smart card management innovation · 2014. 11. 7. · -shinhan card case study may, 07. 2009 gyung...
TRANSCRIPT
© 2009 IBM Corporation
Smart Card Management Innovation- Shinhan Card Case Study
May, 07. 2009
Gyung Eun Choi, [email protected]
Advisory Software EngineerIBM KSSL(Korea Software Solutions Lab.)
2
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
ContentsKSSL Introduction
What is IBM CoreSCMS
SCMS Market in Korea– Shinhan Card was one of the earliest companies in the world to adopt SCMS
Shinhan Card Case– First Release, 2005
– Second Release (OTA Service Support), 2007
– Shinhan Day2, 2008 & Current
3
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
KSSL Introduction
WWMarket
WWIndustry
Solutions
WWSW Acquisitions
CloudSolution Center
CloudSolution Center
FinanceS/W Solution Center
FinanceS/W Solution Center
TelcoS/W Solution Center
TelcoS/W Solution Center
IndustrialS/W Solutions
IndustrialS/W Solutions
Cross-BrandS/W Solutions
Cross-BrandS/W Solutions
Impact business with moreIndustryCoverage
Impact business with more solutions in each focused industry
Leading-EdgeMarket Requirements
Right Solutions
Korea Software Solution Lab.
Identify& RemoveGaps
WW SWG Solution & Products
IBM SW Group announced the launch of Korea Software Solutions Lab in April 2007. It consists of three solution centers:
4
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
What is IBM CoreSCMS
Card and Applet Lifecycle Mgmt.
Card Holder Support
Reporting
Card Product Design & Building
Post-Issuance Support
VALID FROM
VALID FROM
GOOD THRU
01/20001/2000
01/2003
CardIssuerCardCardIssuerIssuer
VALID FROMVALID FROM
GOOD THRUGOOD THRU
01/200001/2000 01/200301/2003John J. DoeJohn J. Doe
4321 076543 789994321 076543 78999
Card Component Mgmt. ….---,,,,
Key Mgmt.
==
IBM CoreSCMS provides management of the overall card lifecycle including card issuance and post-issuance and customer support service.
Issue Mgmt.(Mass Issuing or Instant Issuing)
5
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
SCMS Market in Korea
SCMSKT Corporation
2002 2003 20052004
Credit/Debit Appl.I-Cash Electronic PurseLoyalty Ticketing
…
1.6 million GlobalPlatform cards
2.5 million mobile subscribers are using this mobile banking function
Mobile Banking Service
Money transferBalance checking
Moneta Card
•EMV credit (issued chip)•Visa Cash e-purse•SKT membership•Loyalty (OK Cash bag)•Mifare (in separate contact less chip)
Online BankingStock Auction
Online / Offline Payment
2006 20072001
LG Card SCMS
OTA
USIM enabled 3G phone
CoreSCMS launching
SKT Telecom is largest Telecom Company in Korea. Market share is 51.1%
35 million handsets
T-Money
Mobile Banking Service
Mobile Banking Service
400,000 dongles4.8 million handset
Telecommunication companies achieved increased market share and profit as end-users increased usage of their handsets.
Visa reports that banks were also able to increase their market share and reduce costs by,
providing improved quality customer service
decreasing the need for direct customer care.
6
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Shinhan Card : A Global LeaderAsia’s 1st Card Company, 15th Card Company globally
Card holder : over 13.7 M
<from Nilson report, Dec. 2007, Unit : USD bn>
7
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Shinhan Card CoreSCMS Release
GoalProvide Instant Issuance capabilitiesAdd new interface and integrate with another AMSMass Instance Integration Acceptance testMigration of Existing Card Products
GoalAdd the Issuance Channel with Mobile phone for the VSDC ApplicationAdd OTA Service for VSDC with one Mobile Company (SKT)
GoalIssuance System IntegrationDB MigrationCompliant Global PlatformEfficient IT & Business System
Duration : 5 MonthsDuration : 1 MonthDuration : 8 Months
Shinhan Day2, 2008Second Release, 2007First Release, 2005
8
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Why Shinhan Card choose CoreSCMS, in 2005Shinhan Card requested to solve 4 major problems of their legacy system.3 Principles : 1) Issuance System Integration & DB Migration, 2) Complaint Global System, 3) Efficient IT & Business System.
IBMIBMCoreCoreSCMSSCMS(Smart (Smart CardCard
Mgmt.Mgmt.System)System)
Factor of the SC
MS
Factor of the SC
MS
Migration with whole IC System
Basic P
rincipal
Basic P
rincipal
Host : Extension of Mgmt. Factor
Issuance : Make Applet composition
Compliant Global Platform
Efficient Management Chip& Card product
CMS should integrate IC Legacy System
Customer : Post Issuance System
System Integration
IC Card Product
DB Migration
9
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Shinhan Card (formerly LG Card) SCMS since 2005Since 2005, Shinhan had issued over 30 card products via CoreSCMS and they are continuously adding new card products without having to make any changes to CoreSCMS
Debit
GPIN
E-Cert
SKT
MemberCard
MMAA
VCASH
Mobile
CheckCard
PIMS
Medicine
KTGM
Loyalty
ZOOP
Total 37Application
(2005)
JCOP 10
JCOP 20
SLE661QCR2
Total 11 Chip(2005)
CardPerso.
