<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>
<channel>
	<title>It&#039;s a contactless world! &#187; emv</title>
	<atom:link href="http://contactless-world.com/category/emv/feed/" rel="self" type="application/rss+xml" />
	<link>http://contactless-world.com</link>
	<description>A website dedicated to contactless payment systems</description>
	<lastBuildDate>Wed, 30 Jun 2010 13:07:26 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>EMVCo released handset requirements for contactless mobile payment</title>
		<link>http://contactless-world.com/emvco-released-handset-requirements-for-contactless-mobile-payment/</link>
		<comments>http://contactless-world.com/emvco-released-handset-requirements-for-contactless-mobile-payment/#comments</comments>
		<pubDate>Wed, 30 Jun 2010 13:07:26 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NFC]]></category>
		<category><![CDATA[contactless payment]]></category>
		<category><![CDATA[devices]]></category>
		<category><![CDATA[emv]]></category>
		<guid isPermaLink="false">http://contactless-world.com/?p=122</guid>
		<description><![CDATA[By maintaining the specifications of the banking card applications, EMVCo has a huge effect on banking card business. Visa and MasterCard developed  their own implementations (VSDC and M/Chip respectively) based on EMV specifications. They are almost identical, they have a few configuration changes. Contactless applications payWave and PayPass are also based on EMV specifications, however [...]]]></description>
			<content:encoded><![CDATA[<p>By maintaining the  specifications of the banking card applications, EMVCo has a huge effect on banking card business. Visa and MasterCard developed  their own implementations (VSDC  and M/Chip respectively) based on EMV specifications. They are almost  identical, they have a few configuration changes. Contactless  applications payWave and PayPass are also based on EMV specifications,  however they were developed before EMVCo released a contactless  specification.</p>
<p>It seems EMVCo is ahead of Visa and MasterCard  this time, they released requirements for contactless payments by  handsets. There are already implementations of Visa and MasterCard&#8217;s  applications on handsets, but all of them have been dropped before  launch -after pilot phase.</p>
<p>Basically, a mobile application is a  user interface for accessing the EMV compliant payment application  running on the secure element of the handset. Secure element can reside  on the NFC controller of the handset or on the SIM card.</p>
<p>What  EMVCo requires for these applications are;</p>
<ul>
<li>Application  should have a soft/hard key for easy access. If it&#8217;s a soft key, it must  be accessible from the main/home screen.</li>
<li>Application should  inform the handset/card holder when a contactless transaction is in  place.</li>
<li>Application should be secured by a password and it should  be configurable to enable/disable the application.</li>
<li>There  should be an indication of contactless capability, just like the  bluetooth icon.</li>
<li>Handset shall provide a mechanism to notify the  application when it is powered off.</li>
</ul>
<p>It is a good effort to  draw the boundaries of the environment and will lead the players in the  industry to have a single user experience. It seems we will see more  mobile payment applications on the market -hopefully in the commercial  level rather than pilots.</p>
<p>Original document can be found <a href="http://www.emvco.com/download_agreement.aspx?id=535" target="_blank">here</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://contactless-world.com/emvco-released-handset-requirements-for-contactless-mobile-payment/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Payment vs. ticketing</title>
		<link>http://contactless-world.com/payment-vs-ticketing/</link>
		<comments>http://contactless-world.com/payment-vs-ticketing/#comments</comments>
		<pubDate>Sun, 06 Jun 2010 19:00:58 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NFC]]></category>
		<category><![CDATA[contactless payment]]></category>
		<category><![CDATA[emv]]></category>
		<guid isPermaLink="false">http://contactless-world.com/?p=105</guid>
		<description><![CDATA[Contactless cards are penetrating into more and more market segments day by day. The three most common use cases of contactless cards are clearly ticketing, payment and access control. Now let&#8217;s skip the access control and compare the ticketing and payment use cases. Work Flows Functional requirements of a contactless ticketing application are generally store [...]]]></description>
			<content:encoded><![CDATA[<p>Contactless cards are penetrating into more  and more market segments day by day. The three most common use cases of  contactless cards are clearly ticketing, payment and access control.  Now let&#8217;s skip the access control and compare the ticketing and payment  use cases.</p>
