SlideShare ist ein Scribd-Unternehmen logo
1 von 26
DISCOVER CIDWAY Mobile Security, Authentication & Transactions’ Signature 2009
Agenda 2-Factor Authentication & Transaction Signature ,[object Object],CORPORATE BACKGROUND ,[object Object]
IndustriesPRODUCT PRESENTATION ,[object Object]
Tokens FeaturesBUSINESS CASES ,[object Object]
Key differentiatorsSECURING BANKING TRANSACTIONS ,[object Object]
Scenario 2: Challenged out-of-band Transaction Signature
Scenario 3: Automated out-of-band Transaction Signature,[object Object]
2-Factor Authentication & Transaction Signature Authentication Factors What you know (PIN Code…) What you have (hardware token, mobile Phone…) What you are (biometrics) 2-Factor Authentication ,[object Object],1 & 2: PIN Code on a Mobile Phone, generating a One Time Password. Transaction Signature ,[object Object],One Time Password (OTP) One time use & unique password to replace the static password. An OTP can be event based such as most of the solutions including smsotp (contains some weaknesses) or time-based, such as the one of all Cidway solutions. Transaction Signature Out-of-band Transaction Signature will enable the Bank to prevent Man-in-the-Midle attacks for its online user base in a simple and user friendly way.
CORPORATE BACKGROUND
CIDWAY – Background Cidway ,[object Object]
Head Quarters in Lausanne, CH
Sales Offices in Switzerland & UK
Internal R&D & Patent OfficePartners and Customer Services ,[object Object]
Support center for Partners
Support portal available for partners
Consulting servicesCIDWAY’s Vision Authentication and transactions should be safe, reliable and easy for anyone, anywhere, anytime This vision is fuelled by: ,[object Object]
Making Authentication & Transactions simple, easy, accessible, secure and user friendly
Addressing virtually unlimited vertical applications from one platform
Providing the next generation mobile software security solution for identity, transaction and data protection,[object Object]
PRODUCT PRESENTATION
CIDWAY GAIA / SESAMI Product Line One server for multiple tokens SESAMI SlimTime based OTP Hardware token SESAMI MobileTime based OTP Software token for mobile phones. SIM enabled GAIA ServerAuthentication platform GAIA SDKAuthentication platform SDK SESAMI Mobile SDKTime based OTP Token SDK for mobile phones SESAMI SMSSMS based OTP for mobile phones SDK: Software Development Kit
[object Object]
No stock management
Low on-going costCIDWAY SESAMI SMS FEATURES & CHARACTERISTICS Strong two-factor authentication No need for software installation or activation in the mobile No secret stored in the mobile User convenience – no need to carry any other device User can change his mobile phone time zone or time Easy management – no need to maintain stock and distribute hardware tokens Easy deployment, no need for tokens maintenance Works with any SMS enabled mobile phone or PDA OTP FEATURES 8 decimal digits (or optionally 8 hex-digits) Time-based combined with challenge-response SHA-1 algorithm Validity of few seconds (server parameter) Automatic time management by the server
[object Object]
Secure

Weitere ähnliche Inhalte

Was ist angesagt?

Horizon_Brochure
Horizon_BrochureHorizon_Brochure
Horizon_BrochureOmar Tarish
 
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...OKsystem
 
The Power of Identification Management
The Power of Identification ManagementThe Power of Identification Management
The Power of Identification ManagementViper Web Solutions
 
Smart Card to the Cloud for Convenient, Secured NFC Payment
Smart Card to the Cloud for Convenient, Secured NFC PaymentSmart Card to the Cloud for Convenient, Secured NFC Payment
Smart Card to the Cloud for Convenient, Secured NFC PaymentSazzadur Rahaman
 
Indicus Profile 2013
Indicus Profile 2013Indicus Profile 2013
Indicus Profile 2013samjoshi
 
Eng Images Support Brochure Corporate Brochure2009
Eng Images Support Brochure Corporate Brochure2009Eng Images Support Brochure Corporate Brochure2009
Eng Images Support Brochure Corporate Brochure2009andyahn
 
Sentegra MobileBeat 2010 Startup Competition Presentation
Sentegra MobileBeat 2010 Startup Competition PresentationSentegra MobileBeat 2010 Startup Competition Presentation
Sentegra MobileBeat 2010 Startup Competition PresentationVentureBeat
 
