Card issuers are under increasing pressure to address the growing problems associated with card data theft and database compromises. Criminals are highly organized and sophisticated in their attacks and use the latest technologies to obtain card holder information. Recent compromises have exposed tens of millions of card holders data to fraudsters and criminals worldwide. Efforts around PCI compliance by retailers and processors to secure data are ongoing, however criminals have become increasingly adept in their attacks on the financial network.
The Problem
The key weakness facing the card industry is the static nature of the magnetic stripe on today's credit and debit cards. Since magnetic stripe data is static, once it is compromised it can be used repeatedly for fraudulent transactions without card holder knowledge.
The Solution
QSecure gives card issuers the ability to control financial network transactions without changing retail acceptance systems or card holder behavior. By issuing cards with QSecure's SmartStripe™ technology, issuers can make each magnetic stripe transaction unique. Each time a card is swiped a unique cryptographic security code is included in the standard magnetic stripe data. Only the card issuer knows the code, which allows them to identify fraudulent transactions from compromised data in real time. Not only can issuers identify fraudulent use as it occurs since each transaction is unique, since each transaction is unique, they can locate the source of the original compromise. This renders card data stored by merchants, merchants' POS software or processors worldwide useless, as this information cannot be used again for fraudulent transactions.
The QSecure solution incorporates authentication software (or a service through QSecure partners) that together with SmartStripe™ cards, provide issuers with many benefits:
- ISO compliant credit and debit cards
- No change to card holder, retail or acquirer systems
- Unique number integrated in magnetic stripe data with each card transaction
- Real time identification of replay transactions, fraudulent transactions, batch transactions
- Since each transaction is unique, the issuer knows immediately where the compromise originated
- Small incremental card cost – similar to contactless or EMV without requiring changes to acceptance infrastructure
Several card issuers will be piloting the QSecure solution by early 2008. If you are interested in learning more about QSecure solutions, please email us at: issuer@qsecure.com
Javelin White Paper
Card Data Shown to be a Significant and Ongoing Source of Vulnerability
