SlideShare a Scribd company logo
Get Strong Customer Authentication
Ready for PSD2
Kaveen Rodrigo
Senior Software Engineer
Webinar Outline
● Motivation for this webinar
● Defining Strong Customer Authentication (SCA)
○ SCA in the context of Open Banking flows
○ Three elements of SCA
○ User experience impact of SCA
● Providing better SCA experiences for customers
● How WSO2 Open Banking enables SCA
Motivation
Stakeholders Not Ready For SCA
● Financial Conduct Authority UK pushes SCA deadlines 18
months ahead.
○ Acknowledges the complexity of SCA requirements and customer
adoption
○ Phased roll out of PSD2 SCA
https://www.fca.org.uk/news/press-releases/fca-agrees-plan-phased-implementation-strong-customer-authentication
Strong Customer
Authentication
What’s SCA Trying to Solve?
• PSD2 allows accredited third parties to gain access to customer
accounts/payments with customer consent
• Ensures the consenting customer is not a fraudulent entity
attempting to gain access
1. Initiating Application
5. Perform Transaction
TPP ASPSPPSU
2. Request Consent
4. Sent Consent Status
3. Confirm Consent
Benefit of SCA for Open Banking
• Transactions only take place with user consent
• Gives assurance to banks and users that the request was
understood and agreed upon (WYSIWYS)
• Promotes transparency throughout the transaction to
consumers and the bank.
• Strongly authenticates the user to avoid any fraudsters
8
Strong Customer Authentication
• SCA is an mandatory requirement for PSD2
implementers
• Authentication should take place in two or more
elements
9
‘strong customer authentication’ means an authentication
based on the use of two or more elements
- PSD2
The Three Elements of SCA
10
What is Considered as SCA?
✅ User identifier and password (Knowledge) and SMS one
time password (Possession).
✅ Private pin (Knowledge) and OOBA fingerprint
authentication (Possession/Inherence)
User Identifier and password (Knowledge) and Security Pin
(Knowledge)
11
Unwanted Effects of SCA
• Existing internet banking customers who aren’t familiar with
multi-factor authentication
• Continued use of SCA may tire customers and cause friction to
minimum risk transactions
• Hindrance to user experience
12
Providing Frictionless SCA
Experiences
Introducing Customers to SCA
● Strategy to roll-out SCA incrementally to help adoption
of open banking:
○ Easing the SCA process on initial roll-out
○ Getting customers to adopt an SCA compliant second
factors
14
15
Authorisation User Interfaces
“Consumer research has shown that people find a recognisable ASPSP login
page and process reassuring and increases their confidence in the journey”
● Customer Experience Guidelines 7.2
16
Clarity of Consumer Consent
“Research amongst consumers has shown that the summary information
step acts as a confirmation of exactly what they have consented to”
● Customer Experience Guidelines 7.2
17
Use of Decoupled Authentication
“Research shows that consumers are familiar with decoupled authentication
when making a payment or setting up a new payment ... Many welcome the
additional level of security decoupled authentication provides.”
● Customer Experience Guidelines 7.2
TPP Bank TPP
Consumption Device
Authorisation Device
1 2
3
4
18
Adaptive Authentication
With adaptive authentication, SCA is only applied in scenarios where the
transaction risk is high, therefore the the SCA process is applied intelligently.
Transaction amount
> 30 Euros
Transaction amount
< 30 Euros
Basic Authentication Second SCA element
Basic Authentication
Authenticated
With SCA
Authenticated
With CA
How WSO2 Open Banking
Enables Effective SCA
Customization Flexibility
● WSO2 Open banking provides flexibility to customize the SCA
flow
○ Custom Authenticators
○ APIs for consent management
○ Authorization portal customization
20
Authentication Freedom
• WSO2 Open Banking is built on top of
the WSO2 Identity Server and comes
with the same flexibilities
• Already existing zero-code pluggable
authenticators
Authenticator = SCA Element
https://docs.wso2.com/display/OB140/Adding+Custom+Authenticators
21
Adaptive Authentication Capability
• WSO2 Open Banking provides flexible adaptive authentication
scripting
• WSO2 Open Banking business intelligence provides
out-of-the-box transaction risk analysis and fraud detection
https://docs.wso2.com/display/OB140/Integrate+Open+Banking+Business+Intelligence
22
Takeaway Points
• SCA is an integral part of PSD2 Open Banking
• The implementation strategy will play an important role in the
adoption of open banking
• Special thought on UX is necessary when selecting factors for
SCA
• Flexible SCA options will encourage different consumer groups
to adopt open banking
23
Any Questions?
Lean More On WSO2 Open Banking
More Information http://wso2.com/solutions/financial/open-banking/
Try out WSO2 Open Banking https://openbanking.wso2.com
Get in Touch openbankingdemo@wso2.com
THANK YOU
wso2.com

