SlideShare a Scribd company logo
1 of 21
Download to read offline
Mobile Payments
SDP Global Summit
Rome
12. 9. 2012
Martin Prosek, VAS Platform Development Manager
Telefónica Czech Republic
Telefó
About Telefónica Czech Republic
Fixed and mobile voice and data, IPTV
Operated under commercial brand O2

1
Telefó
Telefónica Globally

2
BlueVia – Global APIs

https://bluevia.com/
Introduction

01 Mobile Payments Quick Review
02 Telefónica Czech Republic Experience
03 Opportunities
04 Technical Solutions
05 Risks and their Mitigations
06 Summary/Recommendations
Disclaimer: The opinions of the author expressed in this document do not
necessarily state or reflect those of Telefónica company
4
Mobile Payments
Most popular service

•
•
•

Users use it – it is convenient method how to perform purchases
Developers need it – provides monetization
Operators like it – gives place in the value chain and another revenue
stream
Mobile
Network
Mobile Network
Operator
Operator

Consumer

Let us do some quick review…

Content Provider
Payments?
What are the Mobile Payments?
Many definitions exist…

•

It generally refers to payment services performed from or via a mobile
device.

Focus on Mobile Network Operator service

•
•
•
•

Not mobile banking
Not payments using credit/debit card
Not payment through online payment provider
Not NFC

Direct to bill (D2B)
Experience in Telefonica CZ
Today is 10th anniversay of service
mJuice m-Platby

•

USSD based, used or cinema tickets purchase

Premium SMS – 7 years old service

Mobile web payments
m-platba – 3 years old
All these payment solutions are pre-SDP
Mobile Payment Methods
Premium SMS – oldest one
Mobile web – already established
In-app payments – great for freemium
InSmartphones penetration still grows…

One-off payments
Subscriptions/direct debit
Google Android
Apple iOS

200802 200806 200810 200902 200906 200910 201002 201006 201010 201102 201106
Limitations
Transaction fees are and will be still high
Limited use for intangible goods, mostly consummable on the
mobile device
Opportunity
The situation is very positive

•
•
•
•

The smartphones penetration is high
Users already have learned to pay for apps
Operators are perceived as trusted parties and have
good track of history in mobile content
User experience is better than for using payment
cards

Mobile Payments can substitute the declining
content revenues
Mobile Payments can help operators to return
to the value chain and stop being dumb pipe
Technical Solutions
SDPs – standard means to expose
Payment API

API standards

Operator
Operator
Business Risks
Repudiation

•
•

When operator cannot prove user‘s consent user later can reject the
payment
Closely connected to subscribe identification

Provider charging without providing service

•
•

By mistake or technical failure
Biggest problem can be fraudulent use

Unclear relation to the provider

•

Not possible to get clear responsibility
Technical Risks
Communication is not direct anymore
Operator
Operator

Man-in-the-middle (M-I-M) attacks are possible
Provider
Provider

Operator
Operator

Even the app itself can compromise the payment security –
App-in-theApp-in-the-middle (A-I-M)*
App
App
* Known examples: fraudulent Premium SMS sending…

Provider
Provider

Operator
Operator
Mitigations
Possible Risk Mitigations
Payment transactions and/or spend limits (per day, month…)
Different security levels for different amount of payments

•

E.g. for purchases under 2 € lower security

Security influenced design of payment authorization

•
•
•

User giving consent as directly as possible (no M-I-M)
Verification of human interaction (login by username/password, PIN,
captcha, mouse movements/gestures…)
Alternative communication channels (SMS, USSD…), use of one-time
password
Mitigations
Possible Risk Mitigations
Payment notifications (by SMS and/or e-mails)

•

User gets info about payment transaction everytime

Offering opt-in model

•

Use must confirm intention to have payments enabled

Best solution would be use of SIM-based transaction signing
Good Balance of Security and Convenience
One click payments
No authorization
Opt-out

