verishield total protect - verifone global - secure...

2
STORE POS MERCHANT HEADQUARTERS DECRYPTION SERVICES ACQUIRER AND/OR PROCESSOR VERISHIELD TOTAL PROTECT TRUSTED LINK 435688 760033 1088 = 1512101 2884426940234 435688 198101 1088 = 5912922 2108900331272 BIN Routing PAN Last 4 Encrypted Data Encrypted Data with format & routing preserved Encrypted Data Discretionary Data Resident on Card Standard Track Data BACK OFFICE SERVER COMPANY NETWORK SERVER COMPANY NETWORK SERVER CONFIDENCE FROM BEGINNING TO END VERISHIELD TOTAL PROTECT With data breaches costing retailers millions of dollars in ruined reputations, depressed sales and extensive damage control, transaction security has never been more critical. VeriFone’s VeriShield Total Protect, secured by RSA, provides industry-leading encryption plus tokenization to secure cardholder data from swipe or tap to the processor – with complete confidence that unencrypted data will never be exposed to potential thieves. Versatile And Flexible • Works with the widest range of payment technologies – mag-stripe, NFC, contactless and EMV smart card • Compatible with the broadest range of payment, portable and mobile devices • Supports card-present, card-not-present, e-commerce or MOTO transactions • Integrates easily with retail systems and applications with little or no disruption and with minimal impact on POS systems Minimizes Retailer Risk • Encrypts cardholder data from the precise moment of acceptance to processing • Protects retailers’ brands and reputations by removing at-risk, unencrypted data from all retail POS systems, networks and servers • Uses proven, random-number tokenization, allowing retailers to store substituted tokens, rather than actual card data, for safer analytics, chargeback processing, loss prevention and more • Strengthens EMV chip and PIN and NFC mobile security by protecting sensitive data when it is vulnerable, both at rest and in transit Reduces PCI DSS Scope • Has been certified by an independent Qualified Security Assessor to help reduce PCI DSS controls and the expense of audits • Meets all 14 criteria of Visa Best Practices for Data Field Encryption • Allows for continuous, centralized monitoring of transaction health and encryption on a device-by-device basis using VeriFone’s VeriShield Monitoring and Compliance Console (VMC)

Upload: dinhtruc

Post on 29-Jun-2018

221 views

Category:

Documents


0 download

TRANSCRIPT

STORE POSMERCHANT

HEADQUARTERS

DECRYPTIONSERVICES

ACQUIRER AND/OR PROCESSOR

VERISHIELD TOTAL PROTECT TRUSTED LINK

435688 760033 1088 = 1512101 2884426940234

435688 198101 1088 = 5912922 2108900331272

BINRouting PAN Last 4

Encrypted DataEncrypted Data with format & routing preserved Encrypted Data

Discretionary DataResident on Card

StandardTrack Data

BACK OFFICE SERVER

COMPANY NETWORK SERVERCOMPANY NETWORK SERVER

CONFIDENCE FROM BEGINNING TO ENDVERISHIELD TOTAL PROTECT

With data breaches costing retailers millions of dollars in ruined reputations, depressed sales and extensive damage control, transaction security has never been more critical. VeriFone’s VeriShield Total Protect, secured by RSA, provides industry-leading encryption plus tokenization to secure cardholder data from swipe or tap to the processor – with complete confidence that unencrypted data will never be exposed to potential thieves.

Versatile And Flexible • Works with the widest range of payment

technologies – mag-stripe, NFC, contactless and EMV smart card

• Compatible with the broadest range of payment, portable and mobile devices

• Supports card-present, card-not-present, e-commerce or MOTO transactions

• Integrates easily with retail systems and applications with little or no disruption and with minimal impact on POS systems

Minimizes Retailer Risk • Encrypts cardholder data from the precise

moment of acceptance to processing

• Protects retailers’ brands and reputations by removing at-risk, unencrypted data from all retail POS systems, networks and servers

• Uses proven, random-number tokenization, allowing retailers to store substituted tokens, rather than actual card data, for safer analytics, chargeback processing, loss prevention and more

• Strengthens EMV chip and PIN and NFC mobile security by protecting sensitive data when it is vulnerable, both at rest and in transit

Reduces PCI DSS Scope • Has been certified by an independent

Qualified Security Assessor to help reduce PCI DSS controls and the expense of audits

• Meets all 14 criteria of Visa Best Practices for Data Field Encryption

• Allows for continuous, centralized monitoring of transaction health and encryption on a device-by-device basis using VeriFone’s VeriShield Monitoring and Compliance Console (VMC)

Eases Retailer Worries • Safeguards raw cardholder data received by payment devices from end to end • Eliminates sensitive cardholder data from the entire retail POS environment • Decreases the effort and expense of PCI DSS compliance by significantly reducing

applicable PCI DSS controls• Provides multiple layers of security, resulting in welcome peace of mind for retailers

due to greatly reduced risks• Available as a managed service on VeriFone’s managed gateway and through most

U.S. processors• From VeriFone, the leader in payment security worldwide for more than 30 years

For more information, please visit www.verifone.com/vtp

Encryption Plus Tokenization and More• Combines Secure Reading & Exchange of Data (SRED)-certified encryption with tokenization to offer the gold

standard in security for retailers • Format- and message-preserving encryption encrypts the primary account number and discretionary data in a way

that other applications interpret as valid card data –minimizing changes required to existing systems or applications• Card-based tokenization, secured by RSA, lets retailers efficiently handle post-authorization tasks such as returned

items, statements and required analytics – with minimal risk• RSA Public Key Infrastructure (PKI) relies on digital certificates as well as public and private cryptographic keys to

secure information exchange• All encryption is processed within tamper-resistant security modules in VeriFone payment devices to protect encryption

keys from virtually any attack

© 2014 VeriFone, Inc. All rights reserved. VeriFone, the VeriFone logo and VeriShield are either trademarks or registered trademarks of VeriFone in the United States and/or other countries. All other trademarks or brand names are the properties of their respective holders. All features and specifications are subject to change without notice. Reproduction or posting of this document without prior VeriFone approval is prohibited. 06/14 45883 Rev B FS

w w w . v e r i f o n e . c o m

WELCOME PEACE OF MIND