logo

Banking Security

The NoWires Research Group has analyzed the security in Norwegian banking systems in five papers. The first paper studies the previous generation of Norwegian Internet banks.


The second paper discusses the ATM system during the '90s.

  • K. J. Hole, V. Moen, A. N. Klingsheim, and K. M. Tande, “Lessons from the Norwegian ATM System,” IEEE Security & Privacy, November/December 2007. (Copyright notice at bottom of page.)

The third paper evaluates BankID, a new national public-key infrastructure owned by the Norwegian banks.


The fourth paper describes a practical attack exploiting vulnerabilities in BankID. Countermeasures were introduced in November 2007 according to the Norwegian BankID community.


The fifth paper analyzes the proof of concept attack in more detail. It also gives a brief description of a modified proof of concept attack. Countermeasures to the second attack were introduced in January 2008.


© 2006, 2007, 2009 IEEE. Personal use of this material is permitted. Permission from IEEE must be obtained for all other uses, including reprinting/republishing this material for advertising or promotional purposes, creating new collective works for resale or redistribution to servers or lists, or reuse of any copyrighted component of this work in other works.

Last updated 28.05.10. Webmaster KJH

© Kjell J. Hole. All rights reserved. Terms of Use