Contactless Payments with Mobile Wallets. Overview and Technology

Size: px
Start display at page:

Download "Contactless Payments with Mobile Wallets. Overview and Technology"

Transcription

1 Contactless Payments with Mobile Wallets Overview and Technology

2

3 History of Contactless Systems Upass (smartcard) a pre-paid card for the transportation system in Seoul and its suburbs, first used in June Octopus Card (smartcard) a rechargeable contactless stored value smart card for making electronic payments in online or offline systems in Hong Kong. Launched in September 1997 to collect fares for the territory's mass transit system, the Octopus card system is the second contactless smart card system in the world, after Upass, and has since grown into a widely used payment system for all public transport in Hong Kong. The Octopus card was introduced for fare payment on the MTR initially, but the use of the card quickly expanded to other retail businesses in Hong Kong. The card is now commonly used in most, if not all, major public transport, fast food restaurants, supermarkets, vending machines, convenient stores, photo booths, parking meters, car parks and many other retails business where small payment are frequently made by customers.

4 History of Contactless Systems Mobile Speedpass (keytag) Introduced in 1997, It was originally developed by Verifone. At one point, Speedpass was deployed experimentally in fast-food restaurants and supermarkets in select markets. McDonald's alone deployed Speedpass in over 400 Chicago area restaurants. Additionally, Stop & Shop grocery chain tested Speedpass at their Boston area stores, but removed the units in early The test was deemed a failure and McDonald's removed the scanners from all their restaurants in mid 2004.

5 Current Contactless Credit Cards Credit card companies launched contactless credit cards in Other form factors were also available, including miniature keyring credit cards and key tags (similar to Mobile SpeedPass). Contactless runs over the same chip and PIN network as normal credit and debit card transactions, there is a payment limit on single transactions and contactless cards can only be used a certain number of times before customers are asked for their PIN. Contactless debit and credit transactions are protected by the same fraud guarantee as standard transactions. All use of the contactless cards are based on the merchant hardware.

6 Contactless Credit Card Types Contactless MSD (magnetic swipe data) Contactless MSD cards are similar to magnetic stripe cards in terms of the data they share across the contactless interface. They are only distributed in the USA. Payment occurs in a similar fashion to magstripe, without a PIN and often in off-line mode (depending on parameters of the terminal). The security level of such a transaction is better than a mag-stripe card, as the chip cryptographically generates a code which can be verified by the card issuer's systems.

7 Contactless Credit Card Types Contactless EMV (Europay Mastercard Visa) Contactless EMV cards have two interfaces (contact and contactless) and work as a normal EMV card via their contact interface. The contactless interface (a small chip embedded in the card, similar to current PIV/CAC) provides similar data to a contact EMV transaction, but usually a subset of the capabilities (e.g. usually issuers will not allow balances to be increased via the contactless interface, instead requiring the card to be inserted into a device which uses the contact interface). EMV cards may carry an "offline balance" stored in their chip, similar to the electronic wallet or purse that users of transit smartcards are used to.

8 Merchant Side American Express ExpressPay (introduced in 2005) MasterCard PayPass (introduced in 2005) Visa paywave (introduced in 2007) Discover Zip

9 Standards for Contactless Smartcards ISO/IEC Identification cards -- Contactless integrated circuit cards -- Proximity cards ISO/IEC :2008 Part 1: Physical characteristics ISO/IEC :2010 Part 2: Radio frequency power and signal interface ISO/IEC :2011 Part 3: Initialization and anticollision ISO/IEC :2008 Part 4: Transmission protocol

10 Technology

11 Wi-Fi Wi-Fi: Already dominated for internet usage, Wi-fi s responsibilities are now beginning to include mobile payments over the internet. Information that would be be communicated would include any information that may be stored for convenience. Passwords Credit/Debit Cards Locations

12 Wi-Fi Wi-Fi Encryption/Authentication has been in place for years. In this case, Over Wi-Fi, the passed data can include: Location Information Financial Information Billing Address Credit Card Information Transaction Information (What was purchased, How Much? Etc.) What was purchased? Item Prices as well as purchase methods (Cards/Gift Cards)

13 Near Field Technology NFC enables devices to share information at a distance less than 4 centimeters with a maximum communication speed of 424kbps. Users can share business cards, make transactions, access information from smart posters or provide credentials for access control systems with a simple touch. NFC s bidirectional communication ability can establish connections with other technologies. NFC is prominent in newer Android Phones and is used because of the ease of use and battery performance compared to Bluetooth.

14 NFC Vulnerabilities NFC itself is not encrypted in any way. Eavesdropping is a possibility, as the transmission occurs over regular RF waves. With the appropriate knowledge and equipment one could eavesdrop on the information being transmitted. NFC signals can also be modified through Man-in-the-Middle attacks in which a nearby device can potentially intercept and change values of the transmission to which the recipient unknowingly accepts the modified information.

15 NFC Players (Hardware) Feature Phones: Samsung Galaxy S3/S4 Samsung Galaxy Note 1/2 Motorola Razr Maxx HD Nexus 4 Windows Phone LG Optimus G Smartphones: Acer, Blackberry, HTC, LG, Motorola, Nexus, Nokia, Samsung, Sony

16 NFC Players (Operating Systems) Android Blackberry OS Windows Phone/8 Symbian Bada(Samsung s Native OS) Nokia OS

17 NFC Players (Customer-side Wallet Applications) Square Wallet (Square, Inc.) Google Wallet (Google, Inc.) ISIS Mobile Wallet (Mobile Carriers)

18 The Secure Element Payment card or other information is encrypted and stored on the Secure Element, which is a dedicated hardware component that operates independently from the rest of the phone and limits access to certain apps. There are three types of Secure Elements, described below.

