2006: A Milestone Year for Two-factor Authentication
Over the past 12 months, the re-definition of traditional business models within the global payments industry has continued at a rapid pace, as banks and financial institutions continue to encourage customers to conduct transactions online.
This irreversible trend has led to a significant and stable increase in the acceptance and deployment of two-factor authentication (2FA) methods across the world, as banks seek to elevate the real and perceived security of their online services. Protecting their organisation from the financial fallout of fraud is one consideration, but success in the lucrative Internet banking arena depends on how safe customers feel when using banking services online.
The most noteworthy development in the global rise of 2FA over the past year has taken place in the US. US banks and financial institutions have until the end of 2006 to conform with guidance, issued by the Federal Financial Institutions Examination Council (FFIEC), to implement 2FA mechanisms in all ‘high risk’ financial transactions involving access to customer information or the movement of funds to other parties. This legislation has been introduced following a decision by the FFIEC that single-factor authentication is inadequate for such transactions.
This development has had a number of major impacts on the global payments industry, which will have both immediate and long-term positive effects. In addition to reinforcing the security advantages of 2FA on a global stage and giving the technology a shining endorsement, the move has opened up a vast market for international vendors of 2FA solutions based on tokens and credit/debit cards. Currently, the most widely implemented authentication tools in the US banking sector cannot be strictly classed as ‘true’ 2FA solutions because they are not based on something the user technically ‘has’ in their possession and knows. Instead, they take a centralised, low-cost approach that creates a ‘speed bump’ for the criminals without fundamentally addressing the weakness created by static passwords. Many banks will subsequently need to upgrade their authentication systems once new attacks penetrate their existing measures.
The move in the US has also set a precedent for mandating advanced security measures to protect Internet banking transactions. Whether or not this legislation will be adopted elsewhere in the global market remains to be seen and may depend entirely on how successful and clever attacks on online transactions become over time.
In Europe, despite a lack of similar legislation, 2FA has continued to be widely implemented throughout 2006. A greater willingness among issuers to deploy such mechanisms demonstrates an understanding of the security advantages associated with authenticating a person online based on what they have and what they know.
In light of worldwide developments and the established acceptance of 2FA as a secure authentication method, the global outlook for 2FA in 2007 looks very optimistic indeed.
EMV – Slow but Evident Acceptance in North America
The success of 2FA in Europe over the past year can be linked, to some extent, to the wide-spread adoption and ongoing roll out of EMV (Eurocard, MasterCard, Visa) technology, which has been driven by the international payment systems and the liability shift deadlines imposed by those organisations.
Many banks and financial institutions have chosen to maximise their migration to EMV by deploying debit and credit cards featuring MasterCard Chip Authentication Program (CAP) applications. These not only enable the user to conduct secure EMV payment transactions in a face-to-face retail environment but also allow them to take advantage of a 2FA mechanism when verifying their identity and authorising transactions online and in card-not-present transactions, such as telephone and mail order.
On the other side of the Atlantic, the US payments industry has been slow to respond to EMV, but it seems that the last stronghold of the magnetic stripe might slowly be opening up to the benefits of chip, thanks to progress being made in Canada to migrate to EMV. It is predicted that the significant mass of all Canadian payment cards will be based on EMV by 2010, making it likely that Canada will be seen as the ‘pacesetter’ for EMV rollout throughout North America.
The mandate for US banks to offer 2FA solutions to online customers by the end of 2006 is another key driver for short/mid-term EMV adoption in the US, since CAP can be seen as a common denominator which offers 2FA protection for online transactions (as mandated) and which addresses payment fraud through point-of-sale terminals. It could therefore be as little as three to four years before we see the US waking up to EMV and deployments start rolling out en masse. In spring 2007 Cryptomathic will be involved in the deployment of one of North America’s first EMV installations, signalling that progress has indeed already begun.
The Rise of Dynamic Data Authentication
With EMV now an established technology in many geographical markets, another trend that has become apparent this year is the shift, by the payments industry in certain regions, away from static data authentication (SDA) in preference of dynamic data authentication (DDA) when authorising EMV transactions.
Both SDA and DDA cards digitally ‘sign’ transactions using keys embedded in the chip during manufacture. The difference is that whilst DDA signatures can be verified off-line, SDA signatures can only be verified by the card issuer, requiring the merchant to be online at the time. Thus the possibility of fraud using SDA cards in off-line environments is the driving force behind DDA adoption.
Many banks across Europe, the Middle East and the Far East have started the process of upgrading their authentication solutions from SDA to DDA and I anticipate that more will seek to undertake this change throughout 2007. It is a process that can be undertaken quite easily while offering huge security advantages. These benefits have also been recognised in the e-passport sector where a similar shift is taking place.
Automated Advanced Key Management
One final observation on trends within the global banking industry throughout 2006 is that there appears to be a growing demand for automated advanced key management systems to secure ATMs and other devices worldwide. Traditionally, key custodians would need to manually install new keys on devices at regular intervals in order to prevent attacks. The introduction of automated key management systems has changed that and many issuers are now seeking to benefit from the cost and time reductions these systems offer. This growth is likely to continue in 2007.