Sunday, August 31, 2014

Mobile Payment Definitions

Mobile Device

Personal device with mobile communication capabilities such as a telecom network connection, Wi-Fi, Bluetooth … which offers connections to internet. Examples of mobile devices include mobile phones, smart phones, tablets ...

MNO(Mobile Network Operator)



A Mobile phone operator that provides a range of mobile services, potentially including facilitation of NFC services. The MNO ensures connectivity Over the Air (OTA) between the consumer and its PSP using its own or leased network (the latter are sometimes referenced as MVNOs - Mobile Virtual Network Operators).

Mobile Payment Service

Payment service made available by software/hardware through a mobile device.

Merchant:

The beneficiary within a mobile payment scheme for payment of goods or services purchased by the consumer/payer.
The merchant is a customer of its PSP.

Digital Wallet

A service accessed through a device (e.g., a PC) which allows the wallet holder to securely access, manage and use a variety of services/applications including payments, identification and non-payment applications. A digital wallet is sometimes also referred to as an e-wallet.

Merchant Wallet

A type of wallet where the payment gateway and the mobile wallet gateway are integrated services at the merchant’s website.


Mobile code

A user verification method used for mobile card payments. It is a code entered via the keyboard of the mobile device to verify the cardholder’s identity as a cardholder verification method.

Credentials

Payment/banking account related data that may include a passcode (mobile code, on-line passcode, etc.) provided by the PSP (issuer) to its customer which is provided via his/her mobile device for identification/authentication purposes in the context of mobile payments.

MCP - Mobile Contactless Payment



A mobile device initiated payment where the cardholder and the merchant (and/or his/her equipment) are in the same location and communicate directly with each other using contactless radio technologies, such as NFC, for data transfer (also known as contactless payments).

TSM - Trusted Service manager 



A trusted third party acting on behalf of the secure element issuers and/or the mobile payment/authentication application issuers in the case where a secure element is involved, or on behalf of the mobile wallet issuers.

MPP - Mobile Proximity Payment

A mobile payment where the communication between the mobile device and the Point of Interaction device takes place through a proximity technology (e.g., NFC, QR code, etc.).

MRP - Mobile Remote Payment

A payment initiated by a mobile device whereby the transaction is conducted over a mobile telecommunication network (e.g., GSM, mobile internet, etc.) and which can be made independently from the payer’s location (and/or his/her equipment).

NFC - Near Field Communication



A contactless protocol specified by ISO/IEC 18092.

Payment Gateway

A service operated by a beneficiary’s PSP or a trusted third party that manages the authorisation of payments for merchants.
It facilitates the transfer of information between the payment portal (such as a website or mobile device) and the beneficiary’s PSP.

Payment Scheme

A technical and commercial arrangement set up to serve one or more payment systems and which provides the organisational, legal and operational framework rules necessary for the payment services marketed (e.g. card scheme, e-payment scheme, …).

MPOS

The usage of a (consumer) mobile device to facilitate payments and enable acceptance of payment instruments.

Mobile Wallet Issuer

The service provider that issues mobile wallet functionalities to the customer (consumer or merchant).

Mobile Wallet Passcode

A code entered by the consumer/payer via his/her mobile device that may be required to activate a mobile wallet.

Payment Gateway

A service operated by a beneficiary’s PSP or a trusted third party that manages the authorisation of payments for merchants.
It facilitates the transfer of information between the payment portal (such as a website or mobile device) and the beneficiary’s PSP.

Mobile Wallet Gateway

A service operated by the mobile wallet issuer or a trusted third party acting on its behalf, which establishes for mobile transactions a link between the consumer/payer and its mobile wallet and between the mobile wallet and the payment gateways.
During the payment transaction, it allows the payment gateway to receive authentication data directly from the mobile wallet.
For life cycle management, it establishes a link between the mobile wallet and the mobile wallet issuer to download credentials, payment and/or authentication applications from the PSP.

Mobile Payments Will Make Credit and ATM Cards Almost Obsolete

This article is by Matthew Friend, managing director of Accenture Payment Services.

Eight-track tapes, rotary phones, videocassette recorders.
Think of outdated technologies and these probably spring to mind.

Will plastic cards eventually join the list? 



Certainly the demise of credit and debit cards isn’t imminent,
but they’re going to begin to lose their appeal in a world where transactions can increasingly be done by smartphone.

With payments more and more going mobile, retailers, banks, card companies, phone operators and just about everyone in between are scrambling for position.
Mobile payments will hit

- $720 billion a year by 2017,
- Up from $235 billion last year,

according to the research firm Gartner.

To be sure, many consumers still walk around today with a stack of plastic jammed into their wallets.
Nearly 550 million credit cards and roughly 590 million debit cards are in use in the U.S.

Plastic cards are used for 75 billion transactions a year, worth more than $4.7 trillion. 

That translated to $21.5 billion in collective profits for seven of the largest U.S credit card issuers last year.

But change is coming, and failure to adapt will carry great risk. For banks, the question boils down to whether they will lead the change or allow rivals to take the payments business away from them. With payments bringing in up to a quarter of banks’ revenues, this is not an idle question.

Payments are a highly contested arena. 
  • Google
  • PayPal 
  • Square 
  • American Express
  • MasterCard
  • Visa, among others, 

have all developed mobile payment platforms. 

Paypal is now the number one or two online payment method in a half dozen countries, including the U.S. Starbucks, whose mobile app is the most used digital payment app, gets more than 14% of its U.S. payments through its mobile app, up from 10% a year ago. 

And Starbucks captures a third of its revenues through its own loyalty card. 

Wendy’s has announced a new program that allows customers to pay using their smartphones at its 5,800 locations, following a similar announcement by Burger King.

