Encryption – PCI DSS Requirements

Encryption helps keep our secrets safe offline and online. When you log in to a website or send an email, the browser or the email application uses encryption to protect information being sent out of your system. In simplest terms encryption converts every character in the information to a different character via employing some mathematical formula and converts the information into a non-readable format during transmission. The information can be read or converted back only by a person who knows the original formula. For example, the formula shift every character of the information into third character and replace x, y and z with a, b and c respectively. With this the word “Key” becomes “NHB” and NHB can only be read by a person who knows that each character needs to be moved back by 2 places.
Coming back, the PCI DSS standard mandates encryption for data at rest and data in motion to prevent disclosure of information to unauthorized parties and malicious actors who might be tapping into the communications. PCI Security Standards Council (PCI SSC) mandates strong cryptography to fulfill PCI DSS encryption requirements as per industry-tested algorithms, together with key lengths that offer a minimum of 112 bits of effective key strength along with key management best practices.

PCI SSC considers the following algorithms and standards as acceptable for fulfilling PCI DSS encryption requirements:

1. Advanced Encryption Standard (AES): AES with key lengths of 128, 192, and 256 bits is widely accepted and recommended for encrypting stored cardholder data. Considered the gold standard for symmetric-key encryption, AES offers robust security and is widely used industry wide as a de facto standard.

2. RSA: An acronym based on the names of its inventors – Ron Rivest, Adi Shamir, and Leonard Adleman, is a significant public-key encryption algorithm. It uses a pair of keys: a public key for encryption and a private key for decryption. The security of RSA relies on the difficulty of factoring large numbers. It’s widely used for secure communications, many cybersecurity systems, antivirus products and digital signatures. Common key sizes used in RSA encryption are 2048 bits and 4096 bits. These key lengths are generally considered secure for most applications, providing a high level of protection against brute force attacks.

3. TDES (Triple Data Encryption Algorithm): A symmetric-key encryption algorithm TDES, is a symmetric-key encryption algorithm that provides a higher level of security than its predecessor, DES. DES has 56bits key length but TDES uses three 56-bit DES keys and hence TDES with a key length of 168bits is significantly more resistant to brute force attacks compared to DES. TDES it is being gradually replaced by the more efficient AES algorithm. TDES is commonly used in legacy systems and applications that require a high level of security but cannot be easily upgraded to AES.

4. Transport Layer Security (TLS): TLS uses both symmetric and asymmetric keys and lengths of the keys varies depending on the specific algorithms and implementations used.

Asymmetric keys are used to establish the initial secure connection and exchange session keys. These keys are public and private key pairs, allowing for authentication and secure communication. 2048 bits or 4096 bits are recommended for asymmetric key algorithms like RSA or ECC.

Symmetric keys are used to encrypt and decrypt the actual data being transmitted. 128 bits or 256 bits are commonly used for symmetric key algorithms like AES. These keys are shorter and faster to use compared to asymmetric keys, making them more efficient for large amounts of data.

This combination of symmetric and asymmetric encryption provides a strong and efficient security mechanism for TLS.

5. Elliptic Curve Cryptography (ECC): ECC is a public-key cryptography system that offers similar security to RSA but with smaller key sizes, 192 bits, 256 bits, 384 bits, and 521 bits, making it more efficient for certain applications. ECC is widely used in various cryptographic applications, including digital signatures, key exchange, and encryption. It is particularly suitable for devices with limited computing power, such as smartphones and embedded systems.

6. Diffie-Hellman (D-H) is a key exchange protocol that allows two parties to establish a shared secret key over an insecure channel. D-H enables secure communication by allowing the parties to derive the shared key without exchanging it directly. The derived key can then be used for encryption and decryption of message. D-H uses 2048bits or longer keys and is widely used in various cryptographic protocols, including TLS and SSH, to provide secure communication over networks.

7. Digital Signature Algorithm (DSA) is a public-key cryptographic standard and is widely used digital signature algorithm used to verify the authenticity of a message or document. It uses a public-key cryptography system to generate a digital signature that is mathematically linked to the message. This signature can be verified using the corresponding public key, ensuring that the message has not been altered or tampered with – that is for message authentication, integrity, and non-repudiation. The signer’s private key is used to create the signature, while the corresponding public key is used for verification.

Additionally, PCI DSS emphasizes the importance of robust key management practices to ensure that encryption keys are securely generated, stored, and managed throughout their lifecycle. Without proper key management practices, even the strongest encryption mechanisms would fail.

Understanding Security Standards: A Comprehensive Guide

In today’s ever evolving cyber world, security standards are more critical than ever. They provide a framework for protecting sensitive information and ensuring the integrity of enterprise systems. This article delves into the key security standards you should be aware of and how they can benefit organizations across the world.

What Are Security Standards?

Security standards are established guidelines and specifications designed to ensure the safety and security of information systems. They help organizations protect data, manage risks, and comply with legal and regulatory requirements.

Key Security Standards

1. ISO/IEC 27001: This international standard provides a framework for an Information Security Management System (ISMS). It helps organizations manage the security of assets such as financial information, intellectual property, employee details, and information entrusted by third parties.

2. NIST Cybersecurity Framework: Developed by the National Institute of Standards and Technology, this framework provides a policy framework of computer security guidance for how private sector organizations in the US can assess and improve their ability to prevent, detect, and respond to cyber-attacks.

3. Payment Card Industry Data Security Standard (PCI DSS): The Payment Card Industry Data Security Standard is a set of security standards designed to ensure that all companies that accept, process, store, or transmit credit card information maintain a secure environment.

4. GDPR: The General Data Protection Regulation is a regulation in EU law on data protection and privacy in the European Union and the European Economic Area. It also addresses the transfer of personal data outside the EU and EEA areas.

5. Committee of Sponsoring Organizations of the Treadway Commission (COSO): COSO Framework is a widely recognized framework for designing, implementing, and evaluating internal controls and guidelines for businesses to evaluate internal controls, risk management, and fraud deterrence. While the original aim was to contain the financial frauds, it has since evolved to cover broader aspects of organizational governance and risk management.

6. NERC CIP
North American Electric Reliability Corporation Critical Infrastructure Protection is a framework of 14 ratified and proposed standards that applies to utility companies within the bulk power system. The standards outline recommended controls and policies to monitor, regulate, manage and maintain the security of critical infrastructure systems.

CIP standards include the following:

CIP-004-6 Cyber Security — Personnel and Training.
CIP-008-6 Cyber Security — Incident Reporting and Response Planning.
CIP-013-1 Cyber Security — Supply Chain Risk Management.
CIP-014-1 Physical Security.
Bulk power system owners, operators and users must comply with the NERC CIP framework.

Benefits of Implementing Security Standards

  • Enhanced Security: Implementing security standards helps protect against data breaches and cyber attacks.
  • Compliance: Adhering to standards ensures compliance with legal and regulatory requirements.
  • Customer Trust: Demonstrating a commitment to security can enhance customer trust and confidence.
  • Risk Management: Standards provide a structured approach to identifying and managing risks.