SlideShare a Scribd company logo
T r u s t t h e E x p e r t s
WHAT TO EXPECT FROM A
MOBILE BANKING SOLUTION
INTRODUCTION
Mobile Banking (M-Banking) involves using
mobile devices to gain access to financial
services.
A large number of mobile banking and
payment solutions are available in the market
catering to various needs of the financial
institutions. The key to successful
implementation is the selection of a software
vendor who would be responsible for
providing solutions to meet the organization’s
requirement and to ensure the key principles
of a good mobile banking solution.BASIC PRINCIPLES OF THE
PLATFORM
Interoperability
Inclusive Implementation
•Available to All
• Delivered to All
• Accessible by all
Security and Privacy
Openness
Flexibility and Scalability
Device Agnosticism
WHITE PAPER
T r u s t t h e E x p e r t s
FUNCTIONAL VIEW OF THE PLATFORM
Legend: NFC: Near Field Communication, SMS: Short Messaging Service, USSD: GSM’s Unstructured Supplementary
Services Data, IVR: Interactive Voice Response
UNIFIED COMMUNICATION MODULE
Unified Communication Module (UCM) acts as an
interface between the various channels and the rest of
the mobile banking platform. The UCM should
communicate with the Telco’s service agents, clients,
devices, applications and portals indicated at a* using
the protocols supported by the various applications.
UCM should be developed to also cater to any future
message-format, channel or device. Future proofing is of
paramount importance and the UCM should support at a
bare minimum, the protocols at b*, The UCM should
TGSLWP - WHITE PAPER 2
a*} SMSC: Short Message Service Center, SMS Aggregator, MMS: Multi
Messaging Service, IVR Server, ATM, Micro ATM, Smart Client application
and Mobile Web portal
b*} SMPP: Short Message Peer to Peer, UCP: Universal Computer Protocol
(a subset of which is EMI or External Machine Interface), HTTP: Hyper Text
Transfer Protocol, HTTPS: HTTP Secure protocol, ISO 8583 and Web
Services protocols such as SOAP: Simple Object Access Protocol and,
REST: Representational State Transfer
have minimum logic and should transfer the incoming
message to the appropriate mobile banking module
using a common interface protocol defined by the
applications. After verifying the data, the UCM may
interface with other modules for
verification/authentication of the message before
passing it on to the next module for further processing.
Similarly all the outgoing messages need to pass through
the UCM; with the UCM translating the message to the
appropriate format before sending it to the mobile device.
WHITE PAPER
TGSLWP - WHITE PAPER 3
INTEROPERABILITY IN SUPPORTED
CHANNELS
In supporting multiple channels it would be important to
ensure the following: -
• Support for Push SMS, Pull SMS, USSD, IVR, Mobile
Web, Smart Client, SIM/WIB based application, NFC,
Mobile as a POS, Outbound dialer (important in areas
where voice confirmation may be preferred over SMS
due to literacy issues), ATM and Mobile Point of Service
(Mobile POS)
• Seamless migration from one channel to another.
• Need for just one-time registration by the user,
irrespective of the channel used.
• Ability of the channel management & communication
module to recognize the transacting channel and
respond appropriately
SMS aggregation service is typically provided by the
SMS Aggregator; hence banks will need to enter into a
techno-commercial relationship with the SMS aggregator
to get a short/long code and also to provide service to
customers of all the telecom providers in the
region/country.
• The SMS based implementation is predominantly
used for pushing the information to the individual user
or business upon occurrence of certain events such as
a purchase, funds-transfer or deposit.
• Instead of opting for a short code (which works across
all the Telcos), a bank may opt for a long code from a
particular Telco.
USSD service requires direct connectivity with the
Telecom operator; hence banks need to have direct
techno-commercial technical relationship with the Telco.
SIM card based applications needs a relationship with
the telecom operator.
IVR & Outbound Dialer services could be implemented
independent of telecom relationship. The service
providers can provide and deploy a self managed
solution at the Bank’s premises. IVR also provides the
option of enabling solutions in local languages.
