Impact of 2FA in Angola Bank Transactions
- 1 ACITE-Academia de Ciências Sociais e Tecnologias, Luanda, Angola
- 2 ACITE-Academia de Ciências Sociais e Tecnologias, Luanda, Angola
- 3 ACITE-Academia de Ciências Sociais e Tecnologias, Luanda, Angola
Abstract
With the advent of formalization of the Angolan economy, the use of electronic payment systems and internet banking, access to which in the traditional model is via a static credential, has become increasingly common, presenting a high degree of vulnerability nowadays, exposing confidential information, sensitive or protected from unauthorized persons. Electronic payment systems are heavily dependent on ICTs and other emerging technologies (fintech) in which customers or users must authenticate themselves to access banking products and services. Unauthorized access to sensitive authentication information can result in financial losses and compromise the image and good name of a given financial institution, in addition to a loss of confidence in the customer’s use of the electronic payment system and internet banking. Given the high rates of fraud and scams motivated by weak authentication systems (static credentials), there was a need to implement the second authentication factor (2FA) which adds another layer of security for accessing or carrying out a banking transaction. For this reason, we will take a look at the impact of the implementation of 2FA in the Angolan Payment System, as well as technologies and solutions to mitigate this problem that greatly affects Angolan families and companies.
- Almeida, M. C. (2010). Audit: A Modern and Complete Curse (7th ed.). Atlas.
- Calado, M. P. (2015). Angolan Emergency Medical Service: Optimization Using Multi-Agent Syste ms . Luanda-Angola.
- Calado, M. P., Ramos, A. A., & Jonas, P. (2019). An Application to Generate, Correct and Grade Multiple-Choice Tests. In 2019 6th International Conference on Systems and Informatics (ICSAI) (pp. 1548-1552). IEEE. https://doi.org/10.1109/icsai48974.2019.9010132
- Cost of Data Breach Report (2024). IBM Security Report 2024 . USA: New Orchard Road Armonk, NY 10504. IBM Corporation & Ponemon Institute.
- Costa, F. M. S. (2024). Security in Banking Transactions: 2FA Implementation Proposal Using TOTP Protocol and Software Authenticator . Luan-da-Angola.
- D’Raihi, Pei, M., Symantec, Rydell, J., & Partwise (2011). TOTP: Time-Based One-Time Password Algorithm . Inc. RFC6238.
- Deloitte (2020). Fraud Survey Angola . Deloitte & Touche.
- Krawczyk, H., Bellare, M., & R. Canetti (1997). [RFC2104] “ HMAC: Keyed — Hashing for Message Authentication ” .
- M’Raihi, D., Bellare, M., Hoornaert, F., Naccache, D., & Ranen, O. (2005). HOTP: An HMAC-Based One-Time Password Algorithm . RFC4226.
- Piqueras Roger, J. (2020a). Security Analysis of SMS. International Journal for Digital Society, 10, 1556-1561.
- Piqueras Roger, J. (2020b). Security Analysis of SMS as a Second Factor of Authentication. Communications of the ACM, 63, 46-52. https://doi.org/10.1145/3424260
- Ramos, A., Calado, M., & Antunes, L. (2020). A Gift-Exchange Model for the Maintenance of Group Cohesion in a Telecommunications Scenario. In F. Herrera, K. Matsui, & S. Rodríguez-González (Eds.), Distributed Computing and Artificial Intelligence, 16th International Conference (pp. 189-196). Springer International Publishing. https://doi.org/10.1007/978-3-030-23887-2_22