๐ณ Payment Security
Complete Study Notes for Banking, SSC, UPSC, Government & Railway Competitive Exams
๐ฎ๐ณ India-Specific: UPI, RBI, NPCI ๐ All Key Tables & Comparisons ๐ 50+ Exam MCQs โก Quick Revision SheetPayment Security refers to the set of technologies, standards, policies, and practices used to protect financial transactions from fraud, theft, unauthorized access, and cybercrime. It covers card payments, online banking, mobile wallets, UPI, ATM transactions, and more.
| Security Goal | In Payment Context | Example |
|---|---|---|
| Confidentiality | Card details not exposed to unauthorized parties | TLS encryption for online transactions |
| Integrity | Transaction amount not altered during processing | Digital signatures on payment messages |
| Availability | Payment systems work 24ร7 without downtime | Bank servers resistant to DDoS attacks |
| Authentication | Verifying the identity of the person making payment | OTP, PIN, biometrics for UPI payments |
| Non-Repudiation | Sender cannot deny initiating a transaction | Digital receipts, transaction logs |
| Organization | Full Form | Role |
|---|---|---|
| RBI | Reserve Bank of India | Apex regulator of all payment & settlement systems in India; issues guidelines for banks, fintech firms |
| NPCI | National Payments Corporation of India | Operates UPI, RuPay, IMPS, NACH, FASTag, Aadhaar Pay, BBPS โ India’s payment infrastructure body |
| DPSS | Dept. of Payment & Settlement Systems | RBI department that regulates payment systems in India |
| IDRBT | Institute for Development & Research in Banking Technology | Technology research arm for Indian banking sector |
| SEBI | Securities & Exchange Board of India | Regulates securities market payments & settlement |
| IRDAI | Insurance Regulatory & Development Authority | Regulates insurance premium payment security |
| CERT-In | Computer Emergency Response Team โ India | National incident response for payment security breaches |
| PCIDSS Council | Payment Card Industry Security Standards Council | Global body setting card payment security standards |
UPI (Unified Payments Interface) is a real-time payment system developed by NPCI that enables instant money transfer between bank accounts through mobile devices using a Virtual Payment Address (VPA).
| UPI Fact | Details |
|---|---|
| Launched by | NPCI (National Payments Corporation of India) |
| Launch Year | 2016 (NPCI) โ publicly available from April 11, 2016 |
| Approved by | RBI (Reserve Bank of India) |
| Daily Limit | โน1 lakh per transaction (โน2 lakh for some verified transactions) |
| Unique Identifier | VPA (Virtual Payment Address) โ e.g., name@bankname |
| Authentication | Device binding + UPI PIN (4 or 6 digit) |
| Underlying Technology | IMPS (Immediate Payment Service) rails, 24ร7 availability |
| Security Layer | End-to-end encryption, 2FA (device + PIN), real-time fraud monitoring |
| Global Expansion | Now available in: Singapore (PayNow link), UAE, UK, France, Bhutan, Nepal, Mauritius |
| Apps using UPI | Google Pay, PhonePe, Paytm, BHIM, Amazon Pay, WhatsApp Pay |
Enters VPA & amount
Authenticates via PIN
Debit request
Routes & settles
Credit
Money received
- Device Binding: UPI is linked to a specific device + SIM โ cannot be used on another phone without reverification
- UPI PIN: Mandatory 4 or 6-digit PIN for every transaction โ different from ATM PIN
- Two-Factor Authentication (2FA): Device binding (something you have) + UPI PIN (something you know)
- End-to-End Encryption: All UPI transaction data is encrypted in transit using TLS
- Real-Time Fraud Monitoring: Banks and NPCI run AI-based fraud detection systems
- Screen Unlock: Phone screen lock adds another layer before UPI app can be opened
- No Card Details: UPI never requires card number or CVV โ reduces risk significantly
PCI DSS is the global security standard for organizations that store, process, or transmit credit/debit card data. It was created by the PCI Security Standards Council (founded by Visa, MasterCard, American Express, Discover, JCB).
