Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Outsourcing security weakness for Sweden’s driver and vehicle data
    October 24, 2017
    The security of driver and vehicle data hit the headlines this summer in Sweden and its authorities are still dealing with the fallout. David Crawford reports. epercussions from Sweden’s vehicle data outsourcing scandal continue to reverberate. Transportstyrelsen, the government’s transport agency, came under fire this summer for risking the personal security of over five million motorists by failing to implement full security checks on personnel in other countries to whom individual work packages could
  • PAX Technology highlights S920 pocket-sized payment terminal
    October 24, 2014
    Secure electronic payment terminal provider PAX Technology will be showing off its popular mPOS terminals and newly- launched S920 pocket-sized payment terminal during CARTES 2014. The products are already proving popular in Brazil with shipments set to reach 300,000 units. “Orders never stop,” comments Gilberto Novaes, sales director at PAX. “Our success brings us around two new big clients per month.” Customers are responding to the embedded technology (contactless, EMV, PCI, SRED) of the D180 and D200 to
  • Free-flow upgrade to Holland's Westerschelde tunnel's toll system
    February 1, 2012
    Unbroken service Technolution's Winifred Roggekamp and Dave Marples describe efforts to upgrade the Westerscheldetunnel's tolling system to give free-flow capability. Until 2003 the Flanders region of Zeeland, in the south-west of the Netherlands, was connected to the mainland only by ferry. The new Westerscheldetunnel, a 6.6km toll tunnel, improves communications with the region considerably, taking some 100km off the alternative road journey. In 2006 it was recognised that the toll plaza for the tunnel ne
  • Infineon: Device authentification increasingly important
    November 20, 2013
    Looking at new opportunities beyond chipcards, Infineon Technologies’ Stephan Hofschen focused on mobile device security, especially with moves to mobile ticketing. Device authentication will be increasingly important. Morpho’s Phillipe d’Andrea added that with cloud storage on the move industry has already secured payments – the next step will be securing smart phones and tablets as well as cards.