Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Don’t forget security threat, says Econolite
    May 6, 2020
    A new level of communication is helping deliver on the promise of Vision Zero and a more sustainable future. But amid the promise, Econolite’s Sunny Chakravarty suggests we need to be mindful of the potential downsides in an age of mass connectivity
  • The case for integrating urban traffic control and parking
    February 3, 2012
    Although urban traffic control and parking management are inextricably linked in so many ways, there remain fundamental differences which undermine closer integration. Car parking guidance systems can have a significant, positive impact on congestion in town and city centres, however conflicting business models still stand in the way of the more profound integration of car parking management and Urban Traffic Control (UTC) systems.
  • Blockchain: the next big thing for ITS? Really?
    October 8, 2018
    Everyone’s heard of blockchain – but most people are less sure about what it really is, and how it might be used in transportation. Andrew Williams peers into cyberspace to find some answers. A growing number of organisations in the ITS industry are exploring how blockchain technology could be used for ITS and mobility applications. So, what exactly is blockchain technology? What are the key current and potential applications in the mobility and ITS sector? And what practical benefits might it bring?
  • Debating contactless toll charging by smartphone
    April 25, 2012
    Developments in the mass transit sector could provide indicators of potential for greater use of mobile consumer electronic devices for charging and tolling, according to Consult Hyperion’s Mike Burden. However, opinion among toll system suppliers is divided. Jason Barnes reports The combination of mass-market devices and their protocols, typified by smartphones featuring near field communication (NFC), points to some exciting cross-fertilisation possibilities in the charging and tolling sector, says Consul