Copyright, 1995-2008 1 Can Mobile Payments be 'Secure Enough'? Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong.

Slides:



Advertisements
Similar presentations
Basic accounting I recap.
Advertisements

A Risk Assessment Framework for Mobile Payments Roger Clarke Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong Kong, Cyberspace.
Copyright COMP 3410 – I.T. in Electronic Commerce eSecurity Mobile Security Roger Clarke Xamax Consultancy, Canberra Visiting Professor, A.N.U.
Copyright Roger Clarke Xamax Consultancy, Canberra Visiting Professor – Cyberspace Law & Policy UNSW and at the ANU and the Uni. of.
Chapter 8 Payment Systems: Getting the Money
Copyright COMP 3410 / 6341 – I.T. in Electronic Commerce E-Trading 3.Electronic Payments Roger Clarke Xamax Consultancy, Canberra Visiting Professor,
Copyright, The Malware Menagerie Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in Cyberspace Law & Policy at U.N.S.W., eCommerce.
Copyright, Can Mobile Payments be 'Secure Enough'? Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong.
Copyright, Issues from Internet Technologies 1 – Internet Connected Devices Roger Clarke, Xamax Consultancy, Canberra Visiting Prof/Fellow,
Copyright A Risk Assessment Framework for Mobile Payments Roger Clarke Xamax Consultancy, Canberra Visiting Professor in Computer Science at.
Copyright © 2003 Pearson Education, Inc. Slide 1 Computer Systems Organization & Architecture Chapters 8-12 John D. Carpinelli.
Chapter 1: Introduction to MYOB Accounting Plus
Copyright 2004: Cybergen Technologies Inc. Slide #1 end-to-end recharge & e-commerce transaction flow scenarios Telco/MSO Billing & Payment System (BPS)
Chang-ho CHUNG 정창호, 鄭彰鎬 Judge, Republic of Korea, since 1993 Head of UNCITRAL and UNIDROIT Research Team of Supreme Court of Korea SNU, LSE, HKU 1.
M.B.A. II SEMESTER Course No. 208 Paper No. – XVI E-Business Dr.N.C.Dhande Unit II e-business frameworks e-selling process, e-buying, e-procurement, e-payments:
Banking Services AVAILABLE FOR A SMALL BUSINESS. BANKING SERVICES 2 Welcome 1. Agenda 2. Ground Rules 3. Introductions.
B2B Solutions Study Summary Charts June – September 2013.
E-commerce business. technology. society. Kenneth C. Laudon
1 STATISTICAL DATA ON THE BANKS PAYMENT SYSTEMS IN FINLAND May 2013.
Credit Card Understanding Your Credit Card Credit Cards 101 Trivia.
The ABCs of Credit Card Finance Essential Facts for Students 2012 Carol A. Carolan, Ph.D.
1 Online payments How do we purchase on the web? What choices of payment have we?
Eligibility, Benefits, and Pre-certifications
A business makes payments for what it buys, In return it receives payments for goods it sells or services it provides.
PRESENTED BY: FATIMA ALSALEH Credit Cards Fraud - skimmers -
Activity 1………….Why Do You Need A Bank?
Activity 1………….Why Do You Need A Bank? Activity 2………The Many Services of a Bank Activity 3…The ABCs of a Chequing Account Activity 4………Opening a Chequing.
Michal Bodlák. Referred to as mobile money, mobile money transfer, and mobile wallet generally refer to payment services operated under financial regulation.
Chapter 3 E-Payment Systems eb-course.weebly.com.
Take Charge of Your Finances
1.7.6.G1 © Family Economics & Financial Education –March 2008 – Financial Institutions – Online Banking – Slide 1 Funded by a grant from Take Charge America,
Analyzing Genes and Genomes
Essential Cell Biology
Intracellular Compartments and Transport
PSSA Preparation.
Chapter 11: E-Commerce.
Accounting Information Systems 8e
Essential Cell Biology
© Paradigm Publishing, Inc Chapter 11 Electronic Commerce Chapter 11 Electronic Commerce.
Introduction to ikhlas ikhlas is an affordable and effective Online Accounting Solution that is currently available in Brunei.
Graduate Admission System User Guide for Applicants 1 Last updated: April 2014.
User Security for e-Post Applications Dr Chandana Gamage University of Moratuwa.
12-CRS-0106 REVISED 8 FEB 2013 PRESENTS Payment Functionality.

