The Central Bank of Nigeria has released a regulatory framework for the use of Unstructured Supplementary Service Data (USSD).
This is to reduce the risk by bank customers who carry out transactions through the USSD platform.
In the proposed framework, USSD based financial transactions will require an end-to-end encryption to protect the integrity of the financial information.
The CBN instructs that mobile money operators are eligible for the issuance of short codes after meeting the necessary requirements of the Nigerian Communication Commission (NCC) for the issuance of the codes.
Financial institutions are required to treat and solve any customer related issues regarding these transactions within 48 hours, and the CBN warns that failure to do so will attract sanctions.
According to the exposure draft, to be eligible for the issuance of unique short codes from the Nigerian Communications Commission (NCC), mobile money operators must meet the necessary requirements of the Commission, while other service providers must obtain a letter of comfort from the CBN before being considered for the issuance of the short codes by the NCC.
It further stated that all providers of USSD based financial services must put in place: “A message authentication mechanism to validate that requests/responses are generated through authenticated users; use secure USSD communication channels with a strong encryption mechanism; not use the USSD service to relay details of other electronic banking channels (in case of banks) to their customers, to prevent compromise of other electronic banking channels through the USSD channel and implement masked PIN entry.”
In addition, the exposure draft proposes that USSD providers must: “Ensure encryption at USSD Gateway by implementing the Hardware Security Module (HMS). Each financial institution key shall be securely loaded through an auditable process.”
USSD providers must also, according to the exposure draft: “Implement end-to-end encryption by ensuring that, at least, radio encryption between users’ phones and base stations, using secure VPN layered with SSL or TSL to ensure secure transmission of USSD signals.”
The CBN also stated that financial institutions are expected to treat and resolve any customer-related issues within 48 hours, adding that Non- compliance shall be subject to penalty as may be prescribed by the CBN, from time to time.
Share this



