Visa said on Tuesday that it is rolling out a new service for acquirers and their merchants that will help to better secure payment card data. The service, Visa Merchant Data Secure with Point-to-Point Encryption, will be fully available to customers by early 2013.
For now, Visa is working with a select group of acquirers, processors and payment technology vendors in order to better develop specs and determine the correct needs. Once complete, the new service will be intergraded into critical systems across the payment processing industry.
The service is built on P2PE (Point-to-point encryption), which protects cardholder information and related data in transit and at rest.
“Merchants large and small have expressed an interest in encryption as a way to protect cardholder data in their payment systems and simplify their security protocols,” said Ellen Richey, Chief Enterprise Risk Officer, Visa Inc.
“Since encrypted data can’t be used to commit fraud, Visa’s point-to-point encryption solution can significantly reduce the risk and impact of data compromises.”
Visa says the new service relies on the same Triple Data Encryption Standard (TDES) and Derived Unique Key per Transaction (DUKPT) key management methods that are used to encrypt PINs today. It’s because of this, that they will reach their goal of a consistent framework for managing keys, while minimizing the impact of merchant system updates. In addition, when the service is fully launched, Visa will also offer the option to use FPE (format preserving encryption).
As mentioned, the service is still in trial and undergoing structured testing. Visa expects the service to launch fully in Q1 2013.
Over the coming months, Visa will provide specifications and implementation guides through technical review agreements.
More from Steve Ragan
- Anonymous Claims Attack on IP Surveillance Firm Brickcom, Leaks Customer Data
- Workers Don’t Trust Employers with Personal Data: Survey
- Root SSH Key Compromised in Emergency Alerting Systems
- Morningstar Data Breach Impacted 184,000 Clients
- Microsoft to Patch Seven Flaws in July’s Patch Tuesday
- OpenX Addresses New Security Flaws with Latest Update
- Ubisoft Breached: Users Urged to Change Passwords
- Anonymous Targets Anti-Anonymity B2B Firm Relead.com
Latest News
- Malicious NPM, PyPI Packages Stealing User Information
- VMware Confirms Exploit Code Released for Critical vRealize Logging Vulnerabilities
- 98% of Firms Have a Supply Chain Relationship That Has Been Breached: Analysis
- Dutch, European Hospitals ‘Hit by Pro-Russian Hackers’
- Gem Security Gets $11 Million Seed Investment for Cloud Incident Response Platform
- Ransomware Leads to Nantucket Public Schools Shutdown
- Stop, Collaborate and Listen: Disrupting Cybercrime Networks Requires Private-Public Cooperation and Information Sharing
- Boxx Insurance Raises $14.4 Million in Series B Funding
