Monday, October 01, 2012

Building future-proof operating models in wholesale transaction banking

By James O'Callaghan, KPMG China

Given the recent transformation of China's markets and the payments market in particular, many banks and payments processors are now seeking to build a level of 'future-proofing' into their transaction banking operating models. This is a welcome trend.

The timing of this is very appropriate given that many Western banks are also looking at their strategy to decide what to do with their legacy core banking platforms, many of which were implemented during the 1980's or inherited through acquisitions. These systems are now struggling to support organisations as they transition through the evolution of mobile payments and technology and respond to the demands and volumes of clients and transactions.


Advantage China China has a clear opportunity to harness its considerable advantages (such as the evolution of mobile technology, increased transaction volumes, rapidly developing Cloud infrastructure and a comparatively stable economy) to develop flexible, scalable and adaptable operating models capable of lasting a generation or more.

However, building future-proof operating models requires China's banks to have a high level of awareness, both of their own structural advantages and limitations, as well as the direction of the changes going on around them. China can also learn from lessons learnt by Western organisations regarding the challenges faced when undertaking such large transformational initiatives.

Look inside and out To start, banks will need to gain a clear understanding of their long-term strategies and objectives. Is the over-riding goal of the organisation to increase transaction volumes or expand into new markets? Is international expansion on the horizon or are all eyes focused on domestic growth? Does the bank have a clear vision of what their clients need now and in the future and how they want to be serviced?

This will allow banks to start to envision their future operating model and develop a framework against which they can properly align their decision making process and design principles. In turn, this will lead to the creation of a target operating model that will act as a roadmap for all future decisions and investments.

Taking a holistic view

Banks will, however, need to be aware of the impact these changes will have on the broader organisation. Indeed, given the interconnectedness of today's banks, true future-proofing cannot successfully occur in individual silos; it requires banks to take a holistic view of the organisation to understand the dependencies of the change and its impact on suppliers, customers, stakeholders and employees.

Of course, a range of other considerations must also be overlaid. For example, take regulation: banks that either have, or plan to have overseas operations, will need to carefully consider how regulation in foreign jurisdictions may influence their operating models. Many markets now require sensitive payment systems and processes to be conducted within the jurisdiction itself, which will impact the ability to centralise operations. In much the same vein, data and security are also key concerns for regulators, possibly requiring the establishment of local data warehouses and new controls and governance systems.

Assessing the dependencies

All of this will naturally impact the sourcing decisions that must be made. Some systems and processes will need to be maintained on-shore, while others may be centralised and put into a shared service model that serves as a regional – or even global – hub.

The introduction of Cloud computing into the payments ecosystem will also add a new dimension to the sourcing decision process.

Key to developing a successful future-proof operating model will be securing the buy-in of senior leadership and the various lines of business. As with any transformation project, the direction and strategy will need to be led and communicated by the business itself, and so tight collaboration between the functions will be critical, especially with the technology partners. Architects of future-proof operating models will also need to dedicate resources towards helping the business to understand the implications of the change, developing future-proof processes and communicating the change throughout the organisation.

Regardless of the shape of the operating model, the bottom line is that – to last into the future – operating models will need to be flexible and agile to ensure that any environmental changes can quickly be absorbed into the daily operations. Ultimately, the ability to adapt will be the only true test of how 'future-proof' the eventual operating model will be.

What to expect at Sibos
China's banks and payments processors will be looking to gain insight and lessons from the successes and failures of operating models in other markets. At Sibos, attendees should anticipate a significant amount of discussion about future-proofing and may want to come to the event with their minds open to creating mutually-beneficial relationships with China's domestic players.

Saturday, September 08, 2012

Market Capitalization

Let's say in a room there are 100 boxes, each priced at Rs 100.

What would be the value of all the boxes? It would amount to Rs100 x 100 boxes = Rs 10,000

If we replace the “boxes” with “shares of a company”, then according to the above working, the cost of all the shares of the company would be Rs 10,000, which is nothing but the total value of outstanding shares or market capitalization of the company.

However, this brings us to another term, “OUTSTANDING SHARES”. OUTSTANDING SHARES are shares currently held by investors, including restricted shares owned by the company's officers and insiders, as well as those held by the public.

However, one should note that shares that have been repurchased by the company are not considered as a part of outstanding shares.

  Now, if the price of the boxes were to go up due an increase in demand, the total prices of the entire set of boxes would go up. Similarly, when the value of the shares goes up, so does the market capitalization.

Now the question is why would the price of the share go up or come down? The price of a share would go up, if the demand for the goods of the company rises.

It would also go up if people's expectation from the company goes up on the back of a new management, innovation, expected demand or some recognition won by the company.

Companies whose total value of Market Capitalization is above x cr. are called “Large Cap” companies.

Companies whose Market Capitalization is between y cr. and z cr are called “Mid-Cap” companies and companies whose market capitalization is below w cr. are called “Small Cap” companies.

Large Cap companies are thus large and stable companies in relation to Mid Cap companies, which again are seen as more stable in comparison to Small Cap companies.

So in terms of risk, the Large Cap companies are the least risky while the “Small Cap” companies are most risky. However, the probability of growth is more in the “Small Cap” companies followed by the Mid Cap companies and then by the Large Cap companies.

Hence investors have to decide the balance between risk and return when making an educated and informed decision.

The reason why Small Cap companies have a higher probability is because not only are they small but perhaps early into a business with larger growth opportunities into the future.

As the companies grow (issue fresh capital and/or increase in share price) they become mid cap companies at some point in time and eventually large cap companies.

  The reason why Large Cap companies are less risky is because of their size, better brand value, better credit worthiness and better grip over the industry due to their experience. Hope this lesson has helped you in understanding the term Market Capitalization.

Tuesday, April 17, 2007

Migration from Magnetic Stripe to Smart Cards - Part 2

The Existing Magnetic Stripe Process

Cards are produced in batches and it is the responsibility of the host system to assemble all data for a given batch of cards. A batch might be generated as a result of the normal replacement cycle (two or three years) or possibly to replace those cards that have been reported lost or stolen during the day. The host system produces the data in a series of records, one record per cardholder. The data is known as a Personalization Data File.

Each record of the Personalization Data File comprises a number of modules. These normally include:
  • Data to be embossed onto the card.
  • Data to be encoded onto the magnetic stripe of the card.
  • Data to be printed on a “paper carrier.” This carrier is used to hold the card, while in its delivery envelope, and is printed, for example, with the cardholder’s name and address.
  • Data for an ID photograph
Most of the information for these modules are held in the cardholder database.
Some items in the magnetic stripe module need to be generated using a security module.

These include a PIN Verification Value (PVV), or equivalent,
and a Card Verification Value (CVV).

Both these items are derived using a cryptographic process that involves the use of secret keys.

The data is the file is not normally encrypted.

The PIN mailer for a card is normally produced in a separate establishment from the cards themselves, often as a separate output from the issuer host system. This separation of PIN mailer and finished card is normally an essential part of the card issuance process. Often, PIN mailers are not posted until the cardholder acknowledges receipt of the card.

With the arrival of the smart card, the issuer needs to produce an extra “module” of data, which is intended to be programmed into the chip itself. Of course, there will be many items of information in this chip data, which are common to the magnetic stripe and the embossing data. Examples of this are a Primary Account Number (PAN) and the cardholder name. However, there are some new items that are specific to smart cards.

Some examples are:-

Upper consecutive offline limit:

This is a value held by the card that determines its spending limit. After this limit has been exceeded, the card forces the transaction to be completed online. This is part of the inherent risk management features of a chip card.

Signature of static card data:

This is a value calculated using a public key cryptographic algorithm at the time the card data is generated. It can be validated by each terminal accepting the card and is used to give some confidence that the card is genuine.

Issuer certificate:

This data is set up by the issuer in conjunction with the card association to which the issuer belongs (Visa or MasterCard). It is placed onto every card issued and contains the public key of the issuer. It is used by the terminal as part of the process to validate the signature in the second item in this list.

Unique Derived Keys (UDKs):

These are DES keys, unique to each card, which are placed on the chip and used as part of the transaction validation process. Basically, the transaction details are passed to the card, which uses the UDK to generate a cryptogram (similar to a MAC) that is passed back to the issuer for validation. Using this technique, the issuer can be sure that the transaction was handled by a valid card.

The various credit and debit specifications define in excess of 40 such data items, which need to be generated and placed on smart cards. It is the issuer’s responsibility to generate these items, something that existing card systems were never designed to handle.

INFO:
The advent of chip cards has meant that for the first time, some of the data passing from issuer to personalizer is now secret and must only be sent in encrypted form. The UDKs previously described are an example of such secret data.

