When the Card is Not Present

Protect, Organize and Communicate
 
Barclays’ PINsentry uses dynamic authentication via a CAP reader
EMV is also helpful for authentication when the card is not present, i.e. online or over the phone. EMV cards and the EMV back-end authentication infrastructure are very well suited as a base for strong, dynamic cardholder authentication using one-time passwords (OTP). The card can verify the cardholder’s PIN offline, either with the help of a small hand-held card reader device (e.g. Barclays PINsentry, and then produce an OTP, which is displayed on the device or on a small display embedded in the card.

During an online transaction, the cardholder transmits this OTP to the issuing bank who is then in a position to verify the OTP using its EMV back-end authentication system. This constitutes dynamic two-factor authentication (2FA) on the base of something you have and something you know. Handheld readers have been distributed to tens of millions of cardholders in Europe and Asia.

When these devices are used, online banking fraud has experienced significant reduction.

It is worth noting that weak authentication in the non-face-to-face world is at the root of much of the negative news on data breaches and identity thefts. Indeed, identity theft has ranked first among complaints to the U.S. Federal Trade Commission for 11 consecutive years, with 1.34 million in 2010, twice as many as in the next category, which is debt collection. Much of that theft could be avoided if authentication in non-face-to-face situations would not only be based on something you know (i.e. something could be stolen from a database) but would be made much stronger by, for example, using OTPs generated by EMV cards.
 

<< Back: EMV Security Next: Benefits of EMV to Issuers and Merchants >>
 
 

<< Back: Overview

   

See also....

More info on Ezio EMV Authentication Solution

Protect e-banking services using the payment card

Gemalto offers a range of readers for securing online transactions using the smart payment card.

The Top Five Reasons to Use
Digital Security Devices With eBanking

Gemalto Blog

5 reasons to up eBanking security

External Links

Has Barclays stamped out fraud with PINsentry?

FTC: ID Theft Again Tops Consumer Complaints