Apple’s shadow also looms large. It is reportedly looking into jumping into mobile payments by deploying its devices and the credit card data of more than half a billion customers to handle how they pay for things online as well as at brick-and-mortar retail stores.

Of course, plastic cards will continue to have a presence in the coming years, that’s why card companies are spending big on digital wallets and social media propositions connected with their plastic. But they must reinvent themselves by developing ways of paying for goods and services that don’t rely on plastic or digital cards.

That’s because consumers expect their smartphones to improve and simplify their lives. They demand greater immediacy and convenience in their day-to-day activities. Increasingly, airline passengers can present electronic boarding passes displayed on their phones. New York and Washington are moving toward electronic fare payment systems for their buses and subways. Using plastic cards online, on the other hand, is arduous, requiring an awkward process of entering 16-digit numbers, addresses, start and end dates, and codes.

Smartphones increasingly act as a remote control for activities ranging from ordering taxis to programming central air conditioning

Controlling payments from your bank account is the next step. 

Danske Bank’s MobilePay app is an example. 

It allows the Danish bank’s customers to log in with a four-digit PIN, enter the amount and mobile number of the recipient, and send the money like a simple text message. The app can also be used at retailers that have registered. It has more than 1.2 million active users.

The U.S. isn’t as far along. JPMorgan Chase, Citigroup, Bank of America, Wells Fargo, Capitol One, and others are building their own mobile payments apps. The next step is to tie into proprietary networks such as clearXchange to enable widespread peer-to-peer payments and real-time business-to-consumer payments.

Banks have an inherent leg up on their new mobile payments competitors, because they own the accounts where customers keep or borrow their money. If they enable those accounts to make payments directly wherever a customer wants, they may be able to retain their dominant role in consumer payments. And despite the reputational damage they suffered from the financial crisis, consumers surveyed by Accenture trust them above any other providers when it comes to handling personal data. That’s another critical advantage.

How can smartphone-based payments be increased? 


More than half of the consumers we surveyed  said they were highly likely to pay by phone more often if they could in so doing track receipts, manage personal finances, and show identification or proof of insurance. 

They also said they would pay by phone more often if offered instant retailer coupons, reward points, and preferential treatment. 

Since the average U.S. household belongs to 21 loyalty programs, you can see the benefit of consolidating and managing these programs in a single place. Many mobile applications already available, such as CardStar and Key Ring, allow users to store all their loyalty card data on their mobile phones.

At the moment, U.S. payments players are focused on October 2015, when retailers and card issuers that haven’t adopted smart card technology—credit and debit cards embedded with microprocessor chips—will begin to be liable for fraudulent transactions. That technology has long been used in Europe and has helped increase security and reduce fraud there.

The transition to smart cards will be a milestone, but it is still just an interim step. Banks should not lose sight of the real revolution already underway, mobile payments.

For banks, it’s clear that digital payments will not generate the fees they currently derive from plastic card transactions. But they face a bigger threat, losing customers, if they get muscled to the sidelines in the payments business.

Tuesday, January 28, 2014

Next-generation credit cards aren't foolproof - From STAR Tribune


New payment technology will make cards harder for data thieves to hack, but the protection features have holes.

