White Paper PCI-Validated Point-to-Point

White Paper
PCI-Validated
Point-to-Point
Encryption On
Microsoft Azure
By Christopher Kronenthal,
Chief Technology Officer
Advanced Commerce Platform
Foreword
2015 will bring incredible change and innovation in the retail industry, especially around how retailers
interact with their customers. Ushered in with next generation Point of Sale (POS) devices, consumers
will encounter a more personalized and protected shopping experience, allowing retailers to be mobile
or stationary at check-out, make more tailored offers to customers in real-time and meet new security
requirements.
Today most U.S. retailers support legacy magnetic stripe credit card technology that is inherently insecure
and prone to fraud and theft. Similarly, much of the technology that handles this magnetic stripe data
does not adequately protect the payment elements and related customer information as it passes through
the retailer’s networks and systems. In an attempt to address this vulnerability, the major credit card
brands are demanding that new payment security standards be adopted as of October, 2015. The new
standards, which are already broadly implemented internationally, are driven by a global consortium
of credit card networks collectively referred to as EMV Co. (Europay, MasterCard, and Visa). Focused
on ensuring consumer identity at the point of purchase, U.S. based credit card issues are replacing
consumers’ old cards with those that have EMV’s secure Chip and consumer-known PIN technology, with
retailers imposed to implement card processing systems that transact with the new technology. Failure to
implement the updated technology will result in increased financial liability for the retailer.
Further, in addition to reacting to upgraded requirements of payment security, successful 2015 retailers
must find innovative ways to connect and engage with their customers. As the advent of integrated
eCommerce and mobility solutions continue to mature, the POS and consumer check-out experience will
prove to be where retailers maximize customer satisfaction and promote sales throughout the store, giving
retailers another way to compete in this modern retail landscape. Security and payment compliance are
the lynchpin of this integrated requirement.
In partnership with FreedomPay and device manufacturers including HP, Panasonic, Ingenico Group and
VeriFone, Microsoft is demonstrating how retailers can create personalized experiences, in real-time,
through smart and secure devices.
by Brendan O’Meara,
Sr. Director WW Retail & Consumer Goods,
Microsoft Corporation
© 2015 FreedomPay, Inc. | www.FreedomPay.com
1
Advanced Commerce Platform
Executive Summary
Merchants are navigating a payments landscape that continues to evolve, as new technologies and
new threats emerge with increasing regularity. Therefore, the Payments Card Industry (PCI) council has
established a set of standards that seek to make payments more secure and easier for merchants to
manage. Specifically, PCI’s Point-to-Point Encryption (P2PE) standard meticulously defines the procedures
that a payment solution provider must adhere to, and in doing so, enables merchants to process payments
securely while keeping their network environment completely out of scope for PCI security audits.
FreedomPay’s P2PE solution, fully audited and validated by PCI, supports traditional and emerging
payment technologies such as EMV, and offers integrations into multiple Point of Sale systems and
payment processors. With the coveted PCI validation, merchants employing the FreedomPay P2PE solution
may reduce their scope for PCI compliance, and can conduct their business with the confidence that no
unencrypted cardholder data flows through their systems.
This white paper will explore the merchant benefits of PCI-Validated P2PE, the process by which
FreedomPay earned validation, and the value-added benefits of the FreedomPay Commerce Platform
hosted on Microsoft Azure.
Why P2PE
Merchants today face an increasing number of challenges related
to payments: ensuring security, maintaining compliance, managing
costs, and keeping pace with an ever-changing payments technology
landscape, to name just a few. Emerging standards, like the 2015 switch
to EMV, and digital wallet products from Apple, Google, PayPal and even
Starbucks have disrupted the payment landscape and sent merchants
scrambling for solutions.
$225,000+
Average cost of a PCI audit
$5MM+
Average cost of a data breach
Source: Ponemon Institute
The stakes are high. For large merchants, a growing threat of cyber crime and malware has placed security
at the top of the priority list. In today’s retail environment, preventing a data breach and keeping customer
data secure is a threat that cannot be ignored. Complicating solving for security, however, is the fact that the
solution marketplace is rife with misinformation, non-validated solutions, and biased opinions based on backdoor revenue shares, and profiting agreements.
By the PCI council declaring and publishing a standard against which to validate solutions, there is now
a technology standard that can completely secure a merchant’s payment infrastructure. With P2PE,
transactions are entirely encrypted before they even enter the merchant’s location, essentially removing
cardholder data from the merchant’s POS and network.
FreedomPay’s P2PE solution, which earned PCI validation in August 2014, offers merchants this unparalleled
payments security and functionality, while also protecting that investment with EMV support, setting the
pace for the entire payments industry. Even better, is that merchants who utilize this solution benefit from a
reduced annual audit report—just 19 controls versus the normal 284.
