Multi-Factor Authentication Method for Online Banking Services in South Africa
Glen Lehlohonolo Moepi, Topside Ehleketani Mathonsi · 2021 International Conference on Electrical, Computer and Energy Technologies (ICECET) · 2021
The banking institutions have adopted innovative banking online service technologies in an effort of increasing service delivery to their customers. However, the escalating threats and evolving attacks to the online banking services, are forcing the banking sectors to always re-evaluate and employ robust online authentication methods. In order to enforce confidentiality, integrity, and unauthorized disclosure of their customers' information. Most banking institutions have adopted the Two-Factor-Authentication (2FA) method which requires a username; a password and a code from the bank via a short message to the registered customer number for authentication. This method has proven to be less effective in combating banking online attacks. Thus, user credential harvest attacks are on the rise. In an effort of mitigating these attacks, this paper seeks to develop a more secure online banking Multi-Factor-Authentication (MFA) method in addition to the conventional username and password and customer device identification. While still adopting the traditional authentication methods used for online banking systems; the username and a password or Personal Identification Number (PIN). This paper seeks to incorporate the user biometrics, either a fingerprint or facial recognition depending on the technological features and specifications of their Internet of Things (IoT) device; combined with a bank registered device either via IP address, cookies, or a digital certificate as an extra layer of security for authentication for the online user authentication. In this paper, design science methodology is proposed in order to design the proposed MFA method. In the future, online users from different levels of skill will evaluate the prototype system against existing online authentication methods.