cloud based payments: the future of mobile payments?

11
www.thales-esecurity.com OPEN Cloud Based Payments: the future of Mobile Payments? SIMON KEATES, THALES E-SECURITY ROB MACMILLAN, PROXAMA

Upload: thales-e-security

Post on 16-Apr-2017

238 views

Category:

Technology


1 download

TRANSCRIPT

Page 1: Cloud based payments: the future of mobile payments?

www.thales-esecurity.com OPEN

Cloud Based Payments: the future of Mobile Payments?SIMON KEATES, THALES E-SECURITYROB MACMILLAN, PROXAMA

Page 2: Cloud based payments: the future of mobile payments?

2 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

NFC Mobile Payments Evolution

▌Why are NFC payments growing?Global Smartphone adoption + consumers use for a range of purposesMandated contactless POS rollout worldwide – convenience and speedFinancial Institutions and Merchants driving mobile engagement

▌Mobile Payments Evolution

▌Where does this leave the issuer?With a potentially confusing and rapidly changing environmentOpportunities and strategic choices

Page 3: Cloud based payments: the future of mobile payments?

3 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

▌Apple Pay, a Game Changer?Oct 2014 launch brought NFC payments to iPhonesSimple consumer enrolmentNew commercial model (15 bps to Apple)Big marketing campaign and rolloutApple in control – even had logo on POS

▌Collaborating rather than disrupting

Uses existing payment card railsUses established technology – EMV, NFCDrove card schemes to launch tokenisation services

▌X-Pays are followingSamsung Pay, Android Pay, etc.But it’s still early days

Apple Pay

Page 4: Cloud based payments: the future of mobile payments?

4 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

▌What is Tokenisation?Protects cardholder by replacing the PAN with a ‘surrogate’ account number, a Token PANTransactions still pass through terminals, acquirers and networksToken PAN domain controls restrict useEMV Co published global framework in Mar 2014

▌Tokenisation scopeToken generationToken provisioning (with payment data) to phoneStoring Token/PAN mapDe-tokenisation for authorisations and clearing

▌Wider use of TokenisationMobile, Card on File, in-App purchasesProtecting other forms of data, e.g. healthcare

Tokenisation

Page 5: Cloud based payments: the future of mobile payments?

5 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

HCE and Cloud Based Payments (CBP)

▌Host Card Emulation (HCE)Technology added in Android 4.4 in 2013Provides choice SE/TSM or HCEEnables an app to use NFC for paymentBut data and processing now in software

▌Cloud Based Payment (CBP)Initial deployments proprietarySchemes introduced standards for operation and security in 2014Transactions are EMV contactless, no changes to POS or networks

▌Consumer ExperienceIssuers can add payment to existing mobile banking appsConsumer uses something that is familiarProvisioning through simple option to add an existing card to the banking app

Page 6: Cloud based payments: the future of mobile payments?

6 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

CBP layered security

▌Dynamic keysNew keys dedicated to CBP transactionsSingle or limited use keys, issuer controls key replenishmentAll transactions online

▌TokenisationToken PAN used instead of Card PAN to protect cardholder dataToken PANs only useable within ‘Domains’

▌Secure communications with mobile phoneKey exchange with mobile phoneAll critical keys and data supplied to phone in encrypted format

▌Application securityTools for tamper resistance and whitebox cryptographyCertification and penetration testing of apps

Page 7: Cloud based payments: the future of mobile payments?

7 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

CBP deployments are spreading

Selected examplesRBC, CanadaBBVA, SpainCapital One, USAQIWI, RussiaTinkoff, RussiaBarclays, UK

Page 8: Cloud based payments: the future of mobile payments?

8 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

Cloud Based Payment future

▌Value Added ServicesPayment on its own won’t drive adoption – consumers need incentivesIssuers can add mobile banking services, loyalty and marketing programmes

▌New types of issuersOther issuers can adopt CBP solutions, e.g. merchant closed loop cards, transit, loyaltyPayment capability could be added to existing apps, especially where issuer has control of the infrastructure

▌Convergence between in-store, on-line and in-app payment

Payment credentials on the phone can be used for more than in-storeCBP credentials can support payments from other apps on the mobile, e.g. enabling merchants to ‘payment enable’ their appsCBP credentials can be used for online ecommerce transactions simplifying and adding extra security

Page 9: Cloud based payments: the future of mobile payments?

9 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

Issuer Choice: CBP and X-Pays

▌X-Pays

▌ ProsSupports a range of handsets (where service is available)Could provide value added services in futureCould leverage scheme tokenisation for multiple X-Pays

▌ ConsConsumer experience controlled by X-PayFuture development controlled by X-PayTokenisation service controlled by scheme, no ‘on-us’ transactions and possible future charges

▌Cloud Based Payments

▌ ProsIssuer retains branding and control of consumer relationshipIssuer can add services and customise consumer experienceIssuer can implement in-house solution and continue on-us processing

▌ ConsCBP not available on Apple devicesMay require more up front investment depending on solution

Page 10: Cloud based payments: the future of mobile payments?

10 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

Conclusion

▌Mobile payments market is growingDriven by consumer demand, NFC smartphones and acceptance infrastructureX-Pays and schemes recognise this and are competing for control

▌Issuers have choiceAdopt X-Pays and/or CBPSelect scheme tokenisation and/or implement in-house

▌CBP puts issuers in controlBranding and customising consumer experienceProvision of in-house solutions

▌CBP is the futureAn increasing number of issuers are deploying solutionsCBP supports value added services and payment convergence

Page 11: Cloud based payments: the future of mobile payments?

11 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales  -  © Thales  2014 All rights reserved.

Contacts

▌Contact us via the websitehttps://www.thales-esecurity.com

▌Or contact me:[email protected]

▌Contact us via the websitehttp://www.proxama.com

▌Or contact me:[email protected]