2
© 2015 FreedomPay, Inc. | www.FreedomPay.com
Buyer Beware
Many vendors in the payments industry are claiming to
offer P2PE, usually bundled with a POS system and/or
payment terminal and/or payment gateway. However,
merchants must be cautious about false claims and
misstatements. Any P2PE solution that does not
adhere to the stated PCI requirements and has not
been listed by the PCI Security Council as validated
P2PE will not take the merchant’s POS and supporting
network infrastructure out of scope of compliance.
It is incumbent on merchants to work with their QSA
on vetting fact from fiction. There are any number
of imposters making claims that simply cannot hold
up to the unambiguous facts as stated by the PCI
Council. Only PCI-Validated P2PE solutions have been
thoroughly audited and evaluated, and can deliver
the merchant benefits of security assurance and true
scope reduction.
PCI P2PE Standards
In 2012 and 2013, the PCI Security Standards Council released the PCI P2PE Standard: a set of controls
that aimed to provide some clarity and definition around point-to-point encryption.
There are three core principles underlying PCI-Validated solutions:
• Hardware to hardware encryption and decryption with a POI (point-of-interaction) device that has
SRED (Secure Reading and Exchange of Data) listed as a function and is enabled.
• Certified to have a validated secure distribution channel. This means that the entire chain of custody
of the POI devices follow strict controls regarding shipping, receiving, tamper-evident packaging
and installation.
• P2PE Instruction Manual (PIM) that guides the merchant on POI device use, storage, return for
repairs and regular PCI reporting.
Any solution provider can claim to offer point-to-point encryption, but not all P2PE solutions are the
same. Only solutions that have been audited and validated to conform to the rigorous scrutiny of the PCI
standards can offer merchants the peace of mind and transparency that customer data is truly secured.
Merchants that implement PCI-Validated P2PE solutions gain another important benefit: a reduction in
the scope of their PCI assessments. Only PCI-Validated P2PE solutions are recognized to have met the
requirements that enable merchants to exclude their POS and network from the scope of their cardholder
data environment.
Maintaining compliance with the PCI Data Security Standard (PCI DSS) is a requirement for all merchants
who accept credit cards, and failure may result in an array of non-compliance penalties. The PCI Data
Security Standard includes requirements and protective measures that are designed to maintain a secure
network, safeguard cardholder data, and ensure the maintenance of information security policies.
© 2015 FreedomPay, Inc. | www.FreedomPay.com
3
Advanced Commerce Platform
As stated on the PCI Security Standards Council’s listing of Validated Point-to-Point Encryption (P2PE)
Solutions, “When correctly implemented, these P2PE solutions may simplify merchants’ PCI compliance
programs by eliminating clear-text cardholder data from their environment and reducing the scope of PCI
DSS requirements.”
The PCI P2PE standard contains detailed security requirements and testing procedures for application
vendors and providers of P2PE solutions to ensure that their solutions can meet the necessary requirements
for the protection of payment card data.
PCI Validation Process
P2PE solutions listed on the PCI Security Standards Council website are compliant with a single,
standardized set of security requirements, security assessment procedures and processes that have been
validated by P2PE assessors. The P2PE standards define a common security assessment framework that is
currently recognized by all participating PCI payment brands.
To earn validation, P2PE solution providers have the responsibility for ensuring that their P2PE solutions
satisfy all requirements of the P2PE standard. As a requirement for the P2PE solution assessment, the P2PE
solution provider must provide the P2PE assessor with all required documentation, software, access to
facilities and access to third-party service providers used in connection with the P2PE solution.
The PCI P2PE standard encompasses close to a thousand individual controls governing encryption and
decryption methodologies, software applications, device management and operations related to distribution
and cryptographic key injection facilities.
To summarize the onerous P2PE Assessment process, solutions must be able to account for:
• Encryption Device Management: Secure cryptographic devices (SCDs) provide tamper-resistance,
detection, and response features to help prevent successful attacks involving penetration, monitoring,
manipulation, modification, or substitution of the devices to recover protected data.
• Application Security: The application does not transmit or store clear-text PAN or SAD outside of the
device, and only uses communications methods included in the scope of the PCI-approved POI device
evaluation.
• Encryption Environment: The solution provider maintains inventory-control and monitoring procedures
to accurately track POI devices in their possession, and provides related instructions to merchants
(P2PE Instruction Manual).
• Decryption Environment Device Management: Documented procedures exist and are demonstrably in
use to ensure the security and integrity of decryption devices placed into service, initialized, deployed,
used, and decommissioned.
