Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Eurosmart: nearly one billion contactless smartcards shipped in 2013
    November 18, 2013
    The global desire for solutions which combine convenience and security shows absolutely no sign of stopping, according to Eurosmart, the acknowledged voice of the smart security industry Revealing some dramatic figures at the opening of CARTES 2013 today, Eurosmart estimates that 7.2 billion Smart Secure Devices will be shipped by the end of this year, with that number growing by 7% to more 7.7 billion units in 2014.
  • Kapsch offers EETS–compliant Tolling Services
    June 7, 2017
    Kapsch’s Bernd Eberstaller explains how the company’s new Tolling Services will help expand the number and capabilities of EETS services providers. By 2017, the European Electronic Tolling Service (EETS) should have been in operation for several years but it still remains some way away and with several significant hurdles still to be addressed. The concept behind EETS is simple enough: road users should be able to drive across Europe using only a single transponder to pay for all tolls, with the account-han
  • ANPR shockwaves emanate from Royston ruling
    October 7, 2013
    Colin Sowman looks at how a ruling regarding ANPR cameras in a small English town could have wide-reaching implications. Superficially it was an easy decision: the local council and traders wanted, and were prepared to fund, automatic number plate recognition (ANPR) cameras installed to deter crime in Royston, a small town (population 17,000) in rural England.
  • GMV contactless payment for Madrid transit
    July 7, 2025
    EMV system used by Madrid Regional Transportation Consortium companies