19 The Secure Element Embedded Secure Elements (Universal Integrated Circuit Card) This type of element is built into the phone at the time of manufacture. Pros: Provides a common architecture for application developers More tamper resistant Less costly Cons: Not portable between phones

20 The Secure Element Secure Element Within the SIM Pros: Relatively secure, can link SIM serial numbers to individuals or devices Portable between phones Can be managed over the air to wipe if the device is lost/stolen Cons: Carriers own the SIM, and can control which third party they grant access to (Verizon is currently not allowing Google access, so Google Wallet is not available to Verizon customers)

21 The Secure Element Secure Element Within a MicroSD Card Pros: The microsd can be issued by a financial institution or mobile network operator as a credit, debit, prepaid or a multiple account digital wallet or for secure access and entry. Simple implementation Portable Cons: Portable Physical characteristics of the device can be limiting; physical location, antenna size, casing material, protective covers MicroSD can only support a single application or payment account Lack of standardizations between MicroSD and NFC Controller may be an issue

22 Current Applications

23 Square Wallet Square Wallet works with merchants that use Square Register Uses NFC for enabled phones, and QR codes for the register to scan for non-nfc enabled phones. Compatible with Apple devices running ios 5 and up, and Android devices running Android 2.2 and up. Users must check-in through the app, their photos appear on the merchant side application. The merchant clicks on the matching photo, scans the QR code or swipes the NFC phone, and payment is made.

24 Square Wallet Security Features Card processing applications adhere to PCI Data Security Standard (PCI-DSS) Level 1. Square prohibits the storage of card numbers, magnetic stripe data and security codes on client devices. Square requires sensitive data to be encrypted using industry-standard methods when stored on disk or transmitted over public networks.

25 Square Wallet In this instance, Square Wallet, a mobile Wallet alternative from Square uses Wi-Fi to to record the transactions being made. In this case, some of the data transfers can show up within monitoring programs In this case however, Square has ensured that this information is encrypted.

26 Google Wallet Requires NFC for in-store purchases When setting up credit or debit cards in the Google Wallet mobile app, a virtual prepaid MasterCard card will be issued by Bancorp. When paying in-store by tapping the phone, Google Wallet passes the virtual card to the merchant for payment, and charges the selected credit or debit card for the purchase. Credit or debit cards are linked to the Google Wallet account, which in turn is connected to your virtual prepaid MasterCard card. The virtual prepaid MasterCard information is stored on the phones Secure Element, no actual card information is on the device. Verizon is currently not licensing secure element space to Google, so this app is not available to Verizon users.

27 Google Wallet

28 Google Wallet Security Features Google Wallet PIN (in addition to the phone s lock screen) Remote control disables the device from being used Credit card numbers are stored on Google encrypted servers, only the virtual account information is stored on the device Does not share actual credit card number with merchants, only passes the virtual MasterCard number Google Wallet does not work on rooted phones

29 ISIS Mobile Wallet Developed as a joint venture between AT&T, Verizon, and T-Mobile, currently in testing in Texas and Utah. Requires NFC SIM (different than regular SIM), available from the mobile carriers in the test cities. Uses the four big credit card contactless systems (MC PayPass, Visa Paywave, AmEx ExpressPay, Discover Zip). Currently only supports Capitol One, Chase and AmEx, and the credit card company has to approve the request.

30 ISIS Mobile Wallet Security Features Payment card credentials are stored in the secure element. The Wallet is accessed by a user-selected PIN, adding another layer of protection. A single call to your wireless carrier or visit to our website can freeze the wallet, disabling payment cards within the Wallet.

31 Security

32 Access Barriers In most cases applications and even phones have their usual safeguards against theft however, additional security includes: Forcing users to enter CCV values for every transaction in which a card is used. Once Credit Cards have been entered, information is then hidden. Many e-wallet applications such as Square and Passbook can store login sessions, this allows the application to be accessed again, without a secure login.

33 Access Barriers Two-Factor Authentication can be provided in which a password, as well as randomly generated code from another source must be provided in succession in order to log into some systems. In some applications, all transactions and accounts are monitored and audited in order to prevent stolen information. With obvious theft in which mobile wallet applications without access barriers can be used to make purchases just like a regular credit card/ cash.

34 Who is Storing What Where? For both ios and Android, applications share these qualities: All application information is stored within a relevant folder containing the application itself as well as relevant information regarding the application. This includes all stored variables such as user names, passcodes. Additionally, on certain poorly written applications credit cards, magnetic strip info, pins, and security codes can be saved onto the device. Additionally, potential business transactions can be saved onto the device, including detail transactions as well as businesses

35 Security - Apple Devices In this case, most all applications rely upon the hardware encryption provided by the device. Since ios 3, the iphone has implemented hardware encryption Apple s Hardware Encryption is currently 256-bit AES encryption. Apple Devices do not allow installation of 3 rd party applications onto the device. Apple prohibits the use of File Browsers and user root access. Only through jail breaking is this possible.

36 Security - Android Devices In this case, most all applications rely upon the hardware encryption provided by the device. Due to the multitude of hardware, Android devices have varying encryption. Android versions up until Version 3 did not include encryption. Android key s are not stored into the hardware of the device, therefor they can be extracted. Android key s are not stored into the hardware of the device, therefor they can be extracted. Android does posses the ability to have a full-disk encryption, if required. Malware-ridden 3 rd -Party applications can exist on various Application Markets

37 Encryption - Transmission For most Wallet and Payment Apps there are various transmission protocols that are used for transmission. Protocols include: (Minimum) 128 bit SSL PGP (Pretty Good Privacy) Encryption From this, Wi-Fi Security comes into play, which depends on the security of your network. NFC transmissions contain no encryption and as a result can immediately be monitored by outside clients Physical Card Readers often perform data encryption the moment the card has been read.