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLD
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLDSECURING ONLINE SERVICES IN A MOBILE FIRST WORLD
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLDForgeRock
 
Audio card - VoIP - Phonecard
Audio card - VoIP - PhonecardAudio card - VoIP - Phonecard
Audio card - VoIP - PhonecardGuy Romanus
 
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...Eswar Publications
 
Voxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Corp
 
SUNDRAY Gigabit Series Wireless Access Controller
SUNDRAY Gigabit Series Wireless Access ControllerSUNDRAY Gigabit Series Wireless Access Controller
SUNDRAY Gigabit Series Wireless Access ControllerSunardi Fatan
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationMarc Vael
 
A Telco and End-user Perspective on the Authentication Journey
A Telco and End-user Perspective on the Authentication JourneyA Telco and End-user Perspective on the Authentication Journey
A Telco and End-user Perspective on the Authentication JourneyFIDO Alliance
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb
 
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSINVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSAndrea Cinelli
 

Was ist angesagt? (20)

Horizon_Brochure
Horizon_BrochureHorizon_Brochure
Horizon_Brochure
 
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
Smart Cards & Devices Forum 2012 - Mobile ID usnadňuje život jak uživatelům, ...
 
The Power of Identification Management
The Power of Identification ManagementThe Power of Identification Management
The Power of Identification Management
 
Smart Card to the Cloud for Convenient, Secured NFC Payment
Smart Card to the Cloud for Convenient, Secured NFC PaymentSmart Card to the Cloud for Convenient, Secured NFC Payment
Smart Card to the Cloud for Convenient, Secured NFC Payment
 
Mobile Payment fraud & risk assessment
Mobile Payment fraud & risk assessmentMobile Payment fraud & risk assessment
Mobile Payment fraud & risk assessment
 
Indicus Profile 2013
Indicus Profile 2013Indicus Profile 2013
Indicus Profile 2013
 
Eng Images Support Brochure Corporate Brochure2009
Eng Images Support Brochure Corporate Brochure2009Eng Images Support Brochure Corporate Brochure2009
Eng Images Support Brochure Corporate Brochure2009
 
Sentegra MobileBeat 2010 Startup Competition Presentation
Sentegra MobileBeat 2010 Startup Competition PresentationSentegra MobileBeat 2010 Startup Competition Presentation
Sentegra MobileBeat 2010 Startup Competition Presentation
 
87559489 auth
87559489 auth87559489 auth
87559489 auth
 
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLD
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLDSECURING ONLINE SERVICES IN A MOBILE FIRST WORLD
SECURING ONLINE SERVICES IN A MOBILE FIRST WORLD
 
M Commerce
M CommerceM Commerce
M Commerce
 
Audio card - VoIP - Phonecard
Audio card - VoIP - PhonecardAudio card - VoIP - Phonecard
Audio card - VoIP - Phonecard
 
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...
Analysis of Applicability of ISO 9564 PIN based Authentication to Closed-Loop...
 
CardConnect
CardConnectCardConnect
CardConnect
 
Voxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactionsVoxeo Summit Day 2 - Securing customer interactions
Voxeo Summit Day 2 - Securing customer interactions
 
SUNDRAY Gigabit Series Wireless Access Controller
SUNDRAY Gigabit Series Wireless Access ControllerSUNDRAY Gigabit Series Wireless Access Controller
SUNDRAY Gigabit Series Wireless Access Controller
 
ISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentationISACA Mobile Payments Forum presentation
ISACA Mobile Payments Forum presentation
 
A Telco and End-user Perspective on the Authentication Journey
A Telco and End-user Perspective on the Authentication JourneyA Telco and End-user Perspective on the Authentication Journey
A Telco and End-user Perspective on the Authentication Journey
 
MobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor AuthenticationMobiWeb - OTP SMS Two Factor Authentication
MobiWeb - OTP SMS Two Factor Authentication
 
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONSINVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
INVENTIA VIDEO KIOSKS AND VIDEO ENGAGEMENT SOLUTIONS
 

Andere mochten auch

Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1lfilliat
 
Staying In Peace In 2009
Staying In Peace In 2009Staying In Peace In 2009
Staying In Peace In 2009themox
 
Cidway Banking 02 2011
Cidway Banking 02 2011Cidway Banking 02 2011
Cidway Banking 02 2011lfilliat
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authenticationlfilliat
 