As the United States lumbers toward a new credit card technology to thwart data thieves like the ones who struck Target Corp., payment security experts say the new system is far from foolproof.
The chip-based smart cards, already in use in much of the world, make it much harder to produce counterfeit cards. But the cards are less effective against the widespread and growing threat of bogus online transactions that require only account information.
EMV, as the technology is known, changes the game but won’t prevent all fraud.
“It’s not a panacea,” said Paul Tomasofsky, an electronic payments expert who heads Two Sparrows Consulting in Montvale, N.J.
EMV, which stands for Europay/MasterCard/Visa, is a fairly old approach rooted in experiments to deter fraud with microprocessor chips embedded in payment cards in France in the 1980s. It spread throughout Europe and became a global standard.
But because of the sheer size of the fragmented U.S. payments system, and the huge cost to convert, the United States is one of the last countries in the world to make the change.
There’s general agreement that EMV alone would not have prevented the Target breach, in which thieves accessed data from as many as 110 million customer accounts. But EMV would have reduced the value of the information by making it almost impossible to clone the cards.
That’s EMV’s biggest boast, that it prevents counterfeit card fraud. “It does that spectacularly,” said Jeff Hall, a security consultant in the Twin Cities for Overland, Kan.-based FishNet Security.
However, that’s only part of the challenge. Online fraud that doesn’t require the presence of an actual card now accounts for nearly half of all credit card fraud in the United States, according to Fair Isaac Corp., and studies show that adopting EMV drives crooks to this card-not-present fraud.
EMV has a vulnerability
EMV has a weakness at the point of sale. While data in the card’s memory chip is encrypted when the card isn’t in use, the data is momentarily vulnerable when customers pay.
Proponents of EMV say this isn’t a big flaw because the chip spits out a unique, one-time-only security code to encrypt the data for transmission.
But critics say that if thieves compromise the card terminal or the register at just the right point, they can access the data before transmission, circumvent the one-time security code and get access to the information they want. The bulk of online merchants don’t ask for the 3- or 4-digit security code on a card, Hall said.
There are other security concerns. In the U.S. rollout, banks issuing EMV cards are not required to put a personal information number, or PIN, on either the debit or credit cards. A PIN, which only the cardholder knows, makes transactions more secure.
More important, magnetic stripes aren’t going away. In an effort to ease the conversion, the new EMV cards will still have magnetic stripes so they will work in stores that lack EMV equipment.
But magnetic stripes are easy to copy and clone. Avivah Litan, a financial services security analyst at Connecticut-based Gartner Research, called the existence of magnetic stripes on EMV cards “a very big security threat.”
U.S. companies are grappling with these issues as the country’s gargantuan payments system undergoes the seismic shift from magnetic stripes to chips. Retailers, banks and myriad other payments players face an October 2015 deadline to be ready.
At that point, Visa, MasterCard, American Express and Discover are shifting the liability for fraud that happens in stores from the card-issuing banks to the merchants, unless the merchant is equipped for EMV.
So problematic is the EMV migration that there are questions about crossing over at all.
“Is it the solution? Honestly, I don’t think it’s ever going to happen,” said J.D. Oder, chief technology officer at Shift4 Corp., a card processing gateway company he co-founded in Las Vegas.
Is EMV worth the bother?
Retailers are understandably concerned that they are spending huge sums to update their card processing equipment for an EMV implementation that has potential security potholes.
“As long as magstripe is around, there will be major breaches, I don’t care how much EMV is out there,” said Mark Horwedel, a former Wal-Mart executive who heads the Merchant Advisory Group, aMinneapolis group working on payments-industry issues. “Visa and MasterCard, in my view, are preoccupied with making the EMV migration in the U.S. as simple as possible for the banks.”
That’s what bothers Dean Sheaffer, chief compliance officer at Boscov’s Inc. in Reading, Pa. His company is spending “hundreds of thousands of dollars,” he said, to install EMV terminals at its department stores when he’s not convinced that EMV will offer enough fraud protection.
“We don’t feel good about it at all,” Sheaffer said. “I see a number of clear issues that I think have to be vetted and resolved.”
At the top of Sheaffer’s list: PINs and magnetic stripes.
Target, a big proponent of EMV, has been rolling out EMV-enabled point-of-sale terminals at its stores since 2012. It declined to discuss EMV security concerns.
“While the new hardware has the capability to process EMV, the software is still in development,” said Target spokeswoman Molly Snyder.
A multitude of technologies are being promoted to make EMV cards more secure, although they aren’t part of this country’s official EMV rollout. One is to encrypt all card data from the instant it’s read in the store until it’s processed by the bank. Another is tokenization, in which card data in the payment processing network is replaced with a meaningless value the minute the card is authenticated.
Add the end-to-end encryption and tokens to EMV cards and you have a “pretty airtight solution,” said Oder at Shift4 Corp.
Other approaches also are circulating.
Hall, at FishNet Security, advocates a single transaction code. It’s a one-time 15- or 16-character transaction code generated by a smartphone or other smart device at the start of a purchase that replaces the card account number. The code could be displayed as a bar code on the phone that could easily be scanned by bar code equipment that retailers already have at the checkout.
“Once it’s used, it’s done,” Hall said.
Time to do away with plastic?
The cards themselves are the root of the problem, Hall and others say, and it’s time for a paradigm shift.
Richard Crone, head of Crone Consulting in suburban San Francisco, calls for ditching the country’s existing card infrastructure altogether and moving to cloud-based mobile payments, in which everything is stored more securely through the Internet in a server farm somewhere.
All payment credentials would be stored behind an encrypted firewall accessible only through strong authentication with only indecipherable tokens provided to the merchant for transaction authorization, Crone said.
“EMV as a fraud deterrent is a complete joke,” Crone said.
Still, proponents say it’s a vast improvement over the magnetic stripe system. Regardless of whatever percentage of fraud EMV doesn’t prevent, it’s better than where we are now, said Madeline Aufseeser, a payments analyst at Boston-based Aite Group.
Litan, at Gartner, agrees. Ultimately, the security arguments over EMV are “a red herring,” she said. It’s not perfect, Litan said, but EMV will significantly improve security compared to magnetic stripes and is the most realistic approach given its widespread adoption everywhere else. Companies will have to layer on other protections to thwart card-not-present fraud.
“It’s crazy to say don’t lock your front door because someone will get in your back door,” she said. “You’ve got to lock both.”

“There really isn’t any better proposal out there.”

Is the EMV going to eliminate the Fraud?

EMV is definitely not the game-changer to stopping fraud.

EMV simply shifts fraud liability from the Issuers to the merchants, as fraud WILL migrate to the online channels.

Eliminating fraud in the Card-Present (CP) space is going to be a challenge as long as the magstripe coexists on the plastic with the chip; and unfortunately magstripes will coexist, 

as merchants will slowly and reluctantly incur further costs to update their terminals. 

This will be a slow and costly process. 

Also, let's not overlook other international markets that have yet to convert over to EMV. 

With the US being a highly desirable location for international tourists, merchants will not want to refuse a sale on non-Chip cards. 

Even after 10 years, UK is still accepting magstripe payments. So the battle will continue, especially as the art of card skimming becomes even more sophisticated and possibly later on chip!! 

For now, EMV "could" become a very effective deterrent to copying card data at the POS, along with shrinking CP Fraud, 

but there are cases in EMV markets where the both card data and PIN have been breached, 
along with consumer negligence over securely looking after their PIN and card(s). 

The bigger question is what will EMV do to fraud? It's highly debatable... 

As seen in the Canadian and UK markets, EMV will certainly shrink CP fraud, but it will also force fraudster to migrate to other easily exploitable channels - namely the online shopping channel, where fraud is rampantly growing!!!

Six Things to Know About Chip Cards (EMV)

I posted the article on  "when EMV will hit the US" on 2006.  Now the time has come.

Six things to know about EMV...


