Skip to content
KEDBYTE
How Money Moves
Chapter
18

Contactless

Part II · The Card|8,373 words|about 36 min read|Volume 2
Fast-moving material. Figures, model names, prices and version numbers in this chapter were verified in August 2026. Claims are separated into established fact, active research and marketing claim. Re-check anything you intend to rely on.

18.0 What this chapter gives you#

  1. You will be able to explain where a card with no battery gets its power, and why the honest description is mutual inductance in the near field rather than radio reception.
  2. You will be able to say why a card works at two centimetres and does nothing at fifteen, and why that short range is a power-budget consequence and not a privacy guarantee.
  3. You will be able to describe how a card that cannot transmit still answers, by shorting a load across its own coil and letting the reader read the dips in its own field.
  4. You will be able to name every layer a single tap traverses, from ISO/IEC 14443-2 up through T=CL, ISO/IEC 7816-4 APDUs, the EMV entry point and the kernel books.
  5. You will be able to explain why the tap limit is a lost-and-stolen control with no relationship to the radio, and name the three independent places that enforce it.
  6. You will be able to trace the UK limit from £10 in 2007 to £100 and £300 in 2021 and to the removal of the mandated caps on 19 March 2026, and say what “the limit” now means.
  7. You will be able to separate eavesdropping, which reaches metres and yields a transaction bound to one amount and one counter, from relaying, which creates a new transaction.
  8. You will be able to explain why a Frame Waiting Time of nearly five seconds leaves the protocol no obstacle whatever to a relay.
  9. You will be able to say what the Relay Resistance Protocol measures, why both entropies end up inside the cryptogram, and why it still works less well than the design suggests.
  10. You will be able to explain why a ticket gate cannot ask your bank, what it verifies before it opens, and why your statement shows one number, a day late, matching no fare on any poster.

There is a moment, at the till, when nothing appears to happen. You hold a card near a lit square of plastic, the square beeps, and you walk away. No slot, no keypad, no paper. The whole event is shorter than the sentence describing it.

That moment is the most heavily specified two-thirds of a second in retail. It involves an international standard for radio, a second layer for how bytes are framed on that radio, a third for how smart cards talk at all, a fourth from EMVCo describing which of eight payment kernels should wake up, and a fifth of scheme rules and regulatory technical standards deciding whether you should have been asked for a PIN. Almost all of it is invisible, and almost all of the public understanding of it is wrong in the same three ways.

This chapter is about all five layers, in order, from the magnetic field upward.

The plain version#

Start with the card. It has no battery. Cut one open and you will find a chip the size of a grain of rice and a loop of very thin wire, or a printed spiral of aluminium, running around the inside edge of the plastic. That is the whole machine. Nowhere for a battery to go.

So where does the power come from? The reader.

Think of a guitar. Pluck a string on one guitar, hold a second guitar close by, and the matching string on the second guitar starts to hum on its own. Nobody touched it. The energy came across the air, and the second string was built to be sympathetic to exactly that note.

The reader in the shop is the plucked string. It hums a note — not a sound, but a magnetic note, oscillating 13,560,000 times every second — constantly, all day, into empty air, whether or not anyone is there. The loop of wire in your card is the sympathetic string. Bring it into the hum and a small current begins to flow around the loop. That current is rectified, smoothed and fed to the chip, and the chip wakes up. It has no idea what time it is or how long it slept. It only knows it now has power.

Now the harder half. Once the card is awake, how does it answer?

You might assume it hums back. It cannot: it has barely enough power to run its own arithmetic, let alone to broadcast. So it does something stranger. It interferes with the reader’s own hum.

Imagine standing at a window at night, looking at a lighthouse. You cannot signal back — you have no lamp. But if you could put your hand in front of the lighthouse’s beam, and take it away, and put it back, in a rhythm, then someone standing next to the lighthouse would see its own light flicker. You would be talking using their light.

That is what the card does. It repeatedly shorts and unshorts a load across its own coil. Each time it does, it drags a tiny amount of energy out of the reader’s field, and the reader — which constantly monitors how much energy its own field is costing it — sees a dip. Dip, no dip, dip, dip, no dip. That is the card talking. It is speaking in the reader’s voice.

Why you have to hold it so close#

The hum falls away brutally fast. Not gently, the way sound fades as you walk from a speaker, but savagely: double the distance and you have roughly an eighth of the strength. This is why a card works at two centimetres and does nothing at fifteen. Nobody imposed that rule. It is the shape of the physics.

A worked example: £8.40 for coffee#

You order a flat white and a pastry. £8.40. The barista taps the total into the till and the till pushes the number to the reader, whose little screen lights up. You present your card. Roughly this happens, in this order.

The card enters the field and powers up. The reader has been calling out, in effect, “anyone there?” — repeatedly, several times a second, all day long. Your card answers with a short serial number so the reader can tell it apart from any other card in range. The reader picks it and says “you, then.”

The reader asks for the card’s list of payment applications, and picks the highest-priority one it also supports.

The reader hands over the facts of the sale: eight pounds forty, pounds sterling, United Kingdom, today’s date, and a random number it has just invented and will never use again.

