Natural Security Alliance

Similar documents
Natural Security Alliance

Die Zukunft des M-Payment The future of m-payment NFC. Andreas Johne. Düsseldorf, 25. Januar 2008

Digital Payments Security Discussion Secure Element (SE) vs Host Card Emulation (HCE) 15 October Frazier D. Evans

Visa paywave Implementation Overview and European Pilot Operating Principles Member Letter: VE 08/08 Type: General 16 April 2008

Will Mobile Phones Replace Cards?

Webinar Tokenization 101

Managing Risk in the Digital World. Jose A. Rodriguez, Director Visa Consulting and Analytics

TECHNICAL STANDARDS ASSESSMENT REPORT

Payment Security: Attacks & Defences

Will Federated Cross Credentialing Solutions Accelerate Adoption of Smart Card Based Identity Solutions?

Secure Over-The-Air Services in NFC Ecosystems

The new standard for user authentication

Practical Attack Scenarios on Secure Element-enabled Mobile Devices

Prepaid Access MIDWEST ANTI-MONEY LAUNDERING CONFERENCE Federal Reserve Bank of Kansas City March 5, 2014

The future of mobile banking

Advances in NFC & Mobile Payments Trials and Technology

Mobile Security / Mobile Payments

FIDO AND PAYMENTS AUTHENTICATION. Philip Andreae Vice President Oberthur Technologies

Business Models in Mobile NFC Services

Mobile NFC Services Opportunities & Challenges. NGUYEN Anh Ton VNTelecom Conference 31/10/2010

SEPA goes Mobile Dr. Marijke De Soete ETSI Security Workshop January 2011 Sophia Antipolis, France

NFC embedded microsd smart Card - Mobile ticketing opportunities in Transit

HCE security implications. Analyzing the security aspects of HCE

EXPERIENCE SIMPLER, STRONGER AUTHENTICATION

MasterCard NFC Mobile Device Approval Guide v July 2015

Mobile software security Building trust in mobile apps

Next steps for NFC and mobile wallets

Validated P2PE for Reduced Compliance Scope, More Peace-of-Mind

FIDO AS REGTECH ADDRESSING GOVERNMENT REQUIREMENTS. Jeremy Grant. Managing Director, Technology Business Strategy Venable LLP

FIDO Alliance: Standards-based Solutions for Simpler, Strong Authentication

The Honest Advantage

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

Strategies for the Implementation of PIV I Secure Identity Credentials

Software-Based PIN Entry on COTS. Jeremy King International Director PCI Security Standards Council

PCI compliance the what and the why Executing through excellence

CB TEST PRODUCTS & SERVICES ORDER FORM

The PCI Security Standards Council

State of US Mobile Payments (NFC)

Session 2: Understanding the payment ecosystem and the issues Visa Europe

PCI DATA SECURITY STANDARDS VERSION 3.2. What's Next?

University of Sunderland Business Assurance PCI Security Policy

Payment Card Industry (PCI) Data Security Standard

Secure Application Trend in Smartphones. STMicroelectronics November 2017

Maintaining Trust: Visa Inc. Payment Security Strategy

PCI DSS 3.1 is here. Are you ready? Mike Goldgof Sr. Director Product Marketing

Site Data Protection (SDP) Program Update

Payment Card Industry (PCI) Data Security Standard

FINGERPRINT SENSOR FOR MASS MARKET APPLICATIONS

Massachusetts Health Data Consortium CAQH CORE - NEHEN - VeriSign/Symantec Pilot. September 2010

Will you be PCI DSS Compliant by September 2010?

American Express Online PIN & PIN Security Requirements

Advanced Certifications PA-DSS and P2PE. Erik Winkler, VP, ControlCase

Payment Card Industry (PCI) Data Security Standard Self-Assessment Questionnaire A and Attestation of Compliance

PCI Compliance Updates

Mobile Payment & Retail Project. Maura Turolla, Telecom Italia - Innovazione

Mobile Payments Building the NFC Ecosystem

Secure Element APIs and Practical Attacks on Secure Element-enabled Mobile Devices

NFC Service Launch in Hong Kong. Alex Kun SVP, Product Development and Management Wireless Business

PSD2: Risks, Opportunities and New Horizons

~150. #1 or #2 27M + $2.1B 35% ~5,300. Verifone Today: Facts And Figures. Active Countries. In Most Markets. Systems Installed. Revenue From Services

Payment Card Industry (PCI) Qualified Integrator and Reseller (QIR)

Payment Card Industry (PCI) Data Security Standard

Mobile Payment Security

User Guide. mpos Readers RP350x & RP457c Mobile Payment Acceptance User Guide for Android

Smart Card Alliance Member Webinar: Mission Expansion and Name Change. February 22, 2017

All the Latest Data Security News. Best Practices and Compliance Information From the PCI Council

Authentication Work stream FIGI Security Infrastructure and Trust Working Group. Abbie Barbir, Chair

PCI Compliance. Network Scanning. Getting Started Guide

Kickstart. Overview. Oct 2017

Data Security Standard

Payment Systems Statistics

Payment Card Industry (PCI) Data Security Standard

USA Debit EMV Test Plan. Version 1.30

Best Practices in Deploying Skype for Business Voice and Video for Office 365

This document is a preview generated by EVS

White Paper. The Impact of Payment Services Directive II (PSD2) on Authentication & Security

ETSI All rights reserved

Mobile Banking in Europe and potentials for MNOs

Solution. Imagine... a New World of Authentication.