Monday, April 16, 2007

Migration from Magnetic Stripe to Smart Cards - Part 1

We need to follow the following steps for migration to Smart Cards

1.Enhancements to the card issuing process
2. Enhancements to the card personalization process
3. Enhancements to the systems that handle card transactions


Enhancements to the Card Issuing Process

Existing systems were developed, often many years ago,
to handle the types of data needed for magnetic stripe cards.

Smart cards require considerably more data to be generated,
including cryptographic keys for the cards themselves.

In most instances, changing existing systems represents a major investment of resources.

Enhancements to the Card Personalization Process

Banks generally personalize their cards in one of two ways:
either using an in-house facility or using an external personalization bureau.

The choice is usually based on the size of the cardholder base,
because setting up an in-house facility is an expensive exercise


Enhancements to the Systems that Handle Card Transactions

Systems are in place today for handling a number of magnetic-stripe-based transactions,
such as ATM cash dispensing,
Online card and PIN verification, and
Offline bulk transaction processing.

By using smart cards, there is a need to extend these systems
to handle the transaction verification mechanism used in smart debit and credit cards,
or in the case of electronic purse schemes, like Visa Cash,
to handle the secure loading of e-cash onto the card.

Sunday, April 15, 2007

Payment Processing Network

The Payment Processing Network

Here’s a breakdown of the participants and elements involved in processing payments:

Acquiring bank: In the online payment processing world, an acquiring bank provides Internet merchant accounts. A merchant must open an Internet merchant account with an acquiring bank to enable online credit card authorization and payment processing. Examples of acquiring banks include Merchant eSolutions and most major banks.

Authorization: The process by which a customer’s credit card is verified as active and that they have the credit available to make a transaction. In the online payment processing world, an authorization also verifies that the billing information the customer has provided matches up with the information on record with their credit card company.

Credit card association: A financial institution that provides credit card services that are branded and distributed by customer issuing banks. Examples include Visa® and MasterCard®

Customer: The holder of the payment instrument—such as a credit card, debit card, or electronic check.

Customer issuing bank: A financial institution that provides a customer with a credit card or other payment instrument. Examples include Citibank and Suntrust. During a purchase, the customer issuing bank verifies that the payment information submitted to the merchant is valid and that the customer has the funds or credit limit to make the proposed purchase.

Internet merchant account: A special account with an acquiring bank that allows the merchant to accept credit cards over the Internet. The merchant typically pays a processing fee for each transaction processed, also known as the discount rate. A merchant applies for an Internet merchant account in a process similar to applying for a commercial loan. The fees charged by the acquiring bank will vary.

Merchant: Someone who owns a company that sells products or services.

Payment gateway: A service that provides connectivity among merchants, customers, and financial networks to process authorizations and payments. The service is usually operated by a third-party provider such as VeriSign.

Processor: A large data center that processes credit card transactions and settles funds to merchants. The processor is connected to a merchant’s site on behalf of an acquiring bank via a payment gateway.

Settlement: The process by which transactions with authorization codes are sent to the processor for payment to the merchant. Settlement is a sort of electronic bookkeeping procedure that causes all funds from captured transactions to be routed to the merchant’s acquiring bank for deposit

Monday, January 09, 2006

EMV: When will it hit the U.S.?

Once the world moves to EMV, the card companies have said they will get rid of the mag-stripe," said Caroline Walpole, a smart card expert in the United Kingdom and senior business consultant for Omaha, Neb.-based ACI Worldwide. "But until everybody in the world is ready, we can’t lose the mag-stripe."

Fortunately, almost "everybody" in the world is ready — everybody but the United States. But experts like Walpole say the United States’ migration isn’t far behind Canada, where the EMV shift is expected to wrap by 2007.

The problem is that until the United States jumps aboard, the rest of the world will have to continue offering both magnetic-stripe and chip-card options at the POS and ATM. Although the mag-stripe will primarily serve as a back-up, as the rest of the world becomes more accustom to chip-cards, the States’ old-fashioned mag-stripe technology is expected to get the boot.


"Many countries are saying that the only reason they have fraud is because of the mag-stripe," Walpole said. "So you could say that within your own country you would use EMV transactions, and for international transactions you would use the mag-stripe. … But that gets confusing," and it ultimately doesn’t eliminate the higher risk of fraud that using a mag-stripe card poses.

Francois Lasnier is North American vice president for Axalto Holding N.V., a France-based provider of smart cards and POS terminals. Lasnier said that he expects MasterCard and Visa to mandate the technology in the United States within the next five years, after the rest of the world is ready to roll.

"That’s the last link is the smart card infrastructure," Lasnier said. "The systems and the payment technology are ready. The acquirers are ready ... and because they are ready for the Canadian market, it will set up well for deployment in the U.S."
"In next two or three years, there won’t be anything to hold it up," he added. "The U.S. will have to catch up."

EMV: A refresher

If you’re at all involved with debit/ATM or credit cards, you’ve heard of EMV — the Europay/MasterCard/Visa standard initiated in 1996 by the three card associations for which the standard is named.

EMV is a standard for chip-embedded cards, often referred to as smart cards. Instead of using a mag-stripe to store account information, the cards use chips. At the moment, however, the cards are equipped with both chips and stripes. And MasterCard and Visa have not said when the stripes will permanently fall from the cards.
In 1999, Europay, MasterCard and Visa founded EMVCo, an independent organization, to manage and enhance EMV specifications. EMVCo updates standards as technology improves. EMVCo’s purpose: to reduce incidents of fraud resulting from compromised cards at the ATM and POS.

Smart cards were an obvious choice for EMV: They’re more secure and can hold more information than mag-stripes.

According to one EMV report, Visa estimates that counterfeiting can be decreased by at least 70 percent with smart cards. And a standard 64 KB smart-card chip can hold about 13 times more information than a standard mag-stripe.
But the idea of using smart cards at the ATM and POS in the United States hasn’t received a warm reception.

"EMV in the U.S. has not gotten out of the starting box," said Martin Macmillan, London-based Level Four Software’s chief executive. "But we noticed fraudsters getting wise in the U.K., and we’re seeing some of this moving into the U.S."

U.K. led the way

The financial industry in the United Kingdom was the first to endorse EMV specifications when card fraud soared in the mid-'90s. In 1999, the U.K. began converting its 80 million mag-stripe debit and credit cards to smart cards. It also required that ATMs and POS terminals be equipped with EMV-compliant card readers.


Today, 80 percent of the U.K.’s cards are EMV compliant, Walpole said. That’s larger because the EMV compliance deadline for the European Union was January 2005. Any fraud at the ATM or POS that could have been prevented with EMV compliance will be the responsibility of ATM deployer or retailer.

"So you could have a customer with an EMV card, but because you did not have an EMV terminal, you had fraud. In that case, you are liable," Walpole said.

The same liability will hit Central and Eastern Europe, the Middle East, Africa and Asia/Pacific in January 2006, the compliance deadline for those regions.

"That would make me, as a U.S. banker, start to think, ‘You know what?’ I’m going to have to start looking at this,’" Walpole said. "Some U.S. banks are global banks, and they’re already rolling this out in the rest of the world — like Citibank. So it’s not like these U.S. banks aren’t getting experience."

The other push: the expected influx of fraud.

"The fraudsters now have difficulty with the cards in the U.K. and France," Walpole said. "So they’ll just take those cards across the border where there is no EMV. The U.S. has said publicly that they aren’t moving to EMV, so fraudsters know to go there."

But making the conversion to EMV is expensive, and the United States has not experienced enough fraud to justify the switch, said Randy Vanderhoof, executive director of the Princeton Junction, N.J.-based Smart Card Alliance.

Also, as Macmillan points out, "POS fraud has not been an issue in the U.S. (as it was in the U.K.)." And there are a few reasons for that, including the United States’ use of PIN-based debit transactions. In the U.K., PIN-based transactions were not the norm before EMV.

However, there already are signs of change. Lasnier said approximately 35 percent of POS systems in the United States are ready for EMV. And he estimates that 50 percent of the POS devices being sold in the United States include smart-card readers.

Robin Gustin, president of Capital Security Systems, a Hicksville, N.Y. ATM systems technology company, also believes EMV is on the way. Her company is marketing its Super ATM platform, which includes an EMV-compliant smart-card reader, in the United States.
"What we developed was a series of process patents," Gustin said. "It’s a process of using the ATMs for actions." Basically, companies buy the patent to use the platform."
But Gustin said it could require a mandate before the United States as a whole is motivated to shift. "The EMV platform, the technology and the legislation all have come together, and the banks have to make the business decision. After that, it will be here like is everywhere else in the world.

