PPSE issues faced by financial IC cards in NFC SIM cards

The business of mobile e-commerce at home and abroad has grown rapidly in recent years. The pilot of near-field trading business based on NFC mobile phones has gradually started in 2012. The business development models and product plans in different countries and regions are not the same, and the business scale is also uneven. Combining the domestic and international mobile operators, financial institutions, terminals and Internet companies, security and card companies in recent years, product development, pilot operations, trials and sorrows, summed up and talk about a series of inevitable problems facing NFC business promotion, and How to solve possible or already used methods and solutions.

This talk about the PPSE issues faced by domestic financial IC cards (PBOC cards and terminals) when used in NFC SIM cards.

What is PPSE? According to the definition of China's financial IC card specification, PPSE is the abbreviation of Proximity Payment Systems Environment, which is called the close-range payment system environment in Chinese. The PPSE is an identification and application selection path file for a contactless financial PBOC application (also referred to as qPBOC) stored in the card, the file storing a number of lists, each list including an application identification (AID) of the financial application accepted in the card, an application Label and application priority indicator. PPSE itself is also an application, it has its own AID, the specification is set to "2PAY.SYS.DDF01".

When was PPSE written to the card? At present, most of the financial banks are in the stage of personalization before the issuance of financial IC cards, and are written and written by the issuing bank or the cooperative card manufacturer. The content to be written varies according to different issuers, and the format is conformable. Each list includes the application identifier (AID) of the financial application accepted in the card, the application tag, and the application priority indicator. The application priority indicator is an order indicating that the financial application in the card is selected.

When was PPSE used? If the terminal supports qPBOC, pre-transaction processing should be performed before prompting the cardholder to present the card and the POS terminal is activated. After the POS terminal detects the contactless card, it attempts to read the PPSE. The process is as follows:

——The POS terminal uses the AID name “2PAY.SYS.DDF01” to select the PPSE;

——The card will provide the PPSE information to the POS terminal according to the list format and the return data (FCI) of the Select command;

- The POS terminal shall establish a list of applications included in the FCI and supported by the terminal. The terminal shall determine the bits 4-1 of the application priority indicator (indicating the order in which the applications are selected) and select the application with the highest priority to process the transaction;

- If only one application is included in the FCI and supported by the terminal, the terminal should select the application regardless of the setting of the application priority indicator that may appear (you can use the following diagram to explain the processing flow of the POS and card) ;

NFC SIM supports one-card multi-application, which means that multiple SIM IC cards can be placed in this SIM, which brings problems that standard financial IC cards will not encounter.

(1) PPSE content conflict problem: The content of a bank account PPSE is determined by the issuing bank. The PPSE content of multiple bank accounts is determined by multiple card issuing banks. There will be multiple PPSEs in one SIM card, and which PPSE will be activated. effect? What if all are valid and encounter content conflicts (such as applying a priority indicator)?

(2) PPSE write process problem: If multiple bank card accounts are preset, it is necessary to go to multiple banks to obtain PPSE data and then write them in advance. No matter how complicated the process is, the theory is always operational. If the user downloads a new bank card into the SIM over the air, it needs a secure TSM platform to write, which TSM platform to use? According to the existing specifications, there is only one PPSE file in the card. Can it be operated by multiple TSM platforms or can it be operated by only one TSM platform?

In the current PBOC IC series specification, there is not much consideration for one-card multi-application. In reality, there is rarely a bank IC card placed in other bank IC applications. As a multi-application card for mobile payment, there will be a series of new problems, such as the problem of card space utilization efficiency in the previous article and the PPSE problem of multiple issuers in this article. In the long run, there is a need to upgrade existing specifications to support the true promotion of mobile payments. In the short term, solutions can be found without changing the specifications, changing existing POS machines, or changing the transaction process.

The solution to the first problem is by setting the default activation of the bank card account. From the perspective of the user, the user sets the bank card account that is activated by default on the mobile phone, and then swipes the card. If the user wants to change the card, select another bank card in the phone, which is like selecting a different bank card from their wallet to consume. The specific technical solutions and implementation details require some design of the card and mobile phone software, which will not be described in detail in this article. Through this scheme, the PPSE content of multiple banks can exist in one SIM card, and the associated PPSE content is returned by the used bank card.

The solution to the second problem is not only the technical solution, but also the cooperation model. From a security perspective, the operation of updating the unique PPSE file in the card should be controlled by a unique platform (TSM platform). If multiple TSM platforms update the PPSE in the SIM card, it will cause mutual trust problems of multiple banks, and it will increase the difficulty of risk control when security problems occur, and even seriously affect the traceability of the cause. Choosing a trusted TSM platform is the key to solving this problem.

NFC is a new technology, NFC business is a series of new business, NFC SIM card cooperation is a new demand, then in this three new environment, we must not stick to the rules, technological innovation and model innovation is the way to product success, and the satisfaction of user needs Good user experience is the basic premise. The promotion of one-card multi-application is the need for multiple card-party cooperation. The basic premise of cooperation is mutual trust. This requires management, technology, and business to constrain and guarantee, but it must be operational.

Custom candle box

 

Candle packaging boxes are designed for those handmade, scented candles. Most candle boxes will have an attractive look and can give protection to your handmade or ready-made candles. Cailang Printing Products Co.,Ltd are capable of providing custom made candle packing boxes for  candle industry with full colors, sizes and styles. Spot UV , embossing , debossing , hot stamping , glitter finishing . We`ll make your candle packaging look amazing . 

If you are still looking for a long-term partner for your packaging , do not hesitate to contact us anytime .


Custom-candle-box

Custom Candle Box

Luxury Custom Candle Box,Custom Candle Box,Rigid Custom Candle Box

Huizhou Cailang Printing Products Co.,Ltd. , https://www.paperboxs.nl