In Sweden banks are combining the EMV payment application(s)
with a separate identity application using PKI.  The reasons are
obvious, one card does it all.

The drawback is that the card holder's identity including social
security numbers etc. is available for any merchant terminal
to read if they want, as the public keys (certificates) are not
protected by PIN codes etc.  If they were protected the card
would be incompatible with existing software and become
harder to use so that is not an option.

I would like to hear if anybody have heard of similar efforts
in other parts of the world.

Anders Rundgren

Reply via email to