Convenience

Security

Authorized payments
Opt-in
SIM-Toolkit based
security
Recommendations
Let the user be in control of the service security settings – provide good web
selfcare
Give the user access to full history of the payments – on the web selfcare
MADo your best to have direct access to user (no M-I-M or A-I-M)
Have clear contracts with providers stating responsibility for all cases
all

17
Empire…
Last Days of the Roman Empire…
Mobile Network Operators had created
„empires“
Huge revenues were funding their
development
But now the „empires“ are under attacks of
„barbarians“ from outside (the Internet…)
If operators are not acting now
the position in the value chain might be lost
– the „fall of empire“
Questions?
Thank you.

More Related Content

What's hot

Mobile Monday (May 2014) - CB Bank - Mobile Banking
Mobile Monday (May 2014) - CB Bank - Mobile BankingMobile Monday (May 2014) - CB Bank - Mobile Banking
Mobile Monday (May 2014) - CB Bank - Mobile BankingMobile Monday Yangon
 
Digital financial services: essentials
Digital financial services: essentialsDigital financial services: essentials
Digital financial services: essentialsSonia Arenaza
 
Mobile banking
Mobile bankingMobile banking
Mobile bankingSrideviHV
 
Online banking
Online bankingOnline banking
Online bankingPreet Raj
 
E-Banking 2009
E-Banking 2009E-Banking 2009
E-Banking 2009keerthi123
 
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Mahindra Comviva
 
Diebold - Mobile Monday Maroc: M-Banking & M-Payment
Diebold - Mobile Monday Maroc: M-Banking & M-Payment Diebold - Mobile Monday Maroc: M-Banking & M-Payment
Diebold - Mobile Monday Maroc: M-Banking & M-Payment mmmaroc
 
SBM - Communication Strategy
SBM - Communication Strategy SBM - Communication Strategy
SBM - Communication Strategy Jason Bholanauth
 
Mycelium payment system
Mycelium payment systemMycelium payment system
Mycelium payment systemmyceliumcard
 
Internet banking
Internet bankingInternet banking
Internet bankingmsarifff
 

What's hot (20)

E banking
E bankingE banking
E banking
 
Mobile Monday (May 2014) - CB Bank - Mobile Banking
Mobile Monday (May 2014) - CB Bank - Mobile BankingMobile Monday (May 2014) - CB Bank - Mobile Banking
Mobile Monday (May 2014) - CB Bank - Mobile Banking
 
Digital financial services: essentials
Digital financial services: essentialsDigital financial services: essentials
Digital financial services: essentials
 
Mobile banking
Mobile bankingMobile banking
Mobile banking
 
Online banking
Online bankingOnline banking
Online banking
 
Semi-Integrated Solution
Semi-Integrated SolutionSemi-Integrated Solution
Semi-Integrated Solution
 
Telebanking and EDI system
Telebanking and EDI systemTelebanking and EDI system
Telebanking and EDI system
 
Online banking
Online bankingOnline banking
Online banking
 
E-Banking 2009
E-Banking 2009E-Banking 2009
E-Banking 2009
 
Ultimate company
Ultimate companyUltimate company
Ultimate company
 
E banking
E bankingE banking
E banking
 
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
Banks can Implement NFC Payment Choosing between two Options - HCE platform &...
 
Diebold - Mobile Monday Maroc: M-Banking & M-Payment
Diebold - Mobile Monday Maroc: M-Banking & M-Payment Diebold - Mobile Monday Maroc: M-Banking & M-Payment
Diebold - Mobile Monday Maroc: M-Banking & M-Payment
 
online banking
online bankingonline banking
online banking
 
E banking
E bankingE banking
E banking
 
E banking
E bankingE banking
E banking
 
SBM - Communication Strategy
SBM - Communication Strategy SBM - Communication Strategy
SBM - Communication Strategy
 
Mycelium payment system
Mycelium payment systemMycelium payment system
Mycelium payment system
 
