A cryptographic study of tokenization systems

Sandra Díaz-Santiago, Lil Maria Rodriguez-Henriquez, Debrup Chakraborty

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

4 Scopus citations

Abstract

Payments through cards have become very popular in today's world. All businesses now have options to receive payments through this instrument, moreover most organizations store card information of its customers in some way to enable easy payments in future. Credit card data is a very sensitive information and its theft is a serious threat to any company. Any organization that stores such data needs to achieve payment card industry (PCI) compliance, which is an intricate process. Recently a new paradigm called "tokenization" has been proposed to solve the problem of storage of payment card information. In this paradigm instead of the real credit card data a token is stored. To our knowledge, a formal cryptographic study of this new paradigm has not yet been done. In this paper we formally define the syntax of a tokenization system, and several notions of security for such systems. Finally, we provide some constructions of tokenizers and analyze their security in the light of our definitions.

Original languageEnglish
Title of host publicationSECRYPT 2014 - Proceedings of the 11th International Conference on Security and Cryptography, Part of ICETE 2014 - 11th International Joint Conference on e-Business and Telecommunications
EditorsMohammad S. Obaidat, Andreas Holzinger, Pierangela Samarati
PublisherSciTePress
Pages393-398
Number of pages6
ISBN (Electronic)9789897580451
DOIs
StatePublished - 2014
Event11th International Conference on Security and Cryptography, SECRYPT 2014 - Part of 11th International Joint Conference on e-Business and Telecommunications, ICETE 2014 - Vienna, Austria
Duration: 28 Aug 201430 Aug 2014

Publication series

NameSECRYPT 2014 - Proceedings of the 11th International Conference on Security and Cryptography, Part of ICETE 2014 - 11th International Joint Conference on e-Business and Telecommunications

Conference

Conference11th International Conference on Security and Cryptography, SECRYPT 2014 - Part of 11th International Joint Conference on e-Business and Telecommunications, ICETE 2014
Country/TerritoryAustria
CityVienna
Period28/08/1430/08/14

Keywords

  • Format preserving encryption
  • Payment card industry standard
  • Provable security
  • Symmetric encryption
  • Tokenization

Fingerprint

Dive into the research topics of 'A cryptographic study of tokenization systems'. Together they form a unique fingerprint.

Cite this