Javascript must be enabled to continue!
Development of a secure multi-factor authentication algorithm for mobile money applications
View through CrossRef
With the expansion of industry 4.0, financial technology (FinTech) has become paramount in this era. Mobile money as one of the FinTech has immensely contributed to improving financial inclusions among the unbanked population in many developing countries. Several mobile money schemes were developed to ensure easy access to mobile money services. However, they have suffered severe authentication security challenges since implementing two-factor authentication (2FA). Therefore, this research developed a secure multi-factor authentication (MFA) algorithm for mobile money applications that combines personal identification number (PIN), one-time password (OTP), and biometric fingerprints to authenticate the mobile money subscribers. It also used the customer’s biometric fingerprints and the agent’s quick response (QR) code to authorise money withdrawal. The PINs and OTP are secured by secure hashing algorithm-256 (SHA-256) and biometric fingerprints by Fast IDentity Online (FIDO), where the Rivest-Shamir-Adleman (RSA) encryption protects the public/private key pair and the fingerprint templates. The QR codes, confidential financial information in the databases, and all the data before transmission to the remote databases are secured using Fernet encryption. A design science research approach was employed in the research using a mixed-method. The review results identified and grouped the threat models into attacks against privacy, authentication, confidentiality, integrity, and availability. The cryptographic functions and personal identification were the countermeasures. The survey identified authentication attacks, identity theft, phishing attacks, and PIN sharing as the crucial security issues Uganda’s mobile money systems encountered. The security analysis of the designed algorithm and developed native genuine mobile money (G-MoMo) applications proved that it provided robust security during authentication and ensured data confidentiality, integrity, privacy and user anonymity. It is highly effective against several security attacks and resilient to non-repudiation. The performance analysis results showed that the algorithm enhanced security but had high communication overhead and computational cost. Lack of a forward navigation button, lack of uniformity in the applications menu title, lack of search field options, lack of actions needed for recovery, and lack of help & documentation, were identified as the results of the usability issues with the native G-MoMo applications’ user interfaces. While the results of the usability testing showed that the native G-MoMo applications were learnable, effective, efficient, memorable, had few errors, satisfaction, ease of use, aesthetic, helpful, easy to integrate, and understandable. In conclusion, implementing a secure mobile money authentication using the ii novel approach combining multiple factors helps mobile money subscribers and other stakeholders trust the mobile money industry since the security goals are highly maintained.
Title: Development of a secure multi-factor authentication algorithm for mobile money applications
Description:
With the expansion of industry 4.
0, financial technology (FinTech) has become paramount in this era.
Mobile money as one of the FinTech has immensely contributed to improving financial inclusions among the unbanked population in many developing countries.
Several mobile money schemes were developed to ensure easy access to mobile money services.
However, they have suffered severe authentication security challenges since implementing two-factor authentication (2FA).
Therefore, this research developed a secure multi-factor authentication (MFA) algorithm for mobile money applications that combines personal identification number (PIN), one-time password (OTP), and biometric fingerprints to authenticate the mobile money subscribers.
It also used the customer’s biometric fingerprints and the agent’s quick response (QR) code to authorise money withdrawal.
The PINs and OTP are secured by secure hashing algorithm-256 (SHA-256) and biometric fingerprints by Fast IDentity Online (FIDO), where the Rivest-Shamir-Adleman (RSA) encryption protects the public/private key pair and the fingerprint templates.
The QR codes, confidential financial information in the databases, and all the data before transmission to the remote databases are secured using Fernet encryption.
A design science research approach was employed in the research using a mixed-method.
The review results identified and grouped the threat models into attacks against privacy, authentication, confidentiality, integrity, and availability.
The cryptographic functions and personal identification were the countermeasures.
The survey identified authentication attacks, identity theft, phishing attacks, and PIN sharing as the crucial security issues Uganda’s mobile money systems encountered.
The security analysis of the designed algorithm and developed native genuine mobile money (G-MoMo) applications proved that it provided robust security during authentication and ensured data confidentiality, integrity, privacy and user anonymity.
It is highly effective against several security attacks and resilient to non-repudiation.
The performance analysis results showed that the algorithm enhanced security but had high communication overhead and computational cost.
Lack of a forward navigation button, lack of uniformity in the applications menu title, lack of search field options, lack of actions needed for recovery, and lack of help & documentation, were identified as the results of the usability issues with the native G-MoMo applications’ user interfaces.
While the results of the usability testing showed that the native G-MoMo applications were learnable, effective, efficient, memorable, had few errors, satisfaction, ease of use, aesthetic, helpful, easy to integrate, and understandable.
In conclusion, implementing a secure mobile money authentication using the ii novel approach combining multiple factors helps mobile money subscribers and other stakeholders trust the mobile money industry since the security goals are highly maintained.
Related Results
Development of a secure multi-factor authentication algorithm for mobile money applications
Development of a secure multi-factor authentication algorithm for mobile money applications
With the evolution of industry 4.0, financial technologies have become paramount and mobile money as one of the financial technologies has immensely contributed to improving financ...
Development of a secure multi-factor authentication algorithm for mobile money applications
Development of a secure multi-factor authentication algorithm for mobile money applications
With the evolution of industry 4.0, financial technologies have become paramount and mobile money as one of the financial technologies has immensely contributed to improving financ...
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
ESSENTIAL SECURITY PRACTICES FOR FORTIFYING MOBILE APPS
“Essential Security Practices for Fortifying Mobile Apps” is a definitive guide designed to empower developers, security professionals, and organizations with the knowledge and too...
Applying a user-centered approach to evaluate the usability of a mobile application for health professionals in home care services (Preprint)
Applying a user-centered approach to evaluate the usability of a mobile application for health professionals in home care services (Preprint)
BACKGROUND
Mobile health (mHealth), or the use of mobile devices in medicine and health, is a sub-category of e-health. mHealth interventions are designed t...
ANALISIS PERTIMBANGAN MAHKAMAH AGUNG DALAM MENGABULKAN KASASI TERDAKWA (STUDI PUTUSAN NOMOR 2959/K/PID.SUS/2022)
ANALISIS PERTIMBANGAN MAHKAMAH AGUNG DALAM MENGABULKAN KASASI TERDAKWA (STUDI PUTUSAN NOMOR 2959/K/PID.SUS/2022)
<p><em><span class="markedContent"><span style="left: calc(var(--scale-factor)*195.53px); top: calc(var(--scale-factor)*496.87px); font-size: calc(var(--scale-...
A Secure and Efficient Multi-Factor Authentication Algorithm for Mobile Money Applications
A Secure and Efficient Multi-Factor Authentication Algorithm for Mobile Money Applications
With the expansion of smartphone and financial technologies (FinTech), mobile money emerged to improve financial inclusion in many developing nations. The majority of the mobile mo...
Mobile Money Adoption and Performance of Informal Family Enterprises During COVID-19 Lockdown in Ekiti State, Nigeria
Mobile Money Adoption and Performance of Informal Family Enterprises During COVID-19 Lockdown in Ekiti State, Nigeria
The study was carried out on family enterprises in Ekiti state during COVID-19 Lockdown: to identify socio-economic characteristics of the family enterprises; to determine the type...
Two-Factor Authentication Scheme for Mobile Money: A Review of Threat Models and Countermeasures
Two-Factor Authentication Scheme for Mobile Money: A Review of Threat Models and Countermeasures
The proliferation of digital financial innovations like mobile money has led to the rise in mobile subscriptions and transactions. It has also increased the security challenges ass...

