@InProceedings{ABCLx07, author = { Ben Adida and Mike Bond and Jolyon Clulow and Amerson Lin and Ross Anderson and Ronald L. Rivest }, title = { On the security of the {EMV} secure messaging {API} (Extended Abstract) }, pages = { 147--149 }, OPTurl = { http://dx.doi.org/10.1007/978-3-642-17773-6_17 }, doi = { 10.1007/978-3-642-17773-6_17 }, booktitle = { Proceedings of Security Protocols Workshop 2007 }, date = { 2010 }, editor = { Bruce Christianson and Bruno Crispo and James A. Malcolm and Michael Roe }, publisher = { Springer }, isbn = { 978-3-642-17772-9 }, series = { Lecture Notes in Computer Science }, volume = { 5964 }, OPTyear = { 2007 }, OPTmonth = { April 18--20, }, eventdate = { 2007-04-18/2007-04-20 }, eventtitle = { SPW '07 }, venue = { Brno, Czech Republic }, OPTannote = { Workshop version is only three pages long; ``prepub'' version (11/4/2005) is fourteen. }, abstract = { We present new attacks against the EMV financial transaction security system (known in Europe as ``Chip and PIN''), specifically on the back-end API support for sending secure messages to EMV smartcards. }, }