EMV: The Future is Now. Moderator: Jason Putnam Vice President of Sales, First American Payment Systems Panelists: Patty Walters Senior Vice President.

Slides:



Advertisements
Similar presentations
Session 4: Data Privacy and Fraud Moderator: Bill Houck, Director, Risk Management, UATP Panelist: Peter Warner, EVP, Retail Decisions Cherie Lauretta,
Advertisements

WHAT IS EMV? A joint effort between Europay, MasterCard and Visa It is a security framework that defines the payment interaction at the physical, electrical,
Gareth Ellis Senior Solutions Consultant Session 5a Key and PIN Management.
Mobile Payment Security The Good, the Bad and the Ugly
HCE AND BLE UNIVERSITY TOMORROWS TRANSACTIONS LONDON, 20 TH MARCH 2014.
ETA UNIVERSITY MARCH 19, 2015 Deana Rich R ICH C ONSULTING, I NC. Edward A. Marshall A RNALL G OLDEN G REGORY LLP Payments 101: Overview of the Payments.
CONFIDENTIAL AND PROPRIETARY ©2014 DISCOVER FINANCIAL SERVICES 2014 Discover ® Dealer Incentive Program & EMV Update.
Leanne Phelps Senior Vice President, Card Services
Protecting Your Customers’ Card Data ASTRA Presentation Brian Chapman and Peter O’Rourke.
1 U.S. EMV Migration Update and Best Practices Hap Huynh, Senior Director Risk Products April 2015.
Vice President, e-Business Development Dubai United Nations Conference on Trade & Development Conference on Electronic Commerce.
Northwest Card Association Acquirer Update January 2012.
Contactless Payment. © Family Economics & Financial Education – January 2007 –– Financial Institution Unit – Contactless Payment - 2 Funded by a grant.
© 2012 Presented by: Preparation For EMV Chip Technology Keith Swiat.
EMV – What you need to know… Jay J. Davis Territory Alliance Manager
Memorial University of Newfoundland An Update on Chip September 26, 2007.
LECTURE 7 REF: CHAPTER 11 ELECTRONIC COMMERCE PAYMENT SYSTEMS PREPARED BY : L. Nouf Almujally Copyright © 2010 Pearson Education, Inc. 1.
International Card Systems Skopje, Macedonia
/RestaurantDotOrg /NationalRestaurantAssociation.
Mar 11, 2003Mårten Trolin1 Previous lecture Diffie-Hellman key agreement Authentication Certificates Certificate Authorities.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
EMV’s Impact on U.S. Retailers – It’s Coming! Presented by: Chris Francis VP, Market Development February 21, 2014.
An Introduction to EMV Presented to:
Emerging Technologies
University of South Florida Credit Card Presentation Credit Card Reconciliation Process.
PCI PIN Entry Device Security Requirements PCI PIN Security Standards
Philip is a subject matter expert in Accenture’s Payment practice with more than 30 years experience across payments, transaction processing, networks,
Payments technology and security
Academy of Risk Management | Innovate. Collaborate. Educate. Fraud Management Solutions Innovative Products & Thought Leadership.
Card Brand Mandates. Key EMV dates from Card Brands © 2012 VeriFone Systems, Inc.  2012: TECH Innovation Program (TIP) - PCI validation relief for Level.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
R U Ready? V M E EUROPAY MASTERCARD VISA EMVco was formed in 1999.
EMV – The New Landscape 21 Days & 12 Hours
Confidential – For Discussion & General Information Purposes Only EMV to Card Not Present Fraud Gavin Levin, CTP eReceivables Consultant.
Introduction To Plastic Card Industry (PCI) Data Security Standards (DSS) April 28,2012 Cathy Pettis, SVP ICUL Service Corporation.
Agenda EMV – What Is It? EMV In The UK EMV Is Coming To The US
The next generation of payments is here. Is your business ready?
Getnationwide.com Let’s Talk about EMV Danielle Rourke.
Security and Fraud Solutions Initiatives: Turning the Threat into an Opportunity.
1.Understand the shifts that are occurring with regard to online payments. 2.Discuss the players and processes involved in using credit cards online.
What you need to know about PCI-DSS Jane Drews Chief Information Security Officer Information Security & Policy Office
University of South Florida Credit Card Presentation Credit Card Reconciliation Process.
EMV: transforming the payment experience
VeriShield Protect Revolutionary technology that simplifies PCI DSS compliance with no system upgrades Now available on V x Solutions!
EMV: What is it and how will it impact your business.
Fall  Comply with PCI compliance policies set forth by industry  Create internal policies and procedures to protect cardholder data  Inform and.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
Summary of Changes. General These are changes that have come up in many EMV migrations that I have assessed and been involved in. The changes are broken.
Confidential and Proprietary - NOT TO BE DISTRIBUTED WITHOUT THE EXPRESS WRITTEN PERMISSION OF BANK OF AMERICA MERCHANT SERVICES. ASTRA EMV Review/Best.
Online Decision Process
EMV Operation and Attacks Tyler Moore CS7403, University of Tulsa Reading: Anderson Security Engineering, Ch (136—138), (328—343) Papers.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
Risk Policy Considerations.  Floor Limits  Fallback considerations  Domestic v International  Credit control (VSDC+) overview  Fraud reporting 
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
EMV.
Making card acceptance work for you
Transaction Flow end-end
A catalyst for mobile contactless payments adoption?
EMV Acceptance Training
Make This Document Your Own
Payment card industry data security standards
CONFERENCE OF WESTERN ATTORNEYS GENERAL
EMV & Parking – 6 Months On
Problems – Technical Requirements
Making card acceptance work for you
Cyber Security and Consumer Financial Transactions Data Security
Chip & Pin and Apple Pay: Vulnerabilities of the Changing Payment Systems Jay Isaacson.
New Jersey Gasoline C-Store Automotive Association
Presentation transcript:

