securing mobile payments: applying lessons learned in the real world

32
World ® ’1 6 Securing Mobile Payments: Applying Lessons Learned in the Real World James Rendell - VP Payment Security Strategy – CA Technologies SCX34S SECURITY

Upload: ca-technologies

Post on 08-Jan-2017

115 views

Category:

Technology


6 download

TRANSCRIPT

Page 1: Securing Mobile Payments: Applying Lessons Learned in the Real World

World®’16

SecuringMobilePayments:ApplyingLessonsLearnedintheRealWorldJamesRendell- VPPaymentSecurityStrategy– CATechnologies

SCX34S

SECURITY

Page 2: Securing Mobile Payments: Applying Lessons Learned in the Real World

2 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ForInformationalPurposesOnlyTermsofthisPresentation

©2016CA.Allrightsreserved.Alltrademarksreferencedhereinbelongtotheirrespectivecompanies.Thepresentationprovided atCAWorld2016isintendedforinformationpurposesonlyanddoesnotformanytypeofwarranty.Someofthespecificslideswith customerreferencesrelatetocustomer'sspecificuseandexperienceofCAproductsandsolutionssoactualresultsmayvary.

CertaininformationinthispresentationmayoutlineCA’sgeneralproductdirection.Thispresentationshallnotserveto(i)affecttherightsand/orobligationsofCAoritslicenseesunderanyexistingorfuturelicenseagreementorservicesagreementrelatingtoanyCAsoftwareproduct;or(ii)amendanyproductdocumentationorspecificationsforanyCAsoftwareproduct.Thispresentationisbasedon currentinformationandresourceallocationsasofNovember1,2016,andissubjecttochangeorwithdrawalbyCAatanytimewithout notice.Thedevelopment,releaseandtimingofanyfeaturesorfunctionalitydescribedinthispresentationremainatCA’ssolediscretion.

Notwithstandinganythinginthispresentationtothecontrary,uponthegeneralavailabilityofanyfutureCAproductrelease referencedinthispresentation,CAmaymakesuchreleaseavailabletonewlicenseesintheformofaregularlyscheduledmajorproductrelease.SuchreleasemaybemadeavailabletolicenseesoftheproductwhoareactivesubscriberstoCAmaintenanceandsupport,onawhen andif-availablebasis.Theinformationinthispresentationisnotdeemedtobeincorporatedintoanycontract.

Page 3: Securing Mobile Payments: Applying Lessons Learned in the Real World

3 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

©2016CA.Allrightsreserved.Alltrademarksreferencedhereinbelongtotheirrespectivecompanies.

Thecontentprovidedinthis CAWorld2016presentationisintendedforinformationalpurposesonlyanddoesnotformanytypeofwarranty. The informationprovidedbyaCApartnerand/orCAcustomerhasnotbeenreviewedforaccuracybyCA.

ForInformationalPurposesOnlyTermsofthisPresentation

Page 4: Securing Mobile Payments: Applying Lessons Learned in the Real World

4 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Abstract

Mobileisthenewblack—thewaypeoplework,shopandconnect.Takingacuefromthepaymentpointofview,thissessionwillpresentbestpracticesforsecuringmobilepaymentsandhowthesepracticesarerelevantacrosstheenterprise.

JamesRendellCATechnologiesVPPaymentSecurityStrategy

Page 5: Securing Mobile Payments: Applying Lessons Learned in the Real World

5 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Agenda

INTRODUCTION:SECURINGMOBILEPAYMENTS

MOBILEAUTHENTICATION

SUMMARY

RISKANALYTICSREAL-TIMENETWORK

NFCMOBILEWALLETPROVISIONING

SECURINGMOBILEIN-APPPURCHASES

1

2

3

4

5

6

Page 6: Securing Mobile Payments: Applying Lessons Learned in the Real World

6 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CAStrategyforSecureMobilePayments

SecureMobilePayment

MobileAuthentication

In-Apppurchase

Mobilewallet

Real-TimeRisk

MobilePushNotification• Multi-factorauthentication• PushNotificationanddisconnectedOTPoptions• Complieswithemergingmandates,e.g.PSD2

