SlideShare a Scribd company logo
1 of 44
Download to read offline
All Rights Reserved | FIDO Alliance | Copyright 20181
FIDO & PSD2
SOLVING THE STRONG
CUSTOMER AUTHENTICATION
CHALLENGE IN EUROPE
2
AGENDA
PSD2 & Strong Customer Authentication
Requirements
Beyond Passwords with FIDO2
Bank Challenges & How FIDO Can Help
All Rights Reserved | FIDO Alliance | Copyright 2018
All Rights Reserved | FIDO Alliance | Copyright 2018
What is PSD2?
“An attempt to drive innovation through regulation”
• Regulates banks, payment services and other related financial services throughout the
European Union (EU) and European Economic Area (EEA)
• Goals:
• Increase competition and participation in financial services and payments by creating a path
for non-bank Third Party Providers (TPPs), including:
• Account Information Service Providers (AISPs) – entities that gather data on a user’s accounts and
present a unified view of finances, as well as offer advice
• Payment Initiation Service Providers (PISPs) – entities that don’t hold payment accounts for users,
but do allow users to make payments through them
• Give consumers non-bank choices in payments and financial services
• Improve consumer protection
3
Open
APIs
4
• New Access to Account mandate ➔ Open APIs
• New Strong Customer Authentication mandate
• New Third Party Provider (TPP) roles
Open
APIs
Open
APIs
Payment
execution
Open
APIs
Open
APIs
Open
APIs
Gives
consent
Payment Initiation
Service Provider (PISP)
Account Information
Service Provider (AISP)
PSD2 – Key Provisions
All Rights Reserved | FIDO Alliance | Copyright 2018
All Rights Reserved | FIDO Alliance | Copyright 2018
PSD2: Why Strong Customer
Authentication (SCA) Matters
If I am going to let a PISP or AISP
1. Access data from my bank account
2. Transfer money from my bank account
for a payment
My bank needs to:
• Authenticate me, and
• Know that I have authorized them
to do this
5
All Rights Reserved | FIDO Alliance | Copyright 2018
How this is often done today
“Credential Caching and Screen Scraping”
• AISP asks me for my username and password
• They store this – and log in with my credentials – sometimes several times a day
• They collect (aka “screen scrape”) all my account data to support their service
6
All Rights Reserved | FIDO Alliance | Copyright 2018
Screen Scraping – Some Issues
1. We tell people “never share your password”
• This requires people to trust a third party with their username and password
• Looks like a phishing attack
2. Passwords are fundamentally insecure
• Letting additional parties store passwords and other “shared secrets” raises risks
• Often breaks tools that protect the login process, including multi-factor
authentication (MFA) and behavior analytics
3. Issues with privacy and consent
• I think I am granting access to a small part of my account – but the TPP may get
access to all of it
• No way for a consumer to authorize access on a granular level
• GDPR concerns
7
Open
APIs
• Third parties can securely connect to a bank – no need to cache passwords
• Banks can share data directly with third parties – no screen scraping needed
• Banks can enable third party payment providers to initiate payments
• Customers can let their bank know they explicitly authorize access, and can
manage access on a granular level
Open
APIs
Open
APIs
Payment
execution
Open
APIs
Open
APIs
Open
APIs
Gives
consent
Payment Initiation
Service Provider (PISP)
Account Information
Service Provider (AISP)
How to address this: Open APIs
All Rights Reserved | FIDO Alliance | Copyright 20188
All Rights Reserved | FIDO Alliance | Copyright 2018
PSD2 SCA – Key Dates
• November 2017 – Final RTS published by EC
• September 2019 – Effective Date of RTS
• March 2019 - Banks must be ready 6 months before
effective date
• Banks must make interfaces available to TPPs for testing
http://ec.europa.eu/finance/docs/level-2-measures/psd2-rts-2017-7782_en.pdf
9
All Rights Reserved | FIDO Alliance | Copyright 2018
What the EBA Strong Customer
Authentication (SCA)rules require
Transactions require Multi-Factor
Authentication (MFA) - 2 of 3 elements:
▸ Something you know (password or PIN)
▸ Something you possess (phone, token,
card)
▸ Something you are (biometric)
Passw00rd
A “multi-purpose” device must protect the
independence of authentication elements
10
All Rights Reserved | FIDO Alliance | Copyright 2018
Requirements around user experience
EC concerns that banks would build bad APIs or
otherwise create obstacles to them accessing
consumer accounts – led to a ban on “obstacles”
to access.
▸ One example: a “redirect” model used with an
API “may” be an obstacle
▸ However, EC has been clear this was only an
example – and there may be redirect
implementations that do not cause obstacles
▸ If any obstacles exist – mandate to shift to a
“fall-back” option (a non-API interface) based
on caching customer’s banking passwords
11
All Rights Reserved | FIDO Alliance | Copyright 2018
Some implications
The “redirect model” is industry-accepted best practice for how a consumer can log in to one
account with a credential from another
▸ Based on proven standards (OAuth 2.0, OpenID Connect, FIDO)
▸ Dozens of vendors lined up behind it
▸ UK Open Banking Implementation Entity (OBIE) has already created standards based on redirect
The key: how to implement it with an excellent user experience
▸ FIDO implementations can streamline the authentication process – delivering strong customer
authentication more efficiently than other MFA tools.
12
All Rights Reserved | FIDO Alliance | Copyright 2018
Will we see PSD2 in the US?
• Unlikely that a regulation forces action
• But – Open Banking and Open Payments is happening
• The key is whether industry can figure it out themselves, rather than have
the government prescribe how to do it
13
All Rights Reserved | FIDO Alliance | Copyright 2018
Open Banking Standards in the US
https://www.fsisac.com/article/fs-isac-enables-safer-financial-data-sharing-api
Want a copy?
Reach out to
Eric Guerrino at
eguerrino@fsisac.com
14
All Rights Reserved | FIDO Alliance | Copyright 2018
Highlights of US FS-ISAC approach
• Standard APIs to enable secure third-party access
• When a consumer wishes to set up or add a bank, brokerage, or insurance account to a
third-party service, they will be seamlessly passed to a secure server at their financial
institution to begin the enrollment process.
• The consumer is presented with the financial institution’s consent page, where they
authorize which data or access privileges they wish to share with the financial application,
giving consumers control.
• After authenticating, the consumer is then seamlessly passed back to the financial
application. Data sharing between financial application servers and financial institution
servers is then done securely via a unique virtual token that identifies the consumer and
their respective accounts.
• Standards recommended: OAuth, OpenID Connect, FIDO
15
All Rights Reserved | FIDO Alliance | Copyright 2018
Details on SCA in the FS-ISAC Approach
• “OAuth 2.0 is the foundation for OpenID Connect 1.0. OpenID Connect 1.0 when used will promote secure user federation. Fast
IDentity Online (FIDO) 1.1 forms the design pattern for authenticating the consumer to allow maximum user agent interoperability
to better support public client agent applications. Use of these patterns should enable FIs to increase aggregator onboarding
velocity in a holistically secure and governable access model.”
• “All FIDO 1.1 security considerations should be observed and accounted for in the final implementations of the FIDO 1.1
specifications for both aggregators and FIs (where FIDO is used) to reduce vulnerabilities associated with this authentication
method.”
• “Use of Fast IDentity Online 1.1 (FIDO) Universal Authentication Framework (UAF) as an authentication method is recommended (in
the absence of a similarly capable FI solution) during the OAuth and OIDC sequence to support strong initial user authentication.
