Sign In

Communications of the ACM

Inside risks

EMV: Why Payment Systems Fail


View as: Print Mobile App ACM Digital Library In the Digital Edition Share: Send by email Share on reddit Share on StumbleUpon Share on Hacker News Share on Tweeter Share on Facebook
EMV: Why Payment Systems Fail, illustrative photo

Credit: Shutterstock.com

U.S. credit card companies and banks are beginning to distribute new credit cards with an embedded chip as well as the magnetic strip that has been in use since the 1970s. Named for its promoters Europay, MasterCard, and Visa, the EMV system augments the old magnetic strip cards with a chip that can authenticate a transaction using cryptography—a so-called "smartcard." EMV was deployed in the U.K. from 2003 to 2006 and in other European countries shortly afterward; it is now being rolled out from India to Canada. The idea was to cut fraud drastically, but real-world experiences turned out to be somewhat more difficult than theory. As shown in Figure 1, fraud in the U.K. went up, then down, and is now heading upward again.

The idea behind EMV is simple enough: The card is authenticated by a chip that is much more difficult to forge than the magnetic strip. The cardholder may be identified by a signature as before, or by a PIN; the chip has the ability to verify the PIN locally. Banks in the U.K. decided to use PIN verification wherever possible, so the system there is branded "chip and PIN"; in Singapore, it is "chip and signature" as banks decided to continue using signatures at the point of sale. The U.S. scheme is a mixture, with some banks issuing chip-and-PIN cards and others going down the signature route. We may therefore be about to see a large natural experiment as to whether it is better to authenticate transactions with a signature or a PIN.


 

No entries found

Log in to Read the Full Article

Sign In

Sign in using your ACM Web Account username and password to access premium content if you are an ACM member, Communications subscriber or Digital Library subscriber.

Need Access?

Please select one of the options below for access to premium content and features.

Create a Web Account

If you are already an ACM member, Communications subscriber, or Digital Library subscriber, please set up a web account to access premium content on this site.

Join the ACM

Become a member to take full advantage of ACM's outstanding computing information resources, networking opportunities, and other benefits.
  

Subscribe to Communications of the ACM Magazine

Get full access to 50+ years of CACM content and receive the print version of the magazine monthly.

Purchase the Article

Non-members can purchase this article or a copy of the magazine in which it appears.