First Data Transarmor Verifone Edition Technical Assessment White Paper
Total Page:16
File Type:pdf, Size:1020Kb
First Data TransArmor VeriFone Edition Technical Assessment White Paper Prepared for: March, 2016 Dan Fritsche, CISSP, QSA (P2PE), PA-QSA (P2PE) [email protected] Table of Contents EXECUTIVE SUMMARY ........................................................................................................................................... 3 OVERVIEW .................................................................................................................................................................... 3 SUMMARY FINDINGS....................................................................................................................................................... 6 PCI DSS VALIDATION REDUCTION .......................................................................................................................... 7 CONTROL REDUCTION FOR MERCHANTS ........................................................................................................................... 11 DEPLOYMENT SCENARIOS .............................................................................................................................................. 11 PCI DSS CONTROL REDUCTION SUMMARY ....................................................................................................................... 12 SUMMARY CHART OF MERCHANT PCI DSS CONTROL REDUCTION ........................................................................................ 12 DETAILED PCI DSS CONTROL REDUCTION ......................................................................................................................... 13 TECHNICAL ASSESSMENT ..................................................................................................................................... 13 SCOPE OF ASSESSMENT ................................................................................................................................................. 13 TRANSARMOR VERIFONE EDITION ENCRYPTION ASSESSMENT ............................................................................................... 18 KEY LOADING AND DISTRIBUTION .................................................................................................................................... 19 APPENDIX A: PCI DSS CONTROL REDUCTION RISK MAPPINGS ............................................................................. 25 DETAILED PCI DSS CONTROL REDUCTION ......................................................................................................................... 25 Copyright 2016, Coalfire Systems Inc. Page | 2 Executive Summary Overview First Data engaged Coalfire Systems Inc. (Coalfire), as a respected Payment Card Industry (PCI) Qualified Security Assessor Point to Point Encryption (QSA P2PE) company to provide an update to the First Data TransArmor VeriFone Edition (TAVE) PCI DSS 3.1 whitepaper reflecting the current standards. Coalfire conducted an independent technical assessment of the TransArmor VeriFone Edition (TAVE), secured by RSA security solution in 2013. During that timeframe, Coalfire conducted assessment activities including technical testing, an architectural assessment, industry analysis, a compliance validation and peer review. The Whitepaper with PCI DSS 2.0 standards was released in July 2013. This paper reflects the revised whitepaper addressing First Data TAVE and how it aligns to current PCI-DSS v3.1 standards. In this paper, Coalfire will describe how the TransArmor VeriFone Edition security solution can dramtically reduce the current risk of payment card data compromise within a merchant’s retail environment and can minimize PCI DSS validation when properly deployed. This reduction in validation effort will be based on evaluating the risk of each of the PCI DSS 3.1 requirements and how the TAVE security solution applies to each control within the context of the current PCI P2PE standards released in 2015. The focus of this paper is to clarify how a merchant can benefit from TAVE even though it is not yet a formally listed solution. The conclusions from this paper are provided as guidance to First Data so that they can make a risk based decision for the reduction of a merchant’s scope when properly using TAVE. About TransArmor VeriFone Edition TransArmor VeriFone Edition is a comprehensive, modular and flexible solution designed to provide merchants with strong encryption of payment card data from the point of capture to the point of decryption in First Data’s secure data center. TAVE combines VeriFone’s encryption methodology, VeriFone Total Protect (VTP) and Format Preserving Encryption (FPE), along with First Data’s TransArmor tokenization technology. The goals of the TransArmor VeriFone Edition solution are: 1. Reduce the risk of compromise to cardholder data throughout the entire transaction process, from point of entry through authorization and settlement. 2. Minimize the number of applicable controls that merchants must address for compliance to the Payment Card Industry (PCI) Data Security Standard (DSS). 3. Simplify and reduce costs associated for merchants with validation of PCI DSS compliance efforts. TAVE helps shift the burden of protecting payment card data from the merchant to First Data using the latest encryption and tokenization technologies. This solution: Combines encryption and tokenization to protect cardholder data at every processing stage. Maintains all the merchant’s business benefits of storing the payment cardholder data without the associated risk. Compliments Card Authentication technologies like EMV. Copyright 2016, Coalfire Systems Inc. Page | 3 TAVE includes these high level components: 1. Merchant Point of Interaction (POI) – A VeriFone device encrypting cardholder data in hardware as it is collected. 2. First Data Switch – This includes First Data’s Front End Authorization Platform (FEP) and Secure Transaction Management (STM) handler for routing and processing capabilities. This is hosted by First Data in a PCI DSS compliant facility. 3. First Data Decryption and Tokenization – This includes the Hardware Security Module (HSM), VeriShield Decryption Service (VSD) and TransArmor (TA) for tokenization. This is again hosted by First Data in a PCI DSS compliant facility. This assessment included the above components in PCI compliant testing labs and focused on First Data’s implementation of VeriFone’s VTP encryption methodology, paired with TransArmor tokenization, to provide a secure encryption solution for merchants. Audience This assessment report has three potential audiences. This report is addressed primarily to the first group, merchants, but can be used by others as well. 1. Merchants: This audience is evaluating the First Data TransArmor VeriFone Edition security solution for deployment in their payment card environment. Merchants will be able to clearly understand what benefits they can receive from using TAVE in their environment, including risk and the reduction of applicable controls. 2. QSAs and the Internal Audit Community: This audience may be evaluating the First Data TransArmor VeriFone Edition security solution to determine the impact on PCI DSS validation on behalf of their merchant. 3. First Data and Partners: The final target audience is the product and engineering teams of First Data and its technology partners. The purpose of including this audience is to provide an independent evaluation of their solution and help them identify any areas for improvement. Assessment Scope The scope of our assessment focused on the critical elements that validate the security and effectiveness of the security solution. Coalfire incorporated in-depth analysis of compliance fundamentals that are essential for evaluation by merchants, service providers and the QSA community. In addition, Coalfire reviewed information and feedback obtained from members of the PCI community; however, the opinions and findings within this evaluation are solely those of Coalfire and do not represent any assessment findings, or opinions, from any other parties. Although tokenization is part of the TAVE solution, this assessment focuses solely on how TAVE uses encryption and decryption technologies. The reader should gain an understanding on how TAVE can be leveraged in the context of PCI DSS v3.1 and the current PCI P2PE standards. Tokenization is relevant to Copyright 2016, Coalfire Systems Inc. Page | 4 protecting and reducing PCI DSS validation post-authorization for data at rest. For additional information regarding the value of Tokenization, please review the link below: http://www.firstdata.com/downloads/thought-leadership/Value-of-Tokens-WP.pdf This First Data paper leverages the testing performed for 2013 FD TAVE assessment and provides an update to the 2013 FD TAVE whitepaper to reflect the current PCI DSS 3.1 standards. Methodology Coalfire has implemented industry best practices in our assessment and testing methodologies. Standard validation methods were used throughout the assessment. Coalfire conducted technical lab testing in both the Coalfire Lab located in Louisville, Colorado and the First Data Lab in Omaha Nebraska. This included interviews, documentation review, transaction testing, encryption evaluation and forensic analysis. Merchant PCI DSS Compliance Scope Even the best encryption technologies do not completely eliminate the scope of PCI DSS compliance validation, as some in the industry have claimed. In fact, if a merchant is accepting a payment card, the entirety of PCI DSS always applies