Tokenization

With tokenization, the sensitive cardholder data obtained during a card transaction is replaced with a marker — or token — in the merchant’s system. A token is typically a randomly generated alphanumeric code that takes the place of the original data. Unlike encryption, the token number is not mathematically related to the original data. Retrieving the original data that was replaced by the token requires an index. The data is stored so when the merchant needs to access this information to issue a refund or for another reason, he/she can retrieve it.

Tokenization secures the information stored only after it is initially authorized or the original data is replaced with the token. Tokenization alone does not provide protection against data theft during transmission. While storage of the index of tokens and original data can be secured, tokenization still offers thieves the ability to retrieve millions of records if any element of the security on the data store is weak. The best alternative is not to create a potential vulnerability at all.

As currently designed, E3 will apply the beneficial elements of post-processing tokenization. Once the data reaches the card brands — encrypted — merchants can receive tokenized authorizations to use for easier refunds, returns and chargebacks. Because the token keys are retained by the cards brands, it is unlikely that the data will wind up in the wrong hands.

In this Section

You are now leaving E3Secure.com
You will be leaving the E3secure.com domain and entering an external link. The link provides additional information that may be useful or interesting and is being provided consistent with the intended purpose of E3secure.com. However, E3secure.com cannot attest to the accuracy of this information provided by this link or any other linked site. Providing links to a non-E3secure.com website does not constitute an endorsement by E3secure.com, Heartland Payment Systems or any of its representatives, affiliates or employees or the information or products presented on the site. Also, be aware that the privacy protection provided on the E3secure.com domain (see Privacy Policy) may not be available at the external link.
Go Back Continue