Tuesday, February 22, 2005

WMS and RFID

WMS and RFID

Although Radio Frequency Identification (RFID) has been around for almost 15 years, it is only recently that the world has woken up to its immense potential. One of the obvious applications of this technology lies in tracking inventory with RFID-enabled tags. (Wal-Mart has already directed its suppliers to gear up and supply goods with RFID tags.) The US retail supply chain, which is today spending around $200 million on RFID, is expected to spend around $1,300 million by 2008.

RFID can be used to turn a WMS into a real-time system. This new possibility has invigorated the WMS market. RFID-enabled WMS will not only reduce operational costs but will also increase warehouse productivity by optimising storage and resource utilisation. RFID-enabled WMS can help implement collaborative sourcing strategies through the real-time flow of information to and from suppliers.

The challenges of incorporating RFID

Of course, RFID technology can create new challenges, and there are a number of technical difficulties that need to be tackled before the dream becomes reality. WMS has to be integrated into RFID readers; for greater efficiency, they will have to read RFID tags in bursts rather than sequentially. Also, the volume of data is going to be enormous, which is going to stretch the limits of a WMS. Making business sense out of the enormous volume of data is also a big challenge which has to be overcome. Error Proofing is another technical hurdle that needs to be surmounted. Accidental and inadvertent reading of adjacent RFID tags can result in incorrect data. Different materials like metals and liquids interfere with reads. It is believed that excessive exposure to radio frequency (RF) can lead to certain ailments. Even though this has not been proved scientifically, there have been cases where workers have resisted RFID implementations. The effect of RF on food and drugs still needs to be explored.

Standardisation has to be brought to the RFID reader and printer market. Without this, making a WMS capable enough of interfacing with all possible readers and printers is going to be a near-impossible task. Unless such standardisation is brought in quickly, it may even kill this promising market.

Monday, February 07, 2005

Better Evolution for Legacy Mainframes

HP strengths


Strategic and versatile partnerships with leading Independent Software Vendors and Systems integrators provide best-in-class solutions

World’s broadest server portfolio delivers unmatched performance, scalability, high availability and security


HP StorageWorks solutions, which attach to both mainframe and HP platforms, provide much higher value and lower TCO than mainframe storage alone


Complete business, migration, IT services, and education offerings help design, build, manage, and evolve your new environment


Flexible, world-class financial services make your move from mainframes to HP both affordable and cost effective


Misson-critical solutions: Did you know that HP -


Handles two-thirds of all credit card transations worldwide -- providing 24X7 service in key financial markets

Powers 14 of the world's largest stock exchanges

Supports 95% of the world's securities transactions

Handles 80% of all telecom billing and customer-care traffic in Europe and Asia

Is the hardware platform for half of all SAP deployments

Manages more than 50,000 heterogenous systems worldwide

Is an $80 billion company which runs entirely without mainframes


Friday, February 04, 2005

Credit Union and FSCC - An Information


What Is A Credit Union?


A credit union is a cooperative financial institution, owned and controlled by the people who use its services. These people are members. Credit unions serve groups that share something in common, such as where they work, live, or go to church. Credit unions are not-for-profit, and exist to provide a safe, convenient place for members to save money and to get loans at reasonable rates. Did you know there are at least seven ways you can find a credit union that you are eligible to join?
Credit unions, like other financial institutions, are closely regulated. And they operate in a very prudent manner. The National Credit Union Share Insurance Fund, administered by the National Credit Union Administration, an agency of the federal government, insures deposits of credit union members at more than 11,000 federal and state-chartered credit unions nationwide. Deposits are insured up to $100,000.
What makes a credit union different from a bank or savings & loan? Like credit unions, these financial institutions accept deposits and make loans--but unlike credit unions, they are in business to make a profit. Banks and savings & loans are owned by groups of stockholders whose interests include earning a healthy return on their investments.


What is FSCC?


Financial Service Centers Cooperative, Inc., (FSCC) is a cooperative credit union service organization, incorporated under the Cooperative laws of the State of California. FSCC is owned and governed by credit unions that are stockholders in the company. FSCC is the only international shared branching network. A company that prides itself on its technology, products and services to its owner and participating credit unions. FSCC is a founding and operating member of the CU Service Centers® Network, a cooperative National shared branching network of over 900 credit unions with over 1,000 locations in thirty-seven states and Puerto Rico. Locations are available on U.S. military bases in five countries. Linked by technology, the Network provides financial services to the credit union public where they live, work, and travel. An appropriate analogy is that of ATM networks, where technology and cooperative relationships between institutions enable the convenient delivery of financial services to consumers.


HP NONSTOP

Operating "Nonstop"

HP Using New OS For Robust, Fault-Tolerant Servers
Reliability is a true measure of any enterprise network. Corporate resources must often be up and available in the face of constant threats from users, bugs, and attacks. Network admins must implement and support fault tolerant systems, which is sometimes a challenge given today’s OSes and applications. Bill Buer, HP product manager, offered some information about HP’s NonStop OS and its recent support for 64-bit Intel servers.

A Long Road

The NonStop OS is certainly not a new platform. The kernel has been around for over 20 years, the result of a push to provide a complete fault-tolerant environment including a combination of hardware, software, and middleware that provides a 100% application uptime. Buer says, "Most systems strive to keep the [hardware] running, but the HP NonStop system addresses every level of the application stack to provide the most robust environment in the industry. Obviously one of the most key elements of the stack is the OS itself."

The improvements for NonStop have been many. "Over the years there have been new releases of the OS that were able to take advantage of new chip architectures, such as the MIPS RISC architecture. What is new here is that HP has announced that the platform that runs the NonStop OS is moving to a standard chip environment, which is the Intel Itanium Processor family. This means our customers will be able to take advantage of the 64-bit capability of Itanium, initially in the memory address space but longer term in having a full 64-bit operating environment," says Buer. Today, the NonStop OS runs on any MIPS-based HP NonStop server. In the future, this will also be any Itanium-based HP NonStop server. Of course, users may need to recompile their applications’ source codes to take best advantage of the Itanium.
NonStop is intended for multiprocessor servers but strives to overcome the loss of performance seen when SMP (symmetric multiprocessing) systems share memory resources. Buer says, "Each additional processor provides a sharply reduced benefit compared to the previous processor. Indeed, SMP systems become impractical with as few as eight processors. The NonStop server’s loosely coupled, shared nothing parallelism provides cost-effective, liner scalability, and, as a result, predictable response times in the face of swelling data volumes, expanding user populations, and a growing number of concurrent queries. Each processor has its own dedicated resources, so an added processor provides a full processor’s worth of performance." Results from large transaction processing and database benchmark tests using the NonStop Kernel OS show that even with more than 112 processors, each additional processor can execute at least 98.2% of the throughput of the first processor.

Performance Features & Management

HP NonStop servers already serve in many mission-critical applications, including the majority of the world’s securities, credit card, point-of-sale, and ATM transactions, as well as emerging zero latency enterprise systems. The NonStop OS is a versatile platform for parallel processing and application throughput. Buer says, "The NonStop Kernel OS enables critical business application processing to be transparently distributed across multiple processors and even multiple systems, either centralized locally or geographically distributed anywhere in the world. This is accomplished without application code changes or relocation of I/O devices because the NonStop Kernel message-based architecture efficiently connects all local and remote devices and processes between as few as two through as many as 4,080 loosely coupled processors working in parallel. Growth within a single server, an HP NonStop ServerNet Cluster, or the entire network can occur without disrupting application and database processing."

The combination of ServerNet technology and the NonStop Kernel OS enable both the data bandwidth and the number of processors to increase as needed to accommodate demanding and data-intensive applications. "Regardless of how large the system grows, the NonStop Kernel OS distributes the workload among the available processors, making efficient use of system resources and achieving exceptionally high aggregate throughput from parallel processing. The NonStop Kernel OS and its compilers automatically create a fully re-entrant code execution environment that makes replication and parallel processing highly efficient," explains Buer.

NonStop-based systems are also fully compliant with many existing system management applications, such as HP OpenView, IBM Tivoli, and CA Unicenter. Buer says, "System management products from HP’s NonStop Enterprise Division and its partners give flexibility and choice to tailor specific system and network management environments to specific business needs. All management solutions for HP NonStop servers automatically inherit the platform advantages of availability, scalability, and manageability."

The Security Question

Given the long line of security vulnerabilities appearing for such OSes as Windows, the security and integrity of a NonStop OS should be a real concern for any admin considering a platform shift. NonStop is certainly not invulnerable to attack, and identifying vulnerabilities and releasing fixes/patches are a high priority for HP. "Security related patches will be communicated to our customer base with appropriate dispatch, with full disclosure of the risks involved with not applying the patch. HP has a team of people that helps identify vulnerabilities on all HP platforms, and HP has policies for identifying and responding to potential vulnerabilities as quickly as possible." Still, he emphasizes that NonStop’s modularity and process separation help to make the OS more secure than other platforms. Pricing for NonStop should be established later in 2004, with general availability in 2005.

