• Contact Us
  • Press Release
Marketcap
Advertise
BitCoinist News
No Result
View All Result
  • Home
  • Bitcoin
    • News
    • Price
    • Businesses
    • Technology
    • Investment
    • Regulations
    • All Bitcoin News
  • Altcoins
    • News
    • Ethereum
    • Litecoin
    • Ripple
    • EOS
    • All Altcoin News
  • Technology
    • Blockchain
    • Fintech
    • Security
  • Industry
  • How-To
  • Events
  • Press Release
Presale
  • Home
  • Bitcoin
    • News
    • Price
    • Businesses
    • Technology
    • Investment
    • Regulations
    • All Bitcoin News
  • Altcoins
    • News
    • Ethereum
    • Litecoin
    • Ripple
    • EOS
    • All Altcoin News
  • Technology
    • Blockchain
    • Fintech
    • Security
  • Industry
  • How-To
  • Events
  • Press Release
No Result
View All Result
BitCoinist News
No Result
View All Result

Building a PCI MPoC v1.1 Solution with Cryptomathic’s MASC Software

February 13, 2025
in Security
0 0
0
Home Technology Security
Share on FacebookShare on Twitter


The primary objective of the PCI MPoC (Mobile Payment on COTS) standard is to ensure that robust security mechanisms are in place for secure mobile payments on commercial off-the-shelf (COTS) devices, such as Android smartphones. 

By nature, COTS devices cannot be inherently trusted. The MPoC security model relies on mechanisms that support attestation, continuous monitoring, anomaly detection, and proactive responses. 

Adopting the MPoC security model is fundamental for enabling secure mobile payments and ensuring the integrity of Point-of-Sale (POS) transactions. 

PCI MPoC Standard Version 1.1 introduces greater flexibility in building and certifying compliant MPoC solutions 

In this document, we will give an overview of the main components of an MPoC solution and present how Cryptomathic’s Mobile Application Security Core (MASC) software can be used to implement either a PCI MPoC compliant solution or service. 

 Overview of an MPoC Solution 

 

Generalized MPoC use case with a COTS device and the surrounding environment. 

An entire MPoC solution is a set of components and processes that support mobile payment acceptance and protection of account data on a COTS device. At a minimum, the solution includes the MPoC Application and the back-end systems and environments that perform attestation, monitoring, and payment processing. Below is a breakdown of the front-end and back-end.  

On the front end:

1. The COTS: commercial off-the-shelf device, typically an Android or iOS device. 

2. Optionally, some extra hardware (e.g. connected card readers) can be used to read contact, contactless or magstripe cards. Fortunately, COTS with NFC capabilities can be used without extra hardware

3. The MPoC application: the mobile payment software application implemented and running on the COTS. This application can make use of the different device functions e.g to capture entry of cardholder PINs or account-data, via the device screen or card reader.   

On the back-end: 

4. Attestation and Monitoring component: mainly in charge of monitoring the health of the device, detect any anomalies and respond to detected threats. 

5. Payment and PIN processing: in charge of processing the payment transactions or the PIN processing once captured by the MPoC application. 

 

Note that the MPoC application running on the COTS can be monolithic or build upon existing PCI MPoC certified software like SDKs. The PCI MPoC standard defines different security requirements for the software components that compose an MPoC solution. It is also possible to build an MPoC solution that would rely on a certified Attestation and Monitoring service. Below, we give an overview of the security requirements of PCI MPoC.  

PCI MPoC Security requirements 

The following section provides an overview of PCI MPoC security requirements. 

PCI MPoC requirements are organized in different domains and sub-modules: 

Domain 

Topic of requirement 

1- MPoC Software Core Requirements 

This domain defines the foundational security requirements for MPoC software. Key areas include vulnerability management, secure cryptographic operations, and secure communication. 

2- MPoC SDK Integration 

This domain focuses on the integration of MPoC SDKs with applications to ensure secure operations.  

3- Attestation and Monitoring 

This domain ensures continuous monitoring and attestation of the security posture of MPoC applications. 

4- MPoC Software Management 

This domain addresses the management and maintenance of MPoC software, including updates and secure storage. 

5- MPoC solution 

Comprehensive requirements for the end-to-end MPoC solution, including user guidance and compliance reporting.  

 

What is MASC, and how does it help meet PCI MPoC requirements?  

MASC is a software suite composed of MASC Core and backend Assurance Service. These components address some of the core requirements in MPoC Software Core Requirements (Domain 1) and Attestation and Monitoring (Domain 3). 

 Mobile application developer relies on MASC Core SDK to secure their mobile payment application and Module 1A-CORE requirements by using among other mechanisms: 

Application integrity protection 

Cryptographic and random generation operations  

Configuration data protection 

Network stack protection 

MASC Core SDK offers a set of toolboxes to protect an application against static and dynamics threats to cover the Module 1B-COTS-based MPoC Software Protection. It includes among others: 

Anti-debug and hooking prevention by crashing the app 

Prevent memory dumping exposing sensitive keys and data 

Rooted/jailbroken device detection, 

Emulator/debugger detection, 

Data and code obfuscation, 

MASC Core SDK sentinels, along with the back-end Assurance Service’s Monitor and Reaction Engine, provide attestation and monitoring as defined by PCI MPoC. These components help meet the requirements outlined in Module 1C (Attestations and Monitoring Software) and Domain 3 (Attestation and Monitoring). 

