Copyrights © 2013 MobiFin Proof of Concept to NAPSA.

Slides:



Advertisements
Similar presentations
RP Designs Semi-Custom e-Commerce Package. Overview RP Designs semi- custom e-commerce package is a complete website solution. Visitors can browse a catalog.
Advertisements

Cloud Banking Services MBSP Mobile Banking Service Provider Welcome to:
RASPro is a secure high performance remote application delivery platform through a perfect combination of application hosting and application streaming.
McAfee One Time Password
ProAssist ® complex assistance services management system Global Assistance & INGENIUM Praha.
Michal Bodlák. Referred to as mobile money, mobile money transfer, and mobile wallet generally refer to payment services operated under financial regulation.
Authenticating Users. Objectives Explain why authentication is a critical aspect of network security Explain why firewalls authenticate and how they identify.
ELECTRONIC BANKING.
POC Security System High security system combining PIN-on-Card, information security, physical access, control and alarm – all in one system.
Module 5: TLS and SSL 1. Overview Transport Layer Security Overview Secure Socket Layer Overview SSL Termination SSL in the Hosted Environment Load Balanced.
SECURITY IN E-COMMERCE VARNA FREE UNIVERSITY Prof. Teodora Bakardjieva.
Extending ForeFront beyond the limit TMGUAG ISAIAG AG Security Suite.
Our Eyes are on the watch for you! One Stop Shop Payment Automation: Innovative and Smart platform that: Increase Sales and Merchant Retentions Creates.
1 Pertemuan 12 Authentication, Encryption, Digital Payments, and Digital Money Matakuliah: M0284/Teknologi & Infrastruktur E-Business Tahun: 2005 Versi:
Atom m-commerce solution. Confidential atom technologies limited atom technologies limited, a Financial Technologies group company, is India’s leading.
© Copyright IBSP – IBSP Hong Kong Ltd Internet Business Service Provider.
SMS Banking. TABLE OF CONTENTS The Mobile World3 SMS Banking - Introduction7 SMS Banking - Push Messages8 SMS Banking - Pull Messages9 Technical Overview11.
Building and Deploying Safe and Secure Android Apps for Enterprise Presented by Technology Consulting Group at Endeavour Software Technologies.
PITCH We will provide prepaid payment instruments charging users zero transaction fees thereby reforming banking in India enabling users to “SHOP ANYWHERE.
Contents: Thinkways profile Introduction to our mobile banking solution Banking Services for Banked Customers: 1. Basic Banking 2. Money Transfer 3. Remittance.
Mobile Payment Forum of India Technology sub-committee Presentation on mobile payments.
It’s always better live. MSDN Events Security Best Practices Part 2 of 2 Reducing Vulnerabilities using Visual Studio 2008.
Uniqueness of user names is enforced Customer information logged to database Require contact information as well as address address will.
Lesson 11-Virtual Private Networks. Overview Define Virtual Private Networks (VPNs). Deploy User VPNs. Deploy Site VPNs. Understand standard VPN techniques.
(Remote Access Security) AAA. 2 Authentication User named "flannery" dials into an access server that is configured with CHAP. The access server will.
ISA 3200 NETWORK SECURITY Chapter 10: Authenticating Users.
FIREWALLS & NETWORK SECURITY with Intrusion Detection and VPNs, 2 nd ed. 10 Authenticating Users By Whitman, Mattord, & Austin© 2008 Course Technology.
“Electronic Payment System”
M-PESA Paybill service C2B
InterSwyft Technology presentation. Introduction InterSwyft brings secured encrypted transmission of SMS messages for internal and external devices such.
Course 6421A Module 7: Installing, Configuring, and Troubleshooting the Network Policy Server Role Service Presentation: 60 minutes Lab: 60 minutes Module.
CSCI 6962: Server-side Design and Programming
Lecture 12 Electronic Business (MGT-485). Recap – Lecture 11 E-Commerce Security Environment Security Threats in E-commerce Technology Solutions.
BANK IN A BOX Baku, Azerbaijan October 2012.
LEVERAGING UICC WITH OPEN MOBILE API FOR SECURE APPLICATIONS AND SERVICES Ran Zhou 1 9/3/2015.
Database Security and Auditing: Protecting Data Integrity and Accessibility Chapter 3 Administration of Users.
EUROCON “Computer as a Tool”, Belgrade, 24 th November 2005 (1) Paul Killoran EUROCON 2005 Paul Killoran, Fearghal Morgan & Michael Schukat National.
Hands-On Microsoft Windows Server 2008
Electronic Payment Systems. How do we make an electronic payment? Credit and debit cards Smart cards Electronic cash (digital cash) Electronic wallets.
ICT in Banking.
Session VI: the Role of New Technologies In Enhancing Access to the Payments Infrastructure Global Remittances: New Initiatives in M-banking The Citigroup-Vodafone.
Extending Forefront beyond the limit TMG UAG ISA IAG Security Suite
·
© 2008 Cisco Systems, Inc. All rights reserved.Cisco ConfidentialPresentation_ID 1 Cisco Secure Mobile Banking Enabling the Collaborative Customer Experience.
E-Commerce Security Professor: Morteza Anvari Student: Xiaoli Li Student ID: March 10, 2001.
OCS Systems Time vending of computers Computer print vending Photocopy and Fax Vending OCS On Account for Hotel Business Centers.
Panamax MobiFin Micro Insurance Panamax MobiFin Micro Insurance
"The majority of users in a typical enterprise simply want frequent, location-independent access to a few key applications, such as , calendar and.
Cuallet step by step guide. Step 1 From the Cuallet home page, click the “Sign Up Now” button. New user / Register.
Security fundamentals Topic 5 Using a Public Key Infrastructure.
Si Online technomart private limited
Database Security Cmpe 226 Fall 2015 By Akanksha Jain Jerry Mengyuan Zheng.
© Copyright 2009 SSLPost 01. © Copyright 2009 SSLPost 02 a recipient is sent an encrypted that contains data specific to that recipient the data.
Secure Mobile Development with NetIQ Access Manager
Vijay V Vijayakumar.  Implementations  Server Side Security  Transmission Security  Client Side Security  ATM’s.
Raj Bank Universal Core Banking System FCBS FINCBS INC Universal Core Banking Solution FCBS – Fin Core Banking Solution
Mobile Money 1/37 Fiserv Mobile Money Staff Education © 2010 Beavercreek Marketing, a division of Beavercreek Inc. All rights reserved. All trademarks.
Electronic Banking & Security Electronic Banking & Security.
1 Example security systems n Kerberos n Secure shell.
Digital Payments STEP BY STEP INSTRUCTIONS FOR VARIOUS MODES OF PAYMENT: Cards, USSD, AEPS, UPI, Wallets.
Digital Payments STEP BY STEP INSTRUCTIONS FOR VARIOUS MODES OF PAYMENT: Cards, USSD, AEPS, UPI, Wallets.
Module Overview Installing and Configuring a Network Policy Server
TIGO PESA CORPORATE SOLUTION
Radius, LDAP, Radius used in Authenticating Users
THE STEPS TO MANAGE THE GRID
BY GAWARE S.R. DEPT.OF COMP.SCI
معرفی سامانه خرید بلیط قطار رجا
IS4680 Security Auditing for Compliance
Modern benefits administration and HR software, supported by us.
Preparing for the Windows 8. 1 MCSA Module 6: Securing Windows 8
Presentation transcript:

