SYS-CON MEDIA Authors: Elizabeth White, Peter Silva, Liz McMillan, Yeshim Deniz, Pat Romanski

News Feed Item

Consult Hyperion and the GSMA Publish Report Contrasting HCE and SIM Secure Element Approaches to NFC Payments

Digital payments experts Consult Hyperion, in conjunction with the GSMA, today published a guide to help banks and mobile operators understand the Host Card Emulation (HCE) and SIM Secure Element approaches for NFC payments. The guide, “HCE and SIM Secure Element: It’s not Black and White”, follows the recent introduction of HCE into Android 4.4 (KitKat) and concludes that the SIM Secure Element and HCE approaches to NFC payments each offer important benefits for financial institutions. Further, they should not be viewed as mutually exclusive and a combination of the approaches may be appropriate for differing applications and markets.

“This paper provides a balanced analysis for financial institutions of HCE as an alternative proposition for NFC payments, alongside the existing SIM approach,” said Alex Sinclair, Chief Technology Officer, GSMA. “The recent inclusion of HCE into Android opens up the possibility of performing NFC payments without using a SIM Secure Element and HCE could also potentially remove complexity associated with SIM-based NFC payments. At the same time, SIM-based NFC offers a proven secure solution that is being commercially deployed today. The challenge for the mobile operator community is to simplify the provisioning process, further accelerating deployments of SIM-based NFC on a global basis.”

“MasterCard has been technology agnostic, enabling mobile payments in a way that allows current card accounts to be used seamlessly and securely from consumers’ favorite electronic devices,” said James Anderson, senior vice president of emerging payments, MasterCard. “We have deployed SIM and Secure Element-based solutions through partnerships with mobile network operators, OS providers and handset manufacturers, while recently adding support for cloud-based payments. This paper will help both the mobile and payments industries understand the strengths of each approach and allow them to choose the options that align with their business strategies.”

Report co-author Steve Pannifer, Head of Delivery at Consult Hyperion said: “The inclusion of HCE into Android has generated a lot of excitement that can only be good for NFC payments. This, combined with the efforts to streamline SIM Secure Element based NFC evident in many markets, will enable NFC payment products to be rolled out with renewed vigour. We hope that this paper will encourage banks and mobile operators to collaborate further in bringing NFC payments to the market. We believe the mobile operators have an important role to play, particularly in providing mobile security and authentication services that are paramount in any payments service.”

The guide shows that whilst HCE does indeed simplify some aspects of the NFC ecosystem by allowing mobile NFC payments to be performed without using a SIM Secure Element, this is only part of the landscape. HCE requires a new approach to security in terms of ecosystem integration, risk management and certification processes. In contrast, SIM Secure Element processes are well defined and mobile operators are actively working with the ecosystem to simplify them further.

The report examines the heritage of SIM-based NFC, the lessons learnt from the first deployments and the actions that have been taken to allow service providers to deploy secure, stable and proven mobile payment services at scale. The guide finds that whilst there is significant interest around HCE, the SIM Secure Element approach for mobile payments still has many complimentary advantages and it will be down to the banks to carefully review their needs in each of their operating markets.

“Both the People’s Bank of China (PBOC) and China UnionPay have released mobile payment specifications, which require a Secure Element to support NFC mobile payments, in order to provide a secure and reliable payment service. China UnionPay has worked very closely with Chinese operators on large-scale commercial NFC services based on the SIM as Secure Element. In conjunction, China UnionPay is working actively on a feasibility study of new technologies including HCE,” said Jiang Haijian, Deputy General Manager, Mobile Payment Dept., China UnionPay.

Consult Hyperion suggests that there are a number of key points for banks to consider as they plan mobile NFC payments:

  • Understand your local environment: The local conditions will play a big role in determining the best approach
  • Understand your target transactions: It is possible that HCE will be less suited to certain transaction types (e.g. offline, high value) than SIM Secure Element.
  • SIM Secure Element and HCE are not mutually exclusive: The most effective solutions over the medium term may be hybrid models where, for example, the SIM is used to address the security and authentication gaps in HCE.
  • Build flexibility into your strategy: There is likely to be considerable overlap between SIM Secure Element and HCE in terms of the systems and capabilities that are required
  • Collaborate with the industry: Until there is a level of standardisation around HCE, there remains the risk that banks could adopt solutions that are insufficiently flexible or lock the banks in.

