SlideShare a Scribd company logo
EXTERNAL USE
JOHANNES GRÜLL
JUNE 22ND, 2016
PRESENT IMPROVED - FUTURE INSIDE
SECURE CLOSED LOOP
PAYMENTS IN AN OPEN
ENVIRONMENT
• Diners Club first contemporary credit card in the
1950’s
• Convenient way to pay for goods & services
without cash
• Convenient use across multiple vendors
• Started as piece of cardboard with signature
• Evolved to complex payment scheme’s like
EMV
• Transaction fees
• Liability shifts
Challenges
From Cardboard to Multi-party Payment Solutions
June 22, 20162.
Agenda
1. Adding value to access credentials
2. Trust & guarding against fraud
3. Practical implementation
• MIFARE DESFire EV2
• MIFARE Plus EV1
• Secure your smartcard a slot in your customer’s
wallet
• Increase personal value of card to customers
• Increased self service possibilities
• Increased customer & brand engagement
• Common Criteria based platforms allow to run
own payment solutions
• Receive cash in advance
• Minimize cash handling cost
• Power own incentive schemes towards customers &
partners
Closed-loop Micropayment
Increasing Value of Credentials
June 22, 20164.
Micropayment in Single-vendor vendor systems
June 22, 20165.
Vendor
Locations
Vendor/
Card Issuer
End
User
Card loadingSpending money
Demand for Multi-vendor Systems
June 22, 20166.
How can I
attract
additional
customers?
Service
Providers
Card
Issuer
End
User
I want
convenient
access with 1
credential only
I want to
increase the
value of my card
to end users
Micropayment in Multi-vendor systems - Challenge
June 22, 20167.
Service
Providers
Card
Issuer
End
User
1.
2.
Purchase
3.
Multiple challenges in claiming and re-
imbursing within the application
provider eco-system arise
• Traceability of Transactions
• Common Criteria certified solutions securing wallets
• New smartcard features securing and proofing transactions
• Authenticity of Transactions
• Tax regulations
• Cash register
• Privacy of individual data
• End user
• Service providers sales data
• Quick & reliable re-imbursement
• Automated
• Scalable
• Protecting individual application providers sales data
Challenges in multi-vendor systems
Shared Wallet Applications
June 22, 20168.
Use Cases: Campus Card
Cashless Campus as Eco-system
June 22, 20169.
• On-Campus Services
• Payment (vending machines, copying machines,…)
• Student self-service (registering, printing documents,..)
• Off-Campus Eco-system integration
• Public transport linking university sites
• Restaurants
• Cafes
• New Value Streams
• Co-promotion
• Fee based model
• Dedication of stipendiums
• Requirement: Scalable & future proof platforms
MIFARE Plus® generation benefits
MIFARE Plus® EV1
June 22, 2016
MIFARE
Plus S
MIFARE
Plus SE
MIFARE
Plus X
MIFARE
Plus EV1
RF Interface
P rotocol
UID –
unique
identifier
Communication
speed
M emory size
[Byte]
2KB 1KB 2KB 2KB
4KB 4KB 4KB
M emory M odel
Crypto
Key Length
Authentication
Communication,
S ecurity
T ransaction
M AC
yes
P roximity Check yes
V irtual Card
S elect
CC Certification EAL4+ no EAL4+ EAL5+
IS O 7816-4
AP DU
yes
NFC compliance
T arget
applications
Input
capacitance
17pF 17pF 17pF 17pF or 70pF
S ecure NFC
channel
in SL1& SL3
M ulti
applications
yes
NFC capabilities in SL3
Public transport / Campus cards / Access management
Compact, Sectors & 16- byte block
Crypto- 1, AES
48- bit crypto- 1, 128- bit AES
3- pass mutual
CMACed
MIFARE Plus
ISO/IEC 14443- 2, type A
ISO/IEC 14443- 3&4
7- byte UID, 4- byte NUID, RID
106- 848 Kbps
in SL3 level
Supported via MAD
no
no
no
1994
MIFARE
Classic
2009
MIFARE Plus
06/2015
MIFARE Plus SE
04/2016
MIFARE Plus EV1
MIFARE DESFire® generation benefits
MIFARE DESFire® EV2
June 22, 201611.
2002
MIFARE DESFire
2008
MIFARE DESFire EV1
2015
MIFARE DESFire EV1 256B
2016
MIFARE DESFire EV2
MIFARE
DESFire EV1
MIFARE
DESFire EV2
ISO/IEC 14443 A 1-4  
ISO/IEC 7816-4 support extended extended
EEPROM data memory 2/4/8KB 2/4/8KB
Flexible file structure  
NFC Forum Tag Type 4  
Secure, high-speed cmd  
Unique ID 7BUID or 4B RID 7BUID or 4B RID
Number of applications 28 unlimited
Number of files per app 32 32
High data rates support up to 848 Kbit/s up to 848 Kbit/s
Crypto algorithms support
DES/2K3DES/
3K3DES/AES
DES/2K3DES/
3K3DES/AES
CC certification (HW + SW) EAL 4+ EAL 5+
MIsmartApp feature - 
Transaction MAC per app - 
Multiple keysets per app - Up to 16 keysets
Multiple file access rights - Up to 8 keys
Inter-app files sharing - 
Virtual Card Architecture - 
Proximity Check - 
Delivery types
Wafer, MOA4 &
MOA8
Wafer, MOA4 &
MOB6
TransactionMAC
Securing your money in a shared economy
June 22, 201612.
• MAC calculated over the data of a whole
transaction
• Prove of card presence
• Counters to eliminate replay attempts
• Possibility to integrate reader ID to allocate
transaction to specific service provider
• Detect missing transactions
TransactionMAC in Multi-vendor Systems
June 22, 201613.
Service
Providers
Clearing
House
TMAC keys shared by card and
clearing house
TMAC‘s sent to clearing house
Re-imbursement after clearing
Thank you
Visit us at http://MIFARE.net
Follow us:
https://twitter.com/nxp_mifare https://at.linkedin.com/in/nxpmifarewww.youtube.com/user/nxpsemiconductorshttp://blog.nxp.com/ https://www.facebook.com/nxpsemi
Q&A
Webinar Series
Outlook
Date Title
May 24th 2016 MIFARE Innovation Roadmap – present improved, future inside
June 1st 2016 How to protect contactless systems today and tomorrow
June 8th 2016 Enhanced user experience through active application management
June 15th 2016 Streamlined user management for multi-vendor installations
June 22nd 2016 Secure closed loop payments in an open environment
June 29th 2016 Introduce the future in your today’s system – how to ensure smooth system
upgrades
July 6th 2016 Added value to card based environments through NFC and cloud – when IoT
becomes reality
July 13th 2016 Complement use cases with mobiles and wearables
NXP MIFARE Webinar: Secure Closed Loop Payments In An Open Environment

