Payeezy.com Security in Apple Pay In-App Development
|
|
- Barbara Morris
- 6 years ago
- Views:
Transcription
1 Payeezy.com Security in Apple Pay In-App Development TM Unlike wallets of the past that saw weak consumer engagement, demand for Apple Pay is being driven directly by consumers. Today, developers are seeing the advantages of engaging in in-app development for Apple Pay and, in particular, coding apps using the Payeezy.com platform.
2 Introduction Never before has the timing been so right to bring everyone together in the payments ecosystem and open a new world of possibilities. It s an exciting time for consumers because convenient payment options are now built right into Apple s newest devices. Unlike previous attempts to introduce mobile payments/wallets, Apple has taken a consumer-centric approach to address mobile payments that includes participants from all over the ecosystem: card associations, banks, payments processors, mobile carriers, and more. What does this mean for consumers? Ubiquity and the expectation that merchants everywhere should start accepting mobile payments. It s also an exciting time for developers. When Apple Pay debuted on October 20, 2014, media hype concentrated mostly on in-store use with contactless terminals. However, in an interview with the Wall Street Journal, Apple SVP Eddie Cue stated that they expect most of their early transactions to be in-app. 1 Apple Pay in-app payments don t require the NFC chip that in-store Apple Pay payments require. But in-app payments do require Apple s TouchID. Consumers using in-app with Apple Pay can pay for items by using a single touch on their device s fingerprint sensor. This alleviates the previous time-consuming processes that required users to create an account and register a credit card. Five companies originally partnered with Apple to provide the API and SDKs necessary to develop in-app payment solutions for Apple Pay. First Data built an Apple Pay developer portal on Payeezy.com and was the first of the five to launch. Payeezy.com provides all the tools necessary to successfully incorporate payments in an app, set up a merchant account on behalf of your client and swiftly get paid. To make that happen, Payeezy.com provides the ios SDK, RESTful API, sample code, a knowledge base, developer blog, developer support and the ability to test and certify apps coded for Apple Pay payment processing. 1 Wakabayashi, D. a. (2014, October 20). Apple Pay Rolls Out, With Limits. Wall Street Journal. firstdata.com 2016 First Data Corporation. All rights reserved. 2
3 How Apple Pay In-App Payments Work For payment integrations that are created from APIs on the Payeezy.com site, or any of the other payment providers, the process of how inapp payment generally works is the same from Apple s prospective: Apple first receives encrypted transaction information and re-encrypts the information with a merchant-specific key before sending it to the merchant. Only anonymous transaction information is retained by Apple Pay. Even what the user is purchasing is not retained. When an app requests a payment, it calls an API to determine information such as whether the device supports Apple Pay, if the user has credit cards that work on a payment network accepted by the merchant, and other pieces of information it needs to conduct the transaction. Next, the app requests ios to present the Apple Pay payment sheet. The full set of information requested by the app isn t provided until the user authorizes the payment with Touch ID or the device passcode. Once authorized, the information presented in the Apple Pay payment sheet will be transferred to the merchant. The Secure Element then passes it to the Apple Pay Servers, which, in turn: decrypt the credential verify the nonce in the credential against the nonce sent by the Secure Element re-encrypt the payment credential with the merchant key associated with the Merchant ID. returns it to the device and the app via the API where the app sends it to the merchant system for processing. The merchant can then use its private key to decrypt the payment credential for processing. The Apple Pay in-app payment process requires a cryptographic nonce which is different from the in-store payment process of obtaining a value returned by the NFC terminal. The app calls the Apple Pay Servers to obtain the cryptographic nonce. The nonce and other transaction data is passed to the Secure Element that generates a payment credential that will be encrypted with an Apple key. firstdata.com 2016 First Data Corporation. All rights reserved. 3
4 A New Standard in ization Gateway-Side ization However, there are some differences between how in-app solutions have traditionally processed payments and a new standard in tokenization with Apple Pay that are important to understand Most ecommerce developers are familiar with the concept of credit card vaults, which receive the and replace it with a token to use instead. Many of the most popular providers use these vaults in their payment gateways including First Data with the TransArmor solution. This type lets users put credit cards on file and can be referred to as gateway-side tokenization. The defining characteristic of these tokens is that they re scoped to a single merchant. They re useful for a developer who wants to keep a credit card on file to enable low-friction transactions. But they don t have the burden of securing and maintaining a database of s and the associated compliance issues. 2 Here s the authorization flow when a gateway-side token is used: $10 Sale $10 Sale $10 Sale App Site Gateway Aquirer Processer Payment Network $10 Sale Vault Gateway-Side ization Issuer Platform First Data has participated in gateway-side tokenization for years, not only for TransArmor, but also in how the company processes most web- and mobile-type transactions. 2 Beatty, J. (2014, September 9). How Apple Pay works and why it matters for developers. Clover Developers Blog. Retrieved from firstdata.com 2016 First Data Corporation. All rights reserved. 4
