SlideShare une entreprise Scribd logo
1  sur  27
The Role of IAM in Open Banking
&
Where Do We Stand?
Colombo IAM User Group - 2nd Meetup
Pushpalanka Jayawardhana
Financial Solutions Team - WSO2
“Banking is necessary; banks are not”
- (Bill Gates, 1990)
International Financial Industry
Concerns
➢Contribute to a more integrated and
efficient European payments market
➢Improve the level playing field for PSPs
(including new players)
➢Make payments safer and more secure
➢Online shopping without a credit card
➢Better protection against fraud
➢Help lower charges for consumers on
card payments
Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf
Payment Card Industry Security Standards
For protection of cardholder payment data,
Payment Services Directive 2
EU Directive that applies to
all Banks operating in the EU
that regulates payment
services throughout the EU,
with a compliance deadline of
January 2018
Open Banking
1 : Possible central view
Banks expose their customer payment and account data, with customer consent, to
Third party Payment Providers (TPPs) via APIs.
TPP
PISP/AISP
Bank A
Bank B
Bank C
Merchant
Now PSD2
Bank A
Bank B
Bank C
Merchant
Open Banking
2 : No Involvement of Card Network
7
➢ Less hops
➢ Lower fees for transactions
➢ Easy to track the path
Aggregated View of Accounts (AISP
Flow)
Payment Flow (PISP)
Credits to Dinosoft Labs from Noun Project
Checkout
Item
Login Page
2 Factor Authentication
Customer Consent
Initiation
payment info
1
2
3
4
PISP
302
5
Token 6
Payment
Complete
7
Settlement
PSD2 Compliance Requirements
➢ API Specification
○ API Definitions
○ Secured API invocation
○ API Usage Monitoring
➢ Strong Customer Authentication
○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin)
○ Adaptive Authentication
○ Consent Management
➢ Incident Reporting
○ Security Incident Reporting [Transactions affected,server downtime, Economic
Strong Customer Authentication
Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Strong Customer Authentication Ctd..
Adaptive Authentication
➢ Authentication flow is defined by risk level
➢ PSD2 define several exemptions for SCA applications
○ Not to kill user experience for small transactions and bulk transactions
➢ Security level can be decided based on,
○ The amount of transaction
○ Time elapsed from previous SCA
○ Transaction patterns on user
○ Role of user - Cooperate or private
Consent Management
➢ Defined by PSD2 RTS on SCA and secure communication and GDPR
➢ Safeguard right of the user on personal data to,
○ be informed - Inform user of personal data collection
○ access - Validate information processing at any time
○ rectification - When user feels data is incomplete or accurate
○ restrict data processing - Just store, don’t process
○ data portability - Transfer data to another party
○ forgotten - Request removal of personal data
○ be notified on a data breach - Report to user within 72 hours
No Screen Scraping
Technology Requirements
“Draft Regulatory Technical Standards, explicitly mentions to be based on
known standards”
● User authentication (with SSO)
○ SAML 2.0
○ OpenID Connect
● Access delegation - OAuth 2.0
● Fine grained authorization - XACML
● Multifactor authentication - SMSOTP, FIDO, DUO, MePin
16
Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf
Other Standards
ISO 27001 - for information security management systems
ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
Inside Story - Open Banking
DEMO
With https://openbanking.wso2.com/
Open Banking: The opportunities
Bank A
Bank B
Bank C
Merchant Bank A
Consolidated
customer account and
payment info across
multiple Banks
TPPTPP
App Development
Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2
1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country
e.g. EUR payment from France to Sri Lanka
1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country
e.g. LKR payment from UK to Sri Lanka
1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country
e.g. EUR payment from Sri Lanka to France
1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country
e.g. LKR payment from Sri Lanka to UK
PSD2 Impact
on Us
Banking Industry in Sri Lanka
➢ Sri Lanka Interbank Payment System (SLIPS)
○ Same day electronic fund transfer
○ Established in 2010, being first in South Asia
➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS)
○ For real-time payments
○ Initiated in 2015
➢ JustPay - From LankaClear (pvt) Ltd
○ Applies 2FA
○ For real time retail payments under Rs. 10 000/=
○ Central Bank of Sri Lanka (CBSL) approved security standards
➢ Have already thought on AISP like applications
➢ Have the foundation of collaboration among banks in real time
JustPay© - http://www.lankaclear.com/product_service/42-overview
Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
Monetization of applications will be made
easy...
Q & A
Twitter : @Pushpalanka
LinkedIn : https://www.linkedin.com/in/pushpalanka/
WSO2 Open Banking : https://openbanking.wso2.com/
Thank You!

