Welcome!

Cloud Security Authors: Pat Romanski, Zakia Bouachraoui, Elizabeth White, Yeshim Deniz, Liz McMillan

Related Topics: Cloud Security, Mobile IoT, @CloudExpo

Cloud Security: Article

Payment Data Security | @CloudExpo #BigData #DataCenter #Storage #InfoSec

Making PCI requirements common practice is what will help reduce the risk of sensitive payment data breaches

The EMV liability shift that began in October 2015 is likely to reduce card present payment card fraud. That's a double-edged sword for retailers with an online presence and those who accept mobile payments, as fraudsters are seeking easier routes to ill-gotten gain. Add to this the ongoing data breach environment that has become the new normal, and securing payment transactions has never been more significant.

Why can't businesses seem to get security right? It's not a technology problem, to be sure. Solutions that provide increased protection for cardholder data, while maintaining the highest levels of performance - up to millions of transactions per day - were defined and developed after the highly publicized breaches in 2009. The Payment Card Industry (PCI) released solution requirements for point-to-point encryption (P2PE) to assist merchants in protecting cardholder data and reducing the scope of their environment for PCI DSS assessments. However, these approaches still seem to be a concept rather than common practice.

Making PCI requirements common practice is what will help reduce the risk of sensitive payment data breaches - encrypting sensitive data at the point of swipe (or dip in the case of EMV cards) in the payment device and only decrypting it at the processor. Direct attacks on devices in the payment acceptance process have become increasingly common and highly sophisticated, but strongly encrypted cardholder data is useless to cyber criminals. To understand the approaches, and the benefits, of implementing sensitive data protection, let's focus on two key areas: traditional payment acceptance terminals and mobile.

Encryption and HSMs
The real balancing act comes when trying to ensure the highest security and high performance for payment card transactions at the same time. Electronic POS solution providers need to maximize security for payment card transactions without slowing performance. Their solutions need to encrypt cardholder data from the precise moment of acceptance on through to the point of processing, where transactions can be decrypted and sent to the payment networks. By deploying P2PE, intermediate systems that sit between the POI (point of interaction - the point of swipe) device and the point of decryption at the processor are removed from the scope of most PCI-DSS compliance requirements, since the sensitive data passing through them is encrypted.

Encrypting data at the point of swipe device is one thing; encrypting the data in the POS system - more specifically the retail terminal - is another. POI devices go through a PCI certification process, thereby providing high-assurance cryptography and key management functionality. Retail terminals, on the other hand, are typically PC/tablet-based devices that usually only offer software-based encryption and do not have the security controls of PCI-certified devices.

Hardware security modules (HSMs) are an important element of the encryption process. At the point of processing, data decryption takes place using HSMs for secure key management, as required by PCI-P2PE requirements. HSMs perform secure key exchanges and, in most applications, key management that produces a unique key to protect each and every payment transaction. Taking advantage of these security capabilities, solution providers can build high-capacity and redundant secure systems so that multiple servers and multiple HSMs, deployed at multiple data centers, can combine seamlessly to service high transaction volumes with automated load balancing and failover.

An example of a secure system of this kind comes from Verifone, a provider of secure payment acceptance solutions. The company uses a distinctive combination of strong security and risk mitigation against malicious capture of cardholder data, while at the same time ensuring performance and availability for transactions. That's a win-win for retailers. The Verifone VeriShield solution was specifically designed to enable retailers to implement Best Practices for Data Field Encryption, providing security that helps reduce the scope of PCI-DSS audits.

Securing mPOS
Low-cost, anywhere payment acceptance, enabled by the widespread adoption of mobile, has been a real win for smaller merchants. However, with the increasing availability of mobile payment acceptance options, small merchants and mobile businesses need to take a moment to consider the security of their customers' payment data.

Here's how these mobile point-of-sale, or mPOS, systems work: an affordable card reader ("dongle") is connected to a mobile device to accept payments from both EMV and magnetic stripe payment cards. As with traditional POS, it is critical that the card reader encrypt the sensitive payment data it receives.

Securing mPOS solutions can be difficult. Here's how two payment services providers, CreditCall and ROYAL GATE, handled it. They used point-to-point encryption (P2PE) to protect the sensitive payment data from their mobile acceptance offerings. They integrated HSMs with their processing application as a critical component to manage keys and secure customer data following PCI P2PE solution requirements. The use of HSMs enables them to defend against external data extraction threats and to protect against compromise by a malicious insider.

Tokenization and Key Management
One of the various approaches to enabling payments with mobile devices has clear market advantages: Host Card Emulation (HCE). Because the security of the payment data and transaction are not dependent on hardware embedded in the phone, it has much broader applicability; any smartphone could use the HCE approach by loading payment credentials on the device and using it in place of a physical card.

To transact payments with a contactless POS terminal, HCE-based applications leverage the NFC (near field communications) controller that are already on mobile devices. However, since the application cannot rely on secure hardware embedded in the phone for protection of the payment credentials, alternative approaches for protecting sensitive data and transaction security have to be used. These approaches include tokenizing payment credential numbers as well as actively managing and rotating keys used for transaction authorization. This enables issuers to manage the risk introduced by having a less secure mobile device environment for payment credential data.

Using HSMs in the issuer environment is necessary for effective key management and tokenization. They not only create the rotating keys but also to send them securely to the mobile device. In addition, the HSMs are also a critical part of the tokenization and transaction authorization process. The HCE infrastructure does not actually introduce any new security processes or procedures for retailers and processors; it just enables issuers to combine their existing strong security practices-comprising key generation/distribution, data encryption and message authentication-into a cohesive offering to enable payments with mobile devices.