MasterCardIdentityCheck• Biometricauthenticationoptions

Page 7: Securing Mobile Payments: Applying Lessons Learned in the Real World

7 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

MobileAuthentication:MobilePushNotification

§ Mobiledeviceasvirtualidentity

§ Out-of-BandAuthentication

§ TransactioninflightPushNotificationonmobile

§ FingerprintAuthenticationonAppledevices– RoadmapwillincorporateAndroidetc.deviceswith

similarcapabilities

Page 8: Securing Mobile Payments: Applying Lessons Learned in the Real World

8 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

DeploymentOptions:MobileOTP*

§ PasscodeGenerationonMobileDevice

§ OfflineOTPgeneration

§ SupportsmultiplecardsonsingleApp

§ AvailableinbothOAuthandEMVmodes

*PlannedServiceAvailabilityforPaymentSecurityduring2017

Page 9: Securing Mobile Payments: Applying Lessons Learned in the Real World

9 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

FeatureHighlights

§ Out-Of-BandAuthenticationfor3-DSecure2.0

§ Easy-to-useOver-the-Airprovisioningforcardholders

§ BasedonIndustrystandardEMVAlgorithm(CAPCertifiedandDPACompliant)

§ Credentialsaresoftwarelockedtotheprovisioneddevice

§ StrongprotectionagainstSIM-Swap

§ CryptographicCamouflagetechnologypreventsbruteforceattack

§ Fine-GrainedAuthenticationControlsusingCARiskAnalytics

§ SuitableforEnterpriseandConsumerdigitalchannels

Page 10: Securing Mobile Payments: Applying Lessons Learned in the Real World

10 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

MultipleProvisioningOptions

§ During3-DSecureTransactionFlow

§ ViaOnlineBankingChannel– OnlineBankingprovidesanoptiontoenrollinMobileAuthentication

byintegratingwithourexposedWebService

§ ViaIssuerMobileApp– Usingan“AddAccount”optionfromwithintheIssuerMobileApp

§ ViaAPIsforenterprisesystemintegration

Page 11: Securing Mobile Payments: Applying Lessons Learned in the Real World

11 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Busin

ess

functio

n

Channe

ls

Onlineservicing

CA-Stron

gAu

then

tication

Payments(3-DSecure)

Enterpriseapplication

Riskevaluationandscoring• Rules• Machine

learning• Statistical• Behavioral

3-DSecure

BiometricDeviceID

CaseManagement/Reporting

Wearables

MFA

Mobilebrowser

Notification

CNP Traditionalbrowser

In-storetablet

Telephone/IVR

OmniChannelEnabler:EnterpriseandConsumer

ApplePay AndroidPay

GoogleWallet

Page 12: Securing Mobile Payments: Applying Lessons Learned in the Real World

12 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CAStrategyforSecureMobilePayments

SecureMobilePayment

MobileAuthentication

In-Apppurchase

Mobilewallet

Real-TimeRisk

RiskAnalyticsReal-TimeNetwork• DeviceIdentityisakeyfraud

indicator• Leverageglobaldeviceidentity/

reputation• Real-Timemodelupdates

Page 13: Securing Mobile Payments: Applying Lessons Learned in the Real World

13 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RiskAnalyticsReal-TimeNetwork

1. Predictivemodellearnsbank-specificcardholderbehaviorandfraudpatterns.

2. Devicesmaybeusedacrossbanks,hencecomplementaryDeviceDistillatesareincorporatedintheRiskAnalyticsNetworkmodel.

3. DeviceDistillatesupdatedinreal-timeastransactionsareprocessed.

4. Scorewillbehigherwhendevicespreviouslyassociatedwithprobablefraudareused.

Bank1 Bank2 Bank3

Real-timeupdate

Page 14: Securing Mobile Payments: Applying Lessons Learned in the Real World

14 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RiskAnalyticsReal-TimeNetworkExplainedFraudNotDetectedbyCurrentRiskAnalyticsModel

Time

CardPivotCARD1

BSYKB,12.5GBPDEVICE1

20130411:14:48:03

20130502:12:01:45

20130527:19:09:36

53

88

510

20130508:10:03:12

405

GOAL8.0GBPDEVICE2

RAModelScore

HUNGRYHOUSE20.7GBPDEVICE1

TRADEMEDIA47.38GBPDEVICE3

NonFraud

Fraud

• Thereare4transactionsonCARD1,twolegitandtwofraud

• CurrentRiskAnalyticsModelscoringnothighenoughtodetecttwofraudulenttransactions

• Lackingvisibilityintohistoricaltransactionsacrossagivendevice

Date/TimeofTransaction

MerchantName

TransactionValue

DeviceIDRiskscoresnothighenough(<600)tobedeemedfraud.

