Mobile phone location technology fights card fraud

By Jeremy Kirk, IDG News Service |  Security, cell phone, Ericsson Add a new comment

Ericsson is courting major banks with a security service the company thinks could cut down on credit card fraud as well as eliminate an inconvenience for travelers using cards overseas.

Banks are increasingly blocking credit card transactions in certain high-risk countries due to increasingly levels of fraud. A business traveler who lives in the U.K. but goes to Russia can likely have a transaction rejected if the person hasn't informed the credit card company of their travel plans. It's embarrassing and inconvenient.

Ericsson's IPX Country Lookup service uses a person's mobile phone to provide a confirmation that a person is actually in the country where the transaction is carried out, said Peter Garside, U.K. and Ireland regional manager for Ericsson's IPX products.

For the service to work, Ericsson's technology must be installed on a mobile operator's network. Once installed, Ericsson will pay the operator a "small fee" every time a bank wants to verify a certain transaction by one of their customer's mobile phones, Garside said. Ericsson will then put a margin on the lookup fee and charge that to banks, he said. The lookup fee hasn't been set yet.

Garside said that Ericsson has figured out how to extract the location information from operators worldwide. The technology only identifies what country a person is in and not where they exactly are in that country. It only works for GSM networks.

To allay privacy concerns, Ericsson is recommending that the banks should get consumers' consent prior to using the transaction verification service. Once a person's approximate location has been passed onto the banks, that data will not be held any longer, Garside said.

The service will work even if someone's phone is off, but as long as they've turned the phone on at least once when they're in a new country. Mobile phones will register with the local operator when turned on in a different country, so Ericsson will be able to query the last known location.

The service comes out of Ericsson's IPX product line, which enables third parties to bill for ring tones or other content via mobile networks.

Garside said operators won't incur any costs to integrate the service into their networks and can make money from the location information they hold. "The operators are sitting on some valuable assets," Garside said.

Banks will be able to set their own policies around the lookup service. For example, a bank may decide it only wants to pay a lookup fee for card transactions that occur in Romania and a few other countries.

Ericsson's technology could be appealing to banks, which are facing ever-increasing levels of cross-border ATM fraud, said Peter Welch, an independent banking analyst who was briefed by Ericsson.

Close to 40 percent of the fraudulent transactions performed with U.K. cards in 2007 were done overseas, according to information published by APACS, a U.K. payment card trade association. Total fraud amounted to around £535.2 million (US$845 million).

The U.K. as well as most European countries now use the chip-and-PIN (Personal Identification Number) cards, which contain a microchip. Consumers must enter a four-digit PIN to complete a transaction, which is verified by the chip. But thieves who steal card details can create cloned cards and use them in ATMs in other countries whose cash machines to not verify that a chip is present in the card.

Bank customers would likely agree to opt-in to the service, especially it reduces the frequency with which overseas card transactions are denied, Welch said.

"I would think there is enormous potential for it," Welch said.

    Add a comment

    Post a comment using one of these accounts
    Or join now
    At least 6 characters

    Note: Comment will appear soon after you have activated your account.
    Obscene/spam comments will be removed and accounts suspended.
    The information you submit is subject to our Privacy Policy and Terms of Service.

    ITworld LIVE

    SecurityWhite Papers & Webcasts

    White Paper

    Overcome Top 7 Admin Challenges of Active Directory

    As Active Directory's role in the enterprise has drastically increased, so has the need to secure the data. Gain insight on creating repeatable, enforceable processes that reduces administrative overhead and enables robust, customizable reporting and auditing capabilities. Brought to you by NetIQ.

    White Paper

    Insiders Can Ruin Your Company. Take Action.

    Did you know that 80 percent of threats to an organization come from the inside? The threat from insiders is often overlooked in organizations worldwide. This white paper from NetIQ, discusses key technology solutions that help to prevent and detect insider threats.

    White Paper

    Top Solutions and Tools to Prevent Devastating Malware

    Custom malware frequently goes undetected. According to Forrester Research, the best way to reduce risk of breach is to deploy file integrity monitoring (FIM) tools that provide immediate alerts. This white paper has been brought to you by NetIQ, the leader in solving complex IT challenges.

    White Paper

    Streamline Compliance and Increase ROI

    Streamline, simplify, and automate compliance related activities; especially those that impact multiple business units. This white paper from NetIQ, outlines solutions that will help your business gain the maximum return on investment possible while aligning your compliance programs.

    White Paper

    X-Ray of the PCI Process-4 Proactive Steps

    This white paper from Forrester Research Inc., helps break PCI into understandable components. Security and risk professionals will gain knowledge and insight into creating a compliant and secure IT environment. Follow these four proactive steps now before your next audit. Brought to you by NetIQ.

    See more White Papers | Webcasts

    Ask a question

    Ask a Question