• P2PE Cryptographic Key Operations: Key management, cryptographic algorithms and cryptographickey lengths must be consistent with international and/or regional standards. Key components must be
protected at all times during transmission, conveyance, or movement between locations.
As the P2PE solution provider, FreedomPay has initially partnered with Ingenico Group and ScanSource to deliver
all facets of the P2PE solution. Ingenico Group’s best in class hardware and ScanSource’s secure distribution and
key injection capabilities have been fully vetted as part of the PCI P2PE assessment process.
4
© 2015 FreedomPay, Inc. | www.FreedomPay.com
PCI DSS Scope Reduction
EEmploying a PCI-Validated P2PE solution offers
merchants significant reductions in scope for PCI DSS
compliance. Because all clear-text cardholder data
is removed from the merchant’s POS and network
environment, that infrastructure is no longer subject to
the PCI compliance documentation.
The PCI Data Security Standard Self-Assessment
Questionnaire is a validation tool intended to assist
merchants and service providers who are permitted by
the payment brands to self-evaluate their compliance
with PCI DSS. With 284 individual controls to document
and maintain, and all of the associated costs, PCI DSS
compliance requires that merchants make a significant
investment in time and resources each year.
“Official PCI Validation for a P2PE solution
means that merchants can significantly
reduce their scope for PCI DSS validation
and obtain third-party assurance that
no cardholder data passes through their
network environment in an unencrypted
state”
– Matt Getzelman, National PCI Practice
Director, Coalfire Systems, Inc.
For merchants employing a PCI-Validated P2PE solution, there is relief for the documentation required,
as well as the underlying costs of maintaining a compliant environment. SAQ P2PE-HW is a substantially
shorter compliance document, available only to merchants who process cardholder data only via
approved payment terminals as part of a Council-listed P2PE solution.
To be eligible for the SAQ P2PE-HW, merchants must confirm that they:
• Are using a PCI P2PE solution that is listed on the PCI SSC’s List of Validated P2PE Solution.
• Do not store, process, or transmit any cardholder data on any system or electronic media (for
example, on computers, portable disks, or audio recordings) outside of the payment terminal used
as part of the Council-listed P2PE solution.
• Do not store any cardholder data in electronic format. This includes verifying that there
is no legacy storage of cardholder data from other payment devices or systems.
• Have implemented all controls in the P2PE Instruction Manual (PIM) provided by the
P2PE Solution Provider.
With just 19 sections to complete, largely related to the proper maintenance and implementation of the
P2PE payment terminal, the SAQ P2PE-HW removes the core elements of the merchant environment
from scope: the POS, operating system and network. As an additional benefit, penetration tests and
vulnerability scans are no longer required. This enables POS devices and operating systems that would
otherwise fall out of compliance to remain in use because the P2PE payment terminal circumvents that
infrastructure, and no cardholder data flows through legacy systems.
© 2015 FreedomPay, Inc. | www.FreedomPay.com
5
Advanced Commerce Platform
P2PE Payment Terminals
Core to the PCI-Validated P2PE solution is the “Secure Reading and Exchange of Data” (SRED) module,
designed to encrypt data at the Point-of-Interaction. The SRED module applies the security and
cryptographic protection of PIN data to the reading of card data presented by magnetic stripe, EMV,
contactless/NFC, and manual entry.
In order for P2PE to be in the SRED module, the encryption key management and encryption of the
cardholder data must be done in the device’s security processor. This and other P2PE program aspects
must be in firmware, as opposed to being in the application. The firmware is reviewed and certified as
meeting the SRED requirements by a PCI approved laboratory.
FreedomPay’s P2PE solution leverages SRED-enabled payment terminals that offer merchants in any
industry the flexibility to roll out a variety of compliant devices. All of the devices that FreedomPay
provides support traditional magnetic stripe payments, and also alternative and emerging payment
methodologies such as EMV and NFC.
FreedomPay Payment Gateway
The FreedomPay Commerce Platform functions as a secure switch that routes payment data from the
point of sale system to the payment processor—seamlessly with its validated P2PE solution. FreedomPay
is broadly integrated with both POS systems and processors, ensuring merchants the flexibility
and coverage to make changes to their POS platform and/or processing partner at any time. While
already the most connected, lowest cost routing network in North America, FreedomPay is continually
expanding its integration list with the goal of complete industry interconnectivity.
In addition to these, the FreedomPay Commerce Platform can support gift cards, vouchers and stored
value (closed-loop cashless) models that execute a declining balance from a prepaid card.
