Voltage SecureDataâ„¢ Tokenization
Reduce PCI audit scope with PAN data tokenization
Tokenization protects against data breaches by replacing primary account numbers (PANs) and other sensitive data with a different value, a "token." The PANs and matching tokens are stored in an encrypted database, and the organization uses the token, instead of the PAN, to process and record transactions within its own systems. If hackers gain access to those systems, they only receive meaningless tokens and are unable to sell or use customer information.
In addition to improving data security, tokenization helps to limit the scope of a merchant’s PCI audit and outsource liability in the event of a data breach. One of the biggest contributors to those rising costs is the expense of PCI audits. However, when an application or database uses tokens instead of actual account numbers, that system generally falls outside of the scope of a PCI audit. As a result, organizations that use Voltage SecureData Tokenization can reduce the size and expense of their audits.
Key Features and Advantages
- Single interface for application developers
Application developers integrating end-to-end data protection into their applications are able to use a single set of high level APIs to enable Tokenization or Format-Preserving Encryption without having to learn additional techniques.
- Common policy framework
Policies relating to how PAN data is transformed can be specified in a centralized manner and applies to Tokenization and Format-Preserving Encryption transformations. This simplifies the overall enforcement of policies.
- Any JDBC Database can be used for Token Stores
In a Tokenization system a token store needs to be designated and secured - with Voltage SecureData Tokenization any JDBC compliant data store can be used, providing maximum flexibility.
- End-to-End Encryption with Back-end Tokenization
Many merchant systems architect today will benefit from being able to utilize end-to-end encryption to protect payment data and be able to tokenize that data at the back-end where it is used by auxiliary business processes. Voltage SecureData is the only solution which enables the dual use of end-to-end encryption and tokenization.
|