Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • CreditCall unveils new EMV and mPOS solutions at CARTES 2013
    November 19, 2013
    In the US from October 2015, any merchant who has not completed migration to EMV-certified chipcard payment will have to carry the cost of any fraudulent transaction that it attempts to process. At CARTES 2013, and in order to help merchants de-risk and meet what is generally held to be an aggressive in-service deadline for change at a national level, multi-channel payment gateway specialist CreditCall is launching ChipDNA. This is a unique bundle, available to acquirers, processors and VARs, which d
  • Lowering the barriers to combined control rooms
    March 29, 2017
    Integrating control rooms can improve traffic management, security and emergency response without excessive cost or compromising privacy. In the wake of the recent terrorist events in France and Germany where the transport system was exploited with deadly consequences, many governments and agencies are reviewing the security arrangements – particularly around popular and high profile events.
  • Lowering the barriers to combined control rooms
    March 29, 2017
    Integrating control rooms can improve traffic management, security and emergency response without excessive cost or compromising privacy. In the wake of the recent terrorist events in France and Germany where the transport system was exploited with deadly consequences, many governments and agencies are reviewing the security arrangements – particularly around popular and high profile events.
  • World Card Summit: 'Significant opportunities and challenges,' says G&D
    November 20, 2013
    Speaking on cloud-based security and mobility at this year’s World Card Summit Axel Deininger, Giesecke & Devrient’s President and Head of Secure Devices Division, said that the already large number of ‘Card not Present’ transactions offer security solution providers significant opportunities and challenges. But, he added, solutions for data encryption can in many cases be derived from existing portfolios – the key is providing both access and secure end-to-end solutions.