Anxiety and Stress Therapy
Anxiety and Stress TherapyAnxiety and Stress Therapy
Anxiety and Stress TherapyAzamhar Tawil
 
Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1lfilliat
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12lfilliat
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12lfilliat
 
Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1lfilliat
 

Andere mochten auch (10)

Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1
 
Staying In Peace In 2009
Staying In Peace In 2009Staying In Peace In 2009
Staying In Peace In 2009
 
Cidway Banking 02 2011
Cidway Banking 02 2011Cidway Banking 02 2011
Cidway Banking 02 2011
 
Cidway Byod Authentication
Cidway Byod AuthenticationCidway Byod Authentication
Cidway Byod Authentication
 
Anxiety and Stress Therapy
Anxiety and Stress TherapyAnxiety and Stress Therapy
Anxiety and Stress Therapy
 
Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12
 
Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12Cidway Secure Mobile Access Transactions Short 05 12
Cidway Secure Mobile Access Transactions Short 05 12
 
Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1Cidway M Gov2009 Barcelona V1
Cidway M Gov2009 Barcelona V1
 
CITRA KOTA
CITRA KOTACITRA KOTA
CITRA KOTA
 

Ähnlich wie Cidway Bank Finance 01 2009 2 Fa Tr

A case for identities - Etisalat, George Held at TADSummit
A case for identities - Etisalat, George Held at TADSummitA case for identities - Etisalat, George Held at TADSummit
A case for identities - Etisalat, George Held at TADSummitAlan Quayle
 
Secure E-Banking with KOBIL technologies
Secure E-Banking with KOBIL technologiesSecure E-Banking with KOBIL technologies
Secure E-Banking with KOBIL technologiesmarketingkobil
 
Going beyond MFA(Multi-factor authentication)-Future demands much more
Going beyond MFA(Multi-factor authentication)-Future demands much moreGoing beyond MFA(Multi-factor authentication)-Future demands much more
Going beyond MFA(Multi-factor authentication)-Future demands much moreindragantiSaiHiranma
 
Security & Seamless CX in User Authentication: How to Achieve Both?
Security & Seamless CX in User Authentication: How to Achieve Both?Security & Seamless CX in User Authentication: How to Achieve Both?
Security & Seamless CX in User Authentication: How to Achieve Both?Ivona M
 
SOTP_Introduction
SOTP_IntroductionSOTP_Introduction
SOTP_IntroductionJohnson Wu
 
Digital Payment and 3-D Secure by Netcetera
Digital Payment and 3-D Secure by NetceteraDigital Payment and 3-D Secure by Netcetera
Digital Payment and 3-D Secure by NetceteraNetcetera
 
Axiom protect-2.0-with-one identity
Axiom protect-2.0-with-one identityAxiom protect-2.0-with-one identity
Axiom protect-2.0-with-one identityVikram Sareen
 
Mtel Cash Mobile Commerce Suite
Mtel Cash Mobile Commerce SuiteMtel Cash Mobile Commerce Suite
Mtel Cash Mobile Commerce Suitewatsongallery
 
Two Factor Authentication Using Smartphone Generated One Time Password
Two Factor Authentication Using Smartphone Generated One Time PasswordTwo Factor Authentication Using Smartphone Generated One Time Password
Two Factor Authentication Using Smartphone Generated One Time PasswordIOSR Journals
 
case-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_encase-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_enAlix Murphy
 
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...IJRTEMJOURNAL
 
Mobile payments and PCI DSS
Mobile payments and PCI DSSMobile payments and PCI DSS
Mobile payments and PCI DSSManish Mahapatra
 
SmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketSmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketOKsystem
 
Emerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryEmerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryErfan Moradian
 
A secure communication in smart phones using two factor authentication
A secure communication in smart phones using two factor authenticationA secure communication in smart phones using two factor authentication
A secure communication in smart phones using two factor authenticationeSAT Journals
 

Ähnlich wie Cidway Bank Finance 01 2009 2 Fa Tr (20)

A case for identities - Etisalat, George Held at TADSummit
A case for identities - Etisalat, George Held at TADSummitA case for identities - Etisalat, George Held at TADSummit
A case for identities - Etisalat, George Held at TADSummit
 
Secure E-Banking with KOBIL technologies
Secure E-Banking with KOBIL technologiesSecure E-Banking with KOBIL technologies
Secure E-Banking with KOBIL technologies
 
Going beyond MFA(Multi-factor authentication)-Future demands much more
Going beyond MFA(Multi-factor authentication)-Future demands much moreGoing beyond MFA(Multi-factor authentication)-Future demands much more
Going beyond MFA(Multi-factor authentication)-Future demands much more
 
Security & Seamless CX in User Authentication: How to Achieve Both?
Security & Seamless CX in User Authentication: How to Achieve Both?Security & Seamless CX in User Authentication: How to Achieve Both?
Security & Seamless CX in User Authentication: How to Achieve Both?
 
