DOI QR코드

DOI QR Code

A Security Reference Model for the Construction of Mobile Banking Services based on Smart Phones

  • Shin, Yong-Nyuo (Department of Computer Engineering, Hanyangcyber University) ;
  • Shin, Woo-Chang (Department of Computer Science, SeoKyeong University)
  • Received : 2011.10.25
  • Accepted : 2011.11.16
  • Published : 2011.12.25

Abstract

As smart phones have become widely adopted, they have brought about changes in individual lifestyles, as well as significant changes in the industry. As the mobile technology of smart phones has become associated with all areas of industry, it is not only accelerating innovation in other industries such as shopping, healthcare service, education, and finance, but is also creating new markets and business opportunities. The preparation of thorough security measures for smart phones is increasing in demand. While offering excellent mobility and convenience, smart phones can be exposed to a range of violation threats. In particular, it is necessary to make efforts to develop a security system that can preemptively cope with potential security threats in the banking service area, which requires a high level of reliability. This paper suggests a security reference model that is considered for the smart phone-based joint mobile banking development project being undertaken by the Bank of Korea in 2010. The purpose of this study is to make a security reference model for a reliable smart phone-based mobile financial service, by recognizing the specific security threats directed toward smart phones, and providing countermeasures to these security threats. The proposed mobile banking security reference model is useful in improving system security by systematically analyzing information security threats to the mobile financial service, and by presenting the guideline for the preparation of countermeasures.

Keywords

References

  1. Joris Claessens, Valentin Dem, and Joos Vandewalee, "On the security of Today's Online Electronic Banking Systems", Computers & Security, Elsevier advanced Technology, 2002, Vol 21, No 3, pp. 257-269.
  2. "Utilization on internet banking service in korea", The Bank of Korea, 2010.
  3. Yung Fu Chang, C.S. Chen, and Hao Zhou, "Smart phone for mobile commerce", Computers & Security, Elsevier advanced Technology, 2009, No 31, pp. 740-747.
  4. Paivi Heikkinen, "A framework for evaluating mobile payments", Financial Markets and Statistics, Bank of Finland, 2009.
  5. Jaewon kim, "Smartphone banking gains popularity", the korea times, 2010.
  6. Worldwide Mobile Security 2010-2014 Forecast and Analysis, IDC, 2010.
  7. Symbian Developer Network, http://developer.symbian.com/
  8. Kaspersky Lab, http://www.kaspersky.com/news?id=207575728
  9. White paper of proxim corporation, "Rogue access point detection: Automatically detect and manage wireless threats to your network, proxim wireless networks", 2004.
  10. Android Development, http://www.android-devs.com/?p=127
  11. Apple iPhone, http://www.apple.com/iphone/
  12. Giles Hogben, Marnix Dekker, "Smartphones: Information security risks, opportunities and recommendations for users", European Network and Information Security Agency, 2010.
  13. Hahmin Jung, Dong Hum Kim, "Control of a Mobile Robot Based on a Tangible Interface using iPhone", Journal of Korea Institute of Intelligent Systems, 2011, Vol 21, No 3, pp. 335-340. https://doi.org/10.5391/JKIIS.2011.21.3.335
  14. Yong-Hyun Cho, "System Development for Guiding Job Information Based on Android Smart-Phone", Journal of Korea Institute of Intelligent Systems, 2011, Vol 21, No 5, pp. 588-594. https://doi.org/10.5391/JKIIS.2011.21.5.588
  15. Yong-Nyuo Shin, "Standard Implementation for Privacy Framework and Privacy Reference Architecture for Protecting Personally Identifiable Information", International Journal of Fuzzy Logic and Intelligent Systems, 2011, Vol 11, No 3, pp. 197-203. https://doi.org/10.5391/IJFIS.2011.11.3.197