Jump to content

Securely Transferring Data Between Two Servers (Pci Compliancy)


Recommended Posts

HI guys have a bit of a logic question. I have a client that does event registration on sites A. B. and C. and they would like to start taking payments for the registrations. Now it would be a bit outlandish to create a payment platform on each site so I'm thinking of handling all the payments on an external source say, site D. now, what i'd need to do is create some sort of API that will receive payment data and handle it accordingly (I.E. process, reject, return messages etc.). My biggest concern is A. the security of this (PCI Compliancy) and B. really differentiating between clients (site A. B. and C.) and the possibility to vastly expand in the future.

My understanding is that there needs to be some sort of handshake(TLS handshake?) from one server to another. I think most importantly it's getting the information from the servers of site A. B. and C. to the server of site D. securely. On site D. I would use a payment library and framework to manage/handle the payments and return a payment status.

Am I understanding this correctly? Am I missing anything? Am I completely off base and risking alot? Thanks guys...

 

 

P.S. if there's any consultants out there that are very good and have experience in this field, and are from the U.S. feel free to get in touch, I do pay.

You could just accept google checkout or something, that would solve your problem immediately.

 

Consider this:

 

Server D has two APIs:

 

1) Establish session

 

2) Accept payment information

 

This is how it would work:

 

1) Servers A, B, and C are about ready to take a customer's payment. They submit a server-to-server call to API 1, "Establish Session", with the username and the domain name of the site.

 

2) Server A/B/C print a form to the client containing this session ID, which POSTS to server D

 

3) Customer fills in billing information, including card number and CVV.

 

4) Customer clicks submit. Data is posted securely to server D (the only server which needs an SSL certificate).

 

5) Server D accepts the payments, processes them, assigns the payment to the account, and redirects the user back to server A/B/C based on the server identifier found in the session.

 

6) The customer never realizes they've hit server D unless they were watching their network traffic.

 

 

This thread is more than a year old. Please don't revive it unless you have something important to add.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.