Gateway Segmentation for PCI Compliance Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems lack standardized regulatory requirements for processing and storing confidential financial information, leading to costly and inflexible PCI compliance that burdens businesses, especially those with diverse service offerings.

Innovation Solution

Implementing a method that uses a gateway to isolate PCI-compliant components within an enterprise network, separating management and administration traffic from user traffic, and employing rigorous security measures only for management traffic to maintain compliance without impacting user experience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an entire corporate network is made PCI compliant, then security of confidential information is improved, but device complexity and implementation cost increase significantly

Engineering Contradiction:
Improvesecurity of confidential informationVSAvoidnetwork architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The network is segmented into a PCI-compliant sub-network containing only components that process confidential information, separated from the rest of the enterprise network through a gateway. This segmentation allows PCI compliance to be applied only where necessary, reducing overall network complexity while maintaining security for confidential data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Stringent security measures and PCI compliance requirements are applied locally only to the sub-network processing confidential information, rather than uniformly across the entire corporate network. This localized approach maintains high security where needed while allowing greater flexibility and lower complexity in other network portions.

Inventive Principle:
Principle #3Local quality

2Reliability

If an entire corporate network is made PCI compliant, then security of confidential information is improved, but implementation cost increases significantly

Engineering Contradiction:
Improvesecurity of confidential informationVSAvoidimplementation cost
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The network is segmented into a PCI-compliant sub-network containing only components that process confidential information, separated from the rest of the enterprise network through a gateway. This segmentation allows PCI compliance to be applied only where necessary, reducing overall network complexity while maintaining security for confidential data.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Stringent security measures and PCI compliance requirements are applied locally only to the sub-network processing confidential information, rather than uniformly across the entire corporate network. This localized approach maintains high security where needed while allowing greater flexibility and lower complexity in other network portions.

Inventive Principle:
Principle #3Local quality

3Reliability

If rigorous security measures are applied to all network traffic, then security of confidential information is improved, but user experience deteriorates

Engineering Contradiction:
Improvesecurity of confidential informationVSAvoiduser experience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

A gateway serves as an intermediary between the user-facing network and the PCI-compliant sub-network. The gateway handles authentication and routing, allowing user traffic to access confidential services without exposing users to the rigorous security measures (such as encryption and authentication protocols) that are applied to management traffic within the secure sub-network.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Different security measures are applied to different types of traffic: management traffic receives rigorous security treatment including encryption and authentication, while user traffic is handled with standard authentication. This differentiated approach maintains security for administrative operations while preserving a smooth user experience for end-users.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS9043589B2System and method for safeguarding and processing confidential information
Publication Date: 2015.05.26 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9043589B2 patent drawing
  • US9043589B2 patent drawing
  • US9043589B2 patent drawing

AI summary

One aspect of the invention is a method for providing restricted access to confidential services without impacting the security of a network. The method includes using a gateway to isolate one or more components providing confidential services from one or more other portions of an enterprise network. A first communication directed to a selected one of the one or more components may be received at the gateway. A determination may be made as to whether the first communication is user traffic or management traffic. The first communication may then be authenticated. If the first communication is user traffic, the first communication is forwarded to a component providing the confidential services. If the first communication is management traffic, the first communication is encrypted and forwarded to a component providing the confidential services. Additionally, components of the sub-network may be monitored to identify malicious changes.