Sunday, January 30, 2005

Smart Card Technology - An Overview

Smart cards, also called chip cards, are old news for many. Most people are aware of their applicability to payments, but have seen many programs fail in the US. Target's rescindment of its smart card program last year seemed to many to seal the fate of the cards in the US. Many businesses have a rather grim outlook on the adoption of smart cards in this country and have shelved their smart card initiatives. However, the movement is not one of extinction, but rather one of hibernation. Those close to the payments industry and with an eye on the progress of smart technology know that smart cards will one day take over magnetic stripes and revolutionize the payment industry. It is only a matter of when and how. Industry estimates of when smart cards will have a strong US presence range from five to 10 years and beyond. Celent does not expect them to have a significant presence for at least seven years.



Celent believes that several factors will determine the fate of smart cards. Some have been known in the market since the decline of the first American smart cards, while others may come as a surprise to those who have had their eyes set on the wrong horizon. They include the proliferation of smart card technology across industries, elimination of cash-based systems, rise in fraud, and the global migration of smart card-enabled payments. No one factor is necessarily more important than another. Every factor is affected by at least one other, so isolating the effects of any one of these issues is virtually impossible. Together they weave an intricate web of events and forces that will ultimately drive the adoption of smart cards in the US.


EMV: The shift in liability associated with EMV is driving many banks to issue smart cards. Under many EMV rules, responsibility for liability fraud that could have been prevented by chip technology will fall on the party that has not made the upgrade. Aside from the threat of increased liability, merchants and banks are being incentivized by lower or higher interchange rates for transactions made with chip cards or POS systems.



Proliferation of Smart Card Technology: For years people have looked at smart technology and its potential, but have hesitated due to the traditionally high cost. Historically, smart card applications were reserved for industries that had either high-margin businesses, a need for strict security, or products for which a one-time fee could be charged to cover the cost of the chip. However, the cost of manufacturing smart technology has dropped significantly over the last few years. The reduction in cost has led managers in low-margin businesses to realistically consider the potential and applicability of smart card technology. The use of smart technology across applications and industries will begin to create familiarity with the technology, not only among managers, but also consumers. This familiarity will come as an epiphany to some as they discover that they have been surrounded by the technology without realizing it. Smart technology's proliferation through all industries, including payments, is most likely inevitable.


Elimination of Cash-Based Systems: The evolution of payments has always been guided by convenience and the cost of doing business. As purse technology evolves, it will become easier to replace cash transactions as well, particularly at locations servicing low-value transactions. Smart cards will also become preferred as business owners realize smart card readers, particularly RF ones, require less maintenance than magnetic stripe readers and currency feeds.


The Rise of Fraud: The US card industry has enjoyed low rates of fraud in recent years. As such, the anti-fraud benefits of a smart card have done little to motivate US adoption. This is certainly not the case in other countries that have experienced astronomically high rates of fraud. Although Celent does not believe that the rise of smart card use in other nations will drastically drive fraud to the US, the existing rise in skimming scams and related frauds in the US, coupled with the increasing use of payment cards will likely push the industry to consider the ennhanced security of a smart card.



International Expansion: Issues of fraud notwithstanding, smart card use in other countries will create pressure in the US to move to smart cards. The movement to smart card programs is beginning to span the globe. Regions around the world are beginning to implement smart card programs, with many of them making such programs mandatory, while others are beginning to lay the foundation for what is to come.


The crystal ball for smart cards in the US is cloudy. Too many factors will ultimately have an effect on the timing and strength of adoption. Answering the "when" part of the smart card question is a bit trickier, as several variables will impact the outcome. The speed at which other countries implement EMV and phase out magnetic stripes will affect the timeline; so will international travel volume. Should a disaster occur that impedes the international travel industry, universal card use and acceptance will be stymied. Another factor is the migration of chip and the speed with which criminals find a way to crack smart cards. Should one happen before the other, the movement of fraud will be affected. Movement will also be affected by concurrent measures to stop crimes such as identity theft, which could give criminals an alternative to compromising cards in their country. So much uncertainty does make planning difficult. Ultimately, smart cards are a payment product and must be driven by the financial services industry, not merchants or consumers. If they were left up to the latter two, the classic card conundrum would take effect and lead the industry nowhere. It is a game of monkey in the middle, and the financial institution must grab the ball and run with it.

Thursday, December 23, 2004

Networks

Access Networks

For most credit card applications, the cost of the access network is the single biggest factor in overall costs, often accounting for over half of the total. For that reason, there are many different solutions, depending on the provider, the application, and geographical constraints.

The simplest form of access network uses 800 service, in one of its many forms. Terminals at merchant locations across the country dial an 800 number that is terminated on a large hunt group of modems, con- nected directly to the acquirer's front-end processor (FEP). The FEP is typically a fault-tolerant machine, since an outage here will take out the entire service. A large acquirer will typically have two or more centers for terminating the 800 service. This allows better economy, due to the nature of 800 service tariffs, and allows for di- saster recovery in case of a failure of one data center. An advantage of 800 service is that it is quite easy to cover the entire country with it. It also provides the most effective utilization of your FEP resources. (A little queuing theory will show you why.) However, 800 service is quite expensive. It always requires 10 (or 11) digits di- aled, and in areas with pulse dialing it can take almost three seconds just to dial 1-800. The delay between dialing and connection is longer for 800 calls than many other calls, because of the way the calls get routed. All of this adds to the perceived response time at the mer- chant location, even though the acquirer has no control over it.

Large acquirers prefer to offer some form of local access service. In this service, terminals at the merchants dial a local telephone number to gain access to the acquirer. Typically, the local number actually connects to a packet network, which then connects to the acquirer. If the packet network is a public network, the terminal must go through a login sequence to get connected across the packet network. Typically, local calls are much less expensive than 800 service calls, and local calls typically connect faster than 800 calls. The cost of those calls are absorbed by the merchants directly. In those few remaining areas where local calls are still free from a business line, this works out well for the merchant. Otherwise, the merchant can end up spending a lot of money on phone calls. Usually, the acquirer has to offer lower prices to accepters who use local calls, to help offset this. Even so, these networks are generally much less expensive for the acquirers. Such networks are difficult to maintain, due to the distributed nature of the access network. Since most packet networks are much more likely to experience failures than the phone network is, the merchant's POS terminal is usually programmed to dial an 800 number for fallback if the local number doesn't work. Also, it is generally not cost effective to cover every free calling area in the entire country with access equipment, so some 800 service is required anyway. There is also an administrative headache associated with keeping track of the different phone numbers that each merchant across the country needs to dial. When you have tens of thousands of terminals to support, this can be formidable.

Acquirers are beginning to experiment with Feature Group B (FGB) ac- cess. FGB access was the method of access used to get to alternative long-distance carriers before "equal access" was available. The tariffs are still on the books, and they are favorable for this appli- cation. FGB access provides a single number, nationwide, for all mer- chants to dial in order to gain access to the acquirer. The call has simpler (hence, presumably, faster) routing than 800 service, and the call is charged to the acquirer, not the accepter. FGB access does have to terminate on equipment that is physically located in the Local Access Toll Area (LATA) where the call originated, so there is the problem of having distributed equipment, as above. This also implies that it is not cost-effective to deploy FGB access everywhere, as well. There are also some technical oddities of FGB, due to its original in- tent, that have made it difficult to implement so far.

The other big switched access capability that is likely to have an im- pact in the future is ISDN. So far, this has been inhibited by limited availability and lack of adequate equipment on the merchant end, but it could be very beneficial when these problems are solved.

Private-line networks are pretty straightforward applications of point-to-point and multipoint private lines. Since private lines are quite expensive, engineering of the networks is challenging. Usually, sophisticated software is used to determine the optimum placement of concentrators in order to minimize costs. Since tariffs, real estate prices, and business needs change frequently, maintaining a stable, cost-effective network is hard work. A typical asynchronous private line network will have multiplexers at remote sites, with backbone links to companion multiplexers at a central site. Synchronous private line networks may use multiplexers, or remote controllers, or remote FEPs, depending on the application and the availability of real estate.


Tuesday, December 21, 2004

SETTLEMENT - An overview

SETTLEMENT

Between Acquirer and Issuer, money has changed ,Thats only financial liability. The purpose of settlement is to shift the financial liability back to the cardholder, and to shift the cardholder's money to the merchant. Theoretically, all authorization information can be simply discarded once an approval is received by a merchant. Of course, contested charges, chargebacks, merchant credits, and proper processing of holds require that the information stay around. Still, it is important to realize that an authorization transaction has no direct financial consequences. It only establishes who is responsible for the financial consequences to follow.