FIDO protocol challenge should be used by the FIDO server to activate the FIDO authentication framework and protocol sequence.
FIDO client registration may also be included as part of the authentication sequence where the customer’s user agent is FIDO-
capable (and FI policy provision allows), but not yet known to the FI’s FIDO server.”
• “FIDO Universal 2nd Factor (U2F) capability, which uses a hardware device to store identity tokens, might also be used to strongly
ensure and verify customer identity and presence executing high-risk operation(s). The FIDO client that implements U2F API must
be present on the user agent platform to respond to the FIDO server 2FA challenge and utilize the FIDO hardware device to retrieve
user identity keys registered with the FI FIDO server for aggregation API MFA / 2FA.”
*From “Control Considerations for Consumer Financial Account Aggregation Services” by the FS-ISAC
16
17
AGENDA
PSD2 & Strong Customer Authentication
Requirements
Beyond Passwords with FIDO2
Bank Challenges & How FIDO Can Help
All Rights Reserved | FIDO Alliance | Copyright 2018
All Rights Reserved | FIDO Alliance | Copyright 201818
The World Has a Password Problem
Data breaches in 2016
that involved weak,
default, or stolen
passwords1
81%
Phishing attacks were
successful in 20161 Breaches in 2017, a 45%
increase over 20162
1 IN 14
1,579
CLUMSY | HARD TO REMEMBER | NEED TO BE CHANGED ALL THE TIME
All Rights Reserved | FIDO Alliance | Copyright 201819
The Solution: Simpler *and* Stronger
open standards for
simpler, stronger
authentication
using public key
cryptography
Single Gesture
Phishing-resistant MFA
=
SECURITY
USABILITY
Poor Easy
WeakStrong
All Rights Reserved | FIDO Alliance | Copyright 201820
How Does FIDO Work?
AuthenticatorUser verification FIDO Authentication
Require user gesture
before private key can
be used
Challenge
(Signed) Response
Private key (handle)
per account Public key
All Rights Reserved | FIDO Alliance | Copyright 201821
Who is using FIDO today?
(Sample of deployments in production)
All Rights Reserved | FIDO Alliance | Copyright 201822
FIDO Specifications
FIDO UAF
FIDO U2F
(@FIDO)
CTAP
(@FIDO)
WebAuthn
(@W3C)
FIDO2 Project
All Rights Reserved | FIDO Alliance | Copyright 201823
WebAuthn Brings FIDO to the Web Browser
Participation
from all these
platform
providers
World Wide Web
Consortium (W3C)
developed
Web Authentication
(“WebAuthn”)
with FIDO Alliance
Contributions
Candidate
Recommendation
A new standard
JavaScript API
That works with all FIDO2
platforms & authenticators
All Rights Reserved | FIDO Alliance | Copyright 201824
FIDO “UNIVERSAL SERVER” Program
Ensures interoperability with all
FIDO Certified Authenticators
FIDO Universal Server
25
AGENDA
PSD2 & Strong Customer Authentication
Requirements
Beyond Passwords with FIDO2
Bank Challenges & How FIDO Can Help
All Rights Reserved | FIDO Alliance | Copyright 2018
26
BANK CHALLENGES WITH PSD2 IMPLEMENTATION
• Deployment of Strong Customer Authentication (SCA) to ALL of users
• Compliance
• With the Regulatory Technical Standards (RTS)
• With security
• With the General Data Protection Regulation (GDPR)
• The customer journey and the issue of “obstacles”
All Rights Reserved | FIDO Alliance | Copyright 2018
All Rights Reserved | FIDO Alliance | Copyright 201827
DEPLOYMENT CHALLENGE
28
BANKS HAVE TO PROVIDE SCA TO ALL OF THEIR USERS
Necessity to reach 100% users ➔ multiple devices may be necessary
All Rights Reserved | FIDO Alliance | Copyright 2018
Bank
App
FIDO Standards reduce the cost of
deploying multiple devices
FIDO server
29
BANK CAN USE AN ALREADY DEPLOYED FIDO DEVICE
All Rights Reserved | FIDO Alliance | Copyright 2018
Bank
App
FIDO server
Metadata
server
Device metadata
Public key
uploaded
Device
Attestation
Bank key pair can be
generated in an
existing FIDO device
Private key
securely stored
Bank can check that the FIDO
device is genuine
➔ Attestation mechanism
1
2
Bank can verify that the FIDO
device complies with its
security policy
➔ Verification of device
metadata (characteristics)
3
All Rights Reserved | FIDO Alliance | Copyright 201830
COMPLIANCE CHALLENGE
31
FIDO STANDARDS ARE FULLY IN LINE WITH THE RTS
• Based on multi-factor authentication
• Secure execution environments ranging from hardened
software to TEE to Secure Elements
• Strong focus on privacy and biometrics
All Rights Reserved | FIDO Alliance | Copyright 2018
32
FIDO HELPS COMPLY WITH GDPR
• FIDO’s principle of no shared secrets is in line with GDPR’s “Privacy by
Design”
• Bank keys (private & public) are generated in the authenticator
• Only public key is uploaded to bank’s server
• Local verification (of PIN, of biometric data)
• No hackable data base of authentication credentials
All Rights Reserved | FIDO Alliance | Copyright 2018
All Rights Reserved | FIDO Alliance | Copyright 201833
FIDO COMES WITH A CERTIFICATION PROGRAM
• It is unclear what the National Competent Authorities will define as a
compliant solution
➔ the FIDO certification program can help
• Functional certification
• Authenticator security certification, with the help of independent
accredited labs
• New biometrics certification
All Rights Reserved | FIDO Alliance | Copyright 201834
THE CUSTOMER JOURNEY AND THE
ISSUE OF “OBSTACLES”
All Rights Reserved | FIDO Alliance | Copyright 201835
FIDO SUPPORTS THE REDIRECTION MODEL
PISP
FIDO
device
ASPSP
Login
Pswd Go
Merchant MerchantMerchant
PISP
Bank 1
Bank 2
Bank 3
Select Bank
Approve
ASPSP
app
Example for payment initiation
36
FIDO SUPPORTS THE DECOUPLED MODEL
All Rights Reserved | FIDO Alliance | Copyright 2018
PISP
Merchant Merchant
Approve
Transaction
Merchant
PISP
Merchant
PISP
ASPSP
app
Approve
Transaction
ASPSP
app
FIDO
device
37
ADVANTAGES OF THE REDIRECTION/DECOUPLED MODEL
• Fastest way for a bank to implement SCA
• Re-uses the authentication for bank’s own services
• In line with current practices
• No dependence on other parties
• No impact on the Open APIs
• There is no need for APIs to support authentication in these models
• Some users will feel comfortable authenticating via
the bank’s interface
• Trust
• Familiarity
All Rights Reserved | FIDO Alliance | Copyright 2018
My Bank
All Rights Reserved | FIDO Alliance | Copyright 201838
ACCOUNT AGGREGATION CAN LEAD TO A
CUMBERSOME USER EXPERIENCE
ASPSP C
Login Go
AISP
AISP
ASPSP B
Login
Pswd Go
Confirm
ASPSP
app
39
FIDO FULLY FUNCTIONAL WITH FEDERATED IDENTITY
An interesting solution to cope with the multiple redirection issue
All Rights Reserved | FIDO Alliance | Copyright 2018
AISPAISP IDP
Authenticate
with your device
IDP
app
ASPSP A ASPSP B ASPSP C
AISP
IDP
authentication Access tokens
FIDO device
40
THE EMBEDDED MODEL, AS FIDO LOOKS AT IT
All Rights Reserved | FIDO Alliance | Copyright 2018
AISPAISP AISP
Authenticate with
your device
PISP
Approve
Transaction
Merchant MerchantPISP
Example for account aggregation
Example for payment initiation
41
FIDO HAS ENGAGED WITH API STANDARDISATION BODIES
• Open APIs must support challenge/response mechanisms
• ASPSPs must “white list” the TPPs
• ASPSPs must agree to the user verification step being handled by the
TPP application
All Rights Reserved | FIDO Alliance | Copyright 2018
42
KEY TAKEAWAYS
• FIDO standards: a good solution for any of the authentication models
• Security and Privacy by Design
• Meet all the RTS requirements
• Alignment with authorization frameworks
• FIDO standards maximize reach
• They support a large variety of devices
• FIDO standards: versatile and future proof
• Bank can support the redirection and decoupled models
• Bank can propose the embedded model to TPPs that integrate FIDO authenticators
in their solutions
All Rights Reserved | FIDO Alliance | Copyright 2018
43 All Rights Reserved | FIDO Alliance | Copyright 2018
FIDO & PSD2
White Papers & Resources
Available at fidoalliance.org
44 All Rights Reserved | FIDO Alliance | Copyright 2018
Connect with FIDO

