SlideShare a Scribd company logo
The Role of IAM in Open Banking
&
Where Do We Stand?
Colombo IAM User Group - 2nd Meetup
Pushpalanka Jayawardhana
Financial Solutions Team - WSO2
“Banking is necessary; banks are not”
- (Bill Gates, 1990)
International Financial Industry
Concerns
➢Contribute to a more integrated and
efficient European payments market
➢Improve the level playing field for PSPs
(including new players)
➢Make payments safer and more secure
➢Online shopping without a credit card
➢Better protection against fraud
➢Help lower charges for consumers on
card payments
Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf
Payment Card Industry Security Standards
For protection of cardholder payment data,
Payment Services Directive 2
EU Directive that applies to
all Banks operating in the EU
that regulates payment
services throughout the EU,
with a compliance deadline of
January 2018
Open Banking
1 : Possible central view
Banks expose their customer payment and account data, with customer consent, to
Third party Payment Providers (TPPs) via APIs.
TPP
PISP/AISP
Bank A
Bank B
Bank C
Merchant
Now PSD2
Bank A
Bank B
Bank C
Merchant
Open Banking
2 : No Involvement of Card Network
7
➢ Less hops
➢ Lower fees for transactions
➢ Easy to track the path
Aggregated View of Accounts (AISP
Flow)
Payment Flow (PISP)
Credits to Dinosoft Labs from Noun Project
Checkout
Item
Login Page
2 Factor Authentication
Customer Consent
Initiation
payment info
1
2
3
4
PISP
302
5
Token 6
Payment
Complete
7
Settlement
PSD2 Compliance Requirements
➢ API Specification
○ API Definitions
○ Secured API invocation
○ API Usage Monitoring
➢ Strong Customer Authentication
○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin)
○ Adaptive Authentication
○ Consent Management
➢ Incident Reporting
○ Security Incident Reporting [Transactions affected,server downtime, Economic
Strong Customer Authentication
Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Strong Customer Authentication Ctd..
Adaptive Authentication
➢ Authentication flow is defined by risk level
➢ PSD2 define several exemptions for SCA applications
○ Not to kill user experience for small transactions and bulk transactions
➢ Security level can be decided based on,
○ The amount of transaction
○ Time elapsed from previous SCA
○ Transaction patterns on user
○ Role of user - Cooperate or private
Consent Management
➢ Defined by PSD2 RTS on SCA and secure communication and GDPR
➢ Safeguard right of the user on personal data to,
○ be informed - Inform user of personal data collection
○ access - Validate information processing at any time
○ rectification - When user feels data is incomplete or accurate
○ restrict data processing - Just store, don’t process
○ data portability - Transfer data to another party
○ forgotten - Request removal of personal data
○ be notified on a data breach - Report to user within 72 hours
No Screen Scraping
Technology Requirements
“Draft Regulatory Technical Standards, explicitly mentions to be based on
known standards”
● User authentication (with SSO)
○ SAML 2.0
○ OpenID Connect
● Access delegation - OAuth 2.0
● Fine grained authorization - XACML
● Multifactor authentication - SMSOTP, FIDO, DUO, MePin
16
Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf
Other Standards
ISO 27001 - for information security management systems
ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
Inside Story - Open Banking
DEMO
With https://openbanking.wso2.com/
Open Banking: The opportunities
Bank A
Bank B
Bank C
Merchant Bank A
Consolidated
customer account and
payment info across
multiple Banks
TPPTPP
App Development
Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2
1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country
e.g. EUR payment from France to Sri Lanka
1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country
e.g. LKR payment from UK to Sri Lanka
1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country
e.g. EUR payment from Sri Lanka to France
1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country
e.g. LKR payment from Sri Lanka to UK
PSD2 Impact
on Us
Banking Industry in Sri Lanka
➢ Sri Lanka Interbank Payment System (SLIPS)
○ Same day electronic fund transfer
○ Established in 2010, being first in South Asia
➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS)
○ For real-time payments
○ Initiated in 2015
➢ JustPay - From LankaClear (pvt) Ltd
○ Applies 2FA
○ For real time retail payments under Rs. 10 000/=
○ Central Bank of Sri Lanka (CBSL) approved security standards
➢ Have already thought on AISP like applications
➢ Have the foundation of collaboration among banks in real time
JustPay© - http://www.lankaclear.com/product_service/42-overview
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Monetization of applications will be made
easy...
Q & A
Twitter : @Pushpalanka
LinkedIn : https://www.linkedin.com/in/pushpalanka/
WSO2 Open Banking : https://openbanking.wso2.com/
Thank You!