Traditionally, a merchant would take the charge slips to the bank that was that merchant's acquirer, and "deposit" them into the merchant account. The acquirer would take the slips, sort them by issuer, and send them to the issuing banks, receiving credits by wire once they arrived and were processed. The issuer would receive the slips, microfilm them (to save the transaction information, as required by federal and state laws) charge them against the cardholder's accounts, send credits by wire to the acquirer, and send out the bill to the cardholder. Problem is, this took time. Merchants generally had to wait a couple of weeks for the money to be available in their accounts, and issuers often suffered from float on the billables of about 45 days.

Therefore, nowadays many issuers and acquirers are moving to on-line settlement of transactions. This is often called "draft capture" in the industry. There are two ways this is done - one based on the host and one based on the terminal at the merchant's premises. In the host-based case, the terminal generally only keeps counts and totals, while the acquirer host keeps all the transaction details. Periodically, the acquirer host and the terminal communicate, and verify that they both agree on the data. In the terminal-based case, the terminal remembers all the important transaction information, and periodically calls the acquirer host and replays it all for several transactions. In either case, once the settlement is complete the merchant account is credited. The acquirer then sends the settlement information electronically to the issuers, and is credited by wire immediately (or nearly so). The issuer can bill directly to the cardholder account, and float can be reduced to an average of 15 days.

The problem is, what to do with the paper? Current regulations in many states require that it be saved, but there is no need for it to be sent to the issuer. Also, for contested charges, a paper trail is much more likely to stand up in court, and much better to use for fraud investigations. Currently, the paper usually ends up back at the issuer, as before, but it doesn't need to be processed, just microfilmed and stored. Much of the market still uses paper settlement methods. Online settlement will replace virtually all of this within the next 5 to 10 years, because of its many benefits.

What do you mean by Acquirer and Issuer?

Acquirer

The acquirer gathers authorization requests from accepters and returns approvals. If the acquirer is an issuer as well, "on us" transactions will typically be turned around locally. As before, the acquirer does not have to forward any requests on to the actual issuer. However, acquirers are not willing to take the financial risks associated with generating local approvals. Thus most transactions are sent on to the issuers (interchanged). The purpose of interchange is to shift finan- cial liability from the acquirer to the issuer.

Typically, an acquirer connects to many issuers, and negotiates differ- ent business arrangements with each one of them. But the acquirer gen- erally provides a uniform interface to the accepter. Thus, the interchange rules are sometimes less stringent than those imposed on the accepter. Also, most issuers will trust acquirers to with respon- sibilities they would never trust to accepters. The acquirer can therefore perform some front-end screening on the transactions, and turn some of them around locally without going back to the issuer.

The first screening by the acquirer would be a "sanity" test, for valid merchant ID, valid Luhn check on PAN, expiration date not past, amount field within reason for type of merchant, etc. After that, a floor limit check will be done. Issuers generally give acquirers higher floor limits than acquirers give accepters, and floor limits may vary by type of merchant. Next, a "negative file" check would be done against a file of known bad cards. (This is essentially the same as the bulletin.) Then a "velocity file" check may be done. A velocity file keeps track of card usage, and limits are often imposed on both number of uses and total amount charged within a given time period. Sometimes multiple time periods are used, and it can get fairly complicated.

Transactions that pass all the checks, and are within the authority vested in the acquirer by the issuer, are approved by the acquirer. (Note that, under the business arrangement, financial liability still resides with the issuer.) An "advice" transaction is sometimes sent to the issuer (perhaps at a later time), to tell the issuer that the transaction took place.

Transactions that "fail" one or more checks are denied by the acquirer (if the cause was due to form, such as bad PAN) or sent to the issuer for further checking. (Note that "failure" here can mean that it's be- yond the acquirer's authority, not necessarily that the card is bad.) Some systems nowadays will periodically take transactions that would otherwise be approved locally, and send them to the issuer anyway. This serves as a check on the screening software and as a countermeasure against fraudulent users who know the limits.

Transactions that go to the issuer are routed according to the first six digits of the PAN, according to the ISO registry mentioned in an earlier section. Actually, it's a bit more complicated than that, since there can be multiple layers of acquirers, and some issuers or acquirers will "stand in" for other issuers when there are hardware or communication failures, but the general principal is the same at each point.

Issuer

An issuer receiving an interchanged transaction will often perform many of the same tests on it that the acquirer performs. Some of the tests may be eliminated if the acquirer is trusted to do them correctly. This is the only point where a velocity file can actually detect all usage of a card. This is also the only point where a "positive file" lookup against the actual account can be done, since only the issuer has the account relationship with the cardholder. If a PIN is used in the transaction, only the issuer can provide true PIN verification - acquirers may be able to do only "PIN offset" checking, as described in a previous section. This is one reason why PINs have not become popular on credit and charge cards.

An account typically has a credit limit associated with it. An ap- proved authorization request usually places a "hold" against the credit limit. If the sum of outstanding holds plus the actual outstanding balance on the account, plus the amount of the current transaction, is greater than the credit limit, the transaction is (usually) denied. Often in such a case the issuer will send back a "call me" response to the merchant. The merchant will then call the issuer's number, and the operator may even want to talk to the cardholder. The credit limit could be extended on the spot, or artificially high holds (from hotels or car rental companies) could be overlooked so that the transaction can be approved.

The difference between the credit limit and the sum of holds and out standing balance is often referred to as the "open to buy" amount. Once a hold is placed on an account, it is kept there until the actual the transaction in question is settled (see below), in which case the amount goes from a hold to a billed amount, with no impact on the open to buy amount, theoretically. For authorizations of an estimated amount, the actual settled amount will be less than or equal to the ap- proved amount. (If not, the settlement can be denied, and the merchant must initiate a new transaction to get the money.) Theoretically, in such a case, the full hold is removed and the actual amount is added to the outstanding balance, resulting in a possible increase in the open to buy amount.

In practice, older systems were not capable of matching settlements to authorizations, and holds were simply expired based on the time it would take most transactions to clear. Newer systems are starting to get more sophisticated, and can do a reasonable job of matching autho- rizations for actual amounts with the settlements. Some of them still don't match estimated amounts well, with varying effects. In some cases, the difference between actual and estimated will remain as a hold for some period of time. In other cases, both the authorization and the settlement will go against the account, reducing the open to buy by up to twice the actual amount, until the hold expires. These problems are getting better as the software gets more sophisticated.

Some issuers are also starting to use much more sophisticated usage checks as well. They will not only detect number of uses and amount over time, but also types of merchandise bought, or other patterns to buying behavior. Most of this stuff is new, and is used for fraud prevention. I expect this to be the biggest effort in authorization soft- ware for the next few years.

American Express does things completely differently. There are no credit limits on AMEX cards. Instead, AMEX relies entirely on usage patterns, payment history, and financial data about cardmembers to determine whether or not to automatically approve a transaction. AMEX also has a policy that a cardmember will never be denied by a machine. Thus, if the computer determines that a transaction is too risky, the merchant will receive a "call me" message. The operator will then get details of the transaction from the merchant, and may talk to the cardmember as well, if cardmember identity is in question or a large amount is requested. To verify cardmember identity, the cardmember will be asked about personal information from the original application, or about recent usage history. The questions are not the same each time. If an unusually large amount is requested, the cardmember may be asked for additional financial data, particularly anything relating to a change in financial status (like a new job or a promotion). People who are paranoid about Big Brother and computer databases should not use AMEX cards.






Organizations and Standards

THE ORGANIZATIONS

ISO sets standards for plastic cards and for data interchange, among other things. ISO standards generally allow for national expansion. Typically, a national standards organization, like ANSI, will take an ISO standard and develop a national standard from it. National standards are generally subsets of the ISO standard, with extensions as allowed in the original ISO standard. Many credit card standards originated in the United States, and were generalized and adopted by ISO later. The ANSI committees that deal with credit card standards are sponsored by the ABA. Most members of these committees work for banks and other financial institutions, or for vendors who supply banks and financial institutions. Working committees report to governing committees. All standards go through a formal comment and review procedure before they are officially adopted.

PHYSICAL STANDARDS

ANSI X4.13, "American National Standard for Financial Services - Financial Transaction Cards" defines the size, shape, and other physical characteristics of credit cards. Most of it is of interest only to mechanical engineers. It defines the location and size of the magnetic stripe, signature panel, and embossing area. This standard also includes the Luhn formula used to generate the check digit for the PAN, and gives the first cut at identifying card type from the account number. (This part was expanded later in other standards.) Also, this standard identifies the character sets that can be used for embossing a card. Three character sets are allowed - OCR-A as defined in ANSI X3.17, OCR-B as defined in ANSI X3.49, and Farrington 7B, which is defined in the appendix of ANSI X4.13 itself. Almost all the cards I have use Farrington 7B, but Sears uses OCR-A. (Sears also uses the optional, smaller card size as, allowed in the standard.) These character sets are intended to be used with optical character readers (hence the OCR), and large issuers have some pretty impressive equipment to read those slips.