5 Network-Level ization With the onset of Apple Pay, a new form of tokenization emerged; one that is closely associated with EMV TM, and that payment networks such as Visa, MasterCard, American Express, etc. built. This new form is referred to as network-level tokenization. More on EMVCo specifications can be downloaded here: EMV Payment isation Specification Technical Framework. 3 Here s the authorization flow when a network-side token is used: $10 Sale $10 Sale $10 Sale App Site Gateway Aquirer Processer Payment Network $10 Sale Vault Service Provider Issuer Platform Network-Side ization First Data, through its partnership with Apple in the launch of Apple Pay, is intricately involved with network-level tokenization. Payeezy.com and, as a result, any developer coding in-app solutions on the Payeezy.com platform uses network-level tokenization. Network-level tokens are very different. They are essentially aliases for s that are exchanged during an authorization by the network. These tokens are provisioned (see below) into the secure element on the iphone 6 and used in authorization flows (further protected with 3-D Secure see above). 4 3 EMVCo. (2014). EMV Payment isation Specification - Technical Framework. EMVCo. 4 Beatty, J. (2014, September 9). How Apple Pay works and why it matters for developers. Clover Developers Blog. Retrieved from firstdata.com 2016 First Data Corporation. All rights reserved. 5
6 This is the typical way that a developer would provision a token:, Exp, CVV, AVS Site or App Payment Gateway Vault Validate Card Payment Network Provisioning As network-level tokenization evolves to other development outside the Apple Pay ecosystem, First Data will continue to be a leader. Key Key Takeaways Takeaways for for Network-Side ization They look like standard s -- e.g. they re 16 digits. They re mostly compatible with the existing payment processing infrastructure. The tokens are issued within a special BIN in the network s routing tables that flag it as a token rather than standard. They are exchanged via the network by Service Providers, a new role in the ecosystem. They are provisioned via a into a secure element of a mobile device or some other secure enough storage (perhaps Android HCE), facilitated by the issuing bank. For more on tokenization, refer to: A Primer on Payment Security Technologies: Encryption and ization 5 5 McMillon, T. H. (2011). A Primer on Payment Security Technologies: Encryption and ization. First Data. firstdata.com 2016 First Data Corporation. All rights reserved. 6
7 3-D Secure 3-D Secure is the way network-level and EMV tokenization is supported on Payeezy.com. 3-D Secure is an XML-based protocol developed by Visa and marketed as Verified by Visa. A version was adopted by MasterCard under MasterCard SecureCode, by JCB International as J/Secure, Diners Club as ProtectBuy SM and American Express as AMEX SafeKey. It is the on-line counterpart to in-store EMV solutions to prevent fraud. On Payeezy.com, 3-D Secure provides authentication from the issuing bank to use the token that has been provisioned onto the iphone. To explain, the JSON Dictionary holds encrypted payment information including: Type A which specifies an Apple Pay transaction The public key certificate corresponding to the merchantidentifier set on the original PKPaymentRequest Refer to Apple Pay documentation. The cryptographic algorithms used to sign and encrypt the payload. Refer to Apple Pay documentation Additional information needed to decrypt and verify the payment. The code below shows you what a transaction message to a gateway looks like before 3-D Secure and after 3-D Secure: Without 3-D Secure With 3-D Secure { } merchant_ref : Astonishing-Sale, transaction_type : purchase, method : credit_card, amount : 1299, currency_code : USD, credit_card : { type : visa, cardholder_name : John Smith, card_number : , exp_date : 1014, cvv : 123 } { merchant_ref : merchant-specific-info (This is optional), transaction_type : purchase, method : 3DS, 3DS : { type : A, version : EC_v1, merchantidentifier : mock-1, applicationdata : VGhpcyBpcyBzb21lIHRlc3QgZGF0YS4gIDAxMjM0NTY3ODk=, data : v6cqgdrjcjucldprksqit..., signature : AKCAMIIBoTCCAUgCAQEwCQYHTBFMQswCQYDVQQGEwJVUzE..., header : { applicationdatahash : 4b5745dd55d72886c06a2c65bb05..., ephemeralpublickey : MFkwEwYHKoZIzj0CAQYIKoZIzj0D..., publickeyhash : YmSWN7lj4+A6fVJVPicP8TgS7gI7oug..., transactionid : } firstdata.com 2016 First Data Corporation. All rights reserved. 7
8 Certifying an App On Payeezy.com There are three levels of developer engagement on the developer portion of Payeezy.com: 1. Anonymous 2. Registered 3. Certified At each level, developers gain increasingly more access and capability. Anonymous Anonymous is just like it sounds. Developers at this level have an un-registered, anonymous account with the following resources: The Apple Pay SDK Starter Kit: Downloadable files and code needed to start creating an app Sample Project Access a sample project (named SampleCharge) in XCode to get hands-on familiarity with the code that drives Apple Pay and Payeezy. Frameworks First Data provides two frameworks that you can drop into your project to start accepting Apple Pay transactions: InAppSDK.framework Enables your app to communicate with the ios device. Masks the complexity of dealing with Apple APIs. PayeezyClient.framework ios client for the API. Enables the handshake with First Data through HTTP calls to the Payeezy API Developers at the anonymous level also have full access to Payeezy.com support, forums, FAQ area and the Payeeyz.com blog. This includes the ability to ask questions, get answers, get tips, see what s new with Payeezy and Apple Pay and learn about upcoming events. firstdata.com 2016 First Data Corporation. All rights reserved. 8