38 Jailbreak/Root Vulnerabilities As of February 6 th, 2013 the recent Evasi0n jailbreak, at has jailbroken at least 9,838,098 devices on the latest ios for iphone (6.1.2). When a device is jailbroken, this brings additional causes for concern. When a device is jailbroken/rooted, a device can access the file system, as well as valuable information over Wi-Fi. In most cases an attacker can simply SSH into the iphone as the credentials are rarely changed. Source -

39 Jailbreak/Root Vulnerabilities Once a device is jailbroken/ Rooted, additional access to files is allowed. In this case, we can see the location of Payment Histories, as well as the application itself.

40 Jailbreak/Root Vulnerabilities Additionally, applications can be decrypted and show the code used to create the application. In this case, tools were used to decrypt and gather Objective-C and arm code of Square Wallet. This technique however can work with any ios application.

41 Jailbreak/Root Vulnerabilities Here is the same process, however this time, the program has been extracted into ARM Code

42 About PaRaBaL PaRaBaL, Inc. founded in 2009 is located in the University of Maryland, Baltimore County (UMBC) Research Park in Catonsville, MD. In early 2011 PaRaBaL was awarded a contract from a US Government Agency to develop and teach an ios security specialist training course, making PaRaBaL the first company to be awarded a US Government ios security training contract. PaRaBaL has gone on to expand its expertise in the field of mobile security to cover Android security training, mobile application development and mobile device management. With this pedigree, PaRaBaL is uniquely suited to take on tough research tasks in computer related cyber activities.

Mobile Near-Field Communications (NFC) Payments

Mobile Near-Field Communications (NFC) Payments Mobile Near-Field Communications (NFC) Payments OCTOBER 2013 GENERAL INFORMATION American Express continues to develop its infrastructure and capabilities to support growing market interest in mobile payments

More information

THE APPEAL FOR CONTACTLESS PAYMENT 3 AVAILABLE CONTACTLESS TECHNOLOGIES 3 USING ISO 14443 BASED TECHNOLOGY FOR PAYMENT 4

THE APPEAL FOR CONTACTLESS PAYMENT 3 AVAILABLE CONTACTLESS TECHNOLOGIES 3 USING ISO 14443 BASED TECHNOLOGY FOR PAYMENT 4 CONTACTLESS THE APPEAL FOR CONTACTLESS 3 AVAILABLE CONTACTLESS TECHNOLOGIES 3 USING ISO 14443 BASED TECHNOLOGY FOR 4 DESIGNING AN EMV LIKE CONTACTLESS SYSTEM 5 INGENICO, LEADER IN CONTACTLESS TECHNOLOGY

More information

permitting close proximity communication between devices in this case a phone and a terminal.

permitting close proximity communication between devices in this case a phone and a terminal. MOBILE PAYMENT What it is. How it works. What it means for Canadians. By EnStream LP for the House of Commons Finance Committee February 13, 2014 INTRODUCTION EnStream was established by Bell, Rogers and

More information

EMV and Restaurants: What you need to know. Mike English. October 2014. Executive Director, Product Development Heartland Payment Systems

EMV and Restaurants: What you need to know. Mike English. October 2014. Executive Director, Product Development Heartland Payment Systems October 2014 EMV and Restaurants: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks, service marks

More information

The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses. National Computer Corporation www.nccusa.com

The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses. National Computer Corporation www.nccusa.com The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses The Impact of Emerging Payment Technologies on Retail and Hospitality Businesses Making the customer payment process convenient,

More information

RF-Enabled Applications and Technology: Comparing and Contrasting RFID and RF-Enabled Smart Cards

RF-Enabled Applications and Technology: Comparing and Contrasting RFID and RF-Enabled Smart Cards RF-Enabled Applications and Technology: Comparing and Contrasting RFID and RF-Enabled Smart Cards January 2007 Developed by: Smart Card Alliance Identity Council RF-Enabled Applications and Technology:

More information

EMV and Small Merchants:

EMV and Small Merchants: September 2014 EMV and Small Merchants: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks, service

More information

American Express Contactless Payments

American Express Contactless Payments PRODUCT CAPABILITY GUIDE American Express Contactless Payments American Express Contactless Payments Help Enable Increased Convenience For Card Members At The Point Of Sale American Express contactless

More information

NACCU 2013. Migrating to Contactless: 2013 1

NACCU 2013. Migrating to Contactless: 2013 1 NACCU 2013 Migrating to Contactless: 2013 1 AGENDA The demise of cards has been predicted for many years. When will this really happen? This presentation by two card industry experts will cover the rise

More information

Mobile Payments Primer

Mobile Payments Primer Mobile Payments Primer February 13 th, 2014 Outline 1 Definitions 2 Introduction to Mobile Payments 3 Near Field Communication and Payment Methods 4 Non-NFC Payment Methods 4 Security 5 Mobile Payments

More information

How Secure are Contactless Payment Systems?

How Secure are Contactless Payment Systems? SESSION ID: HT-W01 How Secure are Contactless Payment Systems? Matthew Ngu Engineering Manager RSA, The Security Division of EMC Chris Scott Senior Software Engineer RSA, The Security Division of EMC 2

More information

EMERGING PAYMENT PRODUCTS AND PAYMENT SYSTEMS

EMERGING PAYMENT PRODUCTS AND PAYMENT SYSTEMS EMERGING PAYMENT PRODUCTS AND PAYMENT SYSTEMS 26th Annual Payment Card Institute May 3-4, 2012 Arlington, VA Wanji J. Walcott Managing Counsel Enterprise Growth Group American Express Andrew J. Lorentz

More information

Inside the Mobile Wallet: What It Means for Merchants and Card Issuers

Inside the Mobile Wallet: What It Means for Merchants and Card Issuers Inside the Mobile Wallet: What It Means for Merchants and Card Issuers Welcome to the age of Universal Commerce commerce that is integrated, personalized, secure, open, and smart. The lines between in-store