6
© 2015 FreedomPay, Inc. | www.FreedomPay.com
Incentives Engine
As a value-added platform provider, FreedomPay offers merchants a robust incentive engine that powers
discounts, promotions and loyalty programs. The FreedomPay Commerce Platform evaluates each
purchase in real-time and applies discounts or points based on particular SKUs, time of day, overall
spend, location, product category and more. As an example, a foodservice provider might consider
offering a point for each dollar spent in the café, and triple points for higher margin items or perishable
items. In a business-to-business setting, FreedomPay can also help merchants, manufacturers and banks
deliver financial terms incentives on large corporate purchases.
FreedomPay’s Incentive Manager allows a merchant to configure any number of promotions or loyalty
point programs. Customers can view offers and loyalty point accruals through a web interface and/ or
mobile app, and redeem incentives in real time at the POS. The platform is designed to provide marketers
with the tools to validate their promotional activity at a SKU level, gaining valuable insight into what offers,
discounts and loyalty rewards are most effective, and for which customer segments.
Microsoft Partnership and Global Scalability
The FreedomPay Commerce Platform is the first PCI-Validated P2PE solution for merchants available
on Microsoft Azure. With connected devices at the point of sale and real-time transaction data in the
cloud, Microsoft and FreedomPay are offering retailers a solution to drive more customer interaction and
engagement at the point of sale.
Microsoft and FreedomPay are enabling retailers to create dynamic and personalized offers at checkout
based on real-time transaction information and customer profile data.
Connected devices at the point of sale leverage transaction data from the FreedomPay platform and
intelligence on the Azure cloud to deliver targeted incentives to customers. The platform can deliver
value-added services for the customer at checkout including real-time offers based on basket contents,
user profile data and third-party data services in the cloud.
Conclusion
FreedomPay has reinvented its business according to the strict standard required by PCI for point-topoint encryption. The exacting process of achieving PCI validation for P2PE has resulted in FreedomPay
building an industry-leading platform that delivers merchants immediate benefits around payment
security and scope reduction, as well as ongoing opportunities to innovate and add value.
As the payment landscape shifts to include EMV and NFC transactions, FreedomPay is helping merchants
stay ahead of the game. As North America’s first fully-functional PCI-Validated P2PE platform with EMV
and NFC-ready terminals, FreedomPay is setting the standard for merchants to deliver a customer
experience based on security, functionality and intelligence. It is here, at the intersection of payments and
data that FreedomPay is able to deliver on its promise to merchants: “We make payments smarter, simpler
and more secure.”
© 2015 FreedomPay, Inc. | www.FreedomPay.com
7
Advanced Commerce Platform
About the Author
Christopher R. Kronenthal, Chief Technology Officer and Alliance Executive
Chris Kronenthal is the payment industry’s preeminent security expert, bringing world-class experience to
the software development processes and compliance solutions of FreedomPay. He led FreedomPay’s effort
to build the market’s first PCI-validated, fully-functional point-to-point encryption (P2PE) payment technology
as part of its cloud-based FreedomPay Commerce Platform™.
Leveraging more than a decade of international experience in diverse industries with a strong focus on
compliance and infrastructure enables Chris to advance a security-focused perspective for any company’s
scalable needs.
Chris joined FreedomPay in 2008 and is responsible for the company’s technology solutions, as well as
key alliances with strategic technology partners. Chris manages security compliance; production network
infrastructure; development of new and existing software products; change and quality control initiatives;
and technology partner strategy.
Prior to joining FreedomPay, Chris held various technology management positions at the Coriell Institute for
Medical Research, the world’s oldest and largest bio-repository. There he led the development of Coriell’s
highly specialized and security-driven bio-repository system.
Chris received his Bachelor’s and Master’s of Science degrees in Information Technology at the Rochester
Institute of Technology.
About FreedomPay
The FreedomPay Commerce Platform is the engine inside the world’s expanding and interconnected
ecosystem of commerce. With broad integrations across point-of-sale devices, payment processors and
financial institutions, FreedomPay connects purchase activity with enterprise data in real-time to enable
more successful customer interactions. Validated by the PCI Security Standards council for Point-to-Point
Encryption (P2PE), the FreedomPay Commerce Platform securely processes transaction data for global
leaders in the retail, hospitality, healthcare, education and financial services sectors. With innovative and
expansive technologies built for real-time commerce, FreedomPay positions any organization for the future
of commerce and customer interaction. www.freedompay.com
Contributors
8
© 2015 FreedomPay, Inc. | www.FreedomPay.com
FreedomPay Inc.
Five Radnor Corporate Center
100 Matsonford Road, Suite 100
Radnor, Pennsylvania 19087 USA
Toll Free: 1.888.495.0222
Tel: +1.610.902.9000
Fax: +1.610.902.9001