Multifactor authentication for e-commerce

William Newhouse · 2019

 Retailers can implement multifactor authentication (MFA) to reduce the opportunity for a customer's online account to be used for fraudulent purchases. MFA is a security enhancement that allows a user to present several pieces of evidence when logging into an account.This evidence falls into three categories: something you know (e.g., password), something you have (e.g., smart card), and something you are (e.g., fingerprint).The presented evidence must come from at least two different categories to enhance security. The National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology (NIST) built a laboratory environment to explore MFA options available to retailers today, and documented the example implementations that retailers can consider for their environment. This NIST Cybersecurity Practice Guide demonstrates how online retailers can implement MFA to help reduce electronic commerce (e-commerce) fraud. CHALLENGESmart chip credit cards and terminals work together to protect in-store payments.The in-store security advances were introduced in 2015, and those have pushed malicious actors who possess stolen credit card data to perform payment card fraud online.This guide describes implementing stronger userauthentication techniques to reduce the risk of e-commerce fraud.The guide documents a system in which risk determines when to trigger MFA challenges to existing customers. SOLUTIONThis project's example implementations analyze risk to prompt returning purchasers with additional authentication requests when risk elements are exceeded during the online shopping session.Risk elements may include contextual data related to the returning purchaser and the current shopping transaction.The example implementations will prompt a returning purchaser to present another distinct authentication factor-something the purchaser has-in addition to the username and password, when automated risk assessments indicate an increased likelihood of fraudulent activity.The MFA capabilities for e-commerce used in this guide are based upon the Fast IDentity Online (FIDO) Universal Second Factor (U2F) authentication specification.The methods chosen in this guide provide examples that can be adopted by retailers to help reduce e-commerce fraud.The NCCoE sought existing technologies that provide the following capabilities: integrate MFA into online shopping systems  mitigate potential exposure to online fraud  integrate into a variety of retail-information technology architectures  provide authentication options to retailers:• capabilities that assess and mitigate a retailer's shopping-transaction risk factors ______________________________________________________________________________________________________ This publication is available free of charge from: https://

Read the paper · More papers on PaperTik