More information

Mobile Electronic Payments

Mobile Electronic Payments Chapter 7 Mobile Electronic Payments 7.1 Rationale and Motivation Mobile electronic payments are rapidly becoming a reality. There is no doubt that users of mobile phones are willing and even asking to

More information

Evolving Mobile Payments Industry Landscape

Evolving Mobile Payments Industry Landscape Evolving Mobile Payments Industry Landscape Mobile Banking: Can the Unbanked Bank on It? Sargent Shriver National Center on Poverty Law webinar August 16, 2012 Marianne Crowe Federal Reserve Bank of Boston

More information

Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER

Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER Emerging Trends in the Payment Ecosystem: The Good, the Bad and the Ugly DAN KRAMER SHAZAM, Senior Vice President Agenda The Ugly Fraud The Bad EMV? The Good Tokenization and Other Emerging Payment Options

More information

Latest and Future development of Mobile Payment in Hong Kong

Latest and Future development of Mobile Payment in Hong Kong Latest and Future development of Mobile Payment in Hong Kong About oti Founded in 1990 (NASDAQ: OTIV). Offices in US, Europe, Africa, Asia Global provider of cashless payment solutions Experts in secured

More information

A Brand New Checkout Experience

A Brand New Checkout Experience A Brand New Checkout Experience EMV Transformation EMV technology is transforming the U.S. payment industry, bringing a whole new experience to the checkout counter. Introduction What is EMV? It s 3 small

More information

A Brand New Checkout Experience

A Brand New Checkout Experience A Brand New Checkout Experience EMV Transformation EMV technology is transforming the U.S. payment industry, bringing a whole new experience to the checkout counter. Introduction What is EMV? It s 3 small

More information

Android pay. Frequently asked questions

Android pay. Frequently asked questions Android pay Frequently asked questions June 2015 Android Pay - FAQs In May 2015, Android Pay was announced by Google. Android Pay is Google s payments solution that allows consumers to do in-store and

More information

MCX/CURRENTC. This payment app will be unique from other mobile payments options in that it is not device specific. Consumers

MCX/CURRENTC. This payment app will be unique from other mobile payments options in that it is not device specific. Consumers Payment Services WHITE PAPER MOBILE PAYMENTS TECHNOLOGY Intelligent solutions to connect with your members. THE HISTORY OF MOBILE As mobile devices have permeated the marketplace, developers have focused

More information

General information about NFC technology

General information about NFC technology General information about NFC technology What is NFC? How does it work? What is a tap? What is link between NFC technology and Tapit? NFC stands for Near Field Communication. This is a short range wireless

More information

Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked Questions. July, 2006. Developed by: Smart Card Alliance Identity Council

Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked Questions. July, 2006. Developed by: Smart Card Alliance Identity Council Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked Questions July, 2006 Developed by: Smart Card Alliance Identity Council Contactless Smart Cards vs. EPC Gen 2 RFID Tags: Frequently Asked

More information

How to connect your D210 using Bluetooth. How to connect your D210 using GPRS (SIM Card)

How to connect your D210 using Bluetooth. How to connect your D210 using GPRS (SIM Card) D210 En User Guide Content 3 Introduction 3 Scope 3 Related Documentation 4 Internet Connectivity 4 Using D210 with Mobile Phone 5 Using D210 with wireless (Wi-Fi) router 6 Using D210 with GPRS (requires

More information

NFC Hacking: The Easy Way

NFC Hacking: The Easy Way DEFCON 20 NFC Hacking: The Easy Way Eddie Lee eddie{at}blackwinghq.com About Me! Security Researcher for Blackwing Intelligence (formerly Praetorian Global)! New site live: blackwinghq.com! We re always

More information

Spring Hill State Bank Mobile Banking FAQs

Spring Hill State Bank Mobile Banking FAQs Spring Hill State Bank Mobile Banking FAQs What is Mobile Banking? Mobile Banking enables you to access your account information using the Bank online banking website. You must first be enrolled as an

More information

NFC Hacking: The Easy Way

NFC Hacking: The Easy Way DEFCON 20 NFC Hacking: The Easy Way Eddie Lee eddie{at}blackwinghq.com About Me! Security Researcher for Blackwing Intelligence (formerly Praetorian Global)! We re always looking for cool security projects!

More information

Credit Card Processing Overview

Credit Card Processing Overview CardControl 3.0 Credit Card Processing Overview Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new

More information

The State of Pay. A mobile revolution. semble.co.nz

The State of Pay. A mobile revolution. semble.co.nz The State of Pay A mobile revolution semble.co.nz 2 November 2015 2 Overview The introduction of the mobile wallet represents the most significant evolution in payments for New Zealand since the Eftpos

More information

Preparing for EMV chip card acceptance

Preparing for EMV chip card acceptance Preparing for EMV chip card acceptance Ben Brown Vice President, Regional Sales Manager, Wells Fargo Merchant Services Lily Page Vice President, Wholesale ereceivables, Wells Fargo Merchant Services June

More information

How to connect your D200 using Bluetooth. How to connect your D200 using GPRS (SIM Card)

How to connect your D200 using Bluetooth. How to connect your D200 using GPRS (SIM Card) D200 En User Guide Content 3 Introduction 3 Scope 3 Related Documentation 4 Internet Connectivity 4 Using D200 with Mobile Phone 5 Using D200 with wireless (Wi-Fi) router 6 Using D200 with GPRS (requires

More information

CardControl. Credit Card Processing 101. Overview. Contents

CardControl. Credit Card Processing 101. Overview. Contents CardControl Credit Card Processing 101 Overview Credit card processing is a very complex and important system for anyone that sells goods. This guide will hopefully help educate and inform new and old

More information

welcome to liber8:payment

welcome to liber8:payment liber8:payment welcome to liber8:payment Our self-service kiosks free up staff time and improve the overall patron experience. liber8:payment further enhances these benefits by providing the convenience

