Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • MaaS must be seamless and invisible - or forget it
    June 5, 2018
    MaaS experts from around the world converged on ITS International’s MaaS Market Atlanta conference to talk about how MaaS can be implemented in the US. Andrew Bardin Williams had a front row seat. Transportation experts from around the world gathered in the US earlier this month to discuss the future of Mobility as a Service (MaaS) and how it could be deployed in the US market. While most attendees at ITS International’s MaaS Market Atlanta conference were familiar with the MaaS concept, the US’s highly
  • Smart Insights: ‘TEE will increasingly displace other security solutions’
    October 28, 2014
    Software- or hardware-only mobile security solutions will increasingly be displaced by TEE (Trusted Execution Environment), according to new research. TEE is essentially a secure area that resides in a mobile device baseband processor and provides security against software attacks.
  • Healthy prospects for floating vehicle data systems
    February 3, 2012
    Elmar Brockfeld, Alexander Sohr and Peter Wagner from the German Aerospace Center's Institute of Transport Systems look at the prospects for floating vehicle data systems. Although Floating Vehicle Data (FVD) or probe vehicle fleets have been around for about a decade, the idea behind them is of course much older: from probe vehicles that flow with the traffic it should be possible to get a precise, fast and spatially near-complete picture of the prevailing traffic flow conditions in an area under surveilla
  • Increasing and improving disabled access to public transport
    January 25, 2012
    An overview of European efforts to increase disabled access to public transport, by David Crawford