IP Library Granted Patent US 8,261,342
Granted Patent B2
US 8,261,342 · App. 12/543,860 · Granted Sep 4, 2012

Payment card industry (PCI) compliant architecture and associated methodology of managing a service infrastructure

Assignee: Reliant Security
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,261,342
App. No.
12/543,860
Granted
Sep 4, 2012
Kind
B2
Abstract

A system to ensure compliance with data security standards for merchants that store, process, and transmit secure data, includes a security appliance having a global unit to monitor the functions of the security appliance, a logging unit to log data from network devices at the merchant's site and from other security appliance units, an integrity unit to construct maps of file systems of the network devices and to compare the constructed maps with previously constructed maps to detect differences between them, and a scanning unit to periodically scan the network to detect unrecognized devices on the network. The system further includes a display unit to provide compliance information on a secure basis, a back-end unit to automate and manage compliance-related tasks and data security events, and a control unit to monitor compliance performance in real-time and to implement required procedures to ensure compliance with data security standards.

Claims (52)

1. A system to ensure compliance with data security standards for merchants that store, process, and transmit secure data, comprising:

a security appliance located at a merchant's site, the merchant's site having a plurality of network devices, the security appliance identifying each network device from the plurality of network devices as being included in one of a first zone containing cardholder data and a second zone not containing cardholder data, the security appliance performing multiple security functions, the security appliance including:

a global unit to monitor the functions of the security appliance and other units of the security appliance;

a logging unit to log data from at least each network device included in the first zone at the merchant's site and from other units of the security appliance;

an integrity unit to construct maps of file systems of at least each network device included in the first zone containing cardholder data and to compare the constructed maps to previously constructed maps of the file systems of at least each network device included in the first zone to detect differences between them; and

a scanning unit to perform periodic network scans to ensure security of at least each network device included in the first zone containing cardholder data and to detect unrecognized devices on the network;

a display unit to provide information of compliance performance of the system on a secure basis;

a back-end unit to automate and manage compliance-related tasks and data security events and to ensure integrity of the network devices; and

a control unit to monitor compliance performance in real-time and to implement additional procedures required based on the monitored compliance to ensure that each network device included in the first zone containing cardholder data is compliant with payment card industry data security standards regardless of the compliance of each network device included in the second zone with the payment card industry data security standards.

2. The system to ensure compliance with data security standards according to claim 1 , wherein each unit of the security appliance performs only one function, and each unit of the security appliance is isolated from each other but communicates with each other securely.

3. The system to ensure compliance with data security standards according to claim 1 , wherein the security appliance implements a secure VPN connection with at least the network devices included in the first zone within the merchant's site, and another secure VPN connection with the back-end unit located remotely from the merchant's site.

4. The system to ensure compliance with data security standards according to claim 3 , wherein a secure VPN connection requires mutual authentication by devices participating in the secure VPN connection.

5. The system to ensure compliance with data security standards according to claim 1 , wherein the integrity unit issues an alert when a difference is detected during the comparing of the constructed maps to previously constructed maps.

6. The system to ensure compliance with data security standards according to claim 1 , wherein the back-end unit constructs maps of file systems of the security appliance and compares the constructed maps of the file systems of the security appliance to previously constructed maps of the file systems of the security appliance to detect changes between the constructed maps and the previously constructed maps.

7. A security appliance located at a merchant's site to perform multiple security functions, the merchant's site having a plurality of network devices, the security appliance configured to identify each network device from the plurality of network devices as being included in one of a first zone containing cardholder data and a second zone not containing cardholder data, the security appliance comprising:

a global unit to monitor the functions of the security appliance and other units of the security appliance;

a logging unit to log data from at least each network device included in the first zone at the merchant's site and from other units of the security appliance;

an integrity unit to construct maps of file systems of at least each network device included in the first zone and to compare the constructed maps to previously constructed maps of the files systems of at least each network device included in the first zone to detect differences between them; and

a scanning unit to perform periodic network scans to ensure security of at least each network device included in the first zone and to detect unrecognized devices on the network, wherein

the security functions performed by the security appliance ensure that each network device located in the first zone containing cardholder data is compliant with payment card industry data security standards regardless of the compliance of each network device included in the second zone with the payment card industry data security standards.

8. The security appliance according to claim 7 , wherein each unit of the security appliance performs only one function, and each unit of the security appliance is isolated from each other but communicates with each other securely.

9. The security appliance according to claim 7 , wherein the security appliance implements a secure VPN connection with at least each network device included in the first zone within a merchant's site, and implements another secure VPN connection with a back-end unit located remotely from the merchant's site.

10. The security appliance according to claim 9 , wherein a secure VPN connection requires mutual authentication by devices participating in the secure VPN connection.

11. The security appliance according to claim 7 , wherein the integrity unit issues an alert when a difference is detected during the comparing of the constructed maps to previously constructed maps.

12. The security appliance according to claim 9 , wherein the back-end unit constructs maps of file systems of the security appliance and compares the constructed maps of the file systems of the security appliance to previously constructed maps of the file systems of the security appliance to detect changes between the constructed maps and the previously constructed maps.

