Sunteți pe pagina 1din 3

Case Study

Aspire provides an Authentication


Platform for a uniquely positioned
electronic payments technology
company

Summary In a nutshell

The customer wanted to build a 2+Factor online authentication platform to The Customer
provide unparalleled security for access to online banking and electronic Industry: E-Payment and Security
payments over the Internet. Aspire Systems helped them build this patent- Product: Platform for
protected global authentication platform. authenticating online transactions
Location: USA

The Engagement
The Customer Engagement Model: Time &
Material
The customer is a uniquely positioned authentication and electronic payments Services Offered: Development,
Technology Company, with the sole purpose of developing an authentication platform Testing, Maintenance and
which meets the needs of a 21st century digital world. Documentation

The Challenge

The customer had to build a product which is an extraordinarily powerful, yet easy to
use USB-based platform for securing online transactions and electronic payments. This
platform needed to provide a simple way to achieve strong authentication, end-to-end
security and a verifiable audit trail for individual access to online networks and
transactions via open public networks.

The Solution

The front-end, consumer-facing product is a 2+Factor USB authentication token. The


token incorporates an RFID contactless payment chip and is used to secure ‘card
present’ online credit or debit payments and contactless payments at points of sale.
The back-end technology is a proprietary software authentication platform that is easy
to integrate into existing online systems. Aspire developed a global authentication
platform, which complies with the FFIEC & PCI DSS standards. Simultaneously, it
complies with the PCI contact-less payments standards, allowing it’s token to be used
with other contact-less payment products.

We provided multiple authentication solutions to their USB token platform, by which


this platform was able to protect participating parties from all known forms of identity
thefts and online attacks including:

Aspire provides an Authentication Platform for a uniquely positioned electronic payments technology company
01
Aspire provides an Authentication Platform for a
uniquely positioned electronic payments
technology company

?
Man- in- the- middle attacks
?
Session high-jacking Tech Snapshot
?
Internet Protocol, URL and referrer spoofing
?
Pharming, Malware & Trojan attacks Platform: Windows
Database: SQL Server 2005 &
The multiple authentication solution includes OTP (One Time Password) token, which MySQL
allows issuers and service providers to authenticate individuals by sending One Time IDE: Visual Studio 2008
Password via an SMS to an individual phone. This solution enables strong Languages: VC++ 9.0
authentication for accessing consumer information or conducting financial Package: DotNetNuke 5.1
transactions and ensures high level of portability.

The USB token platform provides authentication capabilities for any online application
via the implementation of simple API. This enables organizations to implement strong
authentication for their applications without requiring time consuming arduous
changes to their existing code.
Messaging Architecture

End User
Token
SMS

Mobile
Network

Firewall Firewall

Banking Server Web Service

Optional OTP via


SMS Message

Application
Server

HSM

Banking Database
Network Server

Aspire provides an Authentication Platform for a uniquely positioned electronic payments technology company
02
Aspire provides an Authentication Platform for a
uniquely positioned electronic payments
technology company

More Solutions
?
Integrated the Encryption Library with USB token.
?
Provided the new implementation for sending SMS using an SMS Gateway.
?
Provided the new PinPad with Generic option.

Key achievement

Apart from developing the USB token platform, the customer wanted to reduce the
size of ActiveX client component for quick download and installation. Initially the size
of the component was around 6MB. We proposed compression for both the ECD and
library files and thus brought down the size to around 1MB.

The Benefit
?
Ensures that online authentication methodologies are appropriate for all the
organization's Internet-based products and services.
?
Maximizes interoperability and is consistent with a Financial Institution’s
overall strategy for Internet banking and electronic commerce.
?
Adopts a staged deployment approach, with a centralized and highly
scalable architecture.
?
Implements an open architecture and a stable platform.
?
Supports the latest security protocols and standards.
?
Provides the most powerful set of authentication tools available today.

ABOUT ASPIRE SYSTEMS


Aspire Systems is an Outsourced Product Development firm committed to helping our
customers build software products better and faster. We work with some of the
world’s most innovative Independent Software Vendors and software-enabled
businesses, ranging from start-ups to established industry leaders, transforming the
way software is built. Aspire provides complete product lifecycle services, ranging
from new product development and product advancement to product migration, re-
engineering, sustenance and support. We are headquartered at Chennai, India with
offices in USA and UK.

For more information :

Website : www.aspiresys.com
E-mail : info@aspiresys.com
Tel:
USA : +1-408-260-2076
UK : +44 203 170 6115
India : +91-44-6740 4000

Aspire provides an Authentication Platform for a uniquely positioned electronic payments technology company
03

S-ar putea să vă placă și