Internet banking
Internet bankingInternet banking
Internet banking
 
Internet banking
Internet bankingInternet banking
Internet banking
 

Similar to SDP Global Summit 2012

World of mobile payments by Muthu
World of mobile payments by MuthuWorld of mobile payments by Muthu
World of mobile payments by MuthuMuthu Siva
 
Mobile Payments - How is it done?
Mobile Payments - How is it done?Mobile Payments - How is it done?
Mobile Payments - How is it done?Parag Arjunwadkar
 
Presentation of future of mobile commerce
Presentation of future of mobile commercePresentation of future of mobile commerce
Presentation of future of mobile commerceMOUMITA KARMAKAR
 
Mobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsMobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsStomar
 
Mobile payment.and.myanmar.jul2014
Mobile payment.and.myanmar.jul2014Mobile payment.and.myanmar.jul2014
Mobile payment.and.myanmar.jul2014Zaw Aung
 
H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147Himanshu Phatnani
 
H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147Himanshu Phatnani
 
Mobile Financial Services
Mobile Financial ServicesMobile Financial Services
Mobile Financial Servicesmgopik
 
Creating New Payforit Business Models
Creating New Payforit Business ModelsCreating New Payforit Business Models
Creating New Payforit Business ModelsOxygen8 Group
 
What Customers Want
What Customers WantWhat Customers Want
What Customers WantPiotr Merkel
 
Best Practices in Risk Management for Mobile Payments - MRC 2011
Best Practices in Risk Management for Mobile Payments - MRC 2011Best Practices in Risk Management for Mobile Payments - MRC 2011
Best Practices in Risk Management for Mobile Payments - MRC 2011Hill Ferguson
 
Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Starttech Ventures
 
Mobypage Financiall Series Microsoft Isu 1c
Mobypage Financiall Series Microsoft Isu 1cMobypage Financiall Series Microsoft Isu 1c
Mobypage Financiall Series Microsoft Isu 1cChanBarry
 
Paul Mcnea - paythru
Paul Mcnea - paythruPaul Mcnea - paythru
Paul Mcnea - paythruJames Cameron
 
Riding the Mobile Payments Tsunami
Riding the Mobile Payments TsunamiRiding the Mobile Payments Tsunami
Riding the Mobile Payments TsunamiMark Sherman
 
Myanmar Mobile Money Services INtroduction
Myanmar Mobile Money Services INtroductionMyanmar Mobile Money Services INtroduction
Myanmar Mobile Money Services INtroductionAung Cho
 
Technology Changing The Face Of Microfinance
Technology Changing The Face Of MicrofinanceTechnology Changing The Face Of Microfinance
Technology Changing The Face Of MicrofinanceJohn Owens
 

Similar to SDP Global Summit 2012 (20)

World of mobile payments by Muthu
World of mobile payments by MuthuWorld of mobile payments by Muthu
World of mobile payments by Muthu
 
Mobile Payments - How is it done?
Mobile Payments - How is it done?Mobile Payments - How is it done?
Mobile Payments - How is it done?
 
Presentation of future of mobile commerce
Presentation of future of mobile commercePresentation of future of mobile commerce
Presentation of future of mobile commerce
 
Mobile Payment Value chain and Business Models
Mobile Payment Value chain and Business ModelsMobile Payment Value chain and Business Models
Mobile Payment Value chain and Business Models
 
Mobile Convention Amsterdam 2014 - UL - Amos Kater
Mobile Convention Amsterdam 2014 - UL - Amos KaterMobile Convention Amsterdam 2014 - UL - Amos Kater
Mobile Convention Amsterdam 2014 - UL - Amos Kater
 
Direpay product note
Direpay product noteDirepay product note
Direpay product note
 
Mobile payment.and.myanmar.jul2014
Mobile payment.and.myanmar.jul2014Mobile payment.and.myanmar.jul2014
Mobile payment.and.myanmar.jul2014
 
