SlideShare a Scribd company logo
Bernried, September 2018
Kurt Schmid, Managing Director Digital Payments
A small step for a programmer, a big step for payments
Merchant Tokenization & Secure
Remote Commerce
Questions
Who likes to enter PANs again and again
for every new merchant?
Who is worried of fraud on his/her
card?
Who knows all the places where your
card data is stored?
Why is Amazon so powerful?
2
Tokenization
3
When the PAN and other card data is known fraud
can be made with little efforts
The PAN and other card data therefore is in PCI-
Scope
The weakest link makes the level of security
Why Tokenization? What is the problem?
Securing the Card Number (PAN)
Key and surrounding roles
5
Token
Requestor
Token
Service
Provider
Card Issuer
Merchant
End User
PSPScheme
Acquirer
NSP
IoT
Device Wallet
(X Pay)
TR TSP
Issuer
TSP
Card Issuer
Token
Service
Provider
Token
Requestor
Main Use Case: Digitize (Tokenize) Card
6
Yellow case
Step up auth.
Main Use Case: Secure variant of Digitize
7
Token
Requestor
Token
Service
Provider
Card Issuer
authenticates
Encrypted PAN
Green case
Scaling Up Tokenization (1)
8
Token
Requestor
Token
Service
Provider
Card Issuer
Scaling Up Tokenization (2)
9
Token
Requestor
Token Service Provider Card Issuer
MDES, VTS, AETS
Scaling Up Tokenization (3)
10
Token
Requestor
Token
Service
Provider
Card Issuer
Aggregators
Token
Requestor
TSP
Card Issuer
TSP
Know Usage for Mobile Contactless Payment
11
Enabling an App to perform mobile contactless
payment at the POS
Request Tokens via MDES, VTS etc. for Cloud
Based Payments
NFC Interface to Terminals nbased on Host Card
Emulation (HCE)
Replenishment of short living card keys to
increase security (“SUK”, “LUK” instead of CMKs)
MyBankApp
Accounts 6,750.00
Recent Transactions
Ready to Pay
Tokenization in use for Mobile Contactless Payments
12
Token
Requestor
(CMS-D,
MAP)
Scheme
Token
Service
(MDES
VTS
AETS)
Card Issuer
authenticates
Encrypted PAN
PSP,
Acquirer
Network
AuthDeTok.
E-Commerce Payment
13
Enabling an e-Commerce
application for Payments
Card Not Present and 3DS
today’s prevailing
methods for checkout
Concerns in eComm Payments
14
Risk/Fraud through
different attacks
Low Conversion rates
on mobile channels
Abandonning the
checkout process
Higher costs for CNP
versus CP
Merchant concerns Issuer concerns
Risk/Fraud through
different attacks
Cost of customer care
Lost transactional
Revenue
Consumer concerns
Ease of onboarding
Convience at shopping
Why not use Tokenization in e-Commerce?
Each merchant does not store the PAN but a
token
Security will be Card Present like by using a
cryptogram
15
The basic Ideas:
Mastercard started M4M (MDES for
Merchants)
VISA speaking about Tokenizazion in
eCommerce and Card of File (COF)
Tokenization in use for e-Commerce Payments
16
Token
Requestor
(CMS-D,
MAP)
Scheme
Token
Service
(MDES
VTS
AETS)
Card Issuer
PSP,
Acquirer
Network
AuthDeTok.
COF
PAN Entry
Use Cases
Enroll: Add card manually or tokenize from card of file
Display cards: Card art coming from token service (User
sees his real card image)
Transact: Generate EMV cryptogram (can be used for one
or more transactions)
Lifecycle: Issuer Account Update
Secure Remote Commerce
18
SRC
Rocket still to be loaded
Secure Remote Commerce Framework (“SRC”)
Defined by EMVCo ( /)
Scheme agnostic to help interoperability
Pay securely by credit card” button in checkout
Will be scheme neutral successor of MasterPass & Visa Checkout starting 2019 / 2020
Will support card tokenization using MDES and VTS
Will support card present type security (“cryptograms”)
Demonstrator available from Netcetera, Training courses will be available
Roles used in SRC
20
Token
Requestor
Token
Service
Provider
(Scheme)
Card Issuer
Supporting
SRC
SRC System
Digital Card
Facilitator
Digital
Shopping
Application
(aka
Merchant)
PSP
SRC
Inititator
SRC Flow once device is registered / returned user
Versus first time flow
Benefits
Seamless experience – Starts with card entry
like user is used to do
No onboarding required – but device /
merchant pairing possible from issuer app
Works with all schemes in the same way
Tokenization and EMV-like security will
prevent fraud and lower the costs
As Issuer
As Merchant
As PSP
As Acquirer
How to approach this?
Ask for a training
on SRC done by
our expert
Thomas Fromherz
Europaplatz4
4020Linz
Austria
info@netcetera.com
+43664 11211 00
Kurt Schmid
Managing Director Digital Payment
Kurt.Schmid@netcetera.com