Page 15: Securing Mobile Payments: Applying Lessons Learned in the Real World

15 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

RiskAnalyticsReal-TimeNetworkExplainedImprovedFraudDetectionbyRiskAnalyticsNetworkModel

NonFraud

Fraud

Time

CardPivotCARD1

BSYKB,12.5GBPDEVICE1

20130411:14:48:03

20130502:12:01:45

20130527:19:09:36

20130508:10:03:12

GOAL8.0GBPDEVICE2

HUNGRYHOUSE20.7GBPDEVICE1

TRADEMEDIA47.38GBPDEVICE3

62

114

RANetworkModelScore

992De

vicePivot

DEVICE

2

20130508:09:49:36

GOAL

8.0GB

PCA

RD3 610

20130508:09:48:16

GOAL

8.0GB

PCA

RD2 237

20130508:09:56:39

GOAL

8.0GB

PCA

RD4 997

20130508:10:37:43

GOAL

8.0GB

PCA

RD5 976

20130508:10:49:01

GOAL

8.0GB

PCA

RD6 994

960

DevicePivot

DEVICE

3TRAD

EMED

IA47.38GB

PCA

RD5

20130527:15:57:24

142

TRAD

EMED

IA47.38GB

PCA

RD7

20130527:16:46:40

801

TRAD

EMED

IA47.38GB

PCA

RD8

20130527:19:06:05

942

TRAD

EMED

IA47.38GB

PCA

RD4

20130527:19:24:13

978

• Newdevicepivots(i.e.DEVICE2andDEVICE3)areincludedinRiskAnalyticsNetworkmodel.

• Allowsustoalsoconsiderthehistoricaltransactionsbydeviceinevaluationscoring.

• ResultisthatthenewmodelscoreshighonthetwofraudulenttransactionsonCARD1;stoppingthefraud.

Page 16: Securing Mobile Payments: Applying Lessons Learned in the Real World

16 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CAStrategyforSecureMobilePayments

SecureMobilePayment

MobileAuthentication

In-Apppurchase

Mobilewallet

Real-TimeRisk

NFCMobileWalletProvisioning• Cardholderauthenticationwhenprovisioning

carddatatomobiledevice• Acceleratetime-to-marketforissuerswantingto

embrace“*Pay”programs.

Page 17: Securing Mobile Payments: Applying Lessons Learned in the Real World

17 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

WhatIsMobilePaymentEnablement

Addingacustomer’spaymentmethodtoamobileplatform

orwallet

Page 18: Securing Mobile Payments: Applying Lessons Learned in the Real World

18 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

WalletsAreNotNew…TheyAreNotMatureEither

FinancialServicesPayPal

Venmo

Chase

CurrentC

Square

RetailMerchants

Starbucks

Amazon

Walmart

Wholefoods

TraditionalPaymentsMasterCard

Visa

Amex

VeriFone

DeviceMakers

Google

Apple

Samsung

ExistingWalletMarket…EveryoneWantstoCapturetheLoyalty

Page 19: Securing Mobile Payments: Applying Lessons Learned in the Real World

19 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

MobileWallets:ApplePayProvisioningSecurity

§ EarlyNFCMobilewalletdeploymentshadprovisioningweaknesses

§ StolencarddatacouldbeprovisionedtoNFCMobiledevices– CoupledwithcontactlessPointofSale,effectivelycloningEMVcards!!

§ CAdevelopedanincubatorofferingtodoOTPcardholderauthenticationduringNFCMobileWalletprovisioning,increasingtheassurancethatcarddataisbeingprovisionedtothecardholder’sphoneandnotafraudster’s

§ AcceleratedTime-to-Marketfor“*Pay”NFCMobileimplementations

Onboarding Provisioning Transaction Support

Page 20: Securing Mobile Payments: Applying Lessons Learned in the Real World

20 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ProvisioningFlow

Enroll Eligible?

Authenticate OTP

Activation

Walletprovider CardScheme

CAonIssuer’sbehalf

ReturnActivation

data

OTPDelivery

OTPValidation/authentication

Token

Confirmation

AmericanExpress

ApplePay

AndroidPay

GoogleWallet

SamsungPay

AndroidPay

MasterCard

Visa

Page 21: Securing Mobile Payments: Applying Lessons Learned in the Real World

21 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

CAStrategyforSecureMobilePayments

SecureMobilePayment

MobileAuthentication

In-Apppurchase

Mobilewallet

Real-TimeRisk

In-apppurchase• 3-DSecure2.0nativesupportfor

in-apppurchase• Richdataevaluation,fraudrisk

scoring,andmobileauthenticationchallenge.

Page 22: Securing Mobile Payments: Applying Lessons Learned in the Real World

22 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Evolutionof3-DSecure

BuildingTrust

Goals

Actions

Results

Buildconfidenceine-commerce

ReducefrauddisplacedbyEMVimplementation

ImprovecustomerExperience.Reduceabandonments.

Betterauthorizationrates.Accesstomorechannels.