9 Registered For more functionality including the ability to test accounts, a developer has to move to the registered level. This is provided through the Register Now link on the developer.payeezy.com site. This level requires developers to provide a name and address. Once the account is set up, three of the four credentials needed to get started developing an Apple Pay-enabled app are provided: an API Key, an API Secret and a Merchant. These credentials allow the developer to set-up a test account by clicking on My APIs. Payeezy.com Sandbox *Registered Payeezy.com developers can access the sandbox, which mimics a live Apple Pay production environment Create a set of test accounts Format your Payeezy API requests using your API Key, API Secret, Merchant and Apple Pay Merchant ID Run tests against the Payeezy API Review the responses and modify your code as necessary The fourth credential, an Apple Merchant ID, allows the ability to generate the Certificate Signing Request that Apple requires. This step can be complete only after registering on developer.payeezy.com. To obtain an Apple Merchant ID: 1. Go to developer.apple.com and log into your developer account. 2. From the Member Center, navigate to Certificates, Identifiers & Profiles. 3. Go to the Register Merchant IDs section. Your Merchant ID is located in the Identifier field. 4. Click Done At this point, the developer has full ability to code, create and test an Apple Pay-enabled app. firstdata.com 2016 First Data Corporation. All rights reserved. 9
10 Certified Developers should fully test their app to determine that it is working and bug-free before moving to the self-certification step. Then it is time to certify the app and start boarding merchants. To Certify an App on Payeezy.com 1. Log in to developer.payeezy.com 2. Navigate to Get Certified 3. Complete the form 4. First Data will validate the app s transactions and identify any issues 5. If everything is performing properly, certification is issued After a developer certifies an app, there are three steps that need to be taken before payments can start being accepted on the Apple Pay payment platform. 1. Add Merchants 2. Generate a Certificate Signing Request 3. Submit the Certificate Signing Request to Apple firstdata.com 2016 First Data Corporation. All rights reserved. 10
11 These steps are outlined below: To Add Merchants on Payeezy.com 1. Log in to developer.payeezy.com. 2. Navigate to Add Merchants 3. Answer the question Are you the Merchant? If you are acting as a merchant select Yes. If you will be adding merchants who will use your app, select No, I m adding other Merchants 4. If you plan to use Apple Pay in your app, check the Enable this Merchant for Apple Pay checkbox 5. Select Submit and you will be taken to the Notify Merchant screen 6. Enter the contact information about your Merchant and the captcha and select Notify Merchant. This will invite your Merchant to create a Merchant Account. You will be notified when your Merchant has completed the process. Log in to developer.payeezy.com. Generate a Certificate Signing Request (CSR) 1. Log in to developer.payeezy.com. 2. Click on My Merchants from the top menu 3. If you have only completed the lite registration, you will see the CSR as part of your test merchant account on the sandbox tab. If you have completed full registration/certification and are looking for the CSR for your specific merchant(s), select the Live tab. You will need the CSR to transact in either case (in sandbox or live) 4. Once you have identified the CSR you want to download, right click on it and select Save As and save the.pem file to your desktop where you can easily get to it later in the process Submitting your Merchant Certificate Signing Request (CSR) to Apple 1. Login to your apple developer account 2. Go to Certificates, Identifiers & Profiles from the Member Center 3. Click Edit on the Merchant ID page and select Create Certificate 4. Follow the instructions on screen to upload and submit your CSR firstdata.com 2016 First Data Corporation. All rights reserved. 11
12 CONCLUSION In the context of the US market s development, Apple Pay has arrived at a better time than Google Wallet and has a much better chance of wide-spread adoption. New tokenization standards and the adoption of 3-D Secure technology are making the advantages of using Apple Pay clear in terms of security. With Apple Pay, the retailer only sees a token, but not which card or bank has been used. The retailer can t store bank card details, addresses or passwords because it simply does not get them in the first place. Companies like First Data, through their developer portal on Payeezy.com, are paving the way in creating cutting edge environments that utilize new security standards such as network-level tokenization and more. Unlike wallets of the past that saw weak consumer engagement, demand for Apple Pay is being driven directly from the consumer level. Increased privacy and better fraud control have great appeal to a market shell-shocked by repeated news of data security breaches at major retailers. Uncertainties do exist, with disadvantages voiced by some of the larger retailers as well as from companies like Google. Concerns about the inability to track purchases or the use of loyalty card solutions top the list. They point to Apple Pay s lack of global availability. Though alternative contactless systems have long since been adopted in other parts of the world, Apple Pay isn t scheduled to work outside the United States until As a result, some experts and research firms, such as Juniper, predict that Apple Pay will only have a small share of the market by However, developers are seeing the advantages of engaging in in-app development for Apple Pay and, in particular, coding apps using the Payeezy.com platform. Driven by an exploding app market - app analytics firm Distimo states in-app purchases represents 92% of the $10 billion consumers spent in the Apple App Store in developers are rushing to engage with companies such as First Data who are seen as leading the way in enabling the creation of in-app solutions on Apple Pay. For more information, contact your First Data Representative or visit firstdata.com 6 Agten, T. v. (2013). Games: King of the mobile eco-system. Distimo. This White Paper is for informational purposes only. FIRST DATA MAKES NO WARRANTIES, EXPRESS OR IMPLIED, IN THIS WHITE PAPER. First Data cannot be responsible for errors in typography or photography. First Data, Payeezy, and Payeezy.com are trademarks of First Data Corporation. All trademarks, service marks and trade names reference in this material are the property of their respective owners EMV TM is owned by EMVCO LLC. Apple and iphone are trademarks of Apple Inc., registered in the U.S. and other countries. Apple Pay is a trademark of Apple Inc. EMV TM is a trademark owned by EMVCo LLC. Other trademarks and trade names may be used in this document to refer to either the entities claiming the marks and names or their products. First Data disclaims proprietary interest in the marks and names of others. Information in this document is subject to change without notice. firstdata.com 2016 First Data Corporation. All rights reserved
