跳到主要內容

簡易檢索 / 詳目顯示

研究生: 黃振育
Huang, Chen-Yu
論文名稱: 行動身分識別 (Mobile ID)取代簡訊一次性密碼(OTP)於銀行業之成功案例研究 - 以行動銀行裝置綁定防詐應用為例
A Case Study on the Adoption of Mobile ID to Replace SMS One-Time Password (OTP) in the Banking Industry — A Fraud Prevention Application in Mobile Banking Device Binding
指導教授: 彭金隆
Peng, Jin-Lung
口試委員: 王儷玲
詹芳書
學位類別: 碩士
Master
系所名稱: 商學院 - 經營管理碩士學程(EMBA)
Executive Master of Business Administration(EMBA)
論文出版年: 2026
畢業學年度: 115
語文別: 中文
論文頁數: 53
中文關鍵詞: 行動銀行金融詐騙一次性密碼(OTP)行動身分識別(Mobile ID)裝置綁定
外文關鍵詞: Mobile Banking, Financial Fraud, One-Time Password(OTP), Mobile ID, Device Binding
相關次數: 點閱:7下載:0
分享至:
查詢本校圖書館目錄 查詢臺灣博碩士論文知識加值系統 勘誤回報
  • 隨著數位金融的普及,行動銀行已成為金融服務之核心服務通路或主要互動平台,但釣魚簡訊詐騙(Smishing)發生頻率顯著上升。傳統的簡訊一次性密碼(OTP)雖具備普及與低成本優勢,卻存在「認碼不認人」且無法驗證操作裝置的顯著之安全性漏洞,易受社交工程與中間人攻擊(MITM)破解,導致客戶蒙受巨大財產損失。
    為解決此資安痛點,本研究以個案銀行為個案,深入探討其導入臺灣網路認證公司(TWCA)之 Mobile ID(行動身分識別)技術,取代傳統簡訊 OTP 於行動銀行「裝置綁定」與「交易驗證」的防詐成效。本研究採個案研究法,剖析 Mobile ID 的底層技術架構(如 SIM 卡 AKA 協定)及其在 PAIN 信賴框架下的應用價值。
    研究結果顯示,Mobile ID 透過電信網路直接驗證行動裝置中的 SIM 卡與留存門號的一致性,將身分核驗升級為綁定硬體載具的強認證機制。個案銀行自導入該技術後,成功克服了傳統 OTP 無法驗證裝置合法性的漏洞,使得帳戶劫持相關詐騙案件量大幅下降 90%,並精準攔阻逾 1,000 件身分冒用與異常綁定請求,大幅減少約 20% 的潛在詐騙損失。此外,該機制採用靜默認證(Silent Auth),在防禦偽造網頁騙取驗證碼的同時,亦優化了無密碼化的使用者體驗。
    本研究結論指出,數位金融防詐的關鍵在於消除人為介入的漏洞,身分識別正經歷從「記憶性信物」轉向「硬體信任根」的典範轉移。建議未來銀行業應建立「以風險為中心」的動態驗證架構,並加速 Mobile ID 與 FIDO 生物辨識技術的深度整合,進一步擴展至數位開戶與跨業生態圈應用,建構兼具安全與便利的數位金融信任防線。


    With the rapid popularization of digital finance, mobile banking has become the primary battlefield for financial services. However, this shift has been accompanied by increasingly rampant SMS phishing(smishing) scams. While traditional SMS One-Time Passwords (OTP) offer high penetration and low implementation costs, they possess critical vulnerabilities: they authenticate the code rather than the user and fail to verify the operating device. Consequently, they are highly vulnerable to social engineering and Man-in-the-Middle (MITM) attacks, leading to substantial financial losses for customers.
    To address this critical cybersecurity pain point, this study utilizes Cathay United Bank as a case study to explore the fraud prevention effectiveness of adopting Mobile ID technology, provided by Taiwan CA (TWCA). This technology replaces traditional SMS OTP for "device binding" and "transaction verification" in mobile banking. Adopting a case study approach, this research analyzes the underlying technical architecture of Mobile ID (e.g., the SIM card AKA protocol) and evaluates its application value through the PAIN trust framework.
    The findings reveal that Mobile ID directly verifies the consistency between the SIM card inserted in the mobile device and the registered mobile number via telecommunication networks. This upgrades identity verification to a strong authentication mechanism bound to a hardware carrier. Since the implementation of this technology, Cathay United Bank has successfully mitigated the vulnerability of traditional OTPs regarding device legitimacy verification. As a result, fraud cases related to account hijacking have decreased significantly by 90%. Furthermore, the system successfully intercepted over 1,000 abnormal binding requests and identity spoofing attempts, reducing potential fraud losses by approximately 20%. Notably, the mechanism employs "Silent Auth," which not only thwarts fake web pages designed to steal verification codes but also optimizes a seamless, passwordless user experience.
    This study concludes that the core of digital financial fraud prevention lies in eliminating vulnerabilities associated with human intervention. Digital identity verification is currently undergoing a paradigm shift from "memory-based tokens" to a "hardware root of trust." The study recommends that the banking industry establish a "risk-centric" dynamic verification architecture. Furthermore, accelerating the deep integration of Mobile ID with FIDO biometric technology and expanding its application to digital account opening and cross-industry ecosystems will be essential to constructing a secure and convenient digital financial trust perimeter.

