SlideShare a Scribd company logo
1 of 11
www.thales-esecurity.com OPEN
Cloud Based Payments: the
future of Mobile Payments?
SIMON KEATES, THALES E-SECURITY
ROB MACMILLAN, PROXAMA
2 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
NFC Mobile Payments Evolution
▌ Why are NFC payments growing?
Global Smartphone adoption + consumers use for a range of purposes
Mandated contactless POS rollout worldwide – convenience and speed
Financial Institutions and Merchants driving mobile engagement
▌ Mobile Payments Evolution
▌ Where does this leave the issuer?
With a potentially confusing and rapidly changing environment
Opportunities and strategic choices
3 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
▌ Apple Pay, a Game Changer?
Oct 2014 launch brought NFC payments to
iPhones
Simple consumer enrolment
New commercial model (15 bps to Apple)
Big marketing campaign and rollout
Apple in control – even had logo on POS
▌ Collaborating rather than disrupting
Uses existing payment card rails
Uses established technology – EMV, NFC
Drove card schemes to launch tokenisation
services
▌ X-Pays are following
Samsung Pay, Android Pay, etc.
But it’s still early days
Apple Pay
4 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
▌ What is Tokenisation?
Protects cardholder by replacing the PAN with a
‘surrogate’ account number, a Token PAN
Transactions still pass through terminals, acquirers and
networks
Token PAN domain controls restrict use
EMV Co published global framework in Mar 2014
▌ Tokenisation scope
Token generation
Token provisioning (with payment data) to phone
Storing Token/PAN map
De-tokenisation for authorisations and clearing
▌ Wider use of Tokenisation
Mobile, Card on File, in-App purchases
Protecting other forms of data, e.g. healthcare
Tokenisation
5 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
HCE and Cloud Based Payments (CBP)
▌ Host Card Emulation (HCE)
Technology added in Android 4.4 in 2013
Provides choice SE/TSM or HCE
Enables an app to use NFC for payment
But data and processing now in software
▌ Cloud Based Payment (CBP)
Initial deployments proprietary
Schemes introduced standards for operation
and security in 2014
Transactions are EMV contactless, no
changes to POS or networks
▌ Consumer Experience
Issuers can add payment to existing mobile
banking apps
Consumer uses something that is familiar
Provisioning through simple option to add an
existing card to the banking app
6 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
CBP layered security
▌ Dynamic keys
New keys dedicated to CBP transactions
Single or limited use keys, issuer controls key replenishment
All transactions online
▌ Tokenisation
Token PAN used instead of Card PAN to protect cardholder data
Token PANs only useable within ‘Domains’
▌ Secure communications with mobile phone
Key exchange with mobile phone
All critical keys and data supplied to phone in encrypted format
▌ Application security
Tools for tamper resistance and whitebox cryptography
Certification and penetration testing of apps
7 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
CBP deployments are spreading
Selected examples
RBC, Canada
BBVA, Spain
Capital One, USA
QIWI, Russia
Tinkoff, Russia
Barclays, UK
8 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
Cloud Based Payment future
▌ Value Added Services
Payment on its own won’t drive adoption – consumers need incentives
Issuers can add mobile banking services, loyalty and marketing programmes
▌ New types of issuers
Other issuers can adopt CBP solutions, e.g. merchant closed loop cards, transit, loyalty
Payment capability could be added to existing apps, especially where issuer has control of the
infrastructure
▌ Convergence between in-store, on-line and in-app payment
Payment credentials on the phone can be used for more than in-store
CBP credentials can support payments from other apps on the mobile, e.g. enabling
merchants to ‘payment enable’ their apps
CBP credentials can be used for online ecommerce transactions simplifying and adding extra
security
9 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
Issuer Choice: CBP and X-Pays
▌ X-Pays
▌ Pros
Supports a range of handsets (where service
is available)
Could provide value added services in future
Could leverage scheme tokenisation for
multiple X-Pays
▌ Cons
Consumer experience controlled by X-Pay
Future development controlled by X-Pay
Tokenisation service controlled by scheme,
no ‘on-us’ transactions and possible future
charges
▌ Cloud Based Payments
▌ Pros
Issuer retains branding and control of consumer
relationship
Issuer can add services and customise
consumer experience
Issuer can implement in-house solution and
continue on-us processing
▌ Cons
CBP not available on Apple devices
May require more up front investment depending
on solution
10 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
Conclusion
▌ Mobile payments market is growing
Driven by consumer demand, NFC smartphones and acceptance infrastructure
X-Pays and schemes recognise this and are competing for control
▌ Issuers have choice
Adopt X-Pays and/or CBP
Select scheme tokenisation and/or implement in-house
▌ CBP puts issuers in control
Branding and customising consumer experience
Provision of in-house solutions
▌ CBP is the future
An increasing number of issuers are deploying solutions
CBP supports value added services and payment convergence
11 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or
disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved.
Contacts
▌ Contact us via the website
https://www.thales-esecurity.com
▌ Or contact me:
simon.keates@thales-esecurity.com
▌ Contact us via the website
http://www.proxama.com
▌ Or contact me:
rob.macmillan@proxama.com

