2011 6th International Conference on Risks and Security of Internet and Systems (CRiSIS) 2011
DOI: 10.1109/crisis.2011.6061836
|View full text |Cite
|
Sign up to set email alerts
|

A security mechanism to increase confidence in m-transactions

Abstract: International audienceCurrently, NFC phones are coming in the handheld market, providing facilities to perform m-transactions. Obviously, this type of operation requires special security precautions. Indeed, a malicious code could intercept and hijack the system, even if there is a smart card. For example, the amount of the payment displayed in the terminal can be hijacked by an attacker to fool the user, or user's credential can be stolen thanks to a keylogger (and thus malicious codes can perform unwanted m-… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1
1
1
1

Citation Types

0
4
0

Year Published

2015
2015
2019
2019

Publication Types

Select...
4
2

Relationship

0
6

Authors

Journals

citations
Cited by 6 publications
(4 citation statements)
references
References 6 publications
0
4
0
Order By: Relevance
“…Yeh et al [18] introduced a mobile user authentication system in cloud environments that uses CAPTCHA to protect cloud servers against malicious registrations and logins. Pequegnot et al [19] suggested to use CAPTCHA to improve the security of PIN codes on mobile devices against automated attacks. Recently, Althamary el al.…”
Section: Captcha Strengthened Authentication and Its Alternativesmentioning
confidence: 99%
“…Yeh et al [18] introduced a mobile user authentication system in cloud environments that uses CAPTCHA to protect cloud servers against malicious registrations and logins. Pequegnot et al [19] suggested to use CAPTCHA to improve the security of PIN codes on mobile devices against automated attacks. Recently, Althamary el al.…”
Section: Captcha Strengthened Authentication and Its Alternativesmentioning
confidence: 99%
“…Pequegnot et al [11] insisted to use CAPTCHA to enhance the security of PIN codes against automated attacks in mobile devices. To improve the protection of passwords against various attacks Althamary et al [12] proposed a CAPTCHA based authentication in the cloud environment.…”
Section: Literature Reviewmentioning
confidence: 99%
“…Thus, it requires the selection of some elements in the grid, instead of traditional textual CAPTCHAs that requires inputting a string of characters using the mobile keyboard, which results to be challenging. Despite showing some advantages, this scheme has Pequegnot et al [11] proposed an authentication mechanism based on graphical Turing test to increase the confidence in mobile transactions. Their mechanism consists of typing a secure code of three-digit displayed in a CAPTCHA, in addition to the four-PIN digits.…”
Section: Related Workmentioning
confidence: 99%
“…As stated above, we also assume that the sensitive application is running in a TEE or a SE, and is protected with a common PIN code. Despite the strong isolation provided by TEE and SE to protect sensitive applications, the malicious code running in Android OS can steal the user's PIN code (see e.g., [32,33,34,35]) and replay this PIN in the next authentication session to execute unwanted transactions without the user's consent [11]. , most of the current applications running on mobile devices still use PIN codes to authenticate the user that aims to access sensitive services/data or to perform security-critical transactions.…”
Section: Assumptions and Threat Modelmentioning
confidence: 99%