Copyright, Can Mobile Payments be 'Secure Enough'? Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong.
Contactless Payment. © Family Economics & Financial Education – January 2007 –– Financial Institution Unit – Contactless Payment - 2 Funded by a grant.
Chapter 13 Paying Via The Net. Agenda Digital Payment Requirements Fraud Detection Online Payment Methods Online Payment Types The Future Payment.
1.7.2.G1 Electronic/Online Banking & Bill Pay Take Charge of Your Finances.
Elias M. Awad Third Edition ELECTRONIC COMMERCE From Vision to Fulfillment ELC 200 Day 24.
“Electronic Payment System”
Digital Payment Systems
Electronic Payment Systems University of Palestine University of Palestine Eng. Wisam Zaqoot Eng. Wisam Zaqoot March 2010 March 2010 ITSS 4201 Internet.
Electronic Payment Systems
BZUPAGES.COM Electronic Payment Systems Most of the electronic payment systems on internet use cryptography in one way or the other to ensure confidentiality.
ITEC0722: Mobile Business and Implementation: Mobile Payment and Security Suronapee Phoomvuthisarn, Ph.D.
May 28, 2002Mårten Trolin1 Protocols for e-commerce Traditional credit cards SET SPA/UCAF 3D-Secure Temporary card numbers Direct Payments.
Copyright © 2007 Pearson Education, Inc. Slide 6-1 E-commerce Kenneth C. Laudon Carol Guercio Traver business. technology. society. Third Edition.
Electronic Payment Systems. How do we make an electronic payment? Credit and debit cards Smart cards Electronic cash (digital cash) Electronic wallets.
Copyright © 2009 Pearson Education, Inc. Slide 5-1 Chapter 5 Online Security and Payment Systems.
Network Security Lecture 26 Presented by: Dr. Munam Ali Shah.
Chapter 4 E-commerce Security and Payment.
Checking & Savings Accounts Economics What is a Checking Account?  Common financial service used by many consumers (a place to keep money)  Funds.
Electronic Banking & Security Electronic Banking & Security.
BY GAWARE S.R. DEPT.OF COMP.SCI
Chapter 4 E-commerce Security and Payment.
Can Mobile Payments be 'Secure Enough'
Presentation transcript:

Copyright, Can Mobile Payments be 'Secure Enough'? Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong Kong, Cyberspace Law & Policy at U.N.S.W., Computer Science at A.N.U. / EC/MPS {.html,.ppt} Victoria Uni. of Wellington – 1 May 2008

Copyright, Can Mobile Payments be 'Secure Enough'? Agenda 1.Mobile Payment Excitement 2.Payment Mechanisms – Pre-Networks 3.Payment Mechanisms – Network Era 4.Security Analysis 5.The Acceptability of Insecurity

Copyright, Octopus Hong Kong Since Sep 1997 To pay, wave an Octopus card within a few cm of the reader (even if its in a wallet/purse) Audio-acknowledgement (beep) Display of tx amount and remaining balance On MTR and KCR transport, the tx amount is calculated from the entry and exit points

Copyright, RFID Tags for Road-Tolls Car requires a Tag Car drives through Control-Point Fee shown on a static or variable display Control-Point interacts with Tag Toll is deducted automatically Audio-acknowledgement of transaction Depends on blind consumer trust

Copyright, Japanese Osaifu-Keitai / Mobile Wallet Many Japanese mobile phones contain an extra chip, which uses RFID/NFC to communicate with payment-related devices Services include: eMoney (Edy) public transport (Mobile Suica) credit card? vending machines (Cmode) (loyalty card, id card,...) Dont lose it!! The chip is the Sony FeliCa (as in Octopus) Sony Viao PCs can interact with FeliCa

Copyright, Visa MicroTag Trials using Visa payWave Technology Intended to support 'instant purchase' Carried as a key-ring / key-chain Requires proximity (1-2 inches) Provides a visual indication when it operates No confirmation under a threshhold [US$ 25?] Not standards-based? No independent security testing? No public audit and certification? not-here-come-more-contactless-payment-devices.html – 30 Sep 2007

Copyright, UK Parking Payment Customer registers with RingGo RingGo stores (most of) their credit card details Customer uses their mobile phone to call a RingGo phone-number displayed in the car-park Customer keys the car-parks 4-digit code Customer chooses the duration of stay Customer keys remaining digits of credit-card RingGo processes a credit-card transaction, and makes data available on-line to traffic wardens Customer can access the transaction trail online [Still pre-paid, so still risk over-run!]