Copyrights © 2013 MobiFin Proof of Concept to NAPSA

Copyrights © 2013 MobiFin Agenda Introduction Key Advantages mBanking Core Services mBanking Add On Services Interfaces Administration Solution Portfolio – mBanking Pre-requisites Security Scalability Architecture Questions and Answers

Copyrights © 2013 MobiFin Introduction Mobile Penetration has reached parallel to the population of a countries across global and in many countries greater then that too. Mobile Penetration has reached parallel to the population of a countries across global and in many countries greater then that too. Mobile has enabled users with set of services that very were never thought of. Mobile is getting smarter with greater access to data services Mobile is most frequently used and widely acceptable technological device then any other. Finance is key need of any people and it makes sense to enable Mobile with set of financial tools and features. Finance is key need of any people and it makes sense to enable Mobile with set of financial tools and features. Finance sector can utilize advantage of Mobile to penetrate all class off society.

Copyrights © 2013 MobiFin Introduction Mobile Banking solution for banked population The solution is provided to bankscustomers to avail information and transact on the move The solution is provided to bankscustomers to avail information and transact on the move The banks can retain existing customers and attract more by providing this mobile banking solution The banks can retain existing customers and attract more by providing this mobile banking solution Mobile Banking solution for un-banked population Reach out un-banked population in the rural area to expand customer base. Reach out un-banked population in the rural area to expand customer base.

Copyrights © 2013 MobiFin Key Advantage Expand financial sector reach by leveraging Mobile medium. Ease of use for financial services via various interfaces like IVR,USSD, SMS and Smart Apps. Expand Set of Services to larger sector of society. Solution Providers (Service Provider) Acquire large number of customers for their solution or services Acquire large number of customers for their solution or services Banks Expand customer base by providing basic banking facilitythrough financial inclusionto unbanked population. Penetrate unbanked customers. Expand customer base by providing basic banking facilitythrough financial inclusionto unbanked population. Penetrate unbanked customers.