ENCODING STANDARDS

ANSI X4.16, "American National Standard for Financial Services - Financial Transaction Cards - Magnetic Stripe Encoding" defines the physical, chemical, and magnetic characteristics of the magnetic stripe on the card. The standard defines a minimum and maximum size for the stripe, and the location of the three defined encoding tracks. (Some cards have a fourth, proprietary track.)

Track 1 is encoded at 210 bits per inch, and uses a 6-bit coding of a 64-element character set of numeric, alphabet (one case only), and some special characters. Track 1 can hold up to 79 characters, six of which are reserved control characters. Included in these six characters is a Longitudinal Redundancy Check (LRC) character, so that a card reader can detect most read failures. Data encoded on track 1 include PAN, country code, full name, expiration date, and "discretionary data". Discretionary data is anything the issuer wants it to be. Track 1 was originally intended for use by airlines, but many Automatic Teller Machines (ATMs) are now using it to personalize prompts with your name and your language of choice. Some credit authorization applications are starting to use track 1 as well.

Track 2 is encoded at 75 bits per inch, and uses a 4-bit coding of the ten digits. Three of the remaining characters are reserved as delimiters, two are reserved for device control, and one is left undefined. In practice, the device control characters are never used, either. Track 2 can hold up to 40 characters, including an LRC. Data encoded on track 2 include PAN, country code (optional), expiration date, and discretionary data. In practice, the country code is hardly ever used by United States issuers. Later revisions of this standard added a qualification code that defines the type of the card (debit, credit, etc.) and limitations on its use. AMEX includes an issue date in the discretionary data. Track 2 was originally intended for credit authorization applications. Nowadays, most ATMs use track 2 as well. Thus, many ATM cards have a "PIN offset" encoded in the discretionary data. The PIN offset is usually derived by running the PIN through an encryption algorithm (maybe DES, maybe proprietary) with a secret key. This allows ATMs to verify your PIN when the host is offline, generally allowing restricted account access.

Track 3 uses the same density and coding scheme as track 1. The contents of track 3 are defined in ANSI X9.1, "American National Standard - Magnetic Stripe Data Content for Track 3". There is a slight contradiction in this standard, in that it allows up to 107 characters to be encoded on track 3, while X4.16 only gives enough physical room for 105 characters. Actually, there is over a quarter of an inch on each end of the card unused, so there really is room for the data. In practice, nobody ever uses that many characters, anyway. The original intent was for track 3 to be a read/write track (tracks 1 and 2 are intended to be read-only) for use by ATMs. It contains information needed to maintain account balances on the card itself. As far as I know, nobody is actually using track 3 for this purpose anymore, because it is very easy to defraud.

COMMUNICATION STANDARDS

Formats for interchange of messages between hosts (acquirer to issuer) is defined by ANSI X9.2, which I helped define. Financial message authentication is described by ANSI X9.9. PIN management and security is described by ANSI X9.8. There is a committee working on formats of messages from accepter to acquirer. ISO has re-convened the international committee on host message interchange (TC68/SC5/WG1), and ANSI may need to re-convene the X9.2 committee after the ISO committee finishes. These standards are still evolving, and are less specific than the older standards mentioned above. This makes them somewhat less useful, but is a natural result of the dramatic progress in the industry.

ISO maintains a registry of card numbers and the issuers to which they are assigned. Given a card that follows standards (Not all of them do.) and the register, you can tell who issued the card based on the first six digits (in most cases). This identifies not just VISA, MasterCard, etc., but also which member bank actually issued the card.

DE FACTO INDUSTRY STANDARDS

Most ATMs use IBM synchronous protocols, and many networks are migrating toward SNA. There are exceptions, of course. Message formats used for ATMs vary with the manufacturer, but a message set originally defined by Diebold is fairly widely accepted.

Many large department stores and supermarkets (those that take cards) run their credit authorization through their cash register controllers, which communicate using synchronous IBM protocols.

Standalone Point-of-Sale (POS) devices, such as you would find at most smaller stores (i.e. not at department stores), restaurants and hotels use a dial-up asynchronous protocol devised by VISA. There are two generations of this protocol, with the second generation just beginning to get widespread acceptance.

Many petroleum applications use multipoint private lines and a polled asynchronous protocol known as TINET. This protocol was developed by Texas Instruments for a terminal of the same name, the Texas Instruments Numerical Entry Terminal. The private lines reduce response time, but cost a lot more money than dial-up.

NACHA establishes standards for message interchange between ACHs, and between ACHs and banks, for clearing checks. This is important to this discussion due to the emergence of third-party debit cards, as discussed in part 1 of this series. The issuers of third-party debit cards are connecting to ACHs, using the standard messages, and clearing POS purchases as though they were checks. This puts the third parties at an advantage over the banks, because they can achieve the same results as a bank debit card without the federal and state legal restrictions imposed on banks.

Players and their Roles in Electronic Payments

PLAYERS AND THEIR ROLES

American Express (AMEX) is a charge card issuer and acquirer. (Their other businesses are not important to this discussion.) All AMEX purchases are authorized by AMEX. They make most of their money from the discount fees, which is why they have the highest discount fee in the industry. That's one reason why AMEX isn't accepted in as many places as VISA and MC, and a reason why many merchants will prefer another card to an AMEX card. The control AMEX has over authorization allows them to provide what they consider to be better cardholder ("card member" to them) services.

VISA is a non-profit corporation that is best described as a purchasing and marketing coalition of its member banks. VISA issues no credit cards itself - all VISA cards are issued by member banks. VISA does not set terms and conditions for its member banks - the banks can do pretty much as they please in signing cardholders. All VISA charges are ultimately approved by the card issuer, regardless of where the purchase was made.

Many smaller banks share their account databases with larger banks, third parties, or VISA itself, so that the bank doesn't have to provide authorization facilities itself. Master Card (MC) is very much like VISA.

There are some differences that are important to those in the industry, but from the consumers standpoint they operate pretty much the same.

Discover cards are issued by a bank owned by Sears. All Discover purchases are authorized by Sears.

Most petroleum cards, if they are even authorized, are authorized by the petroleum company itself. There are exceptions. Fraud on petroleum cards is so low that the main reason for authorization is to achieve the float reduction of electronic settlement.

Monday, December 20, 2004

Contact Less CHIP Transactions:-

Contact Less CHIP Transactions:-
---------------------------------------------------

New payment methods are being developed and introduced in the payment industry.
One of these new methods is the use of contactless chips that are embedded within a Visa card.
The contactless chip transmits Track 2 data wirelessly without direct physical contact between the card and the terminal.

Visa will implement changes to add new values to identify contactless chip transactions.
Visa U.S.A. will support the issuance of cards with contactless chips and the processing of transactions originated from a contactless chip.

Any Visa credit or Visa debit card may be issued with a contactless chip in accordance with the standards published by Visa.

These Visa contactless chip cards consist of one of the following:

1), a magnetic stripe Visa card with an embedded contactless chip
2) a Visa Smart Debit Credit (VSDC) chip card that has a magnetic stripe and supports a contactless chip.

The contactless chip employs radio frequency identification (RFID) technology that enables the chip to communicate with a point-of-sale (POS)
device that is enabled with a RFID receiver.

All contactless terminals must support RFID technology at the point-of-sale in accordance with the technical specifications ISO 14443 A and B and the Visa
Financial Messaging Specification for Contactless Payment.

The contactless chip employs radio frequency identification (RFID) technology that enables the chip to communicate with a point-of-
sale (POS) device that is enabled with a RFID receiver. A Visa contactless chip card and RFID-enabled terminal
communicate wirelessly so that the magnetic stripe information is sent from the chip to the terminal.

Monday, November 29, 2004

Radio Frequency Identification (RFID)

Features of Radio Frequency Identification

TURNING FULL CIRCLE

The term Radio Frequency Identification (RFID), which describes a type of automatic identification system, was first heard of in the 1980s, when it was used to track applications. The genesis of the technology, however, can be traced to World War II, when it was developed by allied forces for radar operators, to enable them to distinguish between friendly and enemy aircraft!

What started out as a technology with predominantly defense uses, RFID has expanded the ambit of its coverage to include a range of applications such as transportation and logistics, manufacturing and processing, security, animal tagging, waste management, time and attendance, postal tracking, airline baggage reconciliation and road toll management. RFID, which offers users more granular, accurate information and provides a means to automate processes that are manual, has proved itself as a technology that results in dramatic supply-chain improvements.

