Apple in Payments: Bluetooth Edition

by Cherian Abraham 12 min read June 10, 2014

Apple held its annual developers conference last week to showcase its new features within iOS8. One area that still needs clarification is Apple’s intent for mobile payments.Cherian Abraham, Experian Decision Analytics mobile payments analyst, shares what he thinks Apple might look to do in the mobile payment space going forward.

In myfirst post, I touched upon Apple’s program for third party hardware attachment market as being significant and likely to be a key aspect of its payments approach. In this post I discuss these three things:

1. How Apple’s new security paves the way for mobile payments
2. Bluetooth being secured enough where Payments is a use-case
3. Why the iPhone 6 will not have NFC

Last week,9to5mac reportedthat Apple has introduced a new specification for manufacturers in its MFi program (Made for iPad, iPhone and iPod) that allows them to create headphones that connect to iOS devices using a lightning connector instead of relying on the 3.5mm audio jack. Why is it important? Because as Apple looks to rid itself of any such remaining legacy vestiges, it’s also shedding any ambiguity around who is in control of the iOS hardware ecosystem and what it means to be a third party accessory maker – once reliant on open standards supported by all devices and now serving at Apple’s pleasure. It is a strategy that fits against the backdrop of an iOS ecosystem that is made up of software that is increasingly becoming more open, and hardware that is slowly being walled off – primarily in the name of security. The former is evident in how Apple has opened up third-party access to core authentication services like TouchID. What about the latter?

Apple’s new security blanket
Well, first let’s look at what Apple has publicly acknowledged about the MFi program. Every iOS device will initiate communication with a third-party accessory by asking it to prove sufficient authorization by Apple — to respond with an Apple-provided certificate, which iOS subsequently verifies. Further, the iOS device then issues a challenge, which is then answered by the third-party accessory by a signed response. These two steps require that a third-party accessory must have:

• An Apple certificate
• Requisite cryptographic capabilities — preferably in hardware to comply.

That is precisely what Apple doesby encapsulating all this in an Integrated Circuit that it controls – where the entire handshake is transparent to the accessory. With this – Apple’s role in the third-party accessory market becomes non-negotiable. You think you have a cool accessory that requires a trusted connection and intends to share data with an iOS device? Unless you inherit Apple’s controls you are relegated to speaking analog and conducting a limited set of user-driven operations — Start, Pause, Rewind (standard Serial UART audio playback controls) — usable only to headphones using the audio jack. Now, how about them apples?

It’s important to note that these steps to validate whether an accessory is authorized to communicate with an iOS devicecan happen over the lightning connector, Bluetooth or WiFi. The advantage here is that this repels man-in-the-middle attacks because a malicious interceptor will not have the Apple IC to pass authorization, and subsequently will not have the negotiated key that encrypts all subsequent communication. The whole key negotiation occurs over Bluetooth. It is important becausethis approach can solve man-in-the-middle attacks for Bluetooth in scenarios including payments.

A cynical view of the MFi program would be to consider it a toll that Apple is eager to extract from the third-party accessory makers building accessories authorized to communicate with an iOS device. A more pragmatic view would be to recognize Apple’s efforts as an ecosystem owner, whose primary intent is authenticating any and all devices within and in the periphery of the iOS ecosystem and secure all inbound and outbound data transfers.With more iOS device types, and a heterogeneous accessory market Apple is entirely justified in its role as the ecosystem owner to be at the front of the curve, to ensure security is not an afterthought – and instead to – mandate that data in transit or at rest is fully secured at all end-points.In fact, interest in Wearables, Home automation, Healthcare and Telematics are completely rewiring the rules of what it means to be an accessory anymore

I believe this approach to security will be the mainstay of how Apple visualizes its role in enabling payments — regardless of channel. Anything it does to reduce payments friction will be counterbalanced by serious cryptographic measures that secure devices that have a need to communicate in payments — to authenticate, to encrypt and to subsequently transfer a payment token. With TouchID today it does so by verifying the fingerprint before authorizing the transmission of an authentication token from the Secure Enclave to an Apple server in the cloud.I don’t doubt that the authentication token being sent to the Apple server in the cloud is itself signed by the device’s unique ID – which is verified, before the server completes the purchase with a card on file.Thus, crypto pervades everything the iPhone does, touches or trusts.