David Baker, Head of the Card Innovation Payments Unit at the UK Card Association notes: “While Host Card Emulation has been hailed as a potential game changer for card-based NFC proximity payments, this report gives valuable advice and guidance on the issues the industry must address -- and highlights the real need for collaboration between ecosystem partners to ensure greater adoption of mobile payment services.”

The full report can be seen here

Note to Editors:

HCE is a recent feature of Android that allows an Android application to emulate a contactless card via the NFC interface of the handset; previously, this was reserved to applications stored in a secure chip or Secure Element, typically the SIM card, with similar security features as chip-and-PIN plastic cards. HCE opens the way to payment applications without a secure element, but such applications need to reach a satisfactory level of security. In order to achieve this, card schemes are developing a “tokenisation” approach, whereby the payment card identifier is replaced by a single use or limited use “token”. This reduces the impact of data breaches significantly: if a “token” is compromised it will have limited and possibly no value.

The guide was commissioned by the GSMA, 5 New Street Square, London, EC4A 3BF, United Kingdom. Any opinions, findings, and conclusions or recommendations expressed in the material are those of the author(s) and do not necessarily reflect those of the GSMA or its members.

About Consult Hyperion

Consult Hyperion is an independent information technology consultancy that has spent over two decades advising leading organisations around the world. Consult Hyperion helps these organisations to reap real benefits from technological change in the field of secure electronic transactions ranging from retail payments to mobile wallets to contactless transit ticketing. Consult Hyperion is uniquely qualified to advise on turning great business ideas into working systems that can help customers, and to evaluate new business concepts, develop new products and services from specification to customer roll-out, and to test and certify complex systems.

The four main sectors the company operates in are; financial services, with card schemes, banks, retailers and others; telecommunications and media, advising world leading companies; technology, to support some of the largest IT companies, and in the public sector and transit where projects include transit operators, government and law enforcement.

For more information visit Consult Hyperion, follow on Twitter @chyppings and keep up to date with the latest debate at Tomorrow’s Transactions Blog.

About the GSMA

The GSMA represents the interests of mobile operators worldwide. Spanning more than 220 countries, the GSMA unites nearly 800 of the world’s mobile operators with more than 250 companies in the broader mobile ecosystem, including handset makers, software companies, equipment providers and Internet companies, as well as organisations in industry sectors such as financial services, healthcare, media, transport and utilities. The GSMA also produces industry-leading events such as the Mobile World Congress and Mobile Asia Expo.

For more information, please visit the GSMA corporate website at www.gsma.com. Follow the GSMA on Twitter: @GSMA.

More Stories By Business Wire

Copyright © 2009 Business Wire. All rights reserved. Republication or redistribution of Business Wire content is expressly prohibited without the prior written consent of Business Wire. Business Wire shall not be liable for any errors or delays in the content, or for any actions taken in reliance thereon.