More Related Content

PDF
A FEASIBILITY STUDY OF LAUNCHING CAR WASH BUSINESS IN BANGKOK
PPTX
Types of Accounts
PPTX
Audit meaning in hindi
PDF
Anti Money Laundering - CDD & KYC
PDF
Securities Regulation Code of the Philippines
PDF
Quickteller (for merchants)
PPTX
Dubai Islamic Bank
PDF
Revista natura-mx-c13 2019
A FEASIBILITY STUDY OF LAUNCHING CAR WASH BUSINESS IN BANGKOK
Types of Accounts
Audit meaning in hindi
Anti Money Laundering - CDD & KYC
Securities Regulation Code of the Philippines
Quickteller (for merchants)
Dubai Islamic Bank
Revista natura-mx-c13 2019

Similar to Get Strong Customer Authentication Ready for PSD2 (20)

PDF
Building a Fool Proof Security Strategy for PSD2 Compliance
PDF
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
PDF
Application on Know Your Customer Authentication
PDF
Go Beyond PSD2 Compliance with Digital Identity
PDF
KYC VERIFICATION USING BLOCKCHAIN
PDF
Move your customer authentication to the next level!
PDF
What's New With WSO2 Open Banking
PDF
Strong Customer Authentication - All Your Questions Answered
PDF
How Data is Revolutionizing Authentication
PDF
Security & Seamless CX in User Authentication: How to Achieve Both?
PDF
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
PPT
NetworkSecurity.ppt
Building a Fool Proof Security Strategy for PSD2 Compliance
[APIdays Singapore 2019] Implementing a Successful Open Banking Architecture
Application on Know Your Customer Authentication
Go Beyond PSD2 Compliance with Digital Identity
KYC VERIFICATION USING BLOCKCHAIN
Move your customer authentication to the next level!
What's New With WSO2 Open Banking
Strong Customer Authentication - All Your Questions Answered
How Data is Revolutionizing Authentication
Security & Seamless CX in User Authentication: How to Achieve Both?
[APIdays Melbourne 2019] The Consumer Data Right: Building a Successful Open ...
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
NetworkSecurity.ppt
Ad

More from WSO2 (20)

