Can E-money Overtake Cash as King?

Within my 16 years in finance, including 11 years within the banking industry, I was (and still am) promoting e-transactions. I do still believe that cash will be substituted by e-money (e.g. prepaid cards, value stored cards, wire-payments and all kinds of e-banking) inevitably driven by governments as well as banks and corporates. From the point of view of the average consumer, however, in order for e-money to thrive, two key characteristics have to be demonstrated. The first is anonymity and the second is availability.

If the banks or e-money providers as well as governments could guarantee that e-money will have the same level of anonymity as cash and if there was no possibility of the misuse of information about e-money where only authorities with court permission could seek and use such information for criminal investigation, people would accept the transition from material to immaterial currency. The civil rights movement could also raise concerns with the transition to virtual money and it is up to the banking community to address them.

The availability of e-money services must be independent of the availability of network, e-money service provider and clearing house. Also, the technical gadgets (i.e. chip and smart cards, SIM cards, mobile phones, PDA, etc) providing or storing e-money must be as reliable as the special paper and other safety elements of banknotes. In fact, in a few years, the virtual world will be much safer than the real one. It is applicable to banking in the first place and it is ongoing and unstoppable. But the weakest link in the chain of the virtual world is still human nature.

Dynamics of Human Behaviour

I’m currently reading my second book by Nicholas Carr called, ‘The Big Switch’, which is providing me with great ideas and forecasts based on human behaviour in the virtual world. It also demonstrates how the IT industry is moving to the utility model and becoming more consolidated by enjoying economies of scale. Humans want order and a fair environment but they also want independence and sometimes anonymity. I’m aware of the fact that cash is very costly for banks and it is not as secure as money deposited in a bank account. Would e-money be able to provide people with the same advantages as cash?

For the last 10 years, banking (especially transaction banking) has slowly been moving in this direction but the pace of progress has now increased and the consolidation of transaction banking into a utility model is not far away. Cash is still in circulation because it is a job for the central banks. Central banks are well aware of the fact that proportion and volumes (number) of electronic transactions are constantly growing and at the same time the volumes (number) of cash transactions aren’t shrinking in comparison to the growth of e-transfers. As far as I am aware, however, there is no fair explanation for this situation.

In order to make the use of e-money plausible, it would be necessary for a certain period of time to use a fixed connection of everybody’s e-identity with e-money. There are many options as to how to switch our identity to an e-identity. Banks, as well as mobile operators, are trying to do this. The governments are trying to do the same, but do people trust these initiatives?

The mobile operators can identify you not only based on your mobile number but also based on your client number. So what’s your
e-identity? Is it your mobile phone number or your client number? The answer is that both of them are and that both of them are required in the communication between the user (you) and the mobile operator. A similar story is applicable to your bank or insurance company. You have your current account number, payment card number and probably several card numbers (e.g. credit card, ATM card, etc.). You also have your user name, or in many cases the 6-12 digit number instead, and you have your password and one-time password to access your finances via Internet banking. Surely you have got a client number and several other ‘keys’ that you use for identification and communication with your bank. Why? There are two main reasons for that.

Firstly, there are different IT and information systems inside the bank, which are sometimes somehow interconnected via a customer relationship management (CRM) tool, and which use different identification and numeration of customers, contracts or business subjects. The second reason for not having one identification key (number, code) with your bank is security. Banks are rightfully afraid that stolen or manipulated e-identity (i.e. a false identity that is accepted by the bank) could cause huge losses for the bank and customers. What would be more devastating for the bank is the impact on its credibility and reputation not the financial loss on its balance sheet. A bank’s main value does not lie in the amount of money saved by the customers or lending but in its reputation, trust and the way it balances risks. If a bank loses trustworthiness, then its business will surely fail.

Online Security Trends in Banking

There are three basic categories of security tools:

  1. Something the user knows, such as a password or PIN.
  2. Something the user has, such as an ATM card, smart card or security token.
  3. Something the user is, usually based on a physical characteristic, such as a fingerprint, voice pattern or other biometric identification. (Biometric technologies use unique biometric characteristics such as a fingerprint, hand, Iris or voice to identify individuals.)