More Related Content

What's hot

Fido Technical Overview
Fido Technical OverviewFido Technical Overview
Fido Technical OverviewFIDO Alliance
 
FIDO UAF 1.0 Specs: Overview and Insights
FIDO UAF 1.0 Specs: Overview and InsightsFIDO UAF 1.0 Specs: Overview and Insights
FIDO UAF 1.0 Specs: Overview and InsightsFIDO Alliance
 
Web Authentication API
Web Authentication APIWeb Authentication API
Web Authentication APIFIDO Alliance
 
IBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptxIBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptxFIDO Alliance
 
Google & FIDO Authentication
Google & FIDO AuthenticationGoogle & FIDO Authentication
Google & FIDO AuthenticationFIDO Alliance
 
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for AndroidDeveloper Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for AndroidFIDO Alliance
 
Technical Considerations for Deploying FIDO Authentication
Technical Considerations for Deploying FIDO Authentication Technical Considerations for Deploying FIDO Authentication
Technical Considerations for Deploying FIDO Authentication FIDO Alliance
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Alliance
 
Integrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation ProtocolsIntegrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation ProtocolsFIDO Alliance
 
Getting Started with FIDO2
Getting Started with FIDO2Getting Started with FIDO2
Getting Started with FIDO2FIDO Alliance
 
Securing a Web App with Passwordless Web Authentication
Securing a Web App with Passwordless Web AuthenticationSecuring a Web App with Passwordless Web Authentication
Securing a Web App with Passwordless Web AuthenticationFIDO Alliance
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Haniyama Wataru
 
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -NadalinNew FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -NadalinFIDO Alliance
 
FIDO and the Future of User Authentication
FIDO and the Future of User AuthenticationFIDO and the Future of User Authentication
FIDO and the Future of User AuthenticationFIDO Alliance
 
IBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxIBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxFIDO Alliance
 
Introduction to FIDO: A New Model for Authentication
Introduction to FIDO: A New Model for AuthenticationIntroduction to FIDO: A New Model for Authentication
Introduction to FIDO: A New Model for AuthenticationFIDO Alliance
 
WebAuthn - The End of the Password As We Know It?
WebAuthn - The End of the Password As We Know It?WebAuthn - The End of the Password As We Know It?
WebAuthn - The End of the Password As We Know It?Thomas Konrad
 
FIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance
 
Implementing WebAuthn & FAPI supports on Keycloak
Implementing WebAuthn & FAPI supports on KeycloakImplementing WebAuthn & FAPI supports on Keycloak
Implementing WebAuthn & FAPI supports on KeycloakYuichi Nakamura
 

What's hot (20)

Fido Technical Overview
Fido Technical OverviewFido Technical Overview
Fido Technical Overview
 
