Design and development of the desktop version of MULTIVERSA Token – one of CoCoNet’s flagship online banking products.
The CoCoNet group develops next-generation digital banking solutions. The products empower banks and financial service providers to accelerate their digital transformation and compete in today’s rapidly changing world. The product portfolio includes solutions for digital experience and integration platforms and corporate banking. They provide a rich, interactive customer experience.
CoCoNet already had developed an app-based security token to enable secure authentication and authorisation of financial transactions with a smartphone. The white-label software product is called MULTIVERSA Token for Mobile. It is available for iOS and Android smartphones.
While the easiness of the use of the mobile token solution was well received in the market, the handling with an additional device caused sometimes problems for corporate users without company phones. As a result, CoCoNet invented the idea of the desktop version to the MULTIVERSA Token.
The promising feedback from the market and additionally new legal requirements for the ’Strong Customer Authentication’ (SCA) – a two-factor authentication for all electronic payments coming into force on 14 September 2019 as part of the European Commission’s Second Payment Services Directive (PSD2) – caused a short development time for the new product.
Due to small development capacities with specific expertise, CoCoNet needed a development partner, who could act quick and flexible. The project duration was only five-month.
Future Processing’s role
Our role was to design and develop the desktop version of the MULTIVERSA Token. We started with a rough requirements specification prepared by CoCoNet. We worked out specific requirements, designed the architecture of the system, proposed technologies and security measures, and did the development work and testing.
The token supports the secure user authentication and authorisation of payments and other financial operations without any additional devices. The application for Microsoft Windows and Apple macOS fulfils the strong security requirements of PSD2 and complies with the EBICS standard. The obligatory RSA keys are safely stored on the user’s computer.
The need for other devices and security tokens, such as smartcards or RSA tokens becomes superfluous. For the bank, this means a significant simplification of logistics, and savings in terms of support and maintenance.
However simple the functionalities sound, the application’s technical and security side has been extremely complex and demanding. The technologies we chose included Electron (the app was written using React with TypeScript) and a number of cryptographic algorithms.
Main benefits of our partnership
We served as software development partners and technical experts who reacted quickly and flexible to the short timeline and the strong requirements.
CoCoNet’s bank clients can now offer their corporate customers a convenient and secure token solution to authenticate and authorise financial operations through desktops in accordance with the latest security requirements.
“We have had the pleasure to work with an excellent team which helped us to implement the security solution along our product suite. Future Processing was able to help us on a technical field where we lack experience and we can recommend such a collaboration for companies in a similar situation..”;
Björn Hassing, CTO, CoCoNet