Contenu connexe

Tendances

Open Banking Report Executive Summary
Open Banking Report Executive SummaryOpen Banking Report Executive Summary
Open Banking Report Executive SummaryMEDICI Inner Circle
 
Company Presentation (Stripe)
Company Presentation (Stripe)Company Presentation (Stripe)
Company Presentation (Stripe)Rodney Shibu
 
How an online payment gateway works
How an online payment gateway worksHow an online payment gateway works
How an online payment gateway worksIkajo International
 
Session 5 - NGSI-LD Advanced Operations | Train the Trainers Program
Session 5 -  NGSI-LD Advanced Operations | Train the Trainers ProgramSession 5 -  NGSI-LD Advanced Operations | Train the Trainers Program
Session 5 - NGSI-LD Advanced Operations | Train the Trainers ProgramFIWARE
 
A Complete Model of the Payment Service Business
A Complete Model of the Payment Service BusinessA Complete Model of the Payment Service Business
A Complete Model of the Payment Service BusinessFrank Steeneken
 
Digital Banking: Enhancing Customer Experience; Generating Long-Term Loyalty
Digital Banking: Enhancing Customer Experience; Generating Long-Term LoyaltyDigital Banking: Enhancing Customer Experience; Generating Long-Term Loyalty
Digital Banking: Enhancing Customer Experience; Generating Long-Term LoyaltyCognizant
 
PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectiveEmilie Scalla
 
Two Tier CBDC Model Architecture
Two Tier CBDC Model Architecture Two Tier CBDC Model Architecture
Two Tier CBDC Model Architecture Blockchain Worx
 
Webpay - Payment Gateway Business Plan
Webpay -  Payment Gateway Business PlanWebpay -  Payment Gateway Business Plan
Webpay - Payment Gateway Business PlanMufaddal Nullwala
 
Future of cryptocurrency ppt.
Future of cryptocurrency ppt.Future of cryptocurrency ppt.
Future of cryptocurrency ppt.Bitex Global
 
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...apidays
 
White label neobank 2021
White label neobank 2021White label neobank 2021
White label neobank 2021Vadi Ivanen
 
Realex.io sto-architecture-v2
Realex.io sto-architecture-v2Realex.io sto-architecture-v2
Realex.io sto-architecture-v2Avadhesh Gupta
 
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?Blockchain and the Future of Real Estate Industry: Is Revolution Coming?
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?Denis Nemtsev
 
Online payment gateway provider
Online payment gateway providerOnline payment gateway provider
Online payment gateway providerPayment Gateways
 

Tendances (20)

Open Banking Report Executive Summary
Open Banking Report Executive SummaryOpen Banking Report Executive Summary
Open Banking Report Executive Summary
 
Company Presentation (Stripe)
Company Presentation (Stripe)Company Presentation (Stripe)
Company Presentation (Stripe)
 
Payment Card System Overview
Payment Card System OverviewPayment Card System Overview
Payment Card System Overview
 
How an online payment gateway works
How an online payment gateway worksHow an online payment gateway works
How an online payment gateway works
 
Session 5 - NGSI-LD Advanced Operations | Train the Trainers Program
Session 5 -  NGSI-LD Advanced Operations | Train the Trainers ProgramSession 5 -  NGSI-LD Advanced Operations | Train the Trainers Program
Session 5 - NGSI-LD Advanced Operations | Train the Trainers Program
 
A Complete Model of the Payment Service Business
A Complete Model of the Payment Service BusinessA Complete Model of the Payment Service Business
A Complete Model of the Payment Service Business
 
Digital Banking: Enhancing Customer Experience; Generating Long-Term Loyalty
Digital Banking: Enhancing Customer Experience; Generating Long-Term LoyaltyDigital Banking: Enhancing Customer Experience; Generating Long-Term Loyalty
Digital Banking: Enhancing Customer Experience; Generating Long-Term Loyalty
 
