ECSG Contactless Feasibility Study
Total Page:16
File Type:pdf, Size:1020Kb
ERPB/2017/014 ECSG066-17 (v1.0) [X] Public – [ ] Internal Use – [ ] Confidential – [ ] Strictest Confidence Distribution: ERPB European Cards Stakeholders Group Final report Feasibility Study on the development of open specifications for a card and mobile contactless payment application 28 September 2017 THIS DOCUMENT IS BEING OFFERED WITHOUT ANY WARRANTY WHATSOEVER, AND IN PARTICULAR, ANY WARRANTY OF NON-INFRINGEMENT IS EXPRESSLY DISCLAIMED. ANY USE OF THIS DOCUMENT SHALL BE MADE ENTIRELY AT THE IMPLEMENTER'S OWN RISK, AND NEITHER EUROPEAN CARDS STAKEHOLDERS GROUP AISBL (“ECSG”), NOR ANY OF ITS MEMBERS, SHALL HAVE ANY LIABILITY WHATSOEVER TO ANY IMPLEMENTER FOR ANY DAMAGES OF ANY NATURE WHATSOEVER, DIRECTLY OR INDIRECTLY, ARISING FROM THE USE OF THIS DOCUMENT, NOR SHALL ECSG OR ANY OF ITS MEMBERS HAVE ANY RESPONSIBILITY FOR IDENTIFYING ANY INTELLECTUAL PROPERTY RIGHTS European Cards Stakeholders Group AISBL - Cours Saint-Michel 30 - B 1040 Brussels Tel: +32 2 733 35 33 Fax: +32 2 736 49 88 Enterprise N° 656.829.362 www.e-csg.eu [email protected] ERPB/2017/014 Contents 1 Feasibility Study on the development of open specifications for a card and mobile contactless payment application ............................................ 3 1.1 Background and Purpose ....................................................................................... 3 1.2 Executive Summary ................................................................................................ 4 1.3 Structure of the report ............................................................................................. 6 2 Current Deployment of Contactless Specifications ............................ 7 3 ECSG sectors’ analysis on the Issuing domain. ................................. 8 3.1.1 Common Payment Application Contactless Extension ............................................................. 8 3.1.2 PURE ......................................................................................................................................... 8 4 Acceptance domain. ............................................................................ 10 4.1 Scope of the ECSG sectors’ analysis ................................................................... 10 4.1.1 Analysis outline ........................................................................................................................ 10 4.1.2 ECSG assessment .................................................................................................................. 11 4.2 Acceptance side considerations. .......................................................................... 11 4.2.1 Benefits of using an existing kernel as the common open POI contactless kernel ................. 11 4.2.2 Substantial impact on direct cost ............................................................................................. 11 4.2.3 Indirect costs and time to market aspects. .............................................................................. 12 4.2.4 Implications of implementing a common Kernel ...................................................................... 12 4.3 EMV 2nd Generation ............................................................................................ 13 5 European Contactless market ............................................................ 14 5.1 European Market development of Contactless card payments. ............................ 14 5.2 Specific market developments .............................................................................. 15 6 Conclusion ........................................................................................... 17 7 Annex: ECSG Analysis ........................................................................ 18 7.1 SWOT analysis common European Open Contactless POI specification ............. 18 Page 2 of 19 ERPB/2017/014 1 Feasibility Study on the development of open specifications for a card and mobile contactless payment application 1.1 Background and Purpose During its November 2015 meeting, the ERPB recommendation ERPB/2015/rec 10/ii was addressed to the CSG, requesting them to: “Conduct a feasibility study on the development of open specifications for a card and mobile contactless payment application, as well as on their implementation, maintenance and testing. For mobile applications, the open specifications should also address the different possible configurations for the management, provision and personalisation of the card data: secure element (SE, including universal integrated circuit card (UICC), embedded SE and microSD) and host card emulation (HCE). The future specifications should build on the work of EMVCo and GlobalPlatform.” (December 2016) This ERPB recommendation was based on the following identified Issue/Rationale: “The standardisation of open specifications for a card and mobile contactless payment application could allow payment application developers and card manufacturers to achieve economies of scale and would lower the cost of these items for the issuers, thereby fostering contactless adoption. The specification of common POI implementation guidelines will lead to a more uniform payment experience, for both the consumer and the merchant.” Note 1: The ERPB also addressed ERPB/2015/rec 8/i recommendation to EMVCo, to: “Speed up the creation of a single common POI kernel specification for contactless transactions (already planned under EMV 2nd Generation specification) and make the specifications publicly available as soon as possible.” (December 2016). This was based on the following Issue/Rationale: Multiple standards with a variety of options are currently present in the market. The rationale is to streamline the standards used in the industry. Note 2: The other aspects relating to ERPB recommendation ERPB/2015/rec 10 have been addressed by the publication of the SCS Volume Version 8.0 Page 3 of 19 ERPB/2017/014 1.2 Executive Summary In responding to the ERPB request to “Conduct a feasibility study on the development of open specifications for a card and mobile contactless payment application, as well as on their implementation, maintenance and testing.”, the ECSG held discussions with the relevant stakeholders. During these discussions several considerations and observation were made, and some key facts highlighted: 1. Contactless card usage is growing fast and at an increasing rate, and continued growth is expected during the coming months1. 2. The existing acceptance specifications for contactless card payments have been developed over the last 10 years with a different approach from contact cards. There are over 7 POI kernels, which need to be developed, tested, installed and maintained to ensure the acceptance of all contactless solutions. On the acceptance side, some sectors are raising concerns on this situation. 3. EMVCo has announced that the EMV 2nd Gen specs which, as well as upgrades to security and support for new innovative products and services, will also provide a common POI Kernel. The implementation of EMV 2nd Gen is expected to require large investments and an implementation period of several years. 4. On the contactless issuing specification side, at least 2 initiatives (CPACE, PURE) are making specifications available to the market (in one case subject to licensing agreement). A description of these initiatives is given later. 5. Migrating to a common contactless kernel based on current technology mitigates some of the issues associated with multiple kernels, but not all. In addition, it brings additional complexity of supporting ‘new and old’ during a migration period. Migration to a common contactless kernel based on current generation in parallel to the development of 2nd generation specifications introduces a further risk of a double migration; from multiple contactless kernels to a single one, and then to 2nd Generation payments. In view of these considerations, the acceptance side of the contactless payment card market needed a deeper discussion. The discussion on the acceptance side of the market was to evaluate the best strategy for reducing complexity of contactless acceptance. To conduct the evaluation, the ECSG performed research on the following 2 scenarios2: 1. The feasibility of using one of the existing EMVCo contactless kernels as an open SEPA contactless kernel, made available to all interested parties licence free, by the kernel owner, without precluding the use of any existing kernels 1 Adrian Buckle, chief economist at Payments UK, said: "The popularity of contactless means that we expect debit cards to overtake cash as the UK's most frequently used payment method in late 2018, three years earlier than we previously thought”. 2 In arriving at these two scenarios, the ECSG had discussed during its Board meeting in February 2017 whether it would make any sense to develop another kernel on top of the existing seven, if one of the existing kernels could meet the objective of a common contactless kernel, before the deployment of EMV 2nd Gen , and determined it would not. Page 4 of 19 ERPB/2017/014 2. Migrating to EMV 2nd Gen and the common contactless kernel defined within that specification as the ‘SEPA kernel’ The ECSG research consisted of a SWOT analysis, which arrived at the finding that in migrating to either one existing single kernel or EMV 2nd Gen, the disadvantages largely outweigh any benefits with regard to the requested investigation study. Scenario 1 could be considered as an intermediate step using existing kernel(s) as an open