Ensuring the Safety & Security of Payments. Faster Payments Symposium August 4, 2015
Ensuring the Safety & Security of Payments Faster Payments Symposium August 4, 2015 Problem Statement: The proliferation of live consumer account credentials Bank issues physical card Plastic at point
More informationTokenization April Tokenization. Gregory H. Soule, CPA, CISA, CISSP, CFE Senior Manager. Andrews Hooper Pavlik PLC
ization Gregory H. Soule, CPA, CISA, CISSP, CFE Senior Manager Andrews Hooper Pavlik PLC 1 Agenda and Implementation EMV, Encryption, ization Apple Pay Google Wallet Recent Trends Resources Agenda and
More informationOnline Payment Services
A NetPay Guide to... Online Payment Services Online payments, also commonly referred to as CNP or Cardholder not present are those that provide the capability for a purchase to be made without physically
More informationCovering Your Assets: Payment Landscape and Technology
Covering Your Assets: Payment Landscape and Technology Keith Lam Sr. Product Manager 2016 Epicor Software Corporation Keith Lam Senior Product Manager 9+ years at Epicor, focusing on building great products
More informationX Infotech Banking. Software solutions for smart card issuance
X Infotech Banking Software solutions for smart card issuance WWW.X-INFOTECH.COM About X Infotech provides turnkey software solutions for centralized and instant issuance of financial and non-financial
More informationQuick Guide. Token Service Provider
Quick Guide Token Service Provider 1 Introduction to Mobile Payments The mobile payments revolution is here! Driven by the development of near field communication (NFC) enabled smartphones, the launch
More informationMobile and Contactless Payments Requirements and Interactions
Mobile and Contactless Payments Requirements and Interactions Version 1.0 Date: February 2018 2018 U.S. Payments Forum and Smart Card Alliance. All rights reserved. Page 1 About the U.S. Payments Forum
More informationTokenization: What, Why and How
Tokenization: What, Why and How 11/5/2015 UL Transaction Security 2011 Underwriters Laboratories Inc. We have EMV why do we need tokenization? From Magstripe Merchant Signature Issuer Magstripe Risk Management
More informationApple Pay and Tokenization Background and Overview
A Euronet Software Solutions White Paper Apple Pay and Tokenization Background and Overview By Stephen Butcher Euronet Software Solutions Product Manager Cards and Networks November 2014 2014 Euronet Software
More informationVisa s Future of Security Roadmap: Australia
Visa s Future of Security : Australia Contents Executive Summary 3-Domain Secure 2.0 Biometrics Tokenisation EMV Chip Technology Expanding Mobile Acceptance Mobile Geo-location Transaction Controls and
More informationNetSuite Integration for CyberSource. Getting Started Guide
NetSuite Integration for CyberSource Getting Started Guide December 2017 Contents Introduction... 3 Configure Your CyberSource Account... 3 Configure Your NetSuite Account... 5 Add a New CyberSource Credit
More informationIntroduction to EMV BEYOND PAYMENT
Introduction to EMV TAKING YOU TAKING YOU BEYOND PAYMENT Why EMV? Security Magstripe cards are easily reproduced EMV can verify card and user authenticity Chip & PIN Interoperability The world has moved
More informationTokens, Tokens, Tokens: What are the different kinds of tokens and what do they do?
Tokens, Tokens, Tokens: What are the different kinds of tokens and what do they do? Lanny Byers, VP Emerging Payment Solutions February 25, 2019/3:30PM/Grand Ballroom J-K The way consumers buy has changed
More informationEMV 3-D Secure Press Kit Q&A
EMV 3-D Secure Press Kit Q&A 1. What is EMV 3-D Secure? EMV 3-D Secure (3DS) is a messaging protocol that promotes frictionless consumer authentication and enables consumers to authenticate themselves
More informationAuthorize.Net Mobile Application
Authorize.Net Mobile Application Version 3.3.1 for ios and Android User Guide November 2017 Authorize.Net Developer Support http://developer.authorize.net Authorize.Net LLC 082007 Ver.2.0 Authorize.Net
More informationEMV Chip Cards. Table of Contents GENERAL BACKGROUND GENERAL FAQ FREQUENTLY ASKED QUESTIONS GENERAL BACKGROUND...1 GENERAL FAQ MERCHANT FAQ...
EMV Chip Cards FREQUENTLY ASKED QUESTIONS Table of Contents GENERAL BACKGROUND...1 GENERAL FAQ...1 4 MERCHANT FAQ...5 PROCESSOR/ATM PROCESSOR FAQ... 6 ISSUER FAQ... 6 U.S.-SPECIFIC FAQ...7 8 GENERAL BACKGROUND
More informationEMV Secure Remote Commerce. Frequently Asked Questions (FAQ)
EMV Secure Remote Commerce Frequently Asked Questions (FAQ) 1. What is EMV * Secure Remote Commerce? EMV Secure Remote Commerce (SRC) offers an approach to promote security and interoperability within
More informationTokenization: The Future of Payments
Tokenization: The Future of Payments Security? Background The Payment Card Industry Data Security Standard (PCI-DSS) was created to increase controls around cardholder data to reduce credit card fraud
More informationOn-Demand Solution Planning Guide
On-Demand Solution Planning Guide Powering On-Demand Solutions www.growthclick.com hello@growthclick.com Copyright 2019 GrowthClick Inc. All Rights Reserved. 1 3 Steps to Planning an On-Demand Solution
More informationHow Safe Are Mobile Payments? MAC Webinar
How Safe Are Mobile Payments? MAC Webinar March 16, 2017 Dave Lott Payments Risk Expert Federal Reserve Bank of Atlanta The views expressed in this presentation are those of the presenters and do not necessarily
More informationEMV 3-D Secure provides the path to fast, frictionless authentication
EMV 3-D Secure provides the path to fast, frictionless authentication MASTERCARD IDENTITY CHECK TM Current landscape As countries around the globe make the move to EMV chip, organized crime will look for
More informationIgnite Payment s Program on EMV
Ignite Payment s Program on EMV 2015 First Data Corporation. All Rights Reserved. All trademarks, service marks and trade names referenced in this material are the property of their respective owners.