More information

Mobile Payment: The next step of secure payment VDI / VDE-Colloquium. Hans-Jörg Frey Senior Product Manager May 16th, 2013

Mobile Payment: The next step of secure payment VDI / VDE-Colloquium. Hans-Jörg Frey Senior Product Manager May 16th, 2013 Mobile Payment: The next step of secure payment VDI / VDE-Colloquium May 16th, 2013 G&D has been growing through continuous innovation Server software and services Token and embedded security Cards for

More information

Bringing Mobile Payments to Market for an International Retailer

Bringing Mobile Payments to Market for an International Retailer Bringing Mobile Payments to Market for an International Retailer Founded in 2011, Clearbridge Mobile has emerged as a world class studio developing state of the art wearable and mobile wallet / payment

More information

mpos Solution A: Visa, MasterCard and JCB are supported. Both Debit & Credit Cards which is supported by any of this Card Type can be accepted.

mpos Solution A: Visa, MasterCard and JCB are supported. Both Debit & Credit Cards which is supported by any of this Card Type can be accepted. mpos Solution GENERAL Q1: What is mpos Solution? A: mpos Solution is an innovative payment solution that turns a smartphone or tablet into a secure mobile card payment acceptance device. It consists of:

More information

Frequently asked questions - Visa paywave

Frequently asked questions - Visa paywave Frequently asked questions - Visa paywave What is Visa paywave? Visa paywave is a new contactless method of payment - the latest evolution in Visa payments. It is a simple, secure and quick payment method

More information

Changing Consumer Purchasing Patterns. John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association

Changing Consumer Purchasing Patterns. John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association Changing Consumer Purchasing Patterns John Mayleben, CPP SVP, Technology and Product Development Michigan Retailers Association Michigan Retailers Association! Michigan Retailers Association is trade

More information

BGS MOBILE PLATFORM HCE AND CLOUD BASED PAYMENTS

BGS MOBILE PLATFORM HCE AND CLOUD BASED PAYMENTS HCE AND CLOUD BASED PAYMENTS 1 Contactless payments are vital for further development of the payment industry. More than 3 mln POS terminals around the globe can accept contactless payments. Mobile phones

More information

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP

THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP THE FIVE Ws OF EMV BY DAVE EWALD GLOBAL EMV CONSULTANT AND MANAGER DATACARD GROUP WHERE IS THE U.S. PAYMENT CARD INDUSTRY NOW? WHERE IS IT GOING? Today, payment and identification cards of all types (credit

More information

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means

EMV and Chip Cards Key Information On What This Is, How It Works and What It Means EMV and Chip Cards Key Information On What This Is, How It Works and What It Means Document Purpose This document is intended to provide information about the concepts behind and the processes involved

More information

CA ArcotOTP Versatile Authentication Solution for Mobile Phones

CA ArcotOTP Versatile Authentication Solution for Mobile Phones PRODUCT SHEET CA ArcotOTP CA ArcotOTP Versatile Authentication Solution for Mobile Phones Overview Consumers have embraced their mobile phones as more than just calling or texting devices. They are demanding

More information

Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011

Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011 Enhancing Payment Card Security New Measures to be Phased in from 2 nd Quarter 2010 to 1 st Quarter 2011 On 5 th March 2010, The Association of Banks in Singapore announced key measures to adopt a holistic

More information

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard

toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard toast EMV in 2015: How Restaurants Can Prepare for the New Chip-and-Pin Standard Table of Contents For more than 40 years, merchants and consumers have used magnetic stripe credit cards and compatible

More information

About Visa paywave for mobile

About Visa paywave for mobile F A C T S H E E T About Visa paywave for mobile Visa paywave is Visa s contactless payment technology that enables consumers to make wave and go payments at the shop counter using their payment cards,

More information

Beyond the Hype: Mobile Payments for Merchants

Beyond the Hype: Mobile Payments for Merchants Presented by the Mobile Payments Committee of the Electronic Transactions Association Beyond the Hype: Mobile Payments for Merchants Table of Contents Overview... 2 Before We Get Started... 3 Current Status

More information

OVERVIEW OF MOBILE PAYMENT LANDSCAPE

OVERVIEW OF MOBILE PAYMENT LANDSCAPE OVERVIEW OF MOBILE PAYMENT LANDSCAPE NEACH FORUM September 10, 2014 Marianne Crowe Federal Reserve Bank of Boston Disclaimer: The views expressed in this presentation are those of the presenter and do

More information

OVERVIEW OF MOBILE PAYMENT LANDSCAPE Marianne Crowe Federal Reserve Bank of Boston NEACH September 10, 2014

OVERVIEW OF MOBILE PAYMENT LANDSCAPE Marianne Crowe Federal Reserve Bank of Boston NEACH September 10, 2014 OVERVIEW OF MOBILE PAYMENT LANDSCAPE Marianne Crowe Federal Reserve Bank of Boston NEACH September 10, 2014 Disclaimer: The views expressed in this presentation are those of the presenter and do not necessarily

More information

PCI and EMV Compliance Checkup

PCI and EMV Compliance Checkup PCI and EMV Compliance Checkup ATM Security Jim Pettitt Director, ATM Security Diebold Incorporated Agenda ATM threats today Top of mind risk PCI Impact on Security U.S. EMV Migration Conclusions / recommendations

More information

Flexible and secure. acceo tender retail. payment solution. tender-retail.acceo.com

Flexible and secure. acceo tender retail. payment solution. tender-retail.acceo.com Flexible and secure payment solution acceo tender retail payment solution tender-retail.acceo.com Take control of your payment transactions ACCEO Tender Retail is a specialized middleware that handles

More information

Mobile Phone Technology: Smarter Than We Thought

Mobile Phone Technology: Smarter Than We Thought Mobile Phone Technology: Smarter Than We Thought How Technology Platforms are Securing Mobile Payments in the U.S. Marianne Crowe and Elisa Tavilla Federal Reserve Bank of Boston November 16, 2012 The

More information

Best Practices for the Use of RF-Enabled Technology in Identity Management. January 2007. Developed by: Smart Card Alliance Identity Council

Best Practices for the Use of RF-Enabled Technology in Identity Management. January 2007. Developed by: Smart Card Alliance Identity Council Best Practices for the Use of RF-Enabled Technology in Identity Management January 2007 Developed by: Smart Card Alliance Identity Council Best Practices for the Use of RF-Enabled Technology in Identity

More information

EESTEL. Association of European Experts in E-Transactions Systems. Apple iphone 6, Apple Pay, What else? EESTEL White Paper.