More Related Content

What's hot

Linovision Smart IP Surveillance Solutions
Linovision Smart IP Surveillance SolutionsLinovision Smart IP Surveillance Solutions
Linovision Smart IP Surveillance SolutionsMichael Yang
 
What Are Sound Based Payments
What Are Sound Based PaymentsWhat Are Sound Based Payments
What Are Sound Based PaymentsMahindra Comviva
 
Zanaco Zambia
Zanaco ZambiaZanaco Zambia
Zanaco ZambiaChess iT
 
NFC Contactless EMV Payment Device
NFC Contactless EMV Payment DeviceNFC Contactless EMV Payment Device
NFC Contactless EMV Payment DeviceStuart McGregor
 
Massages, Beaches, & Wi-Fi at Dan Hotel
Massages, Beaches, & Wi-Fi at Dan HotelMassages, Beaches, & Wi-Fi at Dan Hotel
Massages, Beaches, & Wi-Fi at Dan Hotel4ipnet
 
TFS Brochure 4_Financial
TFS Brochure 4_FinancialTFS Brochure 4_Financial
TFS Brochure 4_FinancialAnthony Whittle
 
Risk Profile Manager
Risk Profile ManagerRisk Profile Manager
Risk Profile Managernickntg
 
New Science Transaction Security Journal
New Science Transaction Security JournalNew Science Transaction Security Journal
New Science Transaction Security JournalUL
 
Faudalert_Data_Sheet
Faudalert_Data_SheetFaudalert_Data_Sheet
Faudalert_Data_SheetJuan Illidge
 
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSINVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSAndrea Cinelli
 
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...Mistral Mobile
 
TNS Payments Value Added Services Brochure November 2015
TNS Payments Value Added Services Brochure November 2015TNS Payments Value Added Services Brochure November 2015
TNS Payments Value Added Services Brochure November 2015TNSIMarketing
 
6 Considerations When Launching NFC Services
6 Considerations When Launching NFC Services6 Considerations When Launching NFC Services
6 Considerations When Launching NFC ServicesRambus Inc
 
Introduction to Solus
Introduction to SolusIntroduction to Solus
Introduction to SolusSolus
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedTransUnion
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb
 
Empowering smes with mobile payment
Empowering smes with mobile paymentEmpowering smes with mobile payment
Empowering smes with mobile paymentChunJia Sio
 

What's hot (20)

Linovision Smart IP Surveillance Solutions
Linovision Smart IP Surveillance SolutionsLinovision Smart IP Surveillance Solutions
Linovision Smart IP Surveillance Solutions
 
What Are Sound Based Payments
What Are Sound Based PaymentsWhat Are Sound Based Payments
What Are Sound Based Payments
 
Zanaco Zambia
Zanaco ZambiaZanaco Zambia
Zanaco Zambia
 
NFC Contactless EMV Payment Device
NFC Contactless EMV Payment DeviceNFC Contactless EMV Payment Device
NFC Contactless EMV Payment Device
 
