You are on page 1of 16

White Paper

Connecting mobile consumers


and merchants
White Paper

Contents
Executive summary 3

Key drivers of mobile commerce 3


Ease-of-use and convenience 3
Security 4
Easy adaptation to existing payment systems 5

Transaction environments 5
Remote environment 5
Local environment 5
Personal environment 5

Mobile payment landscape today 6


Operator billing 6
Remote transactions 6
Key application areas for remote payments 7
Mobile banking 7
Stock trading 7
Auction 7
Betting 7
Local transactions 7
Electronic purse 8
Person-to-person payment 8
Cross-environment transactions 8
Ticketing 8
Loyalty programs 8
Coupons 9
Receipts 9
Branding 9

Enabling technologies 9
Secure platform services 10

Nokia in the field of mobile commerce 11


Java™ and Symbian platform leaders 11
Mobile wallet for online shopping 12

Technology standardization 13

Expected market development and trends 14

Summary 14

Glossary 15

2
White Paper

Executive summary
The slogan ‘Life goes mobile’ neatly sums vending machines without change or business development for all, consumers
up Nokia’s vision of the role of mobile buying tickets while on the way to an would ideally have several different
devices in our lives today. Thanks to the event. All in all, the overall aim is secure competing payment options to choose
unbeatable benefits of size and utility and fluent mobile transactions for both from.
offered by mobile terminals, we can rely the consumer and merchant. Consistency
on mobile applications and services to as well as convenience needs to be a Today’s mobile commerce markets are
make our lives more fluent and priority in order to make mobile still at a fairly early stage of
enjoyable. In the developed countries, commerce services really take-off. development. Yet, mobile commerce is
purchasing has shifted more and more expected to be an important opportunity,
towards electronic payments, as cash Currently, digital content purchases so the key stakeholders such as network
use has decreased and card based dominate mobile commerce markets – operators, financial institutions, and
payments as well as online shopping nearly all business today comes from mobile terminal vendors are investing
have increased. selling operator logos and ringing tones, to develop both the market and the
making the operator billing system the technology. For developers and service
Convenience is probably the most most commonly used and most providers, mobile commerce offers the
important benefit of mobile commerce. practical payment method. This also chance to diversify their scope of
By reducing the need to carry cash, influences content developers, as parts operation. There is a clear need both for
credit or debit cards, the mobile device of their revenue is directed to the standardized solutions that merchants
allows consumers to make purchases operator commissions in the operator can implement, and to make wireless
virtually anywhere, such as using billing model. To ensure profitable processing attractive.

Key drivers of mobile commerce


Mobile commerce can be defined as any Ease-of-use and Furthermore, mobile phones themselves
electronic transaction or information have their limitations, such as a small
interaction conducted using a mobile convenience display and limited input capabilities.
device and network that leads to transfer Nonetheless, factors such as mobility,
of value in exchange for information, Usability issues are critical if a service is availability, personalization, and ease-of-
services or goods. Mobile commerce to become a commercial success. With use can easily overcome the limitations
allows the consumer to carry out the mobile commerce, the user experience of a pocket-sized device. Moreover,
transaction using the mobile terminal, covers much more than the browser technological advancements, with bigger
whereas many other parts of the trading display of a particular shop site presenting mobile phone colour displays, XHTML
cycle – promotion, selection, ordering, a list of products for sale. The transaction browsers and faster and safer connections
payment fulfillment and delivery – process must proceed naturally and (GPRS, EGPRS, TSL/SSL) have improved
might occur using traditional channels logically, and be familiar after the first the experience of the user, making
or fixed line PCs. Intangible goods such time. The complexity of the payment mobile services much more appealing.
as ringing tones or Java™ Midlets can infrastructure should be hidden from
also be delivered to the phone in digital the consumer to avoid unnecessary It is worth noting that mobile phones
form, making it possible to cover all confusion – consumers should not have already outnumber personal computers
parts of the trading cycle with a mobile to worry about interoperability or other and there are currently more than one
terminal. technological issues, and should be free billion mobile subscribers in the world.
to enjoy seamless access to content. With mobility, services have become
Key drivers of the adoption of mobile far more accessible and are no longer
commerce services are ease-of-use, Ease-of-use depends partly on how often restricted to a specific location or
cost efficiency and convenience, as well the subscriber uses the service. opening hours. Mobile devices also
as the vital issue of security. In addition, Encouraging the use of the mobile phone provide convenience, because they can
mobile commerce solutions must be as a payment device will, of course, be used in seconds, unlike a PC.
based on open and global standards require value-added mobile commerce Furthermore, greater session security
and technologies. In the long term, services. It is not enough to simply develop and more secure client authentication
they are the only way to mass-market mobile extensions of current Internet methods for mobile payments will give
growth and a balanced ecosystem. services, since not all of them will suit mobile phones an undisputed advantage
the characteristics of the mobile world. in conducting e-business.

