0 Comments

Trying to improve PIN security, EFT networks require their members to use a unique encryption key for each ATM. While the requirement has been ignored by some ATM owners due to high implementation costs, a movement toward remote key distribution could improve compliance rates.

The use of unique keys was first required in a standard produced by the X9A3 committee in the early 1990s. Accredited by the American National Standards Institute, X9 develops and publishes voluntary technical standards for the financial services industry. Card associations and networks adopt many of ANSI's standards, thus giving them considerable clout in the electronic funds transfer industry.

Despite the logic of using unique keys, many ATM owners have ignored the requirements. And until recently, networks didn?t push the issue.

Now, all ATM deployers are faced with re-keying their networks to satisfy mandates for Triple DES encryption, which doubles the length of the keys to 32 hexadecimal characters. Because of this, incidents of "fat finger syndrome," in which a service tech enters the wrong digits, could increase, said Jim Shaffer, senior product manager for security initiatives at ACI Worldwide. Most ATMs, however, provide key check digits to ameliorate the fat finger problem, according to Dennis Abraham, president of Trusted Security Solutions and a member of the X9.24 committee.

Abraham said that eliminating humans from the key-loading process at ATMs might also boost PIN security — if the system is properly implemented.

Remote key capability will better position the industry to handle any future PIN security threats, believes John Sheets, chairman of the X9 working group and vice president and chief security officer for point-of-sale terminal manufacturer Ingenico Group.

Rush to remote key?

Trusted Security has added remote re-key functionality that supports Diebold and NCR methods to its A98 Initial Key Establishment System, Abraham said.

While Diebold and NCR machines have included encryption PIN pads with remote key support for nearly two years, most other manufacturers have not yet begun doing so. Hardware upgrades will be required for machines without support for remote key built into EPPs, Abraham said.

In addition, a hardware upgrade of the HSM may be required at the host end, and new software is required at both the host and the ATM.

Using Trusted Security's A98 method will remove some of the complexity, Abraham said. The A98 system's XML-based Remote Re-Key Module will exchange keys, signatures and certificates with the ATM's terminal handler or device driver via a TCP/IP link.

This approach confines modifications to the ATM device driver and eliminates any additional changes at the host, including the need to add public key capability to the HSM, Abraham said.

Related Content

Reader Comments

Add a Comment

We welcome your thoughtful comments. All comments will display your real name.

Want to participate in the discussion?

Or log in for complete access.

  • Clear
  • Post
Be the first to post a comment for this story.
Products & Services

NCR SelfServ™ 71

http://global.networldalliance.com/new/images/products/2071.png

2071/NCR-SelfServ-71

Self-Service Terminals - The TIO Biller Opportunity

http://global.networldalliance.com/new/images/products/tio.gif

2012/Self-Service-Terminals-The-TIO-Biller-Opportunity

KioWare Kiosk Basic – Kiosk Mode Software

http://global.networldalliance.com/new/images/products/4953.png

4953/KioWare-Kiosk-Basic-Kiosk-Mode-Software

Sony® SnapLab® Pedestal

http://global.networldalliance.com/new/images/products/Sony_SnapLab_100.gif

159/Sony-SnapLab-Pedestal

Green KIOSKS

http://global.networldalliance.com/new/images/products/4622.png

4622/Green-KIOSKS

NCR SelfServ™ Bill Payment

http://global.networldalliance.com/new/images/products/2072.png

2072/NCR-SelfServ-Bill-Payment

SlideBuy Interactive Shelf Merchandising System

http://global.networldalliance.com/new/images/products/4746.png

4746/SlideBuy-Interactive-Shelf-Merchandising-System

Encrypting Pin Pad with Function Keys - Cryptera EPP 1318

http://global.networldalliance.com/new/images/products/895.png

895/Encrypting-Pin-Pad-with-Function-Keys-Cryptera-EPP-1318

CUSTOM's TPT60CM II - Kiosk Printer

http://global.networldalliance.com/new/images/products/TPT60CMII_100px.jpg

2195/CUSTOM-s-TPT60CM-II-Kiosk-Printer

Information Kiosk Software - Genkiosk

http://global.networldalliance.com/new/images/products/4839.png

4839/Information-Kiosk-Software-Genkiosk

Customer Experience Technology Buyer
Self-Service Future Trends 2011
Request Information From Suppliers
Save time looking for suppliers. Complete this form to submit a Request for Information to our entire network of partners.