ISS SA le presenta IdentityGuard de Entrust
ISS SA le presenta IdentityGuard de EntrustISS SA le presenta IdentityGuard de Entrust
ISS SA le presenta IdentityGuard de Entrust
 
SOTP_Introduction
SOTP_IntroductionSOTP_Introduction
SOTP_Introduction
 
Digital Payment and 3-D Secure by Netcetera
Digital Payment and 3-D Secure by NetceteraDigital Payment and 3-D Secure by Netcetera
Digital Payment and 3-D Secure by Netcetera
 
Axiom protect-2.0-with-one identity
Axiom protect-2.0-with-one identityAxiom protect-2.0-with-one identity
Axiom protect-2.0-with-one identity
 
Mtel Cash Mobile Commerce Suite
Mtel Cash Mobile Commerce SuiteMtel Cash Mobile Commerce Suite
Mtel Cash Mobile Commerce Suite
 
Two Factor Authentication Using Smartphone Generated One Time Password
Two Factor Authentication Using Smartphone Generated One Time PasswordTwo Factor Authentication Using Smartphone Generated One Time Password
Two Factor Authentication Using Smartphone Generated One Time Password
 
case-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_encase-study-on-digital-identity-swisscom-mobile-id_en
case-study-on-digital-identity-swisscom-mobile-id_en
 
E banking
E   bankingE   banking
E banking
 
N044057478
N044057478N044057478
N044057478
 
Procert Authentication Platform by Mcarbon
Procert Authentication Platform by McarbonProcert Authentication Platform by Mcarbon
Procert Authentication Platform by Mcarbon
 
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...
Improvement of a PIN-Entry Method Resilient to ShoulderSurfing and Recording ...
 
Mobile payments and PCI DSS
Mobile payments and PCI DSSMobile payments and PCI DSS
Mobile payments and PCI DSS
 
SmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication marketSmartCard Forum 2011 - Evolution of authentication market
SmartCard Forum 2011 - Evolution of authentication market
 
Emerging Technologies in Payment Industry
Emerging Technologies in Payment IndustryEmerging Technologies in Payment Industry
Emerging Technologies in Payment Industry
 
120 i143
120 i143120 i143
120 i143
 
A secure communication in smart phones using two factor authentication
A secure communication in smart phones using two factor authenticationA secure communication in smart phones using two factor authentication
A secure communication in smart phones using two factor authentication
 