More informationCiti Pay App Frequently Asked Questions
Citi Pay App Frequently Asked Questions 1. What is Citi Pay? Citi Pay provides the convenience of making secure, in-store payments using your compatible Android mobile phone. This is an optional feature
More informationRealex Payments Redirect/Remote PrestaShop Module for v 1.5+
Realex Payments Redirect/Remote PrestaShop Module for v 1.5+ Integration Guide Version: v 1.0 Document Information Document Name: Realex Payments Redirect/Remote PrestaShop Extension s v 1.5 Document Version:
More informationVolume PLANETAUTHORIZE PAYMENT GATEWAY. SugarCRM Payment Module. User Guide
Volume 2 PLANETAUTHORIZE PAYMENT GATEWAY SugarCRM Payment Module User Guide S A L E M A N A G E R M E R C H A N T S E R V I C E S User Guide and Installation Procedures Information in this document, including
More informationThe Future of Payment Security in Canada
The Future of Payment Security in Canada October 2017 1 Visa Canada Public The Future of Payment Security in Canada Notices Forward-Looking Statements This presentation contains forward-looking statements
More informationEMV FAQ S FROM A MERCHANT S PERSPECTIVE
EMV FAQ S FROM A MERCHANT S PERSPECTIVE WHAT IS EMV? EMV, or Europay MasterCard Visa, is a fraudreducing technology that can help protect issuers, merchants and consumers against losses from the use of
More informationCommerce Driver. ios Quick-Start Guide v1.0
Commerce Driver ios Quick-Start Guide v1.0 Understanding EMV Certification... 2 What is EMV?... 2 How Does it Work?... 2 Becoming EMV Compliant... 2 Level 1 Hardware/Terminal Certification... 2 Level 2
More informationPayment Acceptance Solutions
Payment Acceptance Solutions Increase sales, enhance agility, and mitigate risks with CyberSource CyberSource is a Visa solution Businesses today are developing new strategies for acquiring and retaining
More informationHow to Guide. &FAQ s
How to Guide &FAQ s About Rewards Being part of the Landcare family means you can access hundreds of discounted offers from leading Australian retailers. Take up these offers and you'll also build rewards
More informationDeltek Touch Time & Expense for GovCon 1.2. User Guide
Deltek Touch Time & Expense for GovCon 1.2 User Guide May 19, 2014 While Deltek has attempted to verify that the information in this document is accurate and complete, some typographical or technical errors
More informationDIGITAL CREDIT for EMV QR Credit Card Apps
Digital Debit Group Official Document DIGITAL CREDIT for EMV QR Credit Card Apps Mobile SDK Specification Version 2.1 June 2017 2017 Digital Debit Group U.S., Qondado LLC managing partner. All Rights Reserved.
More informationHCE E-Book HOST CARD EMULATION: NFC S MISSING LINK
HCE E-Book HOST CARD EMULATION: NFC S MISSING LINK HOST CARD EMULATION: NFC S MISSING LINK Contents Executive Summary 3 1. What is HCE? 5 2. Implementation options 11 3. HCE & security: tokenization 12
More informationINNOVATION AT A GLANCE. Wally Mlynarski Chief Product Officer
INNOVATION AT A GLANCE Wally Mlynarski Chief Product Officer Product Innovation: Two Common Approaches Sustaining Innovation Problem is well understood Existing market Innovation improves performance,
More informationQuick Guide. Token Service Provider
Quick Guide Token Service Provider Introduction to Mobile Payments The mobile payments revolution is here! Driven by the development of near field communication (NFC) enabled smartphones, the launch of
More informationWHITE PAPER. Focus on value added services by network companies a paradigm shift. Rahul Kaushal, Ramakant Mittal
WHITE PAPER Focus on value added services by network companies a paradigm shift Rahul Kaushal, Ramakant Mittal Introduction Network association is the most critical player in the payment card industry.
More informationEMV Migration Updates and Next Steps
EMV Migration Updates and Next Steps Michael Carrick, US Business Development Thursday February 16, 2017 1:00 1:35 Agenda ACCEO Tender Retail Who We Are EMV Quick Facts EMV Adoption Rates EMV is a Four
More informationEMV Terminology Guide
To make life easier, TMG has compiled some of the most commonly used EMV terms in this guide. If you have questions about EMV, contact your Director of Client Relations directly or email clientrelations@themebersgroup.com.
