Sunday 13 April 2014

Tokenization – A solution for Security, Convenience and compliance

You have heard about tokenization or tokenization in payments, let me explain what tokenization in payments is “Merchants who accept card details on their payment page, can send the card number and expiration date to some third party (token provider) via a web service (or any other API) and in response merchant will get a token number against the card details, this token number can be used in future to get the actual card number and expiration date from the same token provider” The token number is generated by such algorithms that card details cannot be derived from token number.

At an abstract level tokenization can provide a merchant with

1    1) Increased online sales: Express checkout or one click checkout can be achieved using tokenization. This improves the checkout process dramatically by reducing the checkout time and added security; this also decreases the chances of transaction failure due to invalid card details. These kinds of services also promote the customer to return to merchant page for future requirements.

2    2) More security and reduced PCI DSS scope, as merchant is not storing card details on its system, so will be the reduced PCI DSS scope, and no fear of losing card details in a security breach.

3    3) Use of card details: Many online merchants usually have integration with more than one payment gateway, if tokenization system is independent of these payment gateways then the same card details can be used in any number of payment gateway. This provides the merchant with better flexibility and control.

Follow Payment Technologies for more updates.

Any questions and comments are appreciated. Thanks for reading

Potential Micro-Services in a Payment Gateway

This post is particularly important for you if you want to: Do technology transformation to break a monolith payment solution to micoservi...