Tomorrow's Transactions » gsma http://tomorrowstransactions.com Thought leadership from Consult Hyperion Wed, 10 Sep 2014 20:33:30 +0000 en-US hourly 1 http://wordpress.org/?v=4.0 Yep, people are interested in NFC again http://tomorrowstransactions.com/2014/02/yep-people-are-interested-in-nfc-again/ http://tomorrowstransactions.com/2014/02/yep-people-are-interested-in-nfc-again/#comments Tue, 04 Feb 2014 17:55:18 +0000 http://tomorrowstransactions.com/?p=3863 As we head back to Barcelona for Mobile World Congress again, there’s more talk about NFC and this time it’s not only coming from the operators. In her state of the industry address at the GSMA NFC & Mobile Money Summit last fall in New York, GSMA Director General Anne Bouverot said that NFC is […]

The post Yep, people are interested in NFC again appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

As we head back to Barcelona for Mobile World Congress again, there’s more talk about NFC and this time it’s not only coming from the operators.

In her state of the industry address at the GSMA NFC & Mobile Money Summit last fall in New York, GSMA Director General Anne Bouverot said that NFC is gaining traction globally, and it is certainly true the the number of handsets sold with NFC capabilities is steadily rising, even if most consumers neither know nor care that they have NFC. But it’s not just in phones: NFC is springing up in TVs, printers, cameras and all sorts of other consumer electronics. In our corner of the transaction treehouse, however, NFC means making contactless payments in retail environments. This hasn’t been going so well. As I said at the time, consumers can’t use NFC to ride the bus, which was my throwaway and prosaic benchmark of mass-market acceptability. But they might soon.

Madrid-based non-public bus operator Jiménez constellation is to introduce a brand new cloud-based NFC ticketing resolution that allows Nexus five NFC phones to be used as contactless ticketing readers at a “fraction of the value of ancient contactless reader infrastructures”. Ticktrack, developed by Spanish startup Aditium, uses host card emulation (HCE)…

[From Spanish bus drivers to check tickets using NFC host card emulation - NFC Business Cards]

Interesting. Something has changed. There were handsets out there. There were announcements all the time about pilots, trials and even live services. But somehow the technology was (and is, to be honest) struggling to gain traction, and every time that Apple announce a new phone without NFC there are a plethora of articles about the death of NFC. If you do have a handset with NFC in it, let’s say one of the super new Samsung S4s, you can’t use it for much interesting. I can’t log in to my bank and load my credit card onto it, for example. All I can do with the NFC on my Android phone is use it as a slightly more convenient version of a QR code. Except in Canada, where I could download my Tim Horton app and buy coffee with a tap.

Something has definitely changed. What? Well, here’s a framing of problem that I often hear. The GSMA (and others) opted for an architecture that put the mobile operators in control. And there’s nothing wrong with that. The GSMA is the mobile operators. But — and let’s be frank, to move the sector forward — the banks and operators have found it difficult to work together. I don’t want to cause trouble, especially since Consult Hyperion advises both banks and operators, but I think we have to be honest and open up the discussions that everyone knows are going on behind closed doors.

These MNOs operate a TSM service and establish the trust. Technically perfect, but this is also the problem that get things stuck. It has no technical issues, it is political. The banks just do not want the MNOs in their food chain.

[From EMV compliant NFC transaction from a mobile phone | The Abrantix Blog]

Maybe. And there is certainly evidence from the marketplace that banks will go to some lengths in order to avoid having to deal with the MNOs. This is despite countless attempts to work together. Personally, I suspect that some of this is down to the sheer hassle of it as much as it is to deep-seated strategic aversion to the Single-Wire Protocol (SWP), but it is nonetheless an observable phenomenon.

Bank of China (Hong Kong) is to introduce a microSD card based NFC payments service before the end of the year… BOC e-Wallet will initially be available for the Samsung Galaxy S4 LTE, Galaxy S III LTE, Galaxy Note II LTE, Galaxy S4, Galaxy Note II, Galaxy S III and LG Optimus G Pro smartphones.