The card does its sum. Using a secret key that has never left the chip and can never be read out of it, it computes an eight-byte answer depending on the amount, the currency, the date, that random number, and a counter inside the card that goes up by one every time the card is used. It hands the answer back with the counter’s current value.

The reader beeps. You leave. The reader sends that answer to your bank, and your bank — which holds the other copy of the secret key — does the identical sum and checks it got the identical answer.

Those eight bytes are the whole security model, and here is the point people miss: they are exactly the eight bytes you would get if you had pushed the card into the slot and typed your PIN. Same chip, same key, same maths. The radio changed nothing about the proof that the card is real.

So why is there a tap limit?#

Because the proof that the card is real is not the same as the proof that you are entitled to use it.

When you type a PIN you are answering a second question. Contactless, below a threshold, skips that question for the sake of speed. So the threshold is not protecting you against anything happening in the air. It protects you against a much older and duller crime: someone taking your card out of your coat pocket and spending it in a newsagent before you notice.

The limit is therefore built as a leaky bucket. Two numbers, not one. In the United Kingdom, from 15 October 2021, the rules said: no single tap above £100, and no more than £300 of taps in total since the last time you actually proved who you were.

Work it through with a thief. They lift your card at 09:00 and buy £95 of gift cards. Running total: £95. Again: £190. Again: £285. On the fourth £95 attempt the running total would reach £380, so the answer comes back: not without a PIN. The thief does not have the PIN. The bucket has emptied, and it will not refill until somebody types four digits or inserts the card into a machine.

Three hundred pounds is the size of the hole the industry decided to leave open. Everything above it meets the same wall as always.

Two thieves and a very long wire#

There is one attack the physics genuinely does invite, and it matters because it is the only one where the radio is the point.

Suppose two thieves. One stands near you on a train platform with a device in a bag; the other stands at a till a mile away. The two devices are connected by a phone call. When the shop’s reader asks its question, the thief in the shop relays it down the line to the thief on the platform, whose device asks your pocket. Your card, which cannot see, answers honestly. The answer goes back down the phone and into the shop reader.

Nobody forged anything. Nobody broke any cryptography. The thieves simply made a very long extension lead between a real reader and a real card. This is a relay attack, and the defences are not about secrecy. They are about time and about the PIN — which is exactly why the tap limit matters more than people think.

Buses and barriers#

Finally, the special case that breaks the whole model: the ticket gate.

A shop’s reader can wait a second or two while the message goes to your bank and back. A ticket gate cannot. Behind you there are forty people walking at three miles an hour, and the gate has a few hundred milliseconds to decide before somebody’s nose meets a barrier. There is no time to ask your bank.

So it does not ask. It takes the card’s cryptographic answer, checks it against a locally held list of cards known to be bad, opens the gate, and files the answer away. Then it does the same at your exit gate, and again tomorrow. At the end of the day a computer adds up everything you did, works out the cheapest legal price for that set of journeys — applying the daily cap, the weekly cap, the off-peak rates — and sends your bank a single request for one total.

This is why the entry on your statement is one number matching no fare on any poster, and why it arrives a day or two late. The gate was never charging you. It was collecting evidence.

Where the plain version stops being true#

The card is not “powered by radio waves”, and the distinction has consequences. The guitar analogy is closer than it sounds: this is resonant magnetic coupling in the near field, not radio reception. At 13.56 MHz a full wavelength is about 22 metres and the boundary between near field and far field sits at roughly 3.5 metres. Everything between card and reader happens deep inside that boundary, where energy is exchanged by mutual inductance between two coils rather than radiated away. That is why the working range is centimetres. But it also means the plain version’s reassurance is wrong in a specific way: the range at which a card can be powered and transacted with is not the range at which it can be overheard. Radiated leakage is a separate phenomenon with a much longer reach, and published work has recovered the reader-to-card channel at several metres. Short range is not a privacy guarantee; it is a power-budget consequence.

The £100 was never a technical fact, and as of 2026 it is not a rule either. Nothing in any radio standard, chip specification or EMV kernel knows what a pound is. The limit lives in three places at once — configured amounts inside the terminal, counters inside the card chip, velocity rules inside the issuer’s authorisation host — and it exists because a regulator wrote it down. The UK’s £100 and £300 came from Article 11 of the onshored Strong Customer Authentication regulatory technical standards. On 19 December 2025 the Financial Conduct Authority announced it was removing those mandated caps, and the change took effect on 19 March 2026, leaving firms free to set their own limits provided they have adequate fraud controls. Most major UK issuers did not immediately move. So the correct statement in 2026 is not “the limit is £100” but “your issuer’s limit is probably still £100, and it is now their choice.”

“Contactless is less secure” and “contactless is exactly as secure” are both wrong. The cryptogram is identical; the interface changes nothing about proving the card is genuine. But the seam is real and it is not where people look. It is in cardholder verification: the data elements that tell a terminal whether verification happened are, in some scheme configurations, not covered by the cryptogram. That is a specific, documented, demonstrated flaw with a paper trail, and it has nothing to do with anyone reading your card through your trousers.

The gate has not taken an IOU. The transit picture implies the barrier trusts you and sorts it out later. It does not trust you. Before that gate opened it verified a digital signature generated by your card’s own private key and obtained a full transaction cryptogram over data it supplied. What is deferred is not the proof but the authorisation, the question of whether your bank will honour it. Those are different things, they fail differently, and the transit operator carries the gap between them as a real financial risk with a name.

