Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • The ABC of CARTES 2014: Apple, Bitcoin and cloud security are all on the conference agenda
    October 28, 2014
    CARTES 2014, the global event for payment, identification and mobility, is fast approaching and the world’s experts in the sector are about to head to Paris for its biggest and most important annual gathering. The 2013 event welcomed more than 20,000 visitors, some 1,670 of whom attended the opening conference - the World Card Summit - while also visiting the 450 exhibitors at the venue.
  • Transaxiom shows method to ensure charity funds get to their planned destination
    November 5, 2014
    Anecdotal evidence suggests that only 60% of donations made to developing nations actually reach the people they are supposed to help. But UK company Transaxiom presented at CARTES SECURE CONNEXIONS a method that aims to eliminate this loss. “The moment you hand over the cash, you have no idea what’s happening to it,” says Ram Banerjee, (right) co-founder and director of Transaxiom.
  • Revealed: the SESAMES Awards 2013 winners in full
    November 18, 2013
    Ten companies are celebrating this morning after the winners of the SESAMES Awards were announced at a gala reception in the Automobile Club de Paris (pictured) last night. The purpose of the 11 awards – the Oscars of the secure payments industry – is to recognise and reward the sector’s best innovations every year.
  • ISO standard aids interoperability and data security
    March 30, 2017
    Star Systems International’s Stephen Lockhart, explains how ISO 18000-6C can boost both interoperability and data security in RFID tolling applications. As more states, municipalities and agencies deploy electronic tolling solutions to generate funds and reduce congestion at tollbooths, there have been increased calls for standardisation in the industry.