Cidway Bank Finance 01 2009 2 Fa Tr

  • 1. DISCOVER CIDWAY Mobile Security, Authentication & Transactions’ Signature 2009
  • 2.
  • 3.
  • 4.
  • 5.
  • 6. Scenario 2: Challenged out-of-band Transaction Signature
  • 7.
  • 8.
  • 10.
  • 11. Head Quarters in Lausanne, CH
  • 12. Sales Offices in Switzerland & UK
  • 13.
  • 16.
  • 17. Making Authentication & Transactions simple, easy, accessible, secure and user friendly
  • 18. Addressing virtually unlimited vertical applications from one platform
  • 19.
  • 21. CIDWAY GAIA / SESAMI Product Line One server for multiple tokens SESAMI SlimTime based OTP Hardware token SESAMI MobileTime based OTP Software token for mobile phones. SIM enabled GAIA ServerAuthentication platform GAIA SDKAuthentication platform SDK SESAMI Mobile SDKTime based OTP Token SDK for mobile phones SESAMI SMSSMS based OTP for mobile phones SDK: Software Development Kit
  • 22.
  • 24. Low on-going costCIDWAY SESAMI SMS FEATURES & CHARACTERISTICS Strong two-factor authentication No need for software installation or activation in the mobile No secret stored in the mobile User convenience – no need to carry any other device User can change his mobile phone time zone or time Easy management – no need to maintain stock and distribute hardware tokens Easy deployment, no need for tokens maintenance Works with any SMS enabled mobile phone or PDA OTP FEATURES 8 decimal digits (or optionally 8 hex-digits) Time-based combined with challenge-response SHA-1 algorithm Validity of few seconds (server parameter) Automatic time management by the server
  • 25.
  • 27. Low on-going costCIDWAY SESAMI Slim FEATURES & CHARACTERISTICS Portable, personal and robust (3.2 mm thickness – credit card size) 2 line clear LCD display Replaceable battery (token’s data is not erased during battery replacement) Time based OTP – new OTP every second 8 characters length OTP (hex-decimal or decimal) Initialization through a secure two way IR protocol using the SESAMI initialization set Device protected by user-selected PIN (configurable parameter [0-15 tries]) Protection against token physical attacks (temper evidence) Protection against user physical attacks (stress PIN) Customizable operational parameters 12 operational buttons No need for reader or other equipment Customizable front panel
  • 28.
  • 29. OTP time management to the second
  • 30. Protection against theft or loss of mobile phone: PIN not stored on Mobile, neither transmitted, neither stored on the server (patented solution)
  • 31.
  • 32. Automatic time synchronization (support of any clock change on the mobile)
  • 33.
  • 34. 2-way authentication (server is authenticated by the User)
  • 35. Transaction’s signature (guarantee the integrity of transactions, against MitM)
  • 38. Mobile SDK for integration into any existing mobile application (*) S1-2009
  • 39. CIDWAY Download (Sesami Mobile only) Download Over the Air (Push, Pull) eMail PC Download Pre-loaded Bluetooth Etc. Registration Options: Automatic WAP registration Manual user registration Download Site (sample)
  • 41.
  • 42. Lower the cost of acquisition & maintenance
  • 43. Lower the cost of deployment & replacement
  • 44. Lower transactions’ cost & dispute support
  • 46.
  • 47. A device that the User already has (mobile phone)
  • 48. Simple & easy to use
  • 49.
  • 50. Mobile SDK for integration in any existing mobile application
  • 52.
  • 53. Registration and Activation - Ability to ensure convenient & secure registration procedure for CIDWAY mobile tokens
  • 54. Time Management- Ability to time-stamp the OTP and Transaction Signature to the second and to allow an off-line (after-the-fact) verification of the OTP or the Signature.
  • 55.
  • 56. 2-Way Authentication – ensuring the User he’s connected to the right server
  • 57. Transaction Signature – preventing MitM attacks, with uniquely customizable fields
  • 58.
  • 60. Scenario 1 – Simple out-of-band Transaction Signature BANK BANK TRANSFER BANK Login using Cidway’s OTP & two-way authentication; Go on the Transfer page Cidway Token will generate an 6 digits time based Transaction Code, using the data certification algorithm using input data 1 BANK Transaction Code 560429 Amount Tr. Code Phone will display Transaction Code The web page will display all the fields for a bank transfer including IBAN. BN: BN: BN: 9 9 9 9 4 6 4 6 2 5 2 5 9 9 9 9 0 9 0 9 1 1 9 9 5 6 0 4 2 9 BANK 9 9 9 4 9 6 9 1 BANK TRANSFER 4 2. Input Transfer information as usual (IBAN, Amount, date, etc) 2 BANK Amount Tr. Code BANK TRANSFER 10’546.55 4. Input the displayed code on the Web page and VALIDATE Tr. Code Amount 5 6 0 4 2 9 10’546.55 Application server will receive all information and transmit IBAN & TrCode to Authentication server, that will process an authentication & a data certification. BANK 3 data 3. Input the 8 digits on the mobile phone and Input PIN Code 99969491 PIN Code ******
