Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Meeting the challenges of smartcard fare payment
    July 4, 2012
    David Crawford monitors a growing trend in contactless smartcard ticketing The north east United States has become a hive of activity in the smart fare payment arena. In October 2011, the New York Metropolitan Transportation Authority (MTA) published, as a preliminary to an imminent procurement process, the detailed concept of its New Fare Payment System (NFPS). Based on open payment industry standards, this is designed to be implemented on all MTA bus and subway services operated by New York City Transit (
  • 3M sees big potential in ITS sector
    December 16, 2013
    Having re-entered the ITS market, 3M is busy shaping the future technology for vehicle detection, tolling and parking, as Colin Sowman discovers. Having sold off its Opticom business in 2007, 3M effectively re-entered the ITS market last year paying $110 million for Federal Signal Technology Group (FSTech) – but why?
  • Machine vision - cameras for intelligent traffic management
    January 25, 2012
    For some, machine vision is the coming technology. For others, it’s already here. Although it remains a relative newcomer to the ITS sector, its effects look set to be profound and far-reaching. Encapsulating in just a few short words the distinguishing features of complex technologies and their operating concepts can sometimes be difficult. Often, it is the most subtle of nuances which are both the most important and yet also the most easily lost. Happily, in the case of machine vision this isn’t the case:
  • Coded exchanges
    July 24, 2012
    For many, Ethernet- and IP-based networks are the cast-iron solution to ITS's communications needs. However, there remain issues from manufacturer to manufacturer with interpretation of what are supposed to be common standards The 'promise' of Ethernet was that different devices such as IP video cameras and traffic signals could be easily integrated into communications networks, simplifying the process of transporting data over copper, fibre or wirelessly. However, although Ethernet devices have come to pre