rené m. pelegero retail payments global consulting group l.l › docs › default... ·...

24
Webinar ‐ Tokenization 101 René M. Pelegero Retail Payments Global Consulting Group L.L.C December 15 th , 2014

Upload: others

Post on 08-Jun-2020

1 views

Category:

Documents


0 download

TRANSCRIPT

Page 1: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

Webinar‐ Tokenization101RenéM.Pelegero

RetailPaymentsGlobalConsultingGroupL.L.CDecember15th,2014

Page 2: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

2

WebinarOverview

– Adescriptionoftokenizationandhowthetechnologyisbeingemployedinthepaymentsspace

– Agenda• Whatistokenization?• WhatisNOTtokenization?• Tokenizationinpayments• CardschemetokenizationandApplePay• Tokenizationissues

Page 3: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

3

HistoryofTokens

– TokenDefinition• Tōkən/noun• A thingservingasavisibleortangiblerepresentationofafact,quality,feeling,etc.

• A voucherthatcanbeexchangedforgoodsorservices,typicallyonegivenasagiftorofferedaspartofapromotionaloffer.

Page 4: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

4

TokensintheDigitalWorld

– Replacesensitivedataelementstoprotectthemfromexposure

• AnHRnumberinsteadofSSNastheprimaryaccesskeytoanemployeedatabase

• AnAddressIDtoidentifyafulladdress– Havenobusinessmeaning

• Cannotbeusedtoderivetheoriginalvalue• Donothavetochangeastheunderlyingvaluechanges

Page 5: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

5

TokenizationIsNot

– Encryption

– EMV

– NFC

– HostCardEmulation(HCE)

Page 6: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

6

TokenizationisNOTEncryption

However, tokens are often encrypted

Page 7: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

7

Encryption101

Page 8: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

8

TokenizationisNOTEMV

– Europay,MasterCard,Visa(EMV)• Foundedin1999todefinethespecificationsofchip‐basedpaymentinstruments

• Presentlysixmemberorganizations– AmericanExpress– Discover– JCB– MasterCard(mergedwithEuropay in2002)– UnionPay– Visa

– EMVnameusedtodescribechip‐basedbankcards– Tappedbymemberstodefinetokenizationstandards

• Version1.0oftokenizationpublishedinMarch2014

Page 9: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

9

TokenizationisNOTNFC

– NearFieldCommunications(NFC)• NFCisasetofstandardsforsmartphonesandsimilardevicestoestablishradiocommunicationwitheachoververyshortranges

– Differentimplementations• Embeddedinmobilephone• SIMbased• RemovableSE(SDCard)

– NFCinPayments• NFCchipincludesaSecureElement• Storesinformationinasecuremanner• Itiscontrolledbytelephonecarrier(MNO)orphonemanufacturer

Page 10: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

10

TokenizationisNOTHCE

– HostCardEmulation(HCE)• CardnumberstoredinhostratherthanSecureElement

• SolvestheMNOcontrol,provisioningandassociatedexpenseissues

Page 11: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

11

PuttingItAllTogether

– Tokenscanbe…• DefinedbytheEMVCo specificationorbyanyproprietarystandardbuthavenothingtodowithstandardsforEMVchipcards

• StoredinNFC’sSecureElementoraHostintheCloud• Canbestoredencryptedorintheclear

– Tokenscanbeexchanged…• BetweendevicesusingNFC,HCE,oranyothertechnology

• Generallyinanencryptedmanner

Page 12: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

12

UseofTokensinthePaymentsIndustry

– Tokensreplacebankcardnumbersatdifferentpointsintheprocess

• Tokensreducecardvulnerabilities• TokensreducePCIcomplianceburdens

– Tokenscanbegeneratedinmultipleplaces• MerchantGeneratedTokens• Acquirer/ProcessorsGeneratedTokens• NetworkGeneratedTokens

Page 13: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

13

MerchantGeneratedTokens

– Merchantgeneratestokenwhencardnumberisfirstenteredintomerchantsystem

– Tokendatabasebehindfirewallsandpublicaccess(e.g.cc‐motel,Fluffy,CardVault,etc.)

