BIS Standards for QR Payments, Biometrics and CBDC
Why in the news
As India seeks a global footing for its QR-code payment system, the Bureau of Indian Standards brought in new norms for biometrics, QR payments and digital currency, meant to lower fraud and improve interoperability.
Key facts
| Pillar | Focus |
|---|---|
| Biometric security | Secure storage, protection against identity manipulation, reliable authentication at financial institutions |
| QR-code integrity | Safe QR generation, encryption, safeguards against fake codes and unauthorised transactions |
| Digital currency (CBDC) | Cryptographic safeguards and system resilience for the Digital Rupee as it leaves the pilot phase |
Background
- Who does what: RBI handles the monetary side, NPCI the operations of the UPI network, and BIS sets national technical standards that banks and fintechs follow for hardware and software security and interoperability.
- Quishing: fraudsters paste a malicious QR over a genuine merchant code to redirect payments to a fake account. The standards require encryption and verification to stop such redirection.
- Biometric versus OTP: India is shifting from SMS OTPs, open to SIM swapping and phishing, to fingerprint, iris or face authentication. The norms guard against spoofing using photos or moulds.
Exam angle
- Issuer of standards: Bureau of Indian Standards, not NPCI.
- Three pillars: biometrics, QR code, CBDC.
- Terms: quishing, spoofing, interoperability.