FAQ: Security Evaluation Process for SBMP – General & Technical Questions

FAQs
Mobile NFC Consumer Device

Security Evaluation Process for Software-Based Mobile Payments Frequently Asked Questions (FAQ) 1. What is the Security Evaluation Process for software-based mobile payments? The EMVCo Security Evaluation Process assesses whether a software-based mobile payment (SBMP) component or solution demonstrates sufficient assurance of certain minimum levels of security, including security mechanisms and protections designed to withstand known attacks. The scope of the Security Evaluation Process previously included Integrated Circuit (IC), Platform and Integrated Circuit Card (ICC) products. EMVCo has now extended the scope to include SBMP components or solutions that enable payment transactions on a mobile device. 2. Why has EMVCo established a Security Evaluation Process for SBMP? Unlike traditional chip-based and hardware-based secure element solutions, SBMP applications must operate in the more vulnerable consumer device environment. SBMP solutions therefore often utilise a layered security approach incorporating various device and software components to help with combating the potential threats. This means that SBMP solutions can be built in different ways using different components, which can create complexities during the security evaluation and approval process. Consequently, EMVCo recognised an opportunity to develop a dedicated, common approach to evaluating the security of SBMP components and solutions, consolidating existing processes and industry best-practices. 3. How does the SBMP Security Evaluation Process meet the requirements of industry stakeholders? The SBMP Security Evaluation Process provides an efficient, flexible offering for product providers and promotes a robust security foundation for SBMP solutions. It introduces a ‘component’ and ‘integration’ evaluation model, allowing components to be evaluated independently or together to validate the security of the overall solution. The first component evaluation modules include:

  • Trusted Execution Environment (TEE)
  • Consumer Device Cardholder Verification Method (CDCVM) © 2019 EMVCo, LLC. All rights reserved.
  • Attestation
  • Software Protection Tools (SPT)
  • Mobile Applications and related Software Development Kits (SDK) 4. How else is EMVCo supporting the ecosystem? In order to facilitate the security evaluations of SBMP components and solutions, EMVCo has developed several programme documents. Documents publicly available:
  • SBMP Security Requirements
  • CDCVM Security Requirements
  • SBMP Security Evaluation Process Documents available to registered EMVCo SBMP Product Providers:
  • Software-Based Mobile Payment Security Evaluation Methodology
  • Security Guidelines for TEE-based Mobile Payment 5. Is EMVCo working with any other industry bodies in this area? EMVCo is working with other industry standard bodies, including FIDO Alliance, GlobalPlatform and the Payment Card Industry Security Standards Council (PCI SSC). EMVCo also has a CDCVM Task Force which closely works with the SBMP Task Force in the area of CDCVM and mobile payments. 6. How does an SBMP vendor engage with EMVCo? Please download the SBMP Security Evaluation Process from the website, and follow the steps outlined in the document. 7. How can other industry stakeholders get involved? EMVCo does not work in isolation and actively engages the payment community in developing, enhancing, and evolving future specifications and related testing processes. EMVCo has an established Associates Programme that is open to industry stakeholders. EMVCo receives input from Associates at both technical and business levels, as well as from Subscribers, to support global interoperability and security. © 2019 EMVCo, LLC. All rights reserved. EMVCo encourages new participants who are interested in contributing to EMVCo’s initiatives to join the EMVCo Associates Programme or become an EMVCo Subscriber. © 2019 EMVCo, LLC. All rights reserved.