Feeds

Visa approves wireless payment chip

Two phones approved to surf the payWave

The Power of One Brief: Top reasons to choose HP BladeSystem

Visa has approved a microSD card for proximity payments, slotted into the BlackBerry Bold or Samsung Galaxy S, paving the way for payWave transactions on a mobile phone.

Visa's approval doesn't mean the cards, which come from DeviceFidelity, will definitely be available, but it does mean a bank currently issuing Visa payWave cards now has the option to send customers a microSD card, as long as the customer has the right kind of mobile phone.

PayWave, in common with other proximity-payment mechanisms, requires two components – an induction-powered radio tag and a cryptographically-secure element for authentication. DeviceFidelity squeezes both bits into a microSD card, but getting radio signals in and out is very dependent on what surrounds the card. Where the slot is under the battery, or sandwiched between circuit boards within a metallic case, getting a signal out might be impossible, and not every phone has a microSD slot anyway.

For the iPhone, DeviceFidelity solves the problem with a snap-on case, but now Visa has tested the internal-chip solution on two of the most-popular handsets and reckons it is up to snuff in both security and reliability terms. Visa told NFC Times that both handsets performed reliably in repeated tests, and that it looked forward to approving other handsets soon.

Putting the antenna inside the phone isn't a perfect solution: though this would mean it would be much better integrated with the phone, as in Google's Nexus S handset. But that starts an argument over who controls the secure element, or who gets the keys. A microSD card puts the keys in the hands of the issuing bank, an arrangement which will be more comfortable to many of the financial institutions involved. ®

Application security programs and practises

Whitepapers

Designing a Defense for Mobile Applications
Learn about the various considerations for defending mobile applications - from the application architecture itself to the myriad testing technologies.
Implementing global e-invoicing with guaranteed legal certainty
Explaining the role local tax compliance plays in successful supply chain management and e-business and how leading global brands are addressing this.
Top 8 considerations to enable and simplify mobility
In this whitepaper learn how to successfully add mobile capabilities simply and cost effectively.
Seven Steps to Software Security
Seven practical steps you can begin to take today to secure your applications and prevent the damages a successful cyber-attack can cause.
Boost IT visibility and business value
How building a great service catalog relieves pressure points and demonstrates the value of IT service management.