Q.  The Basics – What are Chip Cards?
EMV chip cards have computer chips embedded in them. They are widely used in Europe and Asia and are beginning to be adopted in the U.S.
People who frequently travel abroad may already have chip cards or may have seen them used in London, Toronto and Istanbul. The rest of us are likely to have chip cards in our hands by 2015.
Q.  Why Chip Cards?
Chip cards better protect your account information from fraud. And every electronic payment – credit cards, debit cards, digital wallets – is almost always more secure than cash.EMV credit card
The magnetic-striped credit and debit cards you are accustomed to contain “static” data, or payment data that does not change. The data stored in the magnetic stripes includes your 16-digit card account number, expiration date and 3-digit security code (CVC) like the one found on the back of your card.
Chip cards contain the same data and more. Each purchase or transaction that you make generates “dynamic” or unique data that is encoded in a safe mode.
EMV helps protect you even if your card or your card data is lost or stolen, the technology:
  • Makes it difficult for anyone but the rightful owner to use the card
  • Protects against the creation of counterfeit cards because dynamic data is only good for a single purchase or use
Q. What is MasterCard Doing?
MasterCard is one of the original founders of the chip card standard known as EMV, short for EuroPay (now part of MasterCard), MasterCard and Visa.
We continue to advance the technology and introduce it to every country around the world . . . allowing you to safely use your MasterCard no matter where you are.
Q.  Will this Change The Way I Pay for Things?
A little bit. Rather than swiping your card, you may soon insert it into or tap it against a card reader so the chip on your card and the reader can “talk” and establish a secure connection.
Q.  Why Isn’t the U.S. Currently Using Chip Card Technology?
Historically, countries with higher fraud rates switched to chip cards earlier than countries with lower fraud rates.
Q. What will I see as a Cardholder?
First, you will see new card readers or payment terminals in your favorite stores and restaurants. Many of the new readers are already in place, especially if the business caters to travelers from outside the U.S.
Next your bank or credit union will send you a new chip card. Some EMV cards are already available in the U.S. However, the chip cards are provided predominantly on an “at request” basis and, as mentioned, most often to international travelers.

Monday, October 01, 2012

Building future-proof operating models in wholesale transaction banking

By James O'Callaghan, KPMG China

Given the recent transformation of China's markets and the payments market in particular, many banks and payments processors are now seeking to build a level of 'future-proofing' into their transaction banking operating models. This is a welcome trend.

The timing of this is very appropriate given that many Western banks are also looking at their strategy to decide what to do with their legacy core banking platforms, many of which were implemented during the 1980's or inherited through acquisitions. These systems are now struggling to support organisations as they transition through the evolution of mobile payments and technology and respond to the demands and volumes of clients and transactions.


Advantage China China has a clear opportunity to harness its considerable advantages (such as the evolution of mobile technology, increased transaction volumes, rapidly developing Cloud infrastructure and a comparatively stable economy) to develop flexible, scalable and adaptable operating models capable of lasting a generation or more.

However, building future-proof operating models requires China's banks to have a high level of awareness, both of their own structural advantages and limitations, as well as the direction of the changes going on around them. China can also learn from lessons learnt by Western organisations regarding the challenges faced when undertaking such large transformational initiatives.

Look inside and out To start, banks will need to gain a clear understanding of their long-term strategies and objectives. Is the over-riding goal of the organisation to increase transaction volumes or expand into new markets? Is international expansion on the horizon or are all eyes focused on domestic growth? Does the bank have a clear vision of what their clients need now and in the future and how they want to be serviced?

This will allow banks to start to envision their future operating model and develop a framework against which they can properly align their decision making process and design principles. In turn, this will lead to the creation of a target operating model that will act as a roadmap for all future decisions and investments.

Taking a holistic view

Banks will, however, need to be aware of the impact these changes will have on the broader organisation. Indeed, given the interconnectedness of today's banks, true future-proofing cannot successfully occur in individual silos; it requires banks to take a holistic view of the organisation to understand the dependencies of the change and its impact on suppliers, customers, stakeholders and employees.

Of course, a range of other considerations must also be overlaid. For example, take regulation: banks that either have, or plan to have overseas operations, will need to carefully consider how regulation in foreign jurisdictions may influence their operating models. Many markets now require sensitive payment systems and processes to be conducted within the jurisdiction itself, which will impact the ability to centralise operations. In much the same vein, data and security are also key concerns for regulators, possibly requiring the establishment of local data warehouses and new controls and governance systems.

Assessing the dependencies

All of this will naturally impact the sourcing decisions that must be made. Some systems and processes will need to be maintained on-shore, while others may be centralised and put into a shared service model that serves as a regional – or even global – hub.

The introduction of Cloud computing into the payments ecosystem will also add a new dimension to the sourcing decision process.

Key to developing a successful future-proof operating model will be securing the buy-in of senior leadership and the various lines of business. As with any transformation project, the direction and strategy will need to be led and communicated by the business itself, and so tight collaboration between the functions will be critical, especially with the technology partners. Architects of future-proof operating models will also need to dedicate resources towards helping the business to understand the implications of the change, developing future-proof processes and communicating the change throughout the organisation.

Regardless of the shape of the operating model, the bottom line is that – to last into the future – operating models will need to be flexible and agile to ensure that any environmental changes can quickly be absorbed into the daily operations. Ultimately, the ability to adapt will be the only true test of how 'future-proof' the eventual operating model will be.

What to expect at Sibos
China's banks and payments processors will be looking to gain insight and lessons from the successes and failures of operating models in other markets. At Sibos, attendees should anticipate a significant amount of discussion about future-proofing and may want to come to the event with their minds open to creating mutually-beneficial relationships with China's domestic players.

Saturday, September 08, 2012

Market Capitalization

Let's say in a room there are 100 boxes, each priced at Rs 100.

