Home > Ask the Information Security Experts > Questions & Answers > Can tokenization of credit card numbers satisfy PCI requirements?
Ask The Security UK Expert: Questions & Answers
EMAIL THIS

Can tokenization of credit card numbers satisfy PCI requirements?

Joel Dubin EXPERT RESPONSE FROM: Joel Dubin

Pose a Question
Other Security UK Categories
Meet all Security UK Experts
Become an Expert for this site


Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


>
QUESTION POSED ON: 31 August 2007
In your tip regarding PCI and tokenization, you say tokenization of credit card numbers can satisfy the PCI requirements for storing cardholder data. I have heard that tokenization was not sufficient because the token could be used for charges and credits, just like a credit card, and therefore should be considered as a credit card number. Is this true?

>
EXPERT RESPONSE
The key issue here is whether the token can be used, like a credit card number, for making purchases. The whole point of the token was to avoid this situation. The token was meant to be a replacement for the card number; that token would then be useless to a thief.

First, let's quickly review tokenization and the Payment Card Industry (PCI) Data Security Standard. One of the 12 points of PCI is that credit card numbers can't be stored on a retailer's point-of-sale (POS) device or its databases after the transaction. To be PCI compliant, merchants who currently don't encrypt such data will have to install expensive encryption systems on their POS systems.

Tokenization, on the other hand, is a technology developed by Shift4 Corp., which involves an easy-to-install driver on POS systems. The driver converts the credit card into a token, or random 16-digit number resembling a credit card number. The difference is that this number is supposedly useless to anyone who might sniff it or steal it.

The PCI standard is currently being revised, and the next version is expected to be released next year. So it's hard to predict exactly how the revised standard will view tokenization. It's probably safe to say that if the token can be used like a credit card number, it probably won't then be PCI compliant anymore.

For a more authoritative answer, contact the PCI Security Standards Council directly. It will provide a written answer that will satisfy your auditors and the qualified security assessors (QSA) mandated by PCI to conduct annual reviews of companies using credit cards.

For more information:

  • In this expert Q&A, Joel Dubin discusses the vulnerabilities of one-time password (OTP) token authentication, including man-in-the-middle attacks.
  • In this learning guide, contributor Craig Norris explains how to successfully implement PCI's five toughest requirements.


  • Digg This!    StumbleUpon Toolbar StumbleUpon    Bookmark with Delicious Del.icio.us   


    RELATED CONTENT
    Biometrics, Smart Cards, Tokens
    Brits accept biometrics to prevent rise in identity theft
    Integrating biometric authentication with Active Directory
    Single sign-on implementation lets South Manchester doctors work more effectively
    Smart card overcomes static PIN
    Biometric authentication systems vs. token-based systems
    One in 10 Brits trusts the Government to guard data
    National DNA Database stirs racial tension
    ID card scheme hits more hurdles
    What precautions should be taken if biometric data is compromised?
    How to choose the right biometric security product

    Compliance Regulations
    The power of the ICO: Liabilities for a data security breach
    Privacy, data protection must be built into system design, says ICO
    Using ISO 27000 to comply with Data Protection Act principles
    Latest U.K. data security laws get tough on fines, PETs and policies
    Will the Data Handling Review improve government security practices?
    The 'appropriate' way to comply with Data Protection Act 1998
    Best practices: Handling compliance during a corporate merger
    Information Commissioner turns up the heat on data breach culprits
    Email confusion could look bad in court
    Firms aim to achieve PCI compliance deadline, despite the cost

    RELATED GLOSSARY TERMS
    Terms from Whatis.com − the technology online dictionary
    Chip and PIN  (SearchSecurityUK.com)
    NO2ID  (SearchSecurityUK.com)
    UK Identity Cards Act  (SearchSecurityUK.com)

    RELATED RESOURCES
    2020software.com, trial software downloads for accounting software, ERP software, CRM software and business software systems
    Search Bitpipe.com for the latest white papers and business webcasts
    Whatis.com, the online computer dictionary



    Search and Browse the Expert Answer Center
    Search and browse more than 25,000 question and answer pairs from more than 250 TechTarget industry experts.
    Browse our Expert Advice

    About Us  |  Contact Us  |  For Advertisers  |  For Business Partners  |  Site Index  |  RSS
    SEARCH 
    TechTarget provides enterprise IT professionals with the information they need to perform their jobs - from developing strategy, to making cost-effective IT purchase decisions and managing their organizations' IT projects - with its network of technology-specific Web sites, events and magazines.

    TechTarget Corporate Web Site  |  Media Kits  |  Site Map




    All Rights Reserved, Copyright 2008 - 2009, TechTarget | Read our Privacy Policy
      TechTarget - The IT Media ROI Experts