Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • UITP highlights mass transit changes
    October 25, 2022
    Increasingly, public transport passengers will no longer need to carry a dedicated smartcard ticket to travel, as technology enables virtually any type of contactless payment system to take over the role.
  • HDcctv Alliance at Security China 2014
    October 21, 2014
    Surveillance video standards organisation the HDcctv Alliance will host a technology and product Gallery at Security China 2014, in Beijing 28-31October. Companies exhibiting on the HDcctv Alliance stand at Security China 2014 include Dahua, Shany, Intersil, Semtech and Technology & Security. In the HDcctv Gallery shared by Alliance Members at Security China 2014, Dahua and Shany will demonstrate HDCVI 2.0-compliant cameras plugging and playing with a compliant DVR. Intersil and Semtech will showcas
  • Global toll revenues $8.5bn while technology ‘battles’ continue
    April 9, 2014
    ABI Research’s Dominique Bonte talks to Jason Barnes about trends in tolling and how a wider appreciation of technology options is sorely needed. Global Electronic Toll Collection (ETC) solution revenues will grow to $8.5bn by 2018, with ETC becoming a main source of funding for both Intelligent Transport Systems (ITS) and Vehicle-to-X (V2X) cooperative infrastructures, according to a new report from ABI Research (Chart 1). But, says the report’s author, ABI Research vice president and practice director Dom
  • Tags or communication based toll payment systems?
    January 20, 2012
    Midland Expressway Ltd's Tom Fanning discusses deployment of Near Field Communicationbased payment on the M6 Toll facility The M6 Toll's introduction from early next year of Near Field Communication (NFC) is a pragmatic response to the relative scarcity of tolled facilities and the concomitant low levels of tag take-up in the UK, according to the road's operator, Midland Expressway Ltd (MEL). Nevertheless, Dedicated Short-Range Communication (DSRC)-based tags operating at 5.8GHz are still a key part of the