SolusDeck
SolusDeckSolusDeck
SolusDeck
 
Massages, Beaches, & Wi-Fi at Dan Hotel
Massages, Beaches, & Wi-Fi at Dan HotelMassages, Beaches, & Wi-Fi at Dan Hotel
Massages, Beaches, & Wi-Fi at Dan Hotel
 
TFS Brochure 4_Financial
TFS Brochure 4_FinancialTFS Brochure 4_Financial
TFS Brochure 4_Financial
 
Risk Profile Manager
Risk Profile ManagerRisk Profile Manager
Risk Profile Manager
 
Cenpos Mobile Overview - US EMV Certified
Cenpos Mobile Overview - US EMV CertifiedCenpos Mobile Overview - US EMV Certified
Cenpos Mobile Overview - US EMV Certified
 
New Science Transaction Security Journal
New Science Transaction Security JournalNew Science Transaction Security Journal
New Science Transaction Security Journal
 
Faudalert_Data_Sheet
Faudalert_Data_SheetFaudalert_Data_Sheet
Faudalert_Data_Sheet
 
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSINVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
 
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...
Mistral Mobile - Money Mobility Suite: m-Agent for agent banking and agent-ba...
 
TNS Payments Value Added Services Brochure November 2015
TNS Payments Value Added Services Brochure November 2015TNS Payments Value Added Services Brochure November 2015
TNS Payments Value Added Services Brochure November 2015
 
Voiztrail Call Recorder
Voiztrail Call RecorderVoiztrail Call Recorder
Voiztrail Call Recorder
 
6 Considerations When Launching NFC Services
6 Considerations When Launching NFC Services6 Considerations When Launching NFC Services
6 Considerations When Launching NFC Services
 
Introduction to Solus
Introduction to SolusIntroduction to Solus
Introduction to Solus
 
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – DecodedPSD2, SCA and the EBA’s Opinion on SCA – Decoded
PSD2, SCA and the EBA’s Opinion on SCA – Decoded
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor Authentication
 
Empowering smes with mobile payment
Empowering smes with mobile paymentEmpowering smes with mobile payment
Empowering smes with mobile payment
 

Similar to Cloud based payments: the future of mobile payments?

Fortumo Company Overview 2015
Fortumo Company Overview 2015Fortumo Company Overview 2015
Fortumo Company Overview 2015Manmohan Kohli
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationMarc Vael
 
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Mahindra Comviva
 
Cloud payments (HCE): a simpler step with Thales HSMs
Cloud payments (HCE): a simpler step with Thales HSMsCloud payments (HCE): a simpler step with Thales HSMs
Cloud payments (HCE): a simpler step with Thales HSMsThales e-Security
 
MVNO for Financial Services - Cartesian - June 2015
MVNO for Financial Services - Cartesian - June 2015MVNO for Financial Services - Cartesian - June 2015
MVNO for Financial Services - Cartesian - June 2015Cartesian
 
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...Alan Quayle
 
Mobile user growth plan for e commerce player in india
Mobile user growth plan for e commerce player in indiaMobile user growth plan for e commerce player in india
Mobile user growth plan for e commerce player in indiaSuman Mishra
 
SDP Global Summit 2012
SDP Global Summit 2012SDP Global Summit 2012
SDP Global Summit 2012Martin Prosek
 
How to Build a Future-Ready Mobile Wallet Platform
How to Build a Future-Ready Mobile Wallet PlatformHow to Build a Future-Ready Mobile Wallet Platform
How to Build a Future-Ready Mobile Wallet PlatformPanamax, Inc
 
Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Starttech Ventures
 
Accessing pay buy mobile model
Accessing pay buy mobile modelAccessing pay buy mobile model
Accessing pay buy mobile modelArief Gunawan
 
What to Expect from a Mobile Banking Solution? (Whitepaper)
What to Expect from a Mobile Banking Solution? (Whitepaper)What to Expect from a Mobile Banking Solution? (Whitepaper)
What to Expect from a Mobile Banking Solution? (Whitepaper)Thinksoft Global
 