AUTHENTICATION/SECURITY
When it comes to authentication of the user and data
security, the Platform: -
• Needs to accept Static Passwords, One Time
Passwords, Biometrics, usernames/passwords and
additional profile questions depending on the type of
activity
• Should be able to accept the Mobile # or Device ID to
authenticate the user
• Should ensure authentication across multiple
channels
• Should be able to support HSM based AES, 3DES
encryption, 1024 bit or higher PKI implementation
(HSM: Hardware Security Module, aka Host Security
Module, AES: Advanced Encryption Standard), 3DES:
Triple Data Encryption Standard, PKI: Public
Key Infrastructure
• Should be able to store encrypted data with the ability
to decrypt it after authentication
• Should have adequate security features to securely
store the data in the device
T r u s t t h e E x p e r t s
• Ability to configure & manage one or more channels for
one or more services
ECO-SYSTEM DEPENDENCY IN
IMPLEMENTING
CHANNELS
In countries, with wide, reliable and
affordable data connectivity, banks are
recommended to use Smart Client or
Mobile Web (WAP and HTML5) as the
channel to implement mobile banking
services without having to depend on
the telecom operator.
ECO-SYSTEM DEPENDENCY IN MOBILE
DEVICES AND OPERATING SYSTEMS
Internationally, there are a large number of mobile devices
available. The features, functionality and operating
systems being supported varies from device to device.
Brand loyalty varies from country to country and within a
country from region to region with a direct impact on the
mobile banking system.
Some of the popular devices are:
Apple’s iPhone running iOS
Samsung, Sony, LG, MTS and Motorola phones
running the Android OS
RIM phones running the Blackberry OS.
Nokia phones running the Symbian OS
Smart phones running the Windows mobile OS
The solution needs to support the most popular device
families in the country. In other words, the bank needs to
make sure that their mobile banking application (smart
client apps) as well as Mobile Web (invoked from the
browser) are compatible with and are certified on the most
widely used mobile devices.
WHITE PAPER
TGSLWP - WHITE PAPER 4
In short the role of the MDM is extremely important in effective deployment of the mobile banking service to
employees, businesses and marquee customers
The MDM Platform needs to take care of the following scenarios at the bare minimum
• Lost Device.
• Unauthorized access to device or application.
• Inappropriate use of the device or application.
• Change in the employee/business/agency status (transfer, termination, change of
responsibility within department etc).
• Changes in the procedures and regulations.
The high level system flow and role of MDM is shown below
The features of MDM should be implemented to: -
• Uniquely identify the device assigned to an employee,
consumer or business.
• Assign business functions and data access based on
the delegation model.
• Encrypt the information stored in the device even
during transit.
• Provide secure access to the application.
• Remotely locate the device.
• Identify abnormal use of the application.
• Prevent use by unauthorized persons - by way of
secure access, location control, usage control etc.
• Remotely erase the data from the device in case of
‘lost device’ or inappropriate or suspicious usage of
the device or application.
• Remotely lock the application/device from any use.
• Ensure a comprehensive anti-virus policy
The conditions relating to data-access and
data-modification will need to be implemented by the
individual departments by providing appropriate
Application Programme Interfaces (APIs), user level
data-access controls and logging/auditing mechanisms.
T r u s t t h e E x p e r t s
MOBILE DEVICE MANAGEMENT (MDM)
The MDM software secures monitors, manages and
supports mobile devices deployed across mobile
operators, service providers and enterprises. MDM
functionality typically includes over-the-air distribution of
applications, data and configuration settings for all types of
mobile devices, including mobile phones, Smartphones,
Tablet computers, ruggedized mobile computers, mobile
printers, mobile POS devices, etc. This applies to both
company-owned and employee-owned (BYOD) devices
across the enterprise or mobile devices owned by
consumers.
By controlling and protecting the data and configuration
settings for all mobile devices in the network, MDM can
reduce support costs and business risks. The intent of
MDM is to optimize the functionality and security of a
mobile communications network while minimizing cost and
downtime.
