Bancontact is a very popular payment method in Belgium for the purchase of goods and services, either online or in-store. It offers secure and reliable debit card payments.
How to certify your SoftPOS solution with MPoC ?
The new security standard enables SoftPOS providers to certify that their solutions for contactless payment on COTS meet the security requirements, ensuring the accurate protection of cardholder data in a tap on phone / tap to phone / tap on mobile environment. The crucial challenge for SoftPOS solution providers is to ensure that their products integrate the highest level of protection of sensitive data and comply with the new PCI MPoC standard.
Not to be mistaken with EFTPOS (Electronic Fund Transfer at Point of Sales), eftpos is the Australian electronic payment system, created 40 years ago to provide australian citizens with an electronic mean of payment for in-store purchase of goods and services, and more.
Since its release last November, MPoC has generated lots of enthusiasm and questioning from all payment industry stakeholders, as it drives a major step towards unifying security requirements for contactless payment on COTS.
A recent communication from Visa Tap to Phone team gave a timeline for Visa Ready SoftPOS solutions to be certified with MPoC, the new PCI security standard defining the required protection mechanisms for safeguarding sensitive data processed during transactions initiated through SoftPOS.
As the industry focuses on the new requirements to build secure software-based payment acceptance solutions,…
Unlike international payment schemes, domestic payment networks process electronic transactions within a national territory. The advantages for payment solution providers offering payment terminals that support both international payments and domestic payment networks is that they benefit an extended deployment market.
What are the benefits of test automation during payment terminal certification ?
Test automation consists in implementing an automatic communication interface between a device under test and a test tool, to check the behavior of a software with minimal human intervention. Major payment schemes such as Visa and Mastercard have published guidelines allowing payment terminal providers to build a communication interface compliant with the test automation requirements.
Focus on tokenisation in transit environment.
Indeed, the transformation of the card data in Card Number Alias or token enables to connect a card number to an individual card holder or an event.
This transformation is performed by cryptography computation.
The computation will always generate the same token for the same card if the same algorithm is used. This algorithm is a one way function, so, there’s no possibility to translate from a token to a card number.
The development of embedded software is a crucial step in the overall payment terminal manufacturing process. Payment devices can only be deployed when they prove compliance with international payment and security standards. Hence the integration and approval of EMV payment software is at the core of terminal manufacturers’ concerns.
The new CPACE standard was created by the ECPC to facilitate contactless payments in Europe. The CPACE ( Common Payment Application Contactless Extension) specifications were built on the EMVCo CPA standard for contact transactions, and was extended for contactless and remote payments.