
Mitigate Identity Theft & Frauds for Banking & Financial Mobile Apps
In recent years, Unified Payments Interface (UPI) has transformed digital payment ecosystem and has emerged as a preferred mode of financial transactions. UPI has clocked monthly 11.24 billion transactions worth Rs. 17.16 Lakh Crore Rupees. Mobile financial fraud has become a lucrative business for fraudsters due to the increase in the use of UPI apps. Fraudster gains illegal access to mobile phone numbers. To mitigate these new fraud scenarios such as SIM Swapping, SIM Jacking and prevent financial losses due to such frauds National Payments Corporation of India (NPCI) has recently added/modified set of robust security controls.
To curb cyber frauds, National Payments Corporation of India (NPCI) has released master circular related to Device and SIM Binding to enhance UPI Apps security
- NPCI has mandated checking the SIM or eSIM status on Android and iOS mobiles. App developers are now compelled to integrate SIM or eSIM status checks into their security protocols.
- Device binding is not allowed while the device is in Airplane Mode
- As per NPCI guidelines, for Android and iOS mobile even if Wi-Fi is available, it permits device binding only when a SIM/e-SIM/telco (telecommunications) connection is available
- Device Binding completion in the same session
- For Android - NPCI has mandated Android mobile users that they are not allowed to toggle between apps or press any button until the device binding process is completed. The token must be invalidated if a customer moves out of active session. Auto notification pertaining to SMS charges received on customer device during registration shall not be considered as toggling.
- For iOS – For iOS mobile users, once the user is redirected to message app and if customer presses cancel or switches to another app, then application should reject the device binding. For any user registration on iOS devices, if time taken for the control to be passed from SMS composer window to application exceeds 5 seconds the customer onboarding PSP shall decline device binding.
- Device binding is not allowed if the same short code (token) is received from multiple mobile numbers.
- Set the token length to minimum 35 characters with a combination of alphanumeric and special characters.
- Block device ID for 24 hours if more than 3 tokens are generated while doing registration for device binding.
- Allow device binding registration only through the latest app version.
- SMS Token Expiry timer should not exceed 45 seconds.
- Dynamic SMS token is being created for every registration attempt.
- Private API Solution for iOS prevents editing of encrypted token and virtual mobile numbers on SMS body when a user sends SMS to register on iOS.
- Customer on-boarding on iOS/Android based Devices is allowed on iPhone devices which supports SMS sent API available from iOS 17 onwards. (Current XR/XS and above devices) and for Android it is allowed from Android API version 23 and above only.
- Every UPI App ensures at least 10 Virtual Mobile Numbers. Token should be generated dynamically and sent randomly to one of the unique VMN. VMN’s should not be in series and should not repeat.
- Every UPI application or PSP should validate successful sent check of SMS for both iOS and Android devices.
All Payment Service Providers (PSPs) are required to implement SIM and Device Binding as per National Payments Corporation of India (NPCI) mandate. SIM cards and devices add an additional layer of authentication and security. It makes SIM Swapping difficult for unauthorized users to access the account and unauthorized transactions. Implementation of SIM and Device Binding is a regulatory requirement, it can help PSPs avoid legal issues and demonstrate their commitment to mobile app security.
Read more about AppBind – Protectt.ai’s Zero Trust DEVICE & SIM Binding Solution. Safe and secure mobile banking experience with advance mobile DEVICE & SIM binding technique.
Key highlights:
- Prevents identity frauds (SIM swapping, SMS spoofing, device theft, brute force attacks and social engineering).
- Creates a unique digital identity for each mobile app user.
- Zero-factor authentication for every app launch.
- Eliminate identity theft and frauds like SMS Spoofing
- Step up Authentication using Tokenization.
- Proprietary Tech (LSAP, 3 Way Hairpin) to authenticate phone number and Looping Enhanced User experience – lesser inputs and advance security.
- Available for Android and IOS
To know more and have a detailed demo, please get in touch with us on sales@protectt.ai
Protectt.ai is ‘A Leader in Mobile App Security in India’, covering both android app security and iOS app security. Built India’s first SaaS-based, Innovative Mobile App Security platform with Runtime Application Self Protection capabilities. Protectt.ai is delivering the next generation Mobile App, Device & Transaction Security Platform with 50+ Mobile App Security features driven by Deep Tech.