Table of Contents

1.0 Problem Statement

Return to User Scenario: Identity

1.1 Background

Return to Top

Nancy is a USA citizen and plans a month-long European vacation with 4 major legs all within the Schengen Agreement Zone1).

Many companies have adopted Multifactor Authentication (MFA) to help avoid fraudulent activities. MFA relies on three main factors in determining the authenticity of a user2):

MFA can use other attributes in combination with the other authentication factors about any transaction:

While Nancy is at home, in the USA using her own network and computer (i.e., Possession Factors and Location Factors), the likelihood of any issues is small. However, as Nancy travels MFA can prohibit her from being able to access or update her information because of Locations Factors and Time Factors. This is why it is essential for Nancy to notify her Credit Card companies and banking institutions about her proposed itinerary.

Nancy needs to identify herself while planning for the trip and during the trip, potentially exposing a lot of Personal Identifiable Information (PII), Digital Signature as well as financial information (i.e., Credit Cards, Debit Cards, etc.) to numerous people in numerous countries from the beginning to the end. In addition to the exposure of her PII to the corporations, businesses, and individuals that she has direct business with, she also has to worry about her PII being processed by partner organizations working with businesses she is working with. As a result of poor Data Residency requirements, her PII might be processed and stored across the world thus limiting her ability for recourse if there are compromises. See 4.3.4.1 Confidentiality.

1.2 Overview of Scenario

Return to Top

An overview of the trip is:

  1. A river cruise along the Rhine River visiting some major cities, villages, and historic sites
  2. A Paris getaway with cultural, shopping, eating, and clubbing activities
  3. A mountain resort adventure with hiking, skydiving, paddleboarding, water skiing, and kayaking
  4. A casino experience with shows, clubbing, and gambling
  5. Nancy does all the bookings in advance for:
    1. Airplane
    2. Cruise ships
    3. Trains
    4. Hotel In Paris
      1. Museum visits
      2. Historical Sights
      3. Restaurants
      4. Discotheque
    5. Resort with some activities such as a
      1. Hiking
      2. Sky Diving
      3. Paddle Boarding
      4. Water Skiing
      5. Kayaking
    6. Casino
      1. Discotheque
      2. Cabaret shows
    7. Long Term Parking
1)
Schengen Agreement, allows passport-free travel between these 26 countries: Austria, Belgium, Czech Republic, Denmark, Estonia, Finland, France, Germany, Greece, Hungary, Iceland, Italy, Latvia, Liechtenstein, Lithuania, Luxembourg, Malta, Netherlands, Norway, Poland, Portugal, Slovak Republic, Slovenia, Spain, Sweden, and Switzerland. There are three islands that are also part of the Schengen Zone, even though their borders are outside of the continent: The Azores, Madeira, and the Canary Islands.
2)
Mary E. Shacklett, TechTarget, Multifaactor Authrtication, Accessed: 24 June 2021, https://searchsecurity.techtarget.com/definition/multifactor-authentication-MFA