Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Lowering the barriers to combined control rooms
    March 29, 2017
    Integrating control rooms can improve traffic management, security and emergency response without excessive cost or compromising privacy. In the wake of the recent terrorist events in France and Germany where the transport system was exploited with deadly consequences, many governments and agencies are reviewing the security arrangements – particularly around popular and high profile events. Increasing security in transport systems that must remain accessible to the general public will not be easy but in ma
  • Widest bridge in the world Port Mann open in Vancouver
    April 25, 2013
    Port Mann Bridge, designed to growing regional congestion and improve the movement of people, goods and transit throughout greater Vancouver, is now open for business. The widest bridge in the world, the Port Mann Bridge located in the metro Vancouver area, in British Columbia, Canada, features an Open Road Tolling (ORT) system, also called All Electronic Tolling (AET), which will ultimately cross all 10 lanes of traffic.
  • Cooperative infrastructure - the future for tolling?
    February 2, 2012
    Leading European tolling solution providers give a snapshot of how they think tolling's technological future will look
  • Delivering accurate vehicle identification
    August 1, 2012
    In the Netherlands, TNO, the independent research organisation, has been engaged in a project on behalf of the RDW, the Dutch vehicle registration and licensing authority, intended to look at the feasibility of using electronic means to make vehicle identification more accurate and less susceptible to fraud. Electronic Vehicle Identification (EVI) has been in existence in various forms for several years now but TNO was tasked with finding out whether OnBoard Unit (OBU)-based applications could be complement