FIDO UAF 1.0 Specs: Overview and Insights
FIDO UAF 1.0 Specs: Overview and InsightsFIDO UAF 1.0 Specs: Overview and Insights
FIDO UAF 1.0 Specs: Overview and Insights
 
Webauthn Tutorial
Webauthn TutorialWebauthn Tutorial
Webauthn Tutorial
 
Web Authentication API
Web Authentication APIWeb Authentication API
Web Authentication API
 
IBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptxIBM - Hey FIDO, Meet Passkey!.pptx
IBM - Hey FIDO, Meet Passkey!.pptx
 
Google & FIDO Authentication
Google & FIDO AuthenticationGoogle & FIDO Authentication
Google & FIDO Authentication
 
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for AndroidDeveloper Tutorial: WebAuthn for Web & FIDO2 for Android
Developer Tutorial: WebAuthn for Web & FIDO2 for Android
 
Technical Considerations for Deploying FIDO Authentication
Technical Considerations for Deploying FIDO Authentication Technical Considerations for Deploying FIDO Authentication
Technical Considerations for Deploying FIDO Authentication
 
FIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for AllFIDO Authentication: Unphishable MFA for All
FIDO Authentication: Unphishable MFA for All
 
Integrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation ProtocolsIntegrating FIDO Authentication & Federation Protocols
Integrating FIDO Authentication & Federation Protocols
 
Getting Started with FIDO2
Getting Started with FIDO2Getting Started with FIDO2
Getting Started with FIDO2
 
Securing a Web App with Passwordless Web Authentication
Securing a Web App with Passwordless Web AuthenticationSecuring a Web App with Passwordless Web Authentication
Securing a Web App with Passwordless Web Authentication
 
Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装Idcon25 FIDO2 の概要と YubiKey の実装
Idcon25 FIDO2 の概要と YubiKey の実装
 
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -NadalinNew FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
New FIDO Specifications Overview -FIDO Alliance -Tokyo Seminar -Nadalin
 
FIDO and the Future of User Authentication
FIDO and the Future of User AuthenticationFIDO and the Future of User Authentication
FIDO and the Future of User Authentication
 
IBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptxIBM: Hey FIDO, Meet Passkey!.pptx
IBM: Hey FIDO, Meet Passkey!.pptx
 
Introduction to FIDO: A New Model for Authentication
Introduction to FIDO: A New Model for AuthenticationIntroduction to FIDO: A New Model for Authentication
Introduction to FIDO: A New Model for Authentication
 
WebAuthn - The End of the Password As We Know It?
WebAuthn - The End of the Password As We Know It?WebAuthn - The End of the Password As We Know It?
WebAuthn - The End of the Password As We Know It?
 
FIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptxFIDO Alliance: Welcome and FIDO Update.pptx
FIDO Alliance: Welcome and FIDO Update.pptx
 
Implementing WebAuthn & FAPI supports on Keycloak
Implementing WebAuthn & FAPI supports on KeycloakImplementing WebAuthn & FAPI supports on Keycloak
Implementing WebAuthn & FAPI supports on Keycloak
 

Similar to FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe

Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...FinTechLabs.io
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationFIDO Alliance
 
Beyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationBeyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationFIDO Alliance
 
FIDO Authentication and GDPR
FIDO Authentication and GDPRFIDO Authentication and GDPR
FIDO Authentication and GDPRFIDO Alliance
 
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...FinTechLabs.io
 
Introduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & StatusIntroduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & StatusFIDO Alliance
 
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance OverviewFIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance OverviewFIDO Alliance
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Alliance
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Alliance
 
FIDO And the Future of User Authentication
FIDO And the Future of User AuthenticationFIDO And the Future of User Authentication
FIDO And the Future of User AuthenticationFIDO Alliance
 
FIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO Alliance
 
Javelin Research's State of Strong Authentication 2019 Report Webinar
Javelin Research's State of Strong Authentication 2019 Report Webinar Javelin Research's State of Strong Authentication 2019 Report Webinar
Javelin Research's State of Strong Authentication 2019 Report Webinar FIDO Alliance
 
Introduction to FIDO Alliance
Introduction to FIDO AllianceIntroduction to FIDO Alliance
Introduction to FIDO AllianceFIDO Alliance
 
FIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government RequirementsFIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government RequirementsFIDO Alliance
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service DirectiveLac Vuong
 
ForgeRock Open banking - Meetup 28/06/2018
ForgeRock Open banking - Meetup 28/06/2018ForgeRock Open banking - Meetup 28/06/2018
ForgeRock Open banking - Meetup 28/06/2018Quentin Castel
 
Introduction to FIDO Authentication
Introduction to FIDO AuthenticationIntroduction to FIDO Authentication
Introduction to FIDO AuthenticationFIDO Alliance
 
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDXapidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDXapidays
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech StartupsLars Markull
 
FIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Alliance
 

Similar to FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe (20)

Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
Open Banking UK “Identity Product” Internals #fapisum - Japan/UK Open Banking...
 
Global Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong AuthenticationGlobal Regulatory Landscape for Strong Authentication
Global Regulatory Landscape for Strong Authentication
 
Beyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer AuthenticationBeyond Passwords: FIDO & the Future of Consumer Authentication
Beyond Passwords: FIDO & the Future of Consumer Authentication
 
FIDO Authentication and GDPR
FIDO Authentication and GDPRFIDO Authentication and GDPR
FIDO Authentication and GDPR
 
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
Trust Frameworks and Open Banking #fapisum - Japan/UK Open Banking and APIs S...
 
Introduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & StatusIntroduction to the FIDO Alliance: Vision & Status
Introduction to the FIDO Alliance: Vision & Status
 
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance OverviewFIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
 
FIDO Authentication Technical Overview
FIDO Authentication Technical OverviewFIDO Authentication Technical Overview
FIDO Authentication Technical Overview
 
FIDO And the Future of User Authentication
FIDO And the Future of User AuthenticationFIDO And the Future of User Authentication
FIDO And the Future of User Authentication
 
FIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong KongFIDO UAF Adoption in Hong Kong
FIDO UAF Adoption in Hong Kong
 
Javelin Research's State of Strong Authentication 2019 Report Webinar
Javelin Research's State of Strong Authentication 2019 Report Webinar Javelin Research's State of Strong Authentication 2019 Report Webinar
Javelin Research's State of Strong Authentication 2019 Report Webinar
 
Introduction to FIDO Alliance
Introduction to FIDO AllianceIntroduction to FIDO Alliance
Introduction to FIDO Alliance
 
FIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government RequirementsFIDO as Regtech - Addressing Government Requirements
FIDO as Regtech - Addressing Government Requirements
 
Open Banking and Payment Service Directive
Open Banking and Payment Service DirectiveOpen Banking and Payment Service Directive
Open Banking and Payment Service Directive
 
ForgeRock Open banking - Meetup 28/06/2018
ForgeRock Open banking - Meetup 28/06/2018ForgeRock Open banking - Meetup 28/06/2018
ForgeRock Open banking - Meetup 28/06/2018
 
Introduction to FIDO Authentication
Introduction to FIDO AuthenticationIntroduction to FIDO Authentication
Introduction to FIDO Authentication
 
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDXapidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
apidays New York 2023 - CATTS out of the bag, Jean-Paul LaClair, FDX
 
figo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startupsfigo Banking API: A Banking Service Provider for FinTech Startups
figo Banking API: A Banking Service Provider for FinTech Startups
 
FIDO Authentication in Hong Kong
FIDO Authentication in Hong KongFIDO Authentication in Hong Kong
FIDO Authentication in Hong Kong
 

More from FIDO Alliance

OTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxOTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxFIDO Alliance
 
CISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxCISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxFIDO Alliance
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)FIDO Alliance
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance
 
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comFIDO Alliance
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向FIDO Alliance
 
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想FIDO Alliance
 
Introduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesIntroduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesFIDO Alliance
 
富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案FIDO Alliance
 
テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察FIDO Alliance
 
「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへFIDO Alliance
 
YubiOnが目指す未来
YubiOnが目指す未来YubiOnが目指す未来
YubiOnが目指す未来FIDO Alliance
 
FIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO Alliance
 
中小企業によるFIDO導入事例
中小企業によるFIDO導入事例中小企業によるFIDO導入事例
中小企業によるFIDO導入事例FIDO Alliance
 
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスVPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスFIDO Alliance
 
CloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークCloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークFIDO Alliance
 
数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポート数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポートFIDO Alliance
 
FIDO Alliance Research: Consumer Attitudes Towards Authentication
FIDO Alliance Research: Consumer Attitudes Towards AuthenticationFIDO Alliance Research: Consumer Attitudes Towards Authentication
FIDO Alliance Research: Consumer Attitudes Towards AuthenticationFIDO Alliance
 
Webinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO AuthenticationWebinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO AuthenticationFIDO Alliance
 
20200303 ISR プライベートセミナー:パスワードのいらない世界へ
20200303 ISR プライベートセミナー:パスワードのいらない世界へ20200303 ISR プライベートセミナー:パスワードのいらない世界へ
20200303 ISR プライベートセミナー:パスワードのいらない世界へFIDO Alliance
 

More from FIDO Alliance (20)

OTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptxOTIS: Our Journey to Passwordless.pptx
OTIS: Our Journey to Passwordless.pptx
 
CISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptxCISA: #MoreThanAPassword.pptx
CISA: #MoreThanAPassword.pptx
 
Introducing FIDO Device Onboard (FDO)
Introducing  FIDO Device Onboard (FDO)Introducing  FIDO Device Onboard (FDO)
Introducing FIDO Device Onboard (FDO)
 
FIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDOFIDO Alliance Webinar: Catch Up WIth FIDO
FIDO Alliance Webinar: Catch Up WIth FIDO
 
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.comConsumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
Consumer Attitudes Toward Strong Authentication & LoginWithFIDO.com
 
新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向新しい認証技術FIDOの最新動向
新しい認証技術FIDOの最新動向
 
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想日立PBI技術を用いた「デバイスフリーリモートワーク」構想
日立PBI技術を用いた「デバイスフリーリモートワーク」構想
 
Introduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS ServicesIntroduction to FIDO and eIDAS Services
Introduction to FIDO and eIDAS Services
 
富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案富士通の生体認証ソリューションと提案
富士通の生体認証ソリューションと提案
 
テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察テレワーク本格導入におけるID認証考察
テレワーク本格導入におけるID認証考察
 
「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ「開けゴマ!」からYubiKeyへ
「開けゴマ!」からYubiKeyへ
 
YubiOnが目指す未来
YubiOnが目指す未来YubiOnが目指す未来
YubiOnが目指す未来
 
FIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみたFIDO2導入してみたを考えてみた
FIDO2導入してみたを考えてみた
 
中小企業によるFIDO導入事例
中小企業によるFIDO導入事例中小企業によるFIDO導入事例
中小企業によるFIDO導入事例
 
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセスVPNはもう卒業!FIDO2認証で次世代リモートアクセス
VPNはもう卒業!FIDO2認証で次世代リモートアクセス
 
CloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワークCloudGate UNOで安全便利なパスワードレスリモートワーク
CloudGate UNOで安全便利なパスワードレスリモートワーク
 
数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポート数々の実績:迅速なFIDO認証の展開をサポート
数々の実績:迅速なFIDO認証の展開をサポート
 
FIDO Alliance Research: Consumer Attitudes Towards Authentication
FIDO Alliance Research: Consumer Attitudes Towards AuthenticationFIDO Alliance Research: Consumer Attitudes Towards Authentication
FIDO Alliance Research: Consumer Attitudes Towards Authentication
 
Webinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO AuthenticationWebinar: Securing IoT with FIDO Authentication
Webinar: Securing IoT with FIDO Authentication
 
20200303 ISR プライベートセミナー:パスワードのいらない世界へ
20200303 ISR プライベートセミナー:パスワードのいらない世界へ20200303 ISR プライベートセミナー:パスワードのいらない世界へ
20200303 ISR プライベートセミナー:パスワードのいらない世界へ
 

Recently uploaded

Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...SUHANI PANDEY
 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceEscorts Call Girls
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...tanu pandey
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtrahman018755
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubaikojalkojal131
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)Delhi Call girls
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...SUHANI PANDEY
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdfMatthew Sinclair
 
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...nilamkumrai
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...SUHANI PANDEY
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...tanu pandey
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查ydyuyu
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftAanSulistiyo
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...nilamkumrai
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls DubaiEscorts Call Girls
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...roncy bisnoi
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...SUHANI PANDEY
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLimonikaupta
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge GraphsEleniIlkou
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Call Girls in Nagpur High Profile
 

Recently uploaded (20)

Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
Shikrapur - Call Girls in Pune Neha 8005736733 | 100% Gennuine High Class Ind...
 