More Related Content

PDF
Digital Payment Quo Vadis
PDF
EMV Secure Remote Commerce (SRC)
PDF
Payment trend scouting - Kurt Schmid, Netcetera
PDF
Merchant tokenization and EMV® Secure Remote Commerce
PDF
Digital Payment in 2020 - Kurt Schmid, Netcetera
PDF
Increase conversion, convenience and security in e-commerce checkouts - Silke...
PDF
Digital Payment and 3-D Secure by Netcetera
PDF
The Future of Payments
Digital Payment Quo Vadis
EMV Secure Remote Commerce (SRC)
Payment trend scouting - Kurt Schmid, Netcetera
Merchant tokenization and EMV® Secure Remote Commerce
Digital Payment in 2020 - Kurt Schmid, Netcetera
Increase conversion, convenience and security in e-commerce checkouts - Silke...
Digital Payment and 3-D Secure by Netcetera
The Future of Payments

What's hot (20)

PDF
Boost your approved transaction volume - Ana Vuksanovikj Vaneska, Netcetera
PDF
3-D Secure 2.0 - Stephan Rüdisüli, Netcetera & Patrick Juffern, INFORM
PDF
Seamless 3-D Secure e-commerce experience
PPTX
3-D Secure 2.0
PPT
Payer Authentication Solutions For Verified by VISA
DOCX
3-D Secure and MPI Integrations
PPTX
What's 3D costing your business?
PDF
Payment Gateway
PDF
3D-Secure 2.2 Webinar
PPT
Payment Gateway
PDF
Seamless payment integration with shopify (1)
PDF
A Complete Model of the Payment Service Business
PPT
Visa master card contactless payment in china_v1
PPTX
Online payment gateway provider
PDF
Powerful Reward Platform
PDF
PPTX
Hacking Point of Sale
PDF
IBM Payments Gateway
PPTX
Peter Afanasiev - Architecture of online Payments
PPTX
Payment gateway/payment service providers and future trends in mobile payment...
Boost your approved transaction volume - Ana Vuksanovikj Vaneska, Netcetera
3-D Secure 2.0 - Stephan Rüdisüli, Netcetera & Patrick Juffern, INFORM
Seamless 3-D Secure e-commerce experience
3-D Secure 2.0
Payer Authentication Solutions For Verified by VISA
3-D Secure and MPI Integrations
What's 3D costing your business?
Payment Gateway
3D-Secure 2.2 Webinar
Payment Gateway
Seamless payment integration with shopify (1)
A Complete Model of the Payment Service Business
Visa master card contactless payment in china_v1
Online payment gateway provider
Powerful Reward Platform
Hacking Point of Sale
IBM Payments Gateway
Peter Afanasiev - Architecture of online Payments
Payment gateway/payment service providers and future trends in mobile payment...
Ad

Similar to Digital Payments - Netcetera Innovation Summit 2018 (20)

PDF
Can security and convenience go hand in hand in e-commerce
PDF
What is Payment Tokenization?
PPTX
Tokenisation 2.0
PPTX
Straight Talk on Data Tokenization for PCI & Cloud
PPT
Pcitf iiw10
PDF
key-trends-in-merchant-security
PPTX
RBI Tokenization And Impact on Digital Adoption
PPTX
Smart Card to the Cloud for Convenient, Secured NFC Payment
PPTX
EMV - The Chips are Coming - Ken Givens U.S. Merchant Payment Solutions 11-15
PDF
pPOS Project Presentation_v1
PDF
Secure Payments: How Card Issuers and Merchants Can Stay Ahead of Fraudsters
PPTX
So you want to be an EMV Issuer...
PPT
E-Commerce 08
PPTX
Tim sloane preparing for rapid payments innovation
PDF
Smart card to the cloud for convenient, secured nfc payment
PDF
EMV: Preparing for Changes to the Retail Payment Process
PPTX
Payment Card System Overview
PDF
Multiple tokenization schemes meet the merchant
PDF
White Paper: Tokenization, Credit Card Fraud Prevention, Beyond PCI Measures
Can security and convenience go hand in hand in e-commerce
What is Payment Tokenization?
Tokenisation 2.0
Straight Talk on Data Tokenization for PCI & Cloud
Pcitf iiw10
key-trends-in-merchant-security
RBI Tokenization And Impact on Digital Adoption
Smart Card to the Cloud for Convenient, Secured NFC Payment
EMV - The Chips are Coming - Ken Givens U.S. Merchant Payment Solutions 11-15
pPOS Project Presentation_v1
Secure Payments: How Card Issuers and Merchants Can Stay Ahead of Fraudsters
So you want to be an EMV Issuer...
E-Commerce 08
Tim sloane preparing for rapid payments innovation
Smart card to the cloud for convenient, secured nfc payment
EMV: Preparing for Changes to the Retail Payment Process
Payment Card System Overview
Multiple tokenization schemes meet the merchant
White Paper: Tokenization, Credit Card Fraud Prevention, Beyond PCI Measures
Ad

