Mobile Payment Solutions
There are various types of mobile payment systems, including:
Banks / Credit Card Companies / Dedicated Payment Processors
- Mobile Credit Card Payments
- Migrating Internet Payment Systems
Mobile Network Operators
- Utilization of existing Billing Mechanisms (Prepaid and contract
based)
Multi-Payment Method Frameworks
- Mobile Network Operators
- Dedicated Payment Processors
- Shopping Malls, Large Shops
Other Mobile Payment Systems
- Mobile Home Banking, Internet Payments, Mobile Retailer Support
The type of system implemented depends largely upon the type of
service to be supported. This may include:
- Prepaid Accounts
- Mobile Credit Card Payments
- Migrating Internet Payment Systems
- Multiple Payment Method Platforms
- Internet Payments With Mobile Phones
- Mobile Home Banking
- Mobile Retailer Support
- Other Mobile Payment Systems
An example of a simple mobile payment is using vending machines:
- Customer connects to payment center by dialing number displayed
on
vending machine
- Payment system calls vending machine and informs it that customer
can purchase the item
- When the item is selected, a response is sent to payment center
- Customer‘s phone bill charged (fixed rate call = cost
of item)
Mobile SET – Secure Electronic Transactions
Mobile SET is a Mobile Payment Standard set by Visa & MasterCard.
It is used for for secure usage of credit cards on the Internet
The standard defines key protocols between Customer, Merchant
and Payment Gateway, including:
- Cardholder registration
- Merchant registration
- Purchase Request
- Payment Authorization
- Payment Capture
Mobile SET uses public-key cryptography, and is being supported
by Credit card companies interested in alternatives to smart cards
& advanced security support in products such as:
- Server Wallets with Customer Id and PIN authorization
- Merchant initiated SET in the background, proprietary forms
in the front-end
Both these services void the main security feature of SET, i.e.
customer non-repudiation.
Issues
Certain issues are still outstanding relating to mobile payments.
These include:
1. Suitable Security Support in the Mobile Environment
- Not just UserId / PIN / TAN
- Strong Public Key Cryptography Based Security Mechanisms
- Smart Card Support
2. Mechanisms Required
- Ensure: Confidentiality, Integrity, Authentication, Non-Repudiation.
- End-2-End security between customer and merchant - –
Equivalent to SSL, WTLS mostly isn‘t good enough
- Mobile Digital Envelopes & Signatures
- Authentication and WPKI-Support
Mobile Security and Payment Standardization Bodies
- WAP Forum
- 3GPP SIM Toolkit standardization
- GMCIF - MasterCard Global Mobile Commerce Interoperability
Forum
- MSign - Brokat Mobile Digital Signature Merchant API
Back To Top
|