More informationVirtual Terminal User Guide
Virtual Terminal User Guide Table of Contents Introduction... 4 Features of Virtual Terminal... 4 Getting Started... 4 3.1 Logging in and Changing Your Password 4 3.2 Logging Out 5 3.3 Navigation Basics
More informationPinless Transaction Clarifications
Pinless Transaction Clarifications April, 2017 Agenda Definition Level Set Application Selection Overview and Scenario Explanation EMV No CVM PIN Bypass Debit Expansion Programs PINless POS Product Signature
More informationWHERE DO YOU WANT TO GROW. Solutions for Community Financial Institutions
WHERE DO YOU WANT TO GROW TODAY? Solutions for Community Financial Institutions 2 Today s users demand more from their financial institution. They expect their banking experiences to be digital, easy,
More informationPayment Gateway Overview. Get familiar with credit card processing & our platform
Payment Gateway Overview Get familiar with credit card processing & our platform What Do Merchants Need to Be Successful Online? Understanding all of the working parts involved in your merchant customers
More informationEMV 3-D Secure Press Kit Q&A
EMV 3-D Secure Press Kit Q&A 1. What is EMV 3-D Secure? EMV Three-Domain Secure (3DS) is a messaging protocol that enables frictionless consumer authentication and the ability for consumers to authenticate
More informationEMV THE DEFINITIVE GUIDE FOR US MERCHANTS AND POS RESELLERS
EMV THE DEFINITIVE GUIDE FOR US MERCHANTS AND POS RESELLERS WHAT IS EMV EMV is a global standard for credit and debit card processing designed to replace magnetic stripe cards. Also referred to as chip
More informationEMV Frequently Asked Questions for Merchants May, 2015
EMV Frequently Asked Questions for Merchants May, 2015 Copyright 2015 Vantiv, LLC. All rights reserved. *EMV is a registered trademark in the U.S. and other countries, and is an unregistered trademark
More informationInnovation at Scale. James Anderson Executive Vice President Mastercard
Innovation at Scale James Anderson Executive Vice President Mastercard 1 trends in digital 2 implications for retail banking 3 Mastercard s innovations trends in digital Mobile Internet Usage mobile internet
More informationA step towards cashless economy - Unified Payments Interface (UPI)
A step towards cashless economy - Unified Payments Interface (UPI) What is Unified Payment Interface? Objective of a unified payments system is to offer an architecture and a set of APIs on top of existing
More informationEMV: Facts at a Glance
EMV: Facts at a Glance 1. What is EMV? EMV is an open-standard set of specifications for smart card payments and acceptance devices. The EMV specifications were developed to define a set of requirements
More informationADDING VALUE TO SECURITY. How Issuers Can Leverage Tokenization to Capture New Revenue-Generating Opportunities. firstdata.com
A First Data Position Paper ADDING VALUE TO SECURITY How Issuers Can Leverage Tokenization to Capture New Revenue-Generating Opportunities firstdata.com Introduction The payments world is undergoing a
More informationSemi-Integrated EMV Payment Solution
acceo tender retail Semi-Integrated EMV Payment Solution tender-retail.acceo.com Take control of your payment transactions ACCEO Tender Retail is a semi-integrated payment middleware solution that handles
More informationA CryptoCodex Ltd. Product
A CryptoCodex Ltd. Product The Pitch QRedit is a Credit Card Cyber Security Solution that is designed to allow consumers to quickly and securely shop online and on social media sites, even on an infected
More informationNovember 2016 Poynt Reseller Portal and Merchant Onboarding Activation
November 2016 Poynt Reseller Portal and Merchant Onboarding Activation 1 Outline 05 Reseller Portal 06 Deployment 07 Merchant Support 2 05 Reseller Portal A tool for onboarding and managing your Poynt
More informationProxama PIN Manager. Bringing PIN handling into the 21 st Century
Proxama PIN Manager Bringing PIN handling into the 21 st Century I am not a number I am a free man So said the The Prisoner in that 1960s cult TV show, but Personal Identification Number, or PIN, was adopted
More informationThe Small Business Guide to Mastering EMV
The Small Business Guide to Mastering EMV EMV 101 Understanding the Basics of EMV Technology Get to Know the Chip What is EMV? Understanding EMV & the Technology that Powers EMV Cards EMV, which stands
More informationSafeguarding Online Transactions, Reducing Fraud and Improving the Consumer Experience
Safeguarding Online Transactions, Reducing Fraud and Improving the Consumer Experience Gustavo Kok, Dafiti Group Frederico Trevisan, Santander Dennis Gamiello, Mastercard Introduction - Authentication
More informationSee Your Customers, Not Payment
See Your Customers, Not Payment Types, with PAR Joseph Koenig (Index) Thursday, March 1, 2018 @ 4:30PM Agenda Everything you wanted to know about PAR: What is a PAR? Why was PAR created? Where can PAR
More informationWhat Do Merchants Need to Be Successful Online?
