Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Securing V2X communications
    June 6, 2016
    Cybersecurity developments are moving fast in the automotive sector, but they’re a significant hurdle for the roll-out of C-ITS applications. Jon Masters reports. In the wake of the high-profile hacking of the Jeep Cherokee and problems like the flaw in the Nissan Leaf’s companion app that could compromise the security of data about recent journeys, initiatives linked to vehicle cybersecurity seem to be moving rapidly.
  • Card industry gathers for CARTES 2013 World Card Summit
    October 29, 2013
    One of the highlights of CARTES 2013 will be the World Card Summit, the prestigious opening conference on the first morning of the show, which promises to set the tone for the whole three days. Key players in the security industry will come together to share their views on what the state of play is at present – and put forward ideas of the technologies and solutions we will all be looking at in the future.
  • France invests in ‘citizen cards’ – but with data collection limitations
    November 5, 2014
    Cities in France are pressing ahead with ‘citizen cards’designed to give residents access to a wide range of services. The card is an NFC device that acts as a portal to areas such as transport services, libraries, sports facilities and residential parking schemes.
  • Init wins e-fare system in Oregon
    April 2, 2014
    In a project valued at more than US$14 million, integrated ITS and ticketing systems supplier Init is to implement a new e-fare/smart card payment system for the Tri-County Metropolitan Transportation District of Oregon (TriMet) in the US. TriMet provides bus, light rail, and commuter rail service in the Portland metro area; the new system will enable passengers to utilise contactless bank cards and mobile phones, offering more convenience and pricing equity. The contract comprises the delivery of a