Jason Kuo APSCA October 29, 2010 Convergence and cross usage of secure elements for mobile PKI and secure mobile contactless services.

Slides:



Advertisements
Similar presentations
1 RFID and Telecommunication Services 25th May 2004 DATA BASE forum RFID and Your Phone Sebastian Nyström Nokia Ventures Organization.
Advertisements

European Consumer Summit 2014 On-line and mobile payments Dr Florent Frederix Trust & Security Unit, DG CONNECT, European Commission 1 th of April 2014.
M-PAYMENT SYSTEM (e–WALLET ).
Digital Identity Group May GIXEL  GIXEL is the professional association of electronic component and system industries in France. It brings together.
EDUCAUSE 2001, Indianapolis IN Securing e-Government: Implementing the Federal PKI David Temoshok Federal PKI Policy Manager GSA Office of Governmentwide.
HCE AND BLE UNIVERSITY TOMORROWS TRANSACTIONS LONDON, 20 TH MARCH 2014.
The GSMA July 2014 Restricted - Confidential Information
NFC Devices: Security and Privacy
1 GP Confidential © GlobalPlatform’s Value Proposition for Mobile Point of Sale (mPOS)
Certification Authority. Overview  Identifying CA Hierarchy Design Requirements  Common CA Hierarchy Designs  Documenting Legal Requirements  Analyzing.
UbIdentity Ubiquitous Identity Management in the Cloud 20/03/2014 Dan BUTNARU Product Line Manager Trusted Identity.
HID Global Corporate Overview Natacha Jaramillo Regional Sales Manager (Latin America) September 2014 Presentation Title Slide.
1 Pertemuan 12 Authentication, Encryption, Digital Payments, and Digital Money Matakuliah: M0284/Teknologi & Infrastruktur E-Business Tahun: 2005 Versi:
Payments – Reloaded! Spending Priorities & Innovation in Payments.
1 TELECOM ITALIA GROUP Trial at the University of Rome: SIM-based Services Trial at the University of Rome: SIM-based Services Author: Alessandro Rabbini.
Secure Element Access from a Web browser W3C Workshop on Authentication, Hardware Tokens and Beyond 11 September Oberthur Technologies – Identity.
Smart Card Development in Hong Kong SIMmate 2000 Product Launch 28 November 2000 Dr LM Cheng Director Smart Card Design Center Dept. of Electronic Engineering.
E-commerce E-commerce, or electronic commerce, refers to systems that support electronically executed business transactions. In this section: E-commerce.
An Open Mobile Identity: An Architecture for Mobile Identity Management Konstantin Hyppönen University of Kuopio Finland.
Smart card – A BT perspective Libraries ATM access Catering & Vending Transit University campuses Passports/ID cards Electronics benefits transfer Access.
UniCredit Group at glance
EPS (Electronic payment system) is an online business process used for fund transfer using electronic means, i.e  Personal computers  services  Mobile.
Mobile Identity and Mobile Authentication (mobile e-signature) Valdis Janovs Sales Director Lattelecom Technology SIA.
1 Smart Card – EMV – Security – Internet 10 June 2002 Presentation by Mr. Alan Siu Deputy Secretary for Information Technology and Broadcasting Government.
Vilnius, October 21st, 2002 © eEurope SmartCards Securing a Telework Infrastructure: Smart.IS - Objectives and Deliverables Dr. Lutz Martiny Co-Chairman,
LEVERAGING UICC WITH OPEN MOBILE API FOR SECURE APPLICATIONS AND SERVICES Ran Zhou 1 9/3/2015.
Hsu-Chen Cheng, *Wen-Wei Liao, Tian-Yow Chi, Siao-Yun Wei
PRESENTATION OF ETSI © ETSI All rights reserved Sophia Antipolis, 22 May 2014 Luis Jorge Romero Director General, ETSI.
Mobile Payment in China —— Concepts, Current Situation and the Future Fang Senior Strategy Analyst Shanghai Pudong Development Bank
Preparatory Committee for foundation of “Japan Promotional Association for Asia PKI forum” Page 1 Asia PKI forum and Establishment of Japan Promotional.
LU Chenglong ( ) DIAO Wenrui ( )
