22 September 2014

Visa preps encryption service

21 August 2012  |  7796 views  |  5 safelock

Visa is preparing to launch an encryption service designed to help merchants, acquirers and processors protect cardholder data.

The card giant says it will launch its Visa Merchant Data Secure with Point-to-Point Encryption service early next year. The technology encrypts sensitive cardholder information within the merchants' and acquirers' systems. The data can only be accessed, or unscrambled, with decryption keys held securely by the acquirer, gateway or Visa.

Visa says it is already working with acquirers, processors and technology vendors to provide specifications for integrating its offering into payment terminals as well as into all critical systems across the processing industry.

The firm argues that its new service is "complementary" to EMV chip technology, providing an added layer of protection against the threat of data breaches, especially as the industry works to reach critical mass in the adoption of chip cards and terminals.

Darren Parslow, global head, processing, Visa, says: "With Visa's global processing reach and capabilities, we are able to provide an encryption solution that meets the needs of merchants and acquirers who want ease of implementation, flexibility, and effective protection. Working in concert, multiple layers of security including point-to-point encryption can help take merchants out of harm's way while mitigating fraud throughout the payment system."

Comments: (5)

David Griffiths - gryffle - Hertford | 21 August, 2012, 14:01

So ...

if this is "complementary" to EMV, it follows that it must be providing more security than EMV does by itself, and in doing so it is protecting against potential EMV data breach risks.  

What exactly are the EMV data breach risks that end-to-end encryption will mitigate?  Are we being led up the PCI-DSS garden path by the nose once again?  Or am I just being stupid?

Nick Collin - Collin Consulting Ltd - London | 21 August, 2012, 17:45

No, you're not being stupid David, but maybe Visa is :-).

A Finextra member | 21 August, 2012, 18:02

Sounds like Visa is not trusting that their merchants are being PCI-DSS compliant, as one of the requirements is encryption.  So, they are helping out by launching the service.  Encryption is needed and useful. Some retailers at the POS do not encrypt the transaction and they move the data from POS to register to a main computer with wireless technology, then they encrypt it, or not. Many smaller merchants are not usually sophisticated or knowledgeable or have the staff to do this themselves. So, this is a good thing for Visa to offer.  Of course, there is more to compliance that encryption, and while nothing will save us from stupidity or mistakes, this is a step in the right direction.

david marsh - first data - atlanta | 28 August, 2012, 16:17

The extra security being provided is to protect the PAN while it is in transit and defend against threats like skimming. It is a common misconception that EMV will protect the PAN - it does not. The PAN continues to be transmitted in the clear. For a couple of years Visa has been pushing EMV as if it were a silver bullet, but while it will greatly help with lost or stolen and counterfeit card fraud, the risk of stored data breaches will remain. This is a significant admission from Visa that other threats must be considered and defended against with a layered security approach. The next logical step is to mandate both encryption and tokenization, because encryption provides excellent protection of the cardholder data in transit but tokenization is a superior solution for protecting cardholder data at rest or data in use. 

David Griffiths - gryffle - Hertford | 29 August, 2012, 11:01

Looks like the guys at First Data smell a sales opportunity - sell the buggers some encryption and whilst we're at it, bundle in some tokenisation.  Just tell 'em the PAN is at risk, talk about skimming in the sales blurb and there you go, no one will know any better and we'll be quids in!

They certainly don't seem to have grasped EMV.

Comment on this story (membership required)
Log in to receive notifications when someone posts a comment

Finextra news in your inbox

For Finextra's free daily newsletter, breaking news flashes and weekly jobs board, sign up now.

Related blogs

Create a blog about this story (membership required)

Related stories

24 July, 2012
30 April, 2012
30 March, 2012
15 March, 2012
17 January, 2012
12 January, 2012

Related company news

 

Featured job

to $120k base ($250k OTE including commission), be...
Boston, MA (USA)

Find your next job