Liabilityshiftforparticipatingmerchants

Simplifyenrolmenttodriveadoption.Strengthenauthenticationoptions

Firststepsinapplicationofanalyticsandpredictivemodelling

3-DSecure2.0.SophisticatedDataScience.AuthorizationIntegration.

Fragmentationandscheme-by-schemeserviceintroduction

Adoptionratesincreaseworldwide

Moreeffectivefraudreduction

Increaseauthorizationratesandlending.Accesstomoretransactions.ReduceFraud.Optimizeduserexperience.

FightingFraud

MinimizingFriction

“SmartAuthorization”

2001

2006

2010

2016

2018

InsightandPersonalization

Reachnewmarketsandcustomersegmentsbyleveragingrichdata.

Analytics.DataFeedstomarketing,personalization,andCRMsystems.

Growcustomerbase.Develophighvaluepartnershipsandrelationships.Reinforcebrandstrength.

Page 23: Securing Mobile Payments: Applying Lessons Learned in the Real World

23 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

ProblemsWith3-DSecure1.0.2

§ 3-DSecure1.0.2wasdesignedforthePC-basedonlineshoppingworld

§ Userexperienceonmobilebrowsersisoftenpoor

§ Merchantswaryofinvoking3-DSecurewithmobiletransactions

§ Nosupportforin-apppurchase

Materialderivedbyreferencetopublicdomaininformation.See:https://www.emvco.com/about_emvco.aspx?id=306http://www.emvco.com/faq.aspx?id=305

Page 24: Securing Mobile Payments: Applying Lessons Learned in the Real World

24 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

3-DSecure2.0

§ DevelopedandownedbyEMVCo– ManagesandcontrolstheEMVstandards

§ Designedforin-apppurchase– NativeappandHTMLUIsupport– Flexibleauthenticationoptions

§ Browserspecificationreplacementfor1.0.2

§ Designedtooptimizeuserexperience– Bypassingdetaileddatafromthemobiledeviceonlyasmallpercentageoftransactions

wouldneedtobechallenged– =>Theleadersinthisnewworldwillbethosewhocanleverageworld-classDataScience

Materialderivedbyreferencetopublicdomaininformation.See:https://www.emvco.com/about_emvco.aspx?id=306http://www.emvco.com/faq.aspx?id=305

Page 25: Securing Mobile Payments: Applying Lessons Learned in the Real World

25 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

What’sNewin3-DSecure2.0?

§ Richdata

§ Earlyriskevaluation

§ Frictionless,Challenge,andOutofBandAuthenticationFlows

§ In-apppurchaseintegration

§ Newbrowserspecification

§ ID&VFlows

Materialderivedbyreferencetopublicdomaininformation.See:https://www.emvco.com/about_emvco.aspx?id=306http://www.emvco.com/faq.aspx?id=305

Page 26: Securing Mobile Payments: Applying Lessons Learned in the Real World

26 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

EarlyRichData

§ Enhanceddatapassedup-frontintheequivalentoftheVEReqmessage– DeviceID/fingerprint– MerchantCategoryCode– Purchaseamount,currency– Optionalcardholderbilling/deliverydetails

§ Enhancedfrauddetection

§ Optimizeuserexperience– Majorityoftransactionswillneverbechallenged

Materialderivedbyreferencetopublicdomaininformation.See:https://www.emvco.com/about_emvco.aspx?id=306http://www.emvco.com/faq.aspx?id=305

Page 27: Securing Mobile Payments: Applying Lessons Learned in the Real World

27 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

TyingItAllTogether

Page 28: Securing Mobile Payments: Applying Lessons Learned in the Real World

28 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Summary:CAStrategyforSecuringMobilePayments

••Nativemobileuserexperience

••Richdataevaluation

••Provisioningsecurity

••Cardholderauthentication

••MobileStrongAuthentication

••OmniChannelenablement

••NeuralNetworks

••DeviceIdentity

TransactionRisk Authentication

MobileappsMobileWallets

NeuralNetworks

Page 29: Securing Mobile Payments: Applying Lessons Learned in the Real World

29 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Don’tMissOurINTERACTIVESecurityDemoExperience!

SNEAKPEEK!

29 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Page 30: Securing Mobile Payments: Applying Lessons Learned in the Real World

30 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Questions?

Page 31: Securing Mobile Payments: Applying Lessons Learned in the Real World

31 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Thankyou.

Stayconnectedatcommunities.ca.com

Page 32: Securing Mobile Payments: Applying Lessons Learned in the Real World

32 ©2016CA.ALLRIGHTSRESERVED.@CAWORLD#CAWORLD

Security

FormoreinformationonSecurity,pleasevisit:http://cainc.to/EtfYyw