QR Code for Digital Signature Online/Offline Payment. James Wu www.jrsys.com.tw 1



Similar documents
Jrsys International Corp.

Secure your Privacy. jrsys, Inc. All rights reserved.

Securing Cloud Computing. Szabolcs Gyorfi Sales manager CEE, CIS & MEA

Entrust Managed Services PKI. Getting an end-user Entrust certificate using Entrust Authority Administration Services. Document issue: 2.

Public Key Infrastructure for a Higher Education Environment

Smart Card- An Alternative to Password Authentication By Ahmad Ismadi Yazid B. Sukaimi

Authentication Levels. White Paper April 23, 2014

Secure Your Enterprise with Usher Mobile Identity

Strong Authentication: Enabling Efficiency and Maximizing Security in Your Microsoft Environment

Controller of Certification Authorities of Mauritius

WHITEPAPER. SECUREAUTH 2-FACTOR AS A SERVICE 2FaaS

Secure Web Access Solution

Entrust IdentityGuard

WHITE PAPER Usher Mobile Identity Platform

Building Secure Applications. James Tedrick

Schlumberger PKI /Corporate Badge Deployment. Neville Pattinson Director of Business Development & Technology IT & Public Sector

Thai Digital ID Co.,Ltd.

Contents. 2 Welcome. 20 Settings. 3 Activation Steps. 4 Introduction. 4 Purpose. 20 Offline Mode Change Password. 5 Key Features

One platform for all your print, scan and device management

esign Online Digital Signature Service

Entrust Managed Services PKI. Getting started with digital certificates and Entrust Managed Services PKI. Document issue: 1.0

WorldPay Mobile Demonstration

Enhancing Web Application Security

How Secure is Authentication?

Safe & Quick Mobile Payment. SQ is an authentication and payment system for mobile, cashless and contactless payment via Smartphone.

Apache Milagro (incubating) An Introduction ApacheCon North America

Advanced Authentication

Software Token Security & Provisioning: Innovation Galore!

Two-Factor Authentication over Mobile: Simplifying Security and Authentication

The e-payment Systems

Strong Authentication in details

SEZ SEZ Online Manual Digital Signature Certficate [DSC] V Version 1.2

Electronic Payments Part 1

Global Transport Secure ecommerce Decision Tree

STRONGER AUTHENTICATION for CA SiteMinder

Microsoft Identity Lifecycle Manager & Gemalto.NET Solutions. Jan 23 rd, 2007

AUTHENTIFIERS. Authentify Authentication Factors for Constructing Flexible Multi-Factor Authentication Processes

SAP NetWeaver Single Sign-On. Product Management SAP NetWeaver Identity Management & Security June 2011

MyKey is the digital signature software governed by Malaysia s Digital Signature Act 1997 & is accepted by the courts of law in Malaysia.

Integration Guide. SafeNet Authentication Client. Using SAC CBA for Check Point Security Gateway

White paper. Implications of digital certificates on trusted e-business.

mpos Solution A: Visa, MasterCard and JCB are supported. Both Debit & Credit Cards which is supported by any of this Card Type can be accepted.

Ericsson Mobile digital identity

The easy way to accept EFTPOS, Visa and MasterCard payments on the spot. Mobile Users Charging your PayClip. 2. Downloading the PayClip app.

Getting Started with Swipe Checkout

NetIQ Advanced Authentication Framework

View from a European Trust Service Provider Server Signing: Return of experience and certification strategy

Mobility, Security and Trusted Identities: It s Right In The Palm of Your Hands. Ian Wills Country Manager, Entrust Datacard

Apple Inc. Certification Authority Certification Practice Statement Worldwide Developer Relations Version 1.14 Effective Date: September 9, 2015

SAP Single Sign-On 2.0 Overview Presentation

Finger Vein digital biometric signature: use cases

Strong authentication of GUI sessions over Dedicated Links. ipmg Workshop on Connectivity 25 May 2012

Onegini Token server / Web API Platform

U S E R S G U I D E Last Modified: 12/06/2012 1

Latest and Future development of Mobile Payment in Hong Kong

Deploying and Managing a Public Key Infrastructure

Single Sign-On Portal User Reference (Okta Cloud SSO)

