MasterCard
®
SecureCode
™
Building Consumer Confidence,
Extending Your Market Reach
An Introduction for Issuers
SecureCode
Introducing
MasterCard
The time is now for gaining greater control over
non-face-to-face transactions, reassuring consumers about
online shopping ease and security… and tapping a
vast market of potential online shoppers estimated
at
$3-plus trillion worldwide.
• A comprehensive strategy and a variety of flexible solutions for guaranteeing payments over remote channels. All parties in an online transaction benefit from a new ability to identify the cardholder.
• MasterCard's approach to e-commerce security is designed to provide issuers with maximum flexibility. Issuers have the option of selecting
MASTERCARD®SECURECODE™AT-A-GLANCE:
the authentication solution that best meets their business and risk management requirements.
• Issuers may elect to use MasterCard’s PC Authentication Program, our Chip Authentication Program, or our implementa-tion of 3-D Secure for their MasterCard or Maestro®portfolios.
• In all cases, MasterCard guaranteed payments are made possible through the cardholder’s unique private code, and our Universal Cardholder Authentication Field (UCAF™), which
enables the secure transport of authentication data within the authorization message.
• MasterCard SecureCode will be actively supported by a variety of global marketing efforts, including a hosted solution that can be fully branded with your institution’s logo, and sample cardholder communications materials.
3 MasterCard
SecureCode works across all virtual channels, using hidden fields and a plug-in application on merchant web pages to carry authentication data.
Inspired by Market Demand
Today’s Online Shopping Environment
Today’s e-business environment presents both unparalleled opportunities and significant challenges for card issuers. The opportunities are clear: as the Internet continues to become a truly global, mainstream shopping channel, it is estimated that fewer than halfof potential online users have ever participated in an electronic transaction. For card issuers, this represents an untapped potential market of U.S. $3 trillion1.
By meeting your cardholders’ growing desire to do more Internet shopping securely and conveniently, you’ll be in a position to strengthen your customer relationships as new technologies take hold.
At the same time, you face significant challenges for securely authenticating your cardholders over the Internet and other emerging channels. Unlike the physical world, there is no signed sales receipt associated with e-commerce transactions, and, thus, there has been no sure way for an issuer to challenge a cardholder claim of not engaging in a given transaction. As a result, online shopping has traditionally experienced the highest levels of consumer chargebacks: instances in which the cardholder claims never to have made the purchase. In fact, MasterCard data shows that chargebacks due to "cardholder non-authorization," represent an increasingly large percentage of all e-commerce chargeback expenses — over 80%2in recent years.
Nor are all consumers completely comfortable shopping online today. In many cases, today’s consumers have serious concerns about fraud, identity theft, and other privacy and security issues associated with e-commerce transactions.
Introducing MasterCard
®SecureCode
™...
— Inspired by market demand
— Informed by consumer insight
— Enabled by MasterCard expertise
1eMarketer, 2002
2MasterCard International INET Reports, Fourth Quarter 2000
“ I like the way it instantly confirms that it’s me.”
Consumer Focus Group London, UK
February, 2002
MasterCard SecureCode
Online
5 4
Each time a card-holder pays online with his or her MasterCard, a window pops up from the card issuer asking for the card-holder’s MasterCard SecureCode — just as banks check for PINs at ATMs. In seconds, the issuer confirms it is in fact the true cardholder performing the transaction.
Submit
Help Cancel
Forgot your SecureCode?
Your Bank Enter Your SecureCode™
Please enter your MasterCard® SecureCode™ in the field below to confirm your identity for this purchase. This information is not shared with the merchant.
Merchant Amount Date Card Number Personal Greeting SecureCode Golf Shop $250.00 07-30-2002 XXXX-XXXX-XXXX-0071 Hi Susan
MasterCard International presents an authentication tool that takes online shopping security and consumer confidence to a new level. It’sMasterCard®
SecureCode™, and it will set a whole new standard for how card issuers,
online merchants and consumers do business online. Issuers adopting MasterCard SecureCode will find that it is an easy, cost-effective way of improving consumer confidence in e-commerce transactions. Best of all, it fills a void for card issuers by delivering a straightforward, new means of achieving fully guaranteed e-commerce transactions.
