Skip to main content

NYUx: Mobile Payment Security

This cybersecurity course for professionals explores the core concepts of mobile payment security. Whether you are an analyst, architect, or administrator, this course will help you uncover the issues that inform any mobile payment implementation.

Mobile Payment Security
4 weeks
3–5 hours per week
Self-paced
Progress at your own speed
This course is archived

About this course

Skip About this course

This course provides details on how card payments are processed, including differences between older ‘magnetic stripe’ transactions and newer EMV (or ‘chip’) based transactions. Using this as a base, the course outlines specifically how payment solutions are being implemented around the world on smartphones and mobile devices, the differences between mobile acceptance and mobile issuance, and how other types of payment methods and payment processes may be implemented on these devices. This includes discussions of tokenization and token service providers, their relationship to financial institutions and merchants, as well as card transactions using card readers, contactless payments, and the rise of mobile apps, mobile wallets, and the ledger systems that are often used to manage these processes. Topics of mobile security, security standards, cryptography, protection of sensitive data, potential data breaches, malware, and key management are touched upon at a high level, but primary focus is provided to the mobile payments eco-system and implementations.

At a glance

  • Institution: NYUx
  • Subject: Computer Science
  • Level: Advanced
  • Prerequisites:

    This course is intended for cybersecurity professionals with an interest in payment systems. Basic knowledge of cybersecurity concepts (cryptography, threat models, etc.) is required, with a BS Degree in Cybersecurity optimal.

  • Language: English
  • Video Transcript: English
  • Associated skills:Cryptography, Smartphone Operation, Cyber Security, Tokenization, Mobile Security, Service Provider, Key Management

What you'll learn

Skip What you'll learn

In this course you will learn how to think systematically and critically about the concepts and challenges informing implementation of any mobile payments strategy. You will come to understand the core issues that underlie the changing landscape of payments and how to secure digital transactions by learning:

  • the principle components of open and closed loop payment systems
  • the difference between MagStripe and EMV payments and threat models associated with each
  • the differences and similarities between contact and contactless payments using EMV
  • what the core standards for payments are and how they are changing
  • the different types of cardholder authentication
  • the differences between mobile issuance and mobile acquiring and the role that financial institutions play in each
  • the roles that tokenization and token service providers play in mobile payments
  • about the migration away from dedicated payment terminals and what that means for the future
  • about securing enrollment and implementation of mobile applications
  • what the key drivers for change are in the area of payments and how these are shaping the emerging patterns for fraud

Week 1: Payments Overview

  • Payment Fundamentals
    • Evolution of Payments
    • How a Payment is Processed
    • Payment Authentication and Settlement
  • EMV and Current Cardholder Authentication
    • EMV and Why It’s Needed
    • EMV Transaction Authentication
    • Cardholder Authentication

Week 2: Introduction to Mobile Payments

  • Mobile Payments Overview
    • Mobile Payments Defined
    • Mobile EMV Issuance
    • Tokenization
    • Mobile Issuance Walkthrough
  • Challenges & Standards
    • Payment Standards & Mobile Payment Challenges
    • Mobile Payment Standards & Reducing PAN Use

Week 3: Payment Problems, Threat Models, and Attacks

  • Threat Modeling
    • Threat Modeling Refresher
    • Payment Threat Models
    • Detailed Attacks on Payment Systems
  • Potential Mobile Issues
    • Mobile Device Security
  • Fixing the Issues
    • Securing Mobile Payments
    • Securing Enrollment & Implementation
    • Mobile Acquiring Walkthrough

Week 4: The Future of Payments

  • Current Trends
    • Current Changes Driving Payments
    • Paying for Payments: Interchange
    • ISO8583 vs ISO 20022
  • Issues for Now and the Future
    • Online Payments vs In-store Payments
    • New Forms of Payments
    • Shared Ledger
    • Managing New Forms of Fraud

Who can take this course?

Unfortunately, learners residing in one or more of the following countries or regions will not be able to register for this course: Iran, Cuba and the Crimea region of Ukraine. While edX has sought licenses from the U.S. Office of Foreign Assets Control (OFAC) to offer our courses to learners in these countries and regions, the licenses we have received are not broad enough to allow us to offer this course in all locations. edX truly regrets that U.S. sanctions prevent us from offering all of our courses to everyone, no matter where they live.

Interested in this course for your business or team?

Train your employees in the most in-demand topics, with edX For Business.