More from Netcetera (20)

PDF
AI First. Erfolgsfaktoren für künstliche Intelligenz im Unternehmen
PPTX
Augmenting Maintenance
PDF
Front-end up front
PDF
The future of Prototpying
PPTX
Online shopping technology in the fast lane?
PPTX
Augmenting Health Care
PDF
Driving transactional growth with 3-D Secure
PDF
EMV® Secure Remote Commerce
PDF
Context: The missing ingredient in multilingual software translation
PDF
"Whats up and new at Netcetera?" - Netcetera Innovation Summit 2018
PDF
Fintech Innovations - Netcetera Innovation Summit 2018
PDF
RiSIC - Stop losing money. Today.
PDF
HoloLens in der Neurochirurgie
PDF
DEVELOPING CONVERSATIONAL INTERFACES FOR IOS
PDF
BUILDING VOICE RESPONSIVE APPS ON IOS
PDF
UNDERSTANDING LANGUAGE ON IOS
PDF
Blockchain use cases in health and education
PDF
Augmented Reality and Conversational Interfaces workshop
PDF
Chances of open banking
PDF
New business cases needed because of new technologies arising
AI First. Erfolgsfaktoren für künstliche Intelligenz im Unternehmen
Augmenting Maintenance
Front-end up front
The future of Prototpying
Online shopping technology in the fast lane?
Augmenting Health Care
Driving transactional growth with 3-D Secure
EMV® Secure Remote Commerce
Context: The missing ingredient in multilingual software translation
"Whats up and new at Netcetera?" - Netcetera Innovation Summit 2018
Fintech Innovations - Netcetera Innovation Summit 2018
RiSIC - Stop losing money. Today.
HoloLens in der Neurochirurgie
DEVELOPING CONVERSATIONAL INTERFACES FOR IOS
BUILDING VOICE RESPONSIVE APPS ON IOS
UNDERSTANDING LANGUAGE ON IOS
Blockchain use cases in health and education
Augmented Reality and Conversational Interfaces workshop
Chances of open banking
New business cases needed because of new technologies arising

Recently uploaded (20)

PDF
Which alternative to Crystal Reports is best for small or large businesses.pdf
PDF
Understanding Forklifts - TECH EHS Solution
PDF
PTS Company Brochure 2025 (1).pdf.......
PPTX
ManageIQ - Sprint 268 Review - Slide Deck
PDF
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
PPTX
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
PDF
Navsoft: AI-Powered Business Solutions & Custom Software Development
PPTX
Odoo POS Development Services by CandidRoot Solutions
PDF
Nekopoi APK 2025 free lastest update
PDF
Digital Strategies for Manufacturing Companies
PDF
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
PPTX
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
PDF
How to Choose the Right IT Partner for Your Business in Malaysia
PDF
System and Network Administration Chapter 2
PDF
2025 Textile ERP Trends: SAP, Odoo & Oracle
PPTX
ai tools demonstartion for schools and inter college
PDF
Softaken Excel to vCard Converter Software.pdf
PDF
Design an Analysis of Algorithms I-SECS-1021-03
PDF
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
PDF
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)
Which alternative to Crystal Reports is best for small or large businesses.pdf
Understanding Forklifts - TECH EHS Solution
PTS Company Brochure 2025 (1).pdf.......
ManageIQ - Sprint 268 Review - Slide Deck
Audit Checklist Design Aligning with ISO, IATF, and Industry Standards — Omne...
Agentic AI : A Practical Guide. Undersating, Implementing and Scaling Autono...
Navsoft: AI-Powered Business Solutions & Custom Software Development
Odoo POS Development Services by CandidRoot Solutions
Nekopoi APK 2025 free lastest update
Digital Strategies for Manufacturing Companies
Flood Susceptibility Mapping Using Image-Based 2D-CNN Deep Learnin. Overview ...
Agentic AI Use Case- Contract Lifecycle Management (CLM).pptx
How to Choose the Right IT Partner for Your Business in Malaysia
System and Network Administration Chapter 2
2025 Textile ERP Trends: SAP, Odoo & Oracle
ai tools demonstartion for schools and inter college
Softaken Excel to vCard Converter Software.pdf
Design an Analysis of Algorithms I-SECS-1021-03
Claude Code: Everyone is a 10x Developer - A Comprehensive AI-Powered CLI Tool
SAP S4 Hana Brochure 3 (PTS SYSTEMS AND SOLUTIONS)