Cardholder Peace of Mind
Industry data suggests that many consumers are holding back on Internet purchases due to lingering security concerns. MasterCard research shows that 90% of non-buyers worry that their personal and financial information may fall into the hands of hackers. Seventy-one percent are concerned about credit card fraud. Even online buyers are concerned: 41% of them have, at least once, ordered online but paid offline, up from 28% in March 2000. MasterCard SecureCode addresses these concerns by enabling cardholders to authenticate themselves when purchasing through a unique, personal code entered by the cardholder with each online purchase. Each time a cardholder pays online at a participating merchant with his or her MasterCard, a separate browser window pops up asking for the cardholder’s MasterCard SecureCode — just as banks check for PINs at ATMs. In seconds, the issuer confirms it is in fact the true cardholder performing the transaction, and allows the purchase to continue. With MasterCard SecureCode, cardholders can enjoy the peace of mind that comes with knowing that no one else has access to their SecureCode™. It’s a small, extra step, but a welcomed confidence booster.
Global Data Collection and Transportation
So how does MasterCard help issuers seize new marketswhile addressing today’s key security issues and minimizing fraud?
In order for merchants to fully support MasterCard’s suite of issuer solutions, MasterCard SecureCode requires a merchant plug-in, hidden fields, and the use of a simple, common method of collecting and passing cardholder authentication data at the merchant web site. Known as the Universal Cardholder Authentication Fieldor UCAF™, this globally interoperable data transport mechanism standardizes the way cardholder authentication data is carried among all parties in a transaction — cardholders, issuers, merchants and acquirers. By leveraging the universal nature of UCAF, MasterCard allows you to choose a solution that best meets your online security needs.
Informed by Consumer Insight
“ When I see secure, I think of protection. I have security.”
Consumer Focus Group Paramus, NJ
7
HOW IT WORKS
6
“ If there was something available online to make your card more
secure, why not use it? There’s no reason not to.”
Consumer Focus Group London, UK
February, 2002
Enabled by MasterCard Expertise
By utilizing the UCAF infrastructure, cardholder authentication data can be used to link cardholders to the transaction much like a signature in the offline payment environment. This, then, gives the card issuer and merchant explicit evidence that the cardholder authorized the purchase — thus reducing fraud and chargeback costs. And, because it fully supports Maestro debit transactions in addition to MasterCard transactions, MasterCard SecureCode (and its underlying UCAF data transport mechanism) gives merchants a new means of enabling PIN-based debit transactions over the Internet, thus opening the door to more e-commerce transactions and cross-border options. This is a particularly valuable feature in countries where debit is more heavily used than credit.
Unmatched Issuer Flexibility
Recognizing that a single solution may not work for all issuers, MasterCard SecureCode enables you to choose from a broad array of security solutions for authenticating your cardholders. By supporting a broad spectrum of issuer options, MasterCard is providing you with the greatest degree of choice in the marketplace.Issuer choices include:
— PC Authentication Program— a download implementation of MasterCard's
Secure Payment Application (SPA™), based on detailed specifications initially
released in June 2001, which fully interoperates with the UCAF hidden fields supported by participating merchants. This specification has been licensed to more than 84 technology vendors and involves the use of a small downloaded applet by the cardholder that works on his or her PC. — Chip Authentication Program— designed to build on the ease of use and
security of an EMV-compliant smart card for authentication through a user's PC. This solution is designed to interoperate with the UCAF hidden fields and specifications and is supported by both standalone and connected smart card readers.
— MasterCard’s Implementation of 3-D Secure— MasterCard is providing further issuer choice by supporting a MasterCard implementation of the 3-D Secure specification. This implementation of 3-D Secure supports the SPA algorithm and UCAF without any changes to the core 3-D Secure specification or protocol. This becomes the client-less (no cardholder download) authentication solution for MasterCard issuers that prefer not to deploy applet-based security solutions.
