Cryptographic Key Management principles applied in South African Internet Banking

نویسنده

  • Emile Parkin
چکیده

The convenience of Internet Banking and the breadth of functionality that it provides to its users have made it exceptionally popular, especially in countries like South Africa. Gone are the days of standing in long queues in the bank just to authorise a debit order or to get an account statement. But where accountholders in the past had to enter a secret PIN into a closed and secure system (e.g. ATM or Bank Branch system), these secrets must now be communicated through the insecure Internet. New threats and vulnerabilities within operating systems and Internet applications are published daily and the obvious question becomes apparent: Is it safe to use Internet Banking applications? In this paper, the current architecture of Internet Banking is re-evaluated, with specific focus awarded to the cryptographic security controls implemented in such systems. Since the current sense of security is primarily based on the premise of cryptography, it is appropriate to assess if best practice principles and standards of cryptography and key management have been applied, and to what extend. Furthermore, we assess the value of applying key management principles to a PIN (or password) as if it is a cryptographic key. Through this exercise, it becomes clear that the use of a static secret value to uniquely authenticate a user is not a secure mechanism and it is not appropriate for authentication over the Internet. Possible solutions are also provided as guidelines in addressing this issue.

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Customer Expectations of Internet Banking in South Africa

The Internet has fundamentally changed the banking industry in South Africa by giving people more immediate control over the management of their finances. This research investigated whether a gap exists between customer expectations of Internet Banking and the satisfaction of these expectations in the virtual environment by South African banking institutions. The research was operationalized by...

متن کامل

Designing for the Functionality South African Internet Banking Websites Should Provide to Address the Needs of Generation-Y Users

Despite the widespread adoption of Internet banking there are no validated guidelines on the functionality the younger, techno-savvy Generation-Y customer segment (18-35 year age bracket) expect from Internet banking websites. This research investigated the functionality the Generation-Y customer segment require from South-African Internet banking websites. The User Centred Design (UCD) philoso...

متن کامل

Customer Satisfaction with Cell Phone Banking in South Africa

The purpose of this study was to investigate the factors influencing satisfaction with cell phone banking in South Africa. The study followed a qualitative approach in which in-depth interviews were conducted with a set of South African cell phone banking users. Thematic analysis was employed to analyse the data. It was confirmed that factors known to influence satisfaction with other electroni...

متن کامل

A Framework for the Comparison of Best Practice Recommendations and Legal Requirements for South African Banks

South African home users of the Internet use it to perform various everyday functions. These functions include, but are not limited to, online shopping, online gaming, social networking and online banking. Home users of online banking face multiple threats, such as phishing and social engineering. These threats come from hackers attempting to obtain confidential information, such as online bank...

متن کامل

Principles in knowledge management maturity: a South African perspective

Purpose – The institutionalization of knowledge management (KM) principles, policies and strategies could be summarized as being diverse, problematic and located across the spectrum of views. Studies suggest that very little is reported on how these principles are institutionalized in organizations. This paper seeks to examine the role these principles play in the establishment of KM and report...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

برای دانلود متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2005