Vulnerability of the Dynamic Array PIN Protocol

Thumbnail Image

Date

2022-02-28

Journal Title

Journal ISSN

Volume Title

Publisher

Ingénierie des Systèmes d’Information

Abstract

We recently proposed the Dynamic Array PIN protocol (DAP), which is a novel approach for user authentication on Automated Teller Machines. DAP replaces bank cards with smartphones that support Near Field Communication (NFC) and allows a user to enter his PIN code in a secure way. We showed that DAP is resistant to 13 different attacks and is therefore better and more cost effective than several other solutions from the literature. However, after carrying a deeper analysis we found that DAP is vulnerable to a complex attack that might lead to unauthorized transactions on ATMs if the user smartphone and his PIN code are both stolen. In this paper we expose how the user PIN code can be discretely discovered using multiple eavesdropping videos or camera records. We also propose several fixes for this vulnerability.

Description

Keywords

Citation

Chabbi, S., Chefrour, D. (2022). Vulnerability of the dynamic array PIN protocol. Ingénierie des Systèmes d’Information, Vol. 27, No. 1, pp. 41-47. https://doi.org/10.18280/isi.270105

Collections

Endorsement

Review

Supplemented By

Referenced By