The technical version#

The radio: ISO/IEC 14443#

The physical and link layers of every contactless payment card in the world are defined by ISO/IEC 14443, a four-part standard originally titled Identification cards — Contactless integrated circuit cards — Proximity cards and retitled in later editions to Cards and security devices for personal identification — Contactless proximity objects. Part 1 covers physical characteristics; Part 2, radio frequency power and signal interface; Part 3, initialization and anticollision; Part 4, transmission protocol.

The standard’s vocabulary matters, because EMV documents use it throughout. The reader is a PCD, a Proximity Coupling Device. The card is a PICC, a Proximity Integrated Circuit Card. Neither term says anything about payments; the same standard carries transport tickets, passports and door badges.

Part 2 sets the numbers everything else hangs from.

Parameter Value
Carrier frequency, fc 13,56 MHz ± 7 kHz
Minimum operating field, Hmin (Class 1) 1,5 A/m rms
Maximum operating field, Hmax (Class 1) 7,5 A/m rms
Subcarrier frequency, fs fc/16, approximately 847 kHz
Initialisation bit rate fc/128, approximately 106 kbit/s
Higher bit rates fc/64 ≈ 212, fc/32 ≈ 424, fc/16 ≈ 848 kbit/s
Elementary time unit 1 etu = 128 / (D × fc); 9,44 µs at D = 1

The field-strength window is the most under-appreciated engineering constraint in the system. A card must work at 1,5 A/m and survive 7,5 A/m: five to one in field terms and considerably more in delivered power. The chip therefore carries a shunt regulator whose job at close range is to throw energy away as heat and whose job at long range is to run a public-key operation on almost nothing. Later editions of Part 2 define six PICC classes with different antenna sizes and correspondingly different windows, from Class 1 at 1,5 to 7,5 A/m up to Class 6 at 4,5 to 18 A/m.

The two signalling variants are not compatible and both are mandatory for payment readers.

Type A. Reader to card: amplitude shift keying at 100 % modulation depth — the field is switched fully off in short pauses — with modified Miller coding. Card to reader: on-off keying of the 847 kHz subcarrier, Manchester coded. The 100 % pauses mean the card loses power entirely during each pause and must ride through on a reservoir capacitor.

Type B. Reader to card: amplitude shift keying at roughly 10 %, with the modulation index specified as between 8 % and 14 %, NRZ-L coded. The field never drops out, so the card’s supply is steadier. Card to reader: BPSK modulation of the same subcarrier.

In both directions the card’s reply is load modulation. The card switches an impedance across its coil; the reader observes the reflected change in its own antenna’s load, appearing as sidebands at fc ± fs. The card never generates a carrier of its own. This matters enormously to relay attacks and their defeat: the card’s timing is not free-running but locked to the reader’s carrier, because that carrier is also the card’s clock.

Above Part 2 sits Part 3. For Type A, the reader continuously issues REQA (or WUPA for halted cards), a card in the field responds with ATQA, and a bitwise anticollision loop over the UID resolves any collision, cascading through up to three levels for 4-, 7- or 10-byte UIDs; the reader then issues SELECT and receives SAK. Type B uses REQB/WUPB, ATQB and ATTRIB with a slot-marker scheme instead. Both terminate at the same place: one selected card, everything else told to be quiet. Two cards in a wallet do not “confuse” the reader in the way folklore suggests; they cause a collision the standard resolves deterministically, ending in a clean read or a “present one card only” prompt.

Part 4 defines the half-duplex block transmission protocol, universally called T=CL. The reader sends RATS (Request for Answer To Select); the card returns ATS, which declares its capabilities. Two of those set the shape of everything above.

The first is frame size. FSDI and FSCI index a fixed table: 16, 24, 32, 40, 48, 64, 96, 128 and 256 bytes. Anything longer must be chained.

The second is the Frame Waiting Time:

FWT = (256 × 16 / fc) × 2^FWI

with FWI in the range 0 to 14 and a maximum FWT of approximately 4 949 ms. If the card needs longer than the FWT it has declared, it sends S(WTX) with a Waiting Time eXtension Multiplier in the range 1 to 59, and the reader grants a temporarily extended FWT, capped at FWTMAX.

That maximum figure — nearly five seconds — should be held in mind. It is the reason the protocol, as designed, offers no obstacle whatever to a relay.

On top of T=CL, the card speaks ISO/IEC 7816-4 command and response APDUs, exactly as it would over the contacts. From the payment application’s point of view the radio is a transport. On top of that sits EMV.

EMVCo layers its own requirements over ISO/IEC 14443 in the EMV Level 1 Specifications for Payment Systems, EMV Contactless Interface Specification, which reached Version 3.1 in December 2020. Specification Bulletin 245, announced by EMVCo on 2 June 2021, required all compliant contactless terminals to decode IQ modulation — to demodulate the in-phase and quadrature components of the card’s load modulation rather than amplitude alone. The stated motivations were reliability, positioning tolerance and transit gate throughput, which tells you where the pressure comes from.