<p><strong>Work Flows</strong></p>
<p>Functional requirements of a  contactless ticketing application are generally store a balance,  contract, expire date and a log space. Typical work flow of a  contactless ticketing transaction is as follows:</p>
<ul>
<li>Identify the  card in the field</li>
<li>Authenticate the card and the ticketing terminal</li>
<li>Read the contract from the card</li>
<li>Read the previous transaction logs  -if necessary</li>
<li>Compute the fare</li>
<li>Debit the card with the fare</li>
<li>Write the transaction log</li>
</ul>
<p>When it comes to payment, the work  flow of a contactless <a href="http://www.emvco.com/" target="_blank">EMV</a> payment is as follows:</p>
<ul>
<li>Identify the  card in the field</li>
<li>Authenticate the card and the terminal</li>
<li>Debit  the card</li>
<li>Store the transaction log</li>
</ul>
<p>As you can see, the main  difference of the payment and the ticketing work flow is the fare  calculation based on some variables like contract type of the card and  the previous transactions performed and stored in the application. This  is something EMV is still uncapable of. Both Visa and MasterCard are  already working on ticketing extensions of <a href="http://www.visa.com/visapaywave/main.jsp" target="_blank">payWave</a> and <a href="www.mastercard.com/paypass" target="_blank">PayPass</a>, however  they will still have many barriers ahead even if the specification are  completed and first samples are out for testing.</p>
<p><strong>Authentication  and cryptography</strong></p>
<p>EMV relies on RSA and Triple DES, while  ticketing applications use mainly DES variants and AES. Contactless EMV  transactions are quite secure with DDA (Dynamic Data Authentication) and  it is a perfect solution for an interoperable environment of different  banks.</p>
<p>Almost all ticketing systems are proprietary and each  transport operator or provider has its own application. Every system has  its own infrastructure and interoperability between ticketing systems  are quite rare. So each system has its own authentication alghoritm and  of course key types and lengths.</p>
<p><strong>Main differences</strong></p>
<p>EMV is  designed for securing the transaction between card and terminal,  terminal and host systems, host system and the card. It&#8217;s the underlying  standard of Visa, MasterCard and JCB. Each organization has its own  application of EMV but  essentially they are mostly identical.  Contactless ticketing application depend heavily on the chip platform  and operating system they are using. Every transport authority, system  integrator or solution provider has its own ticketing application. There  are efforts in Europe to standardize the ticketing applications but  they are not mature enough yet. So basically ticketing is proprietary  for now.</p>
<p>Some time in the near future, payment and ticketing is supposed to meet on the NFC platform, but it seems it&#8217;s still a long way there.</p>
]]></content:encoded>
			<wfw:commentRss>http://contactless-world.com/payment-vs-ticketing/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Highlights from Cardist 2010</title>
		<link>http://contactless-world.com/highlights-from-cardist-2010/</link>
		<comments>http://contactless-world.com/highlights-from-cardist-2010/#comments</comments>
		<pubDate>Mon, 17 May 2010 06:43:31 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[NFC]]></category>
		<category><![CDATA[contactless payment]]></category>
		<category><![CDATA[emv]]></category>
		<guid isPermaLink="false">http://contactless-world.com/?p=92</guid>
		<description><![CDATA[3rd Cardist Card &#38; Smart Technologies Exhibition &#38; Summit is held in Istanbul between 12-14 May 2010 with the main sponsorships of BKM, Visa and MasterCard. Here are my highlights from the exhibition: Garanti &#38; Avea announced a mobile payment product based on mobile phones. Payment is processed by the application running on SIM card [...]]]></description>
			<content:encoded><![CDATA[<p>3rd <a href="http://cardist.com.tr" target="_blank">Cardist Card &amp; Smart Technologies Exhibition &amp; Summit</a> is held in Istanbul between 12-14 May 2010 with the main sponsorships of BKM, Visa and MasterCard.</p>
<p>Here are my highlights from the exhibition:</p>
<p><a href="http://www.garanti.com.tr/" target="_blank">Garanti</a> &amp; <a href="http://www.avea.com.tr/" target="_blank">Avea </a>announced a mobile payment product based on mobile phones. Payment is processed by the application running on SIM card and the SIM card has an external antenna attached. This way, there&#8217;s no need for an NFC based handset, all handsets can be used with. it. Garanti Bank already has more than 1 million contactless credit cards issued and clearly the market leader in contactless payments in Turkey.</p>
