-

Bluefin Expands AES Support Across PCI-Validated Payment Security Infrastructure

Company advances cryptographic agility and future-ready payment security with expanded AES capabilities across supported payment device environments

ATLANTA--(BUSINESS WIRE)--Bluefin, the global leader in payment and data security, today announced the expansion of Advanced Encryption Standard (AES) capabilities across its PCI-validated point-to-point encryption (P2PE) infrastructure, advancing the company’s strategy to build payment security that can evolve alongside changing cryptographic standards and technologies.

The payments industry has long relied on Triple DES (TDES) with Derived Unique Key Per Transaction (DUKPT) for card-present payment encryption, and approved implementations remain widely used and permitted under current PCI standards. As the broader cryptographic landscape evolves, AES provides a modern symmetric encryption standard with significantly greater cryptographic strength and a larger key space than legacy DES-based approaches.

Bluefin is expanding AES support proactively, enabling organizations to incorporate modern cryptography into supported payment environments through new deployments and technology refreshes rather than waiting for a future industry mandate to make migration urgent.

“Payment security can’t be designed around the assumption that today’s cryptography will remain the standard indefinitely,” said Ruston Miles, Founder and Chief Strategy Officer at Bluefin. “The more important question is whether the infrastructure protecting payments can evolve as standards and threats evolve. By expanding AES within our PCI-validated P2PE environment, we’re giving organizations a path to modernize their cryptographic strategy while retaining the security controls, key management and compliance benefits of validated P2PE.”

AES capabilities are already supported within portions of Bluefin’s payment security technology, including Decryptx® P2PE as a Service and the company’s BluePOS payment application. Bluefin is now expanding that foundation across additional supported payment device and deployment environments.

Initial device availability includes supported PAX A and IM series devices across Android, countertop, unattended and mobile payment environments. Bluefin has also extended AES support to ID TECH environments, initially including the VP3350 and SREDKey 2.

AES encryption alone is not a complete payment security architecture. Bluefin combines modern cryptography with the controls, key management, device security, governance and independent assessment required within a PCI-validated P2PE solution, allowing organizations to strengthen cryptography while maintaining the broader security and compliance framework protecting cardholder data.

The expansion reflects Bluefin’s broader approach to cryptographic agility: building payment security infrastructure capable of adapting to changing cryptographic requirements across diverse device ecosystems and enterprise payment environments. As merchants, acquirers, processors, payment platforms and technology providers make infrastructure decisions that may remain in place for years, cryptographic agility helps ensure those environments are built not only for today’s security requirements, but with the flexibility to adapt to what comes next.

“Cryptographic agility is ultimately bigger than AES,” Miles added. “AES is an important step forward, but the long-term objective is infrastructure that can adapt as cryptography changes. Organizations shouldn’t have to rebuild their payment environment every time the security landscape evolves.”

About Bluefin

Bluefin is a global leader in enterprise payment and data security infrastructure, helping organizations securely connect payment systems, applications, processors, and devices through a vendor-agnostic platform. Combining PCI-validated point-to-point encryption (P2PE), vaultless tokenization, orchestration, and centralized management, Bluefin enables enterprises to reduce PCI scope, simplify compliance, and securely orchestrate payments across complex environments. With more than 300 partners, 40,000 businesses, and over $350 billion in protected transactions annually, Bluefin provides the trusted infrastructure that connects modern payment ecosystems. Learn more at www.bluefin.com.

Contacts

Bluefin


Release Versions

Contacts

More News From Bluefin

Bluefin Collaborates with Visa to Deliver Unified Card-Present Acceptance Through Visa Acceptance Solutions

ATLANTA--(BUSINESS WIRE)--Bluefin, the global leader in payment and data security infrastructure for integrated and orchestrated commerce, and Visa (NYSE: V), a world leader in digital payments, today announced a new card-present acceptance offering that combines Bluefin's PCI-validated P2PE solution with Visa Acceptance Solutions. The new offering provides merchants, software providers, and enterprise organizations with a unified approach to secure in-person payment acceptance, bringing togeth...

Bluefin Extends Secure Patient Payments Across the Expanding Epic Ecosystem With Support for Epic Wisdom

ATLANTA--(BUSINESS WIRE)--Bluefin, the global leader in payment and data security infrastructure for integrated and orchestrated commerce, today announced expanded support for Epic Wisdom through its Epic-certified PayConex™ integration and ongoing collaboration with PAX Technology, enabling healthcare organizations to extend secure, integrated patient payment experiences into dental care environments. As healthcare organizations increasingly unify medical, dental, pharmacy, specialty care, and...

Bluefin and Basis Theory Partner to Enable Unified Tokenization Across Digital and In-Person Payments

ATLANTA--(BUSINESS WIRE)--Bluefin, the global leader in payment and data security infrastructure and PCI-validated point-to-point encryption (P2PE), today announced a strategic partnership with Basis Theory, a modern, API-driven tokenization and vaulting platform. Together, the companies enable enterprises to implement a unified token strategy across in-store, call center, online, and backend payment environments without expanding PCI scope or introducing new integration complexity. As organiza...
Back to Newsroom