DMZ DNS Virtual IP Gateway for PCI DSS Compliance
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The existing methods for securing a cardholder data environment, particularly in e-commerce transactions, face challenges in meeting the PCI DSS v1.2 requirement of restricting outbound traffic from the cardholder data environment to the Internet, especially when using SSL with payment-specific certificates, as they require multiple hardware security modules (HSMs) which are invasive and costly.
Innovation Solution
A system architecture that employs a Dynamic Name Service (DNS) Virtual IP (VIP) Gateway (DVG) to allocate and map IP addresses, allowing communication between the cardholder data environment and the external network while ensuring security by using a DMZ to restrict outbound traffic to only access IP addresses within the DMZ, thereby meeting the PCI DSS v1.2 section 1.3.5 requirement without the need for multiple HSMs.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If HTTP proxies with multiple HSMs are used to meet PCI DSS v1.2 requirements for SSL with payment-specific certificates, then security compliance is improved, but device complexity and cost increase significantly
Solution Approach 1:
The patent introduces a DMZ network as an intermediary layer between the cardholder data environment and external networks. The DMZ contains payment gateway servers that handle SSL certificate operations, acting as a mediator that isolates the cardholder data environment from direct exposure to external threats while maintaining PCI DSS compliance without requiring multiple HSMs in the protected environment
Solution Approach 2:
The network architecture is segmented into distinct zones: the cardholder data environment, the DMZ, and external networks. This segmentation allows SSL operations with payment-specific certificates to occur in the DMZ rather than requiring multiple HSMs within the cardholder data environment, reducing device complexity while maintaining security compliance
2Reliability
If a DMZ is implemented to restrict outbound traffic from cardholder data environment, then security is improved, but network complexity increases
Solution Approach 1:
The DMZ is designed to serve multiple functions: it restricts outbound traffic from the cardholder data environment, hosts payment gateway servers for SSL operations, and provides a controlled interface for external network communication. This multi-functionality reduces the need for separate security mechanisms, simplifying the overall network architecture while maintaining security
3Reliability
If multiple HSMs are deployed for SSL with payment-specific certificates, then security compliance is improved, but cost increases
Solution Approach 1:
The DMZ acts as an intermediary that hosts the payment gateway servers requiring SSL certificates. By placing these servers in the DMZ rather than the cardholder data environment, the system maintains PCI DSS compliance while avoiding the need to deploy multiple expensive HSMs within the protected environment
Solution Approach 2:
The patent uses a single HSM in the DMZ to generate and manage payment-specific certificates, effectively copying the security functionality to the DMZ environment where it is more cost-effective to implement, rather than deploying multiple HSMs in the cardholder data environment
Data Source
AI summary
A system of a first network, which is intermediate a second network and a third network, connects a host of the second network to a host of the third network. The system includes at least one processor programmed to receive a domain name service (DNS) request for a hostname corresponding to the host of the third network from the host of the second network. An internet protocol (IP) address of the first network allocated and an IP address of the host of the third network is determined from the hostname. The allocated IP address is mapped to the determined IP address and the allocated IP address is returned to the host of the second network in response to the DNS request.