What would be the value of all the boxes? It would amount to Rs100 x 100 boxes = Rs 10,000

If we replace the “boxes” with “shares of a company”, then according to the above working, the cost of all the shares of the company would be Rs 10,000, which is nothing but the total value of outstanding shares or market capitalization of the company.

However, this brings us to another term, “OUTSTANDING SHARES”. OUTSTANDING SHARES are shares currently held by investors, including restricted shares owned by the company's officers and insiders, as well as those held by the public.

However, one should note that shares that have been repurchased by the company are not considered as a part of outstanding shares.

  Now, if the price of the boxes were to go up due an increase in demand, the total prices of the entire set of boxes would go up. Similarly, when the value of the shares goes up, so does the market capitalization.

Now the question is why would the price of the share go up or come down? The price of a share would go up, if the demand for the goods of the company rises.

It would also go up if people's expectation from the company goes up on the back of a new management, innovation, expected demand or some recognition won by the company.

Companies whose total value of Market Capitalization is above x cr. are called “Large Cap” companies.

Companies whose Market Capitalization is between y cr. and z cr are called “Mid-Cap” companies and companies whose market capitalization is below w cr. are called “Small Cap” companies.

Large Cap companies are thus large and stable companies in relation to Mid Cap companies, which again are seen as more stable in comparison to Small Cap companies.

So in terms of risk, the Large Cap companies are the least risky while the “Small Cap” companies are most risky. However, the probability of growth is more in the “Small Cap” companies followed by the Mid Cap companies and then by the Large Cap companies.

Hence investors have to decide the balance between risk and return when making an educated and informed decision.

The reason why Small Cap companies have a higher probability is because not only are they small but perhaps early into a business with larger growth opportunities into the future.

As the companies grow (issue fresh capital and/or increase in share price) they become mid cap companies at some point in time and eventually large cap companies.

  The reason why Large Cap companies are less risky is because of their size, better brand value, better credit worthiness and better grip over the industry due to their experience. Hope this lesson has helped you in understanding the term Market Capitalization.

Tuesday, April 17, 2007

Migration from Magnetic Stripe to Smart Cards - Part 2

The Existing Magnetic Stripe Process

Cards are produced in batches and it is the responsibility of the host system to assemble all data for a given batch of cards. A batch might be generated as a result of the normal replacement cycle (two or three years) or possibly to replace those cards that have been reported lost or stolen during the day. The host system produces the data in a series of records, one record per cardholder. The data is known as a Personalization Data File.

Each record of the Personalization Data File comprises a number of modules. These normally include:
  • Data to be embossed onto the card.
  • Data to be encoded onto the magnetic stripe of the card.
  • Data to be printed on a “paper carrier.” This carrier is used to hold the card, while in its delivery envelope, and is printed, for example, with the cardholder’s name and address.
  • Data for an ID photograph
Most of the information for these modules are held in the cardholder database.
Some items in the magnetic stripe module need to be generated using a security module.

These include a PIN Verification Value (PVV), or equivalent,
and a Card Verification Value (CVV).

Both these items are derived using a cryptographic process that involves the use of secret keys.

The data is the file is not normally encrypted.

The PIN mailer for a card is normally produced in a separate establishment from the cards themselves, often as a separate output from the issuer host system. This separation of PIN mailer and finished card is normally an essential part of the card issuance process. Often, PIN mailers are not posted until the cardholder acknowledges receipt of the card.

With the arrival of the smart card, the issuer needs to produce an extra “module” of data, which is intended to be programmed into the chip itself. Of course, there will be many items of information in this chip data, which are common to the magnetic stripe and the embossing data. Examples of this are a Primary Account Number (PAN) and the cardholder name. However, there are some new items that are specific to smart cards.

Some examples are:-

Upper consecutive offline limit:

This is a value held by the card that determines its spending limit. After this limit has been exceeded, the card forces the transaction to be completed online. This is part of the inherent risk management features of a chip card.

Signature of static card data:

This is a value calculated using a public key cryptographic algorithm at the time the card data is generated. It can be validated by each terminal accepting the card and is used to give some confidence that the card is genuine.

Issuer certificate:

This data is set up by the issuer in conjunction with the card association to which the issuer belongs (Visa or MasterCard). It is placed onto every card issued and contains the public key of the issuer. It is used by the terminal as part of the process to validate the signature in the second item in this list.

Unique Derived Keys (UDKs):

These are DES keys, unique to each card, which are placed on the chip and used as part of the transaction validation process. Basically, the transaction details are passed to the card, which uses the UDK to generate a cryptogram (similar to a MAC) that is passed back to the issuer for validation. Using this technique, the issuer can be sure that the transaction was handled by a valid card.

The various credit and debit specifications define in excess of 40 such data items, which need to be generated and placed on smart cards. It is the issuer’s responsibility to generate these items, something that existing card systems were never designed to handle.

INFO:
The advent of chip cards has meant that for the first time, some of the data passing from issuer to personalizer is now secret and must only be sent in encrypted form. The UDKs previously described are an example of such secret data.

Monday, April 16, 2007

Migration from Magnetic Stripe to Smart Cards - Part 1

We need to follow the following steps for migration to Smart Cards

1.Enhancements to the card issuing process
2. Enhancements to the card personalization process
3. Enhancements to the systems that handle card transactions


Enhancements to the Card Issuing Process

Existing systems were developed, often many years ago,
to handle the types of data needed for magnetic stripe cards.

Smart cards require considerably more data to be generated,
including cryptographic keys for the cards themselves.

In most instances, changing existing systems represents a major investment of resources.

Enhancements to the Card Personalization Process

Banks generally personalize their cards in one of two ways:
either using an in-house facility or using an external personalization bureau.