[From Bank of China launches NFC payments in Hong Kong • NFC World]

Phones such as the S4, as noted, already have NFC. So, you might wonder, why bother putting a microSD NFC card into a phone that already has it if not to go around the MNO? This is the nub of the problem. In the complicated (but, let’s be clear, very secure) SIM-based SE model, the MNO calls the shots. And that has turned out to be a significant barrier to progress. It’s not impermeable: in some places (Canada and Australia spring to mind) where there are highly concentrated industries (ie, a small number of big banks and a couple of dominant MNOs) and a determination to work together despite thin margins there are now multiple handsets and multiple banks with functioning implementations in the market.

So what has changed? Why are the Canadian coffee chain and the Spanish bus company investing in NFC ? Well, the most interesting case study from Mobile World Congress last year was, as I have said before, BankInter in Spain. They launched what we called at the time a “NOSE” (NO Secure Element) payment service that uses tokenization to shift the risk analysis balance away from SE levels of security. The reason why this was such an interesting case study was that Bank Inter own an MNO. When you own an MNO, and still find it too much hassle to launch a SIM-based NFC payment service, that has to tell you something about the chosen model. Last year I called it an earthquake, and I stand by that.

Technically, what they did was to use a version of Android that had Host Card Emulation (HCE). At high level, this means that handset can pretend to be a payment card rather than having to have the SIM involved. When last year Google announced that HCE would become part of Android and that there would be no need to patch any more, a lot of people suddenly regained interested in the technology. The responses to this technology change have been very interesting indeed, as they seem to indicate considerable latent demand for a technology that we were being told was finished.

“With the entry of HCE we are free”

[From Spanish bus drivers to check tickets using NFC host card emulation • NFC World]

It wasn’t the technology that was the problem, it was the business model. Having previously criticised the SIM-centric model (with genuine integrity and, I think experience has shown, real cause), I stand in testament to the GSMA’s commitment to explore different views on this important topic and I am delighted to be able confirm that I will be giving part of the breakfast briefing on “HCE: NFC Threat or Opportunity” at the Mobile World Congress in Barcleona on Wednesday 26th February at 8.30am. I am genuinely looking forward to this as I personally think that there is an opportunity for mobile operators to use HCE to revitalise NFC in the mass market and, along with BLE, find new and more flexible business models that will make sense to financial services and other sectors. I expect to learn a lot from my fellow panelists and I look forward to seeing you all there.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Yep, people are interested in NFC again appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/02/yep-people-are-interested-in-nfc-again/feed/ 2
Service Opportunities for Mobile Identity http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/ http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/#comments Tue, 28 Jan 2014 09:53:24 +0000 http://tomorrowstransactions.com/?p=3285 I still think that mobile identity is a real opportunity for mobile operators to provide a valuable service and occupy a key position in the future value network. At the Mobile Identity event in London last November, where I was the chair for the second day, I was challenging the speakers to identify barriers to […]

The post Service Opportunities for Mobile Identity appeared first on Tomorrow's Transactions.

]]>
Dgwb blog white border

I still think that mobile identity is a real opportunity for mobile operators to provide a valuable service and occupy a key position in the future value network.

At the Mobile Identity event in London last November, where I was the chair for the second day, I was challenging the speakers to identify barriers to the large-scale deployment of identity services that use the mobile phone to provide practical and convenient identity management tools. After all, I’ve been going to conferences where the opportunities for mobile operators in the identity space have been discussed for at least a decade – and the first Consult Hyperion project on mobile identity that I can remember was in the late 1990s – yet when my card issuer suspected fraud recently they still had to call me (despite their having an app on my smart phone). Why not use the obvious characteristics of the phone to make, in this instance, card payments more secure. Actually, there are folks out there working on this sort of thing.

FICO, a leading predictive analytics and decision management software company, announced the availability of a new proximity correlation service for credit and debit card issuers which is aimed at improving the safety of payment card transactions. The new FICO service which several UK banks are planning to deploy has been developed in partnership with ValidSoft.

[From FICO adoption of ValidSoft Technology brings Safety of Payment Card Transactions to UK Banks - MarketWatch]

This is only one use case. Christophe Enzinger from the GSMA Mobile Identity Program made the point that mobile identity is infrastructural and has applications across communications, commerce, health and other sectors. I agree (strongly) with this infrastructural view. So how, in practice, can the mobile operators take advantage of this potential? Christophe’s very good suggestions included making upfront customer propositions around security and previously, making these essential components of the offer from operators to consumers, and Philippe Clement (the Head of Group Identity Marketing at Orange) develop edsome ideas around the practical deployment of such’s services by talking about identity APIs and their use in apps.

