Top Banner
Webinar ‐ Tokenization 101 René M. Pelegero Retail Payments Global Consulting Group L.L.C December 15 th , 2014
24

René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

Jun 08, 2020

Download

Documents

dariahiddleston
Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

Webinar‐ Tokenization101RenéM.Pelegero

RetailPaymentsGlobalConsultingGroupL.L.CDecember15th,2014

Page 2: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

2

WebinarOverview

– Adescriptionoftokenizationandhowthetechnologyisbeingemployedinthepaymentsspace

– Agenda• Whatistokenization?• WhatisNOTtokenization?• Tokenizationinpayments• CardschemetokenizationandApplePay• Tokenizationissues

Page 3: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

3

HistoryofTokens

– TokenDefinition• Tōkən/noun• A thingservingasavisibleortangiblerepresentationofafact,quality,feeling,etc.

• A voucherthatcanbeexchangedforgoodsorservices,typicallyonegivenasagiftorofferedaspartofapromotionaloffer.

Page 4: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

4

TokensintheDigitalWorld

– Replacesensitivedataelementstoprotectthemfromexposure

• AnHRnumberinsteadofSSNastheprimaryaccesskeytoanemployeedatabase

• AnAddressIDtoidentifyafulladdress– Havenobusinessmeaning

• Cannotbeusedtoderivetheoriginalvalue• Donothavetochangeastheunderlyingvaluechanges

Page 5: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

5

TokenizationIsNot

– Encryption

– EMV

– NFC

– HostCardEmulation(HCE)

Page 6: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

6

TokenizationisNOTEncryption

However, tokens are often encrypted

Page 7: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

7

Encryption101

Page 8: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

8

TokenizationisNOTEMV

– Europay,MasterCard,Visa(EMV)• Foundedin1999todefinethespecificationsofchip‐basedpaymentinstruments

• Presentlysixmemberorganizations– AmericanExpress– Discover– JCB– MasterCard(mergedwithEuropay in2002)– UnionPay– Visa

– EMVnameusedtodescribechip‐basedbankcards– Tappedbymemberstodefinetokenizationstandards

• Version1.0oftokenizationpublishedinMarch2014

Page 9: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

9

TokenizationisNOTNFC

– NearFieldCommunications(NFC)• NFCisasetofstandardsforsmartphonesandsimilardevicestoestablishradiocommunicationwitheachoververyshortranges

– Differentimplementations• Embeddedinmobilephone• SIMbased• RemovableSE(SDCard)

– NFCinPayments• NFCchipincludesaSecureElement• Storesinformationinasecuremanner• Itiscontrolledbytelephonecarrier(MNO)orphonemanufacturer

Page 10: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

10

TokenizationisNOTHCE

– HostCardEmulation(HCE)• CardnumberstoredinhostratherthanSecureElement

• SolvestheMNOcontrol,provisioningandassociatedexpenseissues

Page 11: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

11

PuttingItAllTogether

– Tokenscanbe…• DefinedbytheEMVCo specificationorbyanyproprietarystandardbuthavenothingtodowithstandardsforEMVchipcards

• StoredinNFC’sSecureElementoraHostintheCloud• Canbestoredencryptedorintheclear

– Tokenscanbeexchanged…• BetweendevicesusingNFC,HCE,oranyothertechnology

• Generallyinanencryptedmanner

Page 12: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

12

UseofTokensinthePaymentsIndustry

– Tokensreplacebankcardnumbersatdifferentpointsintheprocess

• Tokensreducecardvulnerabilities• TokensreducePCIcomplianceburdens

– Tokenscanbegeneratedinmultipleplaces• MerchantGeneratedTokens• Acquirer/ProcessorsGeneratedTokens• NetworkGeneratedTokens

Page 13: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

13

MerchantGeneratedTokens

– Merchantgeneratestokenwhencardnumberisfirstenteredintomerchantsystem

– Tokendatabasebehindfirewallsandpublicaccess(e.g.cc‐motel,Fluffy,CardVault,etc.)