The choice is usually based on the size of the cardholder base,
because setting up an in-house facility is an expensive exercise


Enhancements to the Systems that Handle Card Transactions

Systems are in place today for handling a number of magnetic-stripe-based transactions,
such as ATM cash dispensing,
Online card and PIN verification, and
Offline bulk transaction processing.

By using smart cards, there is a need to extend these systems
to handle the transaction verification mechanism used in smart debit and credit cards,
or in the case of electronic purse schemes, like Visa Cash,
to handle the secure loading of e-cash onto the card.

Sunday, April 15, 2007

Payment Processing Network

The Payment Processing Network

Here’s a breakdown of the participants and elements involved in processing payments:

Acquiring bank: In the online payment processing world, an acquiring bank provides Internet merchant accounts. A merchant must open an Internet merchant account with an acquiring bank to enable online credit card authorization and payment processing. Examples of acquiring banks include Merchant eSolutions and most major banks.

Authorization: The process by which a customer’s credit card is verified as active and that they have the credit available to make a transaction. In the online payment processing world, an authorization also verifies that the billing information the customer has provided matches up with the information on record with their credit card company.

Credit card association: A financial institution that provides credit card services that are branded and distributed by customer issuing banks. Examples include Visa® and MasterCard®

Customer: The holder of the payment instrument—such as a credit card, debit card, or electronic check.

Customer issuing bank: A financial institution that provides a customer with a credit card or other payment instrument. Examples include Citibank and Suntrust. During a purchase, the customer issuing bank verifies that the payment information submitted to the merchant is valid and that the customer has the funds or credit limit to make the proposed purchase.

Internet merchant account: A special account with an acquiring bank that allows the merchant to accept credit cards over the Internet. The merchant typically pays a processing fee for each transaction processed, also known as the discount rate. A merchant applies for an Internet merchant account in a process similar to applying for a commercial loan. The fees charged by the acquiring bank will vary.

Merchant: Someone who owns a company that sells products or services.

Payment gateway: A service that provides connectivity among merchants, customers, and financial networks to process authorizations and payments. The service is usually operated by a third-party provider such as VeriSign.

Processor: A large data center that processes credit card transactions and settles funds to merchants. The processor is connected to a merchant’s site on behalf of an acquiring bank via a payment gateway.

Settlement: The process by which transactions with authorization codes are sent to the processor for payment to the merchant. Settlement is a sort of electronic bookkeeping procedure that causes all funds from captured transactions to be routed to the merchant’s acquiring bank for deposit

Monday, January 09, 2006

EMV: When will it hit the U.S.?

Once the world moves to EMV, the card companies have said they will get rid of the mag-stripe," said Caroline Walpole, a smart card expert in the United Kingdom and senior business consultant for Omaha, Neb.-based ACI Worldwide. "But until everybody in the world is ready, we can’t lose the mag-stripe."

Fortunately, almost "everybody" in the world is ready — everybody but the United States. But experts like Walpole say the United States’ migration isn’t far behind Canada, where the EMV shift is expected to wrap by 2007.

The problem is that until the United States jumps aboard, the rest of the world will have to continue offering both magnetic-stripe and chip-card options at the POS and ATM. Although the mag-stripe will primarily serve as a back-up, as the rest of the world becomes more accustom to chip-cards, the States’ old-fashioned mag-stripe technology is expected to get the boot.


"Many countries are saying that the only reason they have fraud is because of the mag-stripe," Walpole said. "So you could say that within your own country you would use EMV transactions, and for international transactions you would use the mag-stripe. … But that gets confusing," and it ultimately doesn’t eliminate the higher risk of fraud that using a mag-stripe card poses.

Francois Lasnier is North American vice president for Axalto Holding N.V., a France-based provider of smart cards and POS terminals. Lasnier said that he expects MasterCard and Visa to mandate the technology in the United States within the next five years, after the rest of the world is ready to roll.

"That’s the last link is the smart card infrastructure," Lasnier said. "The systems and the payment technology are ready. The acquirers are ready ... and because they are ready for the Canadian market, it will set up well for deployment in the U.S."
"In next two or three years, there won’t be anything to hold it up," he added. "The U.S. will have to catch up."

EMV: A refresher

If you’re at all involved with debit/ATM or credit cards, you’ve heard of EMV — the Europay/MasterCard/Visa standard initiated in 1996 by the three card associations for which the standard is named.

EMV is a standard for chip-embedded cards, often referred to as smart cards. Instead of using a mag-stripe to store account information, the cards use chips. At the moment, however, the cards are equipped with both chips and stripes. And MasterCard and Visa have not said when the stripes will permanently fall from the cards.
In 1999, Europay, MasterCard and Visa founded EMVCo, an independent organization, to manage and enhance EMV specifications. EMVCo updates standards as technology improves. EMVCo’s purpose: to reduce incidents of fraud resulting from compromised cards at the ATM and POS.

Smart cards were an obvious choice for EMV: They’re more secure and can hold more information than mag-stripes.

According to one EMV report, Visa estimates that counterfeiting can be decreased by at least 70 percent with smart cards. And a standard 64 KB smart-card chip can hold about 13 times more information than a standard mag-stripe.
But the idea of using smart cards at the ATM and POS in the United States hasn’t received a warm reception.

"EMV in the U.S. has not gotten out of the starting box," said Martin Macmillan, London-based Level Four Software’s chief executive. "But we noticed fraudsters getting wise in the U.K., and we’re seeing some of this moving into the U.S."

U.K. led the way

The financial industry in the United Kingdom was the first to endorse EMV specifications when card fraud soared in the mid-'90s. In 1999, the U.K. began converting its 80 million mag-stripe debit and credit cards to smart cards. It also required that ATMs and POS terminals be equipped with EMV-compliant card readers.