PSD2 - The second Payment Services Directive
PSD2 - The second Payment Services DirectivePSD2 - The second Payment Services Directive
PSD2 - The second Payment Services Directive
 
Two Tier CBDC Model Architecture
Two Tier CBDC Model Architecture Two Tier CBDC Model Architecture
Two Tier CBDC Model Architecture
 
Payment Gateway
Payment GatewayPayment Gateway
Payment Gateway
 
Webpay - Payment Gateway Business Plan
Webpay -  Payment Gateway Business PlanWebpay -  Payment Gateway Business Plan
Webpay - Payment Gateway Business Plan
 
India payment aggregator
India payment aggregatorIndia payment aggregator
India payment aggregator
 
Future of cryptocurrency ppt.
Future of cryptocurrency ppt.Future of cryptocurrency ppt.
Future of cryptocurrency ppt.
 
Credit Card Business Plan
Credit Card Business PlanCredit Card Business Plan
Credit Card Business Plan
 
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...
apidays LIVE Singapore - Open Banking: A foundation for the new world by Bhar...
 
White label neobank 2021
White label neobank 2021White label neobank 2021
White label neobank 2021
 
Realex.io sto-architecture-v2
Realex.io sto-architecture-v2Realex.io sto-architecture-v2
Realex.io sto-architecture-v2
 
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?Blockchain and the Future of Real Estate Industry: Is Revolution Coming?
Blockchain and the Future of Real Estate Industry: Is Revolution Coming?
 
Online payment gateway provider
Online payment gateway providerOnline payment gateway provider
Online payment gateway provider
 
PayPal
PayPal PayPal
PayPal
 

Similaire à The role of IAM in OpenBanking and where do we stand

Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésForums financiers de Wallonie
 
PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropeTransUnion
 
DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022FinTech Belgium
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?FinTech Belgium
 
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony VerhelpenFintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony VerhelpenFinTech Belgium
 
Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts Osborne Clarke
 
WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2
 
Beyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial InclusionBeyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial Inclusion37coins
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity ForgeRock
 
Getting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 ComplianceGetting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 ComplianceWSO2
 
Cryptocurrencies and AML
Cryptocurrencies and AMLCryptocurrencies and AML
Cryptocurrencies and AMLMinerva
 
Risk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTechRisk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTechGeo Coelho
 
Master class Fintech
Master class FintechMaster class Fintech
Master class FintechGerard Alba
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016Pietro Bezza
 
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...Accenture Italia
 
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...Starttech Ventures
 
The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5Jomari Peterson
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Bankingsenakafdo
 

Similaire à The role of IAM in OpenBanking and where do we stand (20)

Le monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunitésLe monde des paiements à l'ère de PSD2 - Défis et opportunités
Le monde des paiements à l'ère de PSD2 - Défis et opportunités
 
PSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in EuropePSD2: The Advent of the New Payments Market in Europe
PSD2: The Advent of the New Payments Market in Europe
 
DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022DFS22_Main Stage_Laurent Bailly_Visa_041022
DFS22_Main Stage_Laurent Bailly_Visa_041022
 
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
Simont Braun - Webinar PSD3 PSR Evolution or Revolution?
 
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony VerhelpenFintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
Fintech Belgium Summit 2017 - PSD2 - Anthony Verhelpen
 
Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts Boot Camp PSD II – Third Party Access To Accounts
Boot Camp PSD II – Third Party Access To Accounts
 
WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2WSO2 Open Banking: Digital Transformation Through PSD2
WSO2 Open Banking: Digital Transformation Through PSD2
 
Beyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial InclusionBeyond Money: The Role of Digital Currencies in Financial Inclusion
Beyond Money: The Role of Digital Currencies in Financial Inclusion
 
Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity Go Beyond PSD2 Compliance with Digital Identity
Go Beyond PSD2 Compliance with Digital Identity
 
Getting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 ComplianceGetting your API Management Strategy on Point for PSD2 Compliance
Getting your API Management Strategy on Point for PSD2 Compliance
 
