Original Article:Business Weekly
(Left: Netron CEO, Aries Lee; Right: HiTRUST Director of Smart Product R&D, Shu-hua Guo)
Fraud and unauthorized transactions are becoming increasingly common. In 2023, the amount reported by issuing institutions in Taiwan for fraud nearly reached 3.3 billion NTD, with over 98% attributed to "non-face-to-face transactions." How can the financial payment cloud platform developed by Netron Information Technology, a network acceleration and security integration services expert, in collaboration with HiTRUST, a provider of secure e-commerce and electronic financial services, leverage AI to enhance the security of online transactions?
In the vast and risk-laden transaction market, financial and e-commerce businesses urgently need secure transaction platforms to protect their brand image and ensure fast, stable transactions. HiTRUST, with years of experience in Taiwan, has developed expertise across four key areas: digital finance, information security, e-commerce payment flow, and artificial intelligence. Their 3DS Credit Card Security Verification System is the world’s first product certified by the EMV international organization, and their one-stop payment gateway service, HiTRUSTpay, holds the top market share in Taiwan.
"We adopted cloud-based payment solutions early on, which aligns with the expectations of banks because it is more stable, scalable, and reduces early investments," said Shu-hua Guo, Director of Smart Product R&D at HiTRUST. In the seven-layer network system architecture, HiTRUST excels in the application layer. The underlying infrastructure and network layers are now supported through their collaboration with Netron Information Technology, establishing a trusted cloud platform on AWS.
The key to cloud migration is not just a one-time move, but rather the long-term support.
Shu-hua Guo, Director of Smart Product R&D at HiTRUST, shared that through Netron Information Technology's comprehensive one-stop professional consulting services, HiTRUST has received significant support.
Netron Information Technology, initially focused on cybersecurity and expanding into multi-cloud services, is an AWS-certified Advanced Partner. It provides a complete one-stop professional consulting service, from planning and deployment to maintenance and operations, as well as training on cybersecurity certifications and social engineering.
Shu-hua Guo stated, "From the initial planning, to construction, service operations, and backend monitoring, the key consideration for us when choosing a cloud service provider was whether they could provide the best support. Having an immediate team available for assistance is a huge help for us." HiTRUST had previously tried other platforms and service providers, but compared to them, Netron offered better support, especially with 24/7 maintenance services provided by professional engineers. Through communication on Line groups, they can discuss issues and share error screens instantly, helping HiTRUST resolve problems at the earliest time.
"On-premise experience cannot be directly applied to the cloud, and for this aspect, we still need to trust the professionals. Netron’s close relationship with AWS, with AWS also supporting discussions during the process, has provided us with immense help," said Guo Shuhua.
A complete cloud architecture must include security, stability, flexibility, and compliance—all of which are essential.
HiTRUST provides secure payment services, and its cloud platform has been PCI DSS certified. Netron Information Technology assisted HiTRUST in setting up five environments on AWS cloud with a dual-AZ (Availability Zone) architecture, utilizing AWS services such as firewall, ELB, EKS, RDS, EC2, and S3 to ensure comprehensive security protection and smooth data flow.
Veri-id Risk Detection System adds an extra layer of security to online transactions.
The Veri-id Risk Detection System, which stands out in HiTRUST's AI Leadership Program and won the 2023 Digital Sandbox Competition, is built on a cloud platform developed with the help of Netron Information Technology. Currently, online accounts on e-commerce platforms often only require a username and password for login, which still leaves numerous vulnerabilities for hackers to exploit. Veri-id, however, uses patented technology to compare the account with the user’s device and hundreds of data points from the device’s environment. By analyzing this data with AI, it determines whether the login attempt is being made by the legitimate user. If abnormal activity is detected, it can either block the login or trigger further identity verification, significantly enhancing transaction security.
