Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Debating the future development of ANPR
    July 31, 2012
    What future is there for automatic number plate recognition? Will it be supplanted by electronic vehicle identification, or will continuing development maintain the technology's relevance? In recent years, digitisation and IP-based communication networks have allowed Automatic Number Plate Recognition (ANPR) to achieve ever-greater utility and a commensurate increase in deployments. But where does the technology go next - indeed, does it have a future in the face of the increasing use of, for instance, Dedi
  • HeERO - harmonising e-Call across Europe
    March 1, 2013
    The second stage of the EC’s HeERO project, which aims to address some of the issues surrounding the eCall system, has just got underway. Jason Barnes reports. As the European Commission (EC)’s Har­monised eCall European Pilot (HeERO) project progresses into its second stage, ‘HeERO 2’, significant progress has already been made in addressing the technological and institutional issues relating to the pan-European deployment of an eCall system based around the new ‘112’ universal emergency telephone number.
  • Launch of first US smartphone commuter rail ticketing system
    November 13, 2012
    Customers in Massachusetts Bay on the US east coast can now purchase and then display rail tickets and passes using the MBTA mTicket app for iPhone and Android. Blackberry devices will also be supported soon. Massachusetts Bay Transportation Authority (MBTA) and Masabi US, the transit mobile ticketing provider, jointly announced the launch of the US’ first full smartphone commuter rail ticketing system. The tickets are displayed on the phone’s screen as an encrypted barcode and as a human readable ticket.
  • What Citizen Kane can teach transportation engineers
    July 14, 2023
    Andy Boenau suggests that one of the most famous movies of all time might have lessons for our industry. And they’re all about not knowing things...