Cryptocurrencies and AML
Cryptocurrencies and AMLCryptocurrencies and AML
Cryptocurrencies and AML
 
Risk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTechRisk Beyond Acquiring: Merchant Risk Across FinTech
Risk Beyond Acquiring: Merchant Risk Across FinTech
 
Master class Fintech
Master class FintechMaster class Fintech
Master class Fintech
 
Psd2 brochure
Psd2 brochurePsd2 brochure
Psd2 brochure
 
(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016(FinPort) TrueLayer deck - Connect Ventures 2016
(FinPort) TrueLayer deck - Connect Ventures 2016
 
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
PSD2 e Instant payments: l’evoluzione attesa dei pagamenti online, in store e...
 
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
Σίσσυ Παπαγιαννίδου, Διευθύντρια της Διεύθυνσης Εποπτείας Πιστωτικού Συστήματ...
 
The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5The Digital Reserve Pitch Deck v5
The Digital Reserve Pitch Deck v5
 
Finance Presentation
Finance PresentationFinance Presentation
Finance Presentation
 
PSD2 & Open Banking
PSD2 & Open BankingPSD2 & Open Banking
PSD2 & Open Banking
 

Plus de Pushpalanka Jayawardhana

Authorization for workloads in a dynamically scaling heterogeneous system
Authorization for workloads in a  dynamically scaling heterogeneous systemAuthorization for workloads in a  dynamically scaling heterogeneous system
Authorization for workloads in a dynamically scaling heterogeneous systemPushpalanka Jayawardhana
 
Identity mediation for enterprise identity bus
Identity mediation for enterprise identity busIdentity mediation for enterprise identity bus
Identity mediation for enterprise identity busPushpalanka Jayawardhana
 
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread PoolsThreads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread PoolsPushpalanka Jayawardhana
 
Approximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule MiningApproximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule MiningPushpalanka Jayawardhana
 
Leveraging federation capabilities of identity server for api gateway
Leveraging federation capabilities  of identity server for api gatewayLeveraging federation capabilities  of identity server for api gateway
Leveraging federation capabilities of identity server for api gatewayPushpalanka Jayawardhana
 
Feedback queuing models for time shared systems
Feedback queuing models for time shared systemsFeedback queuing models for time shared systems
Feedback queuing models for time shared systemsPushpalanka Jayawardhana
 

Plus de Pushpalanka Jayawardhana (11)

Authorization for workloads in a dynamically scaling heterogeneous system
Authorization for workloads in a  dynamically scaling heterogeneous systemAuthorization for workloads in a  dynamically scaling heterogeneous system
Authorization for workloads in a dynamically scaling heterogeneous system
 
Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2Frictionless Adaption of PSD2 with WSO2
Frictionless Adaption of PSD2 with WSO2
 
Identity mediation for enterprise identity bus
Identity mediation for enterprise identity busIdentity mediation for enterprise identity bus
Identity mediation for enterprise identity bus
 
Threads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread PoolsThreads and Concurrency Identifying Performance Deviations in Thread Pools
Threads and Concurrency Identifying Performance Deviations in Thread Pools
 
Approximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule MiningApproximate Protocol for Privacy Preserving Associate Rule Mining
Approximate Protocol for Privacy Preserving Associate Rule Mining
 
Leveraging federation capabilities of identity server for api gateway
Leveraging federation capabilities  of identity server for api gatewayLeveraging federation capabilities  of identity server for api gateway
Leveraging federation capabilities of identity server for api gateway
 
Feedback queuing models for time shared systems
Feedback queuing models for time shared systemsFeedback queuing models for time shared systems
Feedback queuing models for time shared systems
 
Big Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - KanthakaBig Data CDR Analyzer - Kanthaka
Big Data CDR Analyzer - Kanthaka
 
Kanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR AnalyzerKanthaka - High Volume CDR Analyzer
Kanthaka - High Volume CDR Analyzer
 
Experience at WSO2 as an Intern
Experience at WSO2 as an InternExperience at WSO2 as an Intern
Experience at WSO2 as an Intern
 
Cosmology in general
Cosmology in generalCosmology in general
Cosmology in general
 

