Tokenization

PCI DSS Compliance

The Tokenization is another type of data masking, which by the payment card industry isPCI) is specified and is used instead of or in conjunction with the encryption of the Primary Account Number (PAN):

What is the difference between tokenization and encryption?

Electronically transmitting credit card data can be unsettling, whether through a physical scanner or during an online purchase. Personal data can lead to fraudulent charges and identity theft. To ensure better security, a standard has been created that protects users when they provide their credit card numbers. This standard is called the Payment Card Industry Data Security Standard, or PCI DSS for short. This global standard requires every company to comply with its rules when storing, processing, transmitting, or accepting payment card data. One way to meet PCI DSS requirements is through the encryption of the credit card or the „Primary Account Number“ (PAN); another option is tokenization.

Tokenization

Tokenization is another type of data masking that is specified by the Payment Card Industry (PCI) and is used instead of or in conjunction with encrypting the Primary Account Number (PAN).

What is a token

A token is like a hyperlink to where data is stored—no matter what you do with the token, you are not pulling data out of the token itself. Tokens can be associated with a context, meaning a unique version of your credit card number can be created solely for use at Amazon.com without fear of it being used elsewhere. Likewise, another token can point to a credit card number for use at, say, eBay. With encryption, the data is protected, but the data is contained within—it's clear to the hacker that if they break the encryption scheme, they’ll find the data inside. IRI can provide PCI compliant field value tokenization for FieldShield or CoSort sortCL users in the IRI Data Protection or IRI Data Management Suite.

„A token is like a hyperlink to where data is stored – no matter what you do with the token, you don't get data out of the token itself. Tokens can be contextually linked – so a unique version of my credit card number could be created just for use with Amazon.com, without fear of it being used elsewhere. Likewise, another token could point to my credit card number for use with eBay.

With encryption, the data is protected, but the data is contained within it – for the hacker, it's clear that if they break the encryption scheme, they will find the data inside.“

The Swamy, https://www.pymnts.com/

IRI can be a PCI-compliant field value tokenization function for FieldShield– or CoSort SortCL-Provide users with access to the IRI Data Protection or the IRI Data Management Suite.

The logical sequence is:

 
 

Authorized users can tokenize credit card values, which are also encrypted with a Format-Preserving Encryption (FPEcan be treated as a function, first and possibly later.

Modify and secure the function itself using IRI's Professional Services to the PCI Data Security Standard (DSS). In this blog post Find more details about IRI's current tokenization function.