'Security-on-a-Stick' to protect consumers and banks from the most sophisticated hacker attacks
October 29, 2008
The "security-on-a-stick" solution — a handy USB-sized device with a display, a smart card reader and buttons — protects a user's e-banking transactions from even the most malicious attacks. With the new device, developed by an expert team at IBM's Zurich Research Lab, a user sees exactly what transaction data the banking server receives. Moreover, he or she can approve or cancel each transaction directly with the banking server using the buttons on the device.
(PhysOrg.com) -- Resembling a memory stick with an integrated display, a prototype USB device developed at IBM's Zurich Research Lab brings a new level of security to online banking for consumers. Pilot devices are ready and available to banks for trials.
The Zone Trusted Information Channel (ZTIC) plugs into the USB port of any computer and creates a direct, secure channel to a bank's online transaction server, bypassing the PC which could be infected by malicious software (malware) or susceptible to hacker attacks.
The consumer can use the security stick to logon and validate all transactions via a display, while the USB device is securely connected to the server, safeguarding against today's ever more fiendish forms of attacks that can manipulate data in the background, hidden from the consumer and the bank. The USB device adds an extra level of security to the existing authentication solutions provided by smart card, PIN or one-time validation code, in order to counter the newest and most highly manipulative security threats.
Hackers are becoming increasingly inventive in their attempts to attack financial transactions on the Internet. Among the increasingly prominent threats are so called "Man-In-The-Middle" attacks, where a hacker inconspicuously intercepts and modifies the messages flowing between a user and a financial institution. The modified messages appear to be official transactions from the financial institution, and the messages going to the financial institution appear to be from the consumer.
Malware is an even more fiendish form of attack, where the hacker manages to install a virus or Trojan Horse in a user's personal computer and is then free to manipulate the messages seen by and sent by the user. This allows the attacker to redirect communications and manipulate the data displayed by the internet browser in real-time during the user's e-banking session and totally unnoticeable to the user's eyes.
Nearly 90 percent of identity attacks online are targeted at the financial services sector. A 2007 international study by the Swiss Reporting and Analysis Centre for Information Assurance (MELANI), found that successful malware intrusions have increased and that currently established "two-factor authentication systems (e.g. transaction authentication numbers, SecurID, etc.) do not afford protection against such attacks and must be viewed as insecure once the computer of the customer has been infected with malware."
ZTIC provides an extra layer of security in the presence of both of these attacks.
"In the presence of an ever more professionally operating e-crime scene, it became obvious that PC-software based authentication solutions were potentially vulnerable and that we needed to innovate to stay ahead. That was the starting point for developing the ZTIC," explained Dr. Peter Buhler, Manager Computer Science at IBM's Zurich Research Lab. "The design of the solution was governed by and is based on the analysis of pros and cons of present and announced alternative solutions."
This solution effectively moves all the cryptographic and critical user-interface processes away from a consumer's PC onto the ZTIC device, creating a trusted communication endpoint between the banking server and the user. With the new device, a user can then communicate securely with sensitive online services such as a banking server. In combination with a smart card, which can be inserted into the device, this new solution brings a new level of end-to-end security to online banking.
After initial lab prototypes had been realized by the researchers, first pilot devices have now been industrially manufactured and are ready for trials.
Even if a user's PC should be infected by malware that manipulates the information flow in the PC, the user can cancel the transaction while displayed on the ZTIC device. What the user sees on the ZTIC display is identical to what the server "sees," no matter what malicious intervention may occur on the PC or anywhere in the Internet. "Owing to the direct secure connection between ZTIC and server, the device essentially provides a safe window to the server," states Buhler.
Moreover, the ZTIC has been designed such that no change is required in either the server software or the software running on the client's PC. It runs on all major home computing operating systems.
Technological Specifications
The researchers designed the ZTIC as an USB device of about the same size as a memory stick. It runs the commonly used TLS/SSL protocol. The ZTIC hardware consists conceptually, at a minimum, of a processing unit, volatile and persistent memory, a small display and at least two control buttons (OK and Cancel) as well as an optional smartcard reader. The software is minimally configured with a complete TLS engine including all cryptographic algorithms required by today's SSL/TLS servers, an HTTP parser for analyzing the data exchanged between client and server, plus custom system software implementing the USB mass storage device profile and a networking proxy for running on a PC. It supports TLS/SSL client authentication as well as common chip-card based challenge/response protocols.