Dernier

(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)twfkn8xj
 
The Triple Threat | Article on Global Resession | Harsh Kumar
The Triple Threat | Article on Global Resession | Harsh KumarThe Triple Threat | Article on Global Resession | Harsh Kumar
The Triple Threat | Article on Global Resession | Harsh KumarHarsh Kumar
 
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdf
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdfBPPG response - Options for Defined Benefit schemes - 19Apr24.pdf
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdfHenry Tapper
 
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证jdkhjh
 
212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technologyz xss
 
Market Morning Updates for 16th April 2024
Market Morning Updates for 16th April 2024Market Morning Updates for 16th April 2024
Market Morning Updates for 16th April 2024Devarsh Vakil
 
Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Commonwealth
 
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一S SDS
 
Financial analysis on Risk and Return.ppt
Financial analysis on Risk and Return.pptFinancial analysis on Risk and Return.ppt
Financial analysis on Risk and Return.ppttadegebreyesus
 
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTGOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTharshitverma1762
 
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfmagnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfHenry Tapper
 
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...Amil baba
 
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》rnrncn29
 
The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...AES International
 
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...Amil baba
 
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...Amil baba
 
PMFBY , Pradhan Mantri Fasal bima yojna
PMFBY , Pradhan Mantri  Fasal bima yojnaPMFBY , Pradhan Mantri  Fasal bima yojna
PMFBY , Pradhan Mantri Fasal bima yojnaDharmendra Kumar
 
Governor Olli Rehn: Dialling back monetary restraint
Governor Olli Rehn: Dialling back monetary restraintGovernor Olli Rehn: Dialling back monetary restraint
Governor Olli Rehn: Dialling back monetary restraintSuomen Pankki
 
Unveiling Business Expansion Trends in 2024
Unveiling Business Expansion Trends in 2024Unveiling Business Expansion Trends in 2024
Unveiling Business Expansion Trends in 2024Champak Jhagmag
 

Dernier (20)

(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)(中央兰开夏大学毕业证学位证成绩单-案例)
(中央兰开夏大学毕业证学位证成绩单-案例)
 
The Triple Threat | Article on Global Resession | Harsh Kumar
The Triple Threat | Article on Global Resession | Harsh KumarThe Triple Threat | Article on Global Resession | Harsh Kumar
The Triple Threat | Article on Global Resession | Harsh Kumar
 
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdf
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdfBPPG response - Options for Defined Benefit schemes - 19Apr24.pdf
BPPG response - Options for Defined Benefit schemes - 19Apr24.pdf
 
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
原版1:1复刻堪萨斯大学毕业证KU毕业证留信学历认证
 
212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology212MTAMount Durham University Bachelor's Diploma in Technology
212MTAMount Durham University Bachelor's Diploma in Technology
 
Market Morning Updates for 16th April 2024
Market Morning Updates for 16th April 2024Market Morning Updates for 16th April 2024
Market Morning Updates for 16th April 2024
 
Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]Economic Risk Factor Update: April 2024 [SlideShare]
Economic Risk Factor Update: April 2024 [SlideShare]
 
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
(办理学位证)加拿大萨省大学毕业证成绩单原版一比一
 
Financial analysis on Risk and Return.ppt
Financial analysis on Risk and Return.pptFinancial analysis on Risk and Return.ppt
Financial analysis on Risk and Return.ppt
 
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACTGOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
GOODSANDSERVICETAX IN INDIAN ECONOMY IMPACT
 
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdfmagnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
magnetic-pensions-a-new-blueprint-for-the-dc-landscape.pdf
 
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
NO1 WorldWide Genuine vashikaran specialist Vashikaran baba near Lahore Vashi...
 
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
《加拿大本地办假证-寻找办理Dalhousie毕业证和达尔豪斯大学毕业证书的中介代理》
 
The AES Investment Code - the go-to counsel for the most well-informed, wise...
The AES Investment Code -  the go-to counsel for the most well-informed, wise...The AES Investment Code -  the go-to counsel for the most well-informed, wise...
The AES Investment Code - the go-to counsel for the most well-informed, wise...
 
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...
NO1 Certified Black Magic Specialist Expert In Bahawalpur, Sargodha, Sialkot,...
 
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...
NO1 WorldWide Love marriage specialist baba ji Amil Baba Kala ilam powerful v...
 