More Related Content

PPTX
RFID attendance system
PDF
RFID Privacy & Security Issues
PDF
Single Sign On - The Basics
PPTX
RFID (Radio Frequency Identification)
PPTX
RFID security ppt
PDF
IoT Wireless Technologies
PDF
ZigBee module
PDF
Security architecture - Perform a gap analysis
RFID attendance system
RFID Privacy & Security Issues
Single Sign On - The Basics
RFID (Radio Frequency Identification)
RFID security ppt
IoT Wireless Technologies
ZigBee module
Security architecture - Perform a gap analysis

What's hot (20)

PPT
RFID and its applications
PDF
GTC 2022 Keynote
PPTX
Presentation RFID
PPT
RFID based access control ppt
PDF
Sensor networks: 6LoWPAN & LPWAN
PPTX
RFID based Attendance System
PPT
RFID Basics
PDF
LoRaWAN in Depth
PDF
Getting started with Android pentesting
PDF
Rfid based smart attendance system
PPTX
Radio frequency identification
PPTX
7 Steps to Build a SOC with Limited Resources
DOCX
Electronic Notice Board Using Raspberry Pi and Android Phone
PDF
Secure Access – Anywhere by Prisma, PaloAlto
PDF
Cybersecurity Insiders Webinar - Zero Trust: Best Practices for Securing the...
PDF
Bluetooth Low Energy - A Case Study
PPTX
RFID Shopping System
PPTX
Rfid ppt 8th sem
PPT
SaaS Presentation
RFID and its applications
GTC 2022 Keynote
Presentation RFID
RFID based access control ppt
Sensor networks: 6LoWPAN & LPWAN
RFID based Attendance System
RFID Basics
LoRaWAN in Depth
Getting started with Android pentesting
Rfid based smart attendance system
Radio frequency identification
7 Steps to Build a SOC with Limited Resources
Electronic Notice Board Using Raspberry Pi and Android Phone
Secure Access – Anywhere by Prisma, PaloAlto
Cybersecurity Insiders Webinar - Zero Trust: Best Practices for Securing the...
Bluetooth Low Energy - A Case Study
RFID Shopping System
Rfid ppt 8th sem
SaaS Presentation
Ad