3
White Paper

Security
Micro-payments Macro-payments
When conducting monetary transactions, Priority on Priority on
convenience security
security is a key consideration. In mobile
commerce, security measures should be
Information
adjusted according to the value of the ty
uri
Video clips Sec
transaction and there are different

Number of transactions
Ringing tones
solutions available for different needs. Digital
Single city transport tickets signature
The following figure illustrates the
Screen savers
different levels of security needed by Music
Event tickets Trading
varying types of services. All in all, Games Travel
Bill payment, banking
the question is about risk management CDs
Flowers
and matching the right services and Gifts
Simple
solutions together. authentication Catalog shopping
(e.g. MSISDN)
Public transport season ticket
During its existence, the WAP Forum
specified security components that can Value of transaction
be used to provide high session security
when making mobile commerce Figure 1. The level of security depends on the value of the transaction.
transactions in remote environments,
that is, over a wireless network.
The Open Mobile Alliance (OMA) has
continued this by adopting former WAP
WAP 1.x
Forum specifications as part of the
overall architecture. Wireless Transport
WTLS WAP Gateway SSL
Layer Security (WTLS) enables server
Connection is Secure as such,
authentication and data encryption, secure only to The whole end-to-end but data may have
invisibly encrypting and decrypting the WAP gateway security cannot be assured been manipulated or
due to the security gap read in the gateway
information sent between a WAP client in the gateway
and a WAP gateway and aiming to
prevent a third party from deciphering WAP 2.0
the communication between these two
parties. The protocol also protects the HTTPS/TLS, SSL
integrity of communications, enabling WAP Gateway
acting as
the recipient of information to verify a WAP 2.0 proxy
that content has not been altered in
Security is comparable to the Internet model –
transit. transaction all the way to the origin server will be secure

The evolution to WAP 2.0, the next step Figure 2. TCP/IP enables improved security over data connections from the mobile device to the network.
in mobile browsing, allows access over
TCP/IP, which is the standard Internet
transmission control protocol that
allows data to be sent in fixed or mobile
networks. Nowadays nearly all new Based on the Internet security protocol A digital signature can be used for
terminals support WAP 2.0. Compared to Secure Sockets Layer (SSL), TLS is a authentication or non-repudiation
the WAP 1.x stack, TCP/IP enables greater standard for enabling secure Internet purposes (e.g., signing a document or
end-to-end security and means less connections between the devices and confirming a transaction), which are key
protocol conversion – it also provides origin servers by establishing a TLS conditions in establishing the merits for
reliable connections with larger data tunnel in the gateway. SSL and TLS will legally binding commercial transactions.
files. Previously, there were different ensure real end-to-end security with no The digital signature is executed in the
encoding protocols used between the security gap (that is, security protocol WAP application security layer and
mobile device and the WAP gateway and conversion inside the gateway). confirmed by a code.
between the WAP gateway and the In practice, this means improved
network. TCP/IP enables Transport Layer security for information-sensitive Mobile wallets, used alongside digital
Security (TLS) to be used all the way applications such as mobile payments. signatures, greatly improve security in
from the device to the origin server. mobile transactions, and are also
This is depicted in Figure 2. convenient and easy to use.

4
White Paper

Easy adaptation to Transaction environments


existing payment systems
Mobile transactions can be performed Local environment
Existing payment methods and protocols in three environments – remote, local,
have gone through a long process of and personal. Each environment has its In a local – or proximity – environment,
evolution and it has taken a long time to own mobile commerce services and the consumer is in the vicinity of the
develop payment systems that are characteristics that may require specific “other end,” and mobile transactions
globally accepted and adopted. For this technologies. Mobile phones will become are usually initiated over short-range
reason, it is important for mobile the ultimate transaction devices by wireless technology. Performance
payments to be based on existing combining all three environments. requirements for local transactions,
methods and standards if they are to such as speed and ease-of-use, are high,
penetrate the market quickly. Up to now, meaning that transactions must be
most mobile services have been based simple “swipe” transactions with
on SMS, and have thus been charged for
Remote environment extremely low transaction latency.
in the phone bills of mobile network In a remote – or online – environment, Radio Frequency Identification (RFID)
operators. By developing applications transactions are conducted over a is an example of a technology that can
and services that support other payment wireless network, and the physical give convenient local transactions as
methods, a larger number of consumers location of the consumer is not very RF technology is already used in many
will be able to buy a widening set of relevant to their actions. Most remote places, such as access control and public
goods and services. transactions, similar to those conducted transport.
online over the Internet, are conducted
Credit cards are widely used on the with menu-driven applications, resulting Local purchases can be both low cost
fixed-line Internet and can be adapted in a higher latency in transaction time. and impulsive, such as buying a soft
to mobile use. Personal transaction In remote transactions, the phone’s UI drink from a vending machine, or mid-
information, such as the cardholder’s is of paramount importance as it must to high-cost and non-impulsive, such as
name, address, credit card number, relay all relevant information to buying and using an event ticket.
and expiration date can be filled in quite maintain the user’s trust and ensure The payment method can vary from
easily via a PC keyboard, but it takes usability of the services. card payments to prepaid accounts.
time and effort with a mobile phone
keyboard. Some Internet services support Remote transactions range from online
an automatic information exchange purchases and banking to more impulsive
specification called Electronic Commerce activities such as downloading digital
Personal environment
Modeling Language (ECML). Likewise, content. In most cases, the underlying In a personal environment, mobile
the same standard can be used in mobile technology used is Wireless Application transactions are usually conducted on
services. Nokia’s wallet application Protocol (WAP) over a network the UI of another device and augmented
supports the same specification and operator-provided bearer, such as Circuit by security, connectivity, or other
offers a user-friendly solution for Switched Data (CSD) or General Packet functionality provided by the user’s
transferring transaction information via Radio Service (GPRS). The payment mobile phone. This implies that the
a mobile phone. method can vary from card payment to user’s interaction with the mobile device
operator billing, depending on the is limited to, for example, security-
nature of the purchase. The transition to essential functions such as PIN entry,
Extensible Hypertext Markup Language since the primary interaction is with
(XHTML) as the standard browser the device at the other end of the
language and the switch to using the connection.
TCP/IP stack at the transport layer are
expected to increase the number of
remote transactions, as they provide a
richer browsing experience as well as
faster and more secure connections.