PMFBY , Pradhan Mantri Fasal bima yojna
PMFBY , Pradhan Mantri  Fasal bima yojnaPMFBY , Pradhan Mantri  Fasal bima yojna
PMFBY , Pradhan Mantri Fasal bima yojna
 
Q1 2024 Newsletter | Financial Synergies Wealth Advisors
Q1 2024 Newsletter | Financial Synergies Wealth AdvisorsQ1 2024 Newsletter | Financial Synergies Wealth Advisors
Q1 2024 Newsletter | Financial Synergies Wealth Advisors
 
Governor Olli Rehn: Dialling back monetary restraint
Governor Olli Rehn: Dialling back monetary restraintGovernor Olli Rehn: Dialling back monetary restraint
Governor Olli Rehn: Dialling back monetary restraint
 
Unveiling Business Expansion Trends in 2024
Unveiling Business Expansion Trends in 2024Unveiling Business Expansion Trends in 2024
Unveiling Business Expansion Trends in 2024
 

The role of IAM in OpenBanking and where do we stand

  • 1. The Role of IAM in Open Banking & Where Do We Stand? Colombo IAM User Group - 2nd Meetup Pushpalanka Jayawardhana Financial Solutions Team - WSO2
  • 2. “Banking is necessary; banks are not” - (Bill Gates, 1990)
  • 3. International Financial Industry Concerns ➢Contribute to a more integrated and efficient European payments market ➢Improve the level playing field for PSPs (including new players) ➢Make payments safer and more secure ➢Online shopping without a credit card ➢Better protection against fraud ➢Help lower charges for consumers on card payments
  • 4. Ref : https://www.pcisecuritystandards.org/pdfs/webinar_100519pci_pts_3.0.pdf Payment Card Industry Security Standards For protection of cardholder payment data,
  • 5. Payment Services Directive 2 EU Directive that applies to all Banks operating in the EU that regulates payment services throughout the EU, with a compliance deadline of January 2018
  • 6. Open Banking 1 : Possible central view Banks expose their customer payment and account data, with customer consent, to Third party Payment Providers (TPPs) via APIs. TPP PISP/AISP Bank A Bank B Bank C Merchant Now PSD2 Bank A Bank B Bank C Merchant
  • 7. Open Banking 2 : No Involvement of Card Network 7 ➢ Less hops ➢ Lower fees for transactions ➢ Easy to track the path
  • 8. Aggregated View of Accounts (AISP Flow)
  • 9. Payment Flow (PISP) Credits to Dinosoft Labs from Noun Project Checkout Item Login Page 2 Factor Authentication Customer Consent Initiation payment info 1 2 3 4 PISP 302 5 Token 6 Payment Complete 7 Settlement
  • 10. PSD2 Compliance Requirements ➢ API Specification ○ API Definitions ○ Secured API invocation ○ API Usage Monitoring ➢ Strong Customer Authentication ○ 2 Factor Authentication (SMSOTP, FIDO, Duo, MePin) ○ Adaptive Authentication ○ Consent Management ➢ Incident Reporting ○ Security Incident Reporting [Transactions affected,server downtime, Economic
  • 11. Strong Customer Authentication Ref : https://cdn-images-1.medium.com/max/1200/1*cqJ3MUF-vOG9IVTLOOQQTQ.gif
  • 12. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks Strong Customer Authentication Ctd..
  • 13. Adaptive Authentication ➢ Authentication flow is defined by risk level ➢ PSD2 define several exemptions for SCA applications ○ Not to kill user experience for small transactions and bulk transactions ➢ Security level can be decided based on, ○ The amount of transaction ○ Time elapsed from previous SCA ○ Transaction patterns on user ○ Role of user - Cooperate or private
  • 14. Consent Management ➢ Defined by PSD2 RTS on SCA and secure communication and GDPR ➢ Safeguard right of the user on personal data to, ○ be informed - Inform user of personal data collection ○ access - Validate information processing at any time ○ rectification - When user feels data is incomplete or accurate ○ restrict data processing - Just store, don’t process ○ data portability - Transfer data to another party ○ forgotten - Request removal of personal data ○ be notified on a data breach - Report to user within 72 hours
  • 16. Technology Requirements “Draft Regulatory Technical Standards, explicitly mentions to be based on known standards” ● User authentication (with SSO) ○ SAML 2.0 ○ OpenID Connect ● Access delegation - OAuth 2.0 ● Fine grained authorization - XACML ● Multifactor authentication - SMSOTP, FIDO, DUO, MePin 16
  • 17. Ref : https://www.abe-eba.eu/downloads/knowledge-and-research/EBA_May2016_eAPWG_Understanding_the_business_relevance_of_Open_APIs_and_Open_Banking_for_banks.pdf Other Standards ISO 27001 - for information security management systems ISO20022 - remove ambiguity in messages relevant to payments, securities, FX, Trade services & Cards
  • 18. Inside Story - Open Banking
  • 20. Open Banking: The opportunities Bank A Bank B Bank C Merchant Bank A Consolidated customer account and payment info across multiple Banks TPPTPP
  • 22. Ref : Deutsche Bank Global Transaction Banking - Payment Services Directive 2 1. One-leg Out – in EEA currency: EEA currency sent from the EEA to a non-EEA country e.g. EUR payment from France to Sri Lanka 1. One-leg Out – in non-EEA currency: Non-EEA currency sent from the EEA to a non-EEA country e.g. LKR payment from UK to Sri Lanka 1. One-leg in – in EEA currency: EEA currency payment sent from a non-EEA country to an EEA country e.g. EUR payment from Sri Lanka to France 1. One-leg in – in non-EEA currency: Non-EEA currency sent from a non-EEA country to an EEA country e.g. LKR payment from Sri Lanka to UK PSD2 Impact on Us
  • 23. Banking Industry in Sri Lanka ➢ Sri Lanka Interbank Payment System (SLIPS) ○ Same day electronic fund transfer ○ Established in 2010, being first in South Asia ➢ LankaPay Common Electronic Fund Transfer Switch (CEFTS) ○ For real-time payments ○ Initiated in 2015 ➢ JustPay - From LankaClear (pvt) Ltd ○ Applies 2FA ○ For real time retail payments under Rs. 10 000/= ○ Central Bank of Sri Lanka (CBSL) approved security standards ➢ Have already thought on AISP like applications ➢ Have the foundation of collaboration among banks in real time JustPay© - http://www.lankaclear.com/product_service/42-overview
  • 24. Ref : Accenture Payment Services & Accenture Technology Advisory, PSD2 & Open Banking Security and Fraud Impacts on Banks
  • 25. Monetization of applications will be made easy...
  • 26. Q & A Twitter : @Pushpalanka LinkedIn : https://www.linkedin.com/in/pushpalanka/ WSO2 Open Banking : https://openbanking.wso2.com/