Viewers also liked (20)

PDF
Contactless & NFC Ecosystem in Turkey & Yapi Kredi Products/Perspective
PDF
NXP MIFARE Webinar: Introduce The Future In Your Today's System- How To Ensur...
PDF
NXP MIFARE Webinar: Streamlined User Management For Multi-Vendor Installations
PDF
NXP MIFARE Webinar: How To Protect Contactless Systems Today And Tomorrow
PDF
Emerging Technologies in Payment Industry
PDF
NXP MIFARE Webinar: Complement Use Cases With Mobiles And Wearables
PDF
NXP MIFARE Webinar: Added Value To Card Based Environments Through NFC And Cloud
PDF
NXP MIFARE Webinar: Enhanced User Experience Through Active Application Manag...
PDF
NXP MIFARE Webinar: Innovation Road Map: Present Improved- Future Inside
PDF
Rfid security workshop v0.9 -nahuel_grisolia
PDF
NfC Forum Mobile NfC Ecosystem White Paper
PDF
La Saga NFC
PDF
Nfc developers nokia mit event 12 13 10
PPT
Near Field Communication on iPhone with iCarte
PPT
Mobile-based NFC fare collection
PDF
ACR128 product presentation by Advanced Card Systems Ltd.
PDF
Mifare cards
PPT
PPT
ACR122L VisualVantage Serial NFC Reader with LCD
Contactless & NFC Ecosystem in Turkey & Yapi Kredi Products/Perspective
NXP MIFARE Webinar: Introduce The Future In Your Today's System- How To Ensur...
NXP MIFARE Webinar: Streamlined User Management For Multi-Vendor Installations
NXP MIFARE Webinar: How To Protect Contactless Systems Today And Tomorrow
Emerging Technologies in Payment Industry
NXP MIFARE Webinar: Complement Use Cases With Mobiles And Wearables
NXP MIFARE Webinar: Added Value To Card Based Environments Through NFC And Cloud
NXP MIFARE Webinar: Enhanced User Experience Through Active Application Manag...
NXP MIFARE Webinar: Innovation Road Map: Present Improved- Future Inside
Rfid security workshop v0.9 -nahuel_grisolia
NfC Forum Mobile NfC Ecosystem White Paper
La Saga NFC
Nfc developers nokia mit event 12 13 10
Near Field Communication on iPhone with iCarte
Mobile-based NFC fare collection
ACR128 product presentation by Advanced Card Systems Ltd.
Mifare cards
ACR122L VisualVantage Serial NFC Reader with LCD
Ad

Similar to NXP MIFARE Webinar: Secure Closed Loop Payments In An Open Environment (20)

PDF
UFF Tech 2013 - NFC e o futuro da convergência - NXP
PDF
Transaction MAC Feature
PDF
Security Level 3 (SL3) Capabilities
PDF
Embedded System Security: Learning from Banking and Payment Industry
PPT
Introduction to SmartCards - Michael Perlov
PDF
What is A Smart Card
PDF
Smart Cards - Enablers of Electronic Commerce_DeloitteConsultingVS1998
PPS
Nab
PPT
Introduction to Acquirer Systems
PDF
Socket presentation 2014
PPTX
Micro Finance with Smart Card
PPTX
Smart card ppt
PPTX
Session 2.4 - Integrated Transport
PPTX
Paynet systems & Credit Card Processing
PDF
Card payment evolution v1.0
PDF
Pay Shield9000 Vs Hsm8000 Compet V7
PDF
Empowering smes with mobile payment
PPT
Security's Once and Future King
PDF
10 Steps To Secure and PCI Compliant Credit Card Processing In Oracle Receiva...
PDF
First Data Trans Armor
UFF Tech 2013 - NFC e o futuro da convergência - NXP
Transaction MAC Feature
Security Level 3 (SL3) Capabilities
Embedded System Security: Learning from Banking and Payment Industry
Introduction to SmartCards - Michael Perlov
What is A Smart Card
Smart Cards - Enablers of Electronic Commerce_DeloitteConsultingVS1998
Nab
Introduction to Acquirer Systems
Socket presentation 2014
Micro Finance with Smart Card
Smart card ppt
Session 2.4 - Integrated Transport
Paynet systems & Credit Card Processing
Card payment evolution v1.0
Pay Shield9000 Vs Hsm8000 Compet V7
Empowering smes with mobile payment
Security's Once and Future King
10 Steps To Secure and PCI Compliant Credit Card Processing In Oracle Receiva...
First Data Trans Armor