Power harvesting, in detail#

The card’s antenna is a planar coil, typically a small number of turns of etched or wire-embedded conductor running around the perimeter of an ID-1 card body of 85,60 mm × 53,98 mm. It forms a resonant tank with a capacitance that is partly on-chip and partly distributed, tuned so that the loaded resonance sits at or slightly above 13,56 MHz.

Inside the chip, four things happen in parallel from the moment the field arrives. A rectifier converts the induced AC into DC and charges a reservoir. A shunt regulator clamps the supply and dissipates surplus energy — the closer the card, the more it must waste. A clock extractor derives the system clock by dividing the 13,56 MHz carrier, which is why the card has no independent notion of elapsed time. A power-on-reset circuit holds the logic in reset until the supply is stable.

The consequences shape the payment protocol above. There is no clock across power cycles, so the card cannot enforce “no more than one transaction per minute” by itself. There is no battery-backed counter, so any anti-replay counter must live in non-volatile memory and survive the field being pulled away mid-write, which is why torn-transaction recovery is a named feature of contactless kernels. And there is a hard energy budget for asymmetric cryptography: an RSA or ECC operation at 1,5 A/m is genuinely difficult, which is why contactless offline data authentication was optimised into a fast variant rather than reusing the contact flow unchanged.

The EMV layer: entry point and kernels#

A contactless terminal begins not by selecting an application directly but by selecting the Proximity Payment System Environment, whose file name is the ASCII string 2PAY.SYS.DDF01 — the contactless counterpart of 1PAY.SYS.DDF01. The response is a directory of the card’s applications, each with an ADF Name (tag 4F) and priority.

The terminal matches those against its own configured list, and the match determines which kernel processes the transaction. EMVCo publishes the architecture in EMV Contactless Specifications for Payment Systems: Book A for architecture and general requirements, Book B for the entry point, Books C-1 through C-8 for the individual kernels, and Book D for the contactless communication protocol.

Book Kernel Scheme
C-2 Kernel 2 Mastercard
C-3 Kernel 3 Visa
C-4 Kernel 4 American Express
C-5 Kernel 5 JCB
C-6 Kernel 6 Discover
C-7 Kernel 7 UnionPay
C-8 Kernel 8 EMVCo (scheme-neutral)

Book C-1 defines Kernel 1, built on the EMV common core definitions; the scheme mapping quoted for it in secondary sources is inconsistent and is omitted here rather than guessed. Book C-8, Kernel 8 Specification, Version 1.0, was published on 5 October 2022 to reduce the number of kernels the industry maintains; it specifies elliptic curve cryptography, a secure channel, biometric verification and optional on-card data storage.

The practical significance of the split is that “the contactless limit” is not one setting. It is a different named data object in each kernel. In Kernel 2 the terminal-side amounts are carried in proprietary tags in the DF81xx range:

Tag Kernel 2 data object
DF8123 Reader Contactless Floor Limit
DF8124 Reader Contactless Transaction Limit (No On-device CVM)
DF8125 Reader Contactless Transaction Limit (On-device CVM)
DF8126 Reader CVM Required Limit
DF811B Kernel Configuration

Their meanings, in the vocabulary the US Payments Forum uses: above the contactless floor limit the transaction must be authorised online by the issuer; above the CVM required limit cardholder verification must be performed using the full capability of the terminal; above the contactless transaction limit the transaction cannot use the contactless interface at all and the customer is directed to insert or swipe. That last limit is split according to whether on-device cardholder verification is available, which is the mechanism by which a phone can pay £400 where a plastic card cannot.

Kernel 3 does the equivalent work with two well-known tags. The Terminal Transaction Qualifiers, tag 9F66, four bytes, is sent to the card in the PDOL and states what the terminal can and will do. The Card Transaction Qualifiers, tag 9F6C, two bytes, comes back and states what verification the card believes should happen. Tag 9F6E, four bytes, carries the Form Factor Indicator, which is how an issuer learns whether it was a card, a phone or a watch.

The transaction data itself is the same set of objects used on the contact interface: Application Interchange Profile (82), Application File Locator (94), Amount Authorised (9F02), Transaction Currency Code (5F2A), Terminal Country Code (9F1A), Unpredictable Number (9F37), Application Transaction Counter (9F36), Application Cryptogram (9F26), Cryptogram Information Data (9F27), Issuer Application Data (9F10) and CVM Results (9F34). Offline data authentication is normally fDDA (fast DDA) or CDA (Combined Data Authentication), both producing a dynamic signature under the card’s own private key rather than the static signature of SDA. That distinction is essential in transit.

In the authorisation message the interface is signalled by POS entry mode: in common scheme usage, 05 for contact chip, 07 for contactless chip, 91 for the legacy contactless magnetic-stripe mode. Issuers risk-score off that field, which is why an issuer can decline contactless while approving contact for the same card.

Why the tap limit exists, and what it actually protects#

The limit is a lost-and-stolen control. It is not a countermeasure against skimming, eavesdropping or cloning, and it has no relationship to the radio.

Its legal basis in Europe and, by onshoring, in the United Kingdom is Article 11 of Commission Delegated Regulation (EU) 2018/389, the SCA-RTS. The Article permits a payment service provider not to apply strong customer authentication for a contactless transaction at the point of sale provided the individual amount does not exceed EUR 50, and either the cumulative amount since the last application of strong customer authentication does not exceed EUR 150, or the number of consecutive such transactions since then does not exceed five.