5
White Paper

Mobile payment landscape today


Commissions for mobile payments are
currently all generated from the digital Payment commission m€
content micro-payments. Consumers 8000
personalize their mobile phones with Digital content
7000
ring tones, graphics, and so forth and Remote payment
games, downloadable phone 6000
Local payment
applications, as well as music and video
5000
clips, are also growing in popularity.
Because remote and local payments are 4000
not expected to play more important
3000
roles for a few more years, there has
developed a huge gap between digital 2000
content payments and all other forms.
1000
Actually, due to the enormous
dominance of digital content micro- 0
payments, it is very difficult to estimate 2002 2003 2004 2005 2006 2007

when and to what degree local and


remote payments will take-off. This is Figure 3. Mobile Payment Commissions, Source: Nokia Mobile Services forecast 2003.
illustrated in more detail in Figure 3.

This forecast figure is based on the For additional mobile payment methods postpaid shopping account that can also
assumptions that digital content to grow in usability, banks and card be used for non card owners – parents
payment commission is on average 25%, associations need to come up with topping up children’s accounts).
for remote payments approximately 9% solutions that are as simple and easy to Operators too are interested in reducing
and for local payments around 6%. use as operator billing is. Also merchants the number of integrations and have
need to be provided with similar started to form payment consortia e.g.
payment handling options that have SIMpay. All these are steps to improve
been traditional for physical and Internet the field, yet they all must compete with
Operator billing payments. These solutions need to be the convenience of operator billing.
Operator billing is currently the familiar to the ones people are already
dominant method of micro-payment. using, merely a way to bring similar
This is mainly seen as very convenient transactions safely into the mobile
by the consumer, although at times they environment.
Remote transactions
might also value the flexibility of Mobile on-line shopping is a mobile
different payment methods. Moreover, The merchants also see benefits from extension to established electronic
the choice of products and services is operator billing, as it is currently the commerce where goods, services or
limited because of the billing system. only way to handle micro-payments digital content are purchased over the
economically. The possible hindrances mobile Internet. The mobile phone adds
For the operator, there may be legal and here come in the form of several value mainly through its mobility and
practical hindrances as not all goods or integrations required, each with a availability, yet on the other hand,
amounts are billable on the phone bill. proprietary interface. the pocket-sized device with its limited
Furthermore, there might also be a UI capabilities has some challenges for
credit risk for the operator when content Therefore, due to the overall service providers. This has raised the
value increases. functionality of the operator billing, possibility of using different channels
merchants are now taking a closer look product selection – (PC, Catalogue) – and
The long-standing tradition and at alternatives. These could include, for actual payment (mobile phone).
dominance of operator billing is most for instance, subscriptions and
likely to do with the fact that there has transaction aggregation. In addition, The main mobile on-line shopping items
yet not been business cases for financial there are also other players interested in are prepaid account top-up, digital
institutions in this field. Also, it has the field of micro-payments. These could content, tickets, familiar “top-ten”
been so easy for the users to be able to be banks (e.g. Mobilecash: a multi-bank products, games, DVDs, CDs, etc. Digital
purchase goods without any specific mobile payment service using existing content shopping has so far has been
registration and have all the digital banking infrastructure and consumer mainly operator logos, screen savers,
goods purchased just added to their and merchant relationships) and credit pictures for messages and ringing tones.
phone bill. card companies (e.g. Visa, pre- or New terminal technologies such as Java,

6
White Paper

music/video players, DRM, etc. will Stock trading providing even more freedom of place
expand the consumption of content and In many western countries, stock trading and time, allowing people to watch a
the digital content business. and money investing have become football match in the arena or in a bar
much more common among the wider and bet on who will score the first goal
Typically, the following phases can be population. The ability to monitor the in the second half.
identified in a mobile on-line shopping market and trade wherever and
transaction: whenever they want are the key
• Browsing including goods selection elements for investors who are looking
• Payment method selection for short-term earnings.
Local transactions
• User authentication Not all merchants are interested in how
• Transaction authorization Although the actual target consumer people pay, yet they are all interested in
• Transaction acknowledgement group for mobile stock trading is very having them as customers. If given a
• Goods or service delivery either small, the typical value of the stock choice, customers will decide, and for a
digitally or physically trading is high and therefore there is a wireless payment method to prevail,
need for strong authentication and it has to be easier than cash and card
non-repudiation. Push type information payments. Questions such as “Does it
services combined with transaction speed up the transaction process? Does
Key application areas services will increase the value of the it bring value?” need to be answered in
for remote payments mobile phone for stockholders. order to make local transactions
successful in mobile commerce.
Mobile banking Auction In general, to make mobile commerce
Since nearly everyone has a bank There has been great deal of interest in happen, the user’s experience with
account and pays bills regularly, mobile online auctions, especially in the US. payments needs to be consistent, fast,
banking can be seen as a mobile Used cars and business items have been convenient, transparent, employ
commerce application with very good sold online on the Internet for the best hassle-free technology and provide a
potential. A key driver for e-banking offer. The biggest advantage for bidders beneficial, value-added service.
services has been the general cost is that they do not need to be physically
reductions in the banking branch present at the auction and a bidder can The mobile phone can be used as a
networks. It has been estimated that by receive a message on their phone when payment instrument in the local
2006 two-thirds of invoices will be their bid is beaten. environment instead of cash or payment
electronic (Litan – Gartner Research cards. The primary market for local
2003). Mobile banking will continue this However, a mobile channel is seen more payment solutions will be consumers in
trend, adding value with virtually as a customer service providing only unattended or “loosely attended” trading
anytime mobile phone capability and monitoring. The channel itself is not places such as fast food restaurants,
new push type services for e.g. bill seen as a revenue generator – rather, filling stations, retail stores, ticket
payment. These, combined with money goes to the company arranging dispensers, vending machines and
convenient and strong authentication, on-line auctions when people place parking meters. Mobile payment fits well
digital signature functionality, and the something for sale. The starting of with unattended stations where
ability to get rid of costly one-time auctions through the mobile device is magnetic stripe or contact card based
password lists will be the key drivers not seen as likely. terminals can be inoperable because of
for mobile banking. vandalism or where cash management
The use of a digital signature feature is clearly not cost-effective. It seems that
Banks have been very concerned about would provide non-repudiation for the overall solution for places such as
potential security risks jeopardizing mobile auctions. these will be achieved with contact less
their reputation as a main trust provider. cards, with mobile phones employing a
Yet, many of the most advanced banks Betting contact less card interface.
are making significant numbers of Horse racing and betting have
transactions and related services traditionally gone hand in hand. Mobile phone payment in a normal retail
through the Internet. Ease of use, cost of Nowadays betting is an essential part of store is very tempting because of the
service and security are also key many sporting events. It is a huge potentially large volumes, yet it is also
components to allow high volume business and betting offices are very challenging – it’s very hard to beat
banking services. Mobile banking can be constantly developing new betting the speed and convenience of the existing
implemented as a browser service or methods and new alternatives for payment methods. The possibility of
using some specific midlet – both betting. Online betting on the Internet combining loyalty programs with the
options are currently gaining support has already taken off, providing freedom payment transaction and speeding up
from the industry. from betting outlets and enabling last the actual payment process could be
minute betting at home or from the selling points for mobile payment in
office. Mobile betting however is this area.