Unified
Communication Layer
Transaction
Management
Security Management
Check user credentials
Device Management
Check Device profile, user role, and
permissions (location, time restrictions)
WHITE PAPER
TGSLWP - WHITE PAPER 5
B2C (Retail Banking)
• Informational Banking (mini statement, stop cheque,
account balance, activity on account)
• Payment – bill payment, P2P transfer (inter and
intra bank)
• Credit card payment, loading prepaid card with
additional currency/funds
• Time Deposit/Fixed Deposit facility on mobile
• ATM Locator – GPS & Map integration
• Branch Locator – GPS & Map Integration
• Apply for Demand Draft/Traveler’s
Cheque/Manager’s Cheque
• Various Statement in PDF, SMS or other formats
supported on mobile channels
• In application / Out of application notifications or alerts
SERVICES (Features and Functions)
Disclaimer: All the documentation and other material contained herein is the property of Thinksoft Global Services and all intellectual
property rights in and to the same are owned by Thinksoft Global Services. You shall not, unless previously authorized by Thinksoft
Global Services in writing, copy, reproduce, market, license, lease or in any other way, dispose of, or utilize for profit, or exercise any
ownership rights over the same. In no event, unless required by applicable law or agreed to in writing, shall Thinksoft Global Services,
or any person be liable for any loss, expense or damage, of any type or nature arising out of the use of, or inability to use any material
contained herein. Any such material is provided “as is”, without warranty of any type or nature, either express or implied. All names,
logos are used for identification purposes only and are trademarks or registered trademarks of their respective companies.
For more details visit, www.thinksoftglobal.com
T r u s t t h e E x p e r t s
PAYMENT SUPPORT
The platform should integrate with core banking, the
card management system and the prepaid system of the
bank to enable all possible payment and banking options
to customers.
INTEGRATION SUPPORT
The mobile banking platform should have a well defined
integration layer for the platform to enroll more
merchants (billers, over the counter merchants, other
banking systems etc). The platform should have been
developed using an open standard. A well defined Web
Services API needs to be enabled for ease of integration
and faster deployment.
T r u s t t h e E x p e r t s
FRAUD MANAGEMENT
Detecting and preventing fraudulent activities is a key
component of the mobile services platform. The platform
should have the ability to integrate with existing fraud
engines, define fraud rules, generate alerts and have the
ability to either automatically block or provide the process
for administrators to review and block any type of
activity/users from transacting on the system. Detailed and
summarized reporting of the suspicious activities, reporting
of improvements due to implementation of various rules
and the analysis of patterns based on various parameters
are integral part of the fraud management module.
Key features –
• Fraud Prevention – Customer Education, Product
Security (PIN, OTP, BIOMETRIC, Additional Factors –
like profile questions, Device Characteristics mapping,
M# verification)
• Activity alerting – in-apps/out-of-apps (SMS / Call center
call to verify activity)
• Detection of Fraud – transaction (txn) pattern (value or #
of txns, specific type of txn) - look for anomalous
behavior
• Resolution of Fraud– Customer Support, Channel
Specific Fraud & fixing issues specific to channel, legal
mechanism (zero-liability, breach of security due to s/w
mal-function, inadequacies)
USABILITY
• Device specific rendering
• Detection of device modes (portrait Vs landscape or
vertical or horizontal mode), Touch Vs Non-touch device
• Use of device features – for example use of GPS to
