Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Q&A Oberthur
    November 5, 2014
    Didier Lamouche, president and CEO of Oberthur Technologies (OT), explains what ‘users on the move’ means to his company and what can be done about hackers
  • Spire Payments launches Linux-based line of PoS terminals
    October 30, 2013
    Spire Payments has launched the only Linux-based PCI 3.x and SRED-compliant PoS terminals, covering wireless and mobile PoS devices, from fixed countertop to PIN pads. The SP range has been designed to be fully PCI PTS 3.x compliant, including the use of open standards and the adherence to SRED.
  • TAS & KFI /GLOBALCOM Showcase New M-POS Solution at CARTES 2013
    November 20, 2013
    Global card and mobile payments leader TAS Group have revealed a new EMV chip-based mobile Point of Sale (mPOS) solution that allows merchants to securely and quickly take payments “on the go” at CARTES 2013, a solution made possible through a strategic partnership between TAS Group and KFI / Globalcom. TAS Group says its M-POS solution “offers convenience in conjunction with the highest security thanks in large part to the EMV chip and pin technology, which is at the heart of the security system. It is qu
  • ‘Wave and pay’ parking
    July 17, 2012
    APT SkiData has further extended the ‘wave and pay’ capabilities of its parking solutions with the new Artema EMV Level 2 contactless payment module as an integral part of its latest payment devices. Sited conveniently below the ‘traditional’ magnetic strip reader, the reader accepts a number of different contactless payment types in unattended environments, including Visa payWave and MasterCard PayPass cards.