Zero-Trust Mobile Application Architecture for Financial Transactions and Fraud Prevention
Keywords:
zero-trust architecture; mobile banking security; continuous authentication; behavioral biometrics; fraud detection; machine learning; trusted execution environment; multi-factor authentication; micro-segmentation; financial-grade API; malware detection; risk-adaptive policy engineAbstract
With a new network perimeter, mobile financial applications are increasingly adopting a “never trust, always verify” approach to provide protection from credential theft, session hijacking and transaction fraud. This paper consolidates results of 21 sources to propose a unified zero-trust mobile application architecture for financial services which merges the topics of zero-trust architecture, continuous behavioral-biometric authentication, mobile malware detection and machine-learning-based fraud detection. Using National Institute of Standards and Technology, Special Publication 800-207, which requires per-session decision on privileges to be granted on authorization based on a dedicated policy engine, and not on static network location trust. Equal error rates of 2.2% - 15.1% have been reported for continuous authentication mechanisms evaluated, such as touchscreen gestures, hand-movement-orientation-grasp (HMOG) sensor fusion, and keystroke dynamics. The surveyed literature indicates that the accuracy of machine-learning fraud-detection techniques for financial-statement and credit-card fraud detection ranges from about 78% to 99.98%. The proposed architecture is layered on trusted execution environments on the device, network-level micro-segmentation, and application-level risk-adaptive policy enforcement, and is compared to perimeter based virtual private network models on a number of quantitative measures such as breach containment capability, implementation complexity, and cost efficiency. The results show that zero-trust mobile deployments lower the risk of lateral movement, and add some computational and onboarding cost, but the results are measurable and manageable. The paper ends by summarizing some of the problems with migration, regulatory issues regarding open-banking requirements, and some suggested future research directions.
Downloads
References
M. Abuhamad, A. Abusnaina, D. Nyang, and D. Mohaisen, “Sensor-based continuous authentication of smartphones' users using behavioral biometrics: A contemporary survey,” IEEE Internet of Things J., vol. 8, no. 1, pp. 65–84, 2021.
K. G. Al-Hashedi and P. Magalingam, “Financial fraud detection applying data mining techniques: A comprehensive review from 2009 to 2019,” Comput. Sci. Rev., vol. 40, p. 100402, 2021.
M. N. Ashtiani and B. Raahemi, “Intelligent fraud detection in financial statements using machine learning and data mining: A systematic literature review,” IEEE Access, vol. 10, pp. 72504–72525, 2021.
E. Bertino, “Zero trust architecture: Does it help?” IEEE Security & Privacy, vol. 19, no. 5, pp. 95–96, 2021.
C. Buck, C. Olenberger, A. Schweizer, F. Völter, and T. Eymann, “Never trust, always verify: A multivocal literature review on current knowledge and research gaps of zero-trust,” Comput. Secur., vol. 110, p. 102436, 2021.
D. Fett, P. Hosseyni, and R. Küsters, “An extensive formal security analysis of the OpenID financial-grade API,” in Proc. 2019 IEEE Symp. Security and Privacy (S&P), 2019, pp. 1054–1072.
M. A. Ferrag, L. Maglaras, A. Derhab, and H. Janicke, “Authentication schemes for smart mobile devices: Threat models, countermeasures, and open research issues,” Telecommun. Syst., vol. 73, pp. 317–348, 2020.
Y. He, D. Huang, L. Chen, Y. Ni, and X. Ma, “A survey on zero trust architecture: Challenges and future trends,” Wireless Commun. Mobile Comput., vol. 2022, Art. no. 6476274, 2022.
E. Ileberi, Y. Sun, and Z. Wang, “A machine learning based credit card fraud detection using the GA algorithm for feature selection,” J. Big Data, vol. 9, Art. no. 24, 2022.
V. Kouliaridis, K. Barmpatsalou, G. Kambourakis, and S. Chen, “A survey on mobile malware detection techniques,” IEICE Trans. Inf. Syst., vol. E103.D, no. 2, pp. 204–211, 2020.
K. Liu, S. Xu, G. Xu, M. Zhang, D. Sun, and H. Liu, “A review of Android malware detection approaches based on machine learning,” IEEE Access, vol. 8, pp. 124579–124607, 2020.
A. Ometov, S. Bezzateev, N. Mäkitalo, S. Andreev, T. Mikkonen, and Y. Koucheryavy, “Multi-factor authentication: A survey,” Cryptography, vol. 2, no. 1, Art. no. 1, 2018.
S. Rose, O. Borchert, S. Mitchell, and S. Connelly, Zero Trust Architecture, NIST Special Publication 800-207, National Institute of Standards and Technology, 2020.
M. Sabt, M. Achemlal, and A. Bouabdallah, “Trusted execution environment: What it is, and what it is not,” in Proc. 2015 IEEE Trustcom/BigDataSE/ISPA, vol. 1, 2015, pp. 57–64.
S. W. Shah, N. F. Syed, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “LCDA: Lightweight continuous device-to-device authentication for a zero-trust architecture (ZTA),” Comput. Secur., vol. 108, p. 102351, 2021.
Z. Sitová, J. Šeděnka, Q. Yang, G. Peng, G. Zhou, P. Gasti, and K. S. Balagani, “HMOG: New behavioral biometric features for continuous authentication of smartphone users,” IEEE Trans. Inf. Forensics Security, vol. 11, no. 5, pp. 877–892, 2016.
I. Stylios, S. Kokolakis, O. Thanou, and S. Chatzis, “Behavioral biometrics and continuous user authentication on mobile devices: A survey,” Inf. Fusion, vol. 66, pp. 76–99, 2021.
N. F. Syed, S. W. Shah, A. Shaghaghi, A. Anwar, Z. Baig, and R. Doss, “Zero trust architecture (ZTA): A comprehensive survey,” IEEE Access, vol. 10, pp. 57143–57179, 2022.
S. Teerakanok, T. Uehara, and A. Inomata, “Migrating to zero trust architecture: Reviews and challenges,” Security Commun. Netw., vol. 2021, Art. no. 9947347, 2021.
C. Thammarat and W. Kurutach, “A lightweight and secure NFC-base mobile payment protocol ensuring fair exchange based on a hybrid encryption algorithm with formal verification,” Int. J. Commun. Syst., vol. 32, no. 12, Art. no. e3991, 2019.
J. Zhang, B. Chen, Y. Zhao, X. Cheng, and F. Hu, “Data security and privacy-preserving in edge computing paradigm: Survey and open issues,” IEEE Access, vol. 6, pp. 18209–18237, 2018.
Downloads
Published
How to Cite
Issue
Section
License

This work is licensed under a Creative Commons Attribution-ShareAlike 4.0 International License.
All papers should be submitted electronically. All submitted manuscripts must be original work that is not under submission at another journal or under consideration for publication in another form, such as a monograph or chapter of a book. Authors of submitted papers are obligated not to submit their paper for publication elsewhere until an editorial decision is rendered on their submission. Further, authors of accepted papers are prohibited from publishing the results in other publications that appear before the paper is published in the Journal unless they receive approval for doing so from the Editor-In-Chief.
IJISAE open access articles are licensed under a Creative Commons Attribution-ShareAlike 4.0 International License. This license lets the audience to give appropriate credit, provide a link to the license, and indicate if changes were made and if they remix, transform, or build upon the material, they must distribute contributions under the same license as the original.