MARKET FORECASTS

The market forecasts for RFID vary. However, here’s what key analysts are predicting about the market:

Frost & Sullivan’s latest report on the World RFID-Based Applications Market reveals that the industry generated revenues totaling US$1.7 billion in 2003. The turnover of this industry is expected to grow to US$ 11.7 billion by 2010.

Datamonitor has forecast a US$ 5-20 billion European market for intelligent tags and their equipment in year 2005, including the UK.

Frost and Sullivan sees a $10 billion global market for RFID and EAS systems in 2005
based RFID systems, including tags, touched around US$ 1.4 billion in 2002. The market for the tags including smart labels was estimated to be around about US$ 0.7 billion.

Global research conducted by IDTechEx, predicts that by 2013 the RFID market will be worth US$ 10 billion, with 50 percent of the revenues being accounted for by hardware (tags and readers) and the rest by software, services and infrastructure

The leaders in smart labels are each shipping 60 to 120 million chip tags a year, i.e., valued at around US$ 100 million each for the tags alone. Philips, as the largest supplier of RFID chips (one per tag) says global consumption for smart labels is expected to be approximately 1.9 billion units in 2004. In the segment of systems and tags, TransCore has sales of US$ 350 million and Savi Technology has US$ 65 million. All the leading analysts see double-digit growth (typically in the region of 25 percent yearly) of RFID markets by value over the next few years. None of the above forecasts for RFID include RFID contact-less smart cards and tickets.

IT MAJORS: GEARING UP FOR RFID

A number of global and Indian IT software and services companies have started vying for a piece of the RFID pie. IT vendors such as Oracle and others are building supply-chain and warehouse management applications that can work with RFID data. Sun Microsystems, for instance, is building a middleware based on standard specifications for RFID and SAP has released middleware products for linking RFID readers to back-end applications and monitoring business-process expectations.

Closer to home, leading Indian IT software companies have taken significant initiatives on the RFID front. Newsline provides a peek into the RFID strategies of a few IT software and services companies:

COGNIZANT

The solution: Cognizant provides an end-to-end RFID solution, spanning applicability assessment, technical and ergonomic feasibility, scenario modeling, ROI analysis and pilot planning, solution architecture, application development and implementation.
RFID strategy: Currently, Cognizant is working on pilots and proof of concepts for some of its customers across verticals in the area of palette and case labeling. Plans are afoot to extend it to item labeling when the prices of RFID tags drop to realistic levels. As the standards for RFID are still evolving, Cognizant's Centers of Excellence are closely tracking trends in this space before large-scale deployment for customers. Cognizant has set up a dedicated RFID Competency Center and Lab in Kolkatawhich houses its Retail Center of Excellence, for developing and testing RFID solutions.

Cognizant has also built an RFID simulator for software based testing of the RFID architecture. The Lab is currently focused on developing a scalable middleware environment to handle enormous amount of data generated by RFID readers and to bridge the gap between the middleware and the backend systems

INFOSYS

The solution: Infosys offers a comprehensive solution for RFID adoption which includes a range of services from concept-to-implementation. The solution enables clients to evaluate the technology in their business context, build a business case, and develop a roadmap for phased adoption. Infosys' RFID solution stack includes pre-built tools, templates, frameworks and reference models that enable customers to unravel the disruptive potential of this technology. Edge Server Lite, the company's ready-to-deploy software stack for RFID event management and integration helps customers to rapidly embark on their RFID initiatives enabling faster time-to-market at a lower total cost of ownership.

Chitale Digitals

In the RFID segment, the company manufactures "Mifare RF Cards" and "Hitag RF Cards". The Mifare Card system is used for "Attendance and Data Management" applications. The Mifare smart card is a contact less or dual interface RF card. Built on the Mifare architecture the product is centered around ISO/IEC 1443, type A standards. Mifare cards and readers are developed by and manufactured by Philips Semiconductor.

The Hitag RF Cards, consisting of read/write devices, data carriers and Antenna readers represents a new generation of secure passive RFID system. HITAG is the first passive RFID system with anti collision capabilities. This allows several data carriers to operate simultaneously within the communication field of Antenna.

So far, the company has completed installations at the Bhabha Atomic Research Center, IRCON and Philips, among other sites.

Patni Computer Systems

PCS set up an RFID lab eight months ago. Supply-chain and RFID consultants man the lab and it has already delivered an RFID pilot based on Auto-ID’s RFID framework that integrates into a SAP back-end for processing transactions.

Wipro Technologies

To understand the issues surrounding RFID deployments in a retail setting, Wipro Technology has started testing RFID in a retail store. The company operates on the campus of its headquarters in Bangalore, India.

In early July, Wipro finished building an RFID system in the 1,000-square-foot campus store. According to Wipro, designing, developing and deploying its own RFID pilot provided the company with a great deal of first-hand experience regarding the kinds of issues its retail customers will face with their own deployments. Besides highlighting the requirements of middleware and software integration, the project also taught the company about the significance of a site survey, the need to design and deploy RFID hardware within the context of the business for which it is deployed, the importance of antenna orientation for smart shelves, the impact of an RFID system on existing business processes and applications and the amount of work required to develop new systems to work with RFID.

Indian IT companies, therefore, need to take a closer look at RFID and enter a market that is expected to rapidly expand over the next few years. As the cost of RFID implementation comes down, standards emerge and users develop stringent safeguards on how RFID systems are deployed (taking care of privacy issues), the market will offer significant opportunities for Indian IT software and services companies. Against this backdrop, Indian Tier 1 and Tier 2 vendors need to develop expertise in providing customized solutions for RFID and perhaps set up separate practices focused on the technology

ACH - An overview

ACH

The automated clearinghouse (ACH) is an electronic payments network that allows for the clearing and settlement of debit and credit transactions among financial
institutions. Only financial institutions may have direct links to the ACH, and, through
them, more than 3 million businesses and 100 million consumers originate and receive
ACH transactions.

The ACH was created in the mid-1970s as part of the government’s
efforts to begin dispersing electronically the burgeoning number of government payments
(such as Social Security). Since then the ACH has experienced continued growth. The
network is governed by the Operating Rules of the National Automated Clearinghouse
Association (NACHA – The Electronic Payments Association).

There are currently three ACH Operators –
the Federal Reserve,
Electronic Payments Network (EPN; formerly the New York Automated Clearinghouse, or
NYACH), and
Visa.

Though EPN and Visa are both nonbanks, they are bank-owned.

For transactions sent through the Federal Reserve, settlement may take place in the
Federal Reserve account of each financial institution, or in the Federal Reserve account
of designated correspondents. EPN and Visa both ultimately rely on the Federal Reserve
for settlement.

In 2001, nearly 8 billion transactions, with a corresponding dollar value of $14
trillion, were sent over the ACH network. Of those, traditional uses of the ACH, such as
for payroll direct deposit and automatic bill payment, accounted for over 6 billion
transactions.

The transaction begins with a party providing authorization to an originator. That originator passes entries along to the financial institution that will serve as the originating depository financial institution (ODFI). The ODFI, in turn, sends entries to the operator, which edits the entries and distributes them to the appropriate receiving depository financial institutions (RDFI), and effects settlement. The RDFI posts the item(s) to the receiver’s account.

As with other payments system applications, the ACH network allows for the
participation of third-party processors on behalf of financial institutions. There are four
situations in which third-party processors may be participants in the ACH. In the first
scenario, a financial institution allows a corporate customer to send files directly to the
ACH Operator.19 In the second, a financial institution allows a consumer bill payment
service to collect and then disburse funds by sending files directly to the ACH Operator,
using its account at the ODFI as a pass- through account.20 The third scenario is one in
which the ODFI uses a correspondent financial institution for processing and/or
settlement.21 Finally, in the fourth scenario, the ODFI uses a correspondent financial
institution for processing but not for settlement.

Though the bulk of ACH transactions are generated for traditional payments, the
ACH network is also being used for emerging payments. For example, in 1999 NACHA
implemented rules that allow for the conversion of paper checks to ACH items. Two
such conversion opportunities are paper checks written at the POS and paper checks
received at remittance lockboxes.