Latest Stories
SYS-CON Events announced today the DevOps Foundation Certification Course, being held June ?, 2015, in conjunction with DevOps Summit and 16th Cloud Expo at the Javits Center in New York City, NY. This sixteen (16) hour course provides an introduction to DevOps – the cultural and professional movement that stresses communication, collaboration, integration and automation in order to improve the flow of work between software developers and IT operations professionals. Improved workflows will res...
Docker is becoming very popular--we are seeing every major private and public cloud vendor racing to adopt it. It promises portability and interoperability, and is quickly becoming the currency of the Cloud. In his session at DevOps Summit, Bart Copeland, CEO of ActiveState, discussed why Docker is so important to the future of the cloud, but will also take a step back and show that Docker is actually only one piece of the puzzle. Copeland will outline the bigger picture of where Docker fits a...
A new definition of Big Data & the practical applications of the defined components & associated technical architecture models This presentation introduces a new definition of Big Data, along with the practical applications of the defined components and associated technical architecture models. In his session at Big Data Expo, Tony Shan will start with looking into the concept of Big Data and tracing back the first definition by Doug Laney, and then he will dive deep into the description of 3V...
Ayla Networks, whose agile Internet of Things (IoT) platform makes it easy for manufacturers to deliver secure, connected products, today announced it has been included in the list of "Cool Vendors" in the Internet of Things report by Gartner, Inc. “Gartner knows how important it is that manufacturers of all kinds of products have the right IoT solution to help turn their products into connected ‘things,’” said David Friedman, CEO and co-founder of Ayla Networks. “The market for Ayla’s IoT pla...
SYS-CON Events announced today that CenturyLink, Inc., a leader in the network services market, has been named “Platinum Sponsor” of SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. CenturyLink is the third largest telecommunications company in the United States and is recognized as a leader in the network services market by technology industry analyst firms. The company is a global leader in cloud infrastructure and ...
ScriptRock has been included in the list of "Cool Vendors" in the "Cool Vendors in DevOps 2015" report by Gartner, Inc.* ScriptRock provides visibility into the configuration state of an organization's IT environments, enabling the continuous delivery of mission critical services. For enterprises where downtime is not an option, ScriptRock's system-wide overwatch offers the assurance that misconfigurations and anomalies are caught before they affect the business. By satisfying this fundamental ...
As cloud gives an opportunity to businesses to buy services externally – how is cloud impacting your customers? In his General Session at 15th Cloud Expo, Fabio Gori, Director of Worldwide Cloud Marketing at Cisco, provided answers to big questions: Do you see hybrid cloud as where the world is going? What benefits does it bring? And how does Cisco connect all of these clouds? He also discussed Intercloud and Cisco’s investment on it.
SYS-CON Events announced today that B2Cloud, a provider of enterprise resource planning software, will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY. B2cloud develops the software you need. They have the ideal tools to help you work with your clients. B2Cloud’s main solutions include AGIS – ERP, CLOHC, AGIS – Invoice, and IZUM
The Internet of Things Maturity Model (IoTMM) is a qualitative method to gauge the growth and increasing impact of IoT capabilities in an IT environment from both a business and technology perspective. In his session at @ThingsExpo, Tony Shan will first scan the IoT landscape and investigate the major challenges and barriers. The key areas of consideration are identified to get started with IoT journey. He will then pinpoint the need of a tool for effective IoT adoption and implementation, whic...
SYS-CON Events announced today that MangoApps will exhibit at SYS-CON's 16th International Cloud Expo®, which will take place on June 9-11, 2015, at the Javits Center in New York City, NY., and the 17th International Cloud Expo®, which will take place on November 3–5, 2015, at the Santa Clara Convention Center in Santa Clara, CA. MangoApps provides private all-in-one social intranets allowing workers to securely collaborate from anywhere in the world and from any device. Social, mobile, and eas...
There is no doubt that Big Data is here and getting bigger every day. Building a Big Data infrastructure today is no easy task. There are an enormous number of choices for database engines and technologies. To make things even more challenging, requirements are getting more sophisticated, and the standard paradigm of supporting historical analytics queries is often just one facet of what is needed. As Big Data growth continues, organizations are demanding real-time access to data, allowing immed...
Containers and microservices have become topics of intense interest throughout the cloud developer and enterprise IT communities. Accordingly, attendees at the upcoming 16th Cloud Expo at the Javits Center in New York June 9-11 will find fresh new content in a new track called PaaS | Containers & Microservices Containers are not being considered for the first time by the cloud community, but a current era of re-consideration has pushed them to the top of the cloud agenda. With the launch ...
The world's leading Cloud event, Cloud Expo has launched Microservices Journal on the SYS-CON.com portal, featuring over 19,000 original articles, news stories, features, and blog entries. DevOps Journal is focused on this critical enterprise IT topic in the world of cloud computing. Microservices Journal offers top articles, news stories, and blog posts from the world's well-known experts and guarantees better exposure for its authors than any other publication. Follow new article posts on T...
So I guess we’ve officially entered a new era of lean and mean. I say this with the announcement of Ubuntu Snappy Core, “designed for lightweight cloud container hosts running Docker and for smart devices,” according to Canonical. “Snappy Ubuntu Core is the smallest Ubuntu available, designed for security and efficiency in devices or on the cloud.” This first version of Snappy Ubuntu Core features secure app containment and Docker 1.6 (1.5 in main release), is available on public clouds, ...
WebRTC defines no default signaling protocol, causing fragmentation between WebRTC silos. SIP and XMPP provide possibilities, but come with considerable complexity and are not designed for use in a web environment. In his session at @ThingsExpo, Matthew Hodgson, technical co-founder of the Matrix.org, discussed how Matrix is a new non-profit Open Source Project that defines both a new HTTP-based standard for VoIP & IM signaling and provides reference implementations.