S'identifier
 

 The Financial Services Club Blog - Why identity management is so complicated - apr 2010

  • JLS
  • Jeudi 29/04/2010
  • 09:46
  • Lu 1333 fois
  • Version imprimable
 

Mots-clés :

Chris

Your latest blog on identity management is very timely and thought provoking.

I have come across a ‘Sudoku’ type grid to foil web fraud. The system works as under: - Transparent privacy cards with grids are generated by bank. Each card has a unique number pattern. A bunch of these grid cards is issued to customer - Customer logs into the internet banking portal using his ID and regular password. Another grid of privacy card size appears on screen - Customer aligns plastic card grid with screen matrix. Black cells on hand card and on screen grid mutually mask some cells with numbers - After superimposition, some number cells remain visible. These numbers become the one time password for transaction, which varies each time This technology works on the principle of ‘Challenge Response Authentication’ which is a method for proving one’s identity over an insecure medium without giving any information. This is designed to tackle the growing menace of phishing attacks on banking accounts, in which cheats trick you into giving your online passwords through deceptive emails and malicious software that can supply all key stroke information to hackers. The security strength of this system lies in the randomness of position and the random text in that position.

Thanks for this opportunity to interact.

Raghavan Guruswami, Hyderabad, India