    第一章 緒論 1
    第一節 研究背景 1
    第二節 研究動機 2
    第三節 研究目的 3
    第四節 研究架構 3
    第二章 文獻回顧 5
    第一節 數位身分識別之學術理論與PAIN框架 5
    第二節 傳統簡訊一次性密碼 (SMS OTP ) 的架構脆弱性與學術實證 7
    第三節 GSMA OPEN GATEWAY API 與金融行動身分識別之應用趨勢 8
    第四節 金融詐騙的演化趨勢與經濟損失 9
    第五節 釣魚簡訊詐騙的發展趨勢與影響 11
    第六節 OTP 驗證機制之效益與侷限分析 13
    第七節 MOBILE ID 技術的發展歷程與應用場景 15
    第八節 跨國推動實證研究與全球監理趨勢 18
    第三章 個案公司分析 21
    第一節 個案公司介紹與特色 21
    第二節 個案公司面臨詐騙問題 22
    第三節 個案公司因應作為 24
    第四節 MOBILE ID技術於個案公司之應用 25
    第五節 MOBILE ID對於個案公司防詐成效 29
    第六節 MOBILE ID在個案公司其他應用場景(如數位開戶、交易驗證)與發展潛力 30
    第四章 個案研究結果與討論 34
    第一節 個案銀行導入 MOBILE ID 的策略定位與實務經驗 34
    第二節 身分驗證機制之比較分析:MOBILE ID 與傳統簡訊 OTP 35
    第三節 MOBILE ID 提升行動銀行安全性之底層機制探討 37
    第四節 防詐成效與業務效益量化評估 38
    第五節 企業導入MOBILE ID的挑戰與應對策略 41
    第五章 結論與建議 43
    第一節 研究問題之核心發現 43
    第二節 對銀行業未來發展之策略管理建議 47
    參考文獻 50