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts ServiceReal Escorts in Al Nahda +971524965298 Dubai Escorts Service
Real Escorts in Al Nahda +971524965298 Dubai Escorts Service
 
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...Nanded City ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready ...
Nanded City ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready ...
 
Real Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirtReal Men Wear Diapers T Shirts sweatshirt
Real Men Wear Diapers T Shirts sweatshirt
 
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls DubaiDubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
Dubai=Desi Dubai Call Girls O525547819 Outdoor Call Girls Dubai
 
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
WhatsApp 📞 8448380779 ✅Call Girls In Mamura Sector 66 ( Noida)
 
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...Russian Call Girls Pune  (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
Russian Call Girls Pune (Adult Only) 8005736733 Escort Service 24x7 Cash Pay...
 
20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf20240508 QFM014 Elixir Reading List April 2024.pdf
20240508 QFM014 Elixir Reading List April 2024.pdf
 
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...
( Pune ) VIP Pimpri Chinchwad Call Girls 🎗️ 9352988975 Sizzling | Escorts | G...
 
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
Yerawada ] Independent Escorts in Pune - Book 8005736733 Call Girls Available...
 
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...Pune Airport ( Call Girls ) Pune  6297143586  Hot Model With Sexy Bhabi Ready...
Pune Airport ( Call Girls ) Pune 6297143586 Hot Model With Sexy Bhabi Ready...
 
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查在线制作约克大学毕业证(yu毕业证)在读证明认证可查
在线制作约克大学毕业证(yu毕业证)在读证明认证可查
 
Microsoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck MicrosoftMicrosoft Azure Arc Customer Deck Microsoft
Microsoft Azure Arc Customer Deck Microsoft
 
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
( Pune ) VIP Baner Call Girls 🎗️ 9352988975 Sizzling | Escorts | Girls Are Re...
 
Al Barsha Night Partner +0567686026 Call Girls Dubai
Al Barsha Night Partner +0567686026 Call Girls  DubaiAl Barsha Night Partner +0567686026 Call Girls  Dubai
Al Barsha Night Partner +0567686026 Call Girls Dubai
 
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
Call Girls Sangvi Call Me 7737669865 Budget Friendly No Advance BookingCall G...
 
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
Pirangut | Call Girls Pune Phone No 8005736733 Elite Escort Service Available...
 
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRLLucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
Lucknow ❤CALL GIRL 88759*99948 ❤CALL GIRLS IN Lucknow ESCORT SERVICE❤CALL GIRL
 
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
2nd Solid Symposium: Solid Pods vs Personal Knowledge Graphs
 
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...Top Rated  Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
Top Rated Pune Call Girls Daund ⟟ 6297143586 ⟟ Call Me For Genuine Sex Servi...
 