7
White Paper

Local transactions can be divided into Fast and convenient “swipe” Menu driven transactions
two categories, as depicted in Table 1. transactions

The key requirement for local payment Low-cost, impulse purchases Mid-to-high cost, non-impulse purchases
is to adapt to an existing payment
settlement backbone. High-volume commodity transactions Lower-volume, non-commodity
transactions
Extremely low transaction-latency Higher-latency in transaction time
Electronic purse expected accepted
Electronic purse is a smart card
application containing real value in the Applications: vending machines, Applications: ticket purchases, groceries,
form of electronic money paid for in ticketing, parking restaurants
advance. The card, which can be
Table 1.
reloaded with further funds, can be used
for a range of purposes. From a pure
technology point of view, a mobile
electronic purse solution could be very
similar to a mobile ticketing solution Cross-environment Multi-application environments will be
for public transport – the value (money, built up, such as a city-card system
ticket) is downloaded remotely in a
transactions where one device can be used for several
secure way to the phone and then used purposes. The technology will be contact
locally over a RF interface. This is a very This section gives more details of the cards, contact less cards and/or dual
important area that demands that mobile commerce sectors, which are interface cards including both contact
operators and banks provide micro- valid for both remote and local and contact less interfaces. Although
payments economically, with the key transactions. ticketing is one of the main applications
being lower fixed costs per transaction. in the card, the issue is how to manage
This type of solution will compete with Ticketing the different applications and will there
operator billing for micro-payments A ticket serves as a certificate, license, be a main card issuer? How can the
and will probably provide the basis for or permit. Traditionally in paper format, new applications be set in an easy and
local micro-payment solutions, yet digital tickets are already quite widely secure way? The mobile terminal may
currently it is not widely implemented. used in areas such as public transport. help in this case if applications can be
The concept can be roughly divided downloaded over the air, turning the
into event (cinema, concert, match, etc.) mobile phone into a secure multi-
Person-to-person payment and transport (bus, train, plane, etc.) application platform.
Person-to-person payment in the mobile ticketing.
environment means that a person The main motivations for going to
transfers electronic money from his Tickets can be time-based (e.g., a season mobile ticketing are convenience for the
electronic purse or server based account ticket), value-based (e.g., purse user, cost savings for the ticket service
to another person’s electronic purse or application), one-time or a multi-time provider and the mobile terminal as an
account. Although the technology used ticket or a combination of these and a information channel for both parties.
in person-to-person transactions may mobile ticketing platform should The solution where the ticket has been
use the remote connectivity of the accommodate all types of ticketing. bought over the public network, stored
mobile phone, it can also be used very Tickets often have a monetary value, in the phone and used locally will offer
locally, with two persons being together and so the security of ticket transfers the most interesting benefits for all
when the money is lent or paid back. and processing is important. ticketing applications.

Ticketing can be divided into three phases Loyalty programs


– ticket purchasing, most likely over a Nowadays loyalty programs are an
remote connection, ticket management essential part of customer relationship
including browsing of ticket details, management. Their target is to increase
and ticket usage (i.e. validation), customer loyalty in the traditional local
typically over a local connection. Digital payment environment, such as retail
tickets combined with mobile phone shop chains. They are also a way to
local and remote connectivity and ticket collect important customer information,
management capability, will offer clear which can be used for direct marketing
benefits for ticketing compared to any purposes, or trading customer
existing ticketing models. information if this is permitted. So far,

