A Comprehensive Outline of the Security Behind Apple Pay

Apple has described its new Apple Pay payments service, which is designed to be the first step towards the company's goal of replacing the wallet, as "easy, secure, and private." Apple Pay includes several different features that offer customers much greater security than a traditional credit card, including Device Account Numbers that replace credit card numbers, dynamic security codes for each transaction, and biometric payment verification through the use of Touch ID.

Ahead of the release of Apple Pay, TUAW's Yoni Heisler has taken an in-depth look at the security features built into the payments service, outlining the ways Apple is safeguarding customer information.

While Apple Pay is built on existing NFC technology, Heisler's research suggests it is the first implementation of the EMVCo tokenization specification, a newly introduced security framework designed to cover emerging payment methods. According to former credit card executive Tom Noyes, this specification is "the most secure payments scheme on the planet."

applepaytouchid
As previously rumored, Apple Pay utilizes a "token," which the company refers to as a Device Account Number, to replace a user's existing credit card number on the iPhone. A randomized 16-digit number, the Device Account Number ensures that no merchant is able to obtain a user's credit card number, protecting consumers from retail security breaches, as TUAW points out, because tokens are randomized numbers that cannot be decrypted back into a credit card number.

Device Account Numbers, or tokens, are paired with a dynamically generated one-time use code that replaces the credit card's CCV with every transaction.

Providing an additional layer of security, an Apple Pay-equipped iPhone at the time of each transaction also sends a dynamically generated CVV up the chain along with a cryptogram. The CVV is the three-digit string located on the back of your credit card and, in the case of Apple Pay, is a algorithmically-generated dynamic string that's tied directly to the token. The cryptogram itself "uniquely identifies the device" that created the token and, according to the EMV Payment Spec, is likely composed of encrypted data sourced from the token, the device itself, and transaction data. Note, though, that the precise components of the Apple Pay cryptogram aren't publicly known.

As noted by Heisler, a Device Account Number can't be used in a transaction without an accompanying one-time use cryptogram, which verifies that the "token in transit originated from the device being used." Cryptograms also carry transaction information like the merchant's identity and the amount of money being charged.

The transaction comprising the Device Account Number and accompanying cryptogram is further verified through the use of Touch ID, which essentially replaces insecure verification methods like passwords and PINs.

According to a credit card executive who spoke to TUAW, token transactions as implemented by Apple "are a new and much higher standard of security for electronic payments."

The amount of security built into provisioning tokens and supporting transactions is a new standard that I think will definitely shift fraud patterns going forward.

Apple Pay is expected to go live in October, enabled through an update to iOS 8. Hints of Apple Pay have already been found in the iOS 8.1 beta, which was seeded to developers on Monday. TUAW's full look at the security behind Apple Pay, which covers tokens, Touch ID, and more, is well worth a read.

Related Roundup: Apple Pay

Top Rated Comments

GeneralChang Avatar
119 months ago
A matter of time until someone's finger is hacked off? And, didn't they already hack the touch-ID system?

You mean that convoluted system that required a perfect copy of the persons fingerprint and something like four hours of fabrication? I wouldn't really call that "hacked." By the time they got a dummy fingerprint made up, I'd have realized my phone was missing and locked it via iCloud.
Score: 45 Votes (Like | Disagree)
vpndev Avatar
119 months ago
Gw

And for all the Google Wallet fans out there, tokenization is a key differentiator between Apple Pay and Google Wallet.

So please lay off the comments saying that you've been using this for years. You haven't.

However I don't expect that Google will dawdle with incorporation of tokenization (which is an EMV standard - by no means exclusive to Apple). A decent fingerprint reader might take longer.
Score: 31 Votes (Like | Disagree)
taptic Avatar
119 months ago
Apple: setting the example of security and privacy for Google and the NSA since forever.
Score: 26 Votes (Like | Disagree)
ptb42 Avatar
119 months ago
Let's get this out of the way now...

No, a merchant doesn't have to sign up for :apple:pay. All of this is done on the back-end, by the credit card processing networks and the card-issuing banks.

If a merchant supports contactless card payments (PayWave, ExpressPay, PayPass), they can accept payments from your iPhone 6.

Merchants have to replace their point-of-sale terminals before 10/2015 anyway, if they haven't already done so. If their terminal doesn't accept EMV chip cards, the merchant will assume liability for fraudulent transactions.

The only determining factor is whether a merchant chooses to spend a bit extra money to add the NFC option to their point-of-sale terminal.