locate ATM locator in the GPS enabled devices
• Ability to inherit display characteristics of the device
• Personalization to configure alerts/ notifications,
configure service list
• Support for QR code based activity
• QR code on website or in the email, mailer indicating
download URL for apps
• QR code with bill information when scanned can
pre-fill the bill payment information for the customer
• Advanced Market Information
• Allow Securities transactions
B2B (Bank to other businesses)
• Payment to businesses
• Account Details
• Approval – within bank or approval by businesses
(including approval hierarchy support)
WHITE PAPER

More Related Content

PPTX
Computer's project
PPTX
OmniSource_ppt_2011_7-2 (2)(1)
PDF
Mobile Banking – A Transformation of Traditional Banking
PPTX
Wireless Banking
PDF
CellSIM OS Overview 1.0
PPT
Securing Wireless Cellular Systems
PDF
Mobility & Security Technology Risk Considerations
Computer's project
OmniSource_ppt_2011_7-2 (2)(1)
Mobile Banking – A Transformation of Traditional Banking
Wireless Banking
CellSIM OS Overview 1.0
Securing Wireless Cellular Systems
Mobility & Security Technology Risk Considerations

What's hot (20)

PPT
Ec2009 ch08 mobile commerce and pervasive computing
PDF
Mobile technology-Unit 1
PDF
Gemalto Le Mobile 2.0 Edition 2009
PPTX
What UICC Means for NFC & Security
PPTX
Intel_Intelligent Solutions for Military and Aerospace
PDF
CIO Guide To Mobile Recording
PDF
Mobile banking
PDF
Mtel Cash Mobile Commerce Suite
PDF
Retail Banking: Making other Channels mobile
PDF
Mobile Financial Services
PPTX
Next Generation Networks for Contactless and Mobile Ticketing
PDF
Rcs ts.com 14 8-2012
PPTX
Voxeo Summit Day 2 - Securing customer interactions
PDF
M2M Stategy of the Open Mobile Alliance - Fraunhofer FUSECO Forum 2011
PPT
Antique_Bank_Smart_Systems__PPT
PPTX
Cidway Bank Finance 01 2009 2 Fa Tr
PDF
Accessing pay buy mobile model
PDF
Mobile based authentication and payment
PDF
MRV Leaflet English
PPTX
mobile payment in india operative guidelines for
Ec2009 ch08 mobile commerce and pervasive computing
Mobile technology-Unit 1
Gemalto Le Mobile 2.0 Edition 2009
What UICC Means for NFC & Security
Intel_Intelligent Solutions for Military and Aerospace
CIO Guide To Mobile Recording
Mobile banking
Mtel Cash Mobile Commerce Suite
Retail Banking: Making other Channels mobile
Mobile Financial Services
Next Generation Networks for Contactless and Mobile Ticketing
Rcs ts.com 14 8-2012
Voxeo Summit Day 2 - Securing customer interactions
M2M Stategy of the Open Mobile Alliance - Fraunhofer FUSECO Forum 2011
Antique_Bank_Smart_Systems__PPT
Cidway Bank Finance 01 2009 2 Fa Tr
Accessing pay buy mobile model
Mobile based authentication and payment
MRV Leaflet English
mobile payment in india operative guidelines for
Ad

Viewers also liked (8)

PPTX
Why Outsource? HHJR Consulting
PDF
Directional Advertising - ©2013 Best Media
PDF
インプリハック・リベンジハック
PDF
Communications Solutions Pubblica Amministrazione
PDF
Meghaduta - Thinksoft Newsletter (October'13)
PDF
ハッカソンてなに?
PDF
River island
Why Outsource? HHJR Consulting
Directional Advertising - ©2013 Best Media
インプリハック・リベンジハック
Communications Solutions Pubblica Amministrazione
Meghaduta - Thinksoft Newsletter (October'13)
ハッカソンてなに?
River island
Ad

Similar to What to Expect from a Mobile Banking Solution? (Whitepaper) (20)

PPT
Ultimate company
PDF
Inter connect2015 ame-3495
PDF
ISACA Mobile Payments Forum presentation
PPSX
MobiWeb - OTP SMS Two Factor Authentication
PPT
Mobile Money Business Track: understanding the Model and Market
PPSX
MobiWeb - SMS Banking
PDF
otp-sms-two-factor-authentication
PDF
PDF
Introduction to IBM MessageSight - IMPACT 2014
PDF
Introduction to IBM MessageSight
PPTX
M commerce
PDF
Temenos_Connect_Mobile_Banking_Overview
PPTX
Final ppt
PPTX
Introduction to MessageSight - gateway to the internet of things and mobile m...
