Shiny Sreekumar 201 210 414 Gudenauer Weg 57 53127 Bonn [email protected]
Total Page:16
File Type:pdf, Size:1020Kb
Master Thesis Information Management Faculty of Computer Sciences University of Koblenz-Landau Biometric Authentication in Mobile Payments Supervisors: Prof. Dr. J. Felix Hampe Stefan Stein Submitted by: Shiny Sreekumar 201 210 414 Gudenauer Weg 57 53127 Bonn [email protected] Koblenz, September 2010 1 Acknowledgements I would like to acknowledge and thank all the people who contributed, in different ways, to the completion of this thesis: • Professor Dr. J. Felix Hampe for his guidance and support always and for pointing me in the right direction with new ideas. Above all, I am thankful for his undying patience. • Stefan Stein for his friendly assistance at all times. • Professor Elaine Lawrence and Dr. Agnieska Zmijewska who, through email exchanges, sent me relevant papers and answered any queries I might have had. • Lee Barr for the numerous iterations of proof-reading and pep-talks. • My mother and my dear friends for all their help, patience and understanding. Most of all, I would like to thank Alexandra Bohnet for constantly pushing, believing and the final “This is it” weekend! Without her, I could not have done this. Shiny Sreekumar Bonn, September 2010. Picture on title page put together by author using following sources: Pantech PG6200 Phone - (PC Welt, 2006); Fingerprint – (O'Gorman, 1999) Sound wave – www.nanobioart.com/nanolab/category/day7 ; Euro – www.wikipedia.org/wiki/Euro Shiny Sreekumar: Biometric Authentication in Mobile Payments 2 Abstract Mobile payment has been a payment option in the market for a long time now and was predicted to become a widely used payment method. However, over the years, the market penetration rate of mPayments has been relatively low, despite it having all characteristics required of a convenient payment method. The primary reason for this has been cited as a lack of customer acceptance mainly caused due to the lack of perceived security by the end-user. Although biometric authentication is not a new technology, it is experiencing a revival in the light of the present day terror threats and increased security requirements in various industries. The application of biometric authentication in mPayments is analysed here and a suitable biometric authentication method for use with mPayments is recommended. The issue of enrolment, human and technical factors to be considered are discussed and the STOF business model is applied to a BiMoP (biometric mPayment) application. Keywords: Biometric Authentication, mPayments, Speaker Recognition, Fingerprint Recognition, Enrolment, Customer Acceptance, STOF Model. Shiny Sreekumar: Biometric Authentication in Mobile Payments 3 Table of Contents Acknowledgements..................................................................................................... 1 Abstract....................................................................................................................... 2 Table of Contents ....................................................................................................... 3 List of Figures............................................................................................................. 5 List of Abbreviations ................................................................................................. 6 List of Abbreviations ................................................................................................. 6 1. Introduction and Overview ............................................................................... 8 1.1. Motivation............................................................................................. 10 1.2. Scope of the Thesis ............................................................................... 11 1.3. Research Questions............................................................................... 11 1.4. Research Methodology.......................................................................... 12 1.5. Thesis Structure..................................................................................... 12 2. Mobile Payments – An Overview.................................................................... 13 2.1. Definition .............................................................................................. 13 2.2. Important Aspects of mPayments ......................................................... 16 2.2.1. Classification of mPayment Transactions..................................... 16 2.2.2. Players in the mPayment Scenario................................................ 17 2.2.3. The Payment Life-Cycle............................................................... 23 2.3. The mPayment Value – Chain .............................................................. 26 2.4. The Mobile Payment Reference Model ................................................ 28 2.5. Contemporary Security in mPayments ................................................. 33 2.5.1. Payment Security Features............................................................ 34 2.5.2. Authentication – The Key Security Issue...................................... 36 3. Identifying a Biometric for mPayment Systems............................................ 40 3.1. The Basics of Biometrics ...................................................................... 40 3.1.1. Definition ...................................................................................... 41 3.1.2. Categories of Biometrics............................................................... 41 3.1.3. Reasons for using Biometrics........................................................ 43 3.1.4. Identification Vs. Verification ...................................................... 45 3.1.5. Biometric Performance Metrics.................................................... 46 3.2. Using Biometrics in MPayment Systems.............................................. 49 3.2.1. Selecting a Biometric – The Criteria Catalogue ........................... 51 3.2.2. Selecting a Biometric – Possible Alternatives .............................. 55 Shiny Sreekumar: Biometric Authentication in Mobile Payments 4 4. The Market Picture – A Look at Different Continents ................................ 67 4.1. Asia ....................................................................................................... 68 4.1.1. Japan.............................................................................................. 68 4.1.2. Singapore ...................................................................................... 73 4.1.3. India............................................................................................... 74 4.1.4. Australia........................................................................................ 81 4.2. Europe ................................................................................................... 84 4.2.1. Germany........................................................................................ 84 4.2.2. Norway.......................................................................................... 89 4.3. North America....................................................................................... 90 4.3.1. United States of America.............................................................. 90 4.3.2. Canada........................................................................................... 94 5. Using Biometrics in an mPayment Scenario.................................................. 98 5.1. The Issue of Enrolment......................................................................... 98 5.1.2. The Enrolment Process ............................................................... 101 5.2. Factors affecting “Biometric” mPayment Systems............................. 109 5.2.1. Technical Factors ........................................................................ 110 5.2.2. Economic Factors........................................................................ 115 5.2.3. Human Factors ............................................................................ 116 5.3. Customer Acceptance – Issues in the area of Biometrics & mPayments 120 5.3.1. User-Centric Classifying Model ................................................. 121 5.4. Carrying out Customer Enrolment – Appropriate Player ................... 127 5.4.1. MNOs.......................................................................................... 128 5.4.2. BANKS ....................................................................................... 130 6. Prospective Business Model for a BiMoP Application ............................... 133 6.1. The STOF Model ............................................................................... 134 6.1.1. Service Domain........................................................................... 136 6.1.2. Technology Domain.................................................................... 139 6.1.3. Organization Domain.................................................................. 143 6.1.4. Financial Domain........................................................................ 147 7. Summary & Conclusion ................................................................................ 150 7.1. Summary............................................................................................. 150 7.2. Conclusion & Future Outlook............................................................. 152 Literature List .......................................................................................................