More Related Content

What's hot

Open Banking APIs on AWS
Open Banking APIs on AWSOpen Banking APIs on AWS
Open Banking APIs on AWS
Amazon Web Services
 
Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation
WSO2
 
Digital Bank: What and How
Digital Bank: What and HowDigital Bank: What and How
Digital Bank: What and How
Ivano Digital
 
Global Payment System- Reference Architecture
Global Payment System- Reference ArchitectureGlobal Payment System- Reference Architecture
Global Payment System- Reference ArchitectureRamadas MV
 
Webinar: Practical use-cases to monetize Open Banking APIs
Webinar: Practical use-cases to monetize Open Banking APIsWebinar: Practical use-cases to monetize Open Banking APIs
Webinar: Practical use-cases to monetize Open Banking APIs
ShubaS4
 
Demystifying Open Banking
Demystifying Open BankingDemystifying Open Banking
Demystifying Open Banking
accenture
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
Amazon Web Services
 
The future of banking
The future of bankingThe future of banking
The future of banking
Barbara Biro
 
E-sewa (a largest e-commerce website in Nepal)
E-sewa (a largest e-commerce website in Nepal)E-sewa (a largest e-commerce website in Nepal)
E-sewa (a largest e-commerce website in Nepal)
samunnatadhikari
 
Secure and practical authentication in API Platform
Secure and practical authentication in API PlatformSecure and practical authentication in API Platform
Secure and practical authentication in API Platform
Robin Chalas
 
Peter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online PaymentsPeter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online Payments
Ciklum Ukraine
 
Open banking-Future of Banking
Open banking-Future of BankingOpen banking-Future of Banking
Open banking-Future of Banking
farhan ali
 
How Wireless Healthcare Systems benefit from 5G
How Wireless Healthcare Systems benefit from 5GHow Wireless Healthcare Systems benefit from 5G
How Wireless Healthcare Systems benefit from 5G
msh7610
 
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / FintechDigital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
Sameer Singh Jaini
 
Open Banking - The Digital Transformation Opportunity in Disguise
Open Banking - The Digital Transformation Opportunity in Disguise Open Banking - The Digital Transformation Opportunity in Disguise
Open Banking - The Digital Transformation Opportunity in Disguise
WSO2
 
Chase Bank Digital Strategy
Chase Bank Digital Strategy Chase Bank Digital Strategy
Chase Bank Digital Strategy
Sierra Resovsky
 
Banking-as-a-Service 2.0 - Executive Summary
Banking-as-a-Service 2.0 - Executive SummaryBanking-as-a-Service 2.0 - Executive Summary
Banking-as-a-Service 2.0 - Executive Summary
MEDICI Inner Circle
 
Vitesse - InsurTech Innovation Award 2022
Vitesse - InsurTech Innovation Award 2022Vitesse - InsurTech Innovation Award 2022
Vitesse - InsurTech Innovation Award 2022
The Digital Insurer
 
PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services Directive
Emilie Scalla
 
UKCCC: Open Banking Introduction
UKCCC: Open Banking IntroductionUKCCC: Open Banking Introduction
UKCCC: Open Banking Introduction
Freddy Kelly
 

What's hot (20)

Open Banking APIs on AWS
Open Banking APIs on AWSOpen Banking APIs on AWS
Open Banking APIs on AWS
 
Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation Open Banking - Opening the door to Digital Transformation
Open Banking - Opening the door to Digital Transformation
 
Digital Bank: What and How
Digital Bank: What and HowDigital Bank: What and How
Digital Bank: What and How
 
Global Payment System- Reference Architecture
Global Payment System- Reference ArchitectureGlobal Payment System- Reference Architecture
Global Payment System- Reference Architecture
 