So how do the MFi program, Bluetooth, iOS Security fit in within Apple’s plan to tackle retail payments?
For that, let’s start with NFC. With NFC anointed as the only way forward by networks and other stakeholders — every other approach was regarded as being less secure without much thought given to that classification by way of actual risk of fraud. You could build the best payments “whatchamacallit”and throw everything and the kitchen sink at it — and be still branded as ‘Card Not Present’ and inherit a higher cost. Understandably — merchants passed on it as they couldn’t scale with the costs that it confronted. No self-respecting merchant could afford to scale — unless they owned all of the risk (viadecoupled debit, ACH or private label). All they could do was reject contactless and prevent themselves from being burdened by the network’s definition of a payments future. Thus the current NFC impasse was born.

Now with merchants rolling out EMV-compliant terminals, many of which have contactless built in, they are desperately looking to Apple for clarity. If Apple does NFC then they have the entirety of a terminal refresh cycle (approximately 10 years) within which they hope that common sense may prevail (for example, debit as an acceptable payments choice via contactless) and correspondingly toggle the switch to begin accepting contactless payments. If Apple goes in a different direction, a merchant who has chosen an EMV-compliant terminal with or without contactless is locked out until the end of the current refresh cycle.

But what if Apple went with Bluetooth? Two factors stand in the way: Bluetooth is not secure enough for payments today and terminal makers need to comply. Yet, with EMVCo publishing draft standards around tokenization one can argue that non-NFC modalities now are being given fair share, where proximity is not the only guarantee for security and other options such as Bluetooth can begin to address the challenge creatively.

Where is the opportunity among all this for Bluetooth?
Let’s tackleBluetooth Range and Device Pairingthat limit its utility in payments today.

Range is as much a curse as it is a blessing for Bluetooth. If security via proximity was NFC’s raison d’être, then in contrast Bluetooth had to worry about man-in-the-middle attacks due to its range. Though Bluetooth communication is invariably always encrypted, the method in which two devices arrive at the encryption key is suboptimal. Since much of the early key negotiation between devices happens in the clear, brute forcing the shared secret that is key to encryption is a fairly easy and quick attack — and the range makes man-in-the-middle attacks easy to implement and harder to detect.

The approach to device pairing also differs from Bluetooth to BLE. Needless to say, it is even less secure for BLE. Pairing in a payments context brings up further challenges, as it has to be silent, customer initiated and simple to execute. I am not going to pair my iPhone with a point-of-sale by punching in “000000” or another unique code each time I must pay

Can NFC be of use here? It can. In fact, Bluetooth pairing is the only use case where I believe that Apple may feel there is utility for NFC so that an out-of-band key exchange can be possible (versus an in-band key exchange wholly over Bluetooth). This is far more secure than using Bluetooth alone and derives a much stronger encryption key. An out-of-band key exchange thus enables both devices to agree on a strong encryption key that can prevent malicious third parties from splicing themselves in the middle. BLE however does not allow for out-of-band key exchange and therefore is limited in its utility. This is another reason why if you are a BLE accessory maker Apple excludes you from having to participate in the MFi program.

How can Apple secure Bluetooth and make it the standard of choice for a retail payment use case?
The answer to that lies inside Apple’s specification for MFi participants —manifested in the form of the Integrated Circuit Apple provides to them so that these iOS accessories may authorize themselves to an iOS device and secure the communication that follows. This IC which encapsulates the initial setup including the certificate, mutual key negotiation and deriving the encryption key — can support Bluetooth.

So if all that ails Bluetooth can be cured by including an IC – will point-of-sale manufacturers like Verifone and Ingenico line up to join Apple’s MFi program?

The message is clear. You must curry favor with Apple if you want to be able to securely communicate with the iOS ecosystem. That is no tall barrier for terminal makers who would willingly sacrifice far more to be able tospeak to 800M iOS devices and prevent being made irrelevant in an ever-changing retail environment. So why not include a single IC and instantaneously be able to authorize to that broad ecosystem of devices, and be capable of trusted communication? And if they do — or when they do — how will merchants, networks and issuers react?

Today a point of sale is where everything comes together — payments, loyalty, couponing — and it’s also where everything falls apart. Will this be considered Card Present? Even with all the serious crypto that would become the underpinnings of such a system, unfairly or not the decision is entirely that of a few.

Networks and issuers
To answer how they may respond, we must ask how they may be impacted by what Apple builds. Is Apple really upending their role in the value chain?I believe Apple cares little about the funding source.Apple would instead defer to – the merchants who believe it should be debit, and the issuers who believe the customer should choose – and secretly hope that it is credit. I don’t think that Apple would want to get between those two factions. It wants to build simply the most secure, easy way to bring retail payments to iOS devices — and allow all within the transaction flow to benefit.The rails do not change, but the end-points are now much more secured than they ever were, and they form a trusted bond and a far bigger pipe.A customer who authenticates via TouchID, a phone that announces to the point of sale that it’s ready to talk, a smart circuit that negotiates the strongest encryption possible while being invisible to all and a token that stands in for your payment credential that is understood by the point of sale. It is business as usual, and yet not.