| # | Requirement | Category |
|---|---|---|
| 1 | Install and maintain network firewalls to protect cardholder data | Build Secure Network |
| 2 | Do not use vendor-supplied default passwords on systems | Build Secure Network |
| 3 | Protect stored cardholder data (encrypt, mask, don’t store CVV) | Protect Cardholder Data |
| 4 | Encrypt transmission of cardholder data across open/public networks | Protect Cardholder Data |
| 5 | Use and regularly update antivirus software | Vulnerability Management |
| 6 | Develop and maintain secure systems and applications | Vulnerability Management |
| 7 | Restrict access to cardholder data by business need to know | Access Control |
| 8 | Assign unique IDs to all persons with computer access | Access Control |
| 9 | Restrict physical access to cardholder data | Access Control |
| 10 | Track and monitor all access to network resources and data | Monitor & Test |
| 11 | Regularly test security systems and processes | Monitor & Test |
| 12 | Maintain an information security policy for all personnel | Security Policy |
Tokenization replaces sensitive card information (like the 16-digit card number) with a randomly generated, meaningless string called a token. The token can be used for payments but is useless if stolen โ the actual card details remain in a secure vault.
1234 5678 9876 5432
abcd9876xyz123
Stores token only
Processed securely
| Feature | Tokenization | Encryption |
|---|---|---|
| Output | Random, meaningless token (no mathematical link to original) | Ciphertext (mathematically derived from original) |
| Reversible? | Only by TSP vault lookup โ no algorithm can reverse it | Yes โ with the correct decryption key |
| Original Data | Stored in a secure token vault (off-site) | Remains (but scrambled); needs key management |
| Scope Reduction | โ Massively reduces PCI DSS scope | Does not reduce PCI DSS scope |
| Key Management | No encryption keys needed | Requires secure key management |
| Best For | Card storage, recurring payments, e-commerce | Data in transit, full data protection |
โข Effective from October 1, 2022, RBI mandated that merchants CANNOT store customer card details on their servers
โข Instead, merchants must use Card-on-File Tokenization (CoFT) โ storing only a token
โข Tokens are issued by card networks (Visa, MasterCard, RuPay) via Token Service Providers (TSPs)
โข Applies to: All online merchants, e-commerce platforms, subscription services in India
โข Purpose: Prevent card data breaches at merchant endpoints
| System | Full Form | Operator | Transfer Limit | Settlement | Availability |
|---|---|---|---|---|---|
| UPI | Unified Payments Interface | NPCI | โน1 lakh/txn | Immediate (24ร7) | 24ร7ร365 |
| IMPS | Immediate Payment Service | NPCI | โน5 lakh/txn | Immediate | 24ร7ร365 |
| NEFT | National Electronic Funds Transfer | RBI | No upper limit | 30-min batches (24ร7) | 24ร7 (from Dec 2019) |
| RTGS | Real Time Gross Settlement | RBI | Min โน2 lakh | Real-time (gross) | 24ร7 (from Dec 2020) |
| NACH | National Automated Clearing House | NPCI | Varies | Batch (1-2 business days) | Business days |
| AEPS | Aadhaar Enabled Payment System | NPCI | โน50,000/day | Immediate | 24ร7 |
| BBPS | Bharat Bill Payment System | NPCI | Varies by biller | Immediate | 24ร7 |
| RuPay | โ | NPCI | Card limit | Per card scheme | Wherever accepted |
| FASTag | โ | NPCI | Per toll | Immediate RFID debit | Toll plazas |
| Fraud Type | What Happens | How to Prevent |
|---|---|---|
| Card Skimming | Attacker installs a hidden device on ATM/POS to copy card magnetic strip data | Use EMV chip cards; check ATM for skimmer devices; use contactless payments |
| Phishing / Vishing | Fake emails/calls trick users into revealing card numbers, OTPs, or PINs | Never share OTP over phone; verify caller identity; use anti-phishing filters |
| UPI Fraud (Collect Requests) | Attacker sends a UPI “collect money” request pretending to be a refund โ victim approves and money is debited | Never enter UPI PIN for receiving money; scrutinize collect requests carefully |
| Card-Not-Present (CNP) Fraud | Using stolen card details for online shopping where only card number + expiry + CVV are needed | Two-factor authentication (OTP); 3D Secure verification; tokenization |
| Man-in-the-Middle (MITM) | Attacker intercepts payment communication between buyer and server | HTTPS/TLS encryption; avoid public Wi-Fi for banking; certificate pinning |
| Account Takeover (ATO) | Hacker gains access to victim’s bank account using stolen credentials | Strong passwords; MFA; anomaly detection; device binding |