8
White Paper

loyalty programs have not played an These advantages may see digital real-world counterpart to be understood,
important role in Internet e-commerce. receipts become a key functionality that let alone trusted. This can be alleviated
A mobile phone can add value for remote will boost the use of mobile phones for by adding metaphors and associations
payment by combining a payment and payment. to the physical realm that make it easier
loyalty method in an easy and flexible for the user to understand what is
way and convenient loyalty card support Branding happening and assess the level of trust
is certainly crucial to enable local mobile Branding, in this context, refers to he has in the proceedings. The presence
payments. conveying information to the user about of the trusted brands that the user
the branded services that form part of normally associates with payments thus
Coupons the payment transaction. This is makes the digital transactions feel more
In certain countries, coupons are widely accomplished by displaying the media familiar.
used to entice consumers to shops or (images, animations, sounds) associated
certain Internet market places or to buy with the said brand. This media is Nowadays the brand information is
things they would not otherwise be made familiar to the user beforehand, mostly conveyed via images – printed
aware of. Since the mobile phone is a by the brand owner’s publicity effort logos on receipts, credit card
personal device with remote and through day-to-day use. organization logos on plastic cards etc.
connectivity, it can be considered as an Thus the user’s familiarity with and
attractive direct marketing object. While brand media does not directly trust in transactions via the mobile
Coupons with a certain value require convey any monetary value, familiar terminal can be enhanced by displaying
security functionalities such as DRM and brands are an integral part of the the same brand imagery throughout the
a method of using them in financial payment process. The customer expects digital transaction – that is, showing a
transactions. Moreover, if direct to see the logos of a shop chain, credit credit card organization’s logo (or media
marketing (privacy) legislation allows, issuer or loyalty scheme displayed clip) in connection with paying by credit
coupons may play an important role as during the transaction and as such card, or showing a loyalty scheme logo
a direct marketing method including they help boost confidence that it will in order to assure the user that the
commercial value. proceed in the correct way. loyalty scheme has been active during
the transaction. However, it is crucial to
Receipts When moving from physical to digital understand that there are other
A receipt is a document provided by a payment transactions, digital may seem important factors in creating trust, such
merchant, recording the details of the to the user to be too detached from its as consistency of use.
transaction for the customer to retain as
a proof of purchase. The customer may
use this proof of purchase in several
ways, for example as:
• a detailed transaction record for
tracking their personal finances Enabling technologies
• as evidence of a reimbursable expense
to an employer When conducting remote payments, discover downloadable content and
• a warranty, i.e. a proof of purchase to the connection between the content server infotainment.
enable the return of goods to the and the mobile phone is established via
retailer with whom the original a PLMN (Public Land Mobile Network), With the introduction of XHTML Mobile
purchase was made such as the GSM cellular network, which Profile and Wireless Cascading Style
includes bearers such as SMS and GPRS. Sheets (WSSC), the industry is now able
Replacing paper receipts with digital Currently, most mobile content is still to offer compelling, rich and full color
ones in a mobile phone would give paid based on premium rate SMSs, services to users, providing revenue
numerous advantages for the mobile the biggest advantage of which is that it opportunities for operators as well as
phone user: does not require a special web services service providers, content owners and
• Eliminating manual entry of payment interface. Premium rate SMS media companies.
transaction information for personal use will be expanded to Java midlets.
financial accounts or creating expense The next generation mobile services are
reports GPRS has taken over as a primary bearer specified as WAP 2.0 from the WAP
• More detailed tracking of items for mobile Internet. Its adoption along Forum. The specifications have two key
purchased based on date, location, with mobile terminals with color screens elements – the mark-up language
and amount has brought notable benefits to the user, changes to XHTML MP and the
• Reduce or eventually eliminate the both in terms of speed and the overall transmission protocol becomes Wireless
loss of receipts experience of mobile browsing, which Profiled TCP/IP. The industry started to
• Lighten the physical wallet remains one of the most important implement Wireless Profiled TCP/IP in
phone applications and the main way to mid 2003 – it is compatible with

9
White Paper

standard TCP/IP, but includes optimized Moreover, a new RFID technology, Secure platform services
settings to improve performance over Near Field Communication (NFC),
wireless links. Both XTHML and TCP/IP is currently being standardized. As well Various mobile commerce applications
are standards on the fixed Internet, as RFID reader and tag functionality, need secure platform services – a good
so this migration supports the this technology specifies a truly example here is secure storage to store
convergence of the mobile and fixed bi-directional, active communication sensitive payment data in a mobile
domains. mode between two reader devices. wallet. Such services can be offered
Other than that, functional capabilities through a terminal platform.
WTCP/IP will also provide faster data of NFC resemble the ones described
transfer for larger files, better end-to-end earlier in this section. Note that Terminal platform based security
security, and more advanced bi-directional communication in The platform security approach has
applications, resulting in an enhanced mobile terminals is not seen as a likely become something of a trend due to the
browsing experience for the consumer. development. increasing requirements of new
Financial applications such as banking application areas, such as mobile
and Verified by Visa payments will There are several radio frequency commerce and content delivery requiring
benefit from end-to-end encryption technologies using different frequencies copyright protection. The opening of the
enabled by migration to wtCP/IP and modulation methods. Nokia’s terminal platform to third party
transport, as they can now waive their solutions in mobile commerce are applications is the biggest motivation
own secured gateways and instead based on open technologies hence ISO here – issues such as protecting a user
specify a normal Internet address, in the 14443 A/B (supported all over the world) against hostile content is very important
same way as on the fixed Internet. standard is preferred. – obviously with links with mobile
commerce security too. Until now, most
With local payments, the methods for RF contact less technology is most mobile commerce concepts requiring
data transfer are numerous, for example, suitable for fast and convenient “wipe” high security have been able to rely on
Bluetooth and RF are all possible options. transactions and impulse transactions smart cards, with the help of e.g. SIM
Bluetooth is a radio interface operating (vending machines, ticketing, parking, Toolkit support from a terminal.
at 2.4 GHz and is specified by the etc.) with low-cost and applications
Bluetooth Special Interest Group. It has a based on it are already used all over The idea of a phone as the only wallet
theoretical range of several 10s of meters the world: authentication (SpeedPass, for a user will challenge this approach in
and will work out of sight through Toll Tag), asset tracking (Ford, luggage the near future. Sensitive transactional
non-shielding materials. The data rate at airports), access control (automobiles, data including various payment
depends on the implementation and corporate campuses, public transport, instruments is not technically feasible to
the balance between up & down traffic ski lifts), etc. implement based on smart cards only.
and has a maximum of 721 kb/s in one The same is also true with other relevant
direction. It requires power at both RF contact less technology can be features such as Secure UI, where the
ends and the basic interface supports adapted to a mobile terminal either purpose is to make sure that a user
bi-directional, full duplex block exchange based on a smart card or as an interface is protected against attacks,
with transport level encryption. integrated solution. RF contact less is such as trying to steal a user’s PIN code
definitely the most promising candidate by mimicking some real transaction.
Radio Frequency technology enables for local transactions from a technology Secure UI functionality is relevant not
a short-range bi-directional RF perspective. only for Nokia made applications,
transmission for operation at 134.2 kHz but also for 3rd party network based
and 13.56 MHz. It is a battery free functionalities.
technology transferring power and
data at the same time over the air. The importance of OS security is
The cheapest RF tags are read-only currently very high. Clearly, the terminal
with a very small memory. The most platform will notably increase its role
powerful chips include microprocessors, as a secure application platform in the
which can be used via contacts or next few years.
contact less (so called dual interface
chips) with all the security functions
developed for smart cards. The most
important feature of RF contact less
technology is easy and fast local
connection with adequate security.