EMV: The Future is Now

Moderator: Jason Putnam Vice President of Sales, First American Payment Systems Panelists: Patty Walters Senior Vice President of Merchant Products and Security, Vantiv Greg Boardman Senior Vice President of Product and Development, Ingenico John Badovinac Senior Manger US Acquirer Relations, Discover Financial Services 2

Session Objectives EMV -  What is it?  Why does it matter?  How does it impact me?  What opportunities does it create?  What should I be doing right now?  Who can help? EMV: The Future is Now 3

EMV – What is it?  Global standard for chip card technology  Developed by Europay, MasterCard and Visa in 1993  Typically a chip inset within a plastic card  Chip stores cardholder and application data more securely  EMV provides protection against card reproduction fraud  EMV can be contact or contactless 4

 Cards include microprocessor chip that stores info securely and performs cryptographic processing during transaction a payment transaction  Even if fraudsters are able to steal account data from chip transactions, this data cannot be used to create a fraudulent transaction in an EMV or magnetic stripe environment, since every EMV transaction carries dynamic data  Can address card-not-present fraud if cardholders use their EMV cards and individual readers to authenticate Internet transactions  What are the Specifics? Card authentication protects against counterfeit fraud Cardholder verification protects against lost and stolen fraud Issuer and Acquirer defines rules used to authorize transactions EMV – Why does it matter? EMV Reduces Fraud 5

Offline Card Authentication Static Data Authentication (SDA) Dynamic Data Authentication (DDA) Combined Data Authentication (CDA) Online Card Authentication Cryptogram Validation (ARQC) Supported CVM’s Online PINOffline PINSignature No cardholder verification method (CVM) Authorization Rules OnlineOffline BOTH CARD & TERMINAL capabilities impact authorization, authentication & CVM’s used for any given transaction Offline data authentication may still happen even though a transaction is ultimately sent online for approval EMV – Why does it matter? EMV Reduces Fraud 6

In 2011, there was no spike in fraud due to holiday season 2008 – 2010, Canada noticed increased peaks of fraud due to holiday season As EMV penetration at POS increased, counterfeit as well as other types of fraud decreased 7

EMV Global Penetration 31.2% of cards 76.5% of terminals 73.9% of cards 89.0% of terminals 17.6% of cards 60.7% of terminals 27.0% of cards 43.0% of terminals 12.7% of cards 65.4% of terminals * Figures reported as of Q1, 2011 and represent the latest statistics from American Express, JCB, MasterCard, and Visa, as reported by their member financial institutions globally. Figures do not include data from the United States Canada, Latin America, and the Carribean Asia Pacific Africa and the Middle East Europe Zone 1 Europe Zone 2 United States EMV – Why does it matter? EMV Provides Global Interoperability 8

To implement EMV we need to:  Build EMV Processing infrastructure  Establish merchant acceptance for EMV  Encourage issuance of EMV cards Payment networks have facilitated this by issuing compliance guidelines in their annual release: Setting standards/timelines for processing capability Promoting acceptance Promoting issuance Liability Shift EMV – How does it impact me? 9

DatesVISAMasterCardDiscoverAmerican Express Oct 2012 Technology Innovation Program (TIP) Annual PCI DSS audit relief 75% Visa transactions must originate from EMV-chip terminals Terminals must support both contact and contactless including NFC April 2013 Acquirers and sub- processors must support EMV (Mandate) Acquirers / sub-processors must support EMV Maestro ATM liability shift 1 Acquirers, sub-processors, direct connect merchants support EMV elements Acquirers and sub-processors must support EMV, including mobile (Mandate) Oct 2013 Merchant Account Data Compromise(ADC) relief (Phase I) TBA PCI DSS relief 75% of transactions occur on Amex EMV chip-based contact and contactless devices Oct 2015 US Liability Shift 1 US Liability Shift 2 Merchant ADC Relief (Phase II) TBA US Liability Shift Oct 2016 US liability shift for ATM transactions TBA Oct 2017 Automated Fuel Dispenser (AFD) Liability Shift 1 AFD Liability Shift 2 TBA AFD Liability Shift EMV – How does it impact me? 1 Liability for counterfeit transaction shifts to terminal owners if they don’t accept EMV 2 Liability for counterfeit transaction shifts to party who has least-secure support 10