These services allow to monitor the health of the device where the mobile application is running and to detect and to react to anomalies by blocking or crashing the app:  

Rooted/jailbroken device detection, 

Screen sharing detection, 

Keyboard and accessibility provider blacklist 

Together, the MASC software suite—including the MASC Core SDK and back-end Assurance Service—meets PCI MPoC security requirements across multiple domains (Core, SDKs, and A&M). It can be leveraged to develop a PCI MPoC-compliant solution or service. 

Cryptomathic MPoC implementation protected with our Mobile Application Security Core and connected to Obsidian for PIN management and MASC back-end service for attestation and monitoring.  

How to use Cryptomathic MASC to implement a PCI MPoC solution for PIN-entry application? 

Below is an example of the implementation of a PCI MPoC solution for PIN entry using MASC. The MASC SDK protects the MPoC application and guarantees a secure communication to the back-end systems. The MPoC application with an integrated MASC SDK automatically monitors the communication through MASC’s attestation and monitoring back-end service. The PIN is processed and stored in the Cryptomathic Obsidian platform only after successful attestation and monitoring approval. 

The diagram depicts the full solution and is composed of: 

– An MPoC application integrated with the MASC SDK. 

– An OBSIDIAN PIN processing and MASC backend Assurance Service. The Assurance Service provides the attestation and monitoring. 

Conclusion 

Cryptomathic’s MASC and Obsidian solution provides robust security measures and compliance capabilities tailored to meet the PCI MPoC Standard Version 1.1. By addressing each domain’s specific requirements, MASC enables secure mobile payment operations on COTS devices, helping businesses maintain compliance and consumer trust in an evolving threat landscape. 

About Cryptomathic. Cryptomathic is a leading provider of security solutions, offering advanced technologies to secure digital payments, identities, and communications globally. With the Mobile Application Security Core, Cryptomathic delivers unmatched protection and compliance for mobile applications in the payment ecosystem. 

 



Source link

Tags: BuildingCryptomathicsMASCMPoCPCISoftwareSolutionv1.1
Previous Post

Litecoin ETF has 90% chance to get SEC approval in 2025: Analysts

Next Post

AI Art and On-Chain Copyright Explained: What You Need to Know

Related Posts

IACR News item: 19 May 2025
Security

IACR News item: 19 May 2025

May 19, 2025
IACR News item: 17 May 2025
Security

IACR News item: 17 May 2025

May 17, 2025
IACR News item: 16 May 2025
Security

IACR News item: 16 May 2025

May 16, 2025
IACR News item: 15 May 2025
Security

IACR News item: 15 May 2025

May 15, 2025
IACR News item: 12 May 2025
Security

IACR News item: 12 May 2025

May 12, 2025
IACR News item: 09 May 2025
Security

IACR News item: 09 May 2025

May 9, 2025
Next Post
AI Art and On-Chain Copyright Explained: What You Need to Know

AI Art and On-Chain Copyright Explained: What You Need to Know

Bitcoin trades in tight range as XRP, LT, OM, and GT aim to move higher

Bitcoin trades in tight range as XRP, LT, OM, and GT aim to move higher

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

LATEST UPDATE

  • KindlyMD Shareholders Approve Merger With Bitcoin Treasury Company Nakamoto
  • XRP Price Will Still Rally From Here, Crypto Veteran Raoul Pal Forecasts
  • Riot Platforms Upsizes Credit Facility to $200M with Coinbase
  • Open Interest and Media Buzz align for $2.75 ATH Target
  • Bancor files patent infringement lawsuit against Uniswap over DEX tech
BitCoinist News

BitCoinist News delivers the latest updates, trends, and insights from the world of cryptocurrency, blockchain, and finance. Stay informed with expert analysis and in-depth coverage on Bitcoin, Ethereum, and emerging digital assets.

BITCOIN

  • News
  • Businesses
  • Technology
  • Investment
  • Regulations

ALTCOIN

  • News
  • Price
  • Ripple
  • Litecoin
  • EOS

CATEGORIES

  • Technology
  • Blockchain
  • Fintech
  • Security
  • Press Release
  • How-To
  • About Us
  • Advertise With Us
  • Disclaimer
  • Privacy Policy
  • DMCA
  • Cookie Privacy Policy
  • Terms and Conditions
  • Contact Us

Copyright © 2025 Bitcoinist News.
Bitcoinist News is not responsible for the content of external sites.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
No Result
View All Result
  • Home
  • Bitcoin
    • News
    • Price
    • Businesses
    • Technology
    • Investment
    • Regulations
    • All Bitcoin News
  • Altcoins
    • News
    • Ethereum
    • Litecoin
    • Ripple
    • EOS
    • All Altcoin News
  • Technology
    • Blockchain
    • Fintech
    • Security
  • Industry
  • How-To
  • Events
  • Press Release

Copyright © 2025 Bitcoinist News.
Bitcoinist News is not responsible for the content of external sites.