What Do Merchants Need to Be Successful Online? Understanding all of the working parts involved in your merchant customers success online Domain Registrar Web/App Developer Web Hosting Shopping Cart Accepting
More informationFrequently Asked Questions for Merchants May, 2015
EMV Frequently Asked Questions for Merchants May, 2015 Copyright 2015 Vantiv, LLC. All rights reserved. *EMV is a registered trademark in the U.S. and other countries, and is an unregistered trademark
More informationGetting Out of PA-DSS Scope and Eliminating the High Cost of EMV: What you need to know
January 2015 Getting Out of PA-DSS Scope and Eliminating the High Cost of EMV: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2015 Heartland Payment
More informationChowNow bites into Google Wallet to enhance mobile diners convenience
http://www.mobilecommercedaily.com/chownow-bites-into-google-wallet-to-enhance-mobile-dinersconvenience ChowNow bites into Google Wallet to enhance mobile diners convenience By Michael Barris April 7,
More informationExpanding to New Verticals
Expanding to New Verticals Mobile Card Product and Feature Suite Dave Abouchar, Director New Mobile Products Krishna Rajamani, Mobile Product Manager April 12, 2017 Agenda 1. Introduction 2. Credit Card
More informationTennisCollect For Square
TennisCollect For Square Table of Contents Setting up Square for TennisCollect... 2 A few basics... 2 If you do not have a Square account,... 3 1) Create an account... 3 2) Implement Square to the point
More informationPayments - EMV Review. EMV Functionality Inside OpenOne
Payments - EMV Review EMV Functionality Inside OpenOne A Brief History EMV stands for Europay, MasterCard and Visa. It is a global standard for cards equipped with computer chips and the technology used
More informationEMV: Frequently Asked Questions for Merchants
EMV: Frequently Asked Questions for Merchants The information in this document is offered on an as is basis, without warranty of any kind, either expressed, implied or statutory, including but not limited
More informationEMV: Strengthen Your Business Through Secure Payments
PRODUCT CAPABILITY GUIDE EMV Chip Cards Payments EMV Chip Cards Payments EMV: Strengthen Your Business Through Secure Payments As EMV chip-based technology gains coverage around the world, it gets easier
More informationEMV and Educational Institutions:
October 2014 EMV and Educational Institutions: What you need to know Mike English Executive Director, Product Development Heartland Payment Systems 2014 Heartland Payment Systems, Inc. All trademarks,
More informationFINGERPRINTS BIOMETRICS THE MISSING PIECE OF THE PAYMENT CARD PUZZLE?
FINGERPRINTS BIOMETRICS THE MISSING PIECE OF THE PAYMENT CARD PUZZLE? 2018 On-card biometrics is the final piece of the puzzle to bring trust and security to contactless payments, without compromising
More informationFor ios users, requires ios 9.0 or later. For Android users, requires 4.4 or later. 4. Can I have more than 1 PayLah! wallet?
Category/Group Question and Answer General Information 1. What is PayLah! DBS PayLah! is a personal mobile wallet which allows you to perform transactions such as funds transfer via a mobile number, scan
More informationTHE FUTURE OF TRANSACTING
1 Payments - Create and Protect Recurring Revenue Opportunities THE FUTURE OF TRANSACTING The Future is Genius SuperDeck Creative v.1 10.22.2015 Who are we? 2 Our payment solutions enable businesses to
More informationPCI BLOG. P2PE, EMV, Tokenization, Oh My!
Page 1 of 8 PCI BLOG THE UNOFFICIAL PCI COMPLIANCE & IT SECURITY BLOG HOME PCI IN THE NEWS PCI TOOLS IT SEC. JOB BOARD DOCUMENTS CONTACT US FORUM P2PE, EMV, Tokenization, Oh My! June 14, 2016 PCI Blog
More informationVisa Inc Investor Day. North America. Oliver Jenkyn Group Executive, North America
Visa Inc. 2017 Investor Day North America Oliver Jenkyn Group Executive, North America Key takeaways Strong, established market position Deep client relationships, based on partnering to deliver value
More informationMaintenance and Service Interruption Alerts (archived)
Maintenance and Service Interruption Alerts (archived) 6/1/2018 12:00 pm EDT Paya has turned off communication via any protocol below TLS 1.2 as part of PCI Compliance At 12 pm EDT on Friday, June 1st,
More informationSecurity Evaluation of Apple Pay at Point-of-Sale Terminals
2016 10th International Conference on Next Generation Mobile Applications, Security and Technologies Security Evaluation of Apple Pay at Point-of-Sale Terminals Marian Margraf Freie Universität Berlin
More informationYour Gateway to Electronic Payments & Financial Services Getting Started Guide - English
Your Gateway to Electronic Payments & Financial Services Getting Started Guide - English Contents Introduction Register online for noqodi How to fund? How to execute Transactions and Payments? Conclusion
More informationAconite Smart Solutions
Aconite Smart Solutions PIN Management Services Contents PIN MANAGEMENT... 3 CURRENT CHALLENGES... 3 ACONITE PIN MANAGER SOLUTION... 4 OVERVIEW... 4 CENTRALISED PIN VAULT... 5 CUSTOMER PIN SELF SELECT
More informationTesting Solutions for Hyper-Connected Apps
Testing Solutions for Hyper-Connected Apps Don t let functionality cause testing chaos Andrew Morgan (andrew.morgan@infostretch.com) 2019 Infostretch. All rights reserved. 1 1 Your Speaker: Andrew Morgan
More informationGetting Started Guide Vipps via Netaxept
Getting Started Guide Vipps via Netaxept Version 1.2 Table of contents Vipps via Netaxept... 2 Business features and restrictions... 2 Payment flow... 3 Setting up Netaxept for use with Vipps... 6 Activation
More informationCardNav SM by CO-OP Frequently Asked Questions
CardNav SM by CO-OP Frequently Asked Questions What is CardNav SM by CO-OP? CardNav technology enables superior control, security, and financial visibility via your mobile phone. It lets you manage your
More informationInnovation In Payments. Making Sense of Apple Pay & Tokenization, EMV and CardNav
Innovation In Payments Making Sense of Apple Pay & Tokenization, EMV and CardNav TODAY S PRESENTERS CAROLINEWILLARD Executive Vice President, Markets & Strategy CO-OP Financial Services MICHELLETHORNTON
More informationMobile & Online Banking
Mobile & Online Banking Digital banking - no longer a matter of nice to have In today s world, online and mobile banking are no longer nice to have on the consumer s mind. Consumer s daily lives are seamlessly
More informationDirect Operator Billing
Direct Operator Billing 1 Platform Overview / Introduction Wallet, keys, Mobile Phone. The most personal of our daily gadgets has become the primary device through which we socialize and consume. LibancallPlus
More informationIntegrating Payments: Design Principles For A Cashless Future. Monojit Basu, Founder and Director, TechYugadi IT Solutions & Consulting
Integrating Payments: Design Principles For A Cashless Future Monojit Basu, Founder and Director, TechYugadi IT Solutions & Consulting Agenda Current and emerging techniques to integrate merchant apps
More informationIs Apple Pay free? Yes. Be aware that message and data rates may apply, depending on your data plan.