10
White Paper

Nokia in the field of mobile commerce


Nokia actively improves mobile
applications with a special focus on Millions
usability. For the consumers, using 800
services needs to be self guiding and Total shipments
700
effortless and the technological Worldwide Java phone shipments
advancements in display sizes and 600
more intuitive graphical user-interfaces
500
are of high value.
In 2008,
400 85% of the
Furthermore, in the field of mobile shipped
300 terminals
commerce, Nokia supports all relevant support Java
scenarios with secure and safe 200
transactions and with the aim of making
100
them easy to use for the consumer.
Nokia supports several different user 0
authentication methods – certificates 2002 2003 2004 2005 2006 2007 2008

and WIM as well as GSM authentication


for operator transactions. Secure Figure 4. Java enabled terminals’ share of total global shipments. Source: ARC 2003.
transmissions are achieved with WTLS
and SSL/TLS connections.

To protect content, OMA Digital Rights Smartphones shipped (million)


Management (DRM) is applied. The basic 120
Symbian
requirement is that copyright protection
is achieved through forward lock. More 100 WMS
flexible content business is achieved Linux
with the option to preview protected 80 Palm
content before purchasing, as well as
Other
applying time and play count-based 60
usage rights. Reliable delivery can be
ensured with the use of Java and OMA 40
DL technologies.
20
Now that service discovery has improved
greatly, the latest technological 0
advancements, such as high-quality 2003 2004 2005 2006 2007 2008
colour displays and next generation
XHTML browsers over TCP/IP, allow users Figure 5. Symbian terminals constitute the largest and fastest growing segment in the category of smart phones and PDAs.
to enjoy richer and more compelling Source: ARC Chart Nov 2003.
graphical content and increased
efficiency for large data files. Perhaps
the most tangible advancement in the
field of mobile commerce is the new which allows services to become much Symbian terminals are based on a
mobile wallet application, which brings more versatile, ranging from games to dominant smart phone software
added confidence and convenience. information and enterprise applications platform, with total volumes exceeding
using richer multimedia and advanced those of Palm and others together
network capabilities. This makes Java a (ARC Chart Nov 2003, see Figure 5).
major opportunity for developers and For example, an estimate in 2003 from
Java™ and Symbian service providers. Both Java and Symbian Canalys estimates that phones based on
platform leaders OS are open platforms for application Symbian OS accounted for 94% of all
development and are also widely feature phones and smart phones in the
Although digital content is already the supported in Nokia terminals. EMEA region in Q2, 2003.
dominant form of mobile commerce
goods, there is still plenty of new Java will be a standard feature across
business potential in this field. Here a terminals in the next few years. Figure 4.
key accelerator is Java technology, illustrates the expected growth in this area.

11
White Paper

Mobile wallet for online


shopping
Electronic commerce frequently requires
a substantial exchange of information in
order to complete a purchase or other
transaction. The person making a
purchase needs to enter his name,
payment card number and expiry date,
possibly also the delivery address and
other details. Particularly with a mobile
device, which in many cases have
limited input capabilities, keying in all
the required data can be rather time-
consuming and error prone. However,
the main factors driving the usage of
mobile transactions are ease of use and
convenience.

The new version of the wallet application,


first introduced in the Nokia 6220 and
Nokia 6600 phones, makes service
access and mobile payment easy and Figure 6. An example showing how a wallet populates the transaction details and Verified by Visa authenticates the user
convenient for mobile users. It allows before the transaction is completed, Source: Modirum.
users to store a range of personal
information on their mobile phone,
such as usernames and passwords for Consumers Financial institutions Developers
different mobile services, credit and other Easy and convenient More secure and New business opportunities
service access and user friendly using existing standard
payment card details, delivery addresses mobile payment payment services technologies and tools
and personal notes, and retrieve the
data easily during a browsing session to
fill in required data fields.