Will the iPhone6 have NFC?
The presence of NFC in iPhone6 — if it’s announced — will not mean that NFC will be utilized in the same manner as it is today (for example, Isis).The radio will exist, but there will be no global platform secure element.

Today the role of the radio is instrumental (in both secure element or HCE cases) in transmitting the PAN to the point of sale. When there are coupons that need to be presented and reconciled at the point of sale — things begin to get complex. Since theradio becomes the bottleneck, it requires longer than a quick tap for more data to be transmitted. Proximity is a good guarantee for device presence as well as the customer, but it’s a poor vehicle for information.So why wouldn’t one try to relegate it to the initial handshake to enable authentification of the device and therefore the customer with the point of sale?

As I mentioned above,if Apple uses NFC, its role will be to facilitate an out-of-band key exchange to secure the subsequent Bluetooth communication so that an iOS device can trust the point of sale and securely transmit payment data.This data may include any and all tokenized payment credential along with loyalty, couponing and everything else. By using NFC for out-of-band authentication in conjunction with the authentication IC (provided by Apple) in the point of sale, Apple can run circles around the limitations imposed by a pure NFC approach — exceeding it on usability, security, adaptability and merchant utility.

Yet, if NFC’s role is limited to the initial key negotiation, then the case can be made that NFC has very limited utility, it exists only to serve Apple’s security narrative, and utilizing NFC for the initial pairing strengthens the encryption and makes it harder to snoop. If it has only derived incremental value, would Apple care to put it on iPhone6 — and split its utility among customers using iPhone6 versus all others?

With more than 400M iPhones out there that can support Bluetooth LE and iOS8, why ignore that advantage and create a self-induced dependency on a radio that has no subscribers today?

So where do I fall within this debate?I believe iPhone6 will not have NFC.

Learn more about our Global Consulting Practice.

