W3C Web Payment IG. Payment Service Providers. Alibaba Zephyr Tuan



Similar documents
more for your money NetPay for... Mobile App Developers

STRONGER AUTHENTICATION for CA SiteMinder

The Role of Identity Enabled Web Services in Cloud Computing

Key & Data Storage on Mobile Devices

SECURITY AND REGULATORY COMPLIANCE OVERVIEW

Latest and Future development of Mobile Payment in Hong Kong

nexus Hybrid Access Gateway

Meet The Family. Payment Security Standards

E-Commerce payment trends. Petr Polak Senior Sales Manager Czech Republic and Slovakia

THE BANK ACCOUNT AT THE HEART OF THE DIGITAL EXPERIENCE. MyBank for Service Providers

HOL9449 Access Management: Secure web, mobile and cloud access

PCI Security Standards Council

EBA STRONG AUTHENTICATION REQUIREMENTS

/ BROCHURE / CHECKLIST: PCI/ISO COMPLIANCE. By Melbourne IT Enterprise Services

How Secure is Authentication?

Virtual Client Solution: Desktop Virtualization

MECOMS Customer Care & Billing As A Service

A MERCHANTS GUIDE TO THE PAYMENT APPLICATION DATA SECURITY STANDARD (PA-DSS)

Microsoft Enterprise Mobility Suite

TOURISM INNOVATIVE PAYMENT SOLUTIONS. Efficient, flexible, worldwide and secure

Device-Centric Authentication and WebCrypto

Securing Internet Payments. The current regulatory state of play

CONTENTS. Abstract Need for Desktop Management What should typical Desktop Management Software do? Securing Desktops...

Software Enabled Creative Destruction. Jason Jackson, Field CTO, Pivotal

Out-of-Band Multi-Factor Authentication Cloud Services Whitepaper

Beyond passwords: Protect the mobile enterprise with smarter security solutions

TrustedX: eidas Platform

ADDING STRONGER AUTHENTICATION for VPN Access Control

Standardizing client-side API for Web payments? Author: Stéphane Boyera W3C 1

What a Processor Needs from a University to Validate Compliance

owncloud Architecture Overview

Implementing two-factor authentication: Google s experiences. Cem Paya (cemp@google.com) Information Security Team Google Inc.

Signicat white paper. Signicat Solutions. This document introduces the Signicat solutions for digital identities and electronic signatures

How Secure is Authentication?

Android pay. Frequently asked questions

Adding Stronger Authentication to your Portal and Cloud Apps

Guide to Evaluating Multi-Factor Authentication Solutions

Syllabus Windows Enterprise Desktop Deployment. Subject Description: Subject Hours: Performance Objectives: Prerequisites

Innovation with a difference

Power of Oracle in the Cloud

Federated single sign-on (SSO) and identity management. Secure mobile access. Social identity integration. Automated user provisioning.

A brief on Two-Factor Authentication

Bytemark Mobile Ticketing

Security and Compliance challenges in Mobile environment

TrustedX - PKI Authentication. Whitepaper

MOBILITY. Transforming the mobile device from a security liability into a business asset. pingidentity.com

To Build or Buy: Key Decision Points for Choosing the Best Billing Solution. Cloud Based Billing & Subscription Management Expert Series WHITEPAPER

Opinion piece. The mobile wallet already exists! It s called mobile banking. By Simon Cadbury Head of Strategy & Innovation Intelligent Environments

CA Service Desk Manager - Mobile Enabler 2.0

Microsoft Azure Multi-Factor authentication. (Concept Overview Part 1)

Securing Internet Payments across Europe. Guidelines for Detecting and Preventing Fraud

Enabling SSO for native applications

Magento at the Core of ecommerce. The Magento Experience. Magento Enables Success. The ecommerce Ecosystem. Supplemental Pages

the better way to pay

PCI Assessments 3.0 What Will the Future Bring? Matt Halbleib, SecurityMetrics

Office365 Adoption eguide. Identity and Mobility Challenges. Okta Inc. 301 Brannan Street San Francisco, CA

NCR CONNECTED PAYMENTS The vision for payment acceptance in restaurants

Payments Gateways Opportunities for Acquirers

Payment Card Industry (PCI) Data Security Standard. PCI DSS Applicability in an EMV Environment A Guidance Document Version 1

QR Code for Digital Signature Online/Offline Payment. James Wu 1

SECURITY AND REGULATORY COMPLIANCE OVERVIEW

Whitepaper on identity solutions for mobile devices

Payment Card Industry (PCI) Data Security Standard

Two-Factor Authentication over Mobile: Simplifying Security and Authentication

ACI SELF-SERVICE BANKING

Global Iris Integration Guide ecommerce Remote Integration

This is for informational purposes only. MICROSOFT MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS DOCUMENT.

Okta Identity Management for Portals Built on Salesforce.com. An Architecture Review. Okta Inc. 301 Brannan Street San Francisco, CA 94107

CA Single Sign-On Migration Guide

Mobile Financial Services Business Ecosystem Scenarios & Consequences. Summary Document. Edited By. Juha Risikko & Bishwajit Choudhary

How Safe are you in your Cloud?