H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147
 
H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147H imanshu final mcs ppt 20147
H imanshu final mcs ppt 20147
 
Mobile Financial Services
Mobile Financial ServicesMobile Financial Services
Mobile Financial Services
 
Creating New Payforit Business Models
Creating New Payforit Business ModelsCreating New Payforit Business Models
Creating New Payforit Business Models
 
What Customers Want
What Customers WantWhat Customers Want
What Customers Want
 
Best Practices in Risk Management for Mobile Payments - MRC 2011
Best Practices in Risk Management for Mobile Payments - MRC 2011Best Practices in Risk Management for Mobile Payments - MRC 2011
Best Practices in Risk Management for Mobile Payments - MRC 2011
 
Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021Ronald Raffensperger, Digital Banking Forum 2021
Ronald Raffensperger, Digital Banking Forum 2021
 
Mobypage Financiall Series Microsoft Isu 1c
Mobypage Financiall Series Microsoft Isu 1cMobypage Financiall Series Microsoft Isu 1c
Mobypage Financiall Series Microsoft Isu 1c
 
Paul Mcnea - paythru
Paul Mcnea - paythruPaul Mcnea - paythru
Paul Mcnea - paythru
 
Riding the Mobile Payments Tsunami
Riding the Mobile Payments TsunamiRiding the Mobile Payments Tsunami
Riding the Mobile Payments Tsunami
 
PayTech Trends 2016
PayTech Trends 2016PayTech Trends 2016
PayTech Trends 2016
 
Myanmar Mobile Money Services INtroduction
Myanmar Mobile Money Services INtroductionMyanmar Mobile Money Services INtroduction
Myanmar Mobile Money Services INtroduction
 
Technology Changing The Face Of Microfinance
Technology Changing The Face Of MicrofinanceTechnology Changing The Face Of Microfinance
Technology Changing The Face Of Microfinance
 

More from Martin Prosek

SDP Global Summit 2010
SDP Global Summit 2010SDP Global Summit 2010
SDP Global Summit 2010Martin Prosek
 
SDP Global Summit 2009
SDP Global Summit 2009SDP Global Summit 2009
SDP Global Summit 2009Martin Prosek
 
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...Martin Prosek
 
CDN World Summit 2011
CDN World Summit 2011CDN World Summit 2011
CDN World Summit 2011Martin Prosek
 
Broadband Traffic Management 2011
Broadband Traffic Management 2011Broadband Traffic Management 2011
Broadband Traffic Management 2011Martin Prosek
 
Broadband Traffic Management 2010
Broadband Traffic Management 2010Broadband Traffic Management 2010
Broadband Traffic Management 2010Martin Prosek
 
SDP Global Summit 2013
SDP Global Summit 2013SDP Global Summit 2013
SDP Global Summit 2013Martin Prosek
 
Mobile Broadband Optimisation 2011
Mobile Broadband Optimisation 2011Mobile Broadband Optimisation 2011
Mobile Broadband Optimisation 2011Martin Prosek
 

More from Martin Prosek (9)

SDP Global Summit 2010
SDP Global Summit 2010SDP Global Summit 2010
SDP Global Summit 2010
 
SDP Global Summit 2009
SDP Global Summit 2009SDP Global Summit 2009
SDP Global Summit 2009
 
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...
Mobile Identity 2013 - Optimising and simplifying authentication and authoriz...
 