Copyright, Australian M-Payment No information about the security design Unclear risk allocation Unclear/incomplete privacy policy Unclear who's behind the company Unclear/incomplete terms of contract at: Unclear what regulatory regimes apply: RBA/APRA (financial) Ombudsman/ACCC/ASIC (consumer)

Copyright, Links an Account with the Intermediary to: an existing bank account; and/or an existing credit card (but is now becoming a card-issuer as well) Passes on Payment Instructions sent from: web-browser touch-tone to IVR SMS / text-messages (but imposes punitive terms and fees)

Copyright, Payment Mechanisms Pre-Networks Cash Cheque Direct Credit Direct Debit Credit Cards at Point-of-Sale Credit Cards MOTO Charging to Telco Accounts

Copyright, Payment by Cash

Copyright, Payment by Cheque

Copyright, Direct Credit Giro, 'TT', Salary Payments

Copyright, Direct Debit Standing Authorisation

Copyright, Credit Cards and Charge- Cards (in 'Meatspace' Transactions)

Copyright, Credit-Card Details in Card-Not-Present (MOTO) Transactions Changes the have factor from have the card to merely have credit card details No know a secret factor Relies on: secrecy of credit-card details [??] general levels of honesty consumers reconciling their accounts self-insurance by merchants (banks issue charge-backs)

Copyright, Payments in the Network Era ATMs EFTPOS Systems – Cr and Dr Internet Banking Credit Card Tx over the Internet Debit Tx over the Internet eCash ePayment Instructions Stored Value Cards

Copyright, ATMs 2-factor: have card know the PIN PIN keyed into secure PIN-pad, in a manner which makes it difficult to observe [?] Hash of PIN transmitted and compared So the know part is protected from both physical and electronic observation

Copyright, EFTPOS Networks for Credit and Debit Cards

Copyright, Debit-Cards over EFTPOS Networks Followed ATMs and the ATM Security Model 2-factor: have card know the PIN PIN keyed into secure PIN-pad, in a manner which makes it difficult to observe [?] Hash of PIN transmitted and compared So the know part is protected from both physical and electronic observation

Copyright, Credit-Cards over EFTPOS Networks Did *NOT* Follow the ATM Security Model 2-factor: have card reproduce signature pre-recorded on-card No PIN Some improvement through stop-list being automated on-line rather than manual Primary purpose was not security, but the transfer of data-capture costs to merchants

Copyright, Credit Card Tx over the Internet Worse Yet – Applied the CNP/MOTO Model The have factor is not have the card but merely have credit card details No second-factor such as know a secret Relies on: an encrypted channel (SSL/https) secrecy of credit-card details [??] general levels of honesty consumers reconciling their accounts self-insurance by merchants (banks issue charge-backs)

Copyright, Ready – SET – Dont Go Secure Electronic Transaction Processing for Internet Credit Cards Card-Holder states that he wishes to make a payment Merchant acknowledges Card-Holder provides payment amount, digital certificate Merchant requests an authorisation from the Payment- Processing Organisation (via a Payment Gateway / Acquirer) Existing EFTS networks process the authorisation Merchant receives authorisation Merchant sends capture request (to commit the transaction) Merchant receives confirmation the transaction is accepted Merchant sends Card-Holder confirmation

Copyright, Internet Banking – Various Implementations 2-factor or 3-factor authentication, e.g. know account details / login-id pre-registered IP-addresses only know PIN know One-Time Password (OTP) receive and key OTP sent at the time over another channel (e.g. SMS msg) authenticator(s) keyed into insecure key-pad, in a manner which makes it difficult to observe So the know part is protected from physical, and partly from electronic, observation

Copyright, Debit Transactions over the Internet Customer is at a merchants payment page Customer is re-directed to a specialised version of their own banks online-banking services Customer uses their own banks Internet Banking service to authorise the transaction, including an encrypted channel (SSL/https) Customer is redirected to the merchant Canadas scheme is called Interac Online: This leverages on a well-trusted infrastructure, but requires careful interfacing from merchants

Copyright, Credit-Card Transactions over the Internet 3-D Secure A Visa Initiative, but licensed to others: Verified by Visa MasterCard SecureCode JCB J/Secure For merchants and financial institutions, specifies authentication and processing procedures Requires some form of card-holder authentication, at this stage generally keying of a password/PIN

