References in Evaluation Services

Evaluation Guidelines

MasterCard International

  • Contribution to the set-up of the technical process of a certification scheme for mobile payment solutions
Mobile operators
  • Set-up and implementation of a certification scheme for MIDP, Java Card™, Symbian (proof of concept), Linux and WinCE (advanced research) applications based on static analysis
EMVCo
  • Contribution to the security implementation guidelines of the CPA (Common Payment Application), part of the CPA certification process
VISA
  • Contribution to the security implementation guidelines of the VSDC (Visa Debit and Credit transactions), to be used in the Visa certification process

Evaluations

MasterCard International

  • Security Evaluation (Black Box) of most vendors’ Java Card™ platforms (2001-2003). Methodology licensed to MasterCard as the foundation of its Java Card™ risk management program (CAST process).
  • Static analysis technology: supply of TL Application Diagnosis Tool with banking rules to be used in CAST process.
  • Security evaluation of mobile payment solutions
BAROC / GIE Cartes Bancaires / Texas Instruments / Viaccess
  • Security Evaluation (white box) of software and hardware security architectures
SIMalliance
  • Static analysis technology: first license of TL Application Diagnosis Tool with STK rules (Stepping Stones for Interoperability)
Pay TV operators
  • Java Card™ security evaluation support
Mobile operators
  • Consulting in evaluation and certification of new services and applications, before market launch
Card vendors
  • Evaluations of MasterCard M/Chip and Paypass applications, on both native and Java cards
Mobile and terminal manufacturers
  • Evaluations of payment and mobile terminal architectures

Next page : Back to Security Evaluation Services

Back to the top