Telefónica O2 has introduced a unique solution for secure electronic transactions, enabling single-use user verification through the user's mobile. Under the name O2 Enterprise Security, the service is intended for corporate clients who can use it to provide security for their products for end users and protect their data against abuse and unauthorized manipulation.
The entire solution is based on the use of SIM cards that contain password protected E-service applications. Globally, the O2 Enterprise Security platform is an absolutely unique project. Until now, Telefónica O2 has been using it solely for internal needs and is now offering this service to third parties.
"The field of information and telecommunications technologies has evolved dynamically over the last few years. As the number of possible uses increases, a continuously growing emphasis is being placed on security. Our company has developed a solution that enables single-use customer identity verification through their SIM cards and BPIN codes," says Michal Táborský, Director for Product Development, Telefónica O2, adding, "The potential for usage of this function is massive. For instance, banks can use the service for transaction authorization, service providers can use it for client identification, or it can be used for secure access to sensitive data or the implementation of a micropayment system. It offers corporate clientele a means of logging into their respective company VPNs."
The O2 Enterprise Security solution is simple, flexible, and safe. The user simply needs to know their BPIN (a password distributed for GSM banking and this new service), which the customer gets together with the PIN for their SIM card. The user can change this code themselves whenever they want. The user access the O2 Enterprise Security functionality through the "O2 SIM" icon in the menu of their mobile phone. After requesting BPIN, they enter a secure zone in which there is a list of activated services.
This solution can be used in a wide range of ways. The service enables the user to generate and show a unique single-use code for internet banking on their phone's display - to log into a portal and to authorize electronic transactions. The SIM card itself generates the codes and the user is thus not dependent on GSM signal coverage. For a service provider, there is the benefit of cost savings through the replacement of verification SMS messages. Another possibility is the implementation of micropayments by mobile phone, or identification when calling a call center from secure zones. The operator thus does not have to further verify a user's identity - the call is authorized in the CRM system. Telefónica is the first operator in the world to offer such a service on its SIM cards.
The method of single-use customer identification and the services that can be accessed with this function are entirely up to the customer requesting the service
The application also features a PIN manager, which is available to all customers free of charge. The PIN manager offers secure storage of sensitive information, such as PIN codes for payment cards, static passwords, account numbers, and much more.
Up to 20 independent providers of various services can be activated on one SIM card. "In the near future, it is likely that a person will have one 'digital key' in their hand, capable of opening up a wide variety of virtual gateways. Managing internet banking, remote access to company networks, secure communication with banks, telecommunications operators or other service providers, secure electronic betting, and more will not only simplify the life of the end users, but will create considerable savings for business customers," says Vladimír Kajš, SIM Card Product Manager.
All SIM cards that O2 has distributed since 2008 have the secure zone function. If a customer does not have it, they can exchange their current card for the new version at any brand store. Customers of other operators can also use the solution by using O2 SIM cards in USB card readers plugged into their computers.
