Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • June 11, 2013
    Cubic payment application software achieves PCI-DSS certification
    The latest version of Cubic Transportation’s Cubic Payment Application (CPA 3.0) has been successfully validated according to PA-DSS v2.0 by the PCI Security Standards Council, and is listed as acceptable for new deployments on the Payment Card Industry Data Security Standards (PCI-DSS) website. CPA 3.0 is designed to provide optimum performance for securely processing legacy closed-loop payments, such as agency issued transit smartcards, as well as emerging forms of payment including bank-issued contactles
  • November 4, 2014
    Oberthur Technologies secures web payments with Dynamic CVV/CVC
    Card-not-present (CNP) fraud could be all but eliminated thanks to a revolutionary card security innovation set to be rolled out by Oberthur Technologies (OT) next year. OT has developed a dynamic back-of-card security CVC/CVV code that changes every hour on an e-paper panel.
  • November 20, 2013
    Q&A: Spire Payments
    Kazem Aminaee, President and CEO of Spire Payments, talks to CARTES Daily News about challenges and opportunities – and about why the industry must embrace change Q Can you give a brief outline of Spire’s current business priorities? A To remain the fastest-growing European-based POS supplier and best alternative to traditional POS suppliers; to remain the leader in mobile POS; to remain the centre of excellence for T42xx and M43xx technology and to provide the best in kind call centre, logistics and
  • November 3, 2014
    Q&A: Spire Payments
    As CARTES 2014 opens Kazem Aminaee, president and CEO of Spire Payments, tells CARTES Daily News why the cloud presents big opportunities and security remains paramount