    一、 中文文獻
    •內政部警政署(2025)。165 打詐儀錶板年度統計報告:2025 年詐騙趨勢與財損分析。內政部警政署。
    •內政部警政署刑事警察局(2021)。2021 年簡訊釣魚詐騙專案查緝與被害統計分析。內政部警政署刑事警察局。
    •卡巴斯基(2024)。什麼是簡訊釣魚以及如何防禦。卡巴斯基資源中心。
    •台灣金融研訓院(2023)。這種騙人不好笑-金融詐騙防騙招式大公開。台灣金融研訓院。
    •全球防詐騙聯盟與 Gogolook(2025)。2025 亞洲詐騙調查報告。Gogolook。
    •蔡典翰(2024)。應用 FIDO 於支付服務商間交易的嚴格顧客驗證 [碩士論文,國立政治大學]。臺灣博碩士論文知識加值系統。
    •林永福(2023)。我國金融業數位身分管理之探討 [碩士論文,國立臺灣科技大學]。臺灣博碩士論文知識加值系統。
    •林暐翰(2023)。一套適用於數位身分證應用的 FIDO 隱私防護框架 [碩士論文,國立東華大學]。臺灣博碩士論文知識加值系統。
    •紀彥興(2024)。基於 Java Card 的 FIDO2 隱私保護身分鑑別機制之設計與實作 [碩士論文,國立臺灣科技大學]。臺灣博碩士論文知識加值系統。
    •張立仁(2025)。基於 FIDO 與 Kerberos 的元宇宙身分驗證設計研究 [碩士論文,國立政治大學]。臺灣博碩士論文知識加值系統。
    •連子清、杜宏毅(2022)。身分識別之書:身分識別機制運作之原理原則。臺灣網路認證公司。
    •曾繼興(2007)。植基於一次性密碼機制探討網站身分認證及祕密通訊 [碩士論文,大同大學]。臺灣博碩士論文知識加值系統。
    •黃偉恩(2023)。應用零信任與 FIDO 技術於內網安全之身份驗證機制 [碩士論文,國立雲林科技大學]。臺灣博碩士論文知識加值系統。
    •楊秉叡(2016)。基於一次性密碼的身分認證之研究 [碩士論文,朝陽科技大學]。臺灣博碩士論文知識加值系統。
    •滙豐(台灣)商業銀行(2024)。簡訊和電話詐騙。HSBC Business。
    •蕭國振(2025)。透過 CAMARA Open Gateway API 實現零信任架構之多因子安全驗證機制 [碩士論文,國立陽明交通大學]。臺灣博碩士論文知識加值系統。
    •陳俐伶(2020)。論數位身分制度於銀行業之應用與管理法制 [碩士論文,國立政治大學]。臺灣博碩士論文知識加值系統。
    •陳盈蓉(2015)。一次密碼架構之 OpenID 認證 [碩士論文,國立中正大學]。臺灣博碩士論文知識加值系統。
    •陳裕泉(2014)。主動式一次性密碼(AOTP)服務於金融支付創新之研究 [碩士論文,國立高雄第一科技大學]。臺灣博碩士論文知識加值系統。
    二、 英文文獻:
    •Bartłomiejczyk, M., El Fray, I., & Kamoun, F. (2025). Enhancing two-factor authentication security by analyzing and detecting SMS OTP-interception techniques in Android malware. IEEE Access, 13, 185926-185942. https://doi.org/10.1109/ACCESS.2025.3626270 ``
    •ISO/IEC 29115:2013. Information technology — Security techniques — Entity authentication assurance framework. https://online.standard.no/en/isoiec-29115-2013-2
    •Global System for Mobile Communications Association. (2014). Mobile Identity - Unlocking the Potential of the Digital Economy. https://www.gsma.com/solutions-and-impact/technologies/mobile-identity//wp-content/uploads/2014/10/GSMA-SIA-paper_FINALNov-2014.pdf
    •Global System for Mobile Communications Association. (2017). SK Telecom: Integrating existing identity solutions into Mobile Connect. https://www.gsma.com/solutions-and-impact/technologies/mobile-identity/gsma_resources/sk-telecom-integrating-existing-identity-solutions-mobile-connect/
    •National Institute of Standards and Technology. (2025). Digital identity guidelines (NIST Special Publication 800-63-4). U.S. Department of Commerce. https://doi.org/10.6028/NIST.SP.800-63-4
    •An, S., & Wu, Y. (2021). Fine with 1234: An Analysis of SMS One-Time Password Randomness in Android Apps. https://doi.org/10.48550/arXiv.2103.05758
    •Global System for Mobile Communications Association. (2017). Operator cooperation in South Korea has created a successful identity solution. https://www.gsma.com/solutions-and-impact/technologies/mobile-identity/gsma_resources/operator-cooperation-south-korea-created-successful-identity-solution/
    •Monetary Authority of Singapore. (2024). MAS and banks to phase out SMS OTPs for bank account login. https://www.mas.gov.sg/news/media-releases/2024/banks-in-singapore-to-strengthen-resilience-against-phishing-scams
    •Bangko Sentral ng Pilipinas. (2024). Anti-Financial Account Scamming Act (AFASA). https://www.bsp.gov.ph/Regulations/Banking%20Laws/AFASA-Booklet-with-IRRs.pdf
    •Bank Negara Malaysia. (2022). Additional measures to further strengthen fraud safeguards. https://www.bnm.gov.my/-/financial-crime-exhibition-speech-en
    •Reserve Bank of India. (n.d.). Authentication mechanisms for digital payment transactions. https://www.rbi.org.in/Scripts/NotificationUser.aspx?Id=12898&Mode=0
    •Visa. (2024). SMS One-Time Passwords no longer enough to fight Australia’s AI-driven fraud, says Visa. https://www.visa.com.au/about-visa/newsroom/press-releases/sms-one-time-passwords-no-longer-enough-to-fight-australias-ai-driven-fraud-says-visa.html?utm_source=chatgpt.com

    無法下載圖示 全文公開日期 2031/08/05
    QR CODE
    :::