Today, 80 percent of the U.K.’s cards are EMV compliant, Walpole said. That’s larger because the EMV compliance deadline for the European Union was January 2005. Any fraud at the ATM or POS that could have been prevented with EMV compliance will be the responsibility of ATM deployer or retailer.

"So you could have a customer with an EMV card, but because you did not have an EMV terminal, you had fraud. In that case, you are liable," Walpole said.

The same liability will hit Central and Eastern Europe, the Middle East, Africa and Asia/Pacific in January 2006, the compliance deadline for those regions.

"That would make me, as a U.S. banker, start to think, ‘You know what?’ I’m going to have to start looking at this,’" Walpole said. "Some U.S. banks are global banks, and they’re already rolling this out in the rest of the world — like Citibank. So it’s not like these U.S. banks aren’t getting experience."

The other push: the expected influx of fraud.

"The fraudsters now have difficulty with the cards in the U.K. and France," Walpole said. "So they’ll just take those cards across the border where there is no EMV. The U.S. has said publicly that they aren’t moving to EMV, so fraudsters know to go there."

But making the conversion to EMV is expensive, and the United States has not experienced enough fraud to justify the switch, said Randy Vanderhoof, executive director of the Princeton Junction, N.J.-based Smart Card Alliance.

Also, as Macmillan points out, "POS fraud has not been an issue in the U.S. (as it was in the U.K.)." And there are a few reasons for that, including the United States’ use of PIN-based debit transactions. In the U.K., PIN-based transactions were not the norm before EMV.

However, there already are signs of change. Lasnier said approximately 35 percent of POS systems in the United States are ready for EMV. And he estimates that 50 percent of the POS devices being sold in the United States include smart-card readers.

Robin Gustin, president of Capital Security Systems, a Hicksville, N.Y. ATM systems technology company, also believes EMV is on the way. Her company is marketing its Super ATM platform, which includes an EMV-compliant smart-card reader, in the United States.
"What we developed was a series of process patents," Gustin said. "It’s a process of using the ATMs for actions." Basically, companies buy the patent to use the platform."
But Gustin said it could require a mandate before the United States as a whole is motivated to shift. "The EMV platform, the technology and the legislation all have come together, and the banks have to make the business decision. After that, it will be here like is everywhere else in the world.

Tuesday, February 22, 2005

WMS and RFID

WMS and RFID

Although Radio Frequency Identification (RFID) has been around for almost 15 years, it is only recently that the world has woken up to its immense potential. One of the obvious applications of this technology lies in tracking inventory with RFID-enabled tags. (Wal-Mart has already directed its suppliers to gear up and supply goods with RFID tags.) The US retail supply chain, which is today spending around $200 million on RFID, is expected to spend around $1,300 million by 2008.

RFID can be used to turn a WMS into a real-time system. This new possibility has invigorated the WMS market. RFID-enabled WMS will not only reduce operational costs but will also increase warehouse productivity by optimising storage and resource utilisation. RFID-enabled WMS can help implement collaborative sourcing strategies through the real-time flow of information to and from suppliers.

The challenges of incorporating RFID

Of course, RFID technology can create new challenges, and there are a number of technical difficulties that need to be tackled before the dream becomes reality. WMS has to be integrated into RFID readers; for greater efficiency, they will have to read RFID tags in bursts rather than sequentially. Also, the volume of data is going to be enormous, which is going to stretch the limits of a WMS. Making business sense out of the enormous volume of data is also a big challenge which has to be overcome. Error Proofing is another technical hurdle that needs to be surmounted. Accidental and inadvertent reading of adjacent RFID tags can result in incorrect data. Different materials like metals and liquids interfere with reads. It is believed that excessive exposure to radio frequency (RF) can lead to certain ailments. Even though this has not been proved scientifically, there have been cases where workers have resisted RFID implementations. The effect of RF on food and drugs still needs to be explored.

Standardisation has to be brought to the RFID reader and printer market. Without this, making a WMS capable enough of interfacing with all possible readers and printers is going to be a near-impossible task. Unless such standardisation is brought in quickly, it may even kill this promising market.

Monday, February 07, 2005

Better Evolution for Legacy Mainframes

HP strengths


Strategic and versatile partnerships with leading Independent Software Vendors and Systems integrators provide best-in-class solutions

World’s broadest server portfolio delivers unmatched performance, scalability, high availability and security


HP StorageWorks solutions, which attach to both mainframe and HP platforms, provide much higher value and lower TCO than mainframe storage alone


Complete business, migration, IT services, and education offerings help design, build, manage, and evolve your new environment


Flexible, world-class financial services make your move from mainframes to HP both affordable and cost effective


Misson-critical solutions: Did you know that HP -


Handles two-thirds of all credit card transations worldwide -- providing 24X7 service in key financial markets

Powers 14 of the world's largest stock exchanges

Supports 95% of the world's securities transactions

Handles 80% of all telecom billing and customer-care traffic in Europe and Asia

Is the hardware platform for half of all SAP deployments

Manages more than 50,000 heterogenous systems worldwide

Is an $80 billion company which runs entirely without mainframes


Friday, February 04, 2005

Credit Union and FSCC - An Information


What Is A Credit Union?


A credit union is a cooperative financial institution, owned and controlled by the people who use its services. These people are members. Credit unions serve groups that share something in common, such as where they work, live, or go to church. Credit unions are not-for-profit, and exist to provide a safe, convenient place for members to save money and to get loans at reasonable rates. Did you know there are at least seven ways you can find a credit union that you are eligible to join?
Credit unions, like other financial institutions, are closely regulated. And they operate in a very prudent manner. The National Credit Union Share Insurance Fund, administered by the National Credit Union Administration, an agency of the federal government, insures deposits of credit union members at more than 11,000 federal and state-chartered credit unions nationwide. Deposits are insured up to $100,000.
What makes a credit union different from a bank or savings & loan? Like credit unions, these financial institutions accept deposits and make loans--but unlike credit unions, they are in business to make a profit. Banks and savings & loans are owned by groups of stockholders whose interests include earning a healthy return on their investments.