Webinar: Practical use-cases to monetize Open Banking APIs
Webinar: Practical use-cases to monetize Open Banking APIsWebinar: Practical use-cases to monetize Open Banking APIs
Webinar: Practical use-cases to monetize Open Banking APIs
 
Demystifying Open Banking
Demystifying Open BankingDemystifying Open Banking
Demystifying Open Banking
 
Open banking as a service
Open banking as a serviceOpen banking as a service
Open banking as a service
 
The future of banking
The future of bankingThe future of banking
The future of banking
 
E-sewa (a largest e-commerce website in Nepal)
E-sewa (a largest e-commerce website in Nepal)E-sewa (a largest e-commerce website in Nepal)
E-sewa (a largest e-commerce website in Nepal)
 
Secure and practical authentication in API Platform
Secure and practical authentication in API PlatformSecure and practical authentication in API Platform
Secure and practical authentication in API Platform
 
Peter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online PaymentsPeter Afanasiev - Architecture of online Payments
Peter Afanasiev - Architecture of online Payments
 
Open banking-Future of Banking
Open banking-Future of BankingOpen banking-Future of Banking
Open banking-Future of Banking
 
How Wireless Healthcare Systems benefit from 5G
How Wireless Healthcare Systems benefit from 5GHow Wireless Healthcare Systems benefit from 5G
How Wireless Healthcare Systems benefit from 5G
 
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / FintechDigital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
Digital strategy for Banks / NBFCs / Insurance / Mutual Funds / Fintech
 
Open Banking - The Digital Transformation Opportunity in Disguise
Open Banking - The Digital Transformation Opportunity in Disguise Open Banking - The Digital Transformation Opportunity in Disguise
Open Banking - The Digital Transformation Opportunity in Disguise
 
Chase Bank Digital Strategy
Chase Bank Digital Strategy Chase Bank Digital Strategy
Chase Bank Digital Strategy
 
Banking-as-a-Service 2.0 - Executive Summary
Banking-as-a-Service 2.0 - Executive SummaryBanking-as-a-Service 2.0 - Executive Summary
Banking-as-a-Service 2.0 - Executive Summary
 
Vitesse - InsurTech Innovation Award 2022
Vitesse - InsurTech Innovation Award 2022Vitesse - InsurTech Innovation Award 2022
Vitesse - InsurTech Innovation Award 2022
 
PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services Directive
 
UKCCC: Open Banking Introduction
UKCCC: Open Banking IntroductionUKCCC: Open Banking Introduction
UKCCC: Open Banking Introduction
 

Similar to The role of IAM in OpenBanking and where do we stand

An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)
Paul Ark (Polapat Arkkrapridi)
 
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Forums financiers de Wallonie
 
PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
TransUnion
 
DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022
FinTech Belgium
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
FinTech Belgium
 
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony VerhelpenFintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
FinTech Belgium
 
Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts
Osborne Clarke
 
Beyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial InclusionBeyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial Inclusion
37coins
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity
ForgeRock
 
Getting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 ComplianceGetting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 Compliance
WSO2
 
Cryptocurrencies and AML
Cryptocurrencies and AMLCryptocurrencies and AML
Cryptocurrencies and AML
Minerva
 
Risk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTechRisk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTech
Geo Coelho
 
Master class Fintech
Master class FintechMaster class Fintech
Master class Fintech
Gerard Alba
 
Psd2 brochure
Psd2 brochurePsd2 brochure
Psd2 brochure
MirandaCarterGibbs
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016
Pietro Bezza
 
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
Accenture Italia
 
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Starttech Ventures
 
The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5
Jomari Peterson
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
senakafdo
 

Similar to The role of IAM in OpenBanking and where do we stand (20)

An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)An Introduction to Open Banking (PSD2)
An Introduction to Open Banking (PSD2)
 
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
 
PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
 
DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
 
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony VerhelpenFintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
 
Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts
 
Beyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial InclusionBeyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial Inclusion
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity
 
Getting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 ComplianceGetting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 Compliance
 
Cryptocurrencies and AML
Cryptocurrencies and AMLCryptocurrencies and AML
Cryptocurrencies and AML
 