| Shimming | A thin insert placed inside card slot to intercept chip card data | Use contactless/NFC payments; check card slot for tampering |
| Synthetic Identity Fraud | Using a combination of real and fake information to create a new identity for fraudulent accounts | Enhanced KYC verification; AI-based identity checks |
| Business Email Compromise (BEC) | Attacker impersonates a CEO/CFO to instruct finance team to transfer large amounts | Email verification; callback procedures for large transfers; dual approvals |
| SIM Swapping | Fraudster convinces telecom to transfer victim’s number to their SIM โ intercepts OTPs | Lock SIM with telecom provider; use authenticator apps instead of SMS OTP |
| Technology | What It Is | Security Benefit |
|---|---|---|
| EMV Chip Cards | Cards with an embedded microchip (instead of just magnetic strip). EMV = Europay, Mastercard, Visa | Dynamic authentication โ each transaction generates a unique code. Defeats card cloning/skimming |
| 3D Secure (3DS) | Additional authentication layer for online card payments. Used in “Verified by Visa”, “Mastercard SecureCode” | Adds OTP or biometric step during online purchase โ prevents CNP fraud |
| NFC/Contactless Payments | Near Field Communication โ tap card or phone on reader. Works within 4cm range | Uses tokenization; no card PIN for small amounts; reduces physical contact with reader |
| SSL/TLS Encryption | Encryption protocol securing data in transit between browser and payment server (HTTPS) | Prevents MITM attacks; ensures data confidentiality during checkout |
| HSM (Hardware Security Module) | Physical tamper-proof hardware device used to store and process cryptographic keys | Keys never leave secure hardware; protects encryption keys used in banking systems |
| Point-to-Point Encryption (P2PE) | Encrypts card data from the moment of swipe/tap until it reaches the secure decryption environment | Card data is never exposed in readable form at merchant’s system; reduces PCI DSS scope |
| OTP (One-Time Password) | Unique password valid for a single transaction, sent via SMS or authenticator app | Prevents replay attacks โ stolen OTP is useless for another transaction |
| TOTP (Time-based OTP) | OTP that changes every 30 seconds, generated by an app (Google Authenticator, Authy) | More secure than SMS OTP โ not interceptable via SIM swap |
| Biometric Authentication | Fingerprint, face recognition, or iris scan for payment authorization | Cannot be guessed or shared; used in AEPS (Aadhaar + fingerprint) |
| AI/ML Fraud Detection | Machine learning algorithms analyze spending patterns to detect anomalies | Can block suspicious transactions in real-time before fraud completes |
| Guideline / Regulation | Year | What It Mandates |
|---|---|---|
| Payment & Settlement Systems Act | 2007 | Primary law governing all payment systems in India; RBI the designated regulator |
| Card-on-File Tokenization | 2022 | Merchants CANNOT store actual card data; must use tokens from card networks |
| MTSS Guidelines | Updated 2022 | Money Transfer Service Scheme โ regulates foreign inward remittance |
| 2FA for all Card Transactions | Ongoing | All online card transactions in India must have second factor (OTP) โ AFA (Additional Factor of Authentication) |
| Zero Liability for Victims | 2017 | Customers not responsible for unauthorized transactions if reported within time; bank must refund within 10 days |
| Positive Pay System | 2021 | Mandatory confirmation for cheques above โน50,000 โ prevents cheque fraud |
| NBFC Payments Regulations | 2021 | Strengthened guidelines for Non-Banking Finance Companies offering payment services |
| RBI Data Localisation | 2018 | All payment data of Indian customers must be stored ONLY in India โ foreign firms must comply |
| Aadhaar-based eKYC | 2020+ | Allows digital KYC using Aadhaar OTP/biometrics for opening bank accounts and payment wallets |
| Fraud Risk Management (FRM) | Ongoing | Banks must implement FRM systems to detect and prevent payment fraud in real time |
| Card Network | Country of Origin | Key Fact |
|---|---|---|
| Visa | USA | Largest card network globally by transaction volume |
| Mastercard | USA | Second largest; co-founded PCI DSS Security Standards Council |
| RuPay | ๐ฎ๐ณ India | India’s own card network by NPCI โ accepted across India + some international markets |
| American Express | USA | Both issuer and network; premium cards |
