what is payment tokenization

30
WHAT IS PAYMENT TOKENIZATION?

Upload: bell-id

Post on 12-Jul-2015

1.500 views

Category:

Mobile


1 download

TRANSCRIPT

Page 1: What is Payment Tokenization

WHAT IS PAYMENT TOKENIZATION?

Page 2: What is Payment Tokenization

Tokenization enables banks,acquirers and merchants to offer more secure (mobile)

payment services.

Page 3: What is Payment Tokenization

It is the process of replacing card numbers with alternate values.

Page 4: What is Payment Tokenization

The original personal account number (PAN) is disconnected and replaced with a unique identifier called a payment token.

Page 5: What is Payment Tokenization

The ‘mapping’ between the real PAN and the payment tokens is safely stored in the token vault.

Page 6: What is Payment Tokenization

With tokenization the original PAN information is removed from environments where data can be vulnerable.

Page 7: What is Payment Tokenization

Why tokenization?

Page 8: What is Payment Tokenization

1. Tokenization heavily reduces the risk of payment fraud by removing confidential consumer credit card data from the payment network.

Page 9: What is Payment Tokenization

2. The original card numbers stay in control of the bank. External systems do not have accessto this information.

Page 10: What is Payment Tokenization

3. Tokens are random numbers and are not based on cryptography, hence they cannot be traced back to the original value.

Page 11: What is Payment Tokenization

How does tokenization work?

Page 12: What is Payment Tokenization

A token is generated from the PAN for one time use within a specific domain such as a merchant’s website or channel.

Step 1:

Page 13: What is Payment Tokenization

Tokens are sent to the token vault and stored in a PCI-compliant environment.

Page 14: What is Payment Tokenization

Tokens are loaded on the mobile device as part of the virtual card profile.

Step 2:

Page 15: What is Payment Tokenization

The NFC device makes a payment at a merchant’s contactless point-of-sale (POS) terminal using the token as the card number.

Step 3:

Page 16: What is Payment Tokenization

The POS teminal sends the token to the acquiring bank, which sends it to the issuing bank through the payment network.

Step 4:

Page 17: What is Payment Tokenization

The issuer de-tokenizes the token to the real PAN and, if matched, approves the payment.

Step 5:

Page 18: What is Payment Tokenization

Response from the card issuer is returned to the POS terminal using the token as the card reference.

Step 6:

Page 19: What is Payment Tokenization

Payment tokens act like the original PAN for returns, sales reports, marketing analysis and recurring payments.

Page 20: What is Payment Tokenization

How can I use tokens?

Page 21: What is Payment Tokenization

In order to use tokenization, a bank or merchant should become a token service provider (TSP).

Page 22: What is Payment Tokenization

A TSP manages the entire lifecycle of payment credentials including:

Page 23: What is Payment Tokenization

1. Tokenization:

Replaces the PAN with a payment token.

Page 24: What is Payment Tokenization

2. De-Tokenization:

Converts the token back to the PAN using the token vault.

Page 25: What is Payment Tokenization

3. Token vault:

Establishes and maintains the payment token to PAN mapping.

Page 26: What is Payment Tokenization

4. Domain management:

Improves protection by defining payment tokens for specific use.

Page 27: What is Payment Tokenization

5. Identification and verification:

Ensures the original PAN is legitimately used by the token requestor.

Page 28: What is Payment Tokenization

6. Clearing and settlement:

Ad-hoc de-tokenization during clearing and settlement process.

Page 29: What is Payment Tokenization

Thinking of issuing payment tokens to secure mobile payments or

secure your online sales channel?

Bell ID can help:[email protected]

Page 30: What is Payment Tokenization

With over 20 years of expertise, Bell ID is considered the world’s leading provider of lifecycle management solutions for tokens (e.g. smart cards, mobile NFC phones) deployed in single and multi-application programmes.

www.bellid.com

Martin CoxGlobal Head of [email protected]