FIDO & PSD2: Solving the Strong Customer Authentication Challenge in Europe

  • 1. All Rights Reserved | FIDO Alliance | Copyright 20181 FIDO & PSD2 SOLVING THE STRONG CUSTOMER AUTHENTICATION CHALLENGE IN EUROPE
  • 2. 2 AGENDA PSD2 & Strong Customer Authentication Requirements Beyond Passwords with FIDO2 Bank Challenges & How FIDO Can Help All Rights Reserved | FIDO Alliance | Copyright 2018
  • 3. All Rights Reserved | FIDO Alliance | Copyright 2018 What is PSD2? “An attempt to drive innovation through regulation” • Regulates banks, payment services and other related financial services throughout the European Union (EU) and European Economic Area (EEA) • Goals: • Increase competition and participation in financial services and payments by creating a path for non-bank Third Party Providers (TPPs), including: • Account Information Service Providers (AISPs) – entities that gather data on a user’s accounts and present a unified view of finances, as well as offer advice • Payment Initiation Service Providers (PISPs) – entities that don’t hold payment accounts for users, but do allow users to make payments through them • Give consumers non-bank choices in payments and financial services • Improve consumer protection 3
  • 4. Open APIs 4 • New Access to Account mandate ➔ Open APIs • New Strong Customer Authentication mandate • New Third Party Provider (TPP) roles Open APIs Open APIs Payment execution Open APIs Open APIs Open APIs Gives consent Payment Initiation Service Provider (PISP) Account Information Service Provider (AISP) PSD2 – Key Provisions All Rights Reserved | FIDO Alliance | Copyright 2018
  • 5. All Rights Reserved | FIDO Alliance | Copyright 2018 PSD2: Why Strong Customer Authentication (SCA) Matters If I am going to let a PISP or AISP 1. Access data from my bank account 2. Transfer money from my bank account for a payment My bank needs to: • Authenticate me, and • Know that I have authorized them to do this 5
  • 6. All Rights Reserved | FIDO Alliance | Copyright 2018 How this is often done today “Credential Caching and Screen Scraping” • AISP asks me for my username and password • They store this – and log in with my credentials – sometimes several times a day • They collect (aka “screen scrape”) all my account data to support their service 6
  • 7. All Rights Reserved | FIDO Alliance | Copyright 2018 Screen Scraping – Some Issues 1. We tell people “never share your password” • This requires people to trust a third party with their username and password • Looks like a phishing attack 2. Passwords are fundamentally insecure • Letting additional parties store passwords and other “shared secrets” raises risks • Often breaks tools that protect the login process, including multi-factor authentication (MFA) and behavior analytics 3. Issues with privacy and consent • I think I am granting access to a small part of my account – but the TPP may get access to all of it • No way for a consumer to authorize access on a granular level • GDPR concerns 7
  • 8. Open APIs • Third parties can securely connect to a bank – no need to cache passwords • Banks can share data directly with third parties – no screen scraping needed • Banks can enable third party payment providers to initiate payments • Customers can let their bank know they explicitly authorize access, and can manage access on a granular level Open APIs Open APIs Payment execution Open APIs Open APIs Open APIs Gives consent Payment Initiation Service Provider (PISP) Account Information Service Provider (AISP) How to address this: Open APIs All Rights Reserved | FIDO Alliance | Copyright 20188
  • 9. All Rights Reserved | FIDO Alliance | Copyright 2018 PSD2 SCA – Key Dates • November 2017 – Final RTS published by EC • September 2019 – Effective Date of RTS • March 2019 - Banks must be ready 6 months before effective date • Banks must make interfaces available to TPPs for testing http://ec.europa.eu/finance/docs/level-2-measures/psd2-rts-2017-7782_en.pdf 9
  • 10. All Rights Reserved | FIDO Alliance | Copyright 2018 What the EBA Strong Customer Authentication (SCA)rules require Transactions require Multi-Factor Authentication (MFA) - 2 of 3 elements: ▸ Something you know (password or PIN) ▸ Something you possess (phone, token, card) ▸ Something you are (biometric) Passw00rd A “multi-purpose” device must protect the independence of authentication elements 10
  • 11. All Rights Reserved | FIDO Alliance | Copyright 2018 Requirements around user experience EC concerns that banks would build bad APIs or otherwise create obstacles to them accessing consumer accounts – led to a ban on “obstacles” to access. ▸ One example: a “redirect” model used with an API “may” be an obstacle ▸ However, EC has been clear this was only an example – and there may be redirect implementations that do not cause obstacles ▸ If any obstacles exist – mandate to shift to a “fall-back” option (a non-API interface) based on caching customer’s banking passwords 11
  • 12. All Rights Reserved | FIDO Alliance | Copyright 2018 Some implications The “redirect model” is industry-accepted best practice for how a consumer can log in to one account with a credential from another ▸ Based on proven standards (OAuth 2.0, OpenID Connect, FIDO) ▸ Dozens of vendors lined up behind it ▸ UK Open Banking Implementation Entity (OBIE) has already created standards based on redirect The key: how to implement it with an excellent user experience ▸ FIDO implementations can streamline the authentication process – delivering strong customer authentication more efficiently than other MFA tools. 12
  • 13. All Rights Reserved | FIDO Alliance | Copyright 2018 Will we see PSD2 in the US? • Unlikely that a regulation forces action • But – Open Banking and Open Payments is happening • The key is whether industry can figure it out themselves, rather than have the government prescribe how to do it 13
  • 14. All Rights Reserved | FIDO Alliance | Copyright 2018 Open Banking Standards in the US https://www.fsisac.com/article/fs-isac-enables-safer-financial-data-sharing-api Want a copy? Reach out to Eric Guerrino at eguerrino@fsisac.com 14
  • 15. All Rights Reserved | FIDO Alliance | Copyright 2018 Highlights of US FS-ISAC approach • Standard APIs to enable secure third-party access • When a consumer wishes to set up or add a bank, brokerage, or insurance account to a third-party service, they will be seamlessly passed to a secure server at their financial institution to begin the enrollment process. • The consumer is presented with the financial institution’s consent page, where they authorize which data or access privileges they wish to share with the financial application, giving consumers control. • After authenticating, the consumer is then seamlessly passed back to the financial application. Data sharing between financial application servers and financial institution servers is then done securely via a unique virtual token that identifies the consumer and their respective accounts. • Standards recommended: OAuth, OpenID Connect, FIDO 15
  • 16. All Rights Reserved | FIDO Alliance | Copyright 2018 Details on SCA in the FS-ISAC Approach • “OAuth 2.0 is the foundation for OpenID Connect 1.0. OpenID Connect 1.0 when used will promote secure user federation. Fast IDentity Online (FIDO) 1.1 forms the design pattern for authenticating the consumer to allow maximum user agent interoperability to better support public client agent applications. Use of these patterns should enable FIs to increase aggregator onboarding velocity in a holistically secure and governable access model.” • “All FIDO 1.1 security considerations should be observed and accounted for in the final implementations of the FIDO 1.1 specifications for both aggregators and FIs (where FIDO is used) to reduce vulnerabilities associated with this authentication method.” • “Use of Fast IDentity Online 1.1 (FIDO) Universal Authentication Framework (UAF) as an authentication method is recommended (in the absence of a similarly capable FI solution) during the OAuth and OIDC sequence to support strong initial user authentication. FIDO protocol challenge should be used by the FIDO server to activate the FIDO authentication framework and protocol sequence. FIDO client registration may also be included as part of the authentication sequence where the customer’s user agent is FIDO- capable (and FI policy provision allows), but not yet known to the FI’s FIDO server.” • “FIDO Universal 2nd Factor (U2F) capability, which uses a hardware device to store identity tokens, might also be used to strongly ensure and verify customer identity and presence executing high-risk operation(s). The FIDO client that implements U2F API must be present on the user agent platform to respond to the FIDO server 2FA challenge and utilize the FIDO hardware device to retrieve user identity keys registered with the FI FIDO server for aggregation API MFA / 2FA.” *From “Control Considerations for Consumer Financial Account Aggregation Services” by the FS-ISAC 16
