To deploy at a global scale, payment terminal providers must develop their products in compliance with the international payment standard EMV. EMV technology ensures interoperability and secure payment transactions, contact or contactless. EMV contactless specifications are structured into different books, describing the requirements and functionalities that POS systems must comply with to be approved.
PCI MPoC certification is a challenge for SoftPOS providers, but they can optimize the scope of the evaluation.
The current challenge for all players involved in the tap to phone technology is to evaluate the best strategy to easily and rapidly comply with the new specification from the PCI Security Standard and fast track their product deployment.
Bancontact is a very popular payment method in Belgium for the purchase of goods and services, either online or in-store. It offers secure and reliable debit card payments.
How to certify your SoftPOS solution with MPoC ?
The new security standard enables SoftPOS providers to certify that their solutions for contactless payment on COTS meet the security requirements, ensuring the accurate protection of cardholder data in a tap on phone / tap to phone / tap on mobile environment. The crucial challenge for SoftPOS solution providers is to ensure that their products integrate the highest level of protection of sensitive data and comply with the new PCI MPoC standard.
Not to be mistaken with EFTPOS (Electronic Fund Transfer at Point of Sales), eftpos is the Australian electronic payment system, created 40 years ago to provide australian citizens with an electronic mean of payment for in-store purchase of goods and services, and more.
Since its release last November, MPoC has generated lots of enthusiasm and questioning from all payment industry stakeholders, as it drives a major step towards unifying security requirements for contactless payment on COTS.
A recent communication from Visa Tap to Phone team gave a timeline for Visa Ready SoftPOS solutions to be certified with MPoC, the new PCI security standard defining the required protection mechanisms for safeguarding sensitive data processed during transactions initiated through SoftPOS.
As the industry focuses on the new requirements to build secure software-based payment acceptance solutions,…
Unlike international payment schemes, domestic payment networks process electronic transactions within a national territory. The advantages for payment solution providers offering payment terminals that support both international payments and domestic payment networks is that they benefit an extended deployment market.
What are the benefits of test automation during payment terminal certification ?
Test automation consists in implementing an automatic communication interface between a device under test and a test tool, to check the behavior of a software with minimal human intervention. Major payment schemes such as Visa and Mastercard have published guidelines allowing payment terminal providers to build a communication interface compliant with the test automation requirements.
Focus on tokenisation in transit environment.
Indeed, the transformation of the card data in Card Number Alias or token enables to connect a card number to an individual card holder or an event.
This transformation is performed by cryptography computation.
The computation will always generate the same token for the same card if the same algorithm is used. This algorithm is a one way function, so, there’s no possibility to translate from a token to a card number.