Cryptography in Financial Network

cryptography in Magnetic stripe cards


The intention of this section is to demonstrate how cryptographic principles are (usually) applied to magnetic stripe cards in a practical context.
PIN Processing
The PIN principle is based on the fact that nobody other than the legitimate cardholder has knowledge of the PIN. Thus when a PIN is provided for a customer:
It must not be stored anywhere in cleartext (except in the secure PIN mailer destined for the customer)
It must not be possible to reverse-engineer the PIN from information on the magnetic stripe or from a centrally held database.
Normally, a PIN is a 4-digit numeric value. Other schemes exist, but we will use this format for illustration as it is a common standard. When a PIN is issued, the sequence of events is as follows:
A 4-digit random number is generated. This is the PIN.
The PIN is combined with other information, such as the account number, to create a block of data for input to the cryptography process.
The input block is triple encrypted using the PIN working keys
Digits are selected from the ciphertext result. These become the Pin Verification Value or Pin Offset.
The PIN Offset is stored
The PIN mailer is printed
Memory is cleared to binary zeroes to remove all traces of the clear PIN.
At this point, the only place the PIN value exists is inside the PIN mailer. The PIN cannot be derived from the PIN offset.
When the card is used and the PIN entered, the PIN offset is calculated again from the entered PIN, using the PIN working keys and compared to the stored offset value to determine if the correct PIN was entered. Clearly this means that when a PIN is validated, the validating system must have access to the PIN working keys used during initial PIN issue or subsequent PIN change.
It should be re-emphasised that the offset comprises selected digits from the ciphertext. Typically this would be 4-6 digits. It is not possible to recreate the keys or derive the PIN from this value.
Notes:
I.In some implementations, the PIN offset is stored on the magnetic stripe on the card. This is intended to be used in terminals which can perform local PIN validation. However, this technique is becoming rare as it prevents deployment of user-selectable PIN's.
II. Where the user is given the option to change PIN, the new offset is calculated in realtime and written to the database. Note that if the PIN is forgotten, it cannot be recreated.
III. The method described above is generic. There are many variations, such as the IBM3624 Method-A, Diebold method, and so on, however the principle remains the same.
IV. In many methods, the framework exists for using different key pairs based on an index value, usually stored on the magnetic stripe. This is a single digit value denoting the index of the key pair to be used. The intent is so that a) the same keys are not used across the entire cardbase, and c) that new keys can be used on re-issue without affecting existing cards.
CVV processing
It was quickly understood that the proliferation of financial cards exposed institutions to risk from counterfeiters. In the credit card world, this came from manufacture of cards with or without magnetic stripe encoding that possessed valid numbers and seemingly valid names and logos. In the ATM card arena, attackers observed PIN number entry 'over the shoulder', collated these PIN's with information from discarded receipts and so on, and constructed their own magnetic stripes on dummy cards for use at their leisure with observed PIN numbers.
These threats and others led to the introduction of the Card Verification Value, a non-derivable sequence of digits constructed by cryptographic process and written to the magnetic stripe of the card. This means that electronic capture of transactions (either at ATM or Point of Sale) are effectively protected against counterfeiters.
A combination of static data such as account number is triple encrypted using a special Card Verification key pair. Selected digits from the result are used to create the CVV, and this is written onto the magnetic stripe.
Similar comments apply to CVV as those for Pin Offset; As the CVV consists of few digits, and triple encryption is used, the CVV keys and values are highly secure and presence of a valid CVV provides an added level of confidence that the card is not counterfeit.
It should be noted that CVV is simply an additional protection method; it is not foolproof. It does not, for instance, protect against fraudulent captures of magnetic stripe data using, say, fake ATM's.
A further development of CVV, CVV2, is used for telephone authorisations. A similar (although not identical) calculation is performed as for CVV, and selected digits from the result are physically printed on the back of the card. These digits can then be requested by a call centre wishing to determine if the caller is really in possession of the card. Once again, this is an additional check, and not foolproof.
Key management
Key management relates to the storage, protection and transmission of keys. A single financial installation will have many DES keys, and these require careful management if they are not to become compromised or confused. One of the worst forms of debugging of computer faults is when cryptography is involved as traces and dumps are meaningless, and it can be very hard to discover that the wrong cryptography keys are being used!
Keys are normally managed in hierarchies. Keys that are actually used for computation, such as PIN validation [working keys] are themselves stored in enciphered format under a key encryption key. Other key sets will exist for transporting keys from one location to another, such as two nodes in a network. These are known as transport keys.
In good key management systems, working keys are never stored or exposed in clear format. Even when they are initially created, they are frequently created by automated process and never known to individuals.
When initial keys are created, the 64 bits are split between two or more individuals, who then toss a coin once for each bit required. The two or more individuals then key in their segment of the random key alone, and thus no one individual ever has sight of a whole key. This method is normally used for initial master key generation.
Although a simple concept, key management can become quite complex in implementation.
In a simple ATM network for instance, a terminal master key is used to encipher working keys in transit. A terminal master key (TMK) is generated for each terminal, split into two halves and printed (or sometimes encoded on a special magnetic card). Each TMK is then installed at their respective ATM's. The host system will then download terminal working keys, enciphered under the respective terminal master key, to each ATM. The terminal working key is then used to encipher PIN data in transit to the host during normal processing. If required, the terminal working key can be changed at regular intervals or through dynamic key exchange - but this process requires careful management.
It should be noted that the biggest single security exposure to DES based cryptographic subsystems is in the exchange of keys, thus good key management procedures are paramount.
Physical implementation
Cryptographic processing and key management is normally performed in specialised, dedicated secure hardware. Although DES can be implemented entirely in software (using products such as IBM's PCF), it is less secure, and the DES algorithm can be quite processor intensive.
There are companies that specialise in dedicated cryptographic units, such as Racal and Atalla. They are commonly called HSM's (Host Security Module) although this is the Racal proprietary name for the unit.
When using these devices, the intent is that all encipher and decipher activity takes place in the secure unit, and that clear keys and cleartext values are never exposed outside the unit.
Physically, HSM's are tamper proof and intended for installation in secure computer rooms. Attempts to open them will result in the destruction of keys contained in the devices.
HSM's are also capable of generating new random keys and random numbers for use as PIN's in a secure manner.
Some applications use physical telecommunications line encryption for added security, and there are a variety of manufacturers of this type of device. They are effectively 'black box' and require no special knowledge.

Examples
Cryptography in a normal ATM withdrawal
Consider a common ATM transaction:
A customer inserts his card in the ATM
The customer enters his PIN
The customer requests cash
The transaction is approved, cash is dispensed
There's an awful lot of cryptography going on in this process. For simplicity, we'll assume the acquiring and issuing bank are the same.
The cryptography activity is identified in italics in the sequence:
1. A customer inserts his card in the ATM
The magnetic stripe is read and stored in a buffer in the ATM
2. The customer enters his PIN
The PIN is entered into a tamper-proof PIN pad The stored PIN is stored in a security module in hardware
3. The customer requests cash
The message is constructed in the ATM The PIN (and possibly more) is enciphered under the Terminal key
The message is sent to the host, possibly enciphered in comms hardware.
On receipt at the host, the comms level encryption is deciphered The CVV is calculated and compared to the value on the magstripe The PIN under the Terminal key is deciphered The PIN offset or PVV is calculated The PIN offset or PVV is compared to the database of PVV's
4. The transaction is approved, cash is dispensed
Note: all the host cryptography functions are normally performed in the Host Security module. No Cleartext values are exposed to application programs or outside the secure environment.
Cryptography in an EFTPoS transaction
Even in a signature authorised environment, the CVV from the magnetic stripe can be validated at the host system to detect counterfeit cards. Clearly this only works in online environments as the CVV validation requires a cryptographic calculation to be performed at the host.
[Note: It is possible, and some manufacturers support, local key storage on EFTPoS devices and distributed terminals. Because of the key management complications, these devices are not considered here]
A more common use of cryptography in EFTPoS environments (and, increasingly in ATM and other traffic) is the MAC (Message Authentication Code). The MAC check can be thought of as a value calculated from the contents of all the critical fields in a message (such as card number and amount) and passed through a cryptographic algorithm. Although the message is carried over transmission lines in clear, the validation of the MAC field at the recipient will determine whether fields have been tampered with. [for the technically minded, MAC can be thought of as an encrypted LRC field]. The overhead of MAC is quite small. (The MAC is defined as 16 bytes in ISO8583).
Other financial cryptography applications
As well as traditional uses of cryptography as described above, interbank networks (such as SWIFT) have historically been large users of cryptographic techniques.
A plethora of new delivery mechanisms and far wider distribution of advanced technology to the public has increased both the interest in and the use of cryptographic techniques.
In cases where cryptography is required for widespread dissemination to the public (such as PC based home banking) ordinary DES is too complex to manage securely. More appropriate and more secure algorithms such as RSA (A "public key" encryption system) have evolved and been deployed in these environments - they are outside the scope of this paper but review of public key algorithms is especially encouraged where appropriate.
Some corporate, EDI and treasury applications use highly secure DES with a combination of techniques - MAC, physical encryption, dynamic key exchange, smart card key storage and so on. In one implementation reviewed, the working key is changed every transaction by the result of a MAC key calculation residue (a so-called "one time" key system).