Society of Payment Security Professionals Forum  

Go Back   Society of Payment Security Professionals Forum > Discussion Groups > PCI DSS Q&A

Reply
 
Thread Tools Display Modes
  #1  
Old 02-08-2010, 08:44 PM
nambiarenator nambiarenator is offline
Junior Member
 
Join Date: Mar 2009
Posts: 29
Default GPRS encryption

We have the following setup at our end.

We are having mobile ATMs for which we use corporate GPRS service (client to site). Our service provider gives us APN name which is unique per subscriber. All the SIMs subscribed for corporate GPRS service only connect to APN to establish data communication channel.

Can anyone please let me know whether encryption would be mandatory in the aforementioned type of setup?


Thanks in anticipation!

Last edited by nambiarenator; 02-08-2010 at 08:51 PM.
Reply With Quote
  #2  
Old 02-08-2010, 10:57 PM
lyalc lyalc is offline
Senior Member
 
Join Date: Mar 2007
Posts: 580
Default

the PCI Glossary includes GPRS as a network considered "public" and hence untrusted.

Recent hacker-conference presentations have shown that the commonly used A5/1 and A5/2 encryption algorithms used by most/all GPRS network operators are trivially weak. Source codeis, I think, openly available

Accordingly, transmission of card data on GPRS networks needs additional encryption beyond that available from the carrier - SSL, IPSEC etc.

Also, the PCI network controls relevant to any other wireless network and PCI section 1 (e.g. perimeter firewalls) are required in the scenario.

lyalc
Reply With Quote
  #3  
Old 02-10-2010, 12:42 PM
jbhall56's Avatar
jbhall56 jbhall56 is offline
Senior Member
 
Join Date: Feb 2007
Location: Minneapolis, MN
Posts: 1,282
Default

I would concur with Lyalc's analysis that you need something additional to secure your communications link between your ATM switch and the ATMs.

We had a banking client a number of years ago that had ATMs posted at a number of sports venues that used cellular technology for the communciations link to these ATMs. They were using a Cisco router that connected to a cellular modem. The router implemented an encrypted VPN link between the ATM and the ATM switch to secure the ATMs' communciations.
__________________
Jeff Hall, Director, Risk Advisory Services
RSM McGladrey Inc
801 Nicollet Mall, 11th Floor, West Tower
Minneapolis, MN 55402-2526
612 376 9280 - office
612 395 7280 - facsimile
www.mcgladrey.com

The views presented are those of the writer and are not necessarily those of RSM McGladrey Inc
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -8. The time now is 09:46 AM.


Copyright (c) The Aegenis Group, Inc.