":\"\"},\"PeriodicalIF\":0.0000,\"publicationDate\":\"2024-01-24\",\"publicationTypes\":\"Journal Article\",\"fieldsOfStudy\":null,\"isOpenAccess\":false,\"openAccessPdf\":\"\",\"citationCount\":\"0\",\"resultStr\":null,\"platform\":\"Semanticscholar\",\"paperid\":null,\"PeriodicalName\":\"African Journal of Environment and Natural Science Research\",\"FirstCategoryId\":\"1085\",\"ListUrlMain\":\"https://doi.org/10.52589/ajensr-dpcgwn0x\",\"RegionNum\":0,\"RegionCategory\":null,\"ArticlePicture\":[],\"TitleCN\":null,\"AbstractTextCN\":null,\"PMCID\":null,\"EPubDate\":\"\",\"PubModel\":\"\",\"JCR\":\"\",\"JCRName\":\"\",\"Score\":null,\"Total\":0}","platform":"Semanticscholar","paperid":null,"PeriodicalName":"African Journal of Environment and Natural Science Research","FirstCategoryId":"1085","ListUrlMain":"https://doi.org/10.52589/ajensr-dpcgwn0x","RegionNum":0,"RegionCategory":null,"ArticlePicture":[],"TitleCN":null,"AbstractTextCN":null,"PMCID":null,"EPubDate":"","PubModel":"","JCR":"","JCRName":"","Score":null,"Total":0}
引用次数: 0

摘要

最广为接受的认证方法是使用个人识别码(PIN)。这种方法适用于多种技术,其中之一是非结构化补充服务数据(USSD)。USSD 是全球移动通信系统 (GSM) 的一项内置功能。在尼日利亚等一些发展中国家,USSD 被用于进行金融交易。据观察,在使用该技术进行银行交易时,用户为进行身份验证而输入的个人识别码(PIN)会以纯文本形式出现在移动界面上,从而使其受到肩部冲浪攻击。研究结果表明,用户的个人识别码以纯文本形式出现,是因为 USSD 技术的设计只能传输文本数据。这就是为什么许多现有的针对 "人的肩上冲浪 "攻击的身份验证方法都没有在 USSD 信道上实施,这些方法包含图像、颜色或图形密码等功能,可以在移动界面上为用户的 PIN 码提供安全保护。这也是许多现有的验证方法没有在 USSD 信道上实施的原因之一,这些方法设计了图像、颜色或图形密码等功能来防止肩上冲浪攻击。因此,本研究设计了一种新的身份验证方法,可以在 USSD 信道的移动界面上为用户的 PIN 提供安全保护,并确保用户的交易免受肩冲攻击。在这种方法中,采用了挑战响应方法,以提供一种安全的 PIN 输入方法,该方法使用随机化混淆方法,将用户选择的 PIN 按从左到右的顺序随机放置在随机生成的 10 位数字中。为了进一步确保安全,所设计的模型还包括软生物识别信息包(BoSB)和一次性密码(OTP)等功能。
本文章由计算机程序翻译,如有差异,请以英文原文为准。
Adapting User Interface Design to Mitigate Shoulder Surfing Attacks in USSD Channel
The most widely accepted authentication method involves the use of a personal identification number (PIN). This method is applicable across many technologies, of which one of them is Unstructured Supplementary Service Data (USSD). USSD is a capability built into the Global System for Mobile Communication (GSM). In some developing countries like Nigeria, USSD is used in carrying out financial transactions. It has been observed that while carrying out banking transactions using this technology, users' personal identification number (PIN) entered for authentication appears in plain text on the mobile interface, thereby subjecting it to shoulder surfing attacks. Findings revealed that users' PIN appears in plain text because USSD technology is designed to convey only textual data. That is why many existing authentication methods against Human shoulder surfing attacks which contain features like images, colors, or graphical password, that can provide security to users' PIN on mobile interface are not implemented on the USSD channel. This is one of the reasons why many existing authentication methods, which are designed with features such as images, colors or graphical passwords to prevent shoulder surfing attack, are not implemented on the USSD channel. This research is, therefore, on the design of a new authentication method that can provide security to users’ PIN at the mobile interface of the USSD channel and secure the users’ transaction against shoulder surfing attacks. In this method, the challenge response approach is adopted to provide a secure PIN entry method in the presence of a human shoulder surfer, using the randomization obfuscation method that randomly places the user's chosen PIN within randomly generated 10-digit numbers, in Left to Right order. For further security, the designed model includes features like Bag of Soft Biometrics (BoSB) details and one-time password (OTP).
求助全文
通过发布文献求助,成功后即可免费获取论文全文。 去求助
来源期刊
自引率
0.00%
发文量
0
×
引用
GB/T 7714-2015
复制
MLA
复制
APA
复制
导出至
BibTeX EndNote RefMan NoteFirst NoteExpress
×
提示
您的信息不完整,为了账户安全,请先补充。
现在去补充
×
提示
您因"违规操作"
具体请查看互助需知
我知道了
×
提示
确定
请完成安全验证×
copy
已复制链接
快去分享给好友吧!
我知道了
右上角分享
点击右上角分享
0
联系我们:info@booksci.cn Book学术提供免费学术资源搜索服务,方便国内外学者检索中英文文献。致力于提供最便捷和优质的服务体验。 Copyright © 2023 布克学术 All rights reserved.
京ICP备2023020795号-1
ghs 京公网安备 11010802042870号
Book学术文献互助
Book学术文献互助群
群 号:481959085
Book学术官方微信