S-Mbank: Secure Mobile Banking Authentication Scheme Using Signcryption, Pair Based Text Authentication, and Contactless Smartcard
Dea Saka Kurnia Putra, Mohamad Ali Sadikin, Susila Windarta

TL;DR
S-Mbank introduces a secure mobile banking authentication scheme replacing SMS with contactless smart cards, utilizing signcryption, pair-based text authentication, and mutual two-factor authentication to enhance security against common mobile banking threats.
Contribution
The paper proposes a novel mobile banking authentication scheme combining contactless smart cards, signcryption, and pair-based text authentication for improved security and resistance to attacks.
Findings
Enhanced security against SMS spoofing and shoulder-surfing.
Effective use of signcryption for computational efficiency.
Security verified using Scyther analysis tool.
Abstract
Nowadays, mobile banking becomes a popular tool which consumers can conduct financial transactions such as shopping, monitoring accounts balance, transferring funds and other payments. Consumers dependency on mobile needs, make people take a little bit more interest in mobile banking. The use of the one-time password which is sent to the user mobile phone by short message service (SMS) is a vulnerability which we want to solve with proposing a new scheme called S-Mbank. We replace the authentication using the one-time password with the contactless smart card to prevent attackers to use the unencrypted message which is sent to the user's mobile phone. Moreover, it deals vulnerability of spoofer to send an SMS pretending as a bank's server. The contactless smart card is proposed because of its flexibility and security which easier to bring in our wallet than the common passcode…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Advanced Authentication Protocols Security · Privacy, Security, and Data Protection