PPT
Changing Your Enterprise Architecture - Mobile is Not an Add-On
PDF
mobile wallet software solution providers.pdf
PPTX
MIS 11 M-Commerce
PPT
Cmsc666 Mc
PDF
Managing & Securing the Online and Mobile banking - Chew Chee Seng
PPTX
Future of m commerce
Ultimate company
Inter connect2015 ame-3495
ISACA Mobile Payments Forum presentation
MobiWeb - OTP SMS Two Factor Authentication
Mobile Money Business Track: understanding the Model and Market
MobiWeb - SMS Banking
otp-sms-two-factor-authentication
Introduction to IBM MessageSight - IMPACT 2014
Introduction to IBM MessageSight
M commerce
Temenos_Connect_Mobile_Banking_Overview
Final ppt
Introduction to MessageSight - gateway to the internet of things and mobile m...
Changing Your Enterprise Architecture - Mobile is Not an Add-On
mobile wallet software solution providers.pdf
MIS 11 M-Commerce
Cmsc666 Mc
Managing & Securing the Online and Mobile banking - Chew Chee Seng
Future of m commerce

More from Thinksoft Global (20)

PDF
Faximmé - Financial Transaction Simulator
PDF
Mobile payments test automation
PDF
Banking on Thinksoft
PDF
Funds Transfer Pricing
PDF
Payments Testing @ Thinksoft
PDF
Case Study Atom Revitilization
PDF
Integration of supply chain management_Gulf Sabah Bank
PDF
No Choice But to Comply - FATCA
PDF
Capital Markets
PDF
UAT for a Major US Banking Conglomerate
PDF
Cards Performance Testing (Whitepaper)
PDF
ATM Outsourcing in India and Global Trends (Whitepaper)
PDF
UAT - Cards Migration (Whitepaper)
PDF
Solvency II Offering
PDF
Secure your Treasures
PDF
Performance Testing
PDF
General Insurance
PDF
Casualty Insurance
PDF
Global Insurance
PDF
Global Insurance (Case Study)
Faximmé - Financial Transaction Simulator
Mobile payments test automation
Banking on Thinksoft
Funds Transfer Pricing
Payments Testing @ Thinksoft
Case Study Atom Revitilization
Integration of supply chain management_Gulf Sabah Bank
No Choice But to Comply - FATCA
Capital Markets
UAT for a Major US Banking Conglomerate
Cards Performance Testing (Whitepaper)
ATM Outsourcing in India and Global Trends (Whitepaper)
UAT - Cards Migration (Whitepaper)
Solvency II Offering
Secure your Treasures
Performance Testing
General Insurance
Casualty Insurance
Global Insurance
Global Insurance (Case Study)

Recently uploaded (20)

PDF
Building Integrated photovoltaic BIPV_UPV.pdf
PDF
Spectral efficient network and resource selection model in 5G networks
PPTX
A Presentation on Artificial Intelligence
PDF
KodekX | Application Modernization Development
PDF
Encapsulation theory and applications.pdf
PPTX
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
PDF
Network Security Unit 5.pdf for BCA BBA.
PPTX
Understanding_Digital_Forensics_Presentation.pptx
PPTX
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
PDF
cuic standard and advanced reporting.pdf
PPT
Teaching material agriculture food technology
PDF
Mobile App Security Testing_ A Comprehensive Guide.pdf
PDF
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PPTX
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
PDF
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
PDF
Encapsulation_ Review paper, used for researhc scholars
PDF
Advanced methodologies resolving dimensionality complications for autism neur...
PPTX
Cloud computing and distributed systems.
PDF
The Rise and Fall of 3GPP – Time for a Sabbatical?
PPTX
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx
Building Integrated photovoltaic BIPV_UPV.pdf
Spectral efficient network and resource selection model in 5G networks
A Presentation on Artificial Intelligence
KodekX | Application Modernization Development
Encapsulation theory and applications.pdf
Detection-First SIEM: Rule Types, Dashboards, and Threat-Informed Strategy
Network Security Unit 5.pdf for BCA BBA.
