Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Future of tolling: the priorities
    January 14, 2020
    In the final part of his investigation into the future of tolling technology, Josef Czako of Moving Forward Consulting asks what industry figures see as the priorities going forward…
  • Making connections without compromising security
    November 10, 2017
    We listen in as global experts discuss connected vehicles and cybersecurity. By 2019 there will be almost 44 million connected cars globally and by 2022 that figure will be nearer 70 million; some 40% will be electric powered, according to market analyst Frost & Sullivan. But its report said the issue of end-to-end security for the new technology is still under debate, as vehicle OEMs engage with vendors to test specific security application areas for both over-the-air and vehicle-to-exterior services.
  • Mobile payment and transit trial underway in Taiwan
    August 1, 2012
    Taiwanese Cathay United Bank has launched a trial for mobile payments and transit in Taipei. The project enables bank customers to use their mobile phones to make contactless payments at local stores and to access the Taipei public transit system. The NFC-capable microSD cards used as a secure element in this project are supplied by Giesecke & Devrient Secure Flash Solutions. The mobile security card SWP microSD card is the first in Taiwan that is compliant with MasterCard PayPass standards. This card has b
  • Fujitsu and Ingenico join forces on Merseyrail ticketing
    April 16, 2014
    Fujitsu, in collaboration with Ingenico, has upgraded UK transport operator Merseyrail’s ticketing systems to enable contactless payment, enabling 63 Merseyrail stations across the UK to offer contactless payment in terminals and manned ticket outlets. Merseyrail will retain the Fujitsu Star point-of-sale ticketing system which it has operated for the past nine years and Fujitsu, in conjunction with Ingenico, will provide 92 iPP320 contactless PinPads and Axis, its proprietary centralised payment proces