EBA欧洲银行-EBA-Public-Hearing-on-SCA-and-CSC-23-September-2016_27页_1mb
报告摘要
EBA Summary on Strong Customer Authentication & Secure Communication (SCA & CSC) under Article 97 PSD2
Core Content
The European Banking Authority (EBA) conducted a public hearing on Strong Customer Authentication (SCA) and Secure Communication (CSC) under Article 97 of the Payment Services Directive 2 (PSD2) on 23 September 2016 in London. The hearing was part of the EBA's process to develop Regulatory Technical Standards (RTS) in line with its mandate under Article 98 of PSD2, which requires the EBA to establish SCA and CSC requirements for payment service providers (PSPs).
Main Objectives of the Public Hearing
- To summarize the EBA's understanding of the relevant PSD2 provisions.
- To present the draft RTS and seek feedback on its content.
- To clarify the exemptions from SCA and the principles underlying the proposed standards.
EBA's Mandates under PSD2
The PSD2 has assigned the EBA 11 mandates, including the development of RTS for SCA and CSC. These mandates are aimed at ensuring secure and authenticated payment transactions while promoting innovation and interoperability across the financial sector.
Key Requirements of the Draft RTS
1. Strong Customer Authentication (SCA) Procedure
- Scope: SCA applies to electronic payments initiated by the payer (e.g., credit transfers, card payments), but not to those initiated by the payee (e.g., direct debits), unless the payee's PSP is involved in the signing of the e-mandate.
- Authentication Elements: Include PSCs, devices, and software used to generate or receive authentication codes.
- Dynamic Linking:
- Authentication code must be specific to the amount and payee.
- OTP can be generated by the payer's PSP with or without payer action.
- The channel used to display transaction details must be independent or segregated from the channel used for initiating the payment.
- Special procedures are outlined for transactions where the amount is not known or for bulk payments.
2. Exemptions from SCA
- Exemptions are specified in the draft RTS and are not mandatory; they are part of the authentication procedures and must be applied by the ASPSP.
- Exemptions for SCA (Article 97(1)):
- Exclusive access to payment account information without disclosure of sensitive data, provided the PSU has not accessed the account within one month after last SCA.
- Contactless payments up to 50 EUR with cumulative non-remote payments up to 150 EUR.
- Exemptions for SCA with dynamic linking (Article 97(2)):
- Credit transfers to trusted beneficiaries.
- Series of credit transfers with the same amount and payee.
- Payments to oneself (same natural or legal person).
- Remote payments up to 10 EUR with cumulative non-SCA remote payments up to 100 EUR.
3. Protection of Confidentiality and Integrity of PSC Credentials
- The EBA proposes a principle-based approach to ensure the security of PSCs.
- Requirements include the protection of the creation, association, delivery, renewal, and destruction of credentials.
- The EBA suggests that PSU awareness programs are more appropriately included in the EBA's mandate under Article 95 PSD2 or as part of the EU Commission's user-friendly electronic leaflet under Article 106 PSD2.
4. Common and Secure Open Standards of Communication
- The EBA outlines two sets of requirements:
- General Communication Principles: Secure bilateral identification, protection against misdirection, and traceability of all transactions.
- Specific Communication Standards:
- ASPSPs must provide a secure communication interface for AISPs, PISPs, and card-based PSPs.
- The interface must support common and open standards, including ISO 20022 elements.
- The communication interface should offer the same functionalities and availability as the online platform used by the payment service user.
- AISPs must request information from designated payment accounts no more than two times a day unless the user actively requests it.
Key Questions for Feedback
- Q1: Agreement with the EBA's reasoning on SCA requirements and provisions in Chapter 1.
- Q2: Agreement with the EBA's approach to dynamic linking, ensuring independence of channels.
- Q3: Awareness of other threats to authentication elements beyond those identified in the draft RTS.
- Q4: Agreement with the EBA's reasoning on SCA exemptions and related provisions in Chapter 2.
- Q6: Agreement with the EBA's approach to protecting PSC confidentiality and integrity.
- Q7: Agreement with the EBA's reasoning on communication standards in Chapter 4.
- Q8: Agreement that ISO 20022 standards should be required for interoperability.
- Q9: Agreement that e-IDAS qualified certificates are suitable for PSP identification.
- Q10: Agreement with the proposed frequency limit for AIS information requests.
Next Steps
- Consultation Period: Ended on 12 October 2016.
- EBA Actions:
- Assess responses and make necessary amendments.
- Publish the final draft RTS in Q1 2017.
- Include a feedback table detailing all comments and amendments.
- EU Commission Review: Legal review will be conducted, followed by scrutiny by the EU Council and Parliament.
- RTS Adoption and Application:
- RTS will be published in the Official Journal of the EU and enter into force 20 days later.
- The earliest application date is October 2018 as per PSD2.
Summary of EBA's Approach
The EBA seeks to balance security and innovation, aiming to create flexible yet robust standards. The approach involves consultation, principle-based requirements, and technical alignment with international standards like ISO 20022. The EBA emphasizes the importance of interoperability, customer convenience, and security resilience in its RTS proposals.
试读结束,高清完整版pdf/doc/ppt,请点下载