2013 Guide to Frictionless ecommerce for Mobile App Developers How to Optimize Security in Your Mobile Apps to Reduce Abandonment Rates and Improve the Speed and User Experience of your Mobile Apps by Actus Mobile Solutions
Frictionless ecommerce Nearly half of all mobile phone users worldwide will pay by mobile for digital and physical goods by 2014 but with the proviso that the availability of secure, easy-to-use, mobile applications will drive the mobile commerce market. (Juniper Research) The importance of commerce on mobile devices increases every day. Forrester predicts US mobile commerce will quadruple between 2013 and 2018 to more than $90bn, while IDC says global m- commerce to reach $660bn in 2017 and by 2016 four out of five Internet connected devices around the world will be mobile (Boston Consulting Group). To date, the growth of mobile commerce is limited by poor experience and perceived risks: High shopping cart abandonment approximately 90% of all mobile transactions are abandoned; Poor user and brand experience dropping out of app to a browser or frame; Risks of fraud, repudiation and PCI non-compliance; The introduction of a simple and safe in-line checkout results in an increase in the conversion rate on mobile from 5% to over 30%. In addition, a 5% reduction in abandonment increases mobile commerce revenues by up to 50%. Currently, the average e-commerce user spends 25 per transaction and performs up to 100 transactions per annum. With the introduction of simple and safe m-commerce, the immediacy offered by the mobile device results in an increase of nearly 40% in the value of transactions as well as a 25% increase in the volume of transactions. Research also predicts that the move to frictionless m- Commerce will result in a 35% increase in new users. Merchants, wishing to realise the full potential of the mobile channel, need to take action to simplify and secure commerce through their mobile channels, thus protecting their brand and their customer. Secure, frictionless and compliant m:cypher tm from Actus Mobile is the secure payment standard for frictionless mobile commerce. It provides a single-step payment experience for mobile commerce - reducing abandonment and risk, with simple implementation for developers that: Provides a single step for the consumer to complete secure, in-app mobile transactions; Extends PCI compliance and non-repudiation to all mobile devices; Is more secure than 3D Secure; Is a simple integration tool for merchants and their developers and delivers seamless integration into payment service providers; Protects all data stored on a mobile/wireless device such as a mobile phone as well as protecting all data in-flight when being transmitted/received by any mobile or wireless devices; Isolates users from the underlying security technology thus providing a frictionless m-commerce experience for the end-user; Page 2 of 6
This is a closed security eco-system which provides companies/organisations with the capability of being their own trust authority i.e. the company certifies that all transactions originated/terminated between it and its registered clients (the two authorised sources) with each transaction being fully authenticated. This significantly reduces the possibility of fraud as well as 3 rd party interference. Each secured transaction has a Mobile Transaction Fingerprint which uniquely identifies the source and the owner of the transaction thus providing a tamper-proof provenance of the transaction. This ensures that each transaction is protected from intermediaries and therefore cannot be repudiated. Securing Online Commerce Currently, almost all mobile commerce applications and mobile-enabled websites only use standard web security (SSL/TLS) to secure data being transferred to and from the user s phone. In a recent publication, research teams from two German universities were able to hack over 41% of mobile apps. This approach is completely inadequate, and leaves end-users, app developers, app owners and mobile operators seriously exposed for a number of reasons: 1. Web security encrypts only the communications tunnel used to transmit data to and from the phone, not the data itself, and any breaks in communication, which happen very frequently on mobile devices, leave this data in the clear on the device, which could then be harvested if the phone is lost or stolen; 2. Web security affects the performance of apps because data secured using web security takes five times longer to process; 3. Data secured using SSL/TLS assumes an always-on connection between the sender and receiver. As connections are dropped frequently on mobile devices, constantly re-establishing the connection adds significant delays to processing any transaction or results in the transactions being abandoned; Actus Mobile s patented Secure Mobile Transaction Platform fixes these fundamental security, performance and ease-of-use issues, thereby accelerating the adoption of m-commerce as the preferred method for transacting online. This platform: provides end-users with a 100% end-to-end secure environment with up to five-factors of authentication: 5-FA; (note: 2-FA is considered secure enough for web-based/online transactions but is insufficient for the mobile environment); protects all data regardless of type (e.g. financial, personal, business, access, message etc.) being communicated to/from any end-user mobile device whether direct to a business service provider such as a retailer, bank, airline etc. or into/out of the Cloud; is fully supported not only on smartphones and tablets, including iphone, Android, ipad, Tablets, Windows Mobile and Blackberry, but also on Feature (non-smart) phones from manufacturers such as Nokia, Motorola, Sony Ericsson, LG etc., the latter being particularly relevant for less developed economies where feature phones still predominate; is built on a five-layer security stack to provide a secure and scalable transaction environment; Page 3 of 6
Upon the m:cypher tm platform, a range of secure and easy-to-use mobile applications can be built providing a simple and safe m-commerce eco-system. m:cypher tm vs. Web Security As can be seen from figures 1 & 2 below, m:cypher clearly offers higher-levels of security as well as addressing the user experience issues that have been identified. Figure 1: Mobile Security Using SSL/TLS Figure 2: Mobile Security Using m:cypher Page 4 of 6
Summary The m:cypher tm platform is expressly designed to isolate the end-user from the underlying technology thus eliminating the difficulties that have impacted the wide-scale adoption of mobile transactions such as m-commerce. This technology provides any company wishing to supply mobile enabled applications and services such as m-commerce with a 100% secure end-to-end application development environment upon which a wide-range of applications can be built which are: The technology platform is: 1. Very Secure both on handset as well as in-flight ; 2. Very Fast regardless of network connection speed; 3. Very Easy-to-Use regardless of age group; fully Internationalised; available to over 90% of mobile phones; independent of any Mobile Network Operator; immune to attacks such as a Man in the Middle Attack or a Spoofing attempt. If such an attack was attempted m:cypher tm will only allow an intruder to gather data that is already fully encrypted using AES 256-bit encryption i.e. 100% End-to- End Transaction Security; protected as any data cached or stored locally on the handset is encrypted using AES 256-bit encryption cannot be harvested and thus is fully protected against abuse in the event that the handset is lost, cloned or stolen; protected as any cookies stored on the handset are encrypted with AES 256-bit encryption; simply integrated with a Merchant s existing application environment; implemented with little impact on existing in-house IT resources; owned and managed in-house within the Merchant s own Data Centre; Setting the Standard for Secure, Frictionless Mobile Commerce Page 5 of 6
Ray Breen Director & Co-Founder M +353 (0) 87 280 6635 E ray.breen@actusmobile.com Actus Mobile Solutions Atlas Court, IDA Business Park, Bray, Co. Wicklow, Ireland T +353 (0)1 902 3263 @actusms www.actusmobile.com www.ecommercesecurity.co.uk Page 6 of 6