Jing Liu, Yang Xiao, Senior Member, IEEE, Hui Chen, Affiliate, IEEE, Suat Ozdemir, Affiliate, IEEE, Srinivas Dodle, and Vikas Singh,

Abstract—Usage of payment credit cards such as charge cards, debit cards, and prepaid cards, continues to grow. Protection breaches linked to payment cards have generated billion buck losses every year. In order to counter this pattern, major payment card networks have founded the Payment Card Market (PCI) Secureness Standards

Council (SSC), which has designed and released the PCI Info

Security Standard (DSS). This standard courses service providers and merchants to implement stronger security infrastructures that reduce the risks of security removes. This article generally discusses the need for the PCI DSS as well as the data security

requirements defined in the regular to address the continuing security concerns, especially those regarding payment greeting card data controlling. It also surveys various technological solutions, proposed by a few secureness vendors, pertaining to merchant firms and organizations involved in payment card transaction processing to comply with the conventional. The compliance of stores or providers to the PCI DSS will be assessed by PCI Qualified Security Assessors (QSAs). This post thus covers the requirements to be PCI QSAs. In addition , that introduces the PCI security scanning methods that guide the scanning of security plans of a product owner or provider and prepare relevant reports. We believe that survey outdoor sheds light on potential technological research problems pertinent for the PCI DSS and its conformity.

Index Terms—Payment Card Sector, Data Reliability Standard, Protection.



CCORDING to a series of biennial surveys issued by

Dove Consulting and American Brokers Association

(ABA) [24], payment credit cards, such as credit, debit, and prepaid credit cards, are becoming an ever more dominant way of

conducting business across three important payment venues:

in-store purchases, Net purchases, and bill repayments. The above online surveys indicate that cash and check repayments are

declining and that digital payment methods are steadily

taking over. For instance , in 2005, cash and check obligations

accounted for 45% of the total monthly payments, straight down from

49% in 2003 and 57% in 2001 [24]. Due to the convenience

that repayment cards can offer and new payment improvements,

this craze is likely to continue [24].

Manuscript received 29 Oct 2008; modified 15 September 2009.

Jing Liu, Yang Xiao, Srinivas Dodle, and Vikas Singh are with Department of Computer Science, The University or college of The state of alabama, Tuscaloosa, APPROACH 35487-0290 UNITED STATES (e-mail: [email protected] org).

Hui Chen is with Department of Mathematics and Computer Scientific research, Virginia Condition University, Petersburg, VA 23806 USA.

Suat Ozdemir is to use Computer Engineering Department, Gazi University, Maltepe, Ankara, Turkey, TR-06570.

Digital Object Identifier 10. 1109/SURV. 2010. 031810. 00083

Payment cards involve many players, including vendors,

payment credit providers, merchant-acquiring financial institutions, and payment card sites. Service providers and merchants are in charge of for controlling huge amounts of repayment card data.

For example , if a person acquires something from a merchant

using a payment card, the must be verified with the

card provider via the retailer's merchant attaining bank and the corresponding payment card network. After a good

verification, how much purchase can eventually always be debited to the payment credit card account. This kind of often requires the dealer to collect and store the payment cards information and the

transaction information in its personal computers, and to give the information over network for the card issuer. Securities

breach over a merchant's or a card issuer's database program may reveal important payment card details, which can

in turn cause significant...