Risk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTechRisk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTech
 
Master class Fintech
Master class FintechMaster class Fintech
Master class Fintech
 
Psd2 brochure
Psd2 brochurePsd2 brochure
Psd2 brochure
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016
 
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
 
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
 
The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5
 
Finance Presentation
Finance PresentationFinance Presentation
Finance Presentation
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
 

More from Pushpalanka Jayawardhana

Authorization for workloads in a dynamically scaling heterogeneous system
Authorization for workloads in a  dynamically scaling heterogeneous systemAuthorization for workloads in a  dynamically scaling heterogeneous system
Authorization for workloads in a dynamically scaling heterogeneous system
Pushpalanka Jayawardhana
 
Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2
Pushpalanka Jayawardhana
 
Identity mediation for enterprise identity bus
Identity mediation for enterprise identity busIdentity mediation for enterprise identity bus
Identity mediation for enterprise identity bus
Pushpalanka Jayawardhana
 
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread PoolsThreads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Pushpalanka Jayawardhana
 
Approximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule MiningApproximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule Mining
Pushpalanka Jayawardhana
 
Leveraging federation capabilities of identity server for api gateway
Leveraging federation capabilities  of identity server for api gatewayLeveraging federation capabilities  of identity server for api gateway
Leveraging federation capabilities of identity server for api gateway
Pushpalanka Jayawardhana
 
Feedback queuing models for time shared systems
Feedback queuing models for time shared systemsFeedback queuing models for time shared systems
Feedback queuing models for time shared systems
Pushpalanka Jayawardhana
 
Big Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - KanthakaBig Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - Kanthaka
Pushpalanka Jayawardhana
 
Kanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR AnalyzerKanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR Analyzer
Pushpalanka Jayawardhana
 
Experience at WSO2 as an Intern
Experience at WSO2 as an InternExperience at WSO2 as an Intern
Experience at WSO2 as an Intern
Pushpalanka Jayawardhana
 
Cosmology in general
Cosmology in generalCosmology in general
Cosmology in general
Pushpalanka Jayawardhana
 

More from Pushpalanka Jayawardhana (11)

Authorization for workloads in a dynamically scaling heterogeneous system
Authorization for workloads in a  dynamically scaling heterogeneous systemAuthorization for workloads in a  dynamically scaling heterogeneous system
Authorization for workloads in a dynamically scaling heterogeneous system
 
Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2
 
Identity mediation for enterprise identity bus
Identity mediation for enterprise identity busIdentity mediation for enterprise identity bus
Identity mediation for enterprise identity bus
 
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread PoolsThreads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread Pools
 
Approximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule MiningApproximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule Mining
 
Leveraging federation capabilities of identity server for api gateway
Leveraging federation capabilities  of identity server for api gatewayLeveraging federation capabilities  of identity server for api gateway
Leveraging federation capabilities of identity server for api gateway
 
Feedback queuing models for time shared systems
Feedback queuing models for time shared systemsFeedback queuing models for time shared systems
Feedback queuing models for time shared systems
 
Big Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - KanthakaBig Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - Kanthaka
 
Kanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR AnalyzerKanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR Analyzer
 
Experience at WSO2 as an Intern
Experience at WSO2 as an InternExperience at WSO2 as an Intern
Experience at WSO2 as an Intern
 
Cosmology in general
Cosmology in generalCosmology in general
Cosmology in general
 

Recently uploaded

Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit CardPoonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
nickysharmasucks
 
what is the best method to sell pi coins in 2024
what is the best method to sell pi coins in 2024what is the best method to sell pi coins in 2024
what is the best method to sell pi coins in 2024
DOT TECH
 
655264371-checkpoint-science-past-papers-april-2023.pdf
655264371-checkpoint-science-past-papers-april-2023.pdf655264371-checkpoint-science-past-papers-april-2023.pdf
655264371-checkpoint-science-past-papers-april-2023.pdf
morearsh02
 
Economics and Economic reasoning Chap. 1
Economics and Economic reasoning Chap. 1Economics and Economic reasoning Chap. 1
Economics and Economic reasoning Chap. 1
Fitri Safira
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
shetivia
 