The UK version raised the figures without changing the shape:

Date Single transaction Cumulative
2007 £10
2010 £15
2012 £20
2015 £30
1 April 2020 £45 set under SCA-RTS Article 11
15 October 2021 £100 £300, or five consecutive transactions
19 March 2026 set by the firm set by the firm

The 2020 increase was accelerated as part of the industry’s response to Covid-19; the 2021 figures then held for four and a half years. On 14 March 2025 the FCA published an engagement paper on contactless limits, with responses due by 9 May 2025; on 19 December 2025 it announced that it would remove the prescribed limits and allow firms with strong fraud controls to set their own, encouraging them to let customers set personal limits or switch contactless off entirely; the change took effect on 19 March 2026. As of mid-2026 the major UK issuers had publicly retained £100. Consumer protection was explicitly unchanged: unauthorised transactions on a lost or stolen card must still be reimbursed.

Enforcement happens at three independent points, and a practitioner needs to know which one is refusing. The terminal refuses using the kernel data objects above: over the CVM required limit it demands verification, over the transaction limit it refuses the interface entirely, producing “please insert your card” with no network round trip. The card refuses using issuer-personalised counters that force a contact transaction once the number or cumulative amount of contactless transactions passes a threshold; this implements the £300 bucket at chip level, and is why the bucket resets when you insert the card and type a PIN. The issuer host refuses using velocity rules against its own record of the card, and is the only one of the three that sees transactions at other merchants in real time.

The fraud numbers put the control in proportion. UK Finance reported contactless fraud losses of £41,5 million in 2023, a 19 % increase on 2022, against total unauthorised fraud of £708,7 million — about 5,9 %. Its Annual Fraud Report of 15 June 2026, covering 2025, reported total fraud losses of £1,28 billion, of which contactless fraud was £46,8 million, up 8 %; lost and stolen card fraud £109,8 million, down 2 %; and remote purchase fraud — card-not-present, which no tap limit touches — £423,5 million, up 3 %. The tap limit governs a category roughly one ninth the size of the one it cannot govern at all.

Relay attacks#

The design flaw, if it is one, is implicit in the standard: ISO/IEC 14443 has no concept of distance, only of field strength sufficient to operate, which the attacker supplies himself. Nothing in the protocol binds the card’s physical location to anything.

A relay therefore requires no cryptanalysis. The attacker builds two devices — a fake card presented to a genuine reader, a fake reader presented to a genuine card — and forwards APDUs between them over any channel with adequate bandwidth. Gerhard Hancke demonstrated a practical relay against ISO 14443 proximity cards in 2005; Saar Drimer and Steven Murdoch published the case for distance bounding against smartcard relays in 2007; relays using unmodified NFC handsets followed. The problem was solved in principle much earlier, by Brands and Chaum’s distance-bounding protocol in 1993 and Hancke and Kuhn’s practical variant in 2005, both timing single bits at the physical layer and deriving an upper bound on distance from the speed of light.

Two things are frequently conflated. Eavesdropping is passive interception of an existing transaction, and it reaches much further than the operating range because it depends on radiated leakage rather than coupling. Hancke’s experiments at RFIDsec’08, using a wide-range receiver and a commercial antenna kit, recovered the reader-to-card (forward) channel of ISO 14443 Type A at 5 m in an entrance hall and 4 m in a corridor, and the card-to-reader (backward) channel at 1 m; for Type B, the forward channel at 3 m and the backward channel at up to 4 m. Eavesdropping yields the transaction as it happened, not a reusable credential, because the cryptogram is bound to that amount, that unpredictable number and that ATC. Relaying is active and creates a new transaction. It is the dangerous one.

The Relay Resistance Protocol#

The industry’s answer is a timing bound. Mastercard’s Relay Resistance Protocol has been in EMV Book C-2 since 2016, in that book’s sections 3.10, 5.3 and 6.6. The same protocol is specified in publicly available form in the European Card Payment Association’s CPACE Terminal Kernel Specification v1.0 of 12 July 2018, from which the following field-level detail is taken.

The terminal issues an EXCHANGE RELAY RESISTANCE DATA command immediately after application selection:

Field Value
CLA 80
INS EA
P1 00
P2 00
Lc 04
Data Terminal Relay Resistance Entropy, 4 bytes, binary
Le 00

The card returns four data elements: Device Relay Resistance Entropy (4 bytes, binary), Min Time For Processing Relay Resistance APDU (2 bytes), Max Time For Processing Relay Resistance APDU (2 bytes) and Device Estimated Transmission Time For Relay Resistance R-APDU (2 bytes). All three timing values are expressed in units of hundreds of microseconds.

The terminal starts a timer when it sends the command, stops it when the response arrives, and subtracts its own known transmission overheads to isolate the card’s contribution:

Measured Relay Resistance Time = Timer − Terminal Transmission Time For Relay Resistance Command − Expected Minimum Transmission Time For Relay Resistance Response

floored at zero, where the expected minimum is the lesser of the card’s declared estimate and the terminal’s own configured response transmission time. The CPACE defaults for the terminal’s transmission times are 0012 and 0018 in hundreds of microseconds: 1,8 ms for the command, 2,4 ms for the response.