  • 17. 17 AGENDA PSD2 & Strong Customer Authentication Requirements Beyond Passwords with FIDO2 Bank Challenges & How FIDO Can Help All Rights Reserved | FIDO Alliance | Copyright 2018
  • 18. All Rights Reserved | FIDO Alliance | Copyright 201818 The World Has a Password Problem Data breaches in 2016 that involved weak, default, or stolen passwords1 81% Phishing attacks were successful in 20161 Breaches in 2017, a 45% increase over 20162 1 IN 14 1,579 CLUMSY | HARD TO REMEMBER | NEED TO BE CHANGED ALL THE TIME
  • 19. All Rights Reserved | FIDO Alliance | Copyright 201819 The Solution: Simpler *and* Stronger open standards for simpler, stronger authentication using public key cryptography Single Gesture Phishing-resistant MFA = SECURITY USABILITY Poor Easy WeakStrong
  • 20. All Rights Reserved | FIDO Alliance | Copyright 201820 How Does FIDO Work? AuthenticatorUser verification FIDO Authentication Require user gesture before private key can be used Challenge (Signed) Response Private key (handle) per account Public key
  • 21. All Rights Reserved | FIDO Alliance | Copyright 201821 Who is using FIDO today? (Sample of deployments in production)
  • 22. All Rights Reserved | FIDO Alliance | Copyright 201822 FIDO Specifications FIDO UAF FIDO U2F (@FIDO) CTAP (@FIDO) WebAuthn (@W3C) FIDO2 Project
  • 23. All Rights Reserved | FIDO Alliance | Copyright 201823 WebAuthn Brings FIDO to the Web Browser Participation from all these platform providers World Wide Web Consortium (W3C) developed Web Authentication (“WebAuthn”) with FIDO Alliance Contributions Candidate Recommendation A new standard JavaScript API That works with all FIDO2 platforms & authenticators
  • 24. All Rights Reserved | FIDO Alliance | Copyright 201824 FIDO “UNIVERSAL SERVER” Program Ensures interoperability with all FIDO Certified Authenticators FIDO Universal Server
  • 25. 25 AGENDA PSD2 & Strong Customer Authentication Requirements Beyond Passwords with FIDO2 Bank Challenges & How FIDO Can Help All Rights Reserved | FIDO Alliance | Copyright 2018
  • 26. 26 BANK CHALLENGES WITH PSD2 IMPLEMENTATION • Deployment of Strong Customer Authentication (SCA) to ALL of users • Compliance • With the Regulatory Technical Standards (RTS) • With security • With the General Data Protection Regulation (GDPR) • The customer journey and the issue of “obstacles” All Rights Reserved | FIDO Alliance | Copyright 2018
  • 27. All Rights Reserved | FIDO Alliance | Copyright 201827 DEPLOYMENT CHALLENGE
  • 28. 28 BANKS HAVE TO PROVIDE SCA TO ALL OF THEIR USERS Necessity to reach 100% users ➔ multiple devices may be necessary All Rights Reserved | FIDO Alliance | Copyright 2018 Bank App FIDO Standards reduce the cost of deploying multiple devices FIDO server
  • 29. 29 BANK CAN USE AN ALREADY DEPLOYED FIDO DEVICE All Rights Reserved | FIDO Alliance | Copyright 2018 Bank App FIDO server Metadata server Device metadata Public key uploaded Device Attestation Bank key pair can be generated in an existing FIDO device Private key securely stored Bank can check that the FIDO device is genuine ➔ Attestation mechanism 1 2 Bank can verify that the FIDO device complies with its security policy ➔ Verification of device metadata (characteristics) 3
  • 30. All Rights Reserved | FIDO Alliance | Copyright 201830 COMPLIANCE CHALLENGE
  • 31. 31 FIDO STANDARDS ARE FULLY IN LINE WITH THE RTS • Based on multi-factor authentication • Secure execution environments ranging from hardened software to TEE to Secure Elements • Strong focus on privacy and biometrics All Rights Reserved | FIDO Alliance | Copyright 2018
  • 32. 32 FIDO HELPS COMPLY WITH GDPR • FIDO’s principle of no shared secrets is in line with GDPR’s “Privacy by Design” • Bank keys (private & public) are generated in the authenticator • Only public key is uploaded to bank’s server • Local verification (of PIN, of biometric data) • No hackable data base of authentication credentials All Rights Reserved | FIDO Alliance | Copyright 2018
  • 33. All Rights Reserved | FIDO Alliance | Copyright 201833 FIDO COMES WITH A CERTIFICATION PROGRAM • It is unclear what the National Competent Authorities will define as a compliant solution ➔ the FIDO certification program can help • Functional certification • Authenticator security certification, with the help of independent accredited labs • New biometrics certification
  • 34. All Rights Reserved | FIDO Alliance | Copyright 201834 THE CUSTOMER JOURNEY AND THE ISSUE OF “OBSTACLES”
  • 35. All Rights Reserved | FIDO Alliance | Copyright 201835 FIDO SUPPORTS THE REDIRECTION MODEL PISP FIDO device ASPSP Login Pswd Go Merchant MerchantMerchant PISP Bank 1 Bank 2 Bank 3 Select Bank Approve ASPSP app Example for payment initiation
  • 36. 36 FIDO SUPPORTS THE DECOUPLED MODEL All Rights Reserved | FIDO Alliance | Copyright 2018 PISP Merchant Merchant Approve Transaction Merchant PISP Merchant PISP ASPSP app Approve Transaction ASPSP app FIDO device
  • 37. 37 ADVANTAGES OF THE REDIRECTION/DECOUPLED MODEL • Fastest way for a bank to implement SCA • Re-uses the authentication for bank’s own services • In line with current practices • No dependence on other parties • No impact on the Open APIs • There is no need for APIs to support authentication in these models • Some users will feel comfortable authenticating via the bank’s interface • Trust • Familiarity All Rights Reserved | FIDO Alliance | Copyright 2018 My Bank
  • 38. All Rights Reserved | FIDO Alliance | Copyright 201838 ACCOUNT AGGREGATION CAN LEAD TO A CUMBERSOME USER EXPERIENCE ASPSP C Login Go AISP AISP ASPSP B Login Pswd Go Confirm ASPSP app
  • 39. 39 FIDO FULLY FUNCTIONAL WITH FEDERATED IDENTITY An interesting solution to cope with the multiple redirection issue All Rights Reserved | FIDO Alliance | Copyright 2018 AISPAISP IDP Authenticate with your device IDP app ASPSP A ASPSP B ASPSP C AISP IDP authentication Access tokens FIDO device
  • 40. 40 THE EMBEDDED MODEL, AS FIDO LOOKS AT IT All Rights Reserved | FIDO Alliance | Copyright 2018 AISPAISP AISP Authenticate with your device PISP Approve Transaction Merchant MerchantPISP Example for account aggregation Example for payment initiation
  • 41. 41 FIDO HAS ENGAGED WITH API STANDARDISATION BODIES • Open APIs must support challenge/response mechanisms • ASPSPs must “white list” the TPPs • ASPSPs must agree to the user verification step being handled by the TPP application All Rights Reserved | FIDO Alliance | Copyright 2018
  • 42. 42 KEY TAKEAWAYS • FIDO standards: a good solution for any of the authentication models • Security and Privacy by Design • Meet all the RTS requirements • Alignment with authorization frameworks • FIDO standards maximize reach • They support a large variety of devices • FIDO standards: versatile and future proof • Bank can support the redirection and decoupled models • Bank can propose the embedded model to TPPs that integrate FIDO authenticators in their solutions All Rights Reserved | FIDO Alliance | Copyright 2018
  • 43. 43 All Rights Reserved | FIDO Alliance | Copyright 2018 FIDO & PSD2 White Papers & Resources Available at fidoalliance.org
  • 44. 44 All Rights Reserved | FIDO Alliance | Copyright 2018 Connect with FIDO