Recently uploaded (20)

PDF
NewMind AI Weekly Chronicles - August'25-Week II
PDF
Enhancing emotion recognition model for a student engagement use case through...
PDF
Accuracy of neural networks in brain wave diagnosis of schizophrenia
PPTX
A Presentation on Artificial Intelligence
PDF
Getting Started with Data Integration: FME Form 101
PDF
Mushroom cultivation and it's methods.pdf
PPTX
OMC Textile Division Presentation 2021.pptx
PPTX
A Presentation on Touch Screen Technology
PDF
MIND Revenue Release Quarter 2 2025 Press Release
PPTX
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
PDF
project resource management chapter-09.pdf
PDF
Agricultural_Statistics_at_a_Glance_2022_0.pdf
PDF
A comparative analysis of optical character recognition models for extracting...
PDF
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
PPTX
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
PDF
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
PDF
Hybrid model detection and classification of lung cancer
PPTX
Tartificialntelligence_presentation.pptx
PDF
Heart disease approach using modified random forest and particle swarm optimi...
PPTX
SOPHOS-XG Firewall Administrator PPT.pptx
NewMind AI Weekly Chronicles - August'25-Week II
Enhancing emotion recognition model for a student engagement use case through...
Accuracy of neural networks in brain wave diagnosis of schizophrenia
A Presentation on Artificial Intelligence
Getting Started with Data Integration: FME Form 101
Mushroom cultivation and it's methods.pdf
OMC Textile Division Presentation 2021.pptx
A Presentation on Touch Screen Technology
MIND Revenue Release Quarter 2 2025 Press Release
KOM of Painting work and Equipment Insulation REV00 update 25-dec.pptx
project resource management chapter-09.pdf
Agricultural_Statistics_at_a_Glance_2022_0.pdf
A comparative analysis of optical character recognition models for extracting...
Microsoft Solutions Partner Drive Digital Transformation with D365.pdf
TechTalks-8-2019-Service-Management-ITIL-Refresh-ITIL-4-Framework-Supports-Ou...
Video forgery: An extensive analysis of inter-and intra-frame manipulation al...
Hybrid model detection and classification of lung cancer
Tartificialntelligence_presentation.pptx
Heart disease approach using modified random forest and particle swarm optimi...
SOPHOS-XG Firewall Administrator PPT.pptx