The obvious benefit for the user is that


there is now no need to remember
passwords, card numbers and best of all,
no need to manually fill in the data
when using the mobile channel for
transactions. In practice, this reduces
significantly the number of actions
required by the user during a browsing
session. The necessary data can be
sent to the application over-the-air by
service providers and card issuers or Mobile operators Merchants
Increased data traffic Opportunity to easily add
alternatively, consumers can manually and a growing number a mobile channel and to
enter data into the wallet. By using data of mobile purchases create totally new services

that is pre-stored in the terminal, there


is a smaller risk of typos and errors, Figure 7. Key benefits of the mobile wallet.
which are quite common, particularly
with long number sequences.
one who knows the secret password for The 3D secure model is a global solution
All the data in the wallet is encrypted the wallet application. The wallet is most for online payment authentication
and the application can be accessed only appropriate for remote macro-payments. supported by Visa, MasterCard, banks,
with a wallet PIN code. This way, mobile retailers and 3rd parties across North
shopping is not only more convenient In Figure 6 there is an example of how a America, Europe and APAC. The main
and faster, it is also much safer as the wallet can be used with a 3D Secure aim of the 3D model is to help merchants
owner of the mobile phone is the only mobile Verified by Visa transaction. reduce the cost of online fraud. 80% of

12
White Paper

the costly charge backs occur when The wallet was created in order to
cardholders state that they did not improve the usability of mobile services,
participate in or authorize the yet, it is not only the mobile users who
transaction. If a merchant supports the will greatly benefit from this application
3D model it automatically means a shift – all the players in the field will benefit
in liability from merchant to issuer from the growing amount of service
bank. Visa and Nokia have successfully usage. Figure 7 summarizes the key
tested the 3D secure model in a mobile benefits of the wallet application.
environment.

Technology standardization
As an avid supporter of open platforms Payment Forum complements the work signing/authentication API and the
and technologies, Nokia has been an of other industry consortia and has smart card access API. Currently Nokia is
active participant in forming and endorsed several MeT specifications. looking to start a new JSR to define Java
shaping the standardization landscape payment API.
for the needs of digital convergence in The mission of Nokia in MPF is to
numerous different standardization identify and promote solutions that are OMA – Open Mobile Alliance is chartered
organizations. Here is a brief account of of business value to operators while to deliver the open architecture for
some the standardization fora that are preserving terminal value. mobile services. The m-commerce
also relevant to mobile commerce. workgroup was created in late 2002 to
MoBey Forum works as a consolidated analyze the gap in the global m-commerce
MeT Initiative – MeT is the voice of voice of the financial industry regarding landscape. It is uncertain what the next
mobile phone manufacturers. Financial mobile commerce and other financial charter of the group will be. The main
institutions and operators may require services and acts as a forum where needs driver has been the standardization of
manufacturers to include excessive and can be expressed and requirements can operators’ back-office payment interface
proprietary features in mobile phones – be discussed. In addition, the forum for web services.
MeT counteracts this by proposing a promotes mobile commerce to financial
reasonable set of standardized services, institutions. IrDA – The goal of IrDA is to develop and
which enable mobile commerce promote infrared communications for
applications. Nokia representation is strong at the use in the local environment. IrDA has
management level and within the successfully developed several standards,
MeT focuses on mobile phones, defining Business Workgroup. which are widely used.
the minimum set of additional
functionality that may enable the It is expected that the main outcome Bluetooth SIG is developing the Bluetooth
maximum application area, while from the Forum will be the continuous short-range radio communication
preserving the best usability. Nokia has discussion that will shape the acceptable standard. Current work concentrates on
a strong presence in MeT. requirements. Further, Nokia is using development of release 2 of the standard,
MoBey to try out new solutions for which will address several usability issues.
Mobile Payment Forum – The Forum mobile commerce.
was launched late 2001 by the four major The SRFT group within Bluetooth SIG has
payment organizations, American Express, Java Community Process – The JCP is been specifying requirements for the
JCB Co., Ltd., MasterCard International an open organization to develop effective use of Bluetooth for mobile
and Visa International. It currently has components of the Java platform and to commerce. SRFT has no plans to define
approximately 50 members representing offer suggestions for improving and an alternative payment system.
the mobile, technology and financial growing the technology.
industry, with a strong presence from It is believed that the second release of
mobile operators. The terminal-side mobile commerce is the Bluetooth radio specification will
addressed currently by JSR120 (Wireless enable the use of Bluetooth for financial
The main focus of the MPF is to enable Messaging API) and JSR177 (Security and transactions. However, Bluetooth will
mobile commerce by evaluating and Trust Services API for J2ME). JSR120 can remain as the communication channel
improving payment methods based on be used for payments using premium rather than the mobile transaction
existing card relationships. The Mobile rate SMS. JSR177 effectively defines the standard.

