Top Banner
1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager
28

1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

Dec 19, 2015

Download

Documents

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

1

Parex bank experience withDigipass tokens

Deniss Vorona

Online Banking Project Manager

Page 2: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

2

Who We Are

• A leading Latvian bank

• Branches and Representative offices in Europe (Latvia, Lithuania, Estonia, UK, Germany, Sweden,..), Russia and other CIS countries, Japan.

• Two subsidiary banks offer services in Lithuania (Parex Bankas) and Switzerland (AP Anlage und Privatbank)

Page 3: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

3

History:Milestones

• 1992: first client

• 1994: first payment card

• 1996: first Digipass tokens are used for fax banking

• 2001: first user performs online banking transaction

Page 4: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

4

History:Previous Security Schemes

• Homebrew code card, which required manual computation with factored in payment parameters. It was used for:

– Fax banking

– Remote banking application (modem-based)

• PGP for email banking

Page 5: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

5

History:Digipass Tokens Advantages

• Secure

• Easy to use

• Mobile

• Unconnected

• No installation/software support

• Cannot be copied

• Adheres to Electronic signature law

Page 6: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

6

History:A Simple Solution

• A separate application, not connected to banking system

• Manual signature verification

• Printing slips of verification success

Page 7: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

7

Token Usage

• Online banking (digi.parex.lv)

– Login (dynamic password)

– Document signatures

• Fax banking

• Access to the safes

Page 8: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

8

Token Applications

• Dynamic password (time-based response only)

• Signature

Page 9: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

9

Signature Parameters

• Payer account number

• Amount

• Currency code

• Beneficiary account number

Page 10: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

10

Online Banking Login

Page 11: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

11

Online Banking Login

Page 12: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

12

Payment Signature

Page 13: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

13

Payment Confirmation - Go3

Page 14: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

14

System Architecture

Online banking Core banking system

Authorization server Administrative tool

Page 15: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

15

Authorization Server Functions

• Token data

• Token lock/unlock

• Logging

• Signature rights management

• Document uniqueness control

Page 16: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

16

Separate Server Advantages

• Authorization server has stable and strict interfaces which are very rarely changed

• Easy to offer Digipass-based services in other banks within Parex Group

Page 17: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

17

Simple Architecture

Operator tool

Authorization server Administrative tool

Page 18: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

18

Tokens Used

Tokens issued in the past:

• DP500

• DP560

Tokens issued now:

• DP700

• Go3

Page 19: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

19

Tokens Used

• Dp500– A good model with a

calculator– Not supplied anymore

Page 20: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

20

Tokens Used

• Dp560– Dp500 successor– Stylish design– Good for the average

user– Better battery life– Messages in several

languages

Page 21: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

21

Tokens Used

• Dp700– Good for heavy use– Best for signatures– Messages in two

languages– Target audience:

businesses, active users

Page 22: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

22

Tokens Used

• Go3– Easy to use– Target audience:

private customers

Page 23: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

23

Transaction Statistics

0

500000

1000000

1996

1998

2000

2002

2004

2006

1996 < 1000

1997 ~ 80000

1998 ~ 190000

1999 ~ 350000

2000 ~ 550000

Page 24: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

24

Situation in Latvia

• At least 9 out of 23 commercial banks offer services using Digipass tokens

• ID-cards (smart cards issued by the state) are not used to secure online banks

• State web sites tend to use Online banks to secure e-services

Page 25: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

25

Implementation Challenges

• Clear strategy• Difficult to phase out old services• Managers are hard to convince• Clients are hard to convince - not all are security-

conscious• Price

Page 26: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

26

Implementation Challenges

• Planning token configuration for the future

• User experience

• Instructions

Page 27: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

27

Questions?

Don’t hesitate to ask!

Page 28: 1 Parex bank experience with Digipass tokens Deniss Vorona Online Banking Project Manager.

28

Conclusion

Think about security before

your clients have to!