Commercial Bank of Ethiopia
Internet Banking
May-2015
07/31/2024 Epayment subproces 1
Outline
• Description
• Key features
• User authentication
• Types of user
• Personal IB service
• Corporate IB service
• Security features
• First time registration
• Risk control
• ARCIB Architecture
• Benefit of IB
• How to be IB customer
• About Soft token
• Mobile banking FAQ
• Quiz
07/31/2024 Epayment subproces 2
After completion of the training you
will:-
• An overview of internet banking
• Understand CBE internet banking system.
• Types of CBE internet banking and service provided
by the system.
• What sort of security feature's are implemented.
• How to setup a customer for internet banking.
• About soft token
• How to handle customers request
07/31/2024 Epayment subproces 3
Description
• Internet banking :- in an electronic service provided by the
Bank to allow customer to perform transactions, payments
etc. over the Internet - through a bank’s secure website.
• Deployed by Temenos itself.
• CBE has implemented a multi-channel banking system (i.e.
T24) which also incorporate internet banking(R10) and
mobile banking channels, that enables customers to
transact 24 hrs a day and 7 days a week with out a need to
go to the banks counter.
07/31/2024 Epayment subproces 4
Key features
ARC IB provides banks using T24
• Fully integrated personal and corporate banking solution.
• CBE IB supports multi level class of service
Personal
Corporate
• Full real-time access
• Modern
• Scalable
• high availability 24x7 operations.
07/31/2024 Epayment subproces 5
User Authentication
• ARC IB requires third party authentication server to provide
authentication at the web tier prior to any communication with t24
• Currently CBE internet banking secured by actividentity’s 4tress
authentication manager.
• 4tress authentication server allows two factor authentication.
• Two factor authentication using hardware tokens is the standard
offering and will meet US FFIEC OCT,2005 guidelines.
• In 4tress user credential are stored in an encrypted form with the
encryption key normally stored in a built-in Hardware security
module(HSM).
07/31/2024 Epayment subproces 6
Cont’d
• Two factor authentication :-
1. In hand (token hard or soft)
It’s have it’s own pin
Used for authentication and transaction signing
purpose
Soft token have the same functionality like hardware token
Mobile token
Application that runs on mobile device, it depends
on the device platform(Java , Android,
Phone…….etc)
PC token
Application that run on computers
07/31/2024 Epayment subproces 7
Cont’d
2. In mind
User defined password
User credentials are stored in an encrypted form
with the encryption key in a Hardware Security
Module(HSM).
07/31/2024 Epayment subproces 8
Cont’d
• The login page interrogates the authentication server for initial
user authentication.
• Only when a user have given correct credentials for the
authentication server are they logged into T24, non-authenticated
user has no impact on T24 whatsoever.
• The 4tress server also used for transaction confirmation using
additional credentials or challenge/response or OTP.
07/31/2024 Epayment subproces 9
Types of users
• The CBE has implemented “TEMENOS ARC internet
banking” to provide a modern, scalable and fully integrated
personal and corporate internet banking solution.
• The personal and corporate internet banking solution of the
bank supports various functionalities and security features .
07/31/2024 Epayment subproces 10
CONT’D
• Personal IB
• Personal Banking- is an internet banking channel that
provides Commercial Bank of Ethiopia personal clients with
online financial services.
• Corporate IB
• Corporate Banking- is an internet banking channel that
provides online financial services targeting to
Corporate(company, NGO, organization.....etc). Internet
Banking service in addition to the service mentioned in
Personal Internet Banking.
07/31/2024 Epayment subproces 11
Personal IB Service
• Account balance
View Real-time balance
View / download(.csv or html format) account
statement.
Search account statement by given date.
• Create/view and cancel standing order
Automatic fund transfer to given beneficiary account on a
predefined regular basis
• Create/view and delete beneficiary
define your own beneficiary
LMTS(Local Money Transfer)
remittance
07/31/2024 Epayment subproces 12
Cont’d
• Fund Transfer
Own account transfer
transfer between ones own account to other own
account(same bank customer ID).
To other CBE account holder.
To predefined beneficiary.
• Order/view cheque status.
• Messages sent to/ from the bank which allows sending and
receiving messages securely.
• Setting:
Change static password
Login history
07/31/2024 Epayment subproces 13
Corporate IB Service
• Account balance
View Real-time balance
View / download(.csv or html format) account
statement.
Search account statement by given date.
• Create/view and cancel standing order
Automatic fund transfer to given beneficiary account on a
predefined regular basis
• Create/view and delete beneficiary
define your own beneficiary
LMTS(Local Money Transfer)
remittance
07/31/2024 Epayment subproces 14
Cont’d
• Fund Transfer
Own account transfer
transfer between ones own account to other own
account(same bank customer ID).
To other CBE account holder.
To predefined beneficiary.
• Bulk payment
e.g. salary payment
• Letter of Credit(LC)
company can apply a letter of credit to the bank
07/31/2024 Epayment subproces 15
Cont’d
• Order/view cheque status.
• Setup / reverse sweep account
In this menu customer can set up a limit
on account beyond which the balance are
automatically transferred to beneficiary account.
07/31/2024 Epayment subproces 16
CONT’D
• Mange user
Admin users on corporate can assign duties to corporate
inputter and authorizer.
• Messages sent to/ from the bank which allows sending and
receiving messages securely.