– Allfurtheractivityforcustomeronlyusesthetoken,notthecardnumber

– Tokenisconvertedtoactualcardnumberwhenitistimetoauthorizepayment

Page 14: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

14

Acquirer/ProcessorGeneratedTokens

– CardisswipedatPOSandPAN,trackdata,andexpirationdateareencryptedandsenttoprocessordatacenter

– Cardnumberisdecryptedandsenttoissuerforauthorizationandtotokenizationserverfortokenassignment

– Processorreturnsauthorizationandtokentomerchantwhoproceedstostoreonlythetoken

– Settlement,refunds,adjustments,chargebacks,etc.usethetokennumber,notthecardnumber

Page 15: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

15

NetworkGeneratedTokens

– SimilartoAcquirer/Processorgeneratedtokensbutthetokenisgenerated,stored,andmaintainedasapaidservicebythecardnetworks

• VisaTokenService• MasterCardDigitalEnablementService• AmericanExpressTokenService

– BasedonastandardpublishedbyEMVCo inMarch2014

Page 16: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

16

CardSchemeTokenizationServices

– Visawavingallfeesuntiltheendof2015– Amexhasnotreleasesfeesyet– MasterCardDigitalEnablementServices(DES)

• Issuers– DigitalEnablementServiceLifecycleManagement10¢perPAN

– Digitationfeeof50¢whenprovisioningatokentoadevice

• Acquirers– DigitalEnablementfeeof0.01%forselectCNPtransactions

Page 17: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

17

ApplePayTokenization

– Howitworks‐ Registration/Enrollment• ApplePay“app”sendscardnumbertoissuingbankthroughVisaorMasterCard

• Issuingbankapprovescardnumbertobetokenized• VisaorMasterCard“tokenize”thecardnumberandsendstokenbacktoapp

• ApplePay“provisions”(i.e.stores)tokenontoSecureElement(SE)iniPhone“binding”ittoauniquedevice(DAN)

Page 18: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

18

ApplePayTokenization

– Howitworks‐ Purchases• Consumer“taps”onPOSdevice(usingTouchIDtoauthenticatetheuser)

• iPhonetransmitsDANtoPOSplusaonetimecodenumber• POSsendsDANtoAcquirerwhosendstoVisaorMasterCard• VisaorMasterCardtranslatetokenbacktotheoriginalcardnumberandsendsittoissuer(afterinsuringthatthetokencamefromthe“proper”device)

• Issuerapprovesordeclinestransactionasnormal

Page 19: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

19

TokenizationBenefits

– Reduceattractivenessofmassdatabreaches

– ReducedscopeofPCIDSS

– Increasedsecurityofmobilepayments

– Increasedperceptionofsecuritybyconsumers

Page 20: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

20

GeneralTokenizationIssues

– Tokengeneration• Howrandomisrandom?• Cantrue“isolation”beachieved

– Tokenavailability• Databasemanagement

– Availability,backup,andrestore• Interoperability

– Routingdebittransactions– Conflictwithcurrentloyaltyschemes

– Tokensafety• TokenDBprotection

Page 21: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

21

VisaandMasterCardTokenizationIssues

– Compatibilitywithexistingservices• VisaTokenService,MasterCardDigitalEnablementService,AmericanExpressTokenService

vs.• FirstDataTransarmour,TSYSGuardianTokenization,BellIDTokenizationManager,etc.

– Compatibilitywithotherstandardschemes• SecureRemotePaymentCouncil• AccreditedStandardsCommitteeX9Inc.• InternationalStandardsOrganization(ISO)

– OperationalIssues• GUIandCustomerService• Recurringpayments• Chargebacks,refunds,andinvestigations

Page 22: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

22

TokenizationServicesStrategicIssues

– OpenStandards• TokenizationasanOpenStandard‐ IsEMVCo theright“home”fortokenizationstandards?

– Control• VisaandMasterCardcontrolthedataandaccesstofundingaccount– “Thoseofusthatparticipateinthetokeninfrastructurecanmakedecisionsonwhoyouwanttogiveaccessto,whetheryouwanttochargeforitandthingslikethat.”VisaCEOCharlesScharf,BankofAmericaMerrillLynch2014Banking&FinancialServicesConference

– ConflictWithDurbinRouting• AccountswithdebitcardstokenizedbyVisaandMasterCardcanonlybeaccessedbymerchantsthroughVisaandMasterCard

Page 23: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

23

TokenizationSummary

– Tokenizationistheconceptofsubstitutingsensitivedatawithmeaninglessvalues

– Tokenizationisbeingusedbymerchants,acquirers,processors,andnowcardschemestohelpreducevulnerabilitiesofcards

– Visa,MasterCard,andAmexhaveintroducedtokenizationstandardsthatgivesthemcontroloveraccessanddataandwhichwillbeprovidedforafeetoissuersandacquirers

– Anumberofsignificantissuesrelatedtotokenizationhavetobeaddressedandresolvedbythepaymentsindustry

Page 24: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

24