GS Logo
The Green Sheet, Inc

Please Log in

A ThingA Bigger Thing

Voltage Security Inc.

ISO/MLS contact:

E. Drew Soinski
Vice President, Payments
Phone: 619-787-5129
Email: drew@voltage.com

Company address:

4005 Miranda Ave., Suite 210
Palo Alto, CA 94304
Phone: 650-543-1280
Fax: 650-543-1279
Email: partners@voltage.com
Website: www.voltage.com

ISO/MLS benefits:


Article originally appeared in The Green Sheet Issue 100801

Providing voltage to data security

V oltage Security Inc., an enterprise security company, calls itself a global leader in next-generation information encryption derived from breakthrough research in mathematics and cryptographic systems. Voltage's end-to-end encryption (E2EE), tokenization, data masking and stateless key management solutions deliver data-centric security that travels with the data itself.

Voltage said over 850 enterprise-class customers in retail, banking, insurance, energy, health care and government use its services. The company boasts that it became the first E2EE vendor to forge alliances with three of the five largest U.S. payment processors, which include Heartland Payment Systems Inc., Fifth Third Processing Solutions LLC, and Elavon Inc. Its email encryption technology is currently being deployed by Microsoft Corp., Proofpoint Inc. and Sendmail Inc., among others.

From Stanford to startup

The original concept for Voltage evolved from a collaboration among cryptography faculty from Stanford University, as well as U.C. Davis and Stanford students. The team proposed a new method for streamlining the process of securing data transmitted via email. Voltage said the students' plan placed first in the annual Stanford BASES business plan competition and went on to win an international competition for collegiate entrepreneurs.

Spurred by interest in the email encryption technology, members of the academic team sought funding for the project, and in 2002 Voltage was born. Voltage shipped its first product in 2003. Today, prominent experts in the cryptographic community continue to play an important role as advisers to the company.

"The first application of Voltage was around email - so data and movement," stated Doug Dwyre, Vice President of Business Development at Voltage. "Then we quickly migrated into solutions for databases and applications - so data-at-rest and static data. Putting those two together made it logical to secure payments and provide a solution for acquirers, processors and merchants where they could secure data in movement, such as end-to-end encryption, as well as stored data."

Wasim Ahmad, Vice President of Marketing at Voltage, added, "We were able to combine the technology into a solution that protects information from the point the card is swiped through to card brand hand-off and anywhere information is stored in a merchant's IT system. Part of that is protecting the credit card, and part of that is how to make sure the right people who need to process it can access it without a constant cycle of encryption and decryption."

According to Ahmad, when sensitive data is repeatedly encrypted and decrypted during payment processing or for other purposes, it creates potential exposure points in network systems that can be exploited by cyber criminals. Voltage has several patented security features built into its encryption technologies that eliminate such exposure.

One-stop PCI compliance

Working with a single-source data security provider, such as Voltage, Payment Card Industry (PCI) Data Security Standard (DSS) compliance for most merchants can be simplified. According to Dwyre, one of Voltage's big attractions is that merchants don't need to implement separate "point solutions" for implementing E2EE and securing databases and applications. Voltage technology secures data at all points, whether the data is at rest, in transit or in use, he said.

Voltage SecureData enterprise solution for data encryption, de-identification and masking ensures E2EE protection as data is collected, used, stored and distributed, even to less controlled environments, including testing and development platforms, regardless of infrastructure or application format requirements. Integrating an enterprise solution reduces PCI audit scope, as well as the costs associated with deployment and maintenance of privacy compliance, Voltage reported.

A primary objective for Voltage cryptographers was to develop an encryption method that would minimize systemwide impacts of encryption on data structures, schemes and applications. Dwyre said, "If you're familiar with other forms of encryption, many times you may be getting 16 numeric digits, and what may be coming out could be well over a hundred alphanumeric digits. So you can understand how difficult that is to implement into a very large database."

