The Evolution of the Digital Wallet: From Smart Cards to iPhone

The journey towards the modern digital wallet, culminating in solutions like Apple’s Wallet on the iPhone, has deep roots. Early explorations into digital identity and transactions can be seen in concepts like the Smart Card (see What is a Smart Card), and related ideas about digital cash and identity management explored in pages like My Wallet and CanDo. These concepts are connected to broader frameworks like the Prime Ontology, which deals with fundamental elements of identity and value exchange, predating and informing the architecture of today’s digital wallets integrated into platforms like the iPhone.

Central Bank Digital Currency – Someday Soon

https://modernconsensus.com/technology/building-digital-dollar-requires-private-sectors-help-fed-chairman/
Clearly, I am a bit behind.

Crypto

I learned it in school then again at the hand of David Chaum

He taught me that if I kept the key length long the work hard and the hardware self defeating then a digital signature is absolute proof of presence under and agree set of conditions.

We then spoke of operating systems, payments, smart cards, cryptography: asymmetrical and symmetric. Rooted in PKI and the need to assume a trust less world.

Then there is money. We knew, time ago, we could use electrons to replicate notes and coins on ledgers and within balances.

Electronic Passports, National Identity Cards, and Drivers Licenses will have or have had a digital form.

Now we create Digital Assets.

Valued by a market.

Dreaming of unimaginable wealth or food on the table in the morning.

Identifiers, Tokens and Authentication

Often times I have wondered why everyone is so enamored with Tokens and Tokenization. Some time ago I begged the question of the broken token in a presentation to the Smart Card Alliance.

My premise is simple.

Identifiers are not authenticators. Replacing the identifier with a token as a result of turning an Identifier, the PAN, Social Security Number or other identifying index value, is a bandage on a festering mistake.

What we need to do is address the challenge of authentication in a convenient and frictionless way. Having to protect an identifier was the issue that created PCI and the whole issue of PII data. The Identifier should not need to be protected. It was and still should be an index and means of recognizing the relationship the relying party has with you. The authentication function is to make sure the person linked to that identifier is you!

User name: Identifier

Password: *********

Was not a bad start. Single factor authentication “what you know”.

Given the number of relying parties we all maintain relationships with, it is time to retire the password; Introducing “what you have” a secure thing (be it a chip card, Fob, Mobile Phone or Personal computer) and exploit the power of cryptography. Then add a second factor, a password or PIN, is a great first step. Changing the PIN or Password to a Biometric is a great leap into a truly secure environment.

The Key is to embrace the first factor “What You Have” a true token.

We are here to help you figure out the right approach for your organization.

of Identity and Authentication in a Connected World of things.

Various engagement and conversations pull me into thinking about the realities and the necessities, of this emerging world of connected people, objects and thoughts.

Looking back, this topic has been part of my life since 1982 when I was first introduced to the concept of a smart card. At that time we spoke of using the smart card to securely configure a trading deck on Wall Street and in the City of London. The goal securely and automatically configure the voice, video and digital support a particular market trader.

In 1993 to when I was tasked to drive the development of EMV, we could have talked about the fact we were creating a means of secure digital identity. A trusted Identity document based on the trust that existed between the cardholder and the financial institution.

Instead We talked about:

  • Card Authentication “the CAM” now Data Authentication to assure the card was unique and genuine.
  • Cardholder Verification “the CVM” to verify the right user was presenting the card.
  • Card risk management to allow the issuer to support authorization in a offline world.
  • Should we include an electronic purse to support low value transactions?

Today the Debit card could easily be enabled as a secure means of digital identification, with the Financial Institution being the trusted party. Simply knowing the public key of the international or domestic debit card payment scheme allows the party reading the card will know the person was issued this card by that financial institution.

While we in financial services focused on our requirements, the telecom industry was working on the SIM & GSM specifications under ETSI leadership. They created another form of Secure Digital Identity. They focused on securing the identity of the communications channel and were less worried about making sure the right consumer was present, although there is the ability to allow the user to lock the SIM and now even the mobile phone.

2013 I had the opportunity to join the FIDO Board. Within that body, the objective was to separate the concept of identity from the act of authentication. It works from the premise that as digital relationships expanded, the use of passwords and PINs are becomes an issue. The FIDO Alliance also recognized that the only way to secure our digital world, like we secured payments and mobile communications was with the introduction of multi-factor authentication rooted in the belief that the first factor had to be “what You Have” a secure element / enclave, TEE, TPM … capable of generating and or storing secret (symmetric) and private (Asymmetric) keys unique to the object and more importantly unique to the relationship.

Clearly identity and authentication are essential to secure relationships. And, in a digital world, communication is the mechanism that connects people and things together.

Helping consumers manage their relationships assuring privacy is an interesting angle. If I am understanding your platform, at least at the level of the subscription for telecommunications services this you are helping to manage.

Anyway. Back to the pitch. I would like to see about scheduling another conversation and figure out if there is anything I can do to earn an income and create revenue for you.

What next for Smart Card and Mobile Phone

Why not start implementing EMV in the USA. It is the right thing to do. One global standard.

“Chip and PIN”, EMV … ISO 7614

The New York Times, in the previous post, looks at the issue from the obvious perspective.  The result is as one would expect.  Remember when France first introduced smart cards 1984or mandated then back in 1992 and the acceptance nightmare.

In the past I have written on the idea –

Push PCI/EMV into one coherent electronic and secure smart card reader and PIN Pad.

Mandate all new 1 July 2010; with the understanding that the reality –  every piece of equipment will be replaced in a reasonable period, say 7 to 10 years.

VARs should easily be able to do that.

The incremental ($8/device) on the device side goes down over time, as equipment becomes more affordable.

On the system side, most international providers have a solid EMV implementation they can port over to the US platform over that same 7 year time frame.

At the Network switches, gateways and IPSPs; data formats should be changed sooner, say three years from day one.

Issuers can then decide, when to embrace one  global two factor authentication solution; using contact and contact-less EMV  cards to support card authentication [Factor 1] and card holder verification processes (eg. Chip and PIN) [Factor 2] .

Biometrics were understood when EMV was created.  The mechanisms are in place to introduce an agreed, more secure, biometric verification process [Factor 3].