The basic detection method includes identifying logins from unfamiliar devices or suspicious locations. It also looks for unusual keyboard typing speeds or mouse movement acceleration, which could indicate a non-human trying to log in. Additionally, if the system detects that a user is simulating different devices and using different accounts for each login attempt, it may indicate a hacker trying to profit from stolen user information while avoiding detection through the use of simulators. Such activities are flagged as anomalies.
Large e-commerce platforms in Taiwan have already adopted Veri-id. Shu-hua Guo explained, "As a large e-commerce company, we have already invested significant resources in cybersecurity but are constantly striving for improvement. We were already considering relevant technologies and even thinking of developing them ourselves. Fortunately, HiTRUST had already developed a comprehensive service, which allowed us to apply it more flexibly and quickly, leading to a perfect match between the two sides."
Veri-FIDO Passwordless Authentication Service frees users from the security risks of passwords, enabling secure and fast online identity verification without the need for passwords.
Recently, HiTRUST launched the new Veri-FIDO Passwordless Authentication Service, combining the functionality of Veri-id with FIDO2 technology. By leveraging a public-private key architecture, it completely eliminates the need for passwords and uses biometric authentication such as fingerprints or facial recognition to verify identity. Without passwords, consumers no longer need to worry about their passwords being intercepted, stolen, or misused, helping to prevent the social engineering attacks that have caused significant losses in recent years.
Veri-FIDO is not limited to just apps, as earlier FIDO technology was, but also supports smooth use on websites, enabling consumers to easily enhance transaction security.
The HiTRUST Veri-FIDO service has also gained the favor of the major travel platform colatour. This year, colatour has continued to invest heavily in building "Digital colatour", becoming the first travel industry player to adopt FIDO biometric authentication. Furthermore, to actively encourage travelers to complete setup and improve security, colatour launched a lucky draw event before the end of September. Those who complete the quick login binding have a chance to win a 5,000 TWD discount code, providing members with a fast and secure digital travel tool. Additionally, the colatour FIDO2 Security Verification Plan was selected as this year's Digital Trust Field Service Validation Project by the Ministry of Digital Affairs, working together to combat fraud and create a safer and more convenient digital life.
Financial Cloud Era: Cybersecurity Duo Join Forces to Boost Financial and Transaction Security
(HiTRUST and Netron Information Technology Team)
"Cybersecurity in e-commerce is very broad and cannot be solved by a single software or hardware solution. HiTRUST and Netron Information Technology have made a great match by addressing both the upper and lower layers," said Shu-hua Guo.
Li Shang-xiu further added, "E-commerce platforms hold a large amount of transaction data, making them prime targets for hackers, especially when open-source code is used during website development, which increases the risk of backdoors being planted by hackers. Netron Information Technology not only helps clients ensure cybersecurity compliance with certifications such as ISO27001 and PCI DSS from the website development stage, but also assists with automated scanning and alerts through AI automation tools. Especially with the trend of hybrid cloud and multi-cloud environments, engineers have to manage complex systems, increasing the risk of errors. Automated processes and tools are essential for effective management."
Additionally, Li Shang-xiu emphasized that with the current website architecture largely based on APIs, WAF (Web Application Firewall) systems are finding it more difficult to distinguish between human and bot transactions. Furthermore, during website revisions, some APIs might no longer be used but remain active, creating security vulnerabilities. These can all be scanned and tracked using automated tools. For already deployed websites, automated scans can conduct "health checks" to identify security gaps for reinforcement.
With the increasing trend of cloud adoption in the financial sector, HiTRUST and Netron Information Technology also plan to deepen their collaboration. Shu-hua Guo pointed out, "Having cloud experience and related support now becomes one of the advantages when serving financial clients. Moreover, when financial institutions adopt the cloud, they no longer need to purchase a large amount of hardware equipment when adopting new software services, making them more willing to implement them." In a cloud environment, financial institutions rely heavily on Netron's expertise, from overall architecture planning to permissions management. "We greatly depend on Netron's expertise to assist the financial sector in perfecting their cloud mechanisms. They build the cloud ladder from the ground to the cloud, while our application services only need to take the elevator up."