<p><a href="http://www.bkm.com.tr/" target="_blank">BKM</a>, the national switch of Turkey announced the pilot project to run on NFC handsets in which BKM acts as the TSM. 6 banks are attending the pilot project.</p>
<p><a href="http://www.oytek.com.tr/" target="_blank">Oytek</a> demonstrated their NFC solutions running on Nokia 6212. The application has a paid balance, ticketing and couponing extensions. There&#8217;s also a kiosque with a contactless reader and an NFC poster application to complete the NFC picture.</p>
<p><a href="http://www.banksoft.com.tr" target="_blank">Banksoft</a> was awarded with the contactless pre-paid card program which was developed for Halk Bank&#8217;s Bank 24 Visa contactless card. <a href="http://www.smartsoft-it.com/" target="_blank">Smartsoft</a> is also awarded with their pre-paid platform as well.</p>
<p><a href="http://www.paymentscardsandmobile.com" target="_blank">Payment Cards&amp;Mobile</a>, which I think the best magazine on contactless systems was also present in the exhibition as they were in the last two ones.</p>
<p><a href="http://www.belbim.com.tr" target="_blank">Belbim</a>, the technology provider of Istanbul Municipality -including the electronic ticketing for public transport- exhibited their validators and surrounding devices. Belbim has developed a DesFire application for Istanbul public transport but somehow it&#8217;s still not been released for public use.</p>
<p><a href="http://www.kentkart.com/" target="_blank">KentKart</a> was also present and demonstrated contactless only validators and vehicle tracking systems.</p>
]]></content:encoded>
			<wfw:commentRss>http://contactless-world.com/highlights-from-cardist-2010/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Contactless Payments : American and European Way</title>
		<link>http://contactless-world.com/contactless-payments-american-and-european-way/</link>
		<comments>http://contactless-world.com/contactless-payments-american-and-european-way/#comments</comments>
		<pubDate>Tue, 29 Sep 2009 18:42:08 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[contactless payment]]></category>
		<category><![CDATA[emv]]></category>
		<guid isPermaLink="false">http://contactless-world.com/?p=42</guid>
		<description><![CDATA[When it comes to card business, almost everything is different between US and Europe. US market is huge and very mature. US never migrated to EMV, while Europe has almost completed the migration. (Well mostly) EMV is the defining point between these two markets. Europe has chosen the card to be the safest and made [...]]]></description>
			<content:encoded><![CDATA[<p>When it comes to card business, almost everything is different between US and Europe. US market is huge and very mature. US never migrated to <a href="http://www.emvco.com/" target="_blank">EMV</a>, while Europe has almost completed the migration. (Well mostly)</p>
<p>EMV is the defining point between these two markets. Europe has chosen the card to be the safest and made a huge investment. Now European cards have the ability to process an offline PIN, validate itself to the POS terminal prior to online authorization, generate dynamic signature of each transaction (cryptogram), validate the host system, etc. In the US, POS terminals just read out the mag stripe data and send the transaction to the issuing host for authorization.</p>
<p>In this context, contactless transactions work in the same way. US contactless cards just send the mag stripe data over RF interface instead of the mag stripe reader and everything else is almost the same. However, there&#8217;s a slightly different security enhancement which may change the things. Each contactless transaction is sent to host by generating an unique transaction counter, which can not be done in the mag stripe world. Big step.</p>
<p>In Europe, contactless transactions are offline. Visa and MasterCard release specifications for online too, but this was just for compliance with the US network. Offline means the card application needs to authorize the transaction without asking to any central host. To be able to do this, you just need to have a smart application inside the chip which can store some smart decision making data. This is the main difference between Europe and the US.</p>
<p>In the US, contactless only chips can be used without any interaction with the mag stripe. But in Europe, this is simply not possible. The chip needs to be dual interface, meaning that it should work both from contact and the contactless interface.</p>
<p>With the introduction of contactless payments, US market began developing into another era, while for Europe, it was a natural extension to the contact applications. Once again Europe choses the expensive and the safest way while US goes from the opportunistic path.</p>
]]></content:encoded>
			<wfw:commentRss>http://contactless-world.com/contactless-payments-american-and-european-way/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