A Multi-Layered Security Strategy
With billions of dollars up for grabs, cyber criminals continue to create increasingly sophisticated attack vectors, including attacks on payment devices themselves. But the reality is that retailers and their acquirers can reduce their risk and fear if the sensitive cardholder data in their possession is nonsense to hackers. This is why P2PE is so critical in the fight to reduce fraud.

Merchants are well served by a multi-layered approach to payment data security. PCI developed and promotes P2PE for a reason; encrypting sensitive data at the point of swipe or dip in the payment device and only decrypting it at the processor protects the data from direct attacks on devices in the acquiring process. Adding HSMs to the mix helps overcome the challenge of securing implementations and ensures secure key management and sensitive operations are performed in secure hardware. Merchants who deploy these best practices will manage risk on their various payment approaches, remain compliant and rest easier knowing that they have made it nearly impossible for criminals to steal or use their customers' payment data.

More Stories By Jose Diaz

Jose Diaz has worked with the Thales group for over 35 years and is currently responsible for payment product strategy at Thales e-Security. He has worked with payment application providers in developing solutions and roadmaps for securing the payments ecosystem. During his tenure at Thales, Jose has worked in Product Development, Systems Design, Sales in Latin America and the Caribbean, as well as Business Development.

Comments (0)

Share your thoughts on this story.

Add your comment
You must be signed in to add a comment. Sign-in | Register

In accordance with our Comment Policy, we encourage comments that are on topic, relevant and to-the-point. We will remove comments that include profanity, personal attacks, racial slurs, threats of violence, or other inappropriate material that violates our Terms and Conditions, and will block users who make repeated violations. We ask all readers to expect diversity of opinion and to treat one another with dignity and respect.


IoT & Smart Cities Stories
In his general session at 19th Cloud Expo, Manish Dixit, VP of Product and Engineering at Dice, discussed how Dice leverages data insights and tools to help both tech professionals and recruiters better understand how skills relate to each other and which skills are in high demand using interactive visualizations and salary indicator tools to maximize earning potential. Manish Dixit is VP of Product and Engineering at Dice. As the leader of the Product, Engineering and Data Sciences team at D...
Bill Schmarzo, Tech Chair of "Big Data | Analytics" of upcoming CloudEXPO | DXWorldEXPO New York (November 12-13, 2018, New York City) today announced the outline and schedule of the track. "The track has been designed in experience/degree order," said Schmarzo. "So, that folks who attend the entire track can leave the conference with some of the skills necessary to get their work done when they get back to their offices. It actually ties back to some work that I'm doing at the University of San...
When talking IoT we often focus on the devices, the sensors, the hardware itself. The new smart appliances, the new smart or self-driving cars (which are amalgamations of many ‘things'). When we are looking at the world of IoT, we should take a step back, look at the big picture. What value are these devices providing. IoT is not about the devices, its about the data consumed and generated. The devices are tools, mechanisms, conduits. This paper discusses the considerations when dealing with the...
Bill Schmarzo, author of "Big Data: Understanding How Data Powers Big Business" and "Big Data MBA: Driving Business Strategies with Data Science," is responsible for setting the strategy and defining the Big Data service offerings and capabilities for EMC Global Services Big Data Practice. As the CTO for the Big Data Practice, he is responsible for working with organizations to help them identify where and how to start their big data journeys. He's written several white papers, is an avid blogge...
Dynatrace is an application performance management software company with products for the information technology departments and digital business owners of medium and large businesses. Building the Future of Monitoring with Artificial Intelligence. Today we can collect lots and lots of performance data. We build beautiful dashboards and even have fancy query languages to access and transform the data. Still performance data is a secret language only a couple of people understand. The more busine...
If a machine can invent, does this mean the end of the patent system as we know it? The patent system, both in the US and Europe, allows companies to protect their inventions and helps foster innovation. However, Artificial Intelligence (AI) could be set to disrupt the patent system as we know it. This talk will examine how AI may change the patent landscape in the years to come. Furthermore, ways in which companies can best protect their AI related inventions will be examined from both a US and...
Enterprises have taken advantage of IoT to achieve important revenue and cost advantages. What is less apparent is how incumbent enterprises operating at scale have, following success with IoT, built analytic, operations management and software development capabilities - ranging from autonomous vehicles to manageable robotics installations. They have embraced these capabilities as if they were Silicon Valley startups.
Chris Matthieu is the President & CEO of Computes, inc. He brings 30 years of experience in development and launches of disruptive technologies to create new market opportunities as well as enhance enterprise product portfolios with emerging technologies. His most recent venture was Octoblu, a cross-protocol Internet of Things (IoT) mesh network platform, acquired by Citrix. Prior to co-founding Octoblu, Chris was founder of Nodester, an open-source Node.JS PaaS which was acquired by AppFog and ...
The deluge of IoT sensor data collected from connected devices and the powerful AI required to make that data actionable are giving rise to a hybrid ecosystem in which cloud, on-prem and edge processes become interweaved. Attendees will learn how emerging composable infrastructure solutions deliver the adaptive architecture needed to manage this new data reality. Machine learning algorithms can better anticipate data storms and automate resources to support surges, including fully scalable GPU-c...
Cloud-enabled transformation has evolved from cost saving measure to business innovation strategy -- one that combines the cloud with cognitive capabilities to drive market disruption. Learn how you can achieve the insight and agility you need to gain a competitive advantage. Industry-acclaimed CTO and cloud expert, Shankar Kalyana presents. Only the most exceptional IBMers are appointed with the rare distinction of IBM Fellow, the highest technical honor in the company. Shankar has also receive...