Charles Taylor InsureTech - InsurTech Innovation Award 2022
Charles Taylor InsureTech - InsurTech Innovation Award 2022Charles Taylor InsureTech - InsurTech Innovation Award 2022
Charles Taylor InsureTech - InsurTech Innovation Award 2022The Digital Insurer
 
Disruptive forces in digital payments
Disruptive forces in digital paymentsDisruptive forces in digital payments
Disruptive forces in digital paymentsInfosys
 
Mobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsMobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsStomar
 

Similar to Cloud based payments: the future of mobile payments? (20)

Fortumo Company Overview 2015
Fortumo Company Overview 2015Fortumo Company Overview 2015
Fortumo Company Overview 2015
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentation
 
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
 
Cloud payments (HCE): a simpler step with Thales HSMs
Cloud payments (HCE): a simpler step with Thales HSMsCloud payments (HCE): a simpler step with Thales HSMs
Cloud payments (HCE): a simpler step with Thales HSMs
 
MVNO for Financial Services - Cartesian - June 2015
MVNO for Financial Services - Cartesian - June 2015MVNO for Financial Services - Cartesian - June 2015
MVNO for Financial Services - Cartesian - June 2015
 
Mobile payment technology 8.11.2014 final
Mobile payment technology 8.11.2014 finalMobile payment technology 8.11.2014 final
Mobile payment technology 8.11.2014 final
 
Movotek prepaid airtime voucher distribution
Movotek prepaid airtime voucher distributionMovotek prepaid airtime voucher distribution
Movotek prepaid airtime voucher distribution
 
Estel e-Top up brochure
Estel e-Top up brochureEstel e-Top up brochure
Estel e-Top up brochure
 
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
TADSummit Asia 2019, Richard Im, Apigate. Apigate’s Journey from In-house Ini...
 
Mobile user growth plan for e commerce player in india
Mobile user growth plan for e commerce player in indiaMobile user growth plan for e commerce player in india
Mobile user growth plan for e commerce player in india
 
SDP Global Summit 2012
SDP Global Summit 2012SDP Global Summit 2012
SDP Global Summit 2012
 
How to Build a Future-Ready Mobile Wallet Platform
How to Build a Future-Ready Mobile Wallet PlatformHow to Build a Future-Ready Mobile Wallet Platform
How to Build a Future-Ready Mobile Wallet Platform
 
Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021
 
Accessing pay buy mobile model
Accessing pay buy mobile modelAccessing pay buy mobile model
Accessing pay buy mobile model
 
Trends in Fintech
Trends in FintechTrends in Fintech
Trends in Fintech
 
What to Expect from a Mobile Banking Solution? (Whitepaper)
What to Expect from a Mobile Banking Solution? (Whitepaper)What to Expect from a Mobile Banking Solution? (Whitepaper)
What to Expect from a Mobile Banking Solution? (Whitepaper)
 
What are NFC Payments?
What are NFC Payments?What are NFC Payments?
What are NFC Payments?
 
Charles Taylor InsureTech - InsurTech Innovation Award 2022
Charles Taylor InsureTech - InsurTech Innovation Award 2022Charles Taylor InsureTech - InsurTech Innovation Award 2022
Charles Taylor InsureTech - InsurTech Innovation Award 2022
 
Disruptive forces in digital payments
Disruptive forces in digital paymentsDisruptive forces in digital payments
Disruptive forces in digital payments
 
Mobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsMobile Payment Value chain and Business Models
Mobile Payment Value chain and Business Models
 

Recently uploaded

Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomCzechDreamin
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101vincent683379
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfFIDO Alliance
 
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPTiSEO AI
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...panagenda
 
Using IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandUsing IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandIES VE
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...FIDO Alliance
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekCzechDreamin
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераMark Opanasiuk
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...FIDO Alliance
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireExakis Nelite
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxDavid Michel
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?Mark Billinghurst
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityScyllaDB
 
Oauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftOauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftshyamraj55
 