PDF
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
PDF
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
PDF
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
PDF
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
PDF
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
PDF
Platformless Modernization with Choreo.pdf
PDF
Application Modernization with Choreo for the BFSI Sector
PDF
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
PDF
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
PPTX
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
PPTX
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
PPTX
WSO2Con 2025 - Building Secure Customer Experience Apps
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
PPTX
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
PPTX
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
PPTX
WSO2Con 2025 - Architecting Cloud-Native Applications
PDF
Mastering Intelligent Digital Experiences with Platformless Modernization
PDF
Accelerate Enterprise Software Engineering with Platformless
PDF
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Demystifying CMS-0057-F - Compliance Made Seamless with WSO2
Quantum Threats Are Closer Than You Think – Act Now to Stay Secure
Modern Platform Engineering with Choreo - The AI-Native Internal Developer Pl...
Application Modernization with Choreo - The AI-Native Internal Developer Plat...
Build Smarter, Deliver Faster with Choreo - An AI Native Internal Developer P...
Platformless Modernization with Choreo.pdf
Application Modernization with Choreo for the BFSI Sector
Choreo - The AI-Native Internal Developer Platform as a Service: Overview
[Roundtable] Choreo - The AI-Native Internal Developer Platform as a Service
WSO2Con 2025 - Building AI Applications in the Enterprise (Part 1)
WSO2Con 2025 - Building Secure Business Customer and Partner Experience (B2B)...
WSO2Con 2025 - Building Secure Customer Experience Apps
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - AI-Driven API Design, Development, and Consumption with Enhanc...
WSO2Con 2025 - Unified Management of Ingress and Egress Across Multiple API G...
WSO2Con 2025 - How an Internal Developer Platform Lets Developers Focus on Code
WSO2Con 2025 - Architecting Cloud-Native Applications
Mastering Intelligent Digital Experiences with Platformless Modernization
Accelerate Enterprise Software Engineering with Platformless
WSO2Con2024 - WSO2's IAM Vision: Identity-Led Digital Transformation
Ad

Recently uploaded (20)

PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PDF
August Patch Tuesday
PPTX
A Presentation on Artificial Intelligence
PPTX
Group 1 Presentation -Planning and Decision Making .pptx
PDF
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
PDF
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
PDF
Web App vs Mobile App What Should You Build First.pdf
PPTX
TLE Review Electricity (Electricity).pptx
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Hindi spoken digit analysis for native and non-native speakers
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
PDF
Zenith AI: Advanced Artificial Intelligence
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
1 - Historical Antecedents, Social Consideration.pdf
PPTX
OMC Textile Division Presentation 2021.pptx
PPTX
Digital-Transformation-Roadmap-for-Companies.pptx
PDF
Unlocking AI with Model Context Protocol (MCP)
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
August Patch Tuesday
A Presentation on Artificial Intelligence
Group 1 Presentation -Planning and Decision Making .pptx
ENT215_Completing-a-large-scale-migration-and-modernization-with-AWS.pdf
Profit Center Accounting in SAP S/4HANA, S4F28 Col11
Web App vs Mobile App What Should You Build First.pdf
TLE Review Electricity (Electricity).pptx
Enhancing emotion recognition model for a student engagement use case through...
NewMind AI Weekly Chronicles - August'25-Week II
Hindi spoken digit analysis for native and non-native speakers
SOPHOS-XG Firewall Administrator PPT.pptx
Encapsulation_ Review paper, used for researhc scholars
DASA ADMISSION 2024_FirstRound_FirstRank_LastRank.pdf
Zenith AI: Advanced Artificial Intelligence
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
1 - Historical Antecedents, Social Consideration.pdf
OMC Textile Division Presentation 2021.pptx
Digital-Transformation-Roadmap-for-Companies.pptx
Unlocking AI with Model Context Protocol (MCP)

