COSTECH Integrated Repository

A Secure and Efficient Multi-Factor Authentication Algorithm for Mobile Money Applications

Show simple item record

dc.creator Ali, Guma
dc.creator Dida, Mussa
dc.creator Sam, Anael
dc.date 2021-12-01T09:50:24Z
dc.date 2021-12-01T09:50:24Z
dc.date 2021-11-25
dc.date.accessioned 2022-10-25T09:15:56Z
dc.date.available 2022-10-25T09:15:56Z
dc.identifier https://doi.org/10.3390/fi13120299
dc.identifier https://dspace.nm-aist.ac.tz/handle/20.500.12479/1404
dc.identifier.uri http://hdl.handle.net/123456789/94706
dc.description This research article published by MDPI, 2021
dc.description With the expansion of smartphone and financial technologies (FinTech), mobile money emerged to improve financial inclusion in many developing nations. The majority of the mobile money schemes used in these nations implement two-factor authentication (2FA) as the only means of verifying mobile money users. These 2FA schemes are vulnerable to numerous security attacks because they only use a personal identification number (PIN) and subscriber identity module (SIM). This study aims to develop a secure and efficient multi-factor authentication algorithm for mobile money applications. It uses a novel approach combining PIN, a one-time password (OTP), and a biometric fingerprint to enforce extra security during mobile money authentication. It also uses a biometric fingerprint and quick response (QR) code to confirm mobile money withdrawal. The security of the PIN and OTP is enforced by using secure hashing algorithm-256 (SHA-256), a biometric fingerprint by Fast IDentity Online (FIDO) that uses a standard public key cryptography technique (RSA), and Fernet encryption to secure a QR code and the records in the databases. The evolutionary prototyping model was adopted when developing the native mobile money application prototypes to prove that the algorithm is feasible and provides a higher degree of security. The developed applications were tested, and a detailed security analysis was conducted. The results show that the proposed algorithm is secure, efficient, and highly effective against the various threat models. It also offers secure and efficient authentication and ensures data confidentiality, integrity, non-repudiation, user anonymity, and privacy. The performance analysis indicates that it achieves better overall performance compared with the existing mobile money systems.
dc.format application/pdf
dc.language en
dc.publisher MDPI
dc.subject Mobile money systems
dc.subject Multi-factor authentication
dc.subject Piometric fingerprint
dc.subject Fernet encryption
dc.subject Mobile money
dc.title A Secure and Efficient Multi-Factor Authentication Algorithm for Mobile Money Applications
dc.type Article


Files in this item

Files Size Format View
JA_CoCSE_2021.pdf 9.342Mb application/pdf View/Open

This item appears in the following Collection(s)

Show simple item record

Search COSTECH


Advanced Search

Browse

My Account