Hospitality Industry Information Security: The Key To Cyber-Security Is Adopting Encryption AND Tokenization, But Payment Processors Must Adopt Standards