TryTRY
BuyBUY
  • newsletter
  • contact
  • corporate
  • careers
Utimaco
TRYour free HSM simulator
BUYget a quote
  • home
  • solutions
  • products
  • services
  • blog
  • downloads
  • partners
  • company

Utimaco Portal

Here you will find everything you need as a partner and customerLogin required

  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research
  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research

Home / Blogs / EMV for Fleet Cards – Does it make sense for AFD Fuel Cards?

EMV for Fleet Cards – Does it make sense for AFD Fuel Cards?

November 09, 2020

EMV could reshape the future of fleet & fuel cards. This can help managers grow and strengthen their fleets’ overall performance.

A short update about fleet cards

A Fleet card (also referred to as a fuel card, depending on the issuer) is a special type of payment card that is dedicated to vehicle expenses, particularly fuel expenses used in a business context. Fleet cards are given by a company to an employee, usually the driver of a given vehicle operated by the company. Fleet cards can be used to cover various charges: fuel (pay at the pump), repair, maintenance, etc.

What is EMV good for?

Fleet managers are always seeking to improve overall performance and process effectiveness. With regard to fleet cards, this could be done by increasing security or by adding more options.

EMV fleet cards could help to accomplish both.

EMV fleet cards provide:

  • EMV security when applied to the infrastructure of AFD payments transactions;
  • More convenience for cardholder drivers since the chip allows for the hosting of many different applications, e.g. related to IoT applications in vehicles;
  • Compliance with October 2010 EMV deadlines for payments related to the fuel industry  in the United States.

The business potential for the petroleum industry increases with the EMV feature when extending “pay at the pump” transactions with he features of “standard EMV terminals” for processing any EMV bank card.

Understanding the EMV migration in the U.S for the Petroleum Retail Business

EMV, which stands for Europay Mastercard and Visa is a set of norms and standards that have been in use since 1993. These norms provide guidance for chip-based payment cards to reduce fraud and the counterfeiting of cards as done with magnetic strip-based payment cards.

Liability

The EMV standard pushes the responsibility for fraud to merchants and other financial entities involved in payment card transactions. If EMV is not implemented after a given deadline in a given geographical zone, the responsibility for fraud falls on the non-compliant parties.

The service fees for EMV transactions are higher than with a chipless cards, however, the cost of bearing payment card frauds for one’s business may be a far more expensive burden.

Cryptographic features within the secure chips of the fleet cards make it impossible to clone such cards.

Because of the specificity of the petroleum retail businesses, the EMV consortium extended the EMV liability shift in the United States by three years, moving it from October 2017 to October 2020.

Different goals of EMV and PCI

EMV is different from PCI. EMV is maintained by the EMVCo (EMV consortium). PCI standas for the Payment Card Industry. It is a consortium chaired by the PCI Council.

These two bodies consist of approximately identical members.

EMV is more focused on the card itself and the relation between the chip and the terminal.

PCI targets the merchant environment, payment networks and associated databases.

Any merchant that accepts credit, debit or prepaid cards in the United States, including petroleum retail businesses, must ensure PCI-DSS compliance and use PCI compliant devices.

This means that Fleet cards including credit/debit or prepaid card functionality must be used in PCI-DSS compliant infrastructures, independently of the EMV migration.

Fleet cards using EMV technology outside payment networks

Some fleet cards use EMV technology but operate in a proprietary, closed-loop environment. For example, WEX Inc. is offering a more secure chip-based fleet card.

The WEX fleet card meets the payment industry’s EMV standards but processes the transactions inside a closed-loop network. Indeed, WEX handles the entire process of the payment chain and maintains an EMV authority certification and EMV host system.

The chip-based fleet card can embed many options specific to the AFD environment (odometer readings, miles per gallon, driver identification numbers, and other data at the pump).

The EMV deadline for fleet cards in the U.S.

This section describes the migration of Fleet payment cards to the EMV norm.

Fleet cards that are branded by one of the following card companies: Mastercard, Visa, JCB, Discover, or American Express [1] must move to a chip-based EMV system no later than October 2020, in the United States.

There are several characteristics with the petroleum industry that makes EMV implementation and migration harder than it is with banks :

  • The payments mostly take place at Automated Fuel Dispensers (AFDs). Therefore there is a need to replace several specialized parts within the AFDs, hydraulic systems, cables, pump gauges, etc.
  • The payments work by pre-authorization and partial authorization schemes that can vary greatly between gas stations and payment networks.
  • The fleet cards need to collect additional information (odometer, driver ID etc.). This requires specialized equipment, software, and hardware that is not always available.
  • There is a lack of technicians who can install EMV systems in the pumps.
  • Complex channels for trading and reselling

Outlook

We saw how challenging EMV migration for Automatic Fuel Dispenser cards can be.

However, while implicated cost are a disadvantage, the benefits promise to outweigh them by far.

New call-to-action

References and Comments

  • [1] The full list is: Visa, Mastercard, American Express, China Union Pay, JCB, Discover/Diners Club International, NPCI, Verve
Back to overview

Stay on top of our news
Don’t miss out on any Utimaco updates

Subscribe to Utimaco Newsletter

We will keep you posted with news from Utimaco and the industries we protect, as well as information on upcoming events and webinars.

