[Paper Review] M-Banking Security - a futuristic improved security approach
This paper proposes a novel m-banking security framework integrating steganography with custom session and request IDs to enhance transaction confidentiality and authenticity. By embedding encrypted data within digital carriers and enforcing unique, non-guessable identifiers, the approach mitigates man-in-the-middle attacks and spoofing, significantly improving security over conventional methods without increasing user burden.
In last few decades large technology development raised various new needs. Financial sector has also no exception. People are approaching all over the world to fulfill there dreams. Any sector needs to understand changing need of customer. In order to satisfy financial need for customer banks are taking help of new technology such as internet. Only problem remain is of security. The aim of this work is to provide a secure environment in terms of security for transaction by various ways. In order to improve security we are making use of "Steganography" technique in the way never used before. Task of enhancing security include construction of formula for both data encryption and also for hiding pattern. Server should not process any fake request hence concept of custom "Session id" and "Request id" is introduced. Implementation of such a security constraints in banking sector not only help to serve customer in better way but also make customer confident and satisfy.
Motivation & Objective
- To address growing security vulnerabilities in mobile banking due to increasing digital transaction volumes.
- To reduce reliance on traditional encryption by introducing steganography for data obfuscation.
- To prevent fake requests through the introduction of custom, unpredictable session and request IDs.
- To enhance user trust and system resilience in m-banking environments through layered security mechanisms.
- To provide a scalable, application-level security extension compatible with existing banking infrastructures.
Proposed method
- Application of steganography to hide encrypted transaction data within digital media (e.g., images or audio) to prevent eavesdropping.
- Design of a custom session ID and request ID mechanism to prevent replay and spoofing attacks.
- Development of a dual formula for data encryption and steganographic pattern generation to ensure data integrity and concealment.
- Integration of the steganographic layer between the client and server to obscure sensitive transaction details during transmission.
- Enforcement of server-side validation to reject any request lacking a valid, dynamically generated session or request ID.
- Use of a hybrid approach combining symmetric encryption with steganographic embedding for end-to-end confidentiality.
Experimental results
Research questions
- RQ1How can steganography be effectively applied to mobile banking transactions to enhance data confidentiality?
- RQ2What mechanisms can prevent replay and spoofing attacks in m-banking systems without increasing user complexity?
- RQ3Can custom session and request IDs significantly reduce the risk of unauthorized transaction injection?
- RQ4How does the integration of steganography and custom identifiers improve overall system resilience compared to standard encryption alone?
- RQ5To what extent can this approach be deployed in real-world banking systems with minimal architectural changes?
Key findings
- The proposed system successfully conceals encrypted transaction data within digital carriers using steganography, rendering it undetectable to passive eavesdroppers.
- Custom session and request IDs prevent replay and spoofing attacks by ensuring each transaction is uniquely identifiable and time-bound.
- The dual formula for encryption and steganographic pattern generation enhances data integrity and reduces predictability of hidden content.
- Server-side validation of session and request IDs effectively blocks all unauthorized or malformed requests.
- The framework demonstrates improved resistance to common m-banking threats such as MITM and session hijacking in simulated environments.
- The approach maintains backward compatibility with existing banking systems while significantly increasing attack surface difficulty.
Better researchstarts right now
From reading papers to final review, dramatically reduce your research time.
No credit card · Free plan available
This review was created by AI and reviewed by human editors.