Notes de l'éditeur

  1. PTS DSS - PIN Transaction Security Data Security Standard
  2. Open Banking is due to become a regulation in Australia (similar to the enforcement of PSD2 regulation in the EU). Therefore, Banks need to be able to securely expose sensitive data through APIs so that third party providers can build new applications that provide a much better user experience to multi-banked customers.
  3. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  4. Upto 80% of attacks are based on stolen user credentials… One proof from ancient stories Ali baba and 40 thieves.
  5. Behavioral factors such as walking style, typing are also considered now as another factor
  6. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  7. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  8. Exposing APIs can seem to commoditize banks by threatening to take away the sole ownership of customer data that banks so far enjoyed exculsively. However, Banks armed with the correct vision and the technology to achieve that can reap much more benefits from this open banking world. Survey conducted in UK by Accenture showed that consumers prefer Banks to be the ones to provide the 3rd party services as well. If and when Banks can take up that role, they become a rich repository of customer data across multiple banks. They can then use that repository to… Provide better services to their customers (eg:- cashflow management across banks) Provide ‘Insight Sales’ to other businesses. (-> attract new revenue streams)
  9. Incident Reporting Guidelines -set methodology for payment service providers in order to determine whether an operational or security incident should be considered major and, therefore, be notified to the competent authority in the home Member State
  10. Core banking solution, Customer Integrated System, usually has • SWIFT terminals • ATM and POS solutions • MICR checks handler • Phone banking (IVR)