Many banks have already moved from single-factor authentication (such as requiring a customer to enter a user ID and password to log on to a website). Those banks that do not have it will need to apply it soon. Clearly, the Federal Financial Institutions Examination Council (FFIEC) wants banks to adopt stronger, dual-authentication methods to verify identity. In addition to something the customer knows, such as user ID and password, for instance, information from something the user has might need to be provided as well, such as entering a one-time password displayed on a security token. Each authentication method has its strengths and weaknesses, which need to be weighed by the bank, including the impact on customers.

From the issues described above, key questions for the banking industry arise:

  • Shall we follow the above-mentioned move from single-factor authentication? The answer is YES.
  • Shall we use current banking security tools and combine them? YES.
  • Shall we implement ‘something the user is’ category of identification? NOT YET.

There are several important reasons and possibilities for implementing only ‘one-ID’:

  • Nowadays, there is no individual user level ID of individual customers of e-banking and other banking services.
  • SMEs and corporate customers (companies) are composed from individuals/physical persons.
  • From the legal point of view of anti-money laundering (AML), it is mandatory for the bank to identify all individuals that have the right to manage the financial resources of the company (or own) held by financial institution including bank accounts.
  • Payment/credit cards are unique – there is no same card number for two or more cards.
  • The number of the card is build from 16-digit number (plus 3 position) – maximum 19-digit number – enough for all people around the globe.
  • The same number on the card could be used for one user repeatedly (‘one-ID’ for the whole communication with the bank).
  • The number of the card could be used as a personal and unique ID of the banks’ customer.
  • There are a lot of security tools (e.g. tokens, personal key identification/PKI, virtual code SIM card tools) and personal identification means (user name plus password, token or PKI log-in, biometric) available for the financial sector.
  • If banks do accept the individual personal ID concept, these IDs could be used in all banking services and databases.
  • There are multi-purpose cards available – combination of magnetic stripe and chip. The chip could be divided into different segments – payment card, e-wallet, secure and non-secure, – and it could bear a data or application (including a software-based token in the secure area of the chip).

There are two major components of the e-identity:

1. Security tools for log-in as well for e-signatures:
  • Chip card – secure storage of PKI data or application, portable.
  • Hard drive – storage of PKI (less secure than chip card), tied with PC.
  • USB key – storage of PKI (less secure than chip card) but portable.
  • Hardware (HW) token – with or without switch on PIN, one-time password generator (software/SW card, Vasco, Active Card, etc.).
  • Sim card token – GSM sim cards used for mobile phones in combination with token application with the same functionality as HW tokens but inside mobile phones.
  • ID plus password – the same principle as in Windows log-in.
  • Biometric tools – see tables 1 and& 2 below.
  • Identity management – ID management holds different security tools identifications with one-ID for all banking applications. It could be called business logic.
Table 1: Biometric Tools Overview

Biometric Identify vs. Verify How robust? How distinctive? How intrusive?
Fingerprint Either Moderate High Touching
Palm Verify Moderate Low Touching
Facial recognition Either Moderate Moderate 12+ inches
Voice recognition Verify Moderate Low Remote
Iris scan Either High High 12+ inches
Retinal scan Either High High 1-2 inches
Dynamic signature verification Verify Low Moderate Touching
Keystroke dynamics Verify Low Low Touching

2. Applications: all bank internal (not available for customers) and external oriented applications:
  • Internet banking.

  • Web portal – user name plus password (at least) customisable web information exchange tool between the bank and customers allowing secure exchange of information with obligatory content (i.e. card application, overdraft contract, P&L, etc.)
  • Cards – payment and credit cards, with magnetic strip and/or chip. Chip cards could be provided not only with customer ID within the magnetic strip, but also with e-wallet (deposit money for micro payments such parking, sub-way ticket, etc.) and/or PKI application.
  • Back-end – banking system/s with different types of accounts, booking systems.
  • Data warehouse – storage of structured data for querying and reporting.
  • CRM – Customer relationship management tool used for overview, search and analysis over the data warehouse. This should also include workflow, time and task management of customer relationship managers etc.