Get Strong Customer Authentication Ready for PSD2

  • 1. Get Strong Customer Authentication Ready for PSD2 Kaveen Rodrigo Senior Software Engineer
  • 2. Webinar Outline ● Motivation for this webinar ● Defining Strong Customer Authentication (SCA) ○ SCA in the context of Open Banking flows ○ Three elements of SCA ○ User experience impact of SCA ● Providing better SCA experiences for customers ● How WSO2 Open Banking enables SCA
  • 4. Stakeholders Not Ready For SCA ● Financial Conduct Authority UK pushes SCA deadlines 18 months ahead. ○ Acknowledges the complexity of SCA requirements and customer adoption ○ Phased roll out of PSD2 SCA https://www.fca.org.uk/news/press-releases/fca-agrees-plan-phased-implementation-strong-customer-authentication
  • 6. What’s SCA Trying to Solve? • PSD2 allows accredited third parties to gain access to customer accounts/payments with customer consent • Ensures the consenting customer is not a fraudulent entity attempting to gain access
  • 7. 1. Initiating Application 5. Perform Transaction TPP ASPSPPSU 2. Request Consent 4. Sent Consent Status 3. Confirm Consent
  • 8. Benefit of SCA for Open Banking • Transactions only take place with user consent • Gives assurance to banks and users that the request was understood and agreed upon (WYSIWYS) • Promotes transparency throughout the transaction to consumers and the bank. • Strongly authenticates the user to avoid any fraudsters 8
  • 9. Strong Customer Authentication • SCA is an mandatory requirement for PSD2 implementers • Authentication should take place in two or more elements 9 ‘strong customer authentication’ means an authentication based on the use of two or more elements - PSD2
  • 10. The Three Elements of SCA 10
  • 11. What is Considered as SCA? ✅ User identifier and password (Knowledge) and SMS one time password (Possession). ✅ Private pin (Knowledge) and OOBA fingerprint authentication (Possession/Inherence) User Identifier and password (Knowledge) and Security Pin (Knowledge) 11
  • 12. Unwanted Effects of SCA • Existing internet banking customers who aren’t familiar with multi-factor authentication • Continued use of SCA may tire customers and cause friction to minimum risk transactions • Hindrance to user experience 12
  • 14. Introducing Customers to SCA ● Strategy to roll-out SCA incrementally to help adoption of open banking: ○ Easing the SCA process on initial roll-out ○ Getting customers to adopt an SCA compliant second factors 14
  • 15. 15 Authorisation User Interfaces “Consumer research has shown that people find a recognisable ASPSP login page and process reassuring and increases their confidence in the journey” ● Customer Experience Guidelines 7.2
  • 16. 16 Clarity of Consumer Consent “Research amongst consumers has shown that the summary information step acts as a confirmation of exactly what they have consented to” ● Customer Experience Guidelines 7.2
  • 17. 17 Use of Decoupled Authentication “Research shows that consumers are familiar with decoupled authentication when making a payment or setting up a new payment ... Many welcome the additional level of security decoupled authentication provides.” ● Customer Experience Guidelines 7.2 TPP Bank TPP Consumption Device Authorisation Device 1 2 3 4
  • 18. 18 Adaptive Authentication With adaptive authentication, SCA is only applied in scenarios where the transaction risk is high, therefore the the SCA process is applied intelligently. Transaction amount > 30 Euros Transaction amount < 30 Euros Basic Authentication Second SCA element Basic Authentication Authenticated With SCA Authenticated With CA
  • 19. How WSO2 Open Banking Enables Effective SCA
  • 20. Customization Flexibility ● WSO2 Open banking provides flexibility to customize the SCA flow ○ Custom Authenticators ○ APIs for consent management ○ Authorization portal customization 20
  • 21. Authentication Freedom • WSO2 Open Banking is built on top of the WSO2 Identity Server and comes with the same flexibilities • Already existing zero-code pluggable authenticators Authenticator = SCA Element https://docs.wso2.com/display/OB140/Adding+Custom+Authenticators 21
  • 22. Adaptive Authentication Capability • WSO2 Open Banking provides flexible adaptive authentication scripting • WSO2 Open Banking business intelligence provides out-of-the-box transaction risk analysis and fraud detection https://docs.wso2.com/display/OB140/Integrate+Open+Banking+Business+Intelligence 22
  • 23. Takeaway Points • SCA is an integral part of PSD2 Open Banking • The implementation strategy will play an important role in the adoption of open banking • Special thought on UX is necessary when selecting factors for SCA • Flexible SCA options will encourage different consumer groups to adopt open banking 23
  • 25. Lean More On WSO2 Open Banking More Information http://wso2.com/solutions/financial/open-banking/ Try out WSO2 Open Banking https://openbanking.wso2.com Get in Touch openbankingdemo@wso2.com