Copyrights © 2013 MobiFin Key Advantage Telecom Operators Higher revenue through increased GPRS and SMS usage Higher revenue through increased GPRS and SMS usage Increase ARPU to the mobile operator. Increase ARPU to the mobile operator. Utility Organizations Prompt payment of bills enabling better cash flow Subscriber / Customers Basic banking facility made available and advantage to transact on the move.

Copyrights © 2013 MobiFin Mobile Banking Core Services Banking Services for Banked Customers Cash In From Bank Account Cash Out to Bank Account Wallet Statement Wallet Transfer Cash In From Bank Account Cash Out to Bank Account Wallet Statement Wallet Transfer Cheque Request Bank Account Statement Bank Fund Transfer Add Bank Account Remove Bank Account Cheque Request Bank Account Statement Bank Fund Transfer Add Bank Account Remove Bank Account Mobile Wallet Wallet Services Banking Services

Copyrights © 2013 MobiFin Add on Services Payment Services for Banked Customers Mobile DTH Electricity Insurance Mobile DTH Electricity Insurance Mobile Wallet Add On Bill Pay Mobile DTH Electricity Data Top UP Mobile DTH Electricity Data Top UP TopUp Bus Ticket School Fee Movie Tickets Railway Tickets Bus Ticket School Fee Movie Tickets Railway Tickets Utility Pay Merchant Payments Pay Now Wallet Transfer

Copyrights © 2013 MobiFin Customer Interface Customized Commands to operate Wallet over easy sms interface. Customized Commands to operate Wallet over easy sms interface. Mobile Wallet Interfaces SMS IVR USSD Mobile Apps Multilingual IVR System to enable customer to operate their wallets Multilingual IVR System to enable customer to operate their wallets Customized Commands and service menu over USSD interface provide faster access to Wallet services. Customized Commands and service menu over USSD interface provide faster access to Wallet services. J2ME M-Banking App for Low End Mobile Devices. Android and Iphone Apps for Smart Mobile Devices. J2ME M-Banking App for Low End Mobile Devices. Android and Iphone Apps for Smart Mobile Devices.

Copyrights © 2013 MobiFin Platform Key Modules Wallet Service Module Service Provider –Integration Module Distribution Module Customer Support Module Business Rule Module Notification Module Loyalty Program Module MIS Reports Module

Copyrights © 2013 MobiFin Mobile Banking – Enrolment Process Bank Customer Enrolment for mBanking Enrolled DataPre Data Validation Process data and Storage Server Smart Login and APP DispatchmBanking Smart Login Personalized and Printing Processed Enrolment Data BANK

Copyrights © 2013 MobiFin Mobile Banking – Basic Banking Balance Inquiry Select Check Account Balance Banking Service Check Account Balance Last 5 Transaction Request Check Book Bill Payment Utility Payment Airtime BOB A/C No AXIM A/C No. 1XXXX ICICI A/C No. 1XXXX Check Account Balance Select Check Account Balance Choose the Account Number

Copyrights © 2013 MobiFin Mobile Banking – Basic Banking Balance Inquiry Enter the Transaction PIN Choose the Account Number Check Account Balance Enter PIN Number XXXX Your Balance on Dt. 12, 2012 At 11PM GMT 3.00 is TSH Check Account Balance

Copyrights © 2013 MobiFin Mobile Banking – Basic Banking Account Statement Select the Account Number Enter the Transaction PIN Lists the first 4 transactions. Click on the transaction to view details Transaction is displayed as shown

Copyrights © 2013 MobiFin Mobile Banking – Basic Banking Money Transfer Select Money Transfer option Enter Receiver ’s Account Number Choose Account to transfer from Enter the Amount to be transferr ed Enter the Transact ion PIN Transact ion confirm ation

Copyrights © 2013 MobiFin Mobile Banking – Basic Banking Bank Integration using ISO 8583 Standard for Financial Transaction Card Originated Messages Basic Bank feature for banked customer Bank Integration using ISO 8583 Standard for Financial Transaction Card Originated Messages Basic Bank feature for banked customer API Integration To secure, encrypt and sign the transaction requests Mobile OS Integration (Encrypted) USSD driven secure Menu Access Code Integrations with all Carriers (Inbound request) USSD driven secure Menu Access Code Integrations with all Carriers (Inbound request) USSD Gateway Bulk SMS provisioning (Outbound) Access Code Integrations with all Carriers (Inbound SMS) Bulk SMS provisioning (Outbound) Access Code Integrations with all Carriers (Inbound SMS) SMSC Gateway (optional) SMSC Gateway (optional) Inbound IVR call IVR Acess Number (optional) IVR Acess Number (optional)

Copyrights © 2013 MobiFin Abstract Mobile Commerce service, also referred to as Mobile Top Up, Mobile payment, Mobile Banking, Mobile Money Transfer and Mobile wallet generally refer to payment services operated under financial regulation and perform from or via a mobile device or various end interface.mobile devicevarious end interface Mobile Commerce Service is attractive because it is a convenient approach to perform remote transaction, banking, money transfer but there are security shortfalls in the present mobile topup / banking implementations. This presentations discusses some of these security feature.