  • 61.
  • 62. Security: prevents from changing Bank Transfer information (MitM attacks) as it protects digits of the IBAN (and amount), using Data Certification
  • 63. Security: Data Certification & Strong Authentication, time based and time stamped.
  • 64. Simplicity: does not require encryption and seamless integration into existing infrastructure
  • 65. Improve ROI: same application can be used for mBanking, ATM fraud fighting, Login…BANK The data to input on the phone can vary depending on the required level of security, can also apply to the amount or any other data of the transfer. The CIDWAY Mobile application can be customized accordingly to match input fields (from 1 to 4, alpha, titles, etc.)
  • 66. Scenario 2 – Challenged out-of-band Transaction Signature BANK TransferenciaBancaria Login using Cidway’s OTP & two-way authentication; Go on the Transfer page BANK Cidway Token will generate an 8 digits time based OTP, using the data certification algorithm with input data from web site 1 BANK Transaction Code 560429 Amount Tr. Code The web page will display all the fields for a transfer including IBAN, with 8 digits pre-highlighted (the Challenge – randomly selected* changed for each transfer) Phone will display Transaction Code IBAN: IBAN: IBAN: 9 9 9 9 2 9 0 2 9 0 4 6 4 6 0 2 1 5 0 2 1 5 9 9 9 9 0 9 9 0 9 9 1 1 9 9 5 6 0 4 2 9 (*) see next slide BANK 9 4 2 9 9 0 9 1 H C H C TransferenciaBancaria 4 2. Input Transfer information as usual (IBAN, Amount, date, etc) 2 BANK Amount Tr. Code BANK TRANSFER 10’546.55 4. Input the displayed code on the Web page and VALIDATE Tr. Code Amount 5 6 0 4 2 9 10’546.55 Application server will receive all information and transmit IBAN & TrCode to Authentication server, that will process an authentication & a data certification. BANK 3 3. Input the highlighted 8 digits on the phone and Input PIN Code data 92909941 PIN Code ******
  • 67.
  • 68. Security: prevents from changing Bank Transfer information (mitM Attacks) as it protects digits of the IBAN (and amount), but selected randomly, using Data Certification
  • 69. Security: combines Challenge Response, Data Certification & Strong Authentication, time based and time stamped.
  • 70. Simplicity: does not require encryption and seamless integration into existing infrastructure
  • 71. Improve ROI: same application can be used for mBanking, ATM fraud fighting, Login…BANK The number of pre-highlighted digits can vary depending on the required level of security, can also apply to the amount or any other data of the transfer. Taking into account the IBAN structure, the pre-highlighted digits, even though selected with a random generator, should always include digits in the Bank Code, Branch Code and Account. IBAN format: ESkk BBBB GGGG KKCC CCCC CCCC - B = bank code, G=Branch/office number, K=Check digits, C = account No.
  • 72. Scenario 3 – Automated out-of-band Transaction Signature BANK BANK TRANSFER OTA Communications BANK 3 1 BANK Send Send Date IBAN CH99122900599969491 Amount 10’546.- Date 09.10.08 3. User will verify displayed information received directly on the BANK Mobile application, press YES and input his PIN Code. Amount Login using Cidway’s OTP & two-way authentication; Go on the Transfer page PIN ****** IBAN: IBAN 9 9 9 2 0 4 6 2 0 1 5 9 9 9 0 9 1 9 H C BANK BANK TRANSFER 2 The Application Server will send transfer data (using OTA communications to the pre-registered mobile number), that will be directly displayed by the BANK Mobile application (no search in sms inbox…). When the User validate & input his PIN Code it will generate a time based Transaction Code, with Data Certification of the entire data set, with NO data input from the User. The BANK Mobile application will then send (OTA) this Code to the Application Server (an alternative is for the User to input the displayed OTP on the PC to avoid a second OTA communication), that will finalize the transaction and acknowledge it on the Web. Date 09 / 10 / 08 Amount 10’546.00 2. Input transfer information as usual (IBAN, Amount, date, etc) and click SEND Application server will receive all information and transmit IBAN & Amount to the BANK Mobile Phone application (already opened) for validation.
  • 73.
  • 74. Security: prevents any attacks on the PC as the transaction is validated and signed completely out-of-band (MitM Attacks), using a strong time based algorithm.
  • 75. Security: combines Challenge Response, Data Certification & Strong Authentication, time based and time stamped.
  • 76. Simplicity: does not require encryption and seamless integration into existing infrastructure
  • 77. Improve ROI: same application can be used for mBanking, ATM fraud fighting, Login…
  • 78.
  • 79. THANK YOU FOR YOUR ATTENTION For more information, contact: Laurent FILLIAT VP Strategic Business Mob. +41 78 842 11 47 Tel. +41 21 331 27 00 Fax +41 21 331 27 09 Email: laurent.filliat@cidway.com