CHARGE Anywhere Universal Shopping Cart

Improving Online Security with Strong, Personalized User Authentication

Mobile Identity: Improved Cybersecurity, Easier to Use and Manage than Passwords. Mika Devonshire Associate Product Manager

White Paper. McAfee Cloud Single Sign On Reviewer s Guide

MiniPOS and BluePad-50 user manual

SAP Mobile Documents. December, 2015

Secure Mail Message Retrieval Instructions

Agenda. How to configure

The Cloud, Mobile and BYOD Security Opportunity with SurePassID

GoldKey Product Info. Do not leave your Information Assets at risk Read On... Detailed Product Catalogue for GoldKey

Whitepaper on AuthShield Two Factor Authentication with ERP Applications

Electronic Commerce and E-wallet

Credit Card Processing Overview

A brief on Two-Factor Authentication

Enforce AD RMS Policies for PDF documents in SharePoint Environments Enforce AD RMS Policies for PDF documents in Exchange Environments...

Configuration Guide. SafeNet Authentication Service. SAS Agent for Microsoft Outlook Web Access 1.06

TABLE OF CONTENTS. Vendor Registration Usage of Digital Signature Certificate... 3

A8.1 Asset Management Responsibility for assets: To identify organisational assets and define appropriate protection responsibilities.

How CA Arcot Solutions Protect Against Internet Threats

Authentication Scenarios India. Ramachandran

DIGIPASS KEY series and smart card series for Juniper SSL VPN Authentication

EVERYTHING YOU NEED FOR BRANDING ON MULTIPLE CHANNELS

Research Article. Research of network payment system based on multi-factor authentication

Moving to Multi-factor Authentication. Kevin Unthank

m Commerce Working Group

ADDING STRONGER AUTHENTICATION for VPN Access Control

CHARGE Anywhere. Mobile POS. User s Guide

Digital Certificates (Public Key Infrastructure) Reshma Afshar Indiana State University

GETTING STARTED GUIDE

DigitalPersona Pro Enterprise

Idaho State University CASHNet ipad App Step-By-Step Training Guide

How To Set Up A Xerox Econcierge Powered By Xerx Account

NASDAQ Web Security Entitlement Installation Guide November 13, 2007

New Features. Sybase Mobiliser Platform 5.1

Financial industry Solutions. Redefining Micro Location for the Financial industry in a Mobile World

REDCap project creation is not possible in the Mobile App

Transcription:

QR Code for Digital Signature Online/Offline Payment James Wu www.jrsys.com.tw 1

Big Risk of Online Shopping You may lost Card Number + Expiration Date + CVV Card Not Present Transaction Trojan, Sniffer, Phishing site e-commerce site compromised 2

On-Line Payment No more Card Number + Expiration Date + CVV Just Scan the Secure QR Code Commerce 1.Prepare checkout data 2.Create a Digital Signed Checkout QR code on the screen Consumer 3.Scan the checkout QR code 4.Select virtual credit card 5.Input PIN code to confirm the payment Credit card information is not transmitted Date:2014/10/02 Merchant s Digital Signature 3

Off-Line Payment More Secure and Fast than Magnetic Credit Card Swipe Payment Mobile Payment Before Out-of-band authentication Handwriting signature Card can be Cloned Sign a Credit card Check Merchant scan the QR 4

Offline Payment Process Consumer 1.Select Virtual credit card 2.Enter the amount 3.Input PIN to make a digital signature and Generate a QR code Commerce 4.Scan the QR code 5.Make a Digital Signature 6.Connect to Payment Gateway Date:2014/10/02 Consumer s Digital Signature 5 Commerce cannot clone any card!