Three checks then run. If the measured time is below the card’s declared minimum by more than the configured tolerance, the transaction fails outright — a card that answers too fast is as suspicious as one that answers too slowly, because it suggests a pre-computed answer. If the measured time exceeds the declared maximum plus tolerance, a Terminal Verification Results bit is set and the protocol may be retried, the relay resistance counter permitting a maximum of two attempts. And if the card’s estimated transmission time and the terminal’s own differ by more than a configured percentage, or the measured time exceeds the declared minimum by more than a configured difference limit, further TVR bits are set for the issuer to act on.

The terminal-side configuration lives in Kernel 2 proprietary tags:

Tag Kernel 2 data object
DF8132 Minimum Relay Resistance Grace Period
DF8133 Maximum Relay Resistance Grace Period
DF8134 Terminal Expected Transmission Time For Relay Resistance C-APDU
DF8135 Terminal Expected Transmission Time For Relay Resistance R-APDU
DF8136 Relay Resistance Accuracy Threshold
DF8137 Relay Resistance Transmission Time Mismatch Threshold

Crucially, both entropies are subsequently included in the data over which the Application Cryptogram is computed. A relay cannot pre-compute the exchange, and cannot substitute its own timing values, because the values it saw are bound into the cryptogram the issuer will verify.

How well it works#

Honestly: less well than the design suggests, because the measurement is taken at the wrong layer.

Researchers at the Universities of Birmingham and Surrey, working under the NCSC-funded TimeTrust project, measured the RRP exchange on a test card and found a mean round-trip of about 53 000 µs on the first exchange with a standard deviation near 13 170 µs, and about 40 100 µs on subsequent exchanges. Against a card-declared maximum of 79,62 ms they relayed successfully in 67,79 to 77,05 ms. The jitter inherent in an application-layer measurement forces the acceptance window so wide that a competent relay fits inside it. Their conclusion was that distance bounding is more reliable at Level 1, at the ISO/IEC 14443-A layer where timing is locked to the carrier, than at Level 3 where it is at the mercy of APDU processing; they proposed a Level 1 relay protection protocol, L1RP, and verified it formally in Tamarin.

The same group showed why relay protection matters beyond plastic: a non-standard sequence of bytes preceding the standard ISO 14443-A wake-up command would convince Apple Pay that it was speaking to a transport reader, unlocking the Express Transit path. Combined with a Visa credential and a relay, they published video of £1 000 taken from a locked iPhone. Mastercard on Apple Pay and Visa on Samsung Pay were not affected.

The defences that remain, in descending order of effectiveness: the CVM required limit, because a relay attacker still cannot produce the PIN; issuer velocity rules, because a relay is a physically slow crime; the card’s own offline counters; and RRP, which raises the bar without closing the door.

Why contactless is not less secure than chip and PIN in the way people assume#

The popular model is that chip and PIN has two locks and contactless has one. The accurate model is that both have exactly the same lock on the card; the difference is entirely in the cardholder lock and in offline authorisation policy.

The Application Cryptogram at tag 9F26 is a MAC computed over the transaction data, the AIP and the ATC using a session key derived from the card’s issuer master key. It is the same computation on both interfaces, and it is bound to one amount, one currency, one unpredictable number and one value of a counter that never repeats. It cannot be replayed for a different amount, at a different terminal, or twice.

So the “digital pickpocket” scenario — a criminal walking through a crowd with a reader in a bag — fails structurally. What can be read without interaction is limited, and what would be needed to monetise it is absent: no CVV2, no pair usable for card-not-present, no cryptogram usable for anything but the single transaction it was generated for. To take money the criminal must run a transaction against a real acquirer, which means being a merchant, which means being findable.

The real weaknesses, when they have appeared, have been in the layer that decides whether verification happened, and they are worth stating precisely because they are the seam.

In 2014, Emms, Arief, Freitas, Hannon and van Moorsel of Newcastle University presented at ACM CCS an attack showing that Visa contactless cards would approve foreign-currency transactions for any amount up to €999 999,99 without the cardholder’s PIN. The UK limit then in force was £20. The flaw was not in the radio or the cryptogram: the limit check was performed against the terminal’s own currency and no check existed for others.

In 2021, Basin, Sasse and Toro-Pozo of ETH Zurich presented “The EMV Standard: Break, Fix, Verify” at IEEE Security and Privacy, describing a PIN bypass on Visa contactless. The Card Transaction Qualifiers, tag 9F6C, tells the terminal what verification the card expects, and in the affected configurations it is neither authenticated nor cryptographically protected against modification. A man-in-the-middle clears bit 8 of the first byte, removing the online-PIN requirement, and sets bit 8 of the second byte, asserting that on-device cardholder verification was performed; in their published log 8200 became 0280. The terminal then believes the cardholder has already been verified. They demonstrated it with an Android proof of concept in a real shop for approximately $190. Mastercard was not vulnerable to the same manipulation, because there the equivalent capability is signalled in the second bit of the first byte of the Application Interchange Profile, and the AIP is covered by the cryptogram.

