• No results found

Understanding the Role of Hardware Data Encryption in EMV and P2PE from the CEO s Perspective

N/A
N/A
Protected

Academic year: 2021

Share "Understanding the Role of Hardware Data Encryption in EMV and P2PE from the CEO s Perspective"

Copied!
18
0
0

Loading.... (view fulltext now)

Full text

(1)

Understanding the Role of

Hardware Data Encryption in

EMV and P2PE from the

CEO’s Perspective

(2)

Futurex. An Innovative Leader in

Encryption Solutions.

• For over 30 years, more than 15,000 customers worldwide • Hardware-based solutions with integrated applications

provide the highest levels of compliance and security

• Entrepreneurial culture, fostering agility and innovation in the development of hardware encryption solutions

• Results-oriented engineering team based in our U.S. Technology Campus, with significant experience

delivering First-to-Market Customer Initiatives

• Members of ANSI X9F and PCI Security Standards Council bodies, CTGA-certified Solutions Architects

(3)

Unique Perspective of Futurex

As a hardware data encryption provider, Futurex has a

unique perspective of security in card transactions.

 Issuers: data preparation, personalization, validation

 Device Manufacturers: Certificate Authority (CA) and key management

 Merchant Service Providers: key management and CA

 Merchants: transaction security and key management

 Acquirers: processing encrypted data in transactions

 Switches: processing encrypted data in transactions

(4)

Why Use Hardware Security Modules?

• Prevents insider attack

– Dual Control

– Split Knowledge

– Tamper Protection for Keys

– Encryption Key Management

• PCI Requirement (aka SCD)

• Certifications (FIPS, PCI HSM)

(5)

PCI Requirements for HSMs

PCI DSS Requirement HSM Coverage (*Summary)

#3.4 Render PAN unreadable… Encryption, decryption, tokenization #3.5 Protect any keys… FIPS 140-2 Level 3 Secure Cryptographic

Devices (SCDs) #3.6 Fully document and

implement…key-management

NIST approved pseudo random number generator (PRNG), use key encrypting keys, and protect all keys under the Master File Key.

#4.1 Use strong cryptography to protect cardholder data

Meet PCI requirements for strong cryptography.

* Full details provided in separate white paper.

“In addition, it is important to note that in EMV

environments the PAN is not kept confidential at

any point in the transaction, indeed, it is necessary

for the PAN to be processed by the point-of-sale

terminal in the clear in order to complete critical

steps in the EMV transaction process. The expiry

date and other cardholder data are also

transmitted in clear-text.”

Ref: PCI DSS Applicability in an EMV Environment – A Guidance Document October 2010

(6)

Attack Vectors in a Card Transaction

1. Card cloning attacks

Transaction Acquirer Payment Card Brand Point-of-Interaction Cardholder Card Issuer

“P2PE technology is complementary to EMV chip

technology, by providing an added layer of protection

against the threat of data breaches...”

Aug 2012 VISA Press Release on PR Newswire.

2. Attacks internal to POI devices

3. Network attacks

4. System level attacks

A. Malware attacks

B. Attacks on applications and databases C. Attacks on backups/storages media

(7)

7

Role of HSM in EMV

 Online Card Validation During Transaction

 Data Preparation and Card Personalization

(8)

Role of HSM in EMV

Online Card Validation During Transaction

1.Authentication request from POI to issuer

Transaction Acquirer Payment Card

Brand

3. Response Cryptogram 1. Request Cryptogram

Card Issuer Point-of-Interaction Cardholder HSM/SCD Host 2 3

2. Issuer validates request

(9)

Role of HSM in EMV

Data Preparation and Card Personalization

Data Preparation

• Key generation for authentication

• Digital signatures for authentication and data integrity

• Standards-based PIN block creation for user authentication

Integrated Circuit Card (ICC) or Smart Card

Issuer Data Personalization Preparation

Personalization

• Key generation for confidentiality, authentication, and data integrity • Protection of sensitive personalization data

(10)

10

Role of HSM in P2PE

 What is Point-to-Point Encryption?

 Protecting Data In Transit: Device Key Management

 Encryption, Decryption, Key Management, Tokens

(11)

What is Point-to-Point Encryption?

Point-to-Point Encryption (P2PE) is encryption of sensitive data at the Point-of-Interaction for secure transmission to a secure

boundary where it may be decrypted, re-encrypted or tokenized.

Host Application

HSM/SCD Point of Interaction

(12)

The Role of HSMs in P2PE

Protecting Data in Transit: Device Key Management

• HSM for compliant key generation

HSM/SCD

Secure Injection Facility

HSM/SCD

Datacenter Remote Device

• Key lifecycle management

• Remote or direct key injection

Generate Distribute Track Usage Backup Revoke Terminate Archive

(13)

Role of HSM in P2PE

Encryption, Decryption, Key Management & Tokens

• Encryption and Decryption

• Key Management

= Encryption/Decryption = Data At Rest

= Data In Transit Switch Host Merchant (POI) Acquirer Host DB HSM/SCD DB = Token

• Tokens

* Case Study available upon request

(14)

14

Role of HSM in EMV and P2PE Environments

 Typical Architecture of HSMs

 Services to Look for in an HSM Provider

 What to Ask for when Selecting HSMs

(15)

Typical Architecture for HSMs

• Remote Access • Centralized Administration • High Availability • Redundant • Compliant • Secured • Customizable Primary Site HSM #1 HSM #2 Secure Management Server Redundant Failover HSM #1 HSM #2 Secure Management Server Secondary Site

Direct Load Balancing

Automatic Synchronization* (All devices designated as Production within group)

Remote Access Device

(16)

Exceptional Support

 TR-39-certified and PCI Subject Matter Experts  24x7x365 Business Critical support

 Exceptional Support Services • Training (virtual or onsite) • Customized consulting • Hosted solutions

• Certificate authority

• Hosted HSMs for development and testing • Customized solution development

(17)

In Summary…

What to ask for when selecting HSMs

• Is the solution comprehensive?

• Is the solution manageable (i.e., will

you be able to pass audits easily)?

• Is the solution scalable?

• Does the vendor’s support team have

expertise in industry compliance

requirements?

(18)

Thank You!

18

Greg Stone

Sr. Solutions Architect

[email protected]

Ryan Smith

Chief Solutions Architect

[email protected]

References

Related documents

IAIK Scenarios A & B Scenario A Encryption key Encrypted data My 1st device Smartphone Encryption key Encrypted data My 1st device Smartphone Encryption key My 2nd device

http://muzquizcoahuila.com/ http://furama-villas.com/ http://jozbdn.com/ http://www.hdwebtv.it/ http://www.denuncio.cl/ http://www.turismoyarte.com/

Stem leaves (7)10–65 × 1–6 mm, stem leaves linear, margin flat and usually revolute, apex long-attenuate, acute, base not broad, decurrent 4–10 mm long; basal leaves 85–90

EMNCs on average perform better than their respective country market indices, a widely used benchmark to measure emerging market returns, S&P500 and, global market

The templates that we are going to use for planning a CLIL unit and a CLIL lesson are the ones published on the website of Conselleria d'Educacio, Servei d'ensenyament

We did a prospective observational study between Jan 23, 2014, and April 13, 2015, in residential care homes for elderly people in southeast England that reported scabies

Using TDE with a key management HSM provides customers with comprehensive data protection; it matches the best practice recommendations of security professionals

The present study will offer a novel behavioural perspective in examining consumer confusion in retail settings. It will demonstrate the way to explore consumer