PCI
TG-3
TR-31
|
TR-31
In 2005 ANSI published TR-31: Interoperable Secure Key Exchange Key Block Specification for Symmetric Algorithms.
The intent of TR-31 is to establish an interoperable standard replacing the present X9.17 interoperable key exchange standard.
The utilization of Key Block is required for any key derived from TDEA (Triple Des Encryption Algorithm.) Therefore,
if a key exists whether at rest or in motion, Key Blocking must be employed.
The American National Standards Institute (ANSI), which has published the Technical Guideline 3 (TG-3), specifically calls for the usage of TR-31.
- Failure to comply with this guideline may be cause for any one of the following payment networks to refuse connection: Star, Pulse, and NYCE.
- The Payment Card Industry has mandated that PIN Pad manufacturers provide for TR-31 or equivalent methodology.
- HSM manufacturers as well as Payment Application systems are making this technology available.
The implementation of this technology will be significantly more intensive than the migration from SDES to TDES.
Payment networks have already put plans in motion to begin enforcement of TR-31 compliance. As such, GEOBRIDGE
recognizes that now is the time to begin planning for this implementation.
GEOBRIDGE is a member of Accredited Standards Committee X9 (ASC X9) and has an extensive background in payment security, both in technology solutions and consulting services.
Leveraging this experience, GEOBRIDGE is well suited to provide a wide variety of service options pertaining to TR-31:
- Educational services, including introductions to TR-31 and staff awareness training.
- Planning and implementation services for TR-31 implementations.
- Advisory services to provide a resource on questions about TR-31 and compliance requirements.
- End-to-end technology reviews.
Contact Us for more information about GEOBRIDGE TR-31 Compliance Services.
|