<2005>
10
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Central issuance systemIf the new issuance channel is added, Core-Engine can be used and add the channel only.
Branch PCIntelligent
Device
Card IssuerCard Issuer
CoreSCMS
Internet Channel
PC Customer
Mobile Channel
Request IssuanceIssuance
Channel…
Phone user
Support
Various ChannelSCMS Administrator
1. IBM
2. Dreamsoft
3. M-Bank
4. E-Wallet
Select
[ ID Card ]
Options Back
Details
Delete
Block/Unblock
Update
Details
Delete
Block/Unblock
Update
Mass Issuance System
11
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Post Issuance via WebPost Issuance Web Page, Read the Chip and mix the information of the CoreSCMSSystem.
12
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
OTA System (Financial Side OTA Case)First Card Issuer is Telco. OTA System of Telco. has the role of downloading VM and load/install card applet. Second Card Issuer, Financial Company has the module of VSDC application issuance and DL Server for communication with VM on Mobile
Telco Company
CoreSCMS
Wireless Networking
Financial Company
OTA System
TLS Security Zone
SOAP EAI(MQ)
Legacy System
UICC Card
TLS SecuritySEED (128 bit)RAS (1024 bit)
WAP Browser,VM Program
Dedicated Line
GP MessageEncrypted Data
DLServer
(PI)
DLServer
(PI)
SD Key
ISD Key
Applet Load/Install
Applet Personalization
13
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
To go USIM Menu
Push “OK” buttonGo to [Show USIM] icon
14
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Start USIM Manager Menu
15
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Go to Credit card Icon for VM download
16
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
OTA Service on the Phone •CoreSCMS checks the card instance status
•Password, CVC verification and Second issuance : If there is no problem, then send the APDUs to requester
17
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Shinhan Card SCMS migration, since 2008. Shinhan Card acquired LG Card. IBM CoreSCMS manages the issuance process including the new Instance Issuance
Windows NTWindows NT
Instance Perso. at Branch OfficeInstance Perso. at Branch Office
e-Biz Channel System
e-Biz Channel System
IBM WebSphere V6, IBM DB2 V8.2, AIX V5IBM WebSphere V6, IBM DB2 V8.2, AIX V5
CoreSCMSCoreSCMS
PISPIS
Local Vendor AMSLocal Vendor AMS
KMSKMS
HOSTHOST
CAMS
Issuance Process Mgmt.Personalization Module
Reporting
Eracom HSMEracom HSMMaintain Key Life Cycle Crypto Service
Issuance Order:Basic Part + IC Personalization Part
Issuance Order:Basic Part + IC Part
Upload Issuance Audit File
Channel Push
Add/Delete/Update
ofApplication
& Data
Card/Appl.Info.
AD2000 DC280Instant issuance PC
Data Preparation ModuleCard Component Profile
“Secured Perso Channel”
ProfileValidation & Sync.
Issuance Result Update
Perso. ProxyChannel Server
Billing I/F
ApplicationProvider
ApplicationProvider
Card IssuerCard Issuer
FTPTCP/Socket
EAI ChannelEAI
D.P.Request
Perso. Audit
Perso. BureauPerso. BureauSCPMSCPMPerso. Proxy
Issuance Order:IC Personalization Part
Issuance Order:Basic Part
PC
Send Audit Data Automatically
D.P.Response
18
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Business BenefitShinhan Card started Smart Card Instant Issuance through successful deployment of IBM CoreSCMS as well as Mass Issuance
– Number of Instant Issuances doubled after deployment
– With this process model, CoresSCMS is now scaling to over 20,000 instant issuances and over 40,000 mass issuances per day.
Shinhan Card expands the service via mobile– OTA Service is supporting the 3 Telco. Companies in Korea
– OTA Card holder is increasing more and more.
– 150 – 200 OTA issuance per Month
19
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Entity in SCMS of Shinhan Card
CoreSCMSCoreSCMS
Kiosk
CustomerCare System
Mass IssuanceSystem
KeyMgmt
School
Web
Legacy SystemMilitary
Service System
Authorization System
20
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Thanks
21
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
Loyalty Usage with NFCWith NFC readable smart poster, chip update the point
Smart poster
22
IBM CoreSCMS
CTST2009, International Mobile User Cases: Shinhan Card Case © 2009 IBM Corporation
ID Check with the NFCCheck the ID value inside of the Cardlet. If the id & password information is correct, the device ready the chip information and check the ID valid.
Id/password OK
Id/password not OK