What is FSCC?


Financial Service Centers Cooperative, Inc., (FSCC) is a cooperative credit union service organization, incorporated under the Cooperative laws of the State of California. FSCC is owned and governed by credit unions that are stockholders in the company. FSCC is the only international shared branching network. A company that prides itself on its technology, products and services to its owner and participating credit unions. FSCC is a founding and operating member of the CU Service Centers® Network, a cooperative National shared branching network of over 900 credit unions with over 1,000 locations in thirty-seven states and Puerto Rico. Locations are available on U.S. military bases in five countries. Linked by technology, the Network provides financial services to the credit union public where they live, work, and travel. An appropriate analogy is that of ATM networks, where technology and cooperative relationships between institutions enable the convenient delivery of financial services to consumers.


HP NONSTOP

Operating "Nonstop"

HP Using New OS For Robust, Fault-Tolerant Servers
Reliability is a true measure of any enterprise network. Corporate resources must often be up and available in the face of constant threats from users, bugs, and attacks. Network admins must implement and support fault tolerant systems, which is sometimes a challenge given today’s OSes and applications. Bill Buer, HP product manager, offered some information about HP’s NonStop OS and its recent support for 64-bit Intel servers.

A Long Road

The NonStop OS is certainly not a new platform. The kernel has been around for over 20 years, the result of a push to provide a complete fault-tolerant environment including a combination of hardware, software, and middleware that provides a 100% application uptime. Buer says, "Most systems strive to keep the [hardware] running, but the HP NonStop system addresses every level of the application stack to provide the most robust environment in the industry. Obviously one of the most key elements of the stack is the OS itself."

The improvements for NonStop have been many. "Over the years there have been new releases of the OS that were able to take advantage of new chip architectures, such as the MIPS RISC architecture. What is new here is that HP has announced that the platform that runs the NonStop OS is moving to a standard chip environment, which is the Intel Itanium Processor family. This means our customers will be able to take advantage of the 64-bit capability of Itanium, initially in the memory address space but longer term in having a full 64-bit operating environment," says Buer. Today, the NonStop OS runs on any MIPS-based HP NonStop server. In the future, this will also be any Itanium-based HP NonStop server. Of course, users may need to recompile their applications’ source codes to take best advantage of the Itanium.
NonStop is intended for multiprocessor servers but strives to overcome the loss of performance seen when SMP (symmetric multiprocessing) systems share memory resources. Buer says, "Each additional processor provides a sharply reduced benefit compared to the previous processor. Indeed, SMP systems become impractical with as few as eight processors. The NonStop server’s loosely coupled, shared nothing parallelism provides cost-effective, liner scalability, and, as a result, predictable response times in the face of swelling data volumes, expanding user populations, and a growing number of concurrent queries. Each processor has its own dedicated resources, so an added processor provides a full processor’s worth of performance." Results from large transaction processing and database benchmark tests using the NonStop Kernel OS show that even with more than 112 processors, each additional processor can execute at least 98.2% of the throughput of the first processor.

Performance Features & Management

HP NonStop servers already serve in many mission-critical applications, including the majority of the world’s securities, credit card, point-of-sale, and ATM transactions, as well as emerging zero latency enterprise systems. The NonStop OS is a versatile platform for parallel processing and application throughput. Buer says, "The NonStop Kernel OS enables critical business application processing to be transparently distributed across multiple processors and even multiple systems, either centralized locally or geographically distributed anywhere in the world. This is accomplished without application code changes or relocation of I/O devices because the NonStop Kernel message-based architecture efficiently connects all local and remote devices and processes between as few as two through as many as 4,080 loosely coupled processors working in parallel. Growth within a single server, an HP NonStop ServerNet Cluster, or the entire network can occur without disrupting application and database processing."

The combination of ServerNet technology and the NonStop Kernel OS enable both the data bandwidth and the number of processors to increase as needed to accommodate demanding and data-intensive applications. "Regardless of how large the system grows, the NonStop Kernel OS distributes the workload among the available processors, making efficient use of system resources and achieving exceptionally high aggregate throughput from parallel processing. The NonStop Kernel OS and its compilers automatically create a fully re-entrant code execution environment that makes replication and parallel processing highly efficient," explains Buer.

NonStop-based systems are also fully compliant with many existing system management applications, such as HP OpenView, IBM Tivoli, and CA Unicenter. Buer says, "System management products from HP’s NonStop Enterprise Division and its partners give flexibility and choice to tailor specific system and network management environments to specific business needs. All management solutions for HP NonStop servers automatically inherit the platform advantages of availability, scalability, and manageability."

The Security Question

Given the long line of security vulnerabilities appearing for such OSes as Windows, the security and integrity of a NonStop OS should be a real concern for any admin considering a platform shift. NonStop is certainly not invulnerable to attack, and identifying vulnerabilities and releasing fixes/patches are a high priority for HP. "Security related patches will be communicated to our customer base with appropriate dispatch, with full disclosure of the risks involved with not applying the patch. HP has a team of people that helps identify vulnerabilities on all HP platforms, and HP has policies for identifying and responding to potential vulnerabilities as quickly as possible." Still, he emphasizes that NonStop’s modularity and process separation help to make the OS more secure than other platforms. Pricing for NonStop should be established later in 2004, with general availability in 2005.