 An EMV card is inserted into a terminal  The chip embedded in the card contains encrypted data, this is accessed by the reader in the terminal  Using data from the card, the terminal creates and sends a unique code, or “cryptogram” to the processor’s host during the transaction, validating the card  The card is removed when the transaction is completed EMV – How does it impact me? EMV How it Works 11

The Authentication Process EMV – How does it impact me? EMV How it Works 12

 An EMV chip can be on a “contactless” card where the chip is “tapped” or “held” near the terminal …..or…..  A chip can be inside your smart phone and the phone is “waived” near the terminal…  Mobile wallets (eWallets) are rapidly growing in number, which multiplies the opportunity for incremental sales for merchants and new revenue options for ISOs Remember that the incentives from the card brand associations are predicated on accepting both contact and contactless EMV as well as NFC EMV – How does it impact me? EMV How it Works 13

EMV – How does it impact me? EMV Implementation Impacts  Modify the Terminal- to-Acquirer interface to support EMV  Add EMV data elements to authorization and clearing messages  Review disputes processes to support EMV  Provide user guides and technical specifications  Update policies, procedures, and operating regulations to incorporate EMV  Facilitate the testing and certification of network partners to ensure they can properly support EMV  Support EMV data elements in authorization messages  Define how chip cards will work  Enhance risk management systems  Determine the card migration strategy  Update customer support and operational systems  Obtain and store required security data  Enhance data preparation and card personalization  Achieve certification TerminalsAcquirerNetworkIssuer Card Production  Install EMV security data in terminal and upgrade to process EMV transactions 14

 An EMV chip can make decisions and do calculations  An EMV chip can operate ‘offline’ and speed transactions for transit, sporting events, concerts, etc.  An EMV chip can provide access control credentials for identification and campus access  EMV is enabling new payment technologies that will accelerate the development of mobile payment solutions EMV - What new opportunities does it create? 15

16 EMV - What should I be doing right now? 16

 Designate an in-house EMV expert / program owner (critical for large merchants / ISO / Processor)  Ensure POS providers / VARS aligned with EMV (including plan and roadmap)  Ensure POS that I own or will soon own supports all payment types Remember: Contact, Contactless / NFC, and magstripe My NFC support includes mobile wallet (of my choosing) The device bears all the necessary approvals (Lvl1, Lvl2, C’less approvals, PCI PTS) Remember that V1 expires in 2014! Ensure the ability to remotely manage (some peripherals may not accommodate this)…  Ensure EMV migration dates coincide with the Payment Network’s key dates for compliance  Ensure POS provider can assist in the migration process  Ensure processor / acquirer is available for the migration and planning I have received my end to end certification process from them (if applicable) I have all the test tools I need (cards, etc.)  Develop a training program for my personnel To understand the new payment types To understand the changes in consumer behavior at the POS To dispel myths EMV - What should I be doing right now? 17

Small  Typically tier 4  Simple structure  Small EMV footprint  Easy conversion  Single – several store  Storefront Mid-sized  Typically tier 3  Small structure  Light EMV footprint  Small conversion  Regional chains  Storefront  E-commerce Large  Tier 2 level merchant  Large structure  Large EMV footprint  Challenging conversion  Regional – nat. chains  Storefront  E-commerce  MOTO  Field Services Super  Tier 1 level merchant  Complex Structure  Huge EMV footprint  Integrated POS  Difficult conversion  National chains  Storefront  E-commerce  MOTO  Field Services  Multiple brands EMV - What should I be doing right now? Retail Infrastructure Use Cases 18

EMV - What should I be doing right now? Retail Infrastructure Use Cases 19

SetupPOSTRegisterControllerSwitchEnd to End CertProcessorImpact HWSWHWSW Countertop POST Replace w/new POST Low Countertop POST Add all-in-one PINpad ---- High Mobile POST Replace w/new POST Low POS w/mag wedge Replace w/CT POST Low POS w/mag wedge Replace w/PINpad - -- Medium Integrated PINpad Replace w/new PINpad - High Integrated wedge Replace w/PINpad - High Smart phone integrated Replace w/EMV dongle - High Smart phone stand alone Replace w/EMV dongle Low EMV - What should I be doing right now? Merchant Impact Chart 20

Main page: EMV Migration: CSCIP Certification Program: Roadmap whitepaper: map_in_the_US_ pdf EMV – Who can help? 21

Main page: EMV – Who can help? 22

Main page: Best Practices: Guide to EMV: White Papers: EMV – Who can help? 23

mandate-for-u-s-canada-and-mexico/ emv-migration-roadmap-to-atm-channel/ Press: Portals: EMV – Who can help? 24

Solutions Providers White papers: FAQ: Press: Portals: Blogs: s-Denis-Predicts-the-Future-of-EMV-in-North-America merchants-part-iii/ EMV – Who can help?  Consultation  Training  Advocacy  Enablement  Presence 25

1099 Days remaining to October, 2015 liability shift days remaining Start Planning Today! EMV - What should I be doing right now? 26

EMV: The Future is Now Q&A EMV: The Future is Now Q&A