ePaymentsnews Network
Welcome, Guest
Please Login or Register.    Lost Password?
SSL or 3DES for IP POS Transactions (1 viewing) (1) Guests
Go to bottom Post Reply Favoured: 0
TOPIC: SSL or 3DES for IP POS Transactions
#54
smsshift4 (User)
Fresh Boarder
Posts: 4
graphgraph
User Offline Click here to see the profile of this user
SSL or 3DES for IP POS Transactions 3 Years, 5 Months ago Karma: 0  
The short answer is you need both or something equivalent. SSL is designed to protect data while it is in transit over the Internet or any LAN/WAN. 3DES would be required to store the data in the terminal.

In your pro's and con's you mentioned a con that SSL is difficult to configure but failed to mention a con about a secure 3DES key management.

Technically, SSL is an asymmetric encryption algorithm meaning that the key used to encrypt is different than the key used for decryption (referred to as a public key & private key). This method by definition means that the key is not a security risk – no data will compromised should a hacker have his/her hands on the public key.

3DES on the other hand is a symmetric encryption algorithm meaning that the key used to encrypt is the same key used for decryption. This method means that your data is only as secure as your protection of the key. The problem is that the terminal needs the key to encrypt the data so you're caught in a catch-22. Tackling this problem is not a simple task.

If I have time, I'll try to add more later on this topic…
 
Logged Logged  
  The administrator has disabled public write access.
      Topics Author Date
    thread link
SSL or 3DES for IP POS Transactions
DBorgs 2005/04/25 20:36
    thread link
thread linkthread link SSL or 3DES for IP POS Transactions
smsshift4 2005/07/06 20:32
Go to top Post Reply
Powered by FireBoardget the latest posts directly to your desktop