CDN World Summit 2011
CDN World Summit 2011CDN World Summit 2011
CDN World Summit 2011
 
Broadband Traffic Management 2011
Broadband Traffic Management 2011Broadband Traffic Management 2011
Broadband Traffic Management 2011
 
Broadband Traffic Management 2010
Broadband Traffic Management 2010Broadband Traffic Management 2010
Broadband Traffic Management 2010
 
3GOptimisation 2012
3GOptimisation 20123GOptimisation 2012
3GOptimisation 2012
 
SDP Global Summit 2013
SDP Global Summit 2013SDP Global Summit 2013
SDP Global Summit 2013
 
Mobile Broadband Optimisation 2011
Mobile Broadband Optimisation 2011Mobile Broadband Optimisation 2011
Mobile Broadband Optimisation 2011
 

Recently uploaded

Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machinePadma Pradeep
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...Fwdays
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Enterprise Knowledge
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024BookNet Canada
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsMark Billinghurst
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Wonjun Hwang
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024The Digital Insurer
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationRidwan Fadjar
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupFlorian Wilhelm
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 3652toLead Limited
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationSlibray Presentation
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostZilliz
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024Lorenzo Miniero
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxhariprasad279825
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piececharlottematthew16
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Mark Simos
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clashcharlottematthew16
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfAddepto
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenHervé Boutemy
 

Recently uploaded (20)

Install Stable Diffusion in windows machine
Install Stable Diffusion in windows machineInstall Stable Diffusion in windows machine
Install Stable Diffusion in windows machine
 
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks..."LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
"LLMs for Python Engineers: Advanced Data Analysis and Semantic Kernel",Oleks...
 
Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024Designing IA for AI - Information Architecture Conference 2024
Designing IA for AI - Information Architecture Conference 2024
 
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: BNC CataList - Tech Forum 2024
 
Human Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR SystemsHuman Factors of XR: Using Human Factors to Design XR Systems
Human Factors of XR: Using Human Factors to Design XR Systems
 
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptxE-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
E-Vehicle_Hacking_by_Parul Sharma_null_owasp.pptx
 
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
Bun (KitWorks Team Study 노별마루 발표 2024.4.22)
 
My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024My INSURER PTE LTD - Insurtech Innovation Award 2024
My INSURER PTE LTD - Insurtech Innovation Award 2024
 
My Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 PresentationMy Hashitalk Indonesia April 2024 Presentation
My Hashitalk Indonesia April 2024 Presentation
 
Streamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project SetupStreamlining Python Development: A Guide to a Modern Project Setup
Streamlining Python Development: A Guide to a Modern Project Setup
 
Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365Ensuring Technical Readiness For Copilot in Microsoft 365
Ensuring Technical Readiness For Copilot in Microsoft 365
 
Connect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck PresentationConnect Wave/ connectwave Pitch Deck Presentation
Connect Wave/ connectwave Pitch Deck Presentation
 
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage CostLeverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
Leverage Zilliz Serverless - Up to 50X Saving for Your Vector Storage Cost
 
SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024SIP trunking in Janus @ Kamailio World 2024
SIP trunking in Janus @ Kamailio World 2024
 
Artificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptxArtificial intelligence in cctv survelliance.pptx
Artificial intelligence in cctv survelliance.pptx
 
Story boards and shot lists for my a level piece
Story boards and shot lists for my a level pieceStory boards and shot lists for my a level piece
Story boards and shot lists for my a level piece
 
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
Tampa BSides - Chef's Tour of Microsoft Security Adoption Framework (SAF)
 
Powerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time ClashPowerpoint exploring the locations used in television show Time Clash
Powerpoint exploring the locations used in television show Time Clash
 
Gen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdfGen AI in Business - Global Trends Report 2024.pdf
Gen AI in Business - Global Trends Report 2024.pdf
 
DevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache MavenDevoxxFR 2024 Reproducible Builds with Apache Maven
DevoxxFR 2024 Reproducible Builds with Apache Maven
 