The lesson generalises. Any data element that steers cardholder verification but is not covered by the Application Cryptogram is a candidate vulnerability, whatever the interface. Contactless made the attack cheaper to mount, but it did not create the seam. The seam was in the data model.

Transit and aggregated fares#

Transit breaks the standard model for one reason: latency. The US Payments Forum’s technical solution for transit contactless open payments states the requirement as a go/no-go customer entry prompt within a sub-second window, typically no more than 500 milliseconds from a valid tap. No online authorisation meets that budget reliably, at every gate, at 08:15.

So the gate runs the transaction offline and pushes everything else downstream. The architecture has four named components.

Offline data authentication at the terminal. The gate performs dynamic ODA — fDDA or CDA — using the card’s public key certificate chain, verified against the scheme CA public key held in the reader. This defeats counterfeit cards, skimming and man-in-the-middle at the gate itself, with no issuer connection. It is also where the energy budget bites: the card must complete an asymmetric operation inside the tap.

A deny list. Every gate holds a locally cached list of blocked cards and checks the credential against it before opening. The forum’s framing is that the ability to hot-list a card quickly, so it is declined at every point of entry, is critical to preventing recurring fraud.

Deferred authorisation. Formally, a request that occurs when a merchant captures transaction information while connectivity is interrupted and holds it until connectivity is restored. Transit uses the mechanism deliberately rather than by accident.

Aggregation. Multiple taps combined into a single authorisation for a single amount. This is what makes fare capping possible: the back office cannot know that today’s fifth journey has hit the daily cap until the fifth journey exists, so it cannot price any journey at the moment of travel.

The financial consequence has a name: first tap risk, the exposure created when a deferred authorisation is eventually declined for insufficient funds after the passenger has travelled. Second tap risk is the follow-on, the same card used again before it reaches the deny list. Neither sits with the issuer or the passenger; both sit with the operator, which is why transit operators are unusually exercised about deny-list latency.

Two data-level points a practitioner must get right. The Amount Authorised in tag 9F02 as sent by the gate will not equal the amount finally cleared, because the cleared amount is the aggregate. And an issuer must validate the cryptogram using only the data carried in the authorisation message’s ICC data field — in ISO 8583 terms, Field 55 — and must not cross-check it against other fields whose values legitimately differ under aggregation. Issuers that get this wrong produce mysterious declines that appear only on transit.

Regulation accommodates this explicitly. Article 12 of the SCA-RTS exempts from strong customer authentication any electronic payment transaction initiated by the payer at an unattended payment terminal for the purpose of paying a transport fare or a parking fee. Without it, the cumulative counter in Article 11 would demand a PIN from every commuter twice a week, at a gate with no keypad.

London is the reference implementation. Contactless bank cards were accepted on London buses from 13 December 2012, with 2 586 journeys on the first day, and on the Tube and rail network from 16 September 2014. By December 2022 buses alone carried about 1,7 million contactless journeys a day, with more than 2,5 billion journeys across all modes since launch and credentials from over 180 countries presented at the gates.

For the passenger the visible artefacts follow directly. Charges appear grouped rather than per journey, and a day or more late, because aggregation runs after the travel day closes. The same card or device must be used to touch in and out, because the back office identifies a journey by matching two taps from the same credential — a card and the phone holding that card are, to the fare engine, two travellers. An incomplete journey draws a maximum fare because the back office cannot infer where you went. Caps are applied by the back office, never by the gate. And a device that runs flat mid-journey costs its owner a maximum fare, which is why Express Transit modes with a power reserve exist, and why those modes are where the interesting attacks live.

The sequence, end to end#

The layers a single tap traverses, and the specification governing each:

Step Governed by
Reader field present, card powers up ISO/IEC 14443-2; EMV Contactless Interface Specification (Level 1)
Polling, REQA/WUPA or REQB/WUPB, anticollision, SELECT ISO/IEC 14443-3
RATS/ATS, frame size and FWT negotiation, T=CL ISO/IEC 14443-4
APDU command and response structure ISO/IEC 7816-4
SELECT 2PAY.SYS.DDF01, candidate list, kernel activation EMV Contactless Book B (Entry Point)
EXCHANGE RELAY RESISTANCE DATA, where supported EMV Contactless Book C-2
GET PROCESSING OPTIONS with PDOL, READ RECORD, fDDA/CDA EMV Contactless Books C-1 to C-8
GENERATE AC, cryptogram returned EMV Contactless Books C-1 to C-8
Authorisation request carrying the cryptogram ISO 8583 or ISO 20022, per scheme

The last four rows are identical to the contact interface. Everything above them is radio. The money never notices the difference.

18.98 Common wrong ideas#

Wrong: the card is powered by radio waves it picks out of the air. Right: at 13,56 MHz the exchange happens deep inside the near field, where energy passes by mutual inductance between two coils rather than being radiated, which is why the range is centimetres.

Wrong: the short operating range means nobody can listen in. Right: the range at which a card can be powered and transacted with is not the range at which it can be overheard, and published work has recovered the reader-to-card channel at several metres.

Wrong: the £100 limit is a technical property of the chip, the radio or the kernel. Right: nothing in any radio standard or EMV kernel knows what a pound is; the figure came from Article 11 of the SCA-RTS and since 19 March 2026 it is the firm’s own choice.

