Visa preps encryption service

Visa preps encryption service

Visa is preparing to launch an encryption service designed to help merchants, acquirers and processors protect cardholder data.

The card giant says it will launch its Visa Merchant Data Secure with Point-to-Point Encryption service early next year. The technology encrypts sensitive cardholder information within the merchants' and acquirers' systems. The data can only be accessed, or unscrambled, with decryption keys held securely by the acquirer, gateway or Visa.

Visa says it is already working with acquirers, processors and technology vendors to provide specifications for integrating its offering into payment terminals as well as into all critical systems across the processing industry.

The firm argues that its new service is "complementary" to EMV chip technology, providing an added layer of protection against the threat of data breaches, especially as the industry works to reach critical mass in the adoption of chip cards and terminals.

Darren Parslow, global head, processing, Visa, says: "With Visa's global processing reach and capabilities, we are able to provide an encryption solution that meets the needs of merchants and acquirers who want ease of implementation, flexibility, and effective protection. Working in concert, multiple layers of security including point-to-point encryption can help take merchants out of harm's way while mitigating fraud throughout the payment system."

Comments: (5)

A Finextra member
A Finextra member 21 August, 2012, 14:011 like 1 like

So ...

if this is "complementary" to EMV, it follows that it must be providing more security than EMV does by itself, and in doing so it is protecting against potential EMV data breach risks.  

What exactly are the EMV data breach risks that end-to-end encryption will mitigate?  Are we being led up the PCI-DSS garden path by the nose once again?  Or am I just being stupid?

Nick Collin
Nick Collin - Collin Consulting Ltd - London 21 August, 2012, 17:45Be the first to give this comment the thumbs up 0 likes

No, you're not being stupid David, but maybe Visa is :-).

A Finextra member
A Finextra member 21 August, 2012, 18:02Be the first to give this comment the thumbs up 0 likes

Sounds like Visa is not trusting that their merchants are being PCI-DSS compliant, as one of the requirements is encryption.  So, they are helping out by launching the service.  Encryption is needed and useful. Some retailers at the POS do not encrypt the transaction and they move the data from POS to register to a main computer with wireless technology, then they encrypt it, or not. Many smaller merchants are not usually sophisticated or knowledgeable or have the staff to do this themselves. So, this is a good thing for Visa to offer.  Of course, there is more to compliance that encryption, and while nothing will save us from stupidity or mistakes, this is a step in the right direction.

A Finextra member
A Finextra member 28 August, 2012, 16:17Be the first to give this comment the thumbs up 0 likes

The extra security being provided is to protect the PAN while it is in transit and defend against threats like skimming. It is a common misconception that EMV will protect the PAN - it does not. The PAN continues to be transmitted in the clear. For a couple of years Visa has been pushing EMV as if it were a silver bullet, but while it will greatly help with lost or stolen and counterfeit card fraud, the risk of stored data breaches will remain. This is a significant admission from Visa that other threats must be considered and defended against with a layered security approach. The next logical step is to mandate both encryption and tokenization, because encryption provides excellent protection of the cardholder data in transit but tokenization is a superior solution for protecting cardholder data at rest or data in use. 

A Finextra member
A Finextra member 29 August, 2012, 11:01Be the first to give this comment the thumbs up 0 likes

Looks like the guys at First Data smell a sales opportunity - sell the buggers some encryption and whilst we're at it, bundle in some tokenisation.  Just tell 'em the PAN is at risk, talk about skimming in the sales blurb and there you go, no one will know any better and we'll be quids in!

They certainly don't seem to have grasped EMV.