https://medium.com/@srkasthuri/understanding-upi-h...
बनाया गया: 13 जुलाई 2025
बनाया गया: 13 जुलाई 2025
The Medium post (18 Dec 2024) gives a primer on India’s Unified Payments Interface (UPI)—its architecture, how a payment actually travels from your phone to another bank account, and the security controls that keep the rail safe. Below is a distilled walkthrough plus up-to-date safety advice.
name@bank
or a QR code.Component | Role | Key point |
---|---|---|
VPA | User-friendly alias to an account | No exposure of bank details Medium |
UPI-PIN | 4–6-digit second-factor | Locally stored; never shared with NPCI/PSPs Medium |
PSP/App | Front-end (PhonePe, Google Pay, Paytm, BHIM) | Collects input, talks to NPCI switch turn6view0L27-L31 |
NPCI switch | Orchestrator | Validates and routes every request Razorpay |
Issuer & Acquirer banks | Sender’s / Receiver’s banks | Debit & credit accounts, confirm back Razorpay |
Layer | Control | Why it helps |
---|---|---|
2-Factor Auth | SIM/device binding + UPI-PIN (and often biometrics) | Stops credential replay if phone number or PIN alone is stolen turn6view0L33-L34 |
End-to-end TLS / AES-encrypted payloads | Data confidentiality over the wire | Mitigates MITM sniffing The Times of India |
Device binding | Transaction allowed only from registered phone | Blocks log-in from cloned apps/devices |
Hard transaction limits | ₹1 lakh/tx & daily caps (bank-configurable) | Limits loss even if account breached view0L62-L63 |
Regulatory oversight (RBI) | Dispute-resolution & mandatory 2FA | Industry-wide baseline security view0L62-L63 |
Vector | How it works | Mitigation tip |
---|---|---|
Phishing / social-engineering “collect” scams | Attacker sends payment request disguised as refund or prize | Verify requester name; never approve unknown collect requests |
Screen-overlay malware | Fake app layer harvests PIN/OTP | Install only from official stores; deny “Appear on top” to unknown apps |
Remote-access trojans (RATs) | Trick user to sideload APK + accessibility permissions | Keep Play Protect on; avoid sideloading |
SIM swap & call-forwarding | Hijack SMS OTP for PIN reset | Enable carrier PIN lock; watch for sudden loss of signal |
Feel free to ask if you’d like a deeper dive—e.g., architectural diagrams, latest RBI circulars, or how UPI compares with FedNow & PIX.