What is Apple Pay? Apple Pay allows you to pay for your purchases with your iphone 6 or iphone 6 Plus by holding your phone near a contactless reader at participating merchants. You can also use your phone,
More informationDatacap s Guide to EMV in the US
Datacap s Guide to EMV in the US A Datacap Whitepaper 2 What is EMV? 3 Datacap s experience with EMV benefit of a one-tomany interface 4 What will EMV with Datacap look like? 6 PIN Pad hardware options
More informationThe Future of Payments. Federal Home Loan Bank Conference Presented by: Brian Day
Mobile The Future of Payments Federal Home Loan Bank Conference Presented by: Brian Day Who Is The Members Group? CARDS SOLUTIONS PAYMENTS SOLUTIONS RELOAD PHOTO CARD CUSTOM SOLUTIONS SPRINGBOARD Agenda
More informationEmpowering SMBs with Big Business Tools
Empowering SMBs with Big Business Tools August 2018 The Right Plan, For Every Business vcita s all-in-one business management solution offers a wide range of value-bringing features for SMBs. vcita includes
More informationMOBILE CHECKOUT SOLUTION
MOBILE CHECKOUT SOLUTION MONEXgroup in this report introduces the Mobile Checkout Solution for merchants who process payments on-the-go using their Smartphone devices. Mobile Checkout allows businesses
More informationWhy Authentication Matters
Why Authentication Matters What you will learn today The challenges facing our industry The opportunities to adapt and improve How increasing mandates, requirements and regulations are impacting commerce
More informationCredit Card Processing Guide
Credit Card Processing Guide Detailed Overview of The Reports in The Envision Software I Credit Card Processing Within Envision Cloud Table of Contents Part I Introduction 1 Part II Processing On A Computer
More informationU.S. RETAILERS: Why You re Not as Ready as You Think for Today s Retail Payments Migration
U.S. RETAILERS: Why You re Not as Ready as You Think for Today s Retail Payments Migration By MATTHEW BRIGHT, Chair, NFC Forum Retail SIG and FRANK TEKAMPE, Chair, NFC Forum Payments SIG November, 2015
More informationPoynt Lodging App. Merchant Guide - Version 2.0
Poynt Lodging App Merchant Guide - Version 2.0 1 Poynt Co 490 South California Ave, Suite 200 Palo Alto, CA 94306 https://poynt.com COPYRIGHT 2017 BY POYNT CO This publication is proprietary to Poynt Co
More informationATM Webinar Questions and Answers May, 2014
May, 2014 Debit Network Alliance LLC (DNA) is a Delaware Limited Liability Company currently comprised of 10 U.S. Debit Networks and open to all U.S. Debit Networks. The goal of this collaborative effort
More informationEMV and Apple Pay. The world of credit cards is on the move.
EMV and Apple Pay The world of credit cards is on the move. Today we will talk about The basics of EMV and Apple Pay. There are a lot of details we could get lost in. This is a high-level overview. We
More informationIn this Document: EMV Payment Tokenisation Payment Account Reference (PAR) FAQ EMV Payment Tokenisation Technical FAQ
In this Document: EMV Payment Tokenisation General FAQ EMV Payment Tokenisation Payment Account Reference (PAR) FAQ EMV Payment Tokenisation Technical FAQ EMV Payment Tokenisation General FAQ 1. What is
More informationThe Changing Landscape of Card Acceptance
The Changing Landscape of Card Acceptance Troy Byram Vice-President Sr. E-Receivables Consultant February 6, 2015 Agenda EMV (Chip and Pin) PCI Compliance and Data Security New Regulations for Municipalities
More informationFrequently Asked Questions (FAQs):
Frequently Asked Questions (FAQs): Product Features: Q1. What is SBI Buddy Merchant App? SBI Buddy Merchant App is State Bank of India s Mobile Wallet for Merchants and Sub-Merchants to accept/collect
More informationMy Visa Long is Getting Long in the Tooth
My Visa Long is Getting Long in the Tooth September 15, 2017 by Chuck Carnevale of F.A.S.T. Graphs Introduction Over my lifetime I have invested in many different things. In the process of doing that,
More informationEMV Basics and the market
EMV Basics and the market What is a smartcard? 1 2 3 4 5 2 What is EMV? EMV is the globally adopted international standard for adding a chip on a payment card A chip is a small computer built into the
More informationCovering Your Bases: The State of EMV & Beyond
Covering Your Bases: The State of EMV & Beyond We are the world leader in digital security +2bn END USERS BENEFIT FROM OUR SOLUTIONS $3.3bn 2014 REVENUE 14,000+ EMPLOYEES 116 NATIONALITIES OF OUR EMPLOYEES
More informationVARTECH NATION. EMV Certification for IT Professionals
The modern credit card is an American invention but in the twenty-first century, Europe has led the way in credit card technology. The first smart cards, equipped with their own computer chips, showed
More information