EESTEL. Association of European Experts in E-Transactions Systems. Apple iphone 6, Apple Pay, What else? EESTEL White Paper. EESTEL White Paper October 29, 2014 Apple iphone 6, Apple Pay, What else? On 2014, September 9 th, Apple has launched three major products: iphone 6, Apple Watch and Apple Pay. On October 17 th, Apple

More information

Mobile Payment Transactions: BLE and/or NFC? White paper by Swen van Klaarbergen, consultant for UL Transaction Security s Mobile Competence Center

Mobile Payment Transactions: BLE and/or NFC? White paper by Swen van Klaarbergen, consultant for UL Transaction Security s Mobile Competence Center Mobile Payment Transactions: BLE and/or NFC? White paper by Swen van Klaarbergen, consultant for UL Transaction Security s Mobile Competence Center Mobile Payment Transactions: BLE and/or NFC? About the

More information

The Future is Contactless

The Future is Contactless Contactless Implementation and Benefits The Future is Contactless One of the most exciting new applications to be launched in the payment world is contactless payment. The technology is already available

More information

Mobile Banking FAQ Page 1 of 9

Mobile Banking FAQ Page 1 of 9 Page 1 of 9 allows anyone with existing online banking access to see their account information from a mobile phone. can be Text Banking, Mobile Browser Banking or Smartphone App Banking. General Questions

More information

A MOBILE PAYMENT SYSTEM WITH AN EXTRA TOKEN OF SECURITY Nael Hirzallah 1 and Sana Nseir 2

A MOBILE PAYMENT SYSTEM WITH AN EXTRA TOKEN OF SECURITY Nael Hirzallah 1 and Sana Nseir 2 A MOBILE PAYMENT SYSTEM WITH AN EXTRA TOKEN OF SECURITY Nael Hirzallah 1 and Sana Nseir 2 1 Applied Science University, Amman, Jordan 2 Zarqa University, Zarqa, Jordan ABSTRACT: The number of people using

More information

SETUP GUIDE. Thank you for your purchase of Hamilton products! In this handy guide, you will discover: ADDITIONAL REQUIREMENTS SETUP HOW IT WORKS

SETUP GUIDE. Thank you for your purchase of Hamilton products! In this handy guide, you will discover: ADDITIONAL REQUIREMENTS SETUP HOW IT WORKS SETUP GUIDE High Speed Secure Credit Card Processing Thank you for your purchase of Hamilton products! In this handy guide, you will discover: WHAT IS INCLUDED ADDITIONAL REQUIREMENTS HOW IT WORKS SETUP

More information

Electronic Commerce and E-wallet

Electronic Commerce and E-wallet International Journal of Recent Research and Review, Vol. I, March 2012 Electronic Commerce and E-wallet Abhay Upadhayaya Department of ABST,University of Rajasthan,Jaipur, India Email: abhayu@rediffmail.com

More information

The Hang Seng Mobile Payment - FAQs

The Hang Seng Mobile Payment - FAQs The Hang Seng Mobile Payment - FAQs A. Introduction to the Service B. Application Requirements C. About the Passcode for the Hang Seng Mobile Payment App D. About Application / Download / Re-activation

More information

Secure your Privacy. www.jrsys.com.tw. jrsys, Inc. All rights reserved.

Secure your Privacy. www.jrsys.com.tw. jrsys, Inc. All rights reserved. Secure your Privacy www.jrsys.com.tw CNN 2013/7/16 8:25PM Man Middle In The I got your ID/Password! Mobile Secure Secure sensitive access data Random Login Web Authentication One Secure Time Channel Password

More information

What Merchants Need to Know About EMV

What Merchants Need to Know About EMV Effective November 1, 2014 1. What is EMV? EMV is the global standard for card present payment processing technology and it s coming to the U.S. EMV uses an embedded chip in the card that holds all the

More information

What is a Smart Card?

What is a Smart Card? An Introduction to Smart Cards and RFIDs Prof. Keith E. Mayes Keith.Mayes@rhul.ac.uk Director of the ISG - Smart Card Centre www.scc.rhul.ac.uk Learning Objectives (MSc MSc) Identify the various types

More information

INTRODUCTION AND HISTORY

INTRODUCTION AND HISTORY INTRODUCTION AND HISTORY EMV is actually younger than we all may think as it only became available, as a specification that could be implemented, in 1996. The evolution of EMV can be seen in the development

More information

Hacking the NFC credit cards for fun and debit ;) Renaud Lifchitz BT renaud.lifchitz@bt.com Hackito Ergo Sum 2012 April 12,13,14 Paris, France

Hacking the NFC credit cards for fun and debit ;) Renaud Lifchitz BT renaud.lifchitz@bt.com Hackito Ergo Sum 2012 April 12,13,14 Paris, France Hacking the NFC credit cards for fun and debit ;) Renaud Lifchitz BT renaud.lifchitz@bt.com Hackito Ergo Sum 2012 April 12,13,14 Paris, France Speaker's bio French computer security engineer working at

More information

Apple Pay. Frequently Asked Questions UK Launch

Apple Pay. Frequently Asked Questions UK Launch Apple Pay Frequently Asked Questions UK Launch Version 1.0 2015 First Data Corporation. All Rights Reserved. All trademarks, service marks and trade names referenced in this material are the property of

More information

Contactless Payments. Björn Salomon-Sörensen, Account Director - Swedbank November 11, 2015

Contactless Payments. Björn Salomon-Sörensen, Account Director - Swedbank November 11, 2015 Contactless Payments Björn Salomon-Sörensen, Account Director - Swedbank CONTACTLESS BASICS AND BENEFITS What s Inside MasterCard Contactless? Similar to a standard MasterCard card with some differences.