Due to the infrastructure requirements for 3-D Secure, MasterCard is deploying a directory service and a multi-issuer Access Control Server (ACS) to support these solutions worldwide. These systems are being deployed in our St. Louis data center along with a hosted program option for issuers who are not pursuing an in-house solution.
MasterCard SecureCode fully supports MasterCard and Maestro credit and debit transactions, opening doors to more cross-border transac-tions, especially in countries where debit is more heavily used.
1.
2.
3.
4.
Cardholder registers for MasterCard SecureCode – per the card issuer’s direction – and sets up their personal “SecureCode.”
The merchant collects the transaction details (using hidden fields as well as a merchant plug-in) and authentication information presented and passes it along with required merchant information to their acquirer.
MasterCard transports the transaction information including the authentication “token” and passes it along to the issuer for authorization processing.
Cardholder shops online at SecureCode-enabled merchants. Upon successful authentication of the cardholder by his or her card issuer, MasterCard SecureCode generates an electronic equivalent of the cardholder’s signature, or an authenti-cation “token.” This token is the key that binds the cardholder to the transaction.
Submit
Help Cancel Forgot your SecureCode?
Your Bank
Enter Your SecureCode™
Please enter your MasterCard® SecureCode™ in the field below to confirm your identity for this purchase. This information is not shared with the merchant.
Merchant Amount Date Card Number Personal Greeting SecureCode Golf Shop $250.00 07-30-2002 XXXX-XXXX-XXXX-0071 Hi Susan MasterCard SecureCode
Cross-Border
Sales:
8
MasterCard
Your Best Business Partner
Marketing Considerations
The program name, MasterCard SecureCode, provides a powerful marketing platform for issuers to introduce their cardholders to a new security enhancement to their existing MasterCard or Maestro account. Cardholders will see the MasterCard SecureCode logo on the web sites of participating online merchants, thus reinforcing cardholder awareness of the service. MasterCard SecureCode, and its associated positioning, have been thoroughly tested in consumer research, and trademarked in all of MasterCard's top markets around the world.A global rollout is underway to promote MasterCard SecureCode, enabling your institution to benefit from the broad awareness MasterCard will be generating for this new service. As part of this initiative, MasterCard is providing its issuers with an array of marketing support,including a hosted solution that can be fully branded with your institution’s logo, and sample cardholder communications materials.
MasterCard is the Right Partner
MasterCard SecureCode is one more example of how MasterCard is putting the full power of e-business to work for you. Our goal is to provide you with the tools you need to efficiently tap into the enormous opportunities of today’s online marketplace. It’s the commitment that you and your cardholders have come to expect from MasterCard.
learn more
CUSTOMIZABLE DIRECT MAIL PIECES
To make it even easier for our card issuers to implement MasterCard SecureCode, MasterCard has created a variety of direct mail marketing materials you can use and customize with your own branding.
Be even
MORE
when you
confident
SHOP online.
S a m p l e A . S a m p l e 1 2 3 A n y S t r e e t A n y t o w n , X X 1 2 3 4 5
Presorted First-Class Mail
US Postage
PAID
Anytown , ST Permit #XXX
Financial Institution LOGO
Return Address Return Address
Now that you have
PEACE OF MIND
online,
do
you
NEED?
what
ELSE
S a m p l e A . S a m p l e 1 2 3 A n y S t r e e t A n y t o w n , X X 1 2 3 4 5
Presorted First-Class Mail
US Postage
PAID
Anytown , ST Permit #XXX
Financial Institution LOGO
Return Address Return Address
WHENyou’re DONE
shopping online,
makeSURE yourcard is, TOO. Statement Insert
Postcards
Introductory Self-Mailer
More
peace of MIND
with your
online
www.mastercardonline.com
MasterCard International Incorporated © 2002
SecureCode-10/02