NXP MIFARE Webinar: Secure Closed Loop Payments In An Open Environment

  • 1. EXTERNAL USE JOHANNES GRÜLL JUNE 22ND, 2016 PRESENT IMPROVED - FUTURE INSIDE SECURE CLOSED LOOP PAYMENTS IN AN OPEN ENVIRONMENT
  • 2. • Diners Club first contemporary credit card in the 1950’s • Convenient way to pay for goods & services without cash • Convenient use across multiple vendors • Started as piece of cardboard with signature • Evolved to complex payment scheme’s like EMV • Transaction fees • Liability shifts Challenges From Cardboard to Multi-party Payment Solutions June 22, 20162.
  • 3. Agenda 1. Adding value to access credentials 2. Trust & guarding against fraud 3. Practical implementation • MIFARE DESFire EV2 • MIFARE Plus EV1
  • 4. • Secure your smartcard a slot in your customer’s wallet • Increase personal value of card to customers • Increased self service possibilities • Increased customer & brand engagement • Common Criteria based platforms allow to run own payment solutions • Receive cash in advance • Minimize cash handling cost • Power own incentive schemes towards customers & partners Closed-loop Micropayment Increasing Value of Credentials June 22, 20164.
  • 5. Micropayment in Single-vendor vendor systems June 22, 20165. Vendor Locations Vendor/ Card Issuer End User Card loadingSpending money
  • 6. Demand for Multi-vendor Systems June 22, 20166. How can I attract additional customers? Service Providers Card Issuer End User I want convenient access with 1 credential only I want to increase the value of my card to end users
  • 7. Micropayment in Multi-vendor systems - Challenge June 22, 20167. Service Providers Card Issuer End User 1. 2. Purchase 3. Multiple challenges in claiming and re- imbursing within the application provider eco-system arise
  • 8. • Traceability of Transactions • Common Criteria certified solutions securing wallets • New smartcard features securing and proofing transactions • Authenticity of Transactions • Tax regulations • Cash register • Privacy of individual data • End user • Service providers sales data • Quick & reliable re-imbursement • Automated • Scalable • Protecting individual application providers sales data Challenges in multi-vendor systems Shared Wallet Applications June 22, 20168.
  • 9. Use Cases: Campus Card Cashless Campus as Eco-system June 22, 20169. • On-Campus Services • Payment (vending machines, copying machines,…) • Student self-service (registering, printing documents,..) • Off-Campus Eco-system integration • Public transport linking university sites • Restaurants • Cafes • New Value Streams • Co-promotion • Fee based model • Dedication of stipendiums • Requirement: Scalable & future proof platforms
  • 10. MIFARE Plus® generation benefits MIFARE Plus® EV1 June 22, 2016 MIFARE Plus S MIFARE Plus SE MIFARE Plus X MIFARE Plus EV1 RF Interface P rotocol UID – unique identifier Communication speed M emory size [Byte] 2KB 1KB 2KB 2KB 4KB 4KB 4KB M emory M odel Crypto Key Length Authentication Communication, S ecurity T ransaction M AC yes P roximity Check yes V irtual Card S elect CC Certification EAL4+ no EAL4+ EAL5+ IS O 7816-4 AP DU yes NFC compliance T arget applications Input capacitance 17pF 17pF 17pF 17pF or 70pF S ecure NFC channel in SL1& SL3 M ulti applications yes NFC capabilities in SL3 Public transport / Campus cards / Access management Compact, Sectors & 16- byte block Crypto- 1, AES 48- bit crypto- 1, 128- bit AES 3- pass mutual CMACed MIFARE Plus ISO/IEC 14443- 2, type A ISO/IEC 14443- 3&4 7- byte UID, 4- byte NUID, RID 106- 848 Kbps in SL3 level Supported via MAD no no no 1994 MIFARE Classic 2009 MIFARE Plus 06/2015 MIFARE Plus SE 04/2016 MIFARE Plus EV1
  • 11. MIFARE DESFire® generation benefits MIFARE DESFire® EV2 June 22, 201611. 2002 MIFARE DESFire 2008 MIFARE DESFire EV1 2015 MIFARE DESFire EV1 256B 2016 MIFARE DESFire EV2 MIFARE DESFire EV1 MIFARE DESFire EV2 ISO/IEC 14443 A 1-4   ISO/IEC 7816-4 support extended extended EEPROM data memory 2/4/8KB 2/4/8KB Flexible file structure   NFC Forum Tag Type 4   Secure, high-speed cmd   Unique ID 7BUID or 4B RID 7BUID or 4B RID Number of applications 28 unlimited Number of files per app 32 32 High data rates support up to 848 Kbit/s up to 848 Kbit/s Crypto algorithms support DES/2K3DES/ 3K3DES/AES DES/2K3DES/ 3K3DES/AES CC certification (HW + SW) EAL 4+ EAL 5+ MIsmartApp feature -  Transaction MAC per app -  Multiple keysets per app - Up to 16 keysets Multiple file access rights - Up to 8 keys Inter-app files sharing -  Virtual Card Architecture -  Proximity Check -  Delivery types Wafer, MOA4 & MOA8 Wafer, MOA4 & MOB6
  • 12. TransactionMAC Securing your money in a shared economy June 22, 201612. • MAC calculated over the data of a whole transaction • Prove of card presence • Counters to eliminate replay attempts • Possibility to integrate reader ID to allocate transaction to specific service provider • Detect missing transactions
  • 13. TransactionMAC in Multi-vendor Systems June 22, 201613. Service Providers Clearing House TMAC keys shared by card and clearing house TMAC‘s sent to clearing house Re-imbursement after clearing
  • 14. Thank you Visit us at http://MIFARE.net Follow us: https://twitter.com/nxp_mifare https://at.linkedin.com/in/nxpmifarewww.youtube.com/user/nxpsemiconductorshttp://blog.nxp.com/ https://www.facebook.com/nxpsemi
  • 15. Q&A
  • 16. Webinar Series Outlook Date Title May 24th 2016 MIFARE Innovation Roadmap – present improved, future inside June 1st 2016 How to protect contactless systems today and tomorrow June 8th 2016 Enhanced user experience through active application management June 15th 2016 Streamlined user management for multi-vendor installations June 22nd 2016 Secure closed loop payments in an open environment June 29th 2016 Introduce the future in your today’s system – how to ensure smooth system upgrades July 6th 2016 Added value to card based environments through NFC and cloud – when IoT becomes reality July 13th 2016 Complement use cases with mobiles and wearables