首页> 外文期刊>International Journal of Information Security >A cryptographic study of tokenization systems
【24h】

A cryptographic study of tokenization systems

机译:令牌化系统的密码学研究

获取原文
获取原文并翻译 | 示例
           

摘要

Payments through cards have become very popular in today's world. All businesses now have options to receive payments through this instrument; moreover, most organizations store card information of its customers in some way to enable easy payments in future. Credit card data are a very sensitive information, and theft of this data is a serious threat to any company. Any organization that stores credit card data needs to achieve payment card industry (PCI) compliance, which is an intricate process where the organization needs to demonstrate that the data it stores are safe. Recently, there has been a paradigm shift in treatment of the problem of storage of payment card information. In this new paradigm instead of the real credit card data a token is stored, this process is called "tokenization." The token "looks like" the credit/debit card number, but ideally has no relation with the credit card number that it represents. This solution relieves the merchant from the burden of PCI compliance in several ways. Though tokenization systems are heavily in use, to our knowledge, a formal cryptographic study of this problem has not yet been done. In this paper, we initiate a study in this direction. We formally define the syntax of a tokenization system and several notions of security for such systems. Finally, we provide some constructions of tokenizers and analyze their security in light of our definitions.
机译:通过卡付款在当今世界已经非常流行。现在,所有企业都可以选择通过此工具接收付款;此外,大多数组织都以某种方式存储其客户的卡信息,以便将来轻松付款。信用卡数据是非常敏感的信息,对这些数据的盗窃对任何公司都构成严重威胁。任何存储信用卡数据的组织都需要满足支付卡行业(PCI)的要求,这是一个复杂的过程,组织需要证明其存储的数据是安全的。近来,在处理支付卡信息的存储问题上发生了范式转变。在此新范式中,存储的是令牌而不是真实的信用卡数据,此过程称为“令牌化”。令牌看起来像信用卡/借记卡号,但理想情况下与它所代表的信用卡号没有关系。该解决方案通过多种方式减轻了商家对PCI合规性的负担。尽管令牌化系统正在大量使用,但据我们所知,尚未对此问题进行正式的密码学研究。在本文中,我们将朝这个方向进行研究。我们正式定义了令牌化系统的语法以及此类系统的几种安全性概念。最后,我们提供了分词器的一些构造,并根据我们的定义分析了它们的安全性。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号