SDP Global Summit 2012

  • 1. Mobile Payments SDP Global Summit Rome 12. 9. 2012 Martin Prosek, VAS Platform Development Manager Telefónica Czech Republic
  • 2. Telefó About Telefónica Czech Republic Fixed and mobile voice and data, IPTV Operated under commercial brand O2 1
  • 4. BlueVia – Global APIs https://bluevia.com/
  • 5. Introduction 01 Mobile Payments Quick Review 02 Telefónica Czech Republic Experience 03 Opportunities 04 Technical Solutions 05 Risks and their Mitigations 06 Summary/Recommendations Disclaimer: The opinions of the author expressed in this document do not necessarily state or reflect those of Telefónica company 4
  • 6. Mobile Payments Most popular service • • • Users use it – it is convenient method how to perform purchases Developers need it – provides monetization Operators like it – gives place in the value chain and another revenue stream Mobile Network Mobile Network Operator Operator Consumer Let us do some quick review… Content Provider
  • 7. Payments? What are the Mobile Payments? Many definitions exist… • It generally refers to payment services performed from or via a mobile device. Focus on Mobile Network Operator service • • • • Not mobile banking Not payments using credit/debit card Not payment through online payment provider Not NFC Direct to bill (D2B)
  • 8. Experience in Telefonica CZ Today is 10th anniversay of service mJuice m-Platby • USSD based, used or cinema tickets purchase Premium SMS – 7 years old service Mobile web payments m-platba – 3 years old All these payment solutions are pre-SDP
  • 9. Mobile Payment Methods Premium SMS – oldest one Mobile web – already established In-app payments – great for freemium InSmartphones penetration still grows… One-off payments Subscriptions/direct debit Google Android Apple iOS 200802 200806 200810 200902 200906 200910 201002 201006 201010 201102 201106
  • 10. Limitations Transaction fees are and will be still high Limited use for intangible goods, mostly consummable on the mobile device
  • 11. Opportunity The situation is very positive • • • • The smartphones penetration is high Users already have learned to pay for apps Operators are perceived as trusted parties and have good track of history in mobile content User experience is better than for using payment cards Mobile Payments can substitute the declining content revenues Mobile Payments can help operators to return to the value chain and stop being dumb pipe
  • 12. Technical Solutions SDPs – standard means to expose Payment API API standards Operator Operator
  • 13. Business Risks Repudiation • • When operator cannot prove user‘s consent user later can reject the payment Closely connected to subscribe identification Provider charging without providing service • • By mistake or technical failure Biggest problem can be fraudulent use Unclear relation to the provider • Not possible to get clear responsibility
  • 14. Technical Risks Communication is not direct anymore Operator Operator Man-in-the-middle (M-I-M) attacks are possible Provider Provider Operator Operator Even the app itself can compromise the payment security – App-in-theApp-in-the-middle (A-I-M)* App App * Known examples: fraudulent Premium SMS sending… Provider Provider Operator Operator
  • 15. Mitigations Possible Risk Mitigations Payment transactions and/or spend limits (per day, month…) Different security levels for different amount of payments • E.g. for purchases under 2 € lower security Security influenced design of payment authorization • • • User giving consent as directly as possible (no M-I-M) Verification of human interaction (login by username/password, PIN, captcha, mouse movements/gestures…) Alternative communication channels (SMS, USSD…), use of one-time password
  • 16. Mitigations Possible Risk Mitigations Payment notifications (by SMS and/or e-mails) • User gets info about payment transaction everytime Offering opt-in model • Use must confirm intention to have payments enabled Best solution would be use of SIM-based transaction signing
  • 17. Good Balance of Security and Convenience One click payments No authorization Opt-out Convenience Security Authorized payments Opt-in SIM-Toolkit based security
  • 18. Recommendations Let the user be in control of the service security settings – provide good web selfcare Give the user access to full history of the payments – on the web selfcare MADo your best to have direct access to user (no M-I-M or A-I-M) Have clear contracts with providers stating responsibility for all cases all 17
  • 19. Empire… Last Days of the Roman Empire… Mobile Network Operators had created „empires“ Huge revenues were funding their development But now the „empires“ are under attacks of „barbarians“ from outside (the Internet…) If operators are not acting now the position in the value chain might be lost – the „fall of empire“