India's Budget 2025-26 cOVEAGE
Presented by:
spot_img

Adaptive Multi-factor Authentication (MFA) in BFSI

Date:

Trending

A few months back (just after the Covid pandemic had started) an important change was implemented by a popular retail US Bank, Bank of America.  This was regarding how their retail net-banking customers would be logging into their banking account.  

- Advertisement -

All users of this bank can now set up an additional security measure during login in the form of a one-time authorization code, that would be sent to their registered mobile.  This will be in addition to their user id and password.  In the case of some users who are deemed to have a security risk during login (due to their high-risk score presumably arrived due to their inconsistent login patterns), this process has been made mandatory.  

Since the bank had suspected that post-covid the number of internet logins and transactions is going to be high, they probably implemented these changes to protect attempts to hijack genuine customer accounts by fraudulent means by hackers.

- Advertisement -

This shows that the era of Multi-Factor Authentication (MFA) has truly arrived and is here to stay.  Previously MFA was used only when bank transactions were performed by users, but now they are required even during the login process.  

The bank was using security questions as a second factor, but now probably had deemed that as risky, as typical user answers for popular security questions of theirs, can be lifted from their social media accounts by hackers.  

So where does this lead to?  Probably, to the next stage of MFA, which is Adaptive MFA in BFSI.  

What is Adaptive MFA? 

When a user login into a bank, several patterns about the login can be measured by the bank.  They can use this data to protect the customer from phishing and other hacker attacks. Like the typical time of the day the user logs in, the network & computer the login happens from, the Geolocation (GPS location) the user logs in from, the time they typically spend during the login, the type of transactions they normally perform, etc.  

With this wealth of data in-store, the banks can now assign risk scores for each activity through AI (Artificial Intelligence) and ML (Machine Learning) methods. If during any login there is an abnormal risk score detected for the user, an adaptive MFA authentication can be triggered.  That is, the user during that login session would be made to go through additional factors of authentication as part of their MFA Auth, for example, an OTP coupled with a Push based authentication sent through to the user’s mobile app, plus a security question or even a phone call based verification.  This helps to control or even eliminate the fraudulent access by a hacker, as it begins to happen.

How this prevents fraud?

During adaptive authentication, the key element to note is most of the factors that are used for authentication are instantly generated, so the hacker would not be knowing all the details of the authentication sequence and credentials in advance, for them to execute a phishing attack on the authenticated session of the user.  Even the user would not know these in advance for the hackers to target gullible users to get credentials from them, before the login.

What are the other adaptive authentication factors that can come into play?

MFA is normally performed by:

•    factors that the users know (passwords, security questions, pre-stored user-approved picture patterns and code numbers),

•    factors the users have (like OTP, mobile push authentication, google authentication) and 

•    factors that define who the users are (biometric authentications like retina scan, fingerprints, facial recognition).  

Out of these the first set of factors “the one the users know” are under severe attack by the hackers.  Hence banks will resort slowly to the second and third categories of authentications mentioned above.  These two categories of factors will be hard to pry out or reproduce like the passwords or security questions, for the reasons mentioned above.

What are the challenges in implementing Adaptive MFA?

The primary challenge is how to protect the user experience.  Users normally do not like too many restrictions just to get to their bank account.  Also, not all users are computer or mobile-savvy.  For example, the bank in the question above has instructed the users who do not have a mobile phone or do not have a valid phone number in the file, to call the bank to get authenticated.   

While this may work temporarily, this cannot be done by the user every time as the waiting times for such calls are high.  So, the banks have to arrive at the right mix of technology and user convenience to implement secure MFA login at the right cost to the user.

THE SNAPSHOTS, IN YOUR INBOX

Get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

THE SNAPSHOTS

Sign up to get quick snaps of everyday happening, directly in your inbox.

We don’t spam! Read our privacy policy for more info.

Support our independent journalism PayPal (Outside India) For PayU (For Indian Readers).

Raj Srinivas
Raj Srinivas
Primarily from a strong security and product engineering background, he has been the principal architect of MISP (Multi-Domain Identity Services Platform) & CIE (Cloud ID Exchange) – in-house IAM & Security products at 8K Miles.

More Latest Stories

More Articles

Finbok Reviews | How Finbok A ttracts and Retains New Traders Around the Globe in 2025

In the competitive world of online trading, choosing the right platform is essential for traders at any level. With a wide range of options...

Budget 2025 Expectations: GST Overhaul Tops Budget 2025 Wishlist for Business and Global Competitiveness

As India prepares for the Union Budget 2025, business leaders are sharing their hopes for reforms aimed at fostering innovation and simplifying processes. There's a strong push for rationalizing GST rates and easing compliance, which would improve the ease of doing business. Many are...

Budget 2025 Expectations: FHRAI Expects Reforms to Boost Hospitality and Tourism Sector

The Federation of Hotel & Restaurant Associations of India (FHRAI), has outlined its expectations...

Union Budget 2025 Expectations: India Inc. Expects Tax Reforms, Startup Incentives, and Support for MSMEs

As the Union Budget 2025 approaches, Business leaders from across industries are urging Finance...