The Icelandic case study presented by Haraldur Bjarnson (the CEO of Audkenni) showed one approach. Their bank-owned consortium, which has been delivering identity services using the Icelandic debit card system (the debit cards have a digital ID certificate on them and about 40% of consumers have activated it), is shifting to a mobile electronic identity solution instead. This includes swapping consumers’s SIMs for SIMs with a PKI application on board. This, I think, is an interesting decision. It costs money to send out new SIMs and it’s a hassle for the users, so the operators must be pretty sure that the consumers will want and will use these services.

Rupert Hill from EE extended the discussion beyond personal by talking about the machine-to-machine (M2M) opportunities. As I had only just written something about the missing identity layer in the “Internet of things” I was very interested to see him attaching such a high priority to the Internet of things in the context of identity services.Some of the issues that need to addressed here are really rather complex. How can I delegate authority to my car? How will you know that it is my car? How will my car know that you are really a policeman? Solving these problems could be a huge business for the mobile operators is they could a) solve them and b) turn the solutions into a business.

What business, though? There are, as we have discussed before, different roles for mobile operators in the identity value network. Sergio Cozzolino from Telecom Italia talked about the difference between providing identity infrastructure and providing identity services, and explored the really useful distinction between mobile operators as identity providers and mobile operators and identity brokers. As Sergio noted, these different roles have different liability models and can allow stakeholders to develop the best business solutions choosing the appropriate liabilities. He talked through the use of SIM-based Secure Element (SE) and PKI applications as the mobile operators preferred solution. (He also, to be fair, explained the obstacles to success with this architecture).

I found the day really useful as it was an opportunity to chat with practitioners in order to get an accurate picture of the state of the sector, but afterwards I remember thinking that I was not sure that my initial challenge had been met. I still don’t really understand why the operators don’t get together and do something in this space. It seems completely ridiculous that with a smartphone running my card issuer’s app in front of me, I still have to phone them up, punch in a PAN and try to remember the answer to “security” questions to get anything done. And it’s even more ridiculous that they have to phone me up, and ask me yet more “security” questions when they want to interact with me, despite the phone company knowing perfectly who I am and where I am. Nevertheless, if you look around, you can see signals for change and mobile operators beginning to exploit potential around identity and authentication, so I think that my continued optimism about the potential for mobile operators to provide mobile identity services remains justified.

Payfone will use an AT&T application programming interface (API) toolkit to access network data that adds to Payfone’s existing service. Using the API toolkit, Payfone’s service will allow businesses to confirm that the device being used during a transaction is authenticated on AT&T’s mobile network.

[From Payfone Strikes Deal with AT&T to Verify Mobile Identity | AT&T]

As I have long been enthusiastic about this more infrastructural approach and the use of APIs to “cement” mobile operators into that infrastructure, I’m very keen to learn more about the latest developments in this areas. So the very good news is that I’m going to get the chance to discuss these issues with the operators themselves — and a great many other people  — at the Mobile World Congress in Barcelona. The GSMA have very kindly invited me to chair a session on “Service Opportunities for Mobile Identity” on Thursday 27th February from 11.30 to 13.00 and I’m genuinely looking forward to it. We’ll be in Hall 4, Auditorium 5 and I will have the honour and pleasure of charing Bjørn Hansen (Chief Scientist, Telenor Research), Siim Sikkut (National ICT Policy Advisor, Government Office of Estonia), Robert Blumenthal (EVP Business Development at SecureKey Technologies) and Steve Shoaff (CEO of Unbound ID). I look forward to seeing you all there and joining in the debate.

These are the personal opinions of Consult Hyperion and its guests and should not be misunderstood as representing the opinion of its clients or suppliers. To discuss how any of the technologies discussed in this post can benefit your business, please contact Consult Hyperion.

The post Service Opportunities for Mobile Identity appeared first on Tomorrow's Transactions.

]]>
http://tomorrowstransactions.com/2014/01/service-opportunities-for-mobile-identity/feed/ 1