Productsprevious-icon
Solutionsprevious-icon
Industriesprevious-icon
Resourcesprevious-icon
Login
sense
npciFrame
Commitment to NPCI Security
Controls on SIM & Device Binding
The following document outlines the terms of use of Sense. Before using any of
Sense's services, you are required to read, understand and agree to these terms.
  • Check SIM State
  • Device Binding Disallowed on Airplane Mode
  • Wi-Fi Mode
  • Device Binding completion in the same session
  • Device Binding Disallowed on multiple short codes (token)
  • Length of Device Binding String
  • Multiple Device Binding Limits
  • Allowing Device Binding only for Latest App Versions
  • SMS Token Expiry
  • Dynamic SMS Token
  • Private API Solution for iOS
  • Customer on-boarding on iOS/Android based Devices
  • VMN Binding for SMS Token
  • Application to check for successful SMS Sent check or auto read OTP Validation
1. Check SIM State
NPCI has mandated all PSPs (Payment Service Providers) to check the SIM or eSIM status on Android and iOS mobiles. It emphasizes real-time validation & ensures digital transactions are conducted only through devices with authenticated and active SIM. App developers are now compelled to integrate SIM or eSIM status checks into their security protocols.
2. Device Binding Disallowed on Airplane Mode
In a significant move to bolster the security of digital transactions, the National Payments Corporation of India (NPCI) has issued a mandate that rejects device binding while the device is in Airplane Mode.
3. Wi-Fi Mode
As per NPCI mandate, for Android and iOS mobile even if Wi-Fi is available, it permits Device Binding only when a SIM/e-SIM/Telco (telecommunications) connection is available. It provides an additional layer of security and authorization. Mobile data is mandatory with authenticated and active SIM.
4. Device Binding completion in the same session
For Android : NPCI has mandated Android mobile users that they are not allowed to toggle between apps or press any button until the Device Binding process is completed. The token must be invalidated if a customer moves out of active session. Auto notification pertaining to SMS charges received on customer device during registration shall not be considered as toggling.
For iOS : For iOS mobile users, once the user is redirected to message app and if customer presses cancel or switches to another app, then application should reject the Device Binding. For any user registration on iOS devices, if time taken for the control to be passed from SMS composer window to application exceeds 5 seconds the customer onboarding PSP shall decline device binding.
5. Device Binding Disallowed on multiple short codes (token)
According to the new NPCI mandate device binding is not allowed if same short code (token) received from multiple mobile numbers
6. Length of Device Binding String
NPCI has set the token length to minimum 35 characters with a combination of alphanumeric and special characters.
7. Multiple Device Binding Limits
NPCI has mandated UPI apps to block device ID for 24 hours if more than 3 tokens are generated while doing registration.
8. Allowing Device Binding only for Latest App Versions
App should allow registration only through the latest app version. If tried to do with older app versions, it should force for upgrade to latest version.
9. SMS Token Expiry
End-to-end device binding timer should not exceed 45 seconds. PSP bank has authority to change or reduce it at their end if they noticed any device binding control has been bypassed.
10. Dynamic SMS Token
According to NPCI mandate PSP (Payment Service Provider) bank should ensure that dynamic SMS token is being created for every registration attempt. PSP bank should invalidate the token if it is generated for virtual mobile number and send it to a different virtual mobile number.
11. Private API Solution for iOS
All UPI apps on iOS platform should implement private API solution. This private API solution prevents editing of encrypted token and virtual mobile numbers on SMS body when a user sends SMS to register on iOS.
12. Customer on-boarding on iOS/Android based Devices
For iOS : Allowed on iPhone devices which supports SMS sent API available from iOS 17 onwards. (Current XR/XS and above devices)
For Android : Allowed from Android API version 23 and above only.
13. VMN Binding for SMS Token
Every UPI App ensures at least 10 Virtual Mobile Numbers. Token should be generated dynamically and sent randomly to one of the unique VMN. VMN's should not be in series and should not repeat.
14. Application to check for successful SMS Sent check or auto read OTP Validation
Every UPI application or PSP should validate successful sent check of SMS for both iOS and Android devices.
Implementation Instructions
The UPI Application or PSP should read the sent items from SMS and validate that it was sent to intended VMN along with correct token ensuring token is sent to correct VMN where UPI app is installed.
If mobile device does not facilitate SMS sent check, then app should trigger auto OTP read functionality, disallowing manual entry of OTP. Auto read OTP should be done with sender ID validation, this will act as additional layer of security for handsets which do not facilitate SMS sent check.
New registration should not be allowed by App/PSP for handsets which do not support SMS sent check or auto read OTP.
All PSPs are required to ensure new additions and modifications mentioned above are implemented by 2023 for their own apps or TPAP's. PSPs are required to undertake periodic testing and deploy additional controls as deemed appropriate.

Want us to explain
to your business?