Copyright, Other Internet Payment Schemes 1996 – 2000 ?? 2009 – 20xx ? Electronic Value-Tokens (cash-like) DigiCash, NetCash incl. micropayment schemes Cybercoin, Millicent Electronic Payment Instructions (cheque- like) NetCheque, NetBill, BankNet, Netchex Stored-Value Cards Mondex

Copyright, MCommerce over Wireless Networks Wide Area Networks – Satellite Geosynchronous (2 second latency) Low-Orbit (Iridium) Wide Area Networks – Cellular (to 20km per cell) 1 – Analogue Cellular 2 – Digital Cellular, e.g. GSM, CDMA 2.5 – e.g. GSM/GPRS,... 3 – e.g. CDMA2000, UMTS/HSPA,... Wide Area Networks – WiMax / IEEE ; iBurst Local Area Networks – WiFi / x (10-100m radius) Personal Area Networks – Bluetooth (1-10 m radius) Contactless Cards / RFID Tags / NFC (1-10cm radius)

Copyright, Credit-Card Payments in the MCommerce Mobile / Handheld / Unwired Era Inherits all weaknesses of MOTO / Internet Less Visible Payee, no Footprint Less Visible Process, perhaps invisible Less Visible Transaction Data? Notification Record / Tx Voucher?

Copyright, Debit-Card Payments in the MCommerce Mobile / Handheld / Wireless Era Less Visible Payee, no Footprint Less Visible Process, perhaps invisible Less Visible Transaction Data? Notification Record / Tx Voucher? Capture of Authenticators on mobile Transmission of PIN or hash w/- SSL?

Copyright, Security Analysis [ Short Version ] EC/MPS-Secy ppt Threats + Vulnerabilities - Safeguards => Harm Second-Party Threats Third-Party Threats Consumer Device: Threats Vulnerabilities Key Categories of Harm Key Safeguards Required

Copyright, Key Safeguards Required Two-Sided Device Authentication, i.e. by Payees Chip of Payers Chip by Payers Chip of Payees Chip Notification to Payer of: Fact of Payment (e.g. Audio-Ack) Amount of Payment At least one Authenticator Protection of the Authenticator(s) A Voucher (Physical and/or Electronic) Regular Account Reconciliation by Payers

Copyright, Sample MPayment Schemes No Notification At All Surreptitious Payment Extraction Real-Time Notification Provided (no record) Octopus, Drive-Through eTags for Road-Tolls Receipt Provided (or at least Offered) UK RingGo Parking Payment Scheme Act of Consent Required e.g. Tap the Pad in Response to Display of Fare Provision of Partial (Non-Secret) Details UK RingGo Parking Payment Scheme Provision of a Secret Authenticator PIN for Telstra/NAB/Visa payWave above US$ 25?

Copyright, Can Mobile Payments be Secure Enough? Things We Need To Know What does the public want? Whats the price of convenience? What security-levels will the public accept? How will we know where the threshhold of acceptability is? If we exceed it, will we harm adoption? How long do people remember stuff-ups? Will the relevant public sullenly accept, become habituated, be sceptical, oppose, reject?

Copyright, Some Factors to Consider Apparent Risk Apparent Size of Payment Monetary Value in Wallet/Purse Monetary Value in Account / Cr Limit Identifiers Authenticators Frequency of Payment Context of Payment Fit to Life-Style: Quick, Simple, Intuitive, In/Style/Fashion Confidence in the System, the Parties

Copyright, Consumer Rights as an Enabler of MPayments Architecture (e.g. Device Authentication) Device and Service Audit and Certification Awareness, Education, Public Information Liability Assignment Complaint Handling Dispute Resolution Recourse But NZ Banks reduced Consumer Rights in July 2007 (and Aust Banks lobbied for it) in particular at para. 4.3

Copyright, Can Mobile Payments be Secure Enough? Conclusion Mobile Payments can be Faster More Intuitive More Convenient Less of an Obstacle

Copyright, Can Mobile Payments be Secure Enough? Conclusion Mobile Payments can be Faster More Intuitive More Convenient Less of an Obstacle For the Thief Too

Copyright, Can Mobile Payments be 'Secure Enough'? Roger Clarke, Xamax Consultancy, Canberra Visiting Professor in eCommerce at Uni of Hong Kong, Cyberspace Law & Policy at U.N.S.W., Computer Science at A.N.U. / EC/MPS {.html,.ppt} Victoria Uni. of Wellington – 1 May 2008