Understanding_Digital_Forensics_Presentation.pptx
Effective Security Operations Center (SOC) A Modern, Strategic, and Threat-In...
cuic standard and advanced reporting.pdf
Teaching material agriculture food technology
Mobile App Security Testing_ A Comprehensive Guide.pdf
Shreyas Phanse Resume: Experienced Backend Engineer | Java • Spring Boot • Ka...
PA Analog/Digital System: The Backbone of Modern Surveillance and Communication
Peak of Data & AI Encore- AI for Metadata and Smarter Workflows
Encapsulation_ Review paper, used for researhc scholars
Advanced methodologies resolving dimensionality complications for autism neur...
Cloud computing and distributed systems.
The Rise and Fall of 3GPP – Time for a Sabbatical?
VMware vSphere Foundation How to Sell Presentation-Ver1.4-2-14-2024.pptx

What to Expect from a Mobile Banking Solution? (Whitepaper)

  • 1. T r u s t t h e E x p e r t s WHAT TO EXPECT FROM A MOBILE BANKING SOLUTION INTRODUCTION Mobile Banking (M-Banking) involves using mobile devices to gain access to financial services. A large number of mobile banking and payment solutions are available in the market catering to various needs of the financial institutions. The key to successful implementation is the selection of a software vendor who would be responsible for providing solutions to meet the organization’s requirement and to ensure the key principles of a good mobile banking solution.BASIC PRINCIPLES OF THE PLATFORM Interoperability Inclusive Implementation •Available to All • Delivered to All • Accessible by all Security and Privacy Openness Flexibility and Scalability Device Agnosticism WHITE PAPER
  • 2. T r u s t t h e E x p e r t s FUNCTIONAL VIEW OF THE PLATFORM Legend: NFC: Near Field Communication, SMS: Short Messaging Service, USSD: GSM’s Unstructured Supplementary Services Data, IVR: Interactive Voice Response UNIFIED COMMUNICATION MODULE Unified Communication Module (UCM) acts as an interface between the various channels and the rest of the mobile banking platform. The UCM should communicate with the Telco’s service agents, clients, devices, applications and portals indicated at a* using the protocols supported by the various applications. UCM should be developed to also cater to any future message-format, channel or device. Future proofing is of paramount importance and the UCM should support at a bare minimum, the protocols at b*, The UCM should TGSLWP - WHITE PAPER 2 a*} SMSC: Short Message Service Center, SMS Aggregator, MMS: Multi Messaging Service, IVR Server, ATM, Micro ATM, Smart Client application and Mobile Web portal b*} SMPP: Short Message Peer to Peer, UCP: Universal Computer Protocol (a subset of which is EMI or External Machine Interface), HTTP: Hyper Text Transfer Protocol, HTTPS: HTTP Secure protocol, ISO 8583 and Web Services protocols such as SOAP: Simple Object Access Protocol and, REST: Representational State Transfer have minimum logic and should transfer the incoming message to the appropriate mobile banking module using a common interface protocol defined by the applications. After verifying the data, the UCM may interface with other modules for verification/authentication of the message before passing it on to the next module for further processing. Similarly all the outgoing messages need to pass through the UCM; with the UCM translating the message to the appropriate format before sending it to the mobile device. WHITE PAPER
  • 3. TGSLWP - WHITE PAPER 3 INTEROPERABILITY IN SUPPORTED CHANNELS In supporting multiple channels it would be important to ensure the following: - • Support for Push SMS, Pull SMS, USSD, IVR, Mobile Web, Smart Client, SIM/WIB based application, NFC, Mobile as a POS, Outbound dialer (important in areas where voice confirmation may be preferred over SMS due to literacy issues), ATM and Mobile Point of Service (Mobile POS) • Seamless migration from one channel to another. • Need for just one-time registration by the user, irrespective of the channel used. • Ability of the channel management & communication module to recognize the transacting channel and respond appropriately SMS aggregation service is typically provided by the SMS Aggregator; hence banks will need to enter into a techno-commercial relationship with the SMS aggregator to get a short/long code and also to provide service to customers of all the telecom providers in the region/country. • The SMS based implementation is predominantly used for pushing the information to the individual user or business upon occurrence of certain events such as a purchase, funds-transfer or deposit. • Instead of opting for a short code (which works across all the Telcos), a bank may opt for a long code from a particular Telco. USSD service requires direct connectivity with the