Decrypting Tokenization What is it and why is it important?

Slides:



Advertisements
Similar presentations
National Bank of Dominica Ltd Merchant Seminar Facilitator: Janiere Frank Fraud & Compliance Analyst June 16, 2011.
Advertisements

Mobile Payment Security The Good, the Bad and the Ugly
PCI DSS for Retail Industry
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
The GSMA July 2014 Restricted - Confidential Information
ETA UNIVERSITY MARCH 19, 2015 Deana Rich R ICH C ONSULTING, I NC. Edward A. Marshall A RNALL G OLDEN G REGORY LLP Payments 101: Overview of the Payments.
CONFIDENTIAL AND PROPRIETARY ©2014 DISCOVER FINANCIAL SERVICES 2014 Discover ® Dealer Incentive Program & EMV Update.
1 Credit card operation and the recent CardSystems incident HONG KONG MONETARY AUTHORITY 4 July 2005.
Presented by : Vivian Eberhardt, Supervisor Cash and Credit Operations
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance Commonwealth of Massachusetts Office of the State Comptroller March 2007.
Geneva, Switzerland, 4 December 2014 Evolving Payments into The Digital World Richard Smith, Vice President, MasterCard Customer Fraud Management
THE TRANSFORMATION OF PAYMENTS. NFC Hosted Payments EMV in the US End-to-End Encryption Mobile POS.
PCI DSS The Payment Card Industry (PCI) Data Security Standard (DSS) was developed by the PCI Security Standards Council to encourage and enhance cardholder.
Payment Card Industry Data Security Standard (PCI DSS) By Roni Argetsinger
Introduction to OIX: A Market Solution to Online Identity Trust Don Thibeau.
The influence of PCI upon retail payment design and architectures Ian White QSA Head of UK&I and ME PCI Team September 4, 2013 Weekend Conference 7 & 8.
Our Portfolio Reflects Our Expanding Possibilities
The Payment Card Industry (PCI) Data Security Standard: What it is and why you might find it useful Fred Hopper, CISSP TASK - 27 March 2007.
Secure Electronic Transaction (SET)
Credit Card Processing Gail “Montreal” Shoffey Keeler August 14, 2007.
PCI DSS Readiness Presented By: Paul Grégoire, CISSP, QSA, PA-QSA
Authentication and Payments 27 June 2000 Ann Terwilliger Product Director eCommerce Authentication Visa International.
PCI Compliance: The Gateway to Paradise PCI Compliance: The Gateway to Paradise.
Data Security and Payment Card Acceptance Presented by: Brian Ridder Senior Vice President First National September 10, 2009.
TransArmorSM A Secure Transaction ManagementSM Solution
What you need to know about PCI-DSS Jane Drews Chief Information Security Officer Information Security & Policy Office
ThankQ Solutions Pty Ltd Tech Forum 2013 PCI Compliance.
The Payment Card Industry (PCI) Data Security Standard (DSS) was developed to encourage and enhance cardholder data security and facilitate the broad.
Standards in Use. EMV June 16Caribbean Electronic Payments LLC2.
CONNECTING ECOMMERCE MERCHANTS TO HIGH- SPENDING CUSTOMERS.
By: Matt Winkeler.  PCI – Payment Card Industry  DSS – Data Security Standard  PAN – Primary Account Number.
Confidential and Proprietary - NOT TO BE DISTRIBUTED WITHOUT THE EXPRESS WRITTEN PERMISSION OF BANK OF AMERICA MERCHANT SERVICES. ASTRA EMV Review/Best.
Copyright 2009, First Data Corporation. All Rights Reserved. How Does TransArmor SM Work at the POS? SafeProxy Merchant Anti FraudAnalytics First Data.
WHAT NEW, WHAT NEXT IN PAYMENT PROCESSING. EMV WHAT IS EMV? 3  An acronym created by Europay ®, MasterCard ® and Visa ®  The global standard for the.
PCI COMPLIANCE & A/R AUTOMATION 101 Nodus Technologies, Inc.
EMV.
Mastercard® Automatic Billing Updater
PCI DSS Improve the Security of Your Ecommerce Environment
A catalyst for mobile contactless payments adoption?
Conversion Optimizations Before the Holidays
PCI-DSS Security Awareness
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Payment card industry data security standards
Agenda What is ECOM? ECOM in MENA and Lebanon
Fraud Prevention Solutions Make it secure, keep it simple!
EMV & Parking – 6 Months On
PCI DSS modular approach for F2F EMV mature environments
Securing the Future of Payments
Internet Payment.
3-D Secure 2.0 What Merchants Need to Know
Secure Electronic Transaction
EMV® 3-D Secure - High Level Overview
October 27, 2016 EMV 3DS Seizing the opportunity to enhance security and deliver a great consumer experience September 22, 2018.
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Cesar Lomeli.
The Evolution of Money and Biometrics
Payment Card Industry (PCI) Data Security Standard (DSS) Compliance
Third-party Payment options, PayPal Implementation
Masterpass: Bill Payments July 18, 2017
EU Schemes and Processors – The “Buzz” for 2016!
Payment Card Industry - Requirements and implementation challenges in Armenian market Vladislav Muradyan Partner.
Going Cardless…. Iran Islamic Finance Forum October 2018.
DieboldNixdorf.com Tokenization Roman Cinkais |
Mastercard® Automatic Billing Updater
Online Payment Options for Government
Why We Love AND Hate Tokenization Making Choices, Not Repairs
ACH to Credit Card Conversions A Merchants Perspective
Increasing approval rates in the digital world
Presentation transcript:

