A payment application needs to be securely stored because it contains sensitive data. Coskun et al (2013) defined the SE as “a combination of hardware, software, interfaces, and protocols embedded in a mobile handset that enables secure storage and processing” (Coskun, Ok, & Ozdenizci, 2013). Figure 5-3 shows the three possible location of the SE on a mobile phone.
Figure 5-3: Possible SE locations
The SE ensures that all communication from outside is processed in encrypted form. The information stored in the SE can be accessed only by certain applications under certain conditions. The SE is separate from the NFC technology. The SE uses the NFC interface to transmit the encrypted data.
5.3.1 SE Alternatives
Figure 5-3 shows the basic locations of the SE that are commonly used but there are other alternatives such as stickers which can be used as SEs. According to Coskun et al (2013), the SE can be categorized into four groups: Nonremovable SEs, Removable SEs, Flexible SE solutions
70
and Software-based SEs. The nonremovable SEs are the ones that are embedded in the mobile device. The removable SEs includes UICC, stickers and Secure Memory Cards (SMC). The Flexible SE solutions include SMC and UICC/SIM. And the Software-Based SEs are located at Trusted third party base.
Besides the issue of the ecosystem another big issue which is affecting the adoption of NFC is the issue of who will control the SE (Ergeerts et al., 2012). Even though there are three possible SE locations on the mobile phone; there are four possibilities of managing the SE (Ergeerts et al., 2012): handset manufacturer centric approach, MNO centric approach, service provider centric approach and neutral third party.
5.3.1.1Handset manufacturer centric approach
The SE is embedded in the mobile device by the handset manufacture. In this case; it is the handset manufacturer who manages the SE. This option does not support the portability requirement because the SE is not removable. The SE which is integrated in the mobile device is tamper proofed and does not depend on OS of the handset (Madlmayr, 2008). The SE is connected to the NFC controller. Examples of mobile phones equipped the SE include Samsung Galaxy Nexus and the Google Nexus S. These SEs are owned by Samsung and Google respectively. This type of SE has all the hardware and software certifications it needs. This architecture has already been tested around the world and has been found to be secure (Smart Card Alliance, 2007). The type of SE used here needs to be replaced and personalized each the mobile device is owned by a different user (Coskun et al., 2013).
5.3.1.2 MNO centric approach
The SE resides in the Universal Integrated Circuit Card (UICC) also known as the SIM card. This approach meets the portability requirement of m-payments. MNOs in most countries that have huge numbers of the unbanked and underbanked already provide money transfer services therefore they can easily add a payment service. The SIM card is issued by the MNO and contains a SIM applet that allows secure authentication on the mobile network (Ergeerts et al., 2012). This option gives too much control to a single stakeholder (Ghag & Hedge, 2012). One of
71
the benefits of this option is that it “meets the security standards imposed by the Financial Institutions” (Ghag & Hedge, 2012).The application on the SIM card can be easily blocked and unblocked. If the UICC is used as the SE, end-to-end processes need to be in place to prevent the new applications from damaging or corrupting the UICC (GSMA, 2011). A question arises as to who maintains control and visibility of credit or debit cards from separate banks if there are multiple payment application on the SIM card.
5.3.1.3 Service provider centric approach
According to Benyo (2009) a Service Provider can be simply defined as an actor that deploys or manages the application or data stored on the SE. In this approach the SE is located on an external memory such as a Micro SD card or an active sticker (Benyo, 2009). In this case the SE is controlled by a TSM. TSM such as Visa and MasterCard are already powerful in the payment industry and they already have a large number of customers (Ergeerts et al., 2012). The Micro SD should be NFC enabled. This option allows banks or financial institution to own the secure element (Ghag & Hedge, 2012). The Micro SD card is compatible with different models of mobile phones.
5.3.1.4 Neutral third party
In this case an independent third party manages the SE. The SE will be located in the Micro SD as well for this option. The third party provide the application and acts as a middle man between the banks and the MNOs. This option provides interoperability.
5.3.2 Summary
The SE affects the m-payment because if affects the business model that is adopted. An NFC enabled m-payment cannot be provided without a SE for the storage of the sensitive information. The business model is also affected by the dominating stakeholders and, the standards and laws of the area where the m-payment will be used. For the use of the SIM card and the mobile device embedded SE, there is need for the stakeholders to collaborate. The MNO centric approach, service provider centric approach and neutral third party provide interoperability but the MNO centric approach will only be limited to the subscribers of the MNO. This research also seeks to
72
propose a business model that is sustainable in MRA. Chapter 10 will look at this business model in more details.
5.4 Conclusion
Contactless m-payments are successful in countries like Japan and South Korea due to the collaboration of the major stakeholders (Ezell, 2009). Because of the complexity of the NFC ecosystem the governments of these countries had to assist in the collaboration. The collaboration of the stakeholders affects the business model that will be adopted and the interoperability of the m-payment applications offered by different stakeholders. Even though there are many m-payments applications that have been deployed in Japan, they lack interoperability and this has caused the retailer merchants to have up to four POS reader terminals (Ezell, 2009). This might cause the merchants to reject m-payments because this will increase the transaction time. Therefore it is very important that the stakeholders collaborate even if they will not provide a single m-payment application. This will ensure interoperability of the m-payments.
The type of business model that is adopted in an m-payment can also be affected by the location of the SE. An NFC enabled m-payment cannot be provided without a SE. Since customers are always changing their mobile devices, it is a good idea use a removable SE if possible. Using the UICC as a SE provides more security because the UICC can be remotely wiped if the device is stolen.
73
6
THEORETICAL MODELS FOR TECHNOLOGY ACCEPTANCE
6.1 Introduction
Over the past years different theoretical models have been developed for measuring the acceptance of a new technology by users. In this chapter we will look at the most popular of these models and modify it for use in this research.