| Diners Club | USA | Premium travel and entertainment cards |
| SWIFT | Belgium | International messaging network for cross-border bank payments (not a card network) |
| Feature | Full Form / Details | Purpose |
|---|---|---|
| CVV / CVV2 | Card Verification Value โ 3-digit code on back (4-digit on AmEx front) | Proves physical card possession for CNP transactions |
| PAN | Primary Account Number โ 16-digit card number | Uniquely identifies the card account |
| Expiry Date | Month/Year printed on card | Added verification for card validity |
| EMV Chip | Europay, Mastercard, Visa chip | Dynamic cryptogram prevents cloning |
| Magnetic Strip | Black strip on card back | Legacy data storage โ insecure; being phased out |
| PIN | Personal Identification Number (4-6 digits) | Physical authentication at ATM/POS terminal |
| OTP/AFA | Additional Factor of Authentication | Mandatory 2FA for online card transactions in India |
| Hologram | Holographic foil sticker | Physical anti-counterfeiting feature |
- A. Reserve Bank of India (RBI)
- B. National Payments Corporation of India (NPCI)
- C. State Bank of India
- D. Ministry of Finance
- A. IFSC Code
- B. Mobile Number only
- C. VPA (Virtual Payment Address)
- D. Aadhaar Number
- A. 2015
- B. 2014
- C. 2016
- D. 2018
- A. NEFT
- B. UPI
- C. IMPS
- D. RTGS
- A. Username and Password
- B. OTP on mobile number
- C. Aadhaar number + Biometric (fingerprint/iris)
- D. Card number and CVV
- A. RTGS
- B. IMPS
- C. UPI
- D. NEFT
- A. Reserve Bank of India (RBI)
- B. State Bank of India (SBI)
- C. National Payments Corporation of India (NPCI)
- D. Ministry of Finance
- A. SEBI
- B. NPCI
- C. Reserve Bank of India (RBI)
- D. IRDAI
- A. UAE
- B. USA
- C. Singapore
- D. UK
- A. RBI
- B. NPCI
- C. SBI
- D. Ministry of Finance
- A. Private Card Identity and Data Security System
- B. Public Card Industry Digital Security Standard
- C. Payment Card Industry Data Security Standard
- D. Protected Card Information and Digital Security Service
- A. RBI, NPCI, SEBI, IRDAI
- B. Visa, Mastercard, American Express, Discover, JCB
- C. World Bank, IMF, WTO, BIS
- D. ISO, NIST, IEEE, W3C
- A. 6
- B. 10
- C. 12
- D. 15
- A. Transaction amounts
- B. Merchant names
- C. CVV/CVV2 values after authorization
- D. Transaction timestamps
- A. Electronic Money Verification
- C. Europay, Mastercard, Visa
- D. Electronic Mobile Value
- A. Encrypting card data with AES-256
- B. Replacing the card number with a random, meaningless token that cannot be mathematically reversed
- C. Hashing the card number with SHA-256
- D. Storing card numbers in a blockchain
- A. January 1, 2021
- B. April 1, 2022
- C. October 1, 2022
- D. January 1, 2023
- A. The merchant website
- B. NPCI directly
- C. Card Networks (Visa, Mastercard, RuPay) via Token Service Providers (TSPs)
- D. The customer’s bank only
- A. Tokenization is faster to compute
- B. Tokens can be decrypted by the merchant if needed
- C. Tokens are mathematically irreversible and reduce PCI DSS compliance scope
- D. Tokenization uses smaller file sizes
- A. Stealing card physically from the holder
- B. Installing a hidden device that copies card data from the magnetic strip
- C. Hacking the bank’s server database
- D. Sending phishing emails to cardholders
- A. Sharing their Aadhaar number
- B. Installing a fake banking app
- C. Entering their UPI PIN to “receive” a refund โ which actually debits their account
- D. Clicking on a bank phishing link
- A. Clone a SIM card physically
- B. Transfer the victim’s phone number to a fraudster’s SIM to intercept OTPs
- C. Install malware on the victim’s phone
- D. Access the victim’s bank app remotely
- A. When a card is physically stolen and used at an ATM
- B. When stolen card details (number, expiry, CVV) are used for online purchases without the physical card
- C. When a debit card is used at a POS terminal
- D. When a hacker accesses the bank’s core banking system
- A. Sending bulk spam emails to steal card numbers
- B. Impersonating a CEO/CFO via email to trick finance staff into transferring funds
- C. Hacking email servers to read financial statements
- D. Creating fake email login pages for banking
- A. Three-dimensional card design authentication
- B. Adding an extra authentication step (OTP/biometric) during online card transactions
- C. Three layers of network firewall for banks
- D. Three-key symmetric encryption for card data
- A. National Finance Communication
- B. Near Field Communication
- C. Network Finance Controller
- D. New Frequency Channel