Telecom operator; hence banks need to have direct techno-commercial technical relationship with the Telco. SIM card based applications needs a relationship with the telecom operator. IVR & Outbound Dialer services could be implemented independent of telecom relationship. The service providers can provide and deploy a self managed solution at the Bank’s premises. IVR also provides the option of enabling solutions in local languages. AUTHENTICATION/SECURITY When it comes to authentication of the user and data security, the Platform: - • Needs to accept Static Passwords, One Time Passwords, Biometrics, usernames/passwords and additional profile questions depending on the type of activity • Should be able to accept the Mobile # or Device ID to authenticate the user • Should ensure authentication across multiple channels • Should be able to support HSM based AES, 3DES encryption, 1024 bit or higher PKI implementation (HSM: Hardware Security Module, aka Host Security Module, AES: Advanced Encryption Standard), 3DES: Triple Data Encryption Standard, PKI: Public Key Infrastructure • Should be able to store encrypted data with the ability to decrypt it after authentication • Should have adequate security features to securely store the data in the device T r u s t t h e E x p e r t s • Ability to configure & manage one or more channels for one or more services ECO-SYSTEM DEPENDENCY IN IMPLEMENTING CHANNELS In countries, with wide, reliable and affordable data connectivity, banks are recommended to use Smart Client or Mobile Web (WAP and HTML5) as the channel to implement mobile banking services without having to depend on the telecom operator. ECO-SYSTEM DEPENDENCY IN MOBILE DEVICES AND OPERATING SYSTEMS Internationally, there are a large number of mobile devices available. The features, functionality and operating systems being supported varies from device to device. Brand loyalty varies from country to country and within a country from region to region with a direct impact on the mobile banking system. Some of the popular devices are: Apple’s iPhone running iOS Samsung, Sony, LG, MTS and Motorola phones running the Android OS RIM phones running the Blackberry OS. Nokia phones running the Symbian OS Smart phones running the Windows mobile OS The solution needs to support the most popular device families in the country. In other words, the bank needs to make sure that their mobile banking application (smart client apps) as well as Mobile Web (invoked from the browser) are compatible with and are certified on the most widely used mobile devices. WHITE PAPER
  • 4. TGSLWP - WHITE PAPER 4 In short the role of the MDM is extremely important in effective deployment of the mobile banking service to employees, businesses and marquee customers The MDM Platform needs to take care of the following scenarios at the bare minimum • Lost Device. • Unauthorized access to device or application. • Inappropriate use of the device or application. • Change in the employee/business/agency status (transfer, termination, change of responsibility within department etc). • Changes in the procedures and regulations. The high level system flow and role of MDM is shown below The features of MDM should be implemented to: - • Uniquely identify the device assigned to an employee, consumer or business. • Assign business functions and data access based on the delegation model. • Encrypt the information stored in the device even during transit. • Provide secure access to the application. • Remotely locate the device. • Identify abnormal use of the application. • Prevent use by unauthorized persons - by way of secure access, location control, usage control etc. • Remotely erase the data from the device in case of ‘lost device’ or inappropriate or suspicious usage of the device or application. • Remotely lock the application/device from any use. • Ensure a comprehensive anti-virus policy The conditions relating to data-access and data-modification will need to be implemented by the individual departments by providing appropriate Application Programme Interfaces (APIs), user level data-access controls and logging/auditing mechanisms. T r u s t t h e E x p e r t s MOBILE DEVICE MANAGEMENT (MDM) The MDM software secures monitors, manages and supports mobile devices deployed across mobile operators, service providers and enterprises. MDM functionality typically includes over-the-air distribution of applications, data and configuration settings for all types of mobile devices, including mobile phones, Smartphones, Tablet computers, ruggedized mobile computers, mobile printers, mobile POS devices, etc. This applies to both company-owned and employee-owned (BYOD) devices across the enterprise or mobile devices owned by consumers. By controlling and protecting the data and configuration settings for all mobile devices in the network, MDM can reduce support costs and business risks. The intent of MDM is to optimize the functionality and security of a mobile communications network while minimizing cost and downtime. Unified Communication Layer Transaction Management Security Management Check user credentials Device Management Check Device profile, user role, and permissions (location, time restrictions) WHITE PAPER
