2017年-SWIFT环球同业银行金融电讯_Strong_Customer_Authentication_under_Payment_Services_Directive_2_PSD2_8页_113kb
报告摘要
Strong Customer Authentication under Payment Services Directive 2 (PSD2) Summary
Core Content
The Payment Services Directive 2 (PSD2), published in December 2015 and applicable from January 2018, aims to enhance transparency, innovation, and security in the European payments market. It introduces stricter requirements for Strong Customer Authentication (SCA), which is a mandatory two-factor authentication process designed to reduce the risk of payment fraud and ensure the authenticity of users accessing their payment accounts or initiating transactions.
SCA requires the use of two or more authentication elements from the following categories:
- Knowledge: Something the user knows, such as a password or code.
- Ownership: Something the user possesses, such as a token or smart card.
- Inheritance: Something the user is, such as a biometric characteristic.
The authentication code must be dynamically linked to the amount and payee of the transaction to prevent fraud. Furthermore, the process must ensure the confidentiality, authenticity, and integrity of the information throughout all phases of authentication, including generation, transmission, and use of the code.
Regulatory Technical Standards (RTS)
The European Banking Authority (EBA), in collaboration with the European Central Bank (ECB), developed the RTS for SCA and secure communication. These standards:
- Define the technical requirements for SCA.
- Provide exemptions from SCA in certain cases.
- Set out security measures to protect users' credentials.
- Establish common and secure open standards for communication between different payment service providers, including ASPSPs, PISPs, and AISPs.
The RTS will become applicable in November 2018, 18 months after its entry into force, allowing the industry time to adapt and implement compliant solutions.
SWIFT's Digital Identity Solution
SWIFT, in partnership with the banking community, introduced 3SKey, a global, multi-bank, and multi-channel digital identity and signature service. It supports strong authentication and personal signatures using a secure, scalable, and cost-effective shared infrastructure.
Key Features of 3SKey
- Multi-bank and multi-channel support: Enables users to securely authenticate transactions across multiple institutions and countries.
- Shared infrastructure: Reduces the need for proprietary systems, lowering costs and complexity.
- FIPS 140-2 certified hardware tokens: Ensures a high level of security.
- Trusted SWIFT Public Key Infrastructure (PKI): Provides a reliable framework for digital identity and authentication.
Advanced Reader Technology
In 2017, SWIFT launched an advanced reader technology to enhance the security of online banking channels and help institutions comply with the new PSD2 requirements. This technology:
- Supports two-factor authentication.
- Enables dynamic linking of the authentication code to the transaction amount and payee.
- Includes a secure display for "See-What-You-Sign" (SWYS) user controls, which help mitigate Man-in-the-Browser (MitB) attacks.
- Offers an integrated PIN pad to protect against keystroke logging attacks.
- Can be used offline for transaction authentication, ensuring interoperability across banking channels.
The advanced reader is targeted for use in secure online channels and is designed to be independent and segregated from the channel used for initiating transactions, reinforcing the security and compliance of the authentication process.
About SWIFT
SWIFT is a global member-owned cooperative that provides secure financial messaging services. It connects over 11,000 banking and securities organizations, market infrastructures, and corporate customers in more than 200 countries and territories.
SWIFT's mission includes:
- Facilitating global and local financial flows.
- Supporting trade and commerce worldwide.
- Promoting operational excellence, cost reduction, and risk mitigation.
About 3SKey and PSD2
3SKey is a compliant solution that supports the regulatory requirements of PSD2. It provides a centralised credential issuance and management system, functioning as a Certification Authority.
Banks can use 3SKey to:
- Register users with their own KYC procedures.
- Define the legal effect of 3SKey signatures.
- Implement secure authentication and digital signing for transactions and files.
For more information on 3SKey or upcoming regulatory standards, contact your SWIFT relationship manager or email swiftforcorporates@swift.com.
Summary of Key Points
- PSD2 mandates Strong Customer Authentication (SCA) for online payments and transactions.
- SCA requires two or more authentication elements (knowledge, ownership, inheritance).
- Dynamic linking ensures that the authentication code is specific to the transaction amount and payee.
- RTS are being developed to provide technical guidance for SCA and secure communication.
- 3SKey is a global digital identity solution developed by SWIFT to support SCA compliance.
- Advanced Reader Technology enhances security by enabling secure authentication, SWYS controls, and mitigation against web attacks.
- 3SKey reduces the need for proprietary systems and independent security devices per bank.
- SWIFT provides a secure messaging platform and industry standards for financial institutions.
试读结束,高清完整版pdf/doc/ppt,请点下载