Related Posts

Workflow Automation for Financial Services

Manual processes are quietly expensive. Every handoff between teams, every file transfer waiting in a queue and every decision that sits on someone's desk adds cost, introduces risk and slows the customer experience. For financial institutions, those delays translate directly into lost revenue and eroded margins. That’s why workflow automation is becoming critical for financial institutions looking to stay competitive. Done well, it doesn't just make existing tasks faster. It reshapes how decisions get made across the entire customer lifecycle, from the first marketing touch to account servicing and beyond. What is workflow automation? Workflow automation is the use of technology to run a sequence of tasks, decisions and handoffs with minimal manual intervention. Instead of a person moving work from one step to the next — pulling data, applying a rule, routing an account and sending a communication — software executes those steps automatically based on defined logic and real-time data. For financial institutions, workflow automation usually combines four ingredients: Data Connecting to the internal and external data sources that inform a decision. Analytics Scores, models and attributes that turn raw data into insights. Decisioning A rules engine that determines the right action for each customer or account. Execution The operational layer that carries out the action, whether that's an offer, a credit line change or outreach. The benefits of workflow automation The value of automation goes well beyond "doing the same thing faster." The benefits financial institutions consistently see include:Greater efficiency and lower operating costsAutomation frees underwriters, analysts and agents to focus on exceptions and high-value work rather than repetitive processing. Faster, more consistent decisionsA credit application that once waited in a queue can be assessed in real time against consistent, auditable policies, improving both the applicant's experience and portfolio quality. Better customer experiencesAutomation enables financial institutions to personalize communications at the point of interaction and offer the self-service options that many people now prefer. Improved compliance and governanceReduce the risk of costly compliance failures with built-in controls, audit trails and guided workflows. ScalabilityRespond to changing volumes without sacrificing speed, consistency or the customer experience. Where workflow automation makes the biggest difference Workflow automation tends to deliver the most value where decisions are frequent, repeatable and informed by data. In financial services, those opportunities exist across the customer lifecycle. Onboarding Onboarding is a customer's first experience of your organization, and it's also where friction can cause customers to abandon the process and turn to another provider. Forty percent of U.S. consumers have considered walking away from opening a new account when the process felt burdensome.1 An automated onboarding workflow can bring together document verification, device intelligence, behavioral analytics, credit attributes and more, then orchestrate them into a single decision. The result is a lower-friction experience for the customer and a consistent, auditable process. Once customers are on the books, serving them well means making continuous, high-volume decisions: credit line changes, cross-sell and up-sell opportunities, risk monitoring and retention actions. Automation makes it practical to run these recurring decisions consistently across an entire portfolio, using a holistic view of each customer that draws on multiple scores and attributes. Lending The underwriting process is a great example of how workflow automation can help prevent applicants from waiting days for an answer. Loan origination and credit decisioning capabilities are designed to create a seamless review process across consumer and commercial lending. After automating originations with our solutions, Michigan State University Federal Credit Union cut application processing time to under 24 hours. Fraud Financial institutions are checking fraud at every touchpoint, and the standard for AI fraud detection continues to rise as fraudsters use AI to slip under the thresholds of any single detection tool. Rather than running fraud checks in isolation, an automated workflow can run multiple fraud and identity verification services in parallel and weigh signals together. A fraud decisioning platform connects signals across internal systems, Experian data and third-party services, allowing teams to stay on top of evolving threats. Build a strong foundation for workflow automation Workflow automation can connect these stages, creating a consistent decisioning framework. What ultimately separates good automation from great automation is the quality of the data and decisioning software underneath it. An automated workflow is only as good as the information feeding it. That's where our comprehensive credit, alternative and identity data with the tools financial institutions need to act on it. Learn more here What is workflow automation in financial services? It's the use of software to execute sequences of data gathering, analysis, decisioning and action. How does automated decisioning improve credit decisions? Automated decisioning applies consistent logic to every account in real time or in bulk, enabling faster and more informed decisions, quicker responses to market and regulatory changes at the point of interaction. Does workflow automation replace human judgment? No. The goal is to automate routine, high-volume decisions so skilled staff can focus on the exceptions and complex cases that genuinely require human judgment. For example, a sensitive collections conversation or a nuanced underwriting call. Are we still compliant with regulations if we use an automated workflow process? Well-designed platforms include built-in governance, audit trails and compliance controls that help institutions align with requirements like the Fair Credit Reporting Act (FCRA) and other regulatory guidelines improving compliance compared with manual processes. How long does it take to implement? It varies by solution and scope, but modern cloud-based platforms are designed for fast onboarding and limited IT involvement. 1.Global Fraud Snapshot 2025: Opportunities and challenge in identity, fraud and financial crime

September 9, 2026 by Zohreen Ismail
Expanding the Prescreen View with Alternative Credit Data

Start with a simple question Credit prescreen is an important tool in many lenders’ growth strategies. But the precision of any prescreen strategy depends on the data behind it. What financial behavior might traditional credit data alone not reveal? With Clarity data now available for Instant Prescreen decisioning, lenders can bring alternative credit insights into their targeting strategy, helping them identify prospects who may align with their established criteria, refine targeting strategies and explore additional acquisition opportunities while maintaining control over their risk thresholds. Additional insights alongside traditional credit data For many consumers, a traditional credit file tells a rich and reliable story. But it doesn't always tell the whole story. Consumers may also be using alternative financial products, such as small-dollar installment loans, single-payment loans, auto title loans or rent-to-own agreements and building payment histories that provide additional signals about their financial behavior. For lenders, those unseen signals can represent untapped opportunities. With more than 60 million unique subprime identities, Clarity's database helps lenders gain a more complete view of their applicant pool. Clarity data adds another dimension to that view, providing alternative credit insights that can help lenders better understand consumers whose financial behavior may not be fully represented by traditional credit data alone. How Clarity data sharpens instant prescreen decisioning Clarity provides specialty alternative credit data, with insights into subprime and near-prime consumer activity that may not appear in traditional credit files. And because Clarity is part of Experian, those insights can now be brought directly into Instant Prescreen decisioning. That means lenders can incorporate additional attributes and scores into their credit decisioning strategies without managing a separate data feed or stitching together disconnected sources. It has quickly become a visibility gap lenders can't ignore. Additional data may help support more granular segmentation and targeting strategies. Lenders remain in control of their criteria and risk thresholds while gaining additional information to inform their prescreen strategies. When considered alongside traditional credit data, alternative credit insights can support several aspects of prescreen decisioning: Identify more opportunities: Surface qualified prospects who may be harder to identify using traditional credit data alone. Refine targeting: Add alternative credit insights to help differentiate consumers with greater precision. Inform offer strategies: Use a broader view of financial behavior to help align consumers with appropriate offers. Expand intelligently: Explore incremental audience opportunities while maintaining control over your established risk criteria. Simplify execution: Access Experian and Clarity insights within a connected Instant Prescreen decisioning environment. See more opportunity in your prescreen strategy Growth doesn’t always require looking for an entirely new audience. Sometimes, it starts with seeing more in the audience already in front of you. By bringing Clarity data into Instant Prescreen, lenders can add another layer of insight to their decisioning, helping identify incremental opportunities, refine targeting and support acquisition decision processes across a broader range of consumers. Explore prescreen solutions

September 3, 2026 by Zohreen Ismail
Are Fraudsters Building Better Identities Than Your Customers?

