Innovative solution to check phishing

Published - February 23, 2010 01:05 am IST - CHENNAI

K. Balaraju was thinking about an innovative way of teaching dance at Saarang using coloured squares on a transparent stage when he says he came up with the idea of secure online transactions that helped him finish his masters’ thesis and file four patents.

On Monday, M.S.Ananth, director, Indian Institute of Technology-Madras (IIT-M), launched IndusInd Bank launched Polaris Software’s Intellect Privacy Card anti-phishing suite at IIT-M, Mr. Balaraju’s alma mater.

Explaining the features of the card based on Mr. Balaraju’s idea, Polaris executives said internet banking customers would use multi-factor authentication to secure each transaction. The first level of security would be provided by the typical password-based login into the bank’s portal. The customer would be provided with a booklet of security cards – transparent sheets with grids of 10x6 squares with each square empty or shaded black or marked with a number. For each transaction, the customer would be prompted to use a particular card from the booklet and superimpose it on a grid generated by the portal on the computer monitor for that transaction. The numbers visible after such superimposition should be used as the password for that transaction.

Each card may be used for a certain number of transactions and each booklet would contain five to ten cards. Customers may submit requests for fresh booklets similar to requests for cheque books. Since each transaction generated a unique password and a physical superimposition was required to generate it, typical phishing attacks including keylogging, screenlogging or using dictionary methods to decipher passwords would not work in this case, executives said.

L.S.Ganesh, co-ordinator of the M.S.(Entrepreneurship) programme at IIT-M, said the Department of Management Studies had worked with the Department of Computer Science to come up with a user-ready product.

Ramesh Ganesan, head of transaction banking, IndusInd Bank, said the bank had said the bank was actively looking for innovations to protect internet banking customers’ data.

0 / 0
Sign in to unlock member-only benefits!
  • Access 10 free stories every month
  • Save stories to read later
  • Access to comment on every story
  • Sign-up/manage your newsletter subscriptions with a single click
  • Get notified by email for early access to discounts & offers on our products
Sign in

Comments

Comments have to be in English, and in full sentences. They cannot be abusive or personal. Please abide by our community guidelines for posting your comments.

We have migrated to a new commenting platform. If you are already a registered user of The Hindu and logged in, you may continue to engage with our articles. If you do not have an account please register and login to post comments. Users can access their older comments by logging into their accounts on Vuukle.