new security considerations for mobile commerce

16
New Security Considerations in Mobile Commerce Pragati Ogal Rai Mobile Technology Evangelist X.commerce (an eBay Inc. Company)

Upload: pragati-ogal-rai

Post on 22-May-2015

982 views

Category:

Technology


1 download

DESCRIPTION

This is the presentation presented at Amphion Forum, Washington D.C. on June 27, 2012.

TRANSCRIPT

Page 1: New Security Considerations for Mobile Commerce

New Security Considerations in Mobile Commerce

Pragati Ogal RaiMobile Technology Evangelist

X.commerce (an eBay Inc. Company)

Page 2: New Security Considerations for Mobile Commerce

X.commerce: Largest Ecosystem of Commerce Capabilities

04/12/2023 2

Consumer Products

Merchant Products

Platform Products

Capabilities

Other Storefronts

X.commerce Fabric

MerchantProducts

OVER 800,000 DEVELOPERSCommunity

Page 3: New Security Considerations for Mobile Commerce

Agenda

What is m-commerce?

M-commerce ecosystem

Use cases & security analysis

Standards

Best Practices

Page 4: New Security Considerations for Mobile Commerce

Mobile is Changing Commerce

Promotions & coupons

Mobile commerce

Payments

Location-based services

In-store research

Self-scanning & self-checkout

Social commerce

Loyalty

Mobile shopping lists

Page 5: New Security Considerations for Mobile Commerce

Mobile is Changing Commerce

Pre-transaction

In-store

Transaction

Post transaction

End-to-end security

Page 6: New Security Considerations for Mobile Commerce

So what’s different with m-commerce?

Too many expectations

New market players and dynamics

Limitations of client devices

Portability

Pervasive computing

Location aware devices

Merchant machines

Standardization & approvals

Page 7: New Security Considerations for Mobile Commerce

Infrastructure

Clients Merchants

M-commerce Ecosystem

Page 8: New Security Considerations for Mobile Commerce

Disconnected: Off-line m-commerce

• Disconnected

• Privacy

• Integrity of State

Page 9: New Security Considerations for Mobile Commerce

Partial Connectivity: Infrastructure Centric Model

Page 10: New Security Considerations for Mobile Commerce

Partial Connectivity: Merchant Centric Model

Page 11: New Security Considerations for Mobile Commerce

Partial Connectivity: Client Centric Model

Page 12: New Security Considerations for Mobile Commerce

Partial Connectivity: Security Analysis

End to end security

Privacy

Client-merchant identification

Communication authentication

More points of attack

Page 13: New Security Considerations for Mobile Commerce

Full Connectivity

• End to end security

Page 14: New Security Considerations for Mobile Commerce

PCI Standard

Standard for payment industry

PCI PTS approved add-on devices

PA DSS approved applications

Working with mobile vendors for further solutions around

mobile payments

Page 15: New Security Considerations for Mobile Commerce

Best Practices

Understand what mobile means for your business

Security asset identification/ threat analysis

Technology analysis

Be aware of emerging standards

Risk and fraud algorithms

Page 16: New Security Considerations for Mobile Commerce

Thank you!

[email protected]@pragatiogal

http://www.slideshare.net/pragatiogal