Skip to content Skip to sidebar Skip to footer

The Chip on a Bank Card Is a Small Computer, and It Has Never Once Told a Machine Its Secret

chip card

The Stripe Was a Cassette Tape

chip card

The brown band on the back of the old cards was magnetic tape, in the same sense that a cassette was magnetic tape, and it worked the same way: tiny regions magnetised in one direction or the other, read by dragging them past a coil.

It held a short string of characters. The card number, the expiry date, the name, and some service codes. That was the whole of it, and the important thing about that list is that it was static. The same data came off the stripe every single time, unchanged, for the life of the card.

Which means a reader could learn everything the card knew, in full, by being swiped once. And since the card proved nothing beyond possessing that string, anything that could reproduce the string was indistinguishable from the card.

That is why the stripe was so vulnerable, and the vulnerability was not a bug or an oversight. A stripe is a storage medium. It has no capacity to do anything, so the only security model available was secrecy of the contents, and the contents had to be revealed to every machine that read it.

Like our content? Follow us for more.

The Chip Does Not Store Your Money, and It Does Not Store a Password Either

chip card

The gold-coloured contact plate is the connection to a small integrated circuit embedded in the plastic. It is a computer: it has a processor, memory that persists without power, and the ability to run a program.

Inside it is a secret key, written in at manufacture, and here is the central point: there is no command that will make the chip output that key. The instruction does not exist. The key is held in a region of memory the chip’s own program can use for calculations but cannot read out, and the chip is physically constructed to make extracting it extremely difficult.

So the chip is not a container holding something valuable that must be kept from thieves. It is a device that possesses something and proves it without disclosing it, which is an altogether different arrangement and a much stronger one.

The practical consequence is the heart of the matter. A machine reading the chip does not receive the secret. It never has, in any transaction, anywhere. There is therefore nothing for a compromised reader to copy, because the thing that would need copying was never transmitted.

It Answers a Different Question Every Time

chip card

The way the chip proves itself is by doing arithmetic that only something holding the key could do.

The terminal sends the chip a challenge: a number, which includes elements that change with every transaction, such as a value that counts upward on the card and a value supplied freshly by the terminal. The chip takes that number, performs a calculation on it using its secret key, and returns the result.

The result is a long number which depends on both the challenge and the key. Anybody can check it, because checking requires only publicly available information. Nobody can produce it without the key.

And because the challenge is different every time, the answer is different every time. A recorded answer is worthless, because the next transaction will ask a different question. This is the single feature that makes the system work: the thing that goes across the connection is a one-time proof rather than a reusable credential.

It is worth dwelling on how complete a reversal this is. The stripe’s security depended on nobody seeing what it sent. The chip’s security does not care who sees what it sends, because what it sends is useless afterwards.

Which Is Why the Card Number Was Never a Secret

chip card

A common and reasonable assumption is that the long number on the front of a card is confidential. It is not, and it was never designed to be.

It is printed on the front in raised characters, it is read aloud over telephones, it appears on receipts and it is stored by every business you have ever bought anything from. A piece of information held by thousands of organisations is not a secret by any useful definition.

What it is, is an address. The first digits identify the issuing scheme and institution, the middle portion identifies the account, and the final digit is a check digit calculated from all the others, which exists purely to catch typing errors. A number mistyped in a single digit, or with two adjacent digits transposed, fails that arithmetic and is rejected before anybody attempts anything with it.

That is a quality control device, not a security one. The number tells a system where to send a request. Authorising the request is a separate problem, and the chip is the answer to it.

Contactless Is the Same Chip With an Aerial

chip card

Tapping a card uses the same integrated circuit, performing the same kind of calculation, with the contacts replaced by a radio link over a very short range.

There is no battery. A loop of wire runs around the inside of the card, forming an aerial, and the reader generates an alternating magnetic field. That field induces a current in the loop, and the current powers the chip for as long as the card is held in the field. The same connection then carries the conversation in both directions.

Which explains two things people notice. The range is tiny, a few centimetres, because the field has to be strong enough to run a computer rather than merely to be detected, and field strength falls away extremely rapidly with distance. And a card works in a reader with no visible contacts because the power and the data are arriving through the plastic.

It also explains why a card held against a phone or another card sometimes fails. Two aerials in the same field interfere with each other, and a reader presented with two cards may decline to proceed rather than guess which one was meant.

And it is why tapping twice does not charge twice. Each transaction is a complete exchange with its own challenge and its own answer, and the terminal will not start a second one until the first has concluded. A card presented again during the same transaction is not a second transaction.

The Four Digits Nobody Can Explain Properly

chip card

The short number on the back exists to solve a problem the chip cannot help with: a transaction where the card is not physically present.

If somebody is typing numbers into a form, there is no chip to challenge and no proof to collect. All that can be done is to ask for something that is printed on the card but, by convention, not stored by the businesses that accept it, so that knowing the long number alone is insufficient.

That is the entire logic of it, and it is a weak form of security by design, because it is still just a secret string being transmitted — exactly the model the chip was introduced to get away from. It persists because it is the best available answer when there is no card to interrogate.

Which is why the whole direction of travel in the field has been to find ways of getting a chip-like proof into situations where there is no chip: a device in your pocket doing the calculation instead, or a number generated once and never reused. The underlying idea is always the same one, and the short printed number is the legacy arrangement it is replacing.

Why It Took So Long

chip card

The mathematics behind this was published long before the cards appeared, and the delay was not conceptual. It was that doing the calculation required a computer, and the computer had to fit inside a piece of plastic 0.76 millimetres thick, cost very little, survive being bent in a back pocket for several years, and run on power supplied by the machine reading it.

Each of those is a hard constraint and together they are brutal. The chip has to tolerate flexing, temperature extremes, washing machines and being used as an ice scraper. It has no power of its own and must complete its work in the fraction of a second a person is prepared to stand still for.

It also had to be deployed into an existing worldwide system of terminals, banks and businesses, every one of which had to be changed, which is why the transition took decades and why cards carried both a chip and a stripe for a long period. The stripe was a fallback for places that had not been converted, and its gradual removal is the last stage of a migration that began long ago.

So the interesting part of the story is not the cryptography, which was understood. It is that somebody got a computer capable of it into a card, for pennies, and persuaded the entire planet to replace its card readers.

What It Does Not Protect Against

For honesty, the limits are worth stating, because a system this well designed in one respect can give a misleading impression of general safety.

The chip proves that the genuine card was present. It does not prove that the person holding it was entitled to. That is what a code typed into a keypad, or a biometric check on a phone, is for, and those are separate mechanisms with separate weaknesses.

The chip also does nothing for a transaction where it is not involved. If a number is typed into a website, no chip took part, and all the protection in the plastic is irrelevant.

And no amount of cleverness in a card addresses the much larger category of problems in which somebody is persuaded to authorise a payment themselves. A perfectly executed transaction with a genuine card and a correct code is indistinguishable, to the system, from a legitimate one.

Which is a reasonable place to finish. The engineering solved a specific and difficult problem completely: proving that a particular object is present without ever revealing what makes it that object. Everything that remains is a different problem, and most of it is not a problem about cards at all.

Like our content? Follow us for more.