Subscribe now

Partners

Abrantix AG Nexus Technology GmbH Synergy Computers (Pvt.) Ltd. - Utimaco Hardware Security Modules Partner AKEA S.A. - Utimaco Hardware Security Modules Partner Secure Source Distribution (M) Sdn Bhd - Utimaco Hardware Security Modules Partner MALKOM D.Malińska i Wspólnicy s.j. IQuantics Corp Microexpert Limited Utimaco HSM - QuintessenceLabs Real security d.o.o. Cryptomathic A/S cv cryptovision GmbH Cryptomathic GmbH VAR Group SpA - Utimaco Hardware Security Modules Partner Cyber Armor Pte Ltd Komar Consulting Inc. - Utimaco Hardware Security Modules Partner CewTec S.A. Throughwave (Thailand) Co.,Ltd - Utimaco Hardware Security Modules Partner MTG - Utimaco Hardware Security Modules Partner CertiSur S.A. Telegrupp AS ESYSCO Sp. z o.o. PKI Solutions Inc. Skytech Computing Solutions Limited. - Utimaco Hardware Security Modules Partner E-Sign S.A. Thomas-Krenn.AG Compumatica secure networks GmbH Compumatica secure networks B.V. PrimeKey Labs GmbH Fortiedge Pte Ltd. CEGA Security Altacom UAB PETA (Thailand) Co., Ltd. SecureMetric Technology Sdn. Bhd. Envoy Data Corporation - Utimaco Hardware Security Modules Partner Rohde & Schwarz Cybersecurity GmbH Cryptomathic Inc. Cogito Group Pty Ltd Versasec Utimaco HSM - InfoGuard Swiss Cyber Security Encryption Consulting LLC Safesoft Kft. Ascertia - Utimaco Hardware Security Modules Partner Baas Control s.r.o. Perceptus-sp.-z-o.-o. Nexus - Utimaco Hardware Security Modules Partner MIcrosec Nexus - Utimaco Hardware Security Modules Partner Softline Solutions GmbH intarsys AG Astel (UK) Ltd. - Utimaco Hardware Security Modules Partner Fornetix - Utimaco Hardware Security Modules Partner Primekey Solutions AB CREA plus d.o.o. EUROPEAN DYNAMICS SA. Utimaco HSM - PTESA_profesionales en transacciones electronicas Clearkey Consulting - Utimaco Hardware Security Modules Partner Macroseguridad CREAplus Italia S.r.l JJNet International Co., Limited - Utimaco Hardware Security Modules Partner
Find a partner

Share this page

EMEA

Utimaco IS GmbH
Germanusstraße 4
52080 Aachen
Germany
Phone: + 49 241 1696 200

Americas

Utimaco Inc.
900 E Hamilton Ave., Suite 400
Campbell, CA 95008
USA
Phone: +1 844 UTIMACO

APAC

Utimaco IS Pte Limited
80 Raffles Place,
#32-01, UOB Plaza
Singapore 048624
Phone: +65 6622 5347

Utimaco

  • support
  • corporate
  • careers
  • legal
  • terms & conditions
  • privacy
  • cookie-policy
© 2021
to top
  • home
  • solutions
    • industries
      • banking and financial services
        • acquirer
        • card scheme
        • issuer
        • hsm-as-a-service
      • government
        • federal government
      • cloud
        • cloud-based innovation
        • multi-cloud agility
      • connected car (V2V)
      • automotive solutions
      • road infrastructure (V2I), toll collection & ITS
      • industrial IoT & manufacturing
      • energy & utilities
      • lottery & gaming
      • media & entertainment
      • telecommunications
    • applications
      • authentication
      • blockchain
      • code signing
      • database encryption
      • document signing
      • key injection
      • post-quantum crypto agility
      • public key infrastructure (PKI)
        • EJBCA
      • random number generator (RNG)
    • compliance
      • certifications & approvals
        • Common Criteria (CC)
        • FIPS 140-2
      • compliance & standardization
        • FISMA, FedRAMP, and FICAM
        • Certificate Policy of the Smart Metering PKI
        • eIDAS
        • GDPR
        • PCI DSS
        • Privacy Shield
  • products
    • general purpose HSM
      • SecurityServer Se Gen2
      • SecurityServer CSe
      • Block-safe
      • CryptoServer CP5 (eIDAS & CC)
      • CryptoServer Cloud
      • TimestampServer
      • Q-safe
    • payment HSM
      • Atalla AT1000
      • PaymentServer Se Gen2
      • PaymentServer CSe
      • Secure Configuration Assistance (SCA)
      • QuickStart Services
      • u.cloud – Atalla PaymentHSMaaS
      • u.trust 360
    • key management
      • Enterprise Key Management
    • Software Development Kit (SDK)
      • CryptoServer SDK
      • CryptoScript SDK
    • HSM simulators
      • Block-safe HSM simulator
      • CryptoServer CP5 simulator (eIDAS & CC)
      • SecurityServer simulator
      • Q-safe HSM simulator
    • form factor
      • LAN appliance
      • PCIe card
      • cloud, “HSM as a Service”
    • KeyBRIDGE
      • KeyBRIDGE POI
      • KeyBRIDGE RKD
      • KeyBRIDGE eKMS
      • TokenBRIDGE™
    • u.trust Anchor
      • u.trust Anchor CSAR
      • u.trust Anchor High Performance HSM
  • services
    • consultancy
      • PQC consultancy
    • support
    • managed services
      • Key Exchange & Escrow Service (KEES™)
    • professional services
    • Utimaco Academy
  • blog
  • downloads
    • brochures
    • data sheets
    • case studies
    • white papers
    • webinars
    • e-books
      • PQC for Dummies e-book
      • HSM for Dummies e-book
    • Utimaco Portal
      • integration guides
      • knowledge base
  • partners
    • Partner Program
      • technology partner
    • Partner Locator
  • company
    • about Utimaco
      • legal
      • terms & conditions
      • privacy
        • cookie-policy
    • locations
    • news
      • newsletter
    • events
    • contact
    • careers
    • investors
    • utimaco management
    • business ethics
    • memberships and certifications
    • engagement in research