• Setting:
Change static password
Login history
07/31/2024 Epayment subproces 17
ARCIB Architecture
07/31/2024 Epayment subproces 18
Transaction signing flow diagram with Pocket
Token
1. Payment transaction
request
2. Customer confirms transaction
detail
3. Customer requested to
generate and enter OTP
4. Transaction confirmed
and completed
Successful credential
authentication response
07/31/2024 Epayment subproces 19
Risk control / Security
• A range of transaction authorization options
• Transaction limits
• Daily transaction limit 100K for personal
• Single transaction limit 100K for personal
• For corporate internet banking the limit depends on a mandate we
put .
• Dual authorization for administrative changes
• Risk attributes for beneficiaries with related limits.
07/31/2024 Epayment subproces 20
Security
CBE IB is a highly secure application. Coupled with additional
components, state-of-the art security can be achieved in
a bank implementation.
Features typically include:
• Secure Sockets Layer (SSL) used
to achieve trusted communication.
When URL begins with https it identifies the site as “secure” (meaning
that it encrypts or scrambles transmitted information)
• Multi-level firewalls
• Two factor authentication
OTP, static password
07/31/2024 Epayment subproces 21
Cont’d
• User lockout after incorrect login attempts
• Inactivity timeout
• No useful data in URLs
• Encrypted authentication credentials
stored on 4tress’s HSM
• Unique personal User ID
given by the bank
• Transaction signing(using One Time Password(OTP) for payment
and beneficiary creation)
07/31/2024 Epayment subproces 22
Benefit of IB
• Easy to access your account
• Financial management
• Availability (24X7)
• Time and cost saving
• Avoiding branch queuing
• Account and fund management at your hand.
• Easy to get/print bank account statement.
• Possibility to process more financial transactions
• Possibility to extend your market
(even out of country)
07/31/2024 Epayment subproces 23
Requirement
• Being CBE customer
• Apply for the service from where your account is
maintained.
To Use the service
• Have User ID, memorable word and Token from the bank
• PC with an internet connection
• Using your user ID , token serial number, registered
phone number or email and memorable word
activate/register your self on soft token activation portal.
07/31/2024 Epayment subproces 24
About soft token
• Software token is a type of two factor
authentication security device used to authorize
the use of computer service.
• With CBE soft token you may not necessarily carry a
hardware token.
• CBE have two types of software tokens
o Mobile token:- the one which is installed on mobile handset,
tablets….
o PC token :- the one which is installed on desktop computer,
laptop…
07/31/2024 Epayment subproces 25
Where to get CBE soft tokens
• For mobile token
Android platform go to play store
search by “CBE Mobile Token”
IOS platform(IPhone) go to pp store
use same search key word “CBE Mobile Token”
• For PC token
Get the link to download from the
CBE’s official site(http://www.combanketh.et)
07/31/2024 Epayment subproces 26
What can we do with SSP
• CBE soft token have four basic work flows
1. Enrollment with Memorable word
• Enables a new user to create all necessary credentials(Static password,sequrity
questions …..
• Existing customer uses first Change or update security questions workflows
2. Change or update password
3. Change or update security questions
4. How to manage tokens
07/31/2024 Epayment subproces 27
How to register customer for IB at
branch
How to register Personal internet banking
How to register Corporate internet banking
How set up Default menu for corporate IB
How set up mandate for corporate IB
How to
merge Accounts that have different customer id
07/31/2024 Epayment subproces 28
How to use SSP
How to Enroll with Memorable word
How to Change or update static password
How to Change or update Security questions
How to manage tokens
07/31/2024 Epayment subproces 29
https://www.cbeib.com.et
Official website
address for CBE
Internet banking
services
07/31/2024 Epayment subproces 30
Login with User-ID , One Time Password and Static Password
ABEBEIB001
65782156 PASSWORD21
Click Login Button
07/31/2024 Epayment subproces 31
Admin user
07/31/2024 Epayment subproces 32
Continue…..Admin user
07/31/2024 Epayment subproces 33
Continue……Admin user
07/31/2024 Epayment subproces 34
Inputter
07/31/2024 Epayment subproces 35
Authorizer
07/31/2024 Epayment subproces 36
Continue….. Authorizer
07/31/2024 Epayment subproces 37
Continue….. Authorizer
07/31/2024 Epayment subproces 38
Internet banking Frequently asked
questions(FAQ)
• How can I add more than one account after starting
the service?
• It says authentication error when am about to login
into the service?
• What type of customer intended to or not to
request corporate or personal IB?
• How to merge two different account that have
different customer id?
• How to start corporate internet banking?
07/31/2024 Epayment subproces 39
Cont’d
• I forget my static password, how can I reset it?
• My token pin is locked?
• My token is lost or damaged?
• Unable to make first time registration?
• Why it displays white page after I login in?
• How can I change my password?
• Is internet banking works out side of Ethiopia?
07/31/2024 Epayment subproces 40
Mobile banking Frequently asked
questions(FAQ)
Common error during authorization
• mo.customer.exist
Remove multi value email address or validate email address
• Customer phone number missing, already exist
customer’s phone number incorrect/already registered
• Stop customer deregistration failed
End date and start date are same
• customer stop error invoking java call j – code -7
customer is already registered ..find it on ARCMOB
• Unable to find user based on Externaluser ID
customer ID is belongs to different branch
07/31/2024 Epayment subproces 41
CONT’D
• How to access more than one account using one
phone number?
• I have only two menus, how can I get the rest of
services?
• I cant make any payment , it says
repository.Nocorebanking.available
07/31/2024 Epayment subproces 42
Resource location
• FTP server
• ftp://10.1.25.8
• Username- TEMENOS
• Password -123456
or
• Username- LMTS
• Password - lmts
• Tel :011-5-54-44-48
• Fax 011-5-54-44-47
07/31/2024 Epayment subproces 43
07/31/2024 Epayment subproces 44
Thank you
07/31/2024 Epayment subproces 45