– Allfurtheractivityforcustomeronlyusesthetoken,notthecardnumber

– Tokenisconvertedtoactualcardnumberwhenitistimetoauthorizepayment

Page 14: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

14

Acquirer/ProcessorGeneratedTokens

– CardisswipedatPOSandPAN,trackdata,andexpirationdateareencryptedandsenttoprocessordatacenter

– Cardnumberisdecryptedandsenttoissuerforauthorizationandtotokenizationserverfortokenassignment

– Processorreturnsauthorizationandtokentomerchantwhoproceedstostoreonlythetoken

– Settlement,refunds,adjustments,chargebacks,etc.usethetokennumber,notthecardnumber

Page 15: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

15

NetworkGeneratedTokens

– SimilartoAcquirer/Processorgeneratedtokensbutthetokenisgenerated,stored,andmaintainedasapaidservicebythecardnetworks

• VisaTokenService• MasterCardDigitalEnablementService• AmericanExpressTokenService

– BasedonastandardpublishedbyEMVCo inMarch2014

Page 16: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

16

CardSchemeTokenizationServices

– Visawavingallfeesuntiltheendof2015– Amexhasnotreleasesfeesyet– MasterCardDigitalEnablementServices(DES)

• Issuers– DigitalEnablementServiceLifecycleManagement10¢perPAN

– Digitationfeeof50¢whenprovisioningatokentoadevice

• Acquirers– DigitalEnablementfeeof0.01%forselectCNPtransactions

Page 17: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

17

ApplePayTokenization

– Howitworks‐ Registration/Enrollment• ApplePay“app”sendscardnumbertoissuingbankthroughVisaorMasterCard

• Issuingbankapprovescardnumbertobetokenized• VisaorMasterCard“tokenize”thecardnumberandsendstokenbacktoapp

• ApplePay“provisions”(i.e.stores)tokenontoSecureElement(SE)iniPhone“binding”ittoauniquedevice(DAN)

Page 18: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

18

ApplePayTokenization

– Howitworks‐ Purchases• Consumer“taps”onPOSdevice(usingTouchIDtoauthenticatetheuser)

• iPhonetransmitsDANtoPOSplusaonetimecodenumber• POSsendsDANtoAcquirerwhosendstoVisaorMasterCard• VisaorMasterCardtranslatetokenbacktotheoriginalcardnumberandsendsittoissuer(afterinsuringthatthetokencamefromthe“proper”device)

• Issuerapprovesordeclinestransactionasnormal

Page 19: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

19

TokenizationBenefits

– Reduceattractivenessofmassdatabreaches

– ReducedscopeofPCIDSS

– Increasedsecurityofmobilepayments

– Increasedperceptionofsecuritybyconsumers

Page 20: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

20

GeneralTokenizationIssues

– Tokengeneration• Howrandomisrandom?• Cantrue“isolation”beachieved

– Tokenavailability• Databasemanagement

– Availability,backup,andrestore• Interoperability

– Routingdebittransactions– Conflictwithcurrentloyaltyschemes

– Tokensafety• TokenDBprotection

Page 21: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

21

VisaandMasterCardTokenizationIssues

– Compatibilitywithexistingservices• VisaTokenService,MasterCardDigitalEnablementService,AmericanExpressTokenService

vs.• FirstDataTransarmour,TSYSGuardianTokenization,BellIDTokenizationManager,etc.

– Compatibilitywithotherstandardschemes• SecureRemotePaymentCouncil• AccreditedStandardsCommitteeX9Inc.• InternationalStandardsOrganization(ISO)

– OperationalIssues• GUIandCustomerService• Recurringpayments• Chargebacks,refunds,andinvestigations

Page 22: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

22

TokenizationServicesStrategicIssues

– OpenStandards• TokenizationasanOpenStandard‐ IsEMVCo theright“home”fortokenizationstandards?

– Control• VisaandMasterCardcontrolthedataandaccesstofundingaccount– “Thoseofusthatparticipateinthetokeninfrastructurecanmakedecisionsonwhoyouwanttogiveaccessto,whetheryouwanttochargeforitandthingslikethat.”VisaCEOCharlesScharf,BankofAmericaMerrillLynch2014Banking&FinancialServicesConference

– ConflictWithDurbinRouting• AccountswithdebitcardstokenizedbyVisaandMasterCardcanonlybeaccessedbymerchantsthroughVisaandMasterCard

Page 23: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

23

TokenizationSummary

– Tokenizationistheconceptofsubstitutingsensitivedatawithmeaninglessvalues

– Tokenizationisbeingusedbymerchants,acquirers,processors,andnowcardschemestohelpreducevulnerabilitiesofcards

– Visa,MasterCard,andAmexhaveintroducedtokenizationstandardsthatgivesthemcontroloveraccessanddataandwhichwillbeprovidedforafeetoissuersandacquirers

– Anumberofsignificantissuesrelatedtotokenizationhavetobeaddressedandresolvedbythepaymentsindustry

Page 24: René M. Pelegero Retail Payments Global Consulting Group L.L › docs › default... · 2014-12-15 · Webinar ‐Tokenization 101 René M. Pelegero Retail Payments Global Consulting

24