1 An Introduction to Electronic Commerce Electronic commerce: conducting business activities (e.g., distribution, buying, selling, marketing, and servicing.
Property of the Smart Card Alliance © 2011 The Future of NFC Mobile Payments Randy Vanderhoof Executive Director Transit Payments Markets Migration to.
PKI interoperability and policy in the wireless world.
Registration Processing for the Wireless Internet Ian Gordon Director, Market Development Entrust Technologies.
E-commerce Vocabulary Terms. E-commerce Buying and selling of goods, services, or information via World Wide Web, , or other pathways on the Internet.
Payment Gateways for e-Government services 24 May 2007
Securing Electronic Transactions University of Palestine Eng. Wisam Zaqoot April 2010 ITSS 4201 Internet Insurance and Information Hiding.
Establishing a Digital Identity Martin Roe - Director of Technology, Royal Mail ViaCode.
E-Commerce Security Professor: Morteza Anvari Student: Xiaoli Li Student ID: March 10, 2001.
E-banking in Hong Kong Financial institution in Hong Kong Group 6.
Andersen Labs for Internet & Security PKI Developments in Asia Pacific 5 December 2000.
THE MOBILE CHANNEL IN FINANCIAL SERVICES TARIK HUSAIN BUSINESS DEVELOPMENT DIRECTOR ASIAN BANKER SUMMIT APRIL 2011.
MobileMonday Shanghai 34 Now playing 5 Coming attractions 15 In The Pipeline Mobile Payment and Transactions March 12th, 2007 David Huang, Solutions Manager,
Near Field Communication Systems Patras, July 2006.
1 7 th CACR Information Workshop Vulnerabilities of Multi- Application Systems April 25, 2001 MAXIMUS.
, Josef NollNISnet NISnet meeting Mobile Applied Trusted Computing Josef Noll,
Internet Security. 2 PGP is a security technology which allows us to send that is authenticated and/or encrypted. Authentication confirms the identity.
Cellular Device – Versatile personal identification Joint workshop on mobile web privacy W3C presentation, Dec
SWEB SWEB Security and Privacy Technologies – Implementation Aspects Venue:SWEB Day in APV, Novi Sad Author(s):Dr. Milan Marković Organisations:MISANU.
Chapter 4 E-commerce Security and Payment.
U-commerce: Fueling economic growth with electronic payments Mark Burbidge, SVP and GM, e-Visa Joint UNCTAD - UN ESCAP Asia Pacific Regional Conference.
Innovation in Business Tom Henriksson Director, Nokia Emerging Business Unit October 3, 2006.
Internet of Things. IoT Novel paradigm – Rapidly gaining ground in the wireless scenario Basic idea – Pervasive presence around us a variety of things.
E-Commerce & M-Commerce. Introduction Electronic commerce, commonly known as e- commerce, It is a type of industry where buying and selling of product.
VPN. CONFIDENTIAL Agenda Introduction Types of VPN What are VPN Tokens Types of VPN Tokens RSA How tokens Work How does a user login to VPN using VPN.
1 1 Patented QR code solutions James Wu We Simplify Security.
Electronic Banking & Security Electronic Banking & Security.
The Future Digital Identity Landscape in Europe Timothée Mangenot, chairman 14th of December, 2015 ACSIEL partners day.
E-commerce, or electronic commerce, refers to systems that support electronically executed business transactions. E-commerce In this section: E-commerce.
© 2016 Global Market Insights, Inc. USA. All Rights Reserved Fuel Cell Market size worth $25.5bn by 2024 NFC POS Terminal Market Pit.
DIGITAL SIGNATURE SERVICE
Merging Security and Convenience with Seos® Credential Technology
OUTLINE Generalization - Types of Smart Card Technology
Near Field Communication (NFC) Market
BY GAWARE S.R. DEPT.OF COMP.SCI
Chapter 4 E-commerce Security and Payment.
Secure Element API An introduction.
Global Market Insights, Inc.
35 years of business with Security and Cloud solutions
Presentation transcript:

