p resentation to 6th cacr information security workshop november 10, 2000
TRANSCRIPT
![Page 1: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/1.jpg)
Presentation to
6th CACRInformation Security
WorkshopNovember 10, 2000
Presentation to
6th CACRInformation Security
WorkshopNovember 10, 2000
![Page 2: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/2.jpg)
PRIVACY PROTECTION
MADE SIMPLE: How technical design
can help you meet your commitment to
privacy in the marketplace
PRIVACY PROTECTION
MADE SIMPLE: How technical design
can help you meet your commitment to
privacy in the marketplace
![Page 3: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/3.jpg)
Who and What Is Mondex When & Where will it be
used How does the Mondex
Technology protect privacy of the individual
![Page 4: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/4.jpg)
![Page 5: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/5.jpg)
MONDEX e-cashMONDEX e-cash
An e-cash application on a MULTOS smart card chip
Lockable/re-loadable chip-to-chip Instant transfer of value No POS settlement
![Page 6: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/6.jpg)
MONDEX -e-cashMONDEX -e-cash
Cash alternative Limited record on chip ‘real’ and ‘virtual’ applications Global /Multi-currency Entrè to smart card platform
![Page 7: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/7.jpg)
ImplementationsImplementations
Guelph, Ontario - Sept 96 - December 98
Sherbrooke,Quebec - August 99 - and continuing
![Page 8: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/8.jpg)
Mondex in SherbrookeMondex in Sherbrooke
Mondex e-cash/Interac debit/client combo card
Bishops University &Champlain College Student/Mondex combo card
$500 card load limit
![Page 9: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/9.jpg)
Mondex in SherbrookeMondex in Sherbrooke
Physical world load/purchase
UPOS Internet load/purchase loyalty Community Access Program
![Page 10: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/10.jpg)
Convenience Accessibility On chip record of
recent transactions Home load Internet purchases
CONSUMER
![Page 11: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/11.jpg)
Reliable-Off line payment
Higher security Low transaction
cost Reduced cash
handling
MERCHANT
![Page 12: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/12.jpg)
Strengthen customer relationships
New financial and commercial partnerships
FINANCIAL INSTITUTION
![Page 13: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/13.jpg)
![Page 14: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/14.jpg)
Future of Smart CardsFuture of Smart Cards
Multi-application cards Canadian chip migration
project for payments (Visa/MasterCard /Interac/Mondex)
7-10 year time-frame
![Page 15: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/15.jpg)
Privacy and Smart Cards Privacy and Smart Cards
The reality of smart cards is the carriage of many application and the availability of a large volume of personal data that can be tied to an individual
![Page 16: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/16.jpg)
How does Mondex Protect PrivacyHow does Mondex Protect Privacy
Principles protected:–Limits for collecting personal
information– limits for using, disclosing and
keeping personal information–keeping personal information
accurate– safeguarding personal
information
![Page 17: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/17.jpg)
How does Mondex Protect PrivacyHow does Mondex Protect Privacy
Limits for collecting personal information
– loads from account–deposits into account– lost transactions
![Page 18: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/18.jpg)
How does Mondex Protect PrivacyHow does Mondex Protect Privacy
Limits for using, disclosing and keeping personal information
– safeguard deposits– to re-imburse for non-
performance
![Page 19: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/19.jpg)
How does Mondex Protect PrivacyHow does Mondex Protect Privacy
Keeping personal information accurate
– load and unload are online– rolling 10 transactions
provides exact spend and retailer name
![Page 20: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/20.jpg)
How does Mondex Protect PrivacyHow does Mondex Protect Privacy
Safeguarding personal information
– firewalls in Multos - between applications - ITSEC 6 designation
– transaction data to retailer is deliberately limited
– individual transaction data is not collected by banks - Mondex is an unaudited system
![Page 21: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/21.jpg)
SummarySummary The unique privacy features
of Mondex e-cash were a deliberate design
–unaudited– limited transaction
information to retailer – specific and limited
information collected by FI–accurate rolling record for
customer –firewalls between applications
![Page 22: P resentation to 6th CACR Information Security Workshop November 10, 2000](https://reader030.vdocuments.site/reader030/viewer/2022032604/56649e665503460f94b611fa/html5/thumbnails/22.jpg)
Thank You______________
www.mondex.ca
Thank You______________
www.mondex.ca