There are limitations associated with the individual security tools though:

  • User name plus password provides very insufficient security.
  • PKI is not acceptable for non-technical users, required connectivity to PC makes it hard to be used everywhere.
  • Tokens provide better opportunities to users and banks: acceptable price, user friendly, portable and secure.
  • Biometric tools – it will take some time for them to be more broadly accepted.
  • Radio frequency identification (RFID) technologies – they will take time to be developed.
Table 2: Security Tools Characteristics Overview

Security tool Portability User friendliness Security level Extensibility Price
User name and password High High Low Supreme Low
PKI in the file (hard disk, USB hard drive, etc.) High (storage medium needed) Low Medium High Low
PKI at chip card Low (card reader needed) Low (need to be installed and certificate renewed) High Medium Medium
PKI at Chip card in the protected area Low (card reader needed) Low (need to be installed and certificate renewed) Supreme Medium Medium
Token Supreme High Supreme Medium (agreement and co-operation with lot of mobile operators needed) Medium
Biometric Supreme Supreme Supreme Low (small business demand) Extremely high

Conclusion

Clearly, there is no single silver or gold secure solution for electronic banking. The same is true for e-money when taking into account the current status of technology. I believe combining two types of technology proven by customer use and time – bar codes and cash – could work.

Banknotes of all currencies in the world could be provided by barcode with no other modification of their design because of the national identity. The barcode would bear a unique identification of each banknote. The World Bank could manage the database of all banknotes, for example. It is impossible to push all central banks and governments to accept the fact that all their local currency banknotes would be part of a World Bank database. But all of those banks would accept it if banknotes with a barcode could become part of a ‘save cash’ entity. All members of this club would receive in return a guarantee from the World Bank that the cash – banknotes – in circulation are genuine. We could go even further.

The same approach could be used by commercial banks towards the merchants and shopkeepers. The shopkeepers equipped with bar code readers and software for identification of bar-code banknotes could, via commercial banks, be connected to the database of the World Bank and therefore payments with false banknotes would be practically impossible. Tracking the barcode banknotes would be possible. However, without the connection of banknotes’ identification with the payers’ ID there is still a lot of anonymity in using such a barcode. Commercial banks could provide all their customers who accept bar codes with better conditions for cash payments (close to the card or e-money transactions) than customers using cash without bar code identification.

If the IT and telco networks and databases become as fast as current central processing units (CPUs), then all barcode banknotes and readers connected and acting online and fast enough with the database of World bank would become reality. Furthermore, they will provide customers with the same comfort as current non-bar code cash and, at the same time, it will be much safer for all participants (i.e. governments, citizens, central banks, commercial banks as well as all parts of the delivery and business chain).

In my opinion, within the next 10 years, cash will still be in circulation in all open and democratic economies even though the business case for e-money makes more sense. With new technologies and increasingly secure environments eliminating the misuse of the system, e-money will eventually start to overtake physical cash.

References:

Nicholas Carr, ‘The Big Switch’ and ‘Does IT Matter?’
Chris Skinner, Research Director, Tower Group
gtnews.afponline.org

Whitepapers & Resources

2021 Transaction Banking Services Survey
Banking

2021 Transaction Banking Services Survey

5y
CGI Transaction Banking Survey 2020

CGI Transaction Banking Survey 2020

6y
TIS Sanction Screening Survey Report
Payments

TIS Sanction Screening Survey Report

7y
Enhancing your strategic position: Digitalization in Treasury
Payments

Enhancing your strategic position: Digitalization in Treasury

7y
Netting: An Immersive Guide to Global Reconciliation

Netting: An Immersive Guide to Global Reconciliation

8y