Provided by IBM
-
Cutting-edge cocktails light up New York
Feb 05, 2012 |
not rated yet |
1
-
Virtual Projection team puts iPhone writing on the wall (w/ video)
Jan 26, 2012 |
4.5 / 5 (4) |
4
-
OnStar opens gate for third-party developers
Jan 09, 2012 |
not rated yet |
2
-
Apple patent sends password secrets to adapters
Jan 06, 2012 |
1.6 / 5 (15) |
9
-
Researchers devise a way to make a simple quantum computer using holograms
Dec 21, 2011 |
4.5 / 5 (16) |
2
-
Fast photon control brings quantum photonic technologies closer
31 minutes ago |
5 / 5 (2) |
0
-
Engineers build first sub-10-nm carbon nanotube transistor
Feb 01, 2012 |
4.9 / 5 (33) |
30
-
Something old, something new: Evolution and the structural divergence of duplicate genes
Jan 31, 2012 |
4.6 / 5 (7) |
1
-
The hidden nanoworld of ice crystals: Revealing the dynamic behavior of quasi-liquid layers
Jan 30, 2012 |
5 / 5 (5) |
1
-
Stock market network reveals investor clustering
Jan 27, 2012 |
3.9 / 5 (23) |
8
-
How to tilt a object
13 hours ago
-
How to calculate total compressibility in liquid porous solid system
18 hours ago
-
Need help reading 3-D
Feb 11, 2012
-
A way to send and receive wireless data
Feb 11, 2012
-
Calling function with no input argument
Feb 10, 2012
-
Force free body diagram problem on gym equipment
Feb 10, 2012
- More from Physics Forums - General Engineering
More news stories
Teaching teens safety in the virtual world
A new cyber safety program on the dangers of social networking is being developed by Flinders University, in light of an alarming report which shows children as young as 12 are meeting internet strangers in ...
59 minutes ago |
not rated yet |
0
Ethanol mandate not the best option
Many people are willing to pay a premium for ethanol, but not enough to justify the government mandate for the corn-based fuel, a Michigan State University economist argues.
Technology / Energy & Green Tech
1 hour ago |
5 / 5 (1) |
0
Building a 'blind-friendly' Internet
Rakesh Babu demonstrates how a blind person uses the Internet.
1 hour ago |
not rated yet |
0
Microsoft India retail site down after 'cyber attack'
Microsoft said Monday it was investigating an attack by hackers on its Indian retail website, reportedly carried out by a Chinese group called the "Evil Shadow Team."
3 hours ago |
not rated yet |
0
Chinese city seizes Apple iPads in name dispute
(AP) -- Authorities have seized Apple iPads from retailers in a city in northern China due to a dispute with a domestic company that says it owns the iPad name, an official said Monday. The Chinese company said it is asking ...
3 hours ago |
not rated yet |
0
Fast photon control brings quantum photonic technologies closer
(PhysOrg.com) -- Using photons instead of electrons to transmit information could lead to faster and more secure ways to communicate, among other advantages. Now a team of physicists has taken another step toward realizing ...
Planck mission steps closer to the cosmic blueprint
(PhysOrg.com) -- ESA's Planck mission has revealed that our Galaxy contains previously undiscovered islands of cold gas and a mysterious haze of microwaves. These results give scientists new treasure to mine ...
New ability to regrow blood vessels holds promise for treatment of heart disease
(Medical Xpress) -- University of Texas at Austin researchers have demonstrated a new and more effective method for regrowing blood vessels in the heart and limbs a research advancement that could have ...
Nanostructured electrodes for rechargeable sodium-Ion batteries
Highly efficient 3V cathodes for rechargeable sodium-ion batteries have been developed by users from Argonne National Laboratory's Materials Science, Chemical Sciences & Engineering, and X-ray Sciences Divisions, ...
A lost world? How zooarchaeology can inform biodiversity conservation
A new study of tropical forests will provide a 50,000-year perspective on how animal biodiversity has changed, explored through an archaeological investigation of animal bones.
Myths and shame keep many from seeking bankruptcy protection
(PhysOrg.com) -- Two interesting facts that may counter modern ideas about bankruptcy: The overwhelming majority of U.S. filings belong to individuals rather than corporations or entities, and most of these ...
Oct 30, 2008
Rank: not rated yet
Like adapting 'wordpad' to read your *.docs
Known since the stoneage, but never used.
Cryptography can be used inside your operative system too:)
Then virus would need the operative systems 'private key' to infect it.
Still, it's a step forward.