Wrong: contactless is less secure than chip and PIN because it has one lock instead of two. Right: the Application Cryptogram is the identical computation on both interfaces; the whole difference is in cardholder verification and offline authorisation policy.

Wrong: contactless is exactly as secure, so there is no seam. Right: the seam is real and documented — data elements that steer whether verification happened, in some configurations not covered by the cryptogram, which is precisely the 2021 Visa PIN bypass.

Wrong: a criminal walking through a crowd with a reader in a bag can harvest usable card details. Right: there is no CVV2, nothing usable card-not-present, and a cryptogram bound to one amount, one unpredictable number and one counter value; to monetise anything the criminal must be a real, findable merchant.

Wrong: two cards in a wallet confuse the reader. Right: they cause a collision that Part 3’s anticollision loop resolves deterministically, ending either in a clean read or a “present one card only” prompt.

Wrong: the ticket gate lets you through on trust and settles up afterwards. Right: before it opened it verified a dynamic signature from the card’s own private key and obtained a full cryptogram; what is deferred is the authorisation, and the gap is first tap risk carried by the operator.

Wrong: the transit charge on your statement is a fare. Right: it is an aggregate computed after the travel day closes, which is why the Amount Authorised sent by the gate never equals the amount finally cleared.

Wrong: the Relay Resistance Protocol closes the relay problem. Right: measured at the APDU layer the jitter forces an acceptance window wide enough for a competent relay, which is why the same researchers argued for timing at the ISO/IEC 14443-A layer instead.

18.99 Chapter summary in 20 lines#

  1. A contactless card has no battery: a chip the size of a grain of rice and a loop of wire around the inside of the plastic is the whole machine.
  2. The reader hums a magnetic note at 13,56 MHz all day, and the card’s coil draws its power out of that field by mutual inductance.
  3. The card cannot transmit, so it answers by repeatedly shorting a load across its own coil and letting the reader see the dips in its own field.
  4. Field strength falls away savagely with distance, so the working range is centimetres — a consequence of the power budget rather than a privacy feature.
  5. ISO/IEC 14443 defines the whole radio layer: Part 2 the field and modulation, Part 3 anticollision, Part 4 the block protocol universally called T=CL.
  6. Above T=CL the card speaks ordinary ISO/IEC 7816-4 APDUs, so from the payment application’s point of view the radio is only a transport.
  7. EMVCo layers its own Level 1 requirements over that, and above them sit Book B’s entry point and the eight contactless kernel books.
  8. Which kernel wakes up determines what the limits are called and where they live, which is why “the contactless limit” is never one setting.
  9. The Application Cryptogram is the same computation on both interfaces, bound to one amount, one currency, one unpredictable number and one value of a counter that never repeats.
  10. So the radio changes nothing about proving the card is genuine, and the tap limit exists to answer an entirely different question.
  11. That limit is a lost-and-stolen control built as a leaky bucket: a single-transaction cap plus a cumulative cap since the last strong authentication.
  12. It is enforced at three independent points — reader data objects, counters inside the card application, and issuer velocity rules — and knowing which one refused is the practitioner’s first question.
  13. Its legal basis was Article 11 of the SCA-RTS; the UK figures climbed from £10 in 2007 to £100 and £300 in 2021, and the FCA removed the mandated caps on 19 March 2026.
  14. The fraud figures keep it in proportion: contactless losses are a small fraction of remote purchase fraud, which no tap limit touches at all.
  15. Eavesdropping is passive, reaches further than the operating range, and yields a transaction that cannot be replayed; relaying is active and creates a new one.
  16. Nothing in ISO/IEC 14443 binds a card to a place, and a maximum Frame Waiting Time of nearly five seconds leaves ample room for a very long extension lead.
  17. The industry’s answer is the Relay Resistance Protocol: a timed exchange whose entropies are afterwards bound into the cryptogram, so the timing cannot be forged.
  18. It helps less than it looks, because application-layer jitter widens the acceptance window enough for a competent relay to fit inside it.
  19. Transit breaks the model on latency alone: the gate performs offline dynamic data authentication, checks a local deny list, opens, and defers both the authorisation and the price.
  20. Aggregation is what makes fare capping possible and what puts first tap risk on the operator, and it is why your statement shows a single number, a day late, matching no fare on any poster.

Sources: ISO/IEC 14443 parts 2, 3 and 4; EMVCo Level 1 EMV Contactless Interface Specification v3.1 and Specification Bulletin 245; EMVCo Book C-8 v1.0; European Card Payment Association CPACE Terminal Kernel Specification v1.0; Commission Delegated Regulation (EU) 2018/389 Articles 11 and 12; FCA contactless limits engagement paper (2025) and press releases (2025); UK Finance contactless limit FAQs and Annual Fraud Report 2026; US Payments Forum papers on contactless limits (2020) and transit contactless open payments (2018); Transport for London press material; and the published research of Hancke (2005, 2008), Emms et al. (CCS 2014), Chothia et al. (FC 2015), Basin, Sasse and Toro-Pozo (IEEE S&P 2021), and Radu, Chothia, Newton, Boureanu and Chen on practical EMV relay protection.