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
Amil Baba Dawood bangali
 
The new type of smart, sustainable entrepreneurship and the next day | Europe...
The new type of smart, sustainable entrepreneurship and the next day | Europe...The new type of smart, sustainable entrepreneurship and the next day | Europe...
The new type of smart, sustainable entrepreneurship and the next day | Europe...
Antonis Zairis
 
The European Unemployment Puzzle: implications from population aging
The European Unemployment Puzzle: implications from population agingThe European Unemployment Puzzle: implications from population aging
The European Unemployment Puzzle: implications from population aging
GRAPE
 
how to sell pi coins on Binance exchange
how to sell pi coins on Binance exchangehow to sell pi coins on Binance exchange
how to sell pi coins on Binance exchange
DOT TECH
 
PF-Wagner's Theory of Public Expenditure.pptx
PF-Wagner's Theory of Public Expenditure.pptxPF-Wagner's Theory of Public Expenditure.pptx
PF-Wagner's Theory of Public Expenditure.pptx
GunjanSharma28848
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
DOT TECH
 
how to sell pi coins effectively (from 50 - 100k pi)
how to sell pi coins effectively (from 50 - 100k  pi)how to sell pi coins effectively (from 50 - 100k  pi)
how to sell pi coins effectively (from 50 - 100k pi)
DOT TECH
 
Proposer Builder Separation Problem in Ethereum
Proposer Builder Separation Problem in EthereumProposer Builder Separation Problem in Ethereum
Proposer Builder Separation Problem in Ethereum
RasoulRamezanian1
 
how can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYChow can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYC
DOT TECH
 
how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.
DOT TECH
 
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
Vighnesh Shashtri
 
Greek trade a pillar of dynamic economic growth - European Business Review
Greek trade a pillar of dynamic economic growth - European Business ReviewGreek trade a pillar of dynamic economic growth - European Business Review
Greek trade a pillar of dynamic economic growth - European Business Review
Antonis Zairis
 
Scope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theoriesScope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theories
nomankalyar153
 
Falcon Invoice Discounting: Optimizing Returns with Minimal Risk
Falcon Invoice Discounting: Optimizing Returns with Minimal RiskFalcon Invoice Discounting: Optimizing Returns with Minimal Risk
Falcon Invoice Discounting: Optimizing Returns with Minimal Risk
Falcon Invoice Discounting
 
US Economic Outlook - Being Decided - M Capital Group August 2021.pdf
US Economic Outlook - Being Decided - M Capital Group August 2021.pdfUS Economic Outlook - Being Decided - M Capital Group August 2021.pdf
US Economic Outlook - Being Decided - M Capital Group August 2021.pdf
pchutichetpong
 

Recently uploaded (20)

Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit CardPoonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
Poonawalla Fincorp and IndusInd Bank Introduce New Co-Branded Credit Card
 
what is the best method to sell pi coins in 2024
what is the best method to sell pi coins in 2024what is the best method to sell pi coins in 2024
what is the best method to sell pi coins in 2024
 
655264371-checkpoint-science-past-papers-april-2023.pdf
655264371-checkpoint-science-past-papers-april-2023.pdf655264371-checkpoint-science-past-papers-april-2023.pdf
655264371-checkpoint-science-past-papers-april-2023.pdf
 
Economics and Economic reasoning Chap. 1
Economics and Economic reasoning Chap. 1Economics and Economic reasoning Chap. 1
Economics and Economic reasoning Chap. 1
 
Intro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptxIntro_Economics_ GPresentation Week 4.pptx
Intro_Economics_ GPresentation Week 4.pptx
 
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
NO1 Uk Divorce problem uk all amil baba in karachi,lahore,pakistan talaq ka m...
 
The new type of smart, sustainable entrepreneurship and the next day | Europe...
The new type of smart, sustainable entrepreneurship and the next day | Europe...The new type of smart, sustainable entrepreneurship and the next day | Europe...
The new type of smart, sustainable entrepreneurship and the next day | Europe...
 