Secure Tokenization Payment No credit card number store in the e-wallet 3rd party cannot get consumer s Credit Card Data All transaction is confirmed by digital signatures 6

How do we protect Card not present Transaction? Issue certificate to the register s e-wallet User input the Card Number + Expiration Date then encrypted it immediately and send to backend server User can decide if he want to encrypted his CVV by his public key so no need to input the CVV for each transaction Support both hardware/software Secure Element 7

System Architecture Jrsys Payment Authentication Servers Jrsys provides: Mobile QR ios/android Client SDK Backend Authentication Servers 8

QR code for Logistic Shipping QR code contains Product codes, Quantities, Date, Time and Manufacture's Digital Signature User can scan and verify it immediately 9

Digital Signed Hard Copy Document User can scan and verify it immediately Before Handwriting Signature Digital Signed PDF Now PDF417 Original Document with Digest Digital signed PDF 417 License Party A s Digital Signature Party B s Digital Signature 10 Digital signed QR code Invoice

Why FoxitSign is different? Besides of online Document Exchange Mobile Signature and Validation Service jrsys Mobile RA WebTrust CA Original Document FoxitCloud PDF417 Digital Signed Document Both parties scan it and Make their digital Signatures by Mobile Party A s Digital Signature Party B s Digital Signature PDF or Hard copy Both parties will receive the digital signed confirmation receipt after they finish their digital signatures 11 Final PDF can keep in the FoxitCloud or print it out

Patented QR Code Payment Digital Signature QR code Not only an URL/ OTP short code But also the transaction with digital signature Date:2014/10/02 Digital Signature Easy to deploy and use No additional hardware cost Patented O2O Payment technology Authentication, Integrity, Confidentiality and Non-repudiation secure transaction 12

The Differences Data Traditional Payment & QR code Payment URL or a short OTP code jrsys QR code Payment Digital Signed Transaction data and OTP Authentication Weak Strong Authorization Weak Strong Encryption Weak Strong Non-repudiation No Yes Credit Card Data Merchant can get Credit Card data Encrypted & Merchant cannot get it 13

Secure Mobile Devices Bluetooth Reader World First ios/android/pc Token e-ink Master OTP card Audio Reader 14 Audio Token

World First ios/android/pc Token ios 8-Pin Lightning Connector Android Mini USB PC USB Platform: PC/Android/iOS Secure MicroSD inside 15

Easy & Fast PKI-enable Solutions PKI-enabled in 3 Days Not 3 Months Cross Platform Various Devices Firefox Plug-In ActiveX Chrome Plug-In Mobile Signature & Validation Service 16

2014 Taiwan ITM Best product Winner Award Security Suits for PC Web Authentication with SE Applications Software Applications can work with Jrsys Middleware Jrsys PC Security Suite and many Firefox Plug-In ActiveX Chrome Plug-In Secure Devices Multiple Tokens 17 Software PFX Smart Card USB Token HSM

2014 Taiwan ITM Best product Winner Award Security Suits for Mobile Applications Mobile Authentication with SE Secure Mobile APP can work with Jrsys Middleware One Time Password Secure e-mail Secure PDF Mobile Signature jrsys Mobile Security Suite Mobile Money and many ios SDK Android SDK Secure Mobile Devices Software PFX HCE Multiple Mobile Tokens Smart Cards Bluetooth reader 18 Secure MicroSD PC/iOS/Android Token

WebTrust RA Issue WebTrust certificates to Mobile & PC Jrsys Secure Mobile/PC Tokens USB PKI Token Smart Cards USB PC/SC reader Secure MicroSD ios/pc /Android Token Bluetooth Reader Software PFX HCE 19

Cloud Validation All in One Authentication Service: ID/Password, OTP, Smart Card, Mobile Tokens and Micro SD. Single Sign On PKI APIs 20

Secret Communication System MDIRS Military Digital ID Registration Service MDIA Military Digital ID Authority MDIRKMS Military Digital ID Repository Key Management Service MDIDS Military Digital ID Directory Service Secure Mobile soldier Internet MDRS Military Distributed Registration Service Secure Login MSVS Mobile Signature & Validation Service Secure SIP Server Secure Phone Secure IM Secure e-mail Secure PDF 21 21 Portal Secure SMS Server

jrsys Worldwide Awards 2014 Taiwan ITM Best 100 products Winner Award APICTA Award 2013 Security Winner 2012 Mobile Money Innovation Award 2012 ASIA PKI Innovation Award One of the 7 innovative ideas from 98 best ideas of 26 countries BY: MIF, IDB, CAF and GSMA 22

Partner with Foxit 27,500 Millions PDF users use jrsys security Suite 23

Mobile Security Patents Gained 2 U.S. Mobile Security Patents 24