Budget 2025 Expectations: Taabi Mobility CEO Pali Tripathi says, Logistics Sector Looks for Tech and Sustainability Focus in India’s Budget 2025

With Union Budget 2025 approaching, the logistics industry highlights the need for government action...

HCLTech Partners with Carrix to Modernize Global Port Operations Using AIoT

HCLTech, a leading global technology company, today announced an agreement with Carrix, the world’s...

The Sustainable Tech That Will Simplify Life as a Homeowner

Owning a home is the ultimate dream…until it’s 7 a.m., your driveway is buried...

Powering the Future: How Digitisation is Transforming Power Transmission & Distribution

As India, the third-largest producer, and consumer of electricity worldwide with over 442 gigawatts...

Top Cybersecurity Practices for Small Businesses: Why a VPN is a Must-Have

In today's hyperconnected world, small businesses face a growing number of cybersecurity threats that can cripple operations and erode customer trust. From phishing attacks...

Equal, OneMoney Appoints Former Supreme Court Judge Justice B.N. Srikrishna as Chairman

Equal, one of India’s leading secure data sharing platforms, and its strategic investee OneMoney...

ECO Hotels & Resorts Ltd Opens 60 Room Property In Bengaluru

ECO Hotels & Resorts Limited, a stock exchange-listed mid-segment hotel chain has today said...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

Botanic Healthcare draws $30 Mn in fresh round funding

Telangana-based nutraceutical company, Botanic Healthcare today announced that it has raised ₹250 crore (approximately...

Delhi High Court Shields Upstox Trademark Rights, Targets Telegram Violators

Delhi High Court has granted an interim injunction in favor of RKSV Securities India Pvt. Ltd., also known as Upstox, restraining unknown entities from...

GPS Renewables Appoints Central Bank of India ex-MD Homai Ardeshir Daruwalla As Independent Director

GPS Renewables, an India-based biogas engineering company on Monday announced the appointment of Central Bank of India's Former Managing Director and Chairman, Homai Ardeshir Daruwalla as an Independent Director to its board. Homai Ardeshir Daruwalla currently serves as an independent director at Vizag Seaport...

Strengthening the First Line of Defense with People, Processes, and Technology

Globally and across industries, the risk landscape is growing more volatile and complex, with...

N Space Tech Launches Maiden Payload SwetchaSAT-V0 on ISRO’s POEM-4

N Space Tech, an India-based defense and aerospace startup, has successfully launched its first...

Embracing Linguistic Diversity: How Multilingual Education Supports India’s Linguistic Heritage

India is a country of rich culture, multilingualism, and heritage. It is the most...

5 Tips to Expand Your Client Base Efficiently

Growing your client base is essential for the success and sustainability of your business....

SustVest Secures $1.7 Mn in pre-Series A round

Haryana-based sustainable investment platform SustVest has raised $1.7 million in a mix of equity...

Web3 in Supply Chain: Qila’s CEO Siddharth Ugrankar On Simplifying Blockchain Adoption for Business

Speaking to TechGraph, Siddharth Ugrankar, CEO of Qila.io highlighted the potential of the company's...

Relata’s Hyper-Realism: CEO Samudragupta Talukdar On Personalized Home Buying Experiences

In an exclusive conversation with TechGraph, Samudragupta Talukdar, Founder and CEO of Relata, a...

Godrej Capital’s Gen AI Plan: CTO Jyothirlatha B on SAKSHAM AI and the Future of Financial Services

Speaking to TechGraph, Godrej Capital CTO Jyothirlatha B shared how the company is harnessing...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...

Neon54 Casino Review: A Vibrant Gaming Experience

When it comes to striking the perfect balance between entertainment and innovation, Neon54 Casino...

Muxcap: Making Bold Moves in Innovation

Muxcap is on a mission to transform the online trading experience by combining cutting-edge...

HR Tech Impact on Employee Learning and Development

In today’s fast-paced world of work, learning and development (L&D) are no longer just...

Proxgy Snaps $3 Mn from Indian Cricketer Ajinkya Rahane and others

Proxgy, a Gurugram-based technology company specializing in virtual assistance and concierge services, has announced...

Groyyo Promotes Nitin Jain to Co-founder

B2B manufacturing technology company Groyyo has announced the promotion of its Managing Director (Exports),...

Botanic Healthcare draws $30 Mn in fresh round funding

Telangana-based nutraceutical company, Botanic Healthcare today announced that it has raised ₹250 crore (approximately...

Godrej Capital’s Gen AI Plan: CTO Jyothirlatha B on SAKSHAM AI and the Future of Financial Services

Speaking to TechGraph, Godrej Capital CTO Jyothirlatha B shared how the company is harnessing...

Preparing for a Data-Driven Future: How the GRE Assesses Academic and Analytical Readiness

As sectors such as artificial intelligence (AI) and machine learning continue to grow and...

Exploring the broad appeal of football: from fashion to video games

Football, often called the world's game, goes far beyond the pitch. Its influence extends...