Friday, June 11, 2010

NEED FOR URGENT SECOND LEVEL AUTHENTICATION IN CARD BUSINESS TRANSACTION IN NIGERIA

In the recent time, there has been serious wave of card and ATM fraud that has swept across the nation in different dimension and shapes. The reasons are many and vary coupled with our business environment. The continued use of Magnetic Stripe in Nigeria has not helped matters because the security around it is far less than desired.

Other reasons for the wide spread card fraud includes but not limited to:
Lack of Awareness
Ignorance on the side of some of the card users
Security issues associated with magnetic stripe.
Poor professionalism on the issuance of the card product
Lack of requisite skill by the switching company.

It is important to state here that Magnetic Stripe has encouraged some common e-business frauds like card cloning/skimming, phishing, shoulder surfing etc which is almost eroding the confidence of the card holders and the entire banking public.

The ATMIA Security Conference in London exposed some of the flaws associated with our current magnetic stripe in Nigeria and set the road map for the more secured and globally accepted CHIP+PIN EMV compliant cards.

WAY FORWARD
The implementation of CHIP+PIN card is the way forward as the control flaws in Magnetic stripe and coupled with risk associated with our business environment is quite enormous and no stop gap measure now can offer any relief.
The implementation of the CHIP+PIN card must be very robust and futuristic as any control lapse will leave us in the hands of intelligent and more powerful cartel coming as fraudsters.

Having reviewed all the option open to us and considering the future of e-banking in Nigeria, we recommend that the bank should adopt:
· Biometrics as second level authentication for ATM and POS.
· TOKEN as second level authentication for WEB transactions.



Our recommendation is premised on the following:

COMPETITIVE EDGE: Second level authentication will give our card the needed security to survive in Nigeria market. It will become a marketing tip for banks as our card will be more secured than that of our competitors in other African countries. The informed banking public will find good reason to drop other banks cards for ours and the patronage of our secured ATM will hit its peak.

ENHANCED SECURITY: Globally biometrics offers the best form of security for card authentication and it is a known fact that common card frauds like cloning/skimming, phishing or shoulder surfing etc will completely be eliminated. Finger Print or Vein has become adaptable for the recently manufactured ATMs like the ones in our country and offers a more robust security that will be almost be impossible to crack. Presently, Japan has achieved 80% compliance from the ATM of Banks on BIOMETRICS as second level authentication for their cards.

INCREASED BUSINESS: If we successfully implement this second level authentication, we will be the first in Africa and Nigeria cardholders will benefit immensely from it. Our idea is that with the successful implementation of the strong second level authentication, the daily limit of the cardholders using secured ATMs all over the country will be enhanced. This will increase the traffic on our ATMs and in effect increase our retail income and importantly restore the confidence of our card holders. It is also important to add that the Nigerian banks with increasing number of ATMs and a secured Platform, will take the leadership position and begin to determine the market.

REDUCTION OF OUR CARD BUSINESS RISK: Our Card Business risk will be reduced to the minimum as there is no way any customer will repudiate any transaction consummated on our secured platform and in effect our associated business risk in card transaction would have been eliminated. This will in effect improve our position with international ratings agents and more genuine customers locally and internationally will take us very serious.

FRAUD REDUCTION: Biometrics will be set on our card (the Chip has memory to the biometrics) and this will authenticate the transactions immediately accepting it or declining as the case may be. This will drastically reduce if not eliminate card related fraud while restoring the needed confidence to our card holders.
EMV/Chip Cards – What is it?
Payment systems standard for integrated chip cards and devices; developed by Europay, MasterCard and Visa to ensure interoperability.

Defines minimum functionality for debit and credit payment applications to ensure correct operation and interoperability– Some mandatory requirements and a wide range of optional features and Characteristics. Basis for chip migration by payment schemes in markets around the world.

Supported Mechanisms
· Static data authentication (SDA)
· Dynamic data authentication (DDA)
· Combined DDA and application cryptogram generation (CDA)

Basics of SDA
· Performed by terminal
· Confirms legitimacy of critical ICC-resident static data
· Detects unauthorized alteration of data after personalization
Settings and process of SDA
· Public key of CA is stored in each terminal
· Public key of issuer bank is certified by CA and stored on ICC
· Static application data are signed by issuer bank and stored on ICC
Security of SDA
· Based on secrecy of private RSA keys
· Counterfeiting/duplication not solved

DDA: Dynamic Data Authentication

Basics of DDA
· Performed by terminal & card (ICC with coprocessor required)
· Confirms legitimacy of critical ICC-resident/generated data and data received from terminal.
· Detects counterfeited/duplicated cards

Settings and process of DDA
· Similar as for SDA
· New unique ICC RSA key pair is stored on each card
· ICC private key is securely stored (cannot leave the card)
· ICC public key is signed & stored together with static application data
· Terminal sends random challenge to be signed by ICC private key
Security of DDA
· Based on secrecy of private RSA keys
· The chip card must be able to protect ICC private key
CDA: Combined DDA and Application Cryptogram (AC) Generation

Basics of CDA
Performed by terminal & card in parallel with card action analysis.
Settings and process of CDA
· Similar as for DDA
· Random challenge is a part of request for AC
· Signed AC contains this random challenge

Security of CDA
· Extra security for AC
· Advantage if secure communication between terminal and ICC cannot be guaranteed.

Automatic Risk Management
Protects against offline undetectable threats
Decides if transaction should be:
approved offline, declined offline, or transmitted online
· Terminal risk management
· Floor limit checking
· Random transaction selection
· Velocity checking

Terminal & card action analysis
· T: reject transaction offline
· C: reject offline
· T: transaction should go online
· C: go online _ reject offline
· T: transaction might be completed offline
· C: go online _ reject offline _ approve offline

EMV Offline Data Authentication
The goal is offline detection of fake (altered/duplicated) cards
Based on asymmetric cryptography (namely on RSA)
RSA public key must be always 3 or 216 − 1
Existence of a certification authority (CA) is required
Integrity of transmitted public keys must be secured
Each EMV terminal must contain actual CA public key



Basic Terminology
· Merchant, payee
· Cardholder, customer, payer, or simply user
· Card issuer, cardholder’s bank, or simply bank
· Fraud, a deception made for a personal gain
· All parties should be protected against the fraud
· Unauthorized and illegal use of a credit card to purchase property
· ICC, an acronym for integrated circuit(s) card