Introduction to Host Card Emulation
Host Card Emulation (HCE) is a revolutionary technology that addresses the challenge of securing mobile phones for credit or debit transactions at physical point-of-sale terminals. Traditionally, payment systems relied on Secure Elements within phones to store payment credentials and cryptographic keys. However, issues such as lack of standardization, complex certification requirements, and banks' reluctance to cede control to third-party Trusted Service Managers (TSMs) hindered mass deployment.
Advantages of Host Card Emulation
Host Card Emulation presents an innovative approach to payment security by storing critical payment credentials in a secure shared repository, eliminating the need for TSMs. This shift allows banks to regain control over payment processes, enhancing security and reducing reliance on external entities. HCE delivers limited-use credentials to phones in advance, facilitating contactless transactions while mitigating security risks associated with traditional payment methods.
Challenges and Solutions
Implementing Host Card Emulation introduces new challenges, such as the centralized storage of payment credentials, creating potential vulnerabilities. The requirement for real-time, online interactions during payment transactions poses security risks that issuers must address. Despite not storing credentials, phones play crucial security roles in HCE, necessitating robust authentication methods and secure communication channels. Solutions like caching credentials and risk-based approval processes will be essential in mitigating these challenges.
Thales CipherTrust Host Card Emulation Solution
Thales CipherTrust offers an advanced solution for Host Card Emulation, enabling businesses to integrate mobile payments securely and efficiently. With Thales, businesses can deploy HCE applications that support new transactions and revenue streams while adhering to stringent security and risk models demanded by HCE. Leveraging Thales' HSM offerings and existing back-office security infrastructure ensures a flexible and comprehensive approach to payment security in the mobile landscape.