Portal Kombat : extension du réseau de propagande russe
Portal Kombat : extension du réseau de propagande russePortal Kombat : extension du réseau de propagande russe
Portal Kombat : extension du réseau de propagande russe中 央社
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Julian Hyde
 
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...CzechDreamin
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfFIDO Alliance
 

Recently uploaded (20)

Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone KomSalesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
Salesforce Adoption – Metrics, Methods, and Motivation, Antone Kom
 
AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101AI presentation and introduction - Retrieval Augmented Generation RAG 101
AI presentation and introduction - Retrieval Augmented Generation RAG 101
 
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdfLinux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
Linux Foundation Edge _ Overview of FDO Software Components _ Randy at Intel.pdf
 
Overview of Hyperledger Foundation
Overview of Hyperledger FoundationOverview of Hyperledger Foundation
Overview of Hyperledger Foundation
 
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
1111 ChatGPT Prompts PDF Free Download - Prompts for ChatGPT
 
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
Easier, Faster, and More Powerful – Alles Neu macht der Mai -Wir durchleuchte...
 
Using IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & IrelandUsing IESVE for Room Loads Analysis - UK & Ireland
Using IESVE for Room Loads Analysis - UK & Ireland
 
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
Secure Zero Touch enabled Edge compute with Dell NativeEdge via FDO _ Brad at...
 
AI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří KarpíšekAI revolution and Salesforce, Jiří Karpíšek
AI revolution and Salesforce, Jiří Karpíšek
 
Intro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджераIntro in Product Management - Коротко про професію продакт менеджера
Intro in Product Management - Коротко про професію продакт менеджера
 
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
ASRock Industrial FDO Solutions in Action for Industrial Edge AI _ Kenny at A...
 
Microsoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - QuestionnaireMicrosoft CSP Briefing Pre-Engagement - Questionnaire
Microsoft CSP Briefing Pre-Engagement - Questionnaire
 
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptxUnpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
Unpacking Value Delivery - Agile Oxford Meetup - May 2024.pptx
 
The Metaverse: Are We There Yet?
The  Metaverse:    Are   We  There  Yet?The  Metaverse:    Are   We  There  Yet?
The Metaverse: Are We There Yet?
 
Optimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through ObservabilityOptimizing NoSQL Performance Through Observability
Optimizing NoSQL Performance Through Observability
 
Oauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoftOauth 2.0 Introduction and Flows with MuleSoft
Oauth 2.0 Introduction and Flows with MuleSoft
 
Portal Kombat : extension du réseau de propagande russe
Portal Kombat : extension du réseau de propagande russePortal Kombat : extension du réseau de propagande russe
Portal Kombat : extension du réseau de propagande russe
 
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
Measures in SQL (a talk at SF Distributed Systems meetup, 2024-05-22)
 
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
Integrating Telephony Systems with Salesforce: Insights and Considerations, B...
 
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdfThe Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
The Value of Certifying Products for FDO _ Paul at FIDO Alliance.pdf
 

Cloud based payments: the future of mobile payments?

