Express Checkout Workshop 20170118
Express Checkout Workshop 20170118
Express Checkout Workshop 20170118
2. Risk Overview
4. Settlement Overview
Product Overview
Projected Conversion Rate
* This rate is referenced from our current China Domestic Express Checkout Success Rate
Benefits of Express Checkout
Email address
Verify
Name
Password
National ID
CVV
Mobile Number
OTP Submit
Complete
Bind Solution 2 Random Charge/Deposit
Email address
Verify
Name
Password
National ID
CVV
Mobile Number
Amount Submit
Complete
Purchase/Transaction Flow
Pay with
Email address
Thank You
Password for your payment
Login Print
Unbind Process
Email address
Reason to Unbind
Security Issue Password to confirm
Password Account Closed
xxxx-xxxx-8943
Other
Complete
Bind Process (Pre-filled information)
Verify
Email address
Password Authenticated
Login
Refund Process
Transaction History
Email address
Order No. Amount Status Refund Request
12345 Rp1,000 Paid 12345 We are processing your
Password 12445 Rp2,000 Paid refund request
12545 Rp3,000 Paid
Rp1,000
Select Reason
Login Refund Back to Homepage
Submit
Transaction History
Order No. Amount Status
12345 Rp1,000 Refund In Progress
12345 Rp2,000 Paid
12345 Rp3,000 Paid
Refund
Risk Overview
Roles & Responsibilities
Bank
Provides support for enrolment checks
Ensures Authentication is complete and is based on a comprehensive set of
variables suited to the local context
Provides support for any case investigation and assists in sharing key information
for the negative users
Alipay
Provides full risk coverage spanning the entire life-cycle of a transaction (to track
customer behavior spanning non-financials and financial events)
Full suite of risk tools which include risk models, base velocity checks, bot
prevention tools etc. to mitigate possibilities of enrolment risk and takeover risk
Provides member protection* (to banks) and buyer protection** (to end
consumers)
* Excludes cases of technical issues or bugs on the banks side resulting in wrong verification results
** Excludes cases of friendly fraud by end consumers
Two key risks for Express-
Express-checkout business
Enrolment / Post-Binding /
Binding phase Payment phase
payment
Authentication
Alipay Authentication Change password
Alipay
unbinding
Cards Alipay Edit profile
Cards
Cards Info disclosure
Mitigation
Methods
Authentication Strategy Data & Info Security
Encryption
1
7
Post-
Post-Binding / Payment Phase Possibility of ATO Risk
Wallet account take over Data/system Security
Definition A criminal/fraudster poses as a genuine customer, gains control of an account. Customer card data leakage or compromise
Account
Risk Policy
Security
Risk Authenticati
Detection on
Data integration Dynamic authentication
Phishing recognition methods for risk verification
Risk engine Advanced biometric
Fraud analysis authentication methods
1
8
Alipay capabilities | Risk Management
Data-
Data-driven Risk Management & Intelligence
Core
Core TP integration Risk detection AML System security
modules
modules Risk service cooperation Promotion Sanction screening Human recognition
Fraud
abuse
Risk-based Authentication
Member Protection
LOSS
Risk-
Risk-based Authentication
OTP Code
Member Protection
claim investigation
File a dispute customers Alipay notify and compensate
bank
Member dispute
protection Dedicated
Webpage team compensate
Alipays Service + compensate
hotline
Abilities review
Cases directed platform
notify
from bank
Risk Detection
Location
Environment
Pay with Touch ID
Device info
APP info
Outline
* Except for falsely authenticated cases due to banks error. For example, due to a
bank system bug, mismatched card info and KYC info are verified as matched.
System Architecture Overview
Security
As sensitive information are being shared as part of the Express Checkout, important consideration has to
be given to ensure security and confidentiality is not compromised.
Information Security
Card information (card number, expiry date) and Customer information (full name, id
information) to be stored in PCI-compliant environment
Communication Security
Host-to-Host connection to Bank to be performed over Virtual Private Network
Data communication to be secured e.g., REST APIs
Express Checkout APIs (Host-
(Host-to-
to-Host)
An agreement has to be established between 3 parties (Customer, Bank, Alipay) to allow Alipay to make
payments upon Customers instructions.
This agreement can be
terminated (at discretion of Customer)
suspended (at discretion of Bank)
expired (default validity: 20 years)
The API definition will be of 2 types (request and response) and comprises of the following
components:
Global API Specification (cont.)
Request Header
Request Body
Request body will be determined by each different APIs business logic. There is no
common structure for request body of APIs.
Global API Specification (cont.)
Response Header
Global API Specification (cont.)
Response Body
For all responses, the body should include the resultInfo common data structure which comprises of the following fields:
ValidateAgreement
Verify customers details against banks record
Request
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Request
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Request
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Request
Field Data Type Mandatory Description
Response
Field Data Type Mandatory Description
Customer Bank account Refund back to original payment account Acquiring bank
Customer Bank account Fund transfer to withdraw bank account Acquiring bank
T+1 (topup-withdraw)
2.Net Fund settlement on
Topup cash flow
withdraw cash flow
Indonesia site
Merchant 5. Send Remittance result to Merchant
remittance order
2.Create merchant
return
4 .Remittance result
Note:
1. Alipay issues merchant remittance order on behalf
of merchant and send to bank automatically
Matching
Related Records Settlement files
Fund
reconciliation