When you carry out banking transactions through the Internet, you
don't want to take any risk
and rightly so.
Today, the Internet is too
often associated with "VIRUS", "INTRUSION",
"SPAM", etc.
Risks may be high if you work on the Internet without a maximum
security.
Your Bank has always treated the security aspect
with rigour.
Advanced securisation systems
have been set up by the Bank in order to give you the guarantees
you have the right to require.
Please note that, would your banking transaction be intercepted
and altered on the Internet by an ill-intentioned third person,
security systems in place would make it possible to detect immediately
its alteration before it is sent to your Bank.
..... the security in B-Web is guaranteed in different ways
:
The B-Web website is a secured
website
The first security measures lies in the website address "https://".
The unusual "s" in the
address means security and it
means that you are carrying out your banking transactions in a secured
environment.
The "firewalls"
protect the servers of the Bank from any external intrusion.
Access to B-Web is only authorised
with the use of a Digipass or
e-Token so as to ensure the compliance
with the security basic rules such as :
authentication, data
confidentiality, data
integrity.
In other words, the Digipass and the e-Token
make it possible to set up a secured channel between your PC and the
computer of your Bank.
Transactions
(inland, international, from account to account payments, etc.) are
also efficiently protected by the digital signature with Digipass
or e-Token.
..... security in B-Webtakes place at different levels
:
The procedure of subscription
with an "Internet Banking" service
If you want to access B-Web, you have to fill in a subscription
contract in which you are going to identify yourself
precisely and, if you want to, identify the other people that will
also be allowed to connect.
When this signed contract arrives at the Bank, the usual verifications
are carried out.
Then, you receive by mail your initial
personal identification number.
Under separate cover, you will
also receive a Digipass
(sort of small calculator) or an e-Token
(a sort of key to be inserted into the USB port of your PC) depending
on the choice written in your
contract.
Once you have received those two elements (the personal identification
number and the Digipass/ e-token), you send an acknowledgement of
receipt.
After receiving and checking the acknowledgement of receipt, your
Bank will activate your access
to B-Web.
It is by way of a strict procedure that Clear2Pay knows for sure,
during each transaction made in B-Web, that it is in contact with
you, just like you can be sure you are in connection with the Bank.
Access rights entered
in a dedicated management module
B-Web lives up to the expectations of the most demanding customers.
When you subscribe to B-Web, you have to fill in a contract in which
you identify clearly :
The
accounts you want to be displayed,
The
people who will have access (users),
The
actions allowed for each account, for each connection user.
After being encoded, the transactions will necessarily
have to be signed (validation of the transaction by an
authorised person).
B-Web prescribes the respect of your contract
with regard to the validity of your amounts and joint signatures
The most complex scenarios may be parameterised so as to adapt
to the internal organisation of each company, whatever its complexity
at the signature powers level.
Once those access rights have been parameterised, the customer
is sure that those checks will be done automatically and systematically
during each payment signature.
The
DIGIPASS looks like a small calculator.
That small device generates a digital signature that makes it possible
for you to connect, sign your transactions, etc. It calculates a new signature
every time you use it, which guarantees an optimal security.
The DIGIPASS can be used both as :
a traditional calculator,
an authenticator calculator device. This American word simply refers to a number of 6 digits - generated
by DIGIPASS - guaranteeing the origin of a message, or event he integrity
of its contents.
The Digipass is protected by a password that is personal.
If
you already are a B-Web customer and wish to subscribe to a new contract,
please inform your account manager of it. It is possible to consult
different B-Web contract with a single Digipass no matter where your
accounts are open.
First use
As soon as you subscribe to B-Web, you receive a Digipass and a
PIN code from your bank.
Before using the calculator for the first time, you have to initial
it.
During the initialisation phase of the Digipass (to be performed once),
you will be asked to encode the PIN code received from your Bank and
to choose a new personal PIN code.
Once the initialisation procedure has taken place, the PIN code
to be entered will be the one you have chosen personally.
Advantage
In order to access to B-Web or to sign instructions, you absolutely
need two elements :
your
digipass ,
your
PIN code,
Would your Digipass be stolen,
it couldn't be used as it is protected
with a PIN code.
Kind of small key to insert into the USB port of your PC and on which
your certificate and your two keys (private/public keys) have been previously
entered in accordance with the PKI certificate method (Public Key Infrastructure).
Your e-Token is protected by a personal
PIN code.
When you log on to B-Web, you are asked to enter your personal password
that will make it possible to unlock the e-Token so that B-Web may have
access to your certificate/asymmetrical keys. The secured channel between
your PC and the computer of the Bank may then be set up.
If
you already are a B-Web customer and wish to subscribe to a new contract,
please inform your account manager of it. It is possible to consult
different B-Web contract with a single e-Token no matter where your
accounts are open.
First use
As soon as you subscribe to B-Web, you receive an e-Token and a
PIN code from your bank.
During the first connection, you have to enter the PIN code received
from your Bank.
During that connect, B-Web detects that it is the first time your
connect and then asks you to change the PIN code and to choose a totally
personal PIN code.
From now on, you will have to use that PIN code during the later connections.
The PIN code sent by the bank will not be used again.
Advantage
In order to access to B-Web or to sign instructions, you absolutely
need two elements :
your
personal e-Token,
your
personal PIN code.
Would your e-Token be stolen,
it couldn't be used as it is protected
with a PIN code.
The major advantage of the e-Token is its mobility. You can take
it everywhere with you and can carry out your banking transactions
on any computer on which you have installed B-Web (and of course
provided that you have an Internet access and a USB port).