EBA欧洲银行-BSG-response-to-Consultation-Paper-28EBA-DP-2015-03292008-February-2016_9页_221kb
报告摘要
EBA Banking Stakeholder Group Draft Response to EBA/DP/2015/03 on Strong Customer Authentication and Secure Communication (PSD2)
Core Content
The EBA Banking Stakeholder Group (BSG) has provided a detailed response to the Discussion Paper on future Draft Regulatory Technical Standards (RTS) under the revised Payment Services Directive (PSD2), focusing on strong customer authentication (SCA) and secure communication. The BSG emphasizes the importance of maintaining high levels of security while also promoting competition and innovation in the payment services market.
Main Concerns
- Security of Personal Security Credentials (PSC): The BSG is concerned about the potential risks of sharing PSC with third-party providers (TPPs). They recommend that TPPs should not have direct access to PSC, such as passwords, to prevent fraud and ensure clear liability.
- Customer Experience vs. Security: While promoting the use of SCA, the BSG suggests that for informational purposes, TPPs may access customer accounts if authorized through strong customer authorization (SCA).
- Global Homogeneity of Services: The BSG stresses that the RTS should not restrict the ability of European Payment Service Providers (PSPs) to develop globally interoperable services.
- Behavioral Characteristics: They acknowledge that behavior-based characteristics can be useful for fraud detection but argue they are not sufficient for SCA. These should be used as complementary tools rather than standalone authentication methods.
- Dynamic Linking: The BSG recommends that EBA clarify the concept of dynamic linking and avoid prescribing specific technical solutions to maintain flexibility and innovation.
Key Recommendations
- Exemptions to SCA: Exemptions should be optional and dynamic to counter cybercrime. Risk analysis criteria should be clear and include minimum requirements for tools used.
- Protection of PSC: PSC should not be stored on devices, and mechanisms should be in place to revoke access if compromised.
- Use of Biometrics and Open Standards: The BSG supports the use of biometric data and open standards like Open ID and OAuth for secure credential enrolment.
- Avoiding European-Specific Standards: The BSG advises against developing standards only applicable at the European level, as this could create barriers and increase costs for international operations.
- Synergies with e-IDAS: They suggest that the e-IDAS regulation could help in ensuring secure communication and SCA, especially for customer identification. However, liability for qualified trust services should be managed by the public institution overseeing the e-IDAS system.
Questions for Discussion
4.1 Considerations Prior to Developing the Requirements on Strong Customer Authentication
- Additional Examples of Risky Transactions: The BSG suggests including transactions that involve modifying contact details or authorization mechanisms as exempt from SCA, provided they are subject to strong authorization.
- Possession Elements: Physical elements (tokens, ID cards) are considered appropriate, as well as data elements like soft tokens. Security mechanisms should be in place to prevent misuse.
- Behavior-Based Characteristics: These are not considered strong authentication elements but can be used as complementary tools.
- Dynamic Linking Challenges: The BSG recommends clarity on dynamic linking and avoiding overly specific technical requirements to maintain flexibility.
- Solutions for Mobile Devices: Existing solutions like secure SIM cards, touch ID, and secure device storage can help achieve independence and dynamic linking.
4.2 Exemptions to Strong Customer Authentication
- Usefulness of Clarifications: The BSG finds the clarifications useful but urges them to remain dynamic and flexible.
- Risk Analysis for Exemptions: Exemptions should be based on transaction risk analysis, which may include internal fraud analytics and historical data.
- Complementary Risk Criteria: The BSG suggests considering situations where transactions appear to be executed in different environments, such as a wallet app payment from a remote location.
4.3 Protection of Personal Security Credentials
- Clarification on PSC Protection: The BSG supports the clarification but reiterates that credentials should not be stored on devices.
- Risks Identified: Risks include unauthorized access and impersonation, especially when TPPs act on behalf of the customer.
- Innovative Enrolment Solutions: The BSG recommends using biometric data and existing open standards to ensure secure and confidential enrolment.
4.4 Common and Secure Open Standards of Communication
- Clarifications on Open Standards: The BSG agrees with the clarifications but suggests addressing TPPs' card services.
- Balancing Harmonization and Innovation: RTS should reference international standards to ensure consistency and innovation.
- Governance Model: A governance model should be established to manage liabilities and claims across the value chain.
4.5 Synergies with e-IDAS Regulation
- Agreement on e-IDAS: The BSG supports e-IDAS as a potential solution for secure communication and SCA, especially for customer identification.
- Qualified Trust Services: These could address risks related to PSC confidentiality, integrity, and availability if they are subject to the same liabilities as other participants in the value chain.
Conclusion
The BSG advocates for a balanced approach to SCA and secure communication, emphasizing the need for high security, flexibility, and international standards. They support the use of open standards and behavioral analytics for fraud prevention but stress that PSC should not be shared with TPPs. The group also promotes competition and customer choice while ensuring that liability is clearly defined and security measures are robust.
试读结束,高清完整版pdf/doc/ppt,请点下载