Digital Payments - Netcetera Innovation Summit 2018

  • 1. Bernried, September 2018 Kurt Schmid, Managing Director Digital Payments A small step for a programmer, a big step for payments Merchant Tokenization & Secure Remote Commerce
  • 2. Questions Who likes to enter PANs again and again for every new merchant? Who is worried of fraud on his/her card? Who knows all the places where your card data is stored? Why is Amazon so powerful? 2
  • 4. When the PAN and other card data is known fraud can be made with little efforts The PAN and other card data therefore is in PCI- Scope The weakest link makes the level of security Why Tokenization? What is the problem? Securing the Card Number (PAN)
  • 5. Key and surrounding roles 5 Token Requestor Token Service Provider Card Issuer Merchant End User PSPScheme Acquirer NSP IoT Device Wallet (X Pay) TR TSP Issuer TSP
  • 6. Card Issuer Token Service Provider Token Requestor Main Use Case: Digitize (Tokenize) Card 6 Yellow case Step up auth.
  • 7. Main Use Case: Secure variant of Digitize 7 Token Requestor Token Service Provider Card Issuer authenticates Encrypted PAN Green case
  • 8. Scaling Up Tokenization (1) 8 Token Requestor Token Service Provider Card Issuer
  • 9. Scaling Up Tokenization (2) 9 Token Requestor Token Service Provider Card Issuer MDES, VTS, AETS
  • 10. Scaling Up Tokenization (3) 10 Token Requestor Token Service Provider Card Issuer Aggregators Token Requestor TSP Card Issuer TSP
  • 11. Know Usage for Mobile Contactless Payment 11 Enabling an App to perform mobile contactless payment at the POS Request Tokens via MDES, VTS etc. for Cloud Based Payments NFC Interface to Terminals nbased on Host Card Emulation (HCE) Replenishment of short living card keys to increase security (“SUK”, “LUK” instead of CMKs)
  • 12. MyBankApp Accounts 6,750.00 Recent Transactions Ready to Pay Tokenization in use for Mobile Contactless Payments 12 Token Requestor (CMS-D, MAP) Scheme Token Service (MDES VTS AETS) Card Issuer authenticates Encrypted PAN PSP, Acquirer Network AuthDeTok.
  • 13. E-Commerce Payment 13 Enabling an e-Commerce application for Payments Card Not Present and 3DS today’s prevailing methods for checkout
  • 14. Concerns in eComm Payments 14 Risk/Fraud through different attacks Low Conversion rates on mobile channels Abandonning the checkout process Higher costs for CNP versus CP Merchant concerns Issuer concerns Risk/Fraud through different attacks Cost of customer care Lost transactional Revenue Consumer concerns Ease of onboarding Convience at shopping
  • 15. Why not use Tokenization in e-Commerce? Each merchant does not store the PAN but a token Security will be Card Present like by using a cryptogram 15 The basic Ideas: Mastercard started M4M (MDES for Merchants) VISA speaking about Tokenizazion in eCommerce and Card of File (COF)
  • 16. Tokenization in use for e-Commerce Payments 16 Token Requestor (CMS-D, MAP) Scheme Token Service (MDES VTS AETS) Card Issuer PSP, Acquirer Network AuthDeTok. COF PAN Entry
  • 17. Use Cases Enroll: Add card manually or tokenize from card of file Display cards: Card art coming from token service (User sees his real card image) Transact: Generate EMV cryptogram (can be used for one or more transactions) Lifecycle: Issuer Account Update
  • 19. Secure Remote Commerce Framework (“SRC”) Defined by EMVCo ( /) Scheme agnostic to help interoperability Pay securely by credit card” button in checkout Will be scheme neutral successor of MasterPass & Visa Checkout starting 2019 / 2020 Will support card tokenization using MDES and VTS Will support card present type security (“cryptograms”) Demonstrator available from Netcetera, Training courses will be available
  • 20. Roles used in SRC 20 Token Requestor Token Service Provider (Scheme) Card Issuer Supporting SRC SRC System Digital Card Facilitator Digital Shopping Application (aka Merchant) PSP SRC Inititator
  • 21. SRC Flow once device is registered / returned user
  • 23. Benefits Seamless experience – Starts with card entry like user is used to do No onboarding required – but device / merchant pairing possible from issuer app Works with all schemes in the same way Tokenization and EMV-like security will prevent fraud and lower the costs
  • 24. As Issuer As Merchant As PSP As Acquirer How to approach this? Ask for a training on SRC done by our expert Thomas Fromherz
  • 25. Europaplatz4 4020Linz Austria info@netcetera.com +43664 11211 00 Kurt Schmid Managing Director Digital Payment Kurt.Schmid@netcetera.com