13
White Paper

Expected market development and trends


A major trend among mobile terminals reduce fraud by leveraging their concrete and easily identifiable benefit
is that they can handle more and more authentication capabilities. However, for the user. The necessary enabler for
applications and new types of content, reducing fraud vs. merchant cost would ticketing will be remote payment.
which is a clear expansion on current require additions to the payment
ringing tone and logo sales. Symbian OS back-end. An increasing focus on stored Merchants will be in a key position in
and Java are opening up new value is making micro-payments more the development of mobile commerce.
possibilities for application developers economical for merchants. This new concept must be sold to them,
and the user can easily configure and since they need to invest to update their
personalize the functionality of the Now Visa and MasterCard have launched current point of sales (POS) terminals.
terminal to match his needs. Third parties their 3D secure model, shifting global It’s not realistic to expect merchants to
can also implement the applications. liability from the merchant to the issuer. make radical changes to their existing
A healthy content and service providers’ Therefore, there is an opportunity for a payment systems overnight, so a smooth
business requires convenient, secure, convenient, secure and merchant addition to an existing payment
versatile and cost-effective transaction friendly authenticated payment method settlement backbone is a must. The key
capabilities. to become the de facto standard for drivers from a merchant’s point of
mobile payments. view are fast throughput time, cost-
There are increasing opportunities to effectiveness, customer satisfaction and
leverage SMS, due to its convenience Remote (macro) payment is expected to higher customer loyalty. By speeding
and users’ continuing trust in system. produce the lowest number of up the payment process, merchants
In addition, a standard micro-payment transactions. However, it is playing a key may decrease their operational costs
system will create new business models, role by enabling for example micro- and potentially increase sales. Fast and
such as paying for smaller features or payment account top-up, purchasing convenient payment methods also
local add-on services to general, more higher value (over 5€) digital content favour users in this hectic world.
expensive ones, enabling a consumption and enabling remote payment and local Moreover, a mobile terminal’s
model instead of one based on usage habits. Ticketing is expected to messaging capabilities provide many
subscription. Operators also see an gain in popularity among mobile opportunities for customer relationship
opportunity in local transactions to commerce applications and is seen as a management.

Summary
Today, a considerable proportion of As stated, currently digital content is the connection for ensuring end-to-end
mobile commerce consists of the only relevant form of mobile commerce security in Nokia phones, these
purchase of different types of digital and based on their billing relationships, transactions can easily be conducted
content that in most cases is used in the operators continue to dominate micro- over the mobile channel, extending
mobile phone. Symbian OS and Java payments. Mobile ticketing in public mobile commerce possibilities from the
technology offer new possibilities for transportation is becoming a spearhead currently dominant digital content,
application developers, while users are for mobile commerce, with event e.g. ringing tone and operator logo
able to easily configure and personalize ticketing to follow. Technically, the aim selling, to more diverse choices.
the functionality of the mobile device to is to have a smooth adaptation to the
match their needs and preferences. existing and coming payment and For mobile commerce to really take off,
Consumers increasingly personalize ticketing systems. it must build on established habits,
their mobile phones with ring tones, practices, and infrastructure, and then
screen savers, and wallpapers. Games, A recent step forward in the field of add specific mobility value. The added
downloadable phone applications, mobile commerce has been the value can be, for instance, instant access
as well as music and video clips are also adaptation of the 3D Secure Internet and delivery, flexibility, convenience,
growing in popularity. Once people payment model (Verified by Visa) to the personalization, location awareness,
become more familiar with buying mobile environment. Here, both the or better customer service. The key
digital content and services with their merchant and consumer are drivers in the adoption of mobile
mobile devices, they will then more authenticated and can rely on the commerce services are ease-of-use and
easily adopt the mobile payment transaction to be handled properly. convenience, keeping the issue of
mechanism for physical goods and local With the aid of new and improved security in mind. Applications and
transactions as well. Wallet applications and the SSL services that are too complex and time-

14
White Paper

consuming discourage consumers from


“going mobile.” The challenge is to Glossary
implement a secure payment scheme so
that it remains convenient and simple 3D Three-domain payment model
to use. API Application Programming Interface
DRM Digital Rights Management
Nokia’s main interest in the field of ECML Electronic Commerce Modeling Language
mobile commerce is to deliver world-class EGPRS Enhanced General Packet Radio Service
terminals that offer the level of security HTTP Hypertext Transfer Protocol
and trust demanded by the consumers IrDA Infra Red Data Association
and service providers now and, thanks MeT Mobile Electronic Transactions
to incremental improvements, in the MoBey MoBey Forum
future as well. Nokia’s role as mobile NFC Near Field Communication, two-way RF contact less technology
terminal manufacturer is to provide a OMA Open Mobile Alliance
technological ecosystem, which improves OS Operating System
the user experience in all mobile PIN Personal Identification Number
applications, and, very importantly, POS Point of Sales
in mobile commerce. RF Radio Frequency
RFID Radio Frequency IDentification
SRFT Bluetooth SIG Short Range Financial Transaction Study Group
SSL Secure Socket Layer
SW Software
TLS Transport Layer Security
WAP Wireless Application Protocol
WSSC Wireless Cascading Style Sheets
WIM Wireless Identity Module
WTLS Wireless Transport Layer Security
XHTML Extended Hypertext Markup Language

The contents of this document are copyright © 2004 Nokia. All rights reserved. A license is hereby granted to download and print a copy of this document for personal use only.
No other license to any other intellectual property rights is granted herein. Unless expressly permitted herein, reproduction, transfer, distribution or storage of part or all of
the contents in any form without the prior written permission of Nokia is prohibited.

The content of this document is provided “as is”, without warranties of any kind with regards its accuracy or reliability, and specifically excluding all implied warranties,
for example of merchantability, fitness for purpose, title and non-infringement. In no event shall Nokia be liable for any special, indirect or consequential damages, or any
damages whatsoever resulting form loss of use, data or profits, arising out of or in connection with the use of the document. Nokia reserves the right to revise the document
or withdraw it at any time without prior notice.

Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation. Nokia product names are either trademarks or registered trademarks of Nokia.
Other product and company names mentioned herein may be trademarks or trade names of their respective owners.

15
0104 Indivisual
Copyright © 2004 Nokia. All rights reserved. Nokia and Nokia Connecting People are registered trademarks of Nokia Corporation.
Other product and company names mentioned herein may be trademarks or trade names of their respective owners.
Products are subject to change without notice.

P.O. Box 100

www.nokia.com
Nokia Mobile Phones
NOKIA CORPORATION

Phone: +358 (0) 7180 08000


FIN-00045 NOKIA GROUP, Finland

You might also like