  • 1. www.thales-esecurity.com OPEN Cloud Based Payments: the future of Mobile Payments? SIMON KEATES, THALES E-SECURITY ROB MACMILLAN, PROXAMA
  • 2. 2 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. NFC Mobile Payments Evolution ▌ Why are NFC payments growing? Global Smartphone adoption + consumers use for a range of purposes Mandated contactless POS rollout worldwide – convenience and speed Financial Institutions and Merchants driving mobile engagement ▌ Mobile Payments Evolution ▌ Where does this leave the issuer? With a potentially confusing and rapidly changing environment Opportunities and strategic choices
  • 3. 3 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. ▌ Apple Pay, a Game Changer? Oct 2014 launch brought NFC payments to iPhones Simple consumer enrolment New commercial model (15 bps to Apple) Big marketing campaign and rollout Apple in control – even had logo on POS ▌ Collaborating rather than disrupting Uses existing payment card rails Uses established technology – EMV, NFC Drove card schemes to launch tokenisation services ▌ X-Pays are following Samsung Pay, Android Pay, etc. But it’s still early days Apple Pay
  • 4. 4 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. ▌ What is Tokenisation? Protects cardholder by replacing the PAN with a ‘surrogate’ account number, a Token PAN Transactions still pass through terminals, acquirers and networks Token PAN domain controls restrict use EMV Co published global framework in Mar 2014 ▌ Tokenisation scope Token generation Token provisioning (with payment data) to phone Storing Token/PAN map De-tokenisation for authorisations and clearing ▌ Wider use of Tokenisation Mobile, Card on File, in-App purchases Protecting other forms of data, e.g. healthcare Tokenisation
  • 5. 5 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. HCE and Cloud Based Payments (CBP) ▌ Host Card Emulation (HCE) Technology added in Android 4.4 in 2013 Provides choice SE/TSM or HCE Enables an app to use NFC for payment But data and processing now in software ▌ Cloud Based Payment (CBP) Initial deployments proprietary Schemes introduced standards for operation and security in 2014 Transactions are EMV contactless, no changes to POS or networks ▌ Consumer Experience Issuers can add payment to existing mobile banking apps Consumer uses something that is familiar Provisioning through simple option to add an existing card to the banking app
  • 6. 6 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. CBP layered security ▌ Dynamic keys New keys dedicated to CBP transactions Single or limited use keys, issuer controls key replenishment All transactions online ▌ Tokenisation Token PAN used instead of Card PAN to protect cardholder data Token PANs only useable within ‘Domains’ ▌ Secure communications with mobile phone Key exchange with mobile phone All critical keys and data supplied to phone in encrypted format ▌ Application security Tools for tamper resistance and whitebox cryptography Certification and penetration testing of apps
  • 7. 7 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. CBP deployments are spreading Selected examples RBC, Canada BBVA, Spain Capital One, USA QIWI, Russia Tinkoff, Russia Barclays, UK
  • 8. 8 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. Cloud Based Payment future ▌ Value Added Services Payment on its own won’t drive adoption – consumers need incentives Issuers can add mobile banking services, loyalty and marketing programmes ▌ New types of issuers Other issuers can adopt CBP solutions, e.g. merchant closed loop cards, transit, loyalty Payment capability could be added to existing apps, especially where issuer has control of the infrastructure ▌ Convergence between in-store, on-line and in-app payment Payment credentials on the phone can be used for more than in-store CBP credentials can support payments from other apps on the mobile, e.g. enabling merchants to ‘payment enable’ their apps CBP credentials can be used for online ecommerce transactions simplifying and adding extra security
  • 9. 9 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. Issuer Choice: CBP and X-Pays ▌ X-Pays ▌ Pros Supports a range of handsets (where service is available) Could provide value added services in future Could leverage scheme tokenisation for multiple X-Pays ▌ Cons Consumer experience controlled by X-Pay Future development controlled by X-Pay Tokenisation service controlled by scheme, no ‘on-us’ transactions and possible future charges ▌ Cloud Based Payments ▌ Pros Issuer retains branding and control of consumer relationship Issuer can add services and customise consumer experience Issuer can implement in-house solution and continue on-us processing ▌ Cons CBP not available on Apple devices May require more up front investment depending on solution
  • 10. 10 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. Conclusion ▌ Mobile payments market is growing Driven by consumer demand, NFC smartphones and acceptance infrastructure X-Pays and schemes recognise this and are competing for control ▌ Issuers have choice Adopt X-Pays and/or CBP Select scheme tokenisation and/or implement in-house ▌ CBP puts issuers in control Branding and customising consumer experience Provision of in-house solutions ▌ CBP is the future An increasing number of issuers are deploying solutions CBP supports value added services and payment convergence
  • 11. 11 This document may not be reproduced, modified, adapted, published, translated, in any way, in whole or in part or disclosed to a third party without the prior written consent of Thales - © Thales 2014 All rights reserved. Contacts ▌ Contact us via the website https://www.thales-esecurity.com ▌ Or contact me: simon.keates@thales-esecurity.com ▌ Contact us via the website http://www.proxama.com ▌ Or contact me: rob.macmillan@proxama.com