The European Unemployment Puzzle: implications from population aging
The European Unemployment Puzzle: implications from population agingThe European Unemployment Puzzle: implications from population aging
The European Unemployment Puzzle: implications from population aging
 
how to sell pi coins on Binance exchange
how to sell pi coins on Binance exchangehow to sell pi coins on Binance exchange
how to sell pi coins on Binance exchange
 
PF-Wagner's Theory of Public Expenditure.pptx
PF-Wagner's Theory of Public Expenditure.pptxPF-Wagner's Theory of Public Expenditure.pptx
PF-Wagner's Theory of Public Expenditure.pptx
 
The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.The secret way to sell pi coins effortlessly.
The secret way to sell pi coins effortlessly.
 
how to sell pi coins effectively (from 50 - 100k pi)
how to sell pi coins effectively (from 50 - 100k  pi)how to sell pi coins effectively (from 50 - 100k  pi)
how to sell pi coins effectively (from 50 - 100k pi)
 
Proposer Builder Separation Problem in Ethereum
Proposer Builder Separation Problem in EthereumProposer Builder Separation Problem in Ethereum
Proposer Builder Separation Problem in Ethereum
 
how can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYChow can I sell pi coins after successfully completing KYC
how can I sell pi coins after successfully completing KYC
 
how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.how to sell pi coins at high rate quickly.
how to sell pi coins at high rate quickly.
 
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
Empowering the Unbanked: The Vital Role of NBFCs in Promoting Financial Inclu...
 
Greek trade a pillar of dynamic economic growth - European Business Review
Greek trade a pillar of dynamic economic growth - European Business ReviewGreek trade a pillar of dynamic economic growth - European Business Review
Greek trade a pillar of dynamic economic growth - European Business Review
 
Scope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theoriesScope Of Macroeconomics introduction and basic theories
Scope Of Macroeconomics introduction and basic theories
 
Falcon Invoice Discounting: Optimizing Returns with Minimal Risk
Falcon Invoice Discounting: Optimizing Returns with Minimal RiskFalcon Invoice Discounting: Optimizing Returns with Minimal Risk
Falcon Invoice Discounting: Optimizing Returns with Minimal Risk
 
US Economic Outlook - Being Decided - M Capital Group August 2021.pdf
US Economic Outlook - Being Decided - M Capital Group August 2021.pdfUS Economic Outlook - Being Decided - M Capital Group August 2021.pdf
US Economic Outlook - Being Decided - M Capital Group August 2021.pdf
 

