End-to-end encryption: The PCI security holy grail

How do you make it difficult to illicitly move and use your data? The answer is simple: encrypt it.

  • Email to a friend
  • Print this article
  • Bookmark this page
  • RSS feed

One of the fascinating things to do when in New York City is to visit the Federal Reserve gold vault. The vault lies 86 feet below sea level, resting on Manhattan bedrock, and holds approximately 5,000 metric tons of gold bullion. The Federal Reserve Bank does not own the gold but serves as guardian of the precious metal, which it protects at no charge as a gesture of goodwill to other nations.

Obviously, the security measures to protect hundreds of billions of dollars of gold are intense. But even if a thief were to breach the underground defences and avoid the marksmen, how would he get the gold out? Gold is dense, difficult to transport and heavy, with each bar weighing approximately 27 pounds. Combined with the impossible-to-negotiate downtown Manhattan traffic, those facts contribute to the vault being a safe and sound way to protect the gold.

The data stored within your IT infrastructure is also quite valuable. The challenge - how do you make your data like gold, so that it is difficult to illicitly move and use? The answer is, quite simply, encrypt it.

Getting to grips with PCI Security Standard | Visa warns of PCI security deadline | PCI DSS made easy

Data that is effectively encrypted is unusable to the party who recovers it if that party lacks the proper decryption key(s) and means to decrypt. Imagine if your case of of fifty 600-gigabyte backup tapes was lost in transit. If the tapes were encrypted, you would still want to find them. But if they were not encrypted, you need to call the lawyers and immediately initiate your incident plan.

Many of the data breaches of the past few years could have turned into non-incidents if the data had been encrypted. Most recently, web hosting firm Network Solutions warned over half a million cardholders that their transaction data may have been compromised. In a statement, the firm said it found unauthorised code on servers supporting some of its e-commerce merchant's web sites.

They noted that "after conducting an analysis with the assistance of outside experts, we determined that the unauthorized code may have been used to transfer data on certain transactions for approximately 4,343 of our more than 10,000 merchant web sites to servers outside the company." At no point do they indicate that encryption was used.

The PCI DSS and encryption

PCI DSS Requirement 3 details technical guidelines for protecting stored cardholder data and the requirements for encryption. The PCI DSS has perhaps been the biggest boon for encryption since the creation of PGP. Section 3 provides the high-level details around encryption. At a minimum, PCI requires the PAN (primary account number) to be rendered unreadable anywhere it is stored, including portable digital media, backup media and logs.

For merchant data, if it were all encrypted, then PCI DSS compliance would be much easier to accomplish. Note however, that even if an entity would encrypt all of its data, it would still be required to be PCI compliant if involved in the storing, processing, and/or transmission of cardholder information. The PCI Standards Security Council (PCI SSC) has been adamant and clear that the act of encrypting cardholder information does not render those systems and data involved as out-of-scope with respect to PCI compliance.


Contact Us

For editorial queries:
Max Cooter max_cooter@techworld.com

For website issues:
Email webmaster@techworld.com

For commercial queries
Russell Kearney russell_kearney@idg.co.uk


For more contact details click here.

What are your views on this subject? Use the form below to post a comment on this article up to 500 characters.


Characters remaining: 500

Add your commentComments

Gregory | Published: 23:07 GMT, 17 September 2009

This is a timely piece, as the problem of how to manage increasing certificate and key volumes has reached a tipping point as enterprises wage a security battle to protect data. Organizations claim to have deployed less encryption lately—in spite of increasing executive pressure and mandates, high-profile breaches, regulations, and internal security policies. This while the analysts keep chiming in about the need for “holistic” and “centralized” approaches to EKS. What’s a boy to do?

Mark Bower | Published: 00:06 GMT, 15 September 2009

End to End Encryption can be successfully deployed in less than 60 days. We’ve proven this with large US payment processors and Tier 1 Merchants. E2E is not about big bang integration globally - it’s about solving the problem quickly where it needs to be solved - at retailers, processors, payment gateways, legacy systems, enterprise IT and in value added networks. Mark Bower Vice President, Product Management Voltage Security

Jim Andle | Published: 18:00 GMT, 14 September 2009

Really comprehensive article, and essential on the point of encryption's lack of ubiquity, which really needs to change. There's also a misconception about some cutting edge types of encryption, ie extended validation ssl, that consumers aren't educated enough for the implementation to increase safety or e-commerce conversions. But the solution there is to embrace and spread the technology far and wide. If we should take anything from this article it's that more things need to be encrypted.

Related Security news

Adobe sorry for 16-month-old Flash bug

Unpatched vulnerability 'slipped through the cracks'

HTML 5 leaves client storage open to web attacks

Security researcher says web apps could be vulnerable

Rugged Manifesto calls on developers for secure code

Security professionals call for better programming practices

PayPal suspends service in India

eBay payments company blocks personal payments



Email this article to a friend or colleague:


PLEASE NOTE: Your name is used only to let the recipient know who sent the story, and in case of transmission error. Both your name and the recipient's name and address will not be used for any other purpose.

Techworld White Papers

Challenges and opportunities of PCI

The Payment Card Industry Data Security Standard provides an enterprise structure for improving operational, security, and audit performance. The benefits of the PCI DSS go beyond audit costs and results.

Download Whitepaper

Database security: Preventing enterprise data leaks at the source

IDC discusses the growing internal threats to business information, the impact of government regulations on the protection of data, and how enterprises must adopt database security best practices...

Download Whitepaper

Six essential steps to successful IT centralisation

This report, based on the real experience of a recent centralisation project, is aimed at those involved in IT strategy within their organisation. It provides some practical insights for CIOs, CTOs, Heads of IT, IT Directors and those involved more closely with the service management function.

Download Whitepaper

Application Grid: The ideal platform for IT consolidation

Evaluating the opportunity for consolidation of middleware — Java application servers and related technologies.

Download Whitepaper

Techworld UK - Technology - Business

COLT White Paper

Are all VoIP services the same?

Questions to ask your service provider to ensure you get the VoIP service you need
With careful choice of partner, your business can have all the advantages of VoIP access - reduced costs, flexibility and simplicity - without the drawbacks.
This white paper is your guide to ensure you get right the VoIP service and details the pitfalls which businesses would do well to avoid.

Download white paper
COLT White Paper

IT Misuse Survey

Complete this survey and you could win a Nexus One

Techworld are running a short survey to discover how UK businesses are managing Internet and email misuse in the Enterprise.

Complete Survey

Webcast: IT Financial Management: Cost Optimisation for Efficiency and Agility.
On Demand Webcast
Join this webcast to learn about the techniques and technologies that can help you prove the value of IT to the business by understanding the true cost of today's IT services and those that will be necessary to deliver future success.

Register Today

Site Map

IDG Network

* *