13. A method to be performed by a system to ensure compliance with payment card industry data security standards for merchants that store, process, and transmit secure data, the method comprising:

performing, in a security appliance located at a merchant's site, multiple security functions, the performing including

identifying each network device from the plurality of network devices as being included in one of a first zone containing cardholder data and a second zone not containing cardholder data;

monitoring, in a global unit, functions of the security appliance and of other units of the security appliance;

logging data, in a logging unit, from at least each network device at the merchant's site and from other units of the security appliance;

constructing maps, in an integrity unit, of file systems of at least each network device included in the first zone and comparing the constructed maps to previously constructed maps of at least network device included in the first zone to detect differences between them; and

performing periodic network scans, in a scanning unit, to ensure security of at least each network device included in the first zone and to detect unrecognized devices on the network;

providing information, through a display unit, of compliance performance of the system on a secure basis;

automating and managing, in a back-end unit, compliance-related tasks and data security events and ensuring integrity of the network devices; and

monitoring, in a control unit, compliance performance in real-time and implementing additional procedures required based on the monitored performance to ensure that each network device located in the first zone containing cardholder data is compliant with the payment card industry data security standards regardless of the compliance of each network device included in the second zone with the payment card industry data security standards.

14. The method according to claim 13 , further comprising:

implementing a secure VPN connection with network devices within the merchant's site, and implementing another secure VPN connection with a back-end unit located remotely from the merchant's site.

15. The method according to claim 14 , wherein

implementing a secure VPN connection includes mutually authenticating devices participating in the secure VPN connection.

16. The method according to claim 13 , further comprising:

issuing an alert, in the integrity unit, when a difference is detected during the comparing of the constructed maps to previously constructed maps.

17. The method according to claim 13 , further comprising:

constructing maps, in the back-end unit, of file systems of the security appliance and comparing the constructed maps of the file systems of the security appliance to previously constructed maps of the file systems of the security appliance to detect changes between the constructed maps and the previously constructed maps of the security appliance.

18. A system to ensure compliance with data security standards for merchants that store, process, and transmit secure data, comprising:

a security appliance located at a merchant's site, the merchant's site having a plurality of network devices, the security appliance identifying each network device from the plurality of network devices as being included in one of a first zone containing confidential user data and a second zone not containing confidential user data, the security appliance performing multiple security functions, the security appliance including:

a global unit to monitor the functions of the security appliance and other units of the security appliance;

a logging unit to log data from at least each network device included in the first zone at the merchant's site and from other units of the security appliance;

an integrity unit to construct maps of file systems of at least each network device included in the first zone containing cardholder data and to compare the constructed maps to previously constructed maps of the file systems of at least each network device included in the first zone to detect differences between them; and

a scanning unit to perform periodic network scans to ensure security of at least each network device included in the first zone containing cardholder data and to detect unrecognized devices on the network;

a display unit to provide information of compliance performance of the system on a secure basis;

a back-end unit to automate and manage compliance-related tasks and data security events and to ensure integrity of the network devices; and

a control unit to monitor compliance performance in real-time and to implement additional procedures required based on the monitored compliance to ensure that each network device included in the first zone containing the confidential user data is compliant with data security standards regardless of the compliance of each network device included in the second zone with the data security standards.

Assignments (11)
SECURITY INTEREST Recorded Jan 29, 2026
From: SCALE COMPUTING, LLC
To: TORONTO DOMINION (TEXAS) LLC
Reel/Frame 073633/0710 →
CHANGE OF NAME Recorded Sep 9, 2025
From: ACUMERA, INC.
To: SCALE COMPUTING, INC.
Reel/Frame 073133/0138 →
RELEASE OF SECURITY INTEREST Recorded Jul 2, 2024
From: ALTER DOMUS (US) LLC
To: ACUMERA, INC.
Reel/Frame 067896/0535 →
SECURITY INTEREST Recorded Jun 9, 2023
From: ACUMERA, INC.
To: ALTER DOMUS (US) LLC, AS COLLATERAL AGENT
Reel/Frame 063912/0619 →
RELEASE OF SECURITY INTEREST Recorded Jun 9, 2023
From: CAPITAL FINANCE ADMINISTRATION, LLC
To: ACUMERA, INC.
Reel/Frame 063909/0794 →
SECURITY INTEREST Recorded Aug 4, 2022
From: ACUMERA, INC.; NETSURION WAN US LLC
To: CAPITAL FINANCE ADMINISTRATION, LLC
Reel/Frame 060716/0759 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2022
From: ACUMERA RELIANT, INC.
To: ACUMERA, INC.
Reel/Frame 060136/0799 →
MERGER Recorded Mar 21, 2022
From: RELIANT INFO SECURITY, INC.
To: ACUMERA RELIANT, INC.
Reel/Frame 059325/0073 →
CORRECTIVE ASSIGNMENT TO CORRECT THE ASSIGNEE NAME PREVIOUSLY RECORDED AT REEL: 023182 FRAME: 0872. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Mar 21, 2022
From: NEWMAN, RICHARD
To: RELIANT INFO SECURITY, INC., D/B/A RELIANT SECURITY
Reel/Frame 059452/0837 →
CORRECTIVE ASSIGNMENT TO CORRECT THE FIRST ASSIGNOR'S NAME PREVIOUSLY RECORDED ON REEL 023118 FRAME 0194. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Sep 1, 2009
From: NEWMAN, RICHARD
To: RELIANT SECURITY
Reel/Frame 023182/0872 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 19, 2009
From: NEWMAN, RIRCHARD
To: RELIANT SECURITY
Reel/Frame 023118/0194 →
Continuity (2)
Provisional Application 61090451 · Aug 20, 2008
Related Publication 20100050249A1 · Feb 25, 2010