The role of IAM in OpenBanking and where do we stand

  • 1. The Role of IAM in Open Banking & Where Do We Stand? Colombo IAM User Group - 2nd Meetup Pushpalanka Jayawardhana Financial Solutions Team - WSO2
  • 2. “Banking is necessary; banks are not” - (Bill Gates, 1990)
  • 3. International Financial Industry Concerns ➢Contribute to a more integrated and efficient European payments market ➢Improve the level playing field for PSPs (including new players) ➢Make payments safer and more secure ➢Online shopping without a credit card ➢Better protection against fraud ➢Help lower charges for consumers on card payments
  • 4. Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf Payment Card Industry Security Standards For protection of cardholder payment data,
  • 5. Payment Services Directive 2 EU Directive that applies to all Banks operating in the EU that regulates payment services throughout the EU, with a compliance deadline of January 2018
  • 6. Open Banking 1 : Possible central view Banks expose their customer payment and account data, with customer consent, to Third party Payment Providers (TPPs) via APIs. TPP PISP/AISP Bank A Bank B Bank C Merchant Now PSD2 Bank A Bank B Bank C Merchant
  • 7. Open Banking 2 : No Involvement of Card Network 7 ➢ Less hops ➢ Lower fees for transactions ➢ Easy to track the path
  • 8. Aggregated View of Accounts (AISP Flow)
  • 9. Payment Flow (PISP) Credits to Dinosoft Labs from Noun Project Checkout Item Login Page 2 Factor Authentication Customer Consent Initiation payment info 1 2 3 4 PISP 302 5 Token 6 Payment Complete 7 Settlement
  • 10. PSD2 Compliance Requirements ➢ API Specification ○ API Definitions ○ Secured API invocation ○ API Usage Monitoring ➢ Strong Customer Authentication ○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin) ○ Adaptive Authentication ○ Consent Management ➢ Incident Reporting ○ Security Incident Reporting [Transactions affected,server downtime, Economic
  • 11. Strong Customer Authentication Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
  • 12. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks Strong Customer Authentication Ctd..
  • 13. Adaptive Authentication ➢ Authentication flow is defined by risk level ➢ PSD2 define several exemptions for SCA applications ○ Not to kill user experience for small transactions and bulk transactions ➢ Security level can be decided based on, ○ The amount of transaction ○ Time elapsed from previous SCA ○ Transaction patterns on user ○ Role of user - Cooperate or private
  • 14. Consent Management ➢ Defined by PSD2 RTS on SCA and secure communication and GDPR ➢ Safeguard right of the user on personal data to, ○ be informed - Inform user of personal data collection ○ access - Validate information processing at any time ○ rectification - When user feels data is incomplete or accurate ○ restrict data processing - Just store, don’t process ○ data portability - Transfer data to another party ○ forgotten - Request removal of personal data ○ be notified on a data breach - Report to user within 72 hours
  • 16. Technology Requirements “Draft Regulatory Technical Standards, explicitly mentions to be based on known standards” ● User authentication (with SSO) ○ SAML 2.0 ○ OpenID Connect ● Access delegation - OAuth 2.0 ● Fine grained authorization - XACML ● Multifactor authentication - SMSOTP, FIDO, DUO, MePin 16
  • 17. Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf Other Standards ISO 27001 - for information security management systems ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
  • 18. Inside Story - Open Banking
  • 20. Open Banking: The opportunities Bank A Bank B Bank C Merchant Bank A Consolidated customer account and payment info across multiple Banks TPPTPP
  • 22. Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2 1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country e.g. EUR payment from France to Sri Lanka 1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country e.g. LKR payment from UK to Sri Lanka 1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country e.g. EUR payment from Sri Lanka to France 1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country e.g. LKR payment from Sri Lanka to UK PSD2 Impact on Us
  • 23. Banking Industry in Sri Lanka ➢ Sri Lanka Interbank Payment System (SLIPS) ○ Same day electronic fund transfer ○ Established in 2010, being first in South Asia ➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS) ○ For real-time payments ○ Initiated in 2015 ➢ JustPay - From LankaClear (pvt) Ltd ○ Applies 2FA ○ For real time retail payments under Rs. 10 000/= ○ Central Bank of Sri Lanka (CBSL) approved security standards ➢ Have already thought on AISP like applications ➢ Have the foundation of collaboration among banks in real time JustPay© - http://www.lankaclear.com/product_service/42-overview
  • 24. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
  • 25. Monetization of applications will be made easy...
  • 26. Q & A Twitter : @Pushpalanka LinkedIn : https://www.linkedin.com/in/pushpalanka/ WSO2 Open Banking : https://openbanking.wso2.com/

Editor's Notes

  1. PTS DSS - PIN Transaction Security Data Security Standard
  2. Open Banking is due to become a regulation in Australia (similar to the enforcement of PSD2 regulation in the EU). Therefore, Banks need to be able to securely expose sensitive data through APIs so that third party providers can build new applications that provide a much better user experience to multi-banked customers.
  3. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  4. Upto 80% of attacks are based on stolen user credentials… One proof from ancient stories Ali baba and 40 thieves.
  5. Behavioral factors such as walking style, typing are also considered now as another factor
  6. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  7. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  8. Exposing APIs can seem to commoditize banks by threatening to take away the sole ownership of customer data that banks so far enjoyed exculsively. However, Banks armed with the correct vision and the technology to achieve that can reap much more benefits from this open banking world. Survey conducted in UK by Accenture showed that consumers prefer Banks to be the ones to provide the 3rd party services as well. If and when Banks can take up that role, they become a rich repository of customer data across multiple banks. They can then use that repository to… Provide better services to their customers (eg:- cashflow management across banks) Provide ‘Insight Sales’ to other businesses. (-> attract new revenue streams)
  9. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  10. Core banking solution, Customer Integrated System, usually has • SWIFT terminals • ATM and POS solutions • MICR checks handler • Phone banking (IVR)