More information

MPIW Security Workgroup Initiative Progress to Date and Current Status

MPIW Security Workgroup Initiative Progress to Date and Current Status MPIW Security Workgroup Initiative Progress to Date and Current Status Susan Pandy, Federal Reserve Bank of Boston May 1, 2014 Susan Pandy is a Director in the Payments Strategies Group at the Federal

More information

A Guide to EMV. Version 1.0 May 2011. Copyright 2011 EMVCo, LLC. All rights reserved.

A Guide to EMV. Version 1.0 May 2011. Copyright 2011 EMVCo, LLC. All rights reserved. A Guide to EMV Version 1.0 May 2011 Objective Provide an overview of the EMV specifications and processes What is EMV? Why EMV? Position EMV in the context of the wider payments industry Define the role

More information

Key Topics in Mobile Payments. Marianne Crowe Federal Reserve Bank of Boston m-enabling Summit June 10, 2014

Key Topics in Mobile Payments. Marianne Crowe Federal Reserve Bank of Boston m-enabling Summit June 10, 2014 Key Topics in Mobile Payments Marianne Crowe Federal Reserve Bank of Boston m-enabling Summit June 10, 2014 Agenda Overview of mobile payments landscape Role of Federal Reserve Mobile Payments Industry

More information

Mobile NFC 101. Presenter: Nick von Dadelszen Date: 31st August 2012 Company: Lateral Security (IT) Services Limited

Mobile NFC 101. Presenter: Nick von Dadelszen Date: 31st August 2012 Company: Lateral Security (IT) Services Limited Mobile NFC 101 Presenter: Nick von Dadelszen Date: 31st August 2012 Company: Lateral Security (IT) Services Limited Company Lateral Security (IT) Services Limited Company Overview Founded in April 2008

More information

U.S. Bank. U.S. Bank Chip Card FAQs for Program Administrators. In this guide you will find: Explaining Chip Card Technology (EMV)

U.S. Bank. U.S. Bank Chip Card FAQs for Program Administrators. In this guide you will find: Explaining Chip Card Technology (EMV) U.S. Bank U.S. Bank Chip Card FAQs for Program Administrators Here are some frequently asked questions Program Administrators have about the replacement of U.S. Bank commercial cards with new chip-enabled

More information

EMV in Hotels Observations and Considerations

EMV in Hotels Observations and Considerations EMV in Hotels Observations and Considerations Just in: EMV in the Mail Customer Education: Credit Card companies have already started customer training for the new smart cards. 1 Questions to be Answered

More information

A Guide to Contactless Cards

A Guide to Contactless Cards A Guide to Contactless Cards 1 Guide to Contactless Cards Ever since they were first introduced to the UK market over 50 years ago, credit cards have been in a constant state of evolution, as card issuers

More information

MiniPOS and BluePad-50 user manual

MiniPOS and BluePad-50 user manual MiniPOS and BluePad-50 user manual Welcome to MiniPOS application for mobile and card payments! +386 (30) 70 4444 +386 (30) 70 5555 sales@intech.si www.paywiser.si Slovenska ulica 54 Ljubljana, Slovenija

More information

Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement"

Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement !!!! Stronger(Security(and( Mobile'Payments'! Dramatically*Faster!and$ Cheaper'to'Implement" Here$is$a$simple,$cost$effective$way$to$achieve$transaction$security$for$ mobile$payments$that$allows$easy$and$secure$provisioning$of$cards.$

More information

FOR A BARRIER-FREE PAYMENT PROCESSING SOLUTION

FOR A BARRIER-FREE PAYMENT PROCESSING SOLUTION FOR A BARRIER-FREE PAYMENT PROCESSING SOLUTION MAKE THE SWITCH TO MONEXgroup ecommerce I Mobile I Wireless I Integrated I Countertop Solutions IN-STORE ON-THE-GO ONLINE Accept secure debit and credit card

More information

The What, Who and Why of Contactless Payments

The What, Who and Why of Contactless Payments The What, Who and Why of Contactless Payments Introduction The mass market introduction of contactless technology is an important event for the payments industry. Contactless payments are already providing

More information

Euronet s Contactless Solution

Euronet s Contactless Solution Serving millions of people worldwide with electronic payment convenience. Euronet s Contactless Solution Fast, Secure and Convenient Transactions with No Swiping, PIN or Signature Copyright 2011 Euronet

More information

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note

BlackBerry Enterprise Service 10. Secure Work Space for ios and Android Version: 10.1.1. Security Note BlackBerry Enterprise Service 10 Secure Work Space for ios and Android Version: 10.1.1 Security Note Published: 2013-06-21 SWD-20130621110651069 Contents 1 About this guide...4 2 What is BlackBerry Enterprise

More information

Global Mobile Technologies Guide for Zenprise Enrollment for IOS devices (ipad, iphones)

Global Mobile Technologies Guide for Zenprise Enrollment for IOS devices (ipad, iphones) Global Mobile Technologies Guide for Zenprise Enrollment for IOS devices (ipad, iphones) As part of Sony Pictures commitment to enabling our workforce with the best technology and related tools available,

More information

Card Technology Choices for U.S. Issuers An EMV White Paper

Card Technology Choices for U.S. Issuers An EMV White Paper Card Technology Choices for U.S. Issuers An EMV White Paper This white paper is written with the aim of educating Issuers in the United States on the various technology choices that they have to consider