Transforming Healthcare with mhealth Solutions.

The Role of TSM. TSM Functions. Guy Berg President Collis America May 6, 2009

INFORMATION TECHNOLOGY ONE-YEAR PLAN

Certified Wireless USB from the USB-IF Jeff Ravencraft

Smart Cards. Outline. José Costa Application Domains: Smart Cards. Software for Embedded Systems

SECURITY PRACTICES OVERVIEW

Managing an NFC Ecosystem

Liberty Alliance concepts. Mon Service Public

Payment Card Industry (PCI) Data Security Standard

Smart Card Alliance Update. Update to the Interagency Advisor Board (IAB) June 27, 2012

Visa Inc Investor Day. Technology at Visa. Rajat Taneja EVP, Technology and Operations

The Open Application Platform for Secure Elements.

Discussion on MS contribution to the WP2018

ATIS PROCEDURES FOR CHANGE IN E.164 COUNTRY CODE ASSIGNMENTS

SWIFT Customer Security Controls Framework and self-attestation via The KYC Registry Security Attestation Application FAQ

Safaricom Data Privacy Statement

ebook - TRUSTED esim TESTING FRAMEWORK - June 2016 BUILDING A TRUSTED EMBEDDED SIM TESTING FRAMEWORK IN THE AGE OF IOT

Version 2.3 March 2, WisePad 2 Security Policy

Payment Card Industry (PCI) Data Security Standard

Who What Why

Polycom RealPresence Platform Director

Transcription:

Natural Security Alliance Biometrics Based Projects: How to Build Trust in biometrics projects? October 7-8, 2014 Barcelona

Summary! 3 Key questions 1/ How to succeed biometrics based deployment project? 2/ How to use biometrics without compromising security and privacy 3/ How to evaluate and certify biometrics for non-governmental approach?! Answers involve : Data protection, Standard Vs Proprietary solutions, Model of deployment, Ecosystem of services providers and vendors, testing and certi"cation process, integration into current infrastructure and user experience 2

Current Payment Experience

The authentication problems addressed! Merchants Increase business and customer adoption Universal / not limited to a speci"c payment solution Limited impact on the back-of"ce! Banks Customer Adoption Multi-channel compliant Proven security! Users No privacy concern Ease of use

5 Natural Security Alliance - Standard

Hands-free payment 6

7 Natural Security Alliance - Core speci"cations

8 Natural Security Alliance - Core speci"cations

Natural Security Alliance - Timeline 2007 2008 2008 2012 2012 2013 2014 - INIT R&D PHASE EXPERIMENTATION & PROJECTS PHASE Retailers and banks looking for a new, fast, convenient payment technology Creation of a R&D company: Patents deposit Writing of the speci"cations and certi"cation process Technologies assessment French experimentation: 1000 cardholders 2 cities 200 POS Very good feedback Pictures from the experimenta2on in France (2013) Provision of the speci"cations to an open standard organisation to share the governance and to facilitate the adoption of the technology. Projects starting soon in various countries: France, Russia, Chile Pilot: San Jose University

45 Members from various business areas

6 months pilot (From October 2012 to March 2013 )! 4 large supermarkets and many merchants involved! Near 1000 Cardholders! Near 5000 transactions! 200 POS! Results available online More Than 9 Out of 10 Pilot Participants Ready for Natural Security Biometric Payment 11

Privacy in practice Design Technological choices Privacy by Design Privacy by Default Implementation Evaluation Commitment from data controllers Privacy Rules

Technology compatible standard Environment 802.15.4 Bluetooth 3 POC 802.15.4 802.15.4 / Bluetooth Low Energy / Contact / NFC Secure Storage 802.15.4 Bluetooth 3 POC Smartcard / Secure Element TEE / Smartcard / Secure Element Pictures 13

Sim /Embedded SE /TEE : new implementations SIM CARD SE/TEE THIRD PARTY? 14

GIE Cartes Bancaires Approval (Chip & Tips)! GIE Cartes Bancaires started the certi"cation process of a NS device: EMV-based payment with biometrics as new CVM! 2015: France will be the "rst country to roll out wireless biometric EMV-based supports Risk Assessment Release Acceptation Bulletin Acquirer and issuer Approval framework Approval Reference document 2014 2015 September December May 15

Deployment model

Evaluation! BAI : to de"ne a common process for testing, approval and certi"cation of biometric technology for non-governmental applications : To become the reference on the performance, security and usability of biometrics Aligned with business and user needs, Based on use cases (transactions, online services, physical access control) Focus on the consistency of the evaluation (environment + functionnality + performance + security) A methodoloy for repetability rather than just producing results initiative welcomed by regulators 17

Framework Biometrics Alliance Initiative Business requirements Framework Tools providers Lab Tests run Certi"cation body Certi"cation

Conclusion ALLIANCE

Natural Security Alliance www.twitter.com/naturalsecurity EuraTechnologies, 165 avenue de Bretagne, 59000 Lille contact@naturalsecurityalliance.org www.naturalsecurityalliance.org ( : +33 3 617 614 61 www.linkedin.com/company/natural-security www.twitter.com/naturalsecurity www.vimeopro.com/naturalsecurity/tv 20 SIRET : 800 130 692 / APE : 7490 B