ENZO UNIFIED SOLVES THE CHALLENGES OF REAL-TIME DATA INTEGRATION

TABLE OF CONTENTS. Introduction 3 OTP SMS Two-Factor Authentication 5 Technical Overview 9 Features 10 Benefits 11 About MobiWeb 12 Quality 13

WHITE PAPER. How to simplify and control the cardholder security environment

First Data E-commerce Payments Gateway

The Cloud, Mobile and BYOD Security Opportunity with SurePassID

THE EVOLUTION OF CARD PAYMENTS IN THE TOURISM SECTOR

Information Technology: This Year s Hot Issue - Cloud Computing

Samsung SDS. Enterprise Mobility Management

E-Commerce SOLUTIONS. Generate Online Revenue with E-Commerce Solutions.

Transcription:

W3C Web Payment IG Payment Service Providers Alibaba Zephyr Tuan

01 Internet Finance Ecosystem in China 02 Payment Service Provider Requirements 03 Open Questions

01 When Internet Meet Finance Internet Open Free Flowing Sharing Finance Rigorous Professional Risk Mgmt Security Supervise Creative Platform (Financing, Trading, Crowdfunding, etc.)

01 When Finance Meet Internet Daisy/Husband Shopping, I pay Children Shopping, I pay Transfer Pay for another 亲 密 付

01 What Internet Brings Us? Big Data Operation Cloud Computing Internet Risk Control Credit System

01 Data Operation Example: 10 years Bill of Alipay Diary of 10 years bill Today is my 3316 th day using Alipay My bill By Alipay, I have: Spend: 966,462.38 RMB Earn: 4,527.33 RMB My 5 aspects Payment: 10 scores Credit: great potential Financing: 9 scores Account Management: 9 scores Contacts: 10 scores

01 Internet Finance Ecosystem in China Ecosystem User Financial Merchant PSP Bank Supervisor Cloud

02 What we can do with internet finance standard Standardization Secure Governance Adaptive Compatible Restrictions

02 Requirement Aspects from Payment Service Provider Purchase Information Payment Security Mobile Payments

02 Payment Information QR Code What we can do with QR code: Contain purchase information in the QR code, including: payee, product info, how much, time, etc.

02 Payment Security Traditional authentication approaches New authentication approaches Password matrix card 1 st generation USB key OTP token 2 nd generation USB key

02 Payment Security Biometrics Face recognition Fingerprint recognition Iris recognition

02 Mobile Payment Different modes need different standards

03 Topics for discussion Purchase information Barcode Security Biometrics and other authentication approaches Tokenization PCI compliance Interaction with other protocols, e.g. 3D 2.0 Secure; Mobile User experience Automated payments Regulation Taxes and tax reporting Network issues International payments Risk management

03 Summary of questions discussed before (1) (1)If there were a standard way to communicate payment information between web applications and browsers, what opportunities would this create for your business? Overall, it would be positive due to ease of deployment for all parties including web developers, merchants, PSPs and processors. Security standards are required to be followed in the coding process under the PCI SSC for applications called PA DSS, and the deployment of applications and hardware under PCI DSS. Secure standards that can be audited in a PCI audit would significantly improve the overall reliability of web based payments.

03 Summary of questions discussed before (2) (2)What is the most important service you would like to provide your retail customers but cannot yet do so because of a technology obstacle? What are the reasons? Disintermediation due to ease of changing acquiring service providers. Market manipulation by browser providers to dis-intermediate other players..much the same way it is described in 2 above yet an opposite result. (3)What are the most important value added services (e.g., loyalty) that you would like to build on top of future payment systems? Security with user authentication.

03 Summary of questions discussed before (3) (4)What other mobile payments use cases are you working on and when do you plan to deploy solutions? Tokenization. Direct payments (5)What non-mobile Web payments use cases are you working on and when do you plan to deploy solutions? Credit transfers (6)What Web technologies do you support in your payment applications? (e.g., OAUTH2).

03 Summary of questions discussed before (4) (7)What are the primary obstacles today that prevent you from deploying credit transfer (push) payment schemes? Lack of standards. Europe has defined standards under SEPA and the PSD. It will happen in Europe. US is approaching the issue from a market driven solution perspective. Banks are not motivate to turn loose of this revenue stream. Explains all the disintermediation attempts by PE and VC funds supporting new payment apps. (8)If you are involved in faster payment initiatives, are there new Web technologies that you believe are important to success? Security Implementation/interface standards.

03 Summary of questions discussed before (5) (9)In your region, if there are open API regulatory requirements, are there new Web technologies that you believe are important to success? Europe has open requirements for web payments. It strongly supports and encourages account to account transfers as opposed to cards. New security standards for EU service providers are underdevelopment. (10)What issues (technical, legal, developer, etc.) lead you to choose native mobile platforms over Web applications? Are there specific Web capabilities whose absence is limiting delivery of services?

Thank you!