Decrypting Tokenization What is it and why is it important? Anne Fields, Crutchfield, Director Financial Compliance Nate Morgan, CyberSource, Product Manager Ian Poole, CardinalCommerce, Technical Product Manager

Tokenization What is it & Types of Tokens Merchant Perspective Merchant Considerations Q & A

Payment Tokenization: What is it? Customer Data Other Data Card Data Replaces sensitive data (card numbers, PII data) with a different, unrelated value called a token Cannot be reversed, meaningless to hackers in the event of a breach Mostly follow the PAN (primary account number) format, compatible with existing payment flows, financial systems T

Evolution of Merchant Tokenization Secures stored card and customer data Reduces PCI scope Enables card-on-file Drives omni-channel experiences Supports marketing efforts: analytics, loyalty programs

Merchant Payment Tokens Seamless, friction-less payment experience Your customer data is better protected in the event of a breach Renders sensitive card (and other) data worthless Card data securely stored in your vault PCI scope is reduced; no payment data in your network when using a PSP Tokens, not card numbers used for payment activities Essential for bill payers / returning customers Enables new, “Uber-like” experiences Card updater service highly recommended

Comparing Merchant Tokenization Providers ? Gateway Token Services Acquirer Token Services Proprietary technology, not standardized Designed to safeguards merchants from consequences of data breaches and reduce merchant PCI demands Designed to safeguards merchants from consequences of data breaches and simplify Merchant and Acquirer PCI Tokenization of Payment Data, PII data and other sensitive customer data Tokenization focused on Payment Data Works across all card brands, payment types supported across Acquirers (Acquirer agnostic) Works across all card brands and card issuers supported by Acquirer Tied to Gateway Tied to a Acquirer/Processor Protection of stored card data Reduced PCI scope Processor Agnostic Support for digital payment solutions like Apple Pay, Android Pay, etc. via network tokens Tokenization of PII data (some providers cater to healthcare industries) Proprietary, tied to the acquirer issuing the token- merchant cannot switch acquirers, integrate to/inter-operate with tokens from other acquirers Able to support POS and eCommerce transactions (omni functionality) Other features similar to PSP tokens Protection of stored payment data Reduced PCI scope

EMVCo standards; launch of VTS and MDES Evolution of Issuer Tokenization VTS MDES EMVCo standards; launch of VTS and MDES Enables digital payments such as Apple Pay, Android Pay Powers connected commerce, IoT and other new payment experiences Future applications *EMVCo members include American Express, Discover, JCB, MasterCard, UnionPay and Visa Note: All brand names and logos are the property of their respective owners, are used for identification purposes only, and do not imply product endorsement or affiliation with Visa

Issuer-Side (Network) Payment Tokens Card brands * collaborated as EMVCo, developed standards for worldwide interoperability & security Apple Pay was the first use case, now also Android Pay, Samsung Pay, etc. Visa, Mastercard, Amex built solutions using token standards in the EMVCo framework and are the “TSP” of digital payment tokens Issuers control activation, suspension, deactivation of tokens for cardholder Tokens are unique to device, channel, and stored for future payments May be single or multi-use, merchant specific or have time limitations

Comparing Tokenization Approaches? Issuer (Network Tokenization) Processor (Merchant Tokenization) Based on industry standard Proprietary technology, not standardized Designed to safeguard the payment ecosystem from consequences of data breaches Designed to safeguards merchants from consequences of data breaches Likely requires issuer opt-in participation Likely requires merchant opt-in participation Currently works in limited use cases (mainly the digital payments) Works across all card brands and card issuers Independent of processors and gateways but tied to individual card network Tied to a processor / gateway Processor tokenization may also be referred to as Acquirer tokenization

Tokenization & Connected Commerce Allows commerce to be embedded in everything Device manufacturers, large businesses are becoming token requestors Gearing to enable secure, device-driven on-demand transactions on a massive scale eComm wallet, IoT wallet, Issuer wallet, Wearable wallets, POS – tap and pay

Merchant Perspective Why did we consider Tokenization? How do we Tokenize? What did we want to accomplish with Tokenization?

Merchant Considerations Interoperability considerations Ensure cross-channel compatibility Protect from fraud Recurring/Card on File billing Work with other protocols- 3DS 2.0 Other factor considerations New digital pay adoption Retain access and control of your customer data Consider multi-acquirer requirements Consider tokenization of non-card payment methods Risk Strategy considerations PCI Compliance Cost/Complexity Breach risk / Brand Consequences Security considerations for 3rd Party Seek accredited PCI DSS Level 1 service provider Select a cloud-based solution to reduce PCI scope Augment with other technologies such as hosted payment acceptance, P2PE

Questions from the audience

Tokenization Panel Anne Fields, Crutchfield, Director Financial Compliance afields@crutchfield.com Nate Morgan, CyberSource, Product Manager nmorgan@visa.com Ian Poole, CardinalCommerce, Technical Product Manager ipoole@cardinalcommerce.com If you have any questions about the presentation, go to our LinkedIn Group (the Payments Education Forum) and request an invitation (this is a closed group specifically for the payments industry).