Jason Kuo APSCA October 29, 2010 Convergence and cross usage of secure elements for mobile PKI and secure mobile contactless services

Agenda  Introduction of APSCA  PKI service from Internet to Mobile  Security concern  NFC as a secured device  Mobile PKI service application cases  Summary 2

3 APSCA The Asia Pacific Smart Card Association (APSCA) is a non-profit, independent association for organizations in the smart card industry in the Asia Pacific region. APSCA is the only professional association for smart cards covering the Asia Pacific and has over 60 members in Hong Kong, China, Taiwan, Japan, Korea, Singapore, Malaysia and Thailand.

Bank BBank A User Remittance channel FXML message channel FISC TW WebATM Balance Inquiry Fund Transfer WebPKI 4 Internet Banking using PKI with Smart card Bank C BankB,BankC

Banking service from Internet to Mobile Phone 5

Smart phone is more popular 6

7 Security concern – Internet & Mobile service No idea who you are and is out there! Not sure if private information is compromised No confirmation of information source No assurance of legal protection Too many stories on hackers & cheats! How mobile device have equivalent in security level to the PC ?

New component for mobile Phone with RFID and Security component in NFC Phone 8 SIM -Application logic (java) -User credentials -Open Platform enabled NFC chipset Inside contactless - RF layer - Multi-protocol (type A, B, felica, 15693) RF antenna SWP Single Wire Protocol -1.5 Mbit/s -Battery off mode -Open solution (free IP) -Under standardization (ETSI) -Compatible USB Recommended by (OTA)

The trend and schedule for NFC Phone million units mobile phonesphones w memory slotNFC phones Sources: ABI Research, Juniper Research, G&D NB2 SIM SD card

NFC Core Applications 10

Full NFC is Close  Core specifications are completed  NFC Forum certification program will be launched 4Q 2010  Will enable device manufacturers of all kinds to test against specifications Help stabilize the market Get globally interoperable devices to market 11

4 security element options 12 Embedded SE SIM-based SE Removable SE Trusted Base SE = Secure Element

13 Secure Elements to enable secure applications

EXTERNAL TSM 14 Service applet provisioning with/without Mobile Operators

Security control for Multiple services in one SEs

16 Service application cases Provides best-of-breed for: Electronic identification (mobile eID) Secure mobile payments (mPayment) Mobile commerce (mCommerce) Mobile Banking (mBanking) Mobile Money Transfer (MMT) Document signing Any security ”aware” application

Service Application Providing Internet Office to Mobile Office 17

18 e-banking user e-banking solution mobile phone number 123 authentication request signed confirmation login request Sample use cases: e-banking, electronic stock exchange, electronic insurance services, self-care portals, access to payable content (authentication),... Sample use cases: e-banking, electronic stock exchange, electronic insurance services, self-care portals, access to payable content (authentication),... Service Application Transaction authentication

19 e-government / ERP Home Worker stock sell order authentication 123 sell order signature request signed order Service Application Remote signing for work flow Sample use cases: electronic payment instruction confirmation, purchase or sell orders, self-care portals (contracts, annexes), e-government, e-voting,... Sample use cases: electronic payment instruction confirmation, purchase or sell orders, self-care portals (contracts, annexes), e-government, e-voting,...

Summary  It’s important to identify yourself with ID card in physical and e-ID in virtual environment.  Smart Phone is pushing internet service to Mobile service  Personal and security information shall be store in a secured device  Visa/MasterCard had done many NFC trials for credit card payment  It’s good for PKI as bank card service from web internet to mobile service. 20