Copyrights © 2013 MobiFin Abstract MobiFIN has separate Web based administration console to manage platform which provides SSL based access only. All access to the system restricted using strong user management module which provides in depth security levels to provide restricted accesses. There are three security levels in built in to the system. (1) Partition Level (2) Roles and Access Control List level (3) Field Level Security All Changes and Modification to the system are logged in secure manner. It helps to provide detail AUDIT Trail of Any user access.

Copyrights © 2013 MobiFin Network Security MobiFin architecture is laid out three tier approach. All key entity are modularized based on their roles like Transaction management, Business Rule management, Admin management, Integration management. All of these entities are talking to each other and to third party application on fully secured channels. These channels are secured using virtual private network tunnels and SSL secured channels for public access. In Case of Public access highest level of encryption is applied to channelized data. Access to these entities is allowed based on standard business practice set by operator.

Copyrights © 2013 MobiFin Integration Security MobiFIN is highly versatile platform which needs to integrate with various third party provides to roll out new services. MobiFIN has separate entity to handle this flow and modeled as Integration Manager. All third party integration is done at this level only using following standard procedure. Network Integration over VPN API Integration using SOAP-API or ISO 8583 Transaction Security using AES method

Copyrights © 2013 MobiFin Interface Security Mobile App  MobiFIN mobile app generates unique device fingerprint for each devices on which it is getting installed. Device finger prints are universally unique and are never stored on device at any stage.  Device Finger Print is mapped against Users (Agents,Resellers,Sales) and provisioned using standard Enrollment process till that device and user login is in-active.  User is provisioned with Login and Transaction pin separately.  Login and Transaction PIN are never stored at device side.  Login and Transaction PIN are encrypted using 3DES method and never stored in decrypted form anywhere.  All app communication channel data is encrypted using unique key generated for device which provides full protection against Eavesdropping and data theft using AES encryption method.  AES is used by US Government to store all their Top Secret documents thus provides highest level of security to any point to point communication and storage of data.  Web Password are generated using user’s KYC information.  Two way Authentication and Password Generation Using user’s KYC Info via encrypted sessions o Terminal Key Generation Using KYC o User’s Authentication credential generation using Terminal Key. o Unique Authentication credential for Different UI. o User Credentials stored in device itself rather then server.

Copyrights © 2013 MobiFin Interface Security SMS  Subscriber authentication and subscriber identity confidentiality for each transaction/user.  SMS and other channels used with encryption like 3DES, SHA by mobile applications to protect data integrity and security  Integration to SMSC gateway using Industry standard Hypertext transfer protocol Secure (HTTPS) – additional security we do deploy VPN (Virtual Private Network).

Copyrights © 2013 MobiFin Interface Security WEB  All transactions over Web are on secure channel using industry standard Hypertext transfer protocol Secure (HTTPS).  Automatic inactive lockout (Session expired) - if no activity for a set time after customer logs in, the connection is dropped, locking the user out.  Web Password are generated using user’s KYC information.  Two way Authentication and Password Generation Using user’s KYC Info via encrypted sessions o Terminal Key Generation Using KYC o User’s Authentication credential generation using Terminal Key. o Unique Authentication credential for Different UI.

Copyrights © 2013 MobiFin Interface Security USSD  To Make an transaction exchange using USSD, the banks or mobile operators Connect to our network of server system over a session based ( not store –and – forward)Connection. USSD reduces risk and leaves no trace of transaction on handset from anywhere.  The sender (USSD) can be absolutely sure that they are talking with their own partner and communication via USSD is in sessions instead of an discrete intervals.

Copyrights © 2013 MobiFin Scalability and Redundancy Mobile Banking requires the all time available system to provide key services to user thus require very different system then core financial system which has fixed window of service time. MobiFIN addresses this by highly scalable module platform which has separate module for each services it enables it to achieve very high TPS and also insures high availability likes of telecom systems. MobiFIN platform works on Industry standard App and Databases servers for reliability. Redundancy can be provided at each tier, in an active- active model, and as an active –passive model, with one node serving as a standby or backup At the DB tier, SQL proxies (MySQL) – live replication of MySQL DB Supported. Geographically DR site – in order to avoid DR event with no affect to the total operation.

Copyrights © 2013 MobiFin Architecture IVR WEB Mobile App WEB Interface Firewall Secure ANI https 3DES / AES 3https Application Firewall Integration ISO 8583 Provider Bank

Copyrights © 2013 MobiFin Architecture Panamax Infotech Limited "Panamax House", Plot No. 8, Khushman Society, Nr. Subhash Circle, Memnagar, Ahmedabad Gujarat, India. Tele : Fax :