Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • February 8, 2017
    Cybercrime is not a remote threat for toll operations
    The rise of cybercrime is starting to impact tolling concessions, as Colin Sowman discovers. Yahoo’s revelation that it has taken two years to discover that it had suffered a security breach resulting in hackers stealing the details of 500 million users is shocking - although the hackers only gained access to users’ names, contact details and encrypted passwords.
  • November 19, 2013
    Thales uses standard smartphones to revolutionise mobile point of sale sector at CARTES 2013
    Thales, the UK-based information systems and communications security specialist, is planning to re-shape the mobile point of sale sector at CARTES 2013. The company will be sharing and demonstrating a range of solutions from leading mPOS device manufacturers on its stand at the show, as well as showing off the newly-announced members of its multi-partner ecosystem. “By working with Thales, Miura has been able to simplify and remove the complexity of delivering leading P2PE and Remote Key Injection services
  • November 3, 2014
    CARTES examines the pros and cons of Bitcoin
    Money is changing. Despite some widely-publicised recent problems, the Bitcoin system is now worth around €7 billion ($8.9 billion) and other ‘crypto-currencies’ such as Ripple are gaining momentum. The success of these pioneers shows that customers are increasingly ready to consider payment systems that are different from traditional dollars, euros and yen.
  • November 5, 2014
    Biometrics Institute addresses safety and security issues at CARTES
    The use of biometric technology has spread rapidly in recent years, as it offers customers a simple and secure solution, whether they use it to identify themselves on smartphones, ATMs or bank branches. At CARTES SECURE CONNEXIONS 2014, international experts will discuss the most promising and innovative initiatives in this field.