|
A consortium of industry-leading suppliers in the electronic payments industry
- ACI Worldwide, Diebold Incorporated, Thales e-Security, and VeriFone,
Inc. - today announced the publication of a draft security specification
proposing the first global interoperable method for triple DES (3DES) session
key management. The suppliers also announced their intention to implement
the specification, once finalized, in their products and solutions.
3DES is a state-of-the-art key encryption algorithm that raises the level
of fraud protection for PIN-based debit transactions initiated at automated
teller machines (ATMs) and point-of-sale (POS) terminals. The increasing
sophistication and power of mainstream computing equipment shortens the
useful life of the current single DES key management systems and requires
the industry to proactively address the need for security upgrades.
While standards currently exist for 3DES master key management and 3DES
DUKPT (Derived Unique Key Per Transaction), there is a lack of standards
for session key management. Without standards, each vendor is required
to develop proprietary implementations, placing an added interoperability
burden on the systems that must transport session keys.
The consortium is actively encouraging the financial industry to adopt
a global 3DES standard to increase/enhance interoperability between each
element of an end-to-end payment solution from the host software, to host
security modules, ATMs and POS terminals.
"ACI is proud to have played a role in the creation of this new
specification," said Charles Linberg, CTO of ACI Worldwide. "We
believe that the result of our work will provide the interoperability
and key protection our customers require for their 3DES implementations."
"The ATM industry is currently shifting to 3DES technology, and
we are proud to be at the forefront with this new technology with the
group of vendors," said Ken Justice, vice president of product marketing & management
at Diebold, Incorporated. "Diebold is committed to ensuring our customers
can seamlessly upgrade to this new standard, using the highest quality
products available."
"The resolution of this issue is essential for the continued interoperability
of the worldwide payments networks," said Paul Meadowcroft, head
of transaction security at Thales e-Security. "Thales is fully committed
to the development of an industry wide solution and its implementation
within the Thales transaction security products."
"By sponsoring the introduction of the first global interoperable
specification for triple DES session key management, VeriFone is continuing
its twenty year commitment to the delivery of highly secure and efficient
payment transaction solutions at the point of sale, benefiting customers
and consumers," said Stuart Taylor, vice president of marketing at
VeriFone Inc.
Both Visa and MasterCard are actively encouraging the full implementation
of an end-to-end 3DES compliant solution, from the point of card acceptance
to the issuer host. Considering the longevity of POS systems and the current
push to migrate the entire card-accepting infrastructure to chip-based
payments, the approval of a global 3DES standard is not only timely, it
is an essential component of the end-to-end solution. Until a specification
is available, companies must develop individual proprietary specifications.
Rather than create individual specific implementations, the consortium
companies are creating a global specification that can be adopted to improve
interoperability.
The consortium intends to work with leading card associations, other
vendors and industry standards organizations in the United States and
internationally to finalize and adopt the specification - for a copy and
to submit comments go to http://www.aciworldwide.com/3des/
.
About ACI Worldwide
Every second of every day, consumers are initiating electronic payment
transactions - getting cash at ATMs, using debit and credit cards to
make purchases in stores and on the Internet, banking by phone and PC,
paying bills online. Twenty billion times a year, ACI software is used
to process these transactions, powering the world's online payment systems.
ACI was founded in 1975 and pioneered the development of applications
and networking software for online transaction processing. Today more
than 530 customers in 71 countries use ACI supplied software. Visit
ACI Worldwide on the Internet at http://www.aciworldwide.com
About Diebold
Diebold, Incorporated, is a global leader in providing integrated self-service
delivery systems and services. Diebold employs more than 13,000 associates
with representation in more than 88 countries worldwide with headquarters
in Canton, Ohio, USA. Diebold reported revenue of $1.76 billion in 2001
and is publicly traded on the New York Stock Exchange under the symbol
'DBD.' For more information, visit the company's web site at http://www.diebold.com
.
About Thales in Security
Thales, one of the globe's leading suppliers of integrated security
solutions, addresses the business security needs of corporates and governments
alike, protecting transactions, networks, identification documents and
sensitive sites. Thales' security capability extends to security and
payment technology for financial transactions, networks and e-commerce.
An acknowledged expert in smart card technology and applications, Thales
is a European leader in security critical electronic payments, integrated
Electronic Fund Transfer (EFT), e-purse payment and secured keyboards,
as well as being the UK's leading supplier of electronic card payment
terminals.
About VeriFone, Inc.
VeriFone, Inc., (http://www.verifone.com)
recognized worldwide as the trusted leader in secure electronic payment
technologies, provides
expertise, solutions and services for today with a smart migration strategy for
tomorrow. VeriFone is leading the industry in the delivery of solutions
that add value to the point of sale, resulting in improved merchant
retention and the generation of new sources of revenue for its
partners
and customers. VeriFone solutions are specifically designed to
meet the needs of vertical markets including financial, retail, petroleum,
government and healthcare. VeriFone has shipped over ten million
electronic-payment systems, more than twice the number of its nearest competitor.
Press Contact:
Scott McLean, Hotwire PR +44 (0) 207608 4643
scott.mclean@hotwirepr.com
|