  • 5. TGSLWP - WHITE PAPER 5 B2C (Retail Banking) • Informational Banking (mini statement, stop cheque, account balance, activity on account) • Payment – bill payment, P2P transfer (inter and intra bank) • Credit card payment, loading prepaid card with additional currency/funds • Time Deposit/Fixed Deposit facility on mobile • ATM Locator – GPS & Map integration • Branch Locator – GPS & Map Integration • Apply for Demand Draft/Traveler’s Cheque/Manager’s Cheque • Various Statement in PDF, SMS or other formats supported on mobile channels • In application / Out of application notifications or alerts SERVICES (Features and Functions) Disclaimer: All the documentation and other material contained herein is the property of Thinksoft Global Services and all intellectual property rights in and to the same are owned by Thinksoft Global Services. You shall not, unless previously authorized by Thinksoft Global Services in writing, copy, reproduce, market, license, lease or in any other way, dispose of, or utilize for profit, or exercise any ownership rights over the same. In no event, unless required by applicable law or agreed to in writing, shall Thinksoft Global Services, or any person be liable for any loss, expense or damage, of any type or nature arising out of the use of, or inability to use any material contained herein. Any such material is provided “as is”, without warranty of any type or nature, either express or implied. All names, logos are used for identification purposes only and are trademarks or registered trademarks of their respective companies. For more details visit, www.thinksoftglobal.com T r u s t t h e E x p e r t s PAYMENT SUPPORT The platform should integrate with core banking, the card management system and the prepaid system of the bank to enable all possible payment and banking options to customers. INTEGRATION SUPPORT The mobile banking platform should have a well defined integration layer for the platform to enroll more merchants (billers, over the counter merchants, other banking systems etc). The platform should have been developed using an open standard. A well defined Web Services API needs to be enabled for ease of integration and faster deployment. T r u s t t h e E x p e r t s FRAUD MANAGEMENT Detecting and preventing fraudulent activities is a key component of the mobile services platform. The platform should have the ability to integrate with existing fraud engines, define fraud rules, generate alerts and have the ability to either automatically block or provide the process for administrators to review and block any type of activity/users from transacting on the system. Detailed and summarized reporting of the suspicious activities, reporting of improvements due to implementation of various rules and the analysis of patterns based on various parameters are integral part of the fraud management module. Key features – • Fraud Prevention – Customer Education, Product Security (PIN, OTP, BIOMETRIC, Additional Factors – like profile questions, Device Characteristics mapping, M# verification) • Activity alerting – in-apps/out-of-apps (SMS / Call center call to verify activity) • Detection of Fraud – transaction (txn) pattern (value or # of txns, specific type of txn) - look for anomalous behavior • Resolution of Fraud– Customer Support, Channel Specific Fraud & fixing issues specific to channel, legal mechanism (zero-liability, breach of security due to s/w mal-function, inadequacies) USABILITY • Device specific rendering • Detection of device modes (portrait Vs landscape or vertical or horizontal mode), Touch Vs Non-touch device • Use of device features – for example use of GPS to locate ATM locator in the GPS enabled devices • Ability to inherit display characteristics of the device • Personalization to configure alerts/ notifications, configure service list • Support for QR code based activity • QR code on website or in the email, mailer indicating download URL for apps • QR code with bill information when scanned can pre-fill the bill payment information for the customer • Advanced Market Information • Allow Securities transactions B2B (Bank to other businesses) • Payment to businesses • Account Details • Approval – within bank or approval by businesses (including approval hierarchy support) WHITE PAPER