What is tokenization in PCI?

What is tokenization in PCI?

Tokenization is often used in credit card processing. The PCI Council defines tokenization as “a process by which the primary account number (PAN) is replaced with a surrogate value called a token. De-tokenization is the reverse process of redeeming a token for its associated PAN value.

How does PCI tokenization work?

The POS machine (or ecommerce site) passes the PAN to the credit card tokenization system. The tokenization system generates a string of random characters to replace the PAN or retrieves the associated token (if it has already been created) and records the correlation in the data vault.

How can credit card tokenization be used in PCI DSS compliance?

In the credit card payment process, the payment tokens are automatically issued on a real-time basis and used online in predefined domains or payment environment. In a tokenized payment process, the PAN is not transmitted during the transaction, thus ensuring the payment process to be secure.

Where to find the PCI data security standard ( PCI DSS )?

A: The PCI DSS applies to ANY organization, regardless of size or number of transactions, that accepts, transmits or stores any cardholder data. Q3: Where can I find the PCI Data Security Standard (PCI DSS)? A: The current PCI DSS documents can be found on the PCI Security Standards Council website.

How does tokenization work in a payment processor?

If the business is using a payment processor’s tokenization solution, the token is sent to the payment processor, who, using the same tokenization technology, can de-tokenize and view the original credit card number and process payment.

What is the payment card industry data security standard?

Skip to content Skip to content. A: The Payment Card Industry Data Security Standard (PCI DSS) is a set of security standards designed to ensure that ALL companies that accept, process, store or transmit credit card information maintain a secure environment.