I'm tired of all the people complaining about "deficiencies" in :apple:pay, when they clearly don't even know how it is being implemented. Go read the referenced article, if you don't yet get it.
Score: 14 Votes (Like | Disagree)
taptic Avatar
119 months ago
A matter of time until someone's finger is hacked off? And, didn't they already hack the touch-ID system?
The chances of their being a psycho that starts shooting people in public are probably higher than a psyhco chopping peoples fingers off to shop with at CVS.

And no, people replicated someones fingerprint, but they need to have the original and a lot of time and patience. It's not much of a hack really...
Score: 13 Votes (Like | Disagree)
greytmom Avatar
119 months ago
Folks, if you are being held at gun or knife point so that a thief can get your pin or password, you've got bigger issues than the thief going on a shopping spree.
Score: 10 Votes (Like | Disagree)

Popular Stories

M3 Chip Apple Event Slide

First Benchmark Results Surface for M3 Chip in New Macs

Wednesday November 1, 2023 7:53 am PDT by
The first benchmark results for the standard M3 chip surfaced in the Geekbench 6 database today, providing a closer look at the chip's CPU performance improvements. Based on the results so far, the M3 chip has single-core and multi-core scores of around 3,000 and 11,700, respectively. The standard M2 chip has single-core and multi-core scores of around 2,600 and 9,700, respectively, so the...
iOS 17

Apple Preparing to Release iOS 17.1.1 Update for iPhone

Thursday November 2, 2023 1:22 pm PDT by
Apple appears to be internally testing an iOS 17.1.1 update for the iPhone, based on evidence of the software in our website's analytics logs this week. iOS 17.1.1 will almost certainly be focused on bug fixes, but it's unclear exactly which issues the update will address. The update could include the same fix for Wi-Fi connectivity issues that Apple rolled out in the first iOS 17.2 beta,...
m3 pro chip

Apple M3 Pro Chip Has 25% Less Memory Bandwidth Than M1/M2 Pro

Tuesday October 31, 2023 3:11 am PDT by
Apple's latest M3 Pro chip in the new 14-inch and 16-inch MacBook Pro has 25% less memory bandwidth than the M1 Pro and M2 Pro chips used in equivalent models from the two previous generations. Based on the latest 3-nanometer technology and featuring all-new GPU architecture, the M3 series of chips is said to represent the fastest and most power-efficient evolution of Apple silicon thus far. ...
AitTag New Firmware

Apple Releases New Firmware for AirTags

Tuesday October 31, 2023 11:26 am PDT by
Apple today released a new firmware update designed for the AirTag item trackers. The firmware features a build number of 2A61, up from the 2A36 firmware that came out last December. It has been nearly a year since Apple updated the firmware on the AirTags, and there is no word yet on what might be included in the update. Today's firmware release will be rolling out on a staggered basis....
M3 Max Chip

M3 Max Chip Around as Fast as M2 Ultra in Early Benchmark Results

Wednesday November 1, 2023 7:27 pm PDT by
The first benchmark results for Apple's M3 Max chip surfaced in the Geekbench 6 database today, providing a look at CPU performance. Based on the "Mac15,9" model identifier shown, the results appear to be for the new 16-inch MacBook Pro. The highest multi-core score for the M3 Max with a 16-core CPU is currently 21,084 as of writing. If this early result is accurate, this means the M3 Max is ...
10 New Features With iOS 17

iOS 17.2 Coming Later This Year With These 10 New Features for iPhone

Friday November 3, 2023 1:23 pm PDT by
Apple made the first beta of iOS 17.2 available to developers and public beta testers last week, and the software update includes many new features and changes for iPhones. Below, we have highlighted 10 of these new features and changes. iOS 17.2 is expected to be released to the public in December. Once available, the update can be installed in the Settings app under General → Software...
Pro Display XDR Red

Macs With M3 Chip Still Officially Support Only a Single External Display

Thursday November 2, 2023 7:41 am PDT by
Macs equipped with the standard M3 chip still support only one external display with up to 6K resolution at 60Hz, according to Apple's tech specs. So far, the chip is available in the entry-level 14-inch MacBook Pro and the 24-inch iMac. This limitation has existed since the first Apple silicon Macs with the M1 chip were released in 2020, but users can connect multiple external displays to...
apple music voice plan feature blue green

Apple Music's Lower-Priced Voice Plan Being Discontinued

Wednesday November 1, 2023 11:51 am PDT by
The lower-cost Apple Music Voice Plan is being discontinued this month in the U.S. and all other countries where it was available, according to an Apple support document. Brazilian website MacMagazine was first to alert us to this news. "Beginning in November, Apple will discontinue the Apple Music Voice plan," said Apple. "We are focused on delivering the best, most robust music experience...