Please enable JavaScript.
Coggle requires JavaScript to display documents.
User (Mobile (Personalized Security Credentials (Creation and Transmission…
User
Mobile
Payment Services
Authentication
-
Authentication Elements
No information on authentication elements can be derived from the disclosure of the authentication code
No information on authentication elements can be derived from the disclosure of the authentication code
Make impossible the identification of which authentication element was incorrect in case of failed authentication
Authentification elements (knowledge, possession, inherence) must be protected from disclosure
The breach of one of an authentication element does not compromise the reliability of the other elements
Authentication shall be based on two or more elements categorised as knowledge, possession and inherence
Authentication Code
-
-
Communication sessions must be protected against the capture and manipulation of authentication data during the authentication
-
-
-
-
-
Dynamic Linking
-
Authentication code must corresponds to the original amount of the payment transaction (or blocked funds) and payee identity
-
Confidentiality, authenticity and integrity of the amount of transaction and informations displayed during authenticaiton
Identification
Secure identification when communicating between the payer’s device and the payee’s acceptance devices
-
Traceability
Security mechanisms for the detailed logging of the transaction,
-
-
Online
Payment Services
Payment Services
Authentication
-
Authentication Elements
Authentification elements (knowledge, possession, inherence) must be protected from disclosure
The breach of one of an authentication element does not compromise the reliability of the other elements
No information on authentication elements can be derived from the disclosure of the authentication code
Authentication shall be based on two or more elements categorised as knowledge, possession and inherence
No information on authentication elements can be derived from the disclosure of the authentication code
Make impossible the identification of which authentication element was incorrect in case of failed authentication
Authentication Code
-
-
-
-
-
Communication sessions must be protected against the capture and manipulation of authentication data during the authentication
-
-
Dynamic Linking
-
Authentication code must corresponds to the original amount of the payment transaction (or blocked funds) and payee identity
-
Confidentiality, authenticity and integrity of the amount of transaction and informations displayed during authenticaiton :
Identification
Secure identification when communicating between the payer’s device and the payee’s acceptance devices
-
-
-
-
Others
Payment Terminal
Authentication
-
Authentication Elements
Authentification elements (knowledge, possession, inherence) must be protected from disclosure
The breach of one of an authentication element does not compromise the reliability of the other elements
No information on authentication elements can be derived from the disclosure of the authentication code
Authentication shall be based on two or more elements categorised as knowledge, possession and inherence
No information on authentication elements can be derived from the disclosure of the authentication code
Make impossible the identification of which authentication element was incorrect in case of failed authentication
-
Authentication Code
-
-
-
-
-
Communication sessions must be protected against the capture and manipulation of authentication data during the authentication
Dynamic Linking
-
Authentication code must corresponds to the original amount of the payment transaction (or blocked funds) and payee identity
Confidentiality, authenticity and integrity of the amount of transaction and informations displayed during authenticaiton
-
Identification
Secure identification when communicating between the payer’s device and the payee’s acceptance devices
-
Parking
Payment Services
Dynamic Linking
-
Authentication code must corresponds to the original amount of the payment transaction (or blocked funds) and payee identity
Confidentiality, authenticity and integrity of the amount of transaction and informations displayed during authenticaiton
Authentication
-
Authentication Elements
Authentification elements (knowledge, possession, inherence) must be protected from disclosure
The breach of one of an authentication element does not compromise the reliability of the other elements
No information on authentication elements can be derived from the disclosure of the authentication code
Authentication shall be based on two or more elements categorised as knowledge, possession and inherence
No information on authentication elements can be derived from the disclosure of the authentication code
Make impossible the identification of which authentication element was incorrect in case of failed authentication
-
Authentication Code
-
-
-
-
-
Communication sessions must be protected against the capture and manipulation of authentication data during the authentication
-