- A. Process millions of transactions simultaneously
- B. Generate OTPs for customers
- C. Securely store and process cryptographic keys in tamper-proof hardware
- D. Monitor network traffic for fraud patterns
- A. It stores more data than a magnetic strip
- C. It generates a unique cryptographic code for each transaction โ making copied data useless
- D. It has higher magnetic field strength
- A. Encrypting data between two bank servers only
- B. Card data is encrypted from the moment of card swipe/tap until it reaches the secure decryption environment
- C. End-to-end encryption between the customer and merchant only
- D. Encryption using two different algorithms simultaneously
- A. Banks must have additional firewall protection
- B. All online card transactions must have a second authentication step (OTP) beyond card details
- C. Cards must have two separate PIN numbers
- D. Banks must store an additional copy of card data
- A. 50% refund within 30 days
- B. Full refund within 60 days
- C. Full refund โ bank must credit within 10 working days of reporting
- D. Partial refund based on transaction amount
- A. All digital UPI transactions
- B. ATM withdrawals above โน1 lakh
- C. Cheque payments above โน50,000 โ requiring prior confirmation from issuer
- D. All NEFT transactions above โน1 lakh
- A. Banks must digitize all paper records
- B. Payment data must be processed only in secure servers
- C. All payment data of Indian customers must be stored only within India
- D. Local banks must process all payments domestically
- A. Processing domestic UPI transactions
- B. India’s domestic card payment network
- C. International interbank financial messaging for cross-border transactions
- D. Biometric payment authentication
- A. Card Value Verification
- B. Card Verification Value
- C. Certified Virtual Vault
- D. Credit Value Verification
- A. TOTP is longer in digits
- B. TOTP is generated locally on the device and doesn’t travel over mobile networks โ immune to SIM swap
- C. TOTP requires facial recognition
- D. TOTP is sent through encrypted email
- A. International money transfers
- C. Centralized bill payment for utilities, telecom, insurance, and other billers
- D. Bulk salary disbursements
- A. Fast UPI transactions above โน1 lakh
- B. RFID-based automatic electronic toll collection on national highways
- C. Fast-track ATM withdrawals
- D. Quick credit card bill payment
- A. Card number + CVV
- B. Device binding (registered mobile) + UPI PIN
- C. Username + Password
- D. Aadhaar number + OTP only
- A. UPI
- B. RuPay
- C. NEFT
- D. IMPS
- A. Store all customer card data for fraud investigation
- B. Share card data with third parties for analytics
- C. Use tokenization or encryption to protect stored card data, and never store CVV
- D. Keep card data on unencrypted spreadsheets for easy access
- A. Internet Mobile Payment Service
- B. Immediate Payment Service
- C. Instant Mobile Payment System
- D. Integrated Mobile Payment Service
- A. Regular monthly salary credit
- B. EMI deduction on the same date every month
- C. Multiple high-value transactions in different countries within minutes of each other
- D. Grocery purchases at the same supermarket each week
- A. SEBI
- B. NPCI only
- C. RBI (under Payment Aggregators/Payment Gateways guidelines)
- D. Ministry of Finance directly
- A. Phishing
- B. Card Skimming
- C. Shimming
- D. Vishing
- A. International fund transfers
- B. One-time UPI payments
- C. Bulk and recurring transactions like salary payments, EMI deductions, and subsidy disbursements
- D. High-value real-time settlements
- A. The receiver sends money to the wrong UPI ID
- B. A fraudster sends a collect request pretending it is a refund/prize, and the victim enters their PIN to approve it
- C. The UPI app fails to connect to the bank server
- D. Two users try to pay simultaneously
- A. Aadhaar OTP + Bank PIN
- B. Aadhaar Number + Biometric (fingerprint/iris)
- C. Aadhaar + Debit Card number
- D. Mobile number + OTP only
- A. RTGS is operated by NPCI and used for small retail transactions
- B. RTGS has no minimum transaction amount
- C. RTGS is operated by RBI, settles transactions individually in real-time with minimum โน2 lakh
- D. RTGS works only during banking hours on weekdays
- A. Digital Locker Scheme
- B. Pradhan Mantri Jan Dhan Yojana (PMJDY) + Digital India
- C. UIDAI Aadhaar only
- D. Make in India
- A. 112
- B. 100
- C. 1930
- D. 155260
- A. โน50,000
- B. โน1 lakh (โน2 lakh for specific verified transactions)
- C. โน5 lakh
- D. โน25,000