More information

Mobile Banking User Guide 2015

Mobile Banking User Guide 2015 Mobile Banking User Guide 2015 Page 1 Page 2 Mobile Banking Overview Mobile Banking enables anyone with an online banking account to access their account information from a mobile device. Mobile Banking

More information

EMV Frequently Asked Questions for Merchants May, 2014

EMV Frequently Asked Questions for Merchants May, 2014 EMV Frequently Asked Questions for Merchants May, 2014 Copyright 2014 Vantiv All rights reserved. Disclaimer The information in this document is offered on an as is basis, without warranty of any kind,

More information

Near Field Communication Tap and Fly

Near Field Communication Tap and Fly Near Field Communication Tap and Fly By Simon Mitchell +61 3 9653 914 info@matchbyte.com Level 18, 101 Collins Street Melbourne, VIC Australia 3000 Near Field Communication According to the International

More information

Chair: Russell Schrader, Visa, Inc., San Francisco, California Vice Chair: Veronica K. McGregor, Jones Day, San Francisco, California

Chair: Russell Schrader, Visa, Inc., San Francisco, California Vice Chair: Veronica K. McGregor, Jones Day, San Francisco, California American Bar Association Committee on Consumer Financial Services Electronic Banking and Internet Delivery Subcommittee Winter Meeting Park City, Utah January 7-10, 2012 ELECTRONIC BANKING AND INTERNET

More information

EMV : Frequently Asked Questions for Merchants

EMV : Frequently Asked Questions for Merchants EMV : Frequently Asked Questions for Merchants The information in this document is offered on an as is basis, without warranty of any kind, either expressed, implied or statutory, including but not limited

More information

THE ENTERPRISE MOBILITY POLICY GUIDEBOOK

THE ENTERPRISE MOBILITY POLICY GUIDEBOOK THE ENTERPRISE MOBILITY POLICY GUIDEBOOK October 2010 Edition 2 About This Guidebook Research from Strategy Analytics shows that over 90% of organizations now have employees using smartphones within their

More information

Mobile Applications and OpenTravel Specifications

Mobile Applications and OpenTravel Specifications Mobile Applications and OpenTravel Specifications A G E N D A Introductions Is the Mobile channel important? USER EXPERIENCE What is the next generation of mobile applications? How do Open Standards come

More information

Welcome to your CIBC Dividend Visa * Card

Welcome to your CIBC Dividend Visa * Card Welcome to your CIBC Dividend Visa * Card Turn your everyday spending into cash back rewards Get 2% cash back on all grocery purchases 1 Get started with your new cash back card 1. Activate your card Activate

More information

Payments Transformation - EMV comes to the US

Payments Transformation - EMV comes to the US Accenture Payment Services Payments Transformation - EMV comes to the US In 1993 Visa, MasterCard and Europay (EMV) came together and formed EMVCo 1 to tackle the global challenge of combatting fraudulent

More information

mobile payment acceptance Solutions Visa security best practices version 3.0

mobile payment acceptance Solutions Visa security best practices version 3.0 mobile payment acceptance Visa security best practices version 3.0 Visa Security Best Practices for, Version 3.0 Since Visa s first release of this best practices document in 2011, we have seen a rapid

More information

1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution?

1. What are the System Requirements for using the MaaS360 for Exchange ActiveSync solution? MaaS360 FAQs This guide is meant to help answer some of the initial frequently asked questions businesses ask as they try to figure out the who, what, when, why and how of managing their smartphone devices,

More information

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0

Security Guide. BlackBerry Enterprise Service 12. for ios, Android, and Windows Phone. Version 12.0 Security Guide BlackBerry Enterprise Service 12 for ios, Android, and Windows Phone Version 12.0 Published: 2015-02-06 SWD-20150206130210406 Contents About this guide... 6 What is BES12?... 7 Key features

More information

Recent Developments in Mobile Financial Services Solutions December 12, 2012

Recent Developments in Mobile Financial Services Solutions December 12, 2012 Recent Developments in Mobile Financial Services Solutions December 12, 2012 www.schnader.com 1 Introduction Mobile Financial Services Technology Issues Regulatory Issues www.schnader.com 2 Mobile Financial

More information

Apple Pay. Frequently Asked Questions UK

Apple Pay. Frequently Asked Questions UK Apple Pay Frequently Asked Questions UK Version 1.0 (July 2015) First Data Merchant Solutions is a trading name of First Data Europe Limited, a private limited company incorporated in England (company

More information

Using RFID Techniques for a Universal Identification Device

Using RFID Techniques for a Universal Identification Device Using RFID Techniques for a Universal Identification Device Roman Zharinov, Ulia Trifonova, Alexey Gorin Saint-Petersburg State University of Aerospace Instrumentation Saint-Petersburg, Russia {roman,

More information

EMV-TT. Now available on Android. White Paper by

EMV-TT. Now available on Android. White Paper by EMV-TT A virtualised payment system with the following benefits: MNO and TSM independence Full EMV terminal and backend compliance Scheme agnostic (MasterCard and VISA supported) Supports transactions

More information

Mobile MasterCard PayPass Testing and Approval Guide. December 2009 - Version 2.0

Mobile MasterCard PayPass Testing and Approval Guide. December 2009 - Version 2.0 Mobile MasterCard PayPass Testing and Approval Guide December 2009 - Version 2.0 Proprietary Rights Trademarks The information contained in this document is proprietary and confidential to MasterCard International

More information

Help us make this document better smarttech.com/docfeedback/170892. Security information

Help us make this document better smarttech.com/docfeedback/170892. Security information Help us make this document better smarttech.com/docfeedback/170892 Security information SMART kapp includes data security features designed to keep your content controlled in a predictable way. This document

More information