« On-Line Strategies | Main | More TransactionManager Gymnastics »

Saturday, September 19, 2009

Comments

Feed You can follow this conversation by subscribing to the comment feed for this post.

Andy,

Thanks for sharing!

I'm curious about the online debit transactions taking 1.6 times longer than credit/offline debit? Curious!

Best,
Scott

Hi Scott -

Thanks for reading and for your great observation. It's an interesting tale to tell!

It has to do with PIN translations. At each step in the transaction path (acquirer, gateway, regional debit network - at times, issuer/authorizing agent), the PIN block associated with an online debit transaction has to be put through a translation step. That puts three or more calls 'off box' to a Hardware Security Module in play along the transaction path.

For example, if suppose this is a Chase debit card:

1. At the Acquirer, the HSM performs a translation from the device's incoming DUKPT PIN block to an outgoing PIN block encrypted under the gateway's ZPK.

2. Then, at the gateway, assume for example that they identify that the transaction needs to get routed via NYCE. So, the gateway does a second HSM-enabled translation (from under the ZPK it shares with the Acquirer to under the ZPK it shares with NYCE).

3. Now NYCE gets the transaction...same deal: it recognizes this request as a Chase BIN and does the ZPK- --> ZPK-based translation to obtain a PIN block with keys it shares with Chase.

4. Lastly, Chase (or its authorizing agent) gets the transaction request and, ultimately, must do a PIN Validation. This, too, requires an HSM operation.

Those four calls exact a penalty as you note - an Online Debit transaction is about 1.6x the length of its credit/offline debit brethren. I can pick any day at any acquirer and that basic relationship will hold true.

Andy

Verify your Comment

Previewing your Comment

This is only a preview. Your comment has not yet been posted.

Working...
Your comment could not be posted. Error type:
Your comment has been posted. Post another comment

The letters and numbers you entered did not match the image. Please try again.

As a final step before posting your comment, enter the letters and numbers you see in the image below. This prevents automated programs from posting comments.

Having trouble reading this image? View an alternate.

Working...

Post a comment

My Photo

Tools

  • Google

    The entire web
    www.andyorrock.com
AddThis Social Bookmark Button

Resources

  • Dave Bergert's blog
    Insightful payment systems thoughts by my OLS colleague, Dave Bergert, CISSP, CISA, CompTIA Security+, and former Visa-certified QSA.
  • Glenbrook Partners' Blog List
    Glenbrook Partners has compiled "a current summary of the latest content from some of our favorite payments and banking blogs based upon their RSS feeds." Alejandro, Dave and I are on the list, as are many other good info sources.
  • jPOS
    Faced with payment systems challenges? Start here to learn more about Alejandro Revilla's jPOS project.
  • Randy San Nicolas' blog
    My OLS colleague Randy San Nicolas writes about his wealth of experience in various Issuer- and Acquirer-side endeavors in his Prepaid Enterprise blog.
  • soliSYSTEMS
    My friend Roque Solis is our go-to guy for RFID, smart cards, chip cards, integrated circuit(s) cards (ICC), HSMs, cryptographic accelerators, DES and public-key cryptography.
  • Specs Online - AMEX
    American Express (Amex) puts all its acquirer specs online for public retrieval.
  • Specs Online - First Data
    First Data Merchant Services (FDMS, aka 'FDR') puts all its acquirer specs online for public retrieval. [NOTE: FDMS' spec repository is accessible only via Internet Explorer; this link will not work with Firefox or other browsers.]
Blog Widget by LinkWithin

If you're looking here...

  • Your attention to detail is a great asset. Use it wisely.