Fraudsters are getting surprisingly good at onboarding. Sometimes, better than your customers. Legitimate customers treat onboarding like an errand. They start an application between other tasks, get distracted, forget a password, switch devices, upload a document or come back later to finish. Their digital lives aren’t always linear, because real life isn’t either. Fraudsters approach onboarding differently. For them, opening an account is the objective. Every interaction is designed to increase the odds of success. The difference raises an uncomfortable question hanging over onboarding: What exactly are we rewarding? When smooth becomes suspicious Digital onboarding has traditionally rewarded experiences that feel smooth, consistent and complete. The challenge is that legitimate customers rarely behave that way. Most people approach onboarding somewhere between mildly distracted and mildly annoyed. They pause halfway through because dinner is burning. They reopen an old account only to realize everything is attached to an email they made in college and, somehow, still use for airline receipts. Digital life accumulates history unevenly, because ordinary life does too. Fraudsters have every reason to eliminate those inconsistencies. Applications may be rehearsed. Identity attributes are assembled deliberately. Contact points are prepared in advance. Every interaction is optimized to make the application appear credible. Ironically, the qualities organizations often associate with confidence — clean submissions, steady progression and few corrections — can also describe applications that have been carefully engineered to pass inspection. The challenge isn't that smooth onboarding is meaningless. It's that smooth onboarding, by itself, doesn't tell the whole story. Context changes interpretation A smooth onboarding experience should be the beginning of the evaluation, not the end. Behavior provides important context. How someone moves through an application can reveal whether the experience feels naturally human or unusually orchestrated. Do they interact naturally? Do they hesitate, correct mistakes or navigate in ways that resemble ordinary human behavior? Or does the session appear unusually scripted, automated or repetitive? Identity verification adds another layer. Matching information across trusted sources, validating identity details and strengthening confidence in account creation remain important, particularly when onboarding decisions carry financial, fraud or customer experience consequences. But verification largely answers a point-in-time question: Does this information match right now? A third layer comes from digital history. An inbox attached to years of airline receipts, loyalty accounts, subscription renewals, account recovery, financial notifications and familiar digital routines introduces a different kind of confidence. Legitimate digital identities leave behind patterns of persistence and engagement that develop gradually over time. Fraudsters can assemble convincing identity attributes, but creating years of ordinary digital life is much harder. Building confidence in an identity requires more than verifying information submitted during a single onboarding session. It requires understanding whether the identity reflects a broader history that supports what the application suggests. A multilayered approach builds stronger identity confidence No single signal can provide a complete view of identity risk. Organizations need multiple sources of confidence that reinforce one another. That's the thinking behind our approach: combining behavioral intelligence, identity verification and digital identity continuity into a more complete view of risk. We bring these complementary layers together through: • NeuroID adds behavioral context during onboarding and account creation, helping identify interaction patterns that may indicate automation, manipulation or coordinated fraud. • Precise ID® strengthens identity verification and resolution by comparing applicant information with trusted identity data. • AtData, recently added to our portfolio, contributes email-centered intelligence based on persistence, engagement and long-term digital history. Together, these capabilities help organizations move beyond evaluating a single moment in time to understanding whether an identity is supported by consistent behavior, trusted identity data and an established digital history. The future of fraud prevention isn't about rewarding the smoothest application. It's about recognizing the most trustworthy identity. Fraudsters can rehearse an application. They can optimize an onboarding journey. They can even assemble convincing identity attributes. What they can't easily manufacture is years of ordinary digital life. That's why digital identity continuity has become an important layer of modern fraud prevention. Combined with identity verification and behavioral intelligence, it helps organizations distinguish between identities that simply look convincing and those supported by a history that is much harder to fake. Learn more Contact us

September 2, 2026 by Julie Lee

Subscribe to our Newsletter

Enter your name and email for the latest updates.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Subscribe to our Newsletter

Don't miss out on the latest industry trends and insights!
Subscribe