The company said its Voltage Format-Preserving Encryption, a mode of the Advanced Encryption Standard, encrypts data while preserving its original format and without sacrificing encryption strength. Typically, only the trusted applications that need to see clear data require one or two lines of code, minimizing impacts to network systems, Voltage said.

Another proprietary feature in the Voltage arsenal is Identity-Based Encryption, which allows unstructured data to be secured and distributed without having to issue encryption keys for every endpoint. Voltage's stateless key management system automates the process, "allowing the key to be derived and generated within the device, so there is no communication to a host in order to get that key rotated," Dwyre said. Key rotation can be set to occur at scheduled intervals.

Voltage also protects data in underlying systems, databases and applications. For merchants with recurring payments or billing, or even loyalty applications, Voltage technology encrypts at the lowest possible level: the data itself. According to Dwyre, other encryption systems put a wrapper around the database or application, which exposes the underlying data. For Voltage users, once the technology is implemented, it doesn't interfere with normal day-to-day operations, Dwyre said. The ease of implementation and system maintenance are key advantages, he added.

Processors partnering up

With the May 2010 launch of Heartland's E3-enabled terminal for small and mid-sized merchants, Dwyre predicts widespread merchant adoption ahead for Voltage's integrated POS technology solutions. By June, Heartland had deployed E3-enabled terminals in 118 merchant categories. Voltage has open license agreements with gateways, value-added resellers, hardware manufacturers and software developers, and it charges a fee for its connector licenses.

Steve Elefant, Chief Information Officer for Heartland, stated, "We have 250,000 merchants, and we want to get as many of those as possible using our E3 solution. There's a whole series of devices that we're releasing, including an E3 magnetic stripe reader, the first of this type of product that has a tamper-resistant security module built into the magnetic stripe reader wedge.

"We also chose Voltage as a long-term enterprise solution, so we've not only deployed it in our POS terminals, but we've deployed it in our email, as well as our systems for SecureData, SecureFile and for securing our BlackBerry servers. It's an enterprise encryption solution that we're using throughout the company."

Elavon was also interested in Voltage's back-end capabilities to secure data when it's moving from application to application or database to database. "It's stateless," Dwyre said. "They can move it around, and it stays encrypted and protected no matter what application they're looking at, whether it's a chargeback employee with Elavon who's viewing it, a customer service representative or someone who's boarding an account. Across the board, the information is secure."

For Hypercom, true E2EE - versus point-to-point encryption - was critical. The company now deploys Voltage across its entire product line. Stuart Taylor, Vice President of Marketing at Hypercom, said, "The key management and format-preserving components from Voltage were important to us. E2E encryption is about protecting the whole cardholder data for the lifecycle of that data. Voltage delivers truly enhanced encryption as opposed to just pure point to point."

Taylor added that in selecting Voltage, Hypercom looked at the company and "decided that their technology was excellent for a number of different scenarios. We have a lot of security drivers built into our ISO terminals that the Voltage technology very neatly integrates with, and we believe it gives us a collective edge."

The sales perspective

Voltage offerings also include Voltage SecureData protection for sensitive customer and partner information within databases and applications; SecureFile document and file protection; SecureMail for email, files and documents transmitted internally and externally; SecureMail Network, an on-demand service; Voltage Key Management Server for automated key management; and Voltage Security Network's on-demand managed services for larger networks.

"When we engage an ISO, especially a larger ISO, we work with their organization to develop a marketing and core distribution strategy," said Drew Soinski, Vice President, Payments at Voltage. "We provide marketing collateral that can be branded with their logo. Our support mechanisms are second to none."

ISOs and merchant level salespeople interested in selling Voltage-enabled POS systems may contact any of the Voltage payment partners listed on the company's website or contact Voltage to implement a program with an unlisted payment processor. For merchants requiring a system to protect data across the entire business environment, Voltage believes its solutions will provide the desired jolt.

Notice to readers: These are archived articles. Contact names or information may be out of date. We regret any inconvenience.

Spotlight Innovators:

North American Bancard | USAePay | Super G Capital LLC | Humboldt Merchant Services | Impact Paysystems | Electronic Merchant Systems