Skip to main content

CARTES considers questions of security

Ensuring the security of payment systems is essential to maintain consumer confidence. The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.
November 4, 2014 Read time: 2 mins

Ensuring the security of payment systems is essential to maintain consumer confidence.

The conference track ‘EMV: Challenges and benefits’, looks at ways of improving that security. When a customer uses his payment card in a store, he expects that the system will be secure. The interaction between EMV payment cards and POS terminals is strictly controlled.

However, despite the existence of many systems that encrypt the PAN moving between the card reader and the processing infrastructure, part of the PAN’s journey is still ‘en clair’ – unencrypted. Over the years, the industry has spent a great deal of time and money on enforcing compliance with PCI DSS across the payment industry. However, data breaches still happen.

Milos Dunjic, CTO, Cardis International, will present a new solution that implements PAN with format preserving encryption (FPE) inside the card’s EMV payment application and is fully under the card issuer’s control. The new system is said to be radically different from previous methods. The solution is said to be fully resistant to replay attacks, as it ensures that the PAN reference is valid for only a single transaction. Since POS terminals, merchant acquirer and payment network systems handle only a unique per transaction format preserving PAN references, this eliminates the danger of criminals stealing real PAN data and then using it in CNP payments. Following on from this presentation, Andreas Strobel, board member with the Smart Payment Association, will give a presentation that analyses the advantages and disadvantages of different implementations, reflecting different business models. He will assess the standardisation efforts for online payment using tokens.


‘End-to-end tokenisation of PAN between EMV-application/digital-wallet and issuer host’, 14:40-15:00, Room 3

‘A Secure Profile for Tokenization in E and M-Commerce’, 16:30-17:00, Room 3

Related Content

  • Littlepay enables Helsinki tap-to-pay
    May 12, 2021
    Littlepay used on selected ferries and trams in Finland's capital and on buses in Tampere
  • Verifone and PayPal point way to retail’s connected future at CARTES
    November 3, 2014
    The emerging mobile shopping trends and technologies of the near future will be on show in the dedicated Connected Commerce Area at this year’s CARTES SECURE CONNEXIONS. Eleven hardware, service and payment solutions pioneers will offer hands-on demonstrations of emerging shopping solutions, says Angelo Caci, ADN’Co deputy director.
  • GMV in tune with contactless Balearics
    October 20, 2020
    Spanish holiday islands' transit solution blends smartcards with EMV system
  • Contactless and NFC set to grow finds CARTES commissioned survey
    October 30, 2013
    As the number of smart phone and tablet users continues to soar, consumer purchasing behaviour will change and consumers will increasingly opt for the convenience of contactless cards and NFC-based payments in the next three to five years. This is one of the findings of a new study into retail payment technology trends, commissioned by CARTES Secure Connexions Event and Payments Cards & Mobile, which also revealed that difference stakeholders have different priorities when it comes to the next generation of