Combatting Card-Not-Present fraud and Secure Customer Authentication

Combatting Card-Not-Present fraud and Secure Customer Authentication

David Orme

Senior Vice President at IDEX Biometrics

Views 255

Combatting Card-Not-Present fraud and Secure Customer Authentication

09.01.2019 07:30 am

A ‘Card-Not-Present’ transaction is when a payment is made without a cardholder physically presenting their card to the merchant. Historically these sorts of payments have been used effectively for mail and telephone orders, but now they are used more typically to complete online orders, such as e-commerce and m-commerce (In App).

However, Card-Not-Present transactions are the biggest routes to card fraud, as this form of payment presents a specific challenge to retailers in being able to verify who the actual cardholder is, and consequently being able to authenticate their payment effectively.

The introduction of EMV (Europay, Mastercard and Visa standards) chip and pin brought enhanced authentication and cardholder verification for payment cards, which enabled a decline in Card-Present fraud. As a result, fraudsters have migrated to Card-Not-Present routes of attack, particularly for e-commerce and m-commerce transactions.

Why current methods of online authentication aren’t working

The main online method of authentication consumers must complete, depending on the retailer, is 3D Secure, which stands for 3 Domain Server, there are three parties that are involved in the 3D Secure process. 

  • The merchant the purchase is being made from
  • The acquiring bank (the bank of the company)
  • The card issuer (such as VISA and MasterCard)

The 3D Secure form of authentication is an additional fraud prevention scheme that the majority of retailers use via their chosen Payment Service Provider (PSP). The method allows shoppers to create a password for each of their payment cards, which is used to authenticate an online transaction through a site that requires the 3D scheme.

3D Secure is also the only fraud prevention scheme available that offers companies liability cover for transactions that are verified by the checks. This provides additional protection to companies using the scheme as opposed to those that do not.

However, the scheme is not completely fool proof. Banks and retailers trialled 3DS (3-domain secure), also known as Payer Authentication, for online transactions, which was successful in the UK from 2008 to 2011. However, the success was short-lived due to the lack of 3DS adoption by consumers, as consumers looked for ways to circumnavigate the authentication process in favour of convenience, which also created opportunities for fraudsters.

With the introduction of the regulatory technical standards on Strong Customer Authentication by the EU in September next year, under the Second Payment Services Directive (PSD2), merchants must require two methods of authentication. These two methods must be chosen from the following authentication methods: Something youknow/knowledge (PIN or password), something you have/possess (bank issued card reader) and something you are/inherence (biometric). Many retailers already require the first option; however, the last two factors have proven difficult for merchants to address.

What to consider when developing a Strong Customer Authentication strategy?

Knowledge covers the most widely used methods of payment authentication, such as PINs and passwords, however many banks also encourage a secret question, such as ‘what’s your mother’s maiden name?’ or ‘your first pet’s name’. Possession covers proving that you physically have the card on you, methods such as One Time Passwords (OTP) issued via SMS or inputting your card into a bank issued card reader.

However, personal card readers to provide OTPs can be expensive for banks to issue and extremely inconvenient for consumers to repeatedly use.

The secret piece of the puzzle to balancing security versus convenience lies in the use of analytics and fingerprint biometrics via smartphones. Most smart phones on the market now include integrated fingerprint biometric readers, so it makes sense that retailers and banks leverage this ability to make online, and particularly m-commerce, transactions more secure. However, we face another challenge - in this use case biometric data managed through the smartphone provider, as opposed to the card owner.

Smart Payment Cards with fingerprint biometric sensors are in mass production and due to hit the market in 2019, putting payment security firmly in the hands of the consumer. The level of technology that has been developed behind a biometric sensor makes it very straightforward for the user to record their fingerprint; the reference fingerprint can easily be uploaded to the card by the user, at home, and once it is done the card can be used over existing secure payment infrastructures — including both chip and ID and contactless card readers — in the usual way.

Once it is registered the fingerprint is held only on the card and not on a central bank database, removing the attractive honey pot of biometric fingerprint data for hackers. By also storing the biometric fingerprint data directly on the card itself, it also makes it impossible for casual pick pocketers to use stolen contactless cards.

Retailers and bankers both stand to benefit from the perfect balance of convenience and security created by connecting biometric fingerprint enabled smart cards and the Near Field Communications (NFC) ability of the card direct to the smart phone for online transactions. 

Further possibilities to strengthen retailers’ and merchants’ compliance, would be to add digital dynamic CVV number and Primary Account Number (PAN) tokenisation.  This would essentially replace the printed CVV number currently on the reverse of all cards with a digital display that presents a new code whenever the card owner’s fingerprint is presented on the card and the PAN with a token.  This means that both changing numbers are never exposed to the payments ecosystem, other than to the card issuer, which is standard practise. In turn, the traditional payment card as we know it would be transformed and protect against the theft of static card numbers for fraudulent online transactions and physical card theft in the same breath. This would inherently meet the SCA requirements for online transaction authentication, with an OTP covering knowledge and biometrics covering the inherence requirement. However, this would work with any other method of authentication to accompany biometrics to go above and beyond meeting the SCA regulation. This is an opportunity presented to banks, retailers and customers alike to embrace the most secure and convenient methods of authentication to tackle Card-Not-Present fraud once and for all.

Latest blogs

Andrew Stevens Quadient

Comment on Competition and Markets Authority’s latest customer satisfaction in banking survey

“When the CMA launched this report six months ago, it seemed a natural fit when most customers rated a bank without any branches, First Direct, as the one they would recommend to their friend for online and mobile banking services. Barclays has now Read more »

Mark Smith Ayming

Big data is AI’s big brother

Big data is AI’s big brother. While AI is driven by machine learning, big datasets fuel the intelligence engine. Banks and insurance companies have access to huge volumes of data and are looking to harness this information to drive efficiencies in Read more »

Alan Stewart-Brown Opengear

“When ATMs Go Down” – How Banks Can Achieve Network Resilience

It is a common source of annoyance for anybody in rural communities; towns and cities around the world. You visit your local bank branch’s ATM to withdraw cash or to print out a mini statement and you are met with a message informing you that the Read more »

Todd Latham Currencycloud

Comment on BoE financial report by, Todd Latham, the CMO of Currencycloud

The recent Future of Finance report has outlined a new age of banking, stating how financial services can help bring about a multitude of changes. This new age is also designed to help bring the UK in line with the changing nature of the digital Read more »

Peter Hecht DXC Technology

How Can Insurers Attract and Retain Talent Through Digital Transformation?

Within the insurance industry, digital transformation is boosting productivity – improving the customer experience, creating efficiencies throughout organisations, and enabling actionable insights using analytics and big data. Yet so far, the focus Read more »

Free Newsletter Sign-up
+44 (0) 208 819 32 53 +44 (0) 173 261 71 47
Download Our Mobile App
Financial It Youtube channel