Google Wallet: A brewing battle between Verizon and Google

Turf war looms over a smartphone's secure element

By Matt Hamblen, Computerworld |  Security, Google Wallet, mobile payments Add a new comment

Google Wallet

Attendees watch a demonstration of the Google wallet application screen during a news conference unveiling the mobile payment system in New York May 26, 2011.

REUTERS/Shannon Stapleton

Verizon Wireless is thwarting the use of the Google Wallet mobile payment app, at least for now, on the coming Galaxy Nexus smartphone running on Verizon's 4G LTE network.

The carrier denied it is "blocking," the app in a technical sense, but Google's simple statement made late Monday on the matter speaks volumes: "Verizon asked us not to include [Google Wallet] functionality in the [Galaxy Nexus] product."

These statements signal that a bigger battle is brewing between the Android OS maker and the nation's biggest wireless carrier. The dispute has shades of the carrier-manufacturer disagreements over which apps would be allowed on certain smartphones when mobile apps first emerged in 2008.

But mobile payments are different from other apps because of their need for security, analysts have said.

Given the potential for a huge, protracted battle between these two companies, it's a good thing that Verizon said it is "continuing our commercial discussions with Google on this issue."

What seems to be at issue is whether Verizon's security team can integrate Google Wallet into a "secure hardware element," or the system for storing private data, in phones with near field communications (NFC) technology. Google Wallet would need to work with whatever secure element Verizon and its partners in the Isis mobile payment venture are using. Isis is a consortium of wireless carriers made up of T-Mobile, AT&T and Verizon that would be compete with Google Wallet.

A smartphone 's secure element is usually a chip or a group of chips that bolsters security by recognizing a person's credit credentials apart from the phone's operating system, thus attaching an additional layer of proof for a transaction to go through. The secure element contains a user's personal information that allows a payment to be made, and that information is usually obtained with a cryptographic key.

Over the past two years, a battle has been brewing about which party should control the secure element in a smartphone. The wireless carriers want security put on a SIM chip, while the smartphone and mobile operating system makers, including Google, want the security information stored on an NFC chip or embedded within a separate chip.

That battle of where to place the secure element seems to have boiled over in the latest Google-Verizon spat.

As Gartner analyst Mark Hung pointed out in May, the owner of the payment application (in this case, Google with Google Wallet) should have a cryptographic key to control the app, regardless of which carrier provisions the smartphone.

So far, all the major credit card companies have said they are working to provide software for secure elements on upcoming NFC-ready phones that Isis will use in its mobile payment trials in Salt Lake City and Austin in 2012.

Google, meanwhile, has struck out on its own, obtaining the secure element in the Nexus S smartphone from semiconductor maker NXP, which also provides the phone's NFC chip. NXP is among several companies listed on Google's Web site as partners on Google Wallet. Another is First Data, which makes the Trusted Service Manager software that connects payment cards into a virtual wallet. Other players include MasterCard and Citi. The Nexus S 4G is the first and only smartphone to use Google Wallet, which is available on Sprint's WiMax network. Sprint, the third-largest wireless carrier is not a member of Isis.


Originally published on Computerworld |  Click here to read the original story.

ITworld LIVE

SecurityWhite Papers & Webcasts

Webcast On Demand

Seven Deadly Sins of Cloud Security (Video)

As cloud computing gains popularity, too few people are aware of the security threats that are emerging. In this short video, experts from HP discuss the latest cloud security threats and explain measures to help overcome them. Hear about the seven deadly sins of cloud security and learn how to avoid becoming a victim of poor security in your cloud environment.Intel and the Intel logo are trademarks of Intel Corporation in the U.S. and/or other countries.

Sponsor: HP & Intel

White Paper

Establishing a Strategy for Database Security is No Longer Optional

The options for securing increasingly valuable databases are very broad and deep, and can be confusing. This research provides an overview of three categories of controls that should be implemented to ensure that enterprise data is protected in the most efficient and effective manner.

White Paper

Database Activity Monitoring Is Evolving

Read the analyst report and learn how you can leverage the core capabilities of a DAP solution for better database security.

White Paper

Protecting Against Database Attacks and Insider Threats: Top 5 Scenarios

Read this new eBook to learn the top five scenarios and essential best practices for preventing database attacks and insider threats.

Webcast On Demand

Distributed Database Security with Real-time Monitoring

View this demo and learn how IBM InfoSphere Guardium database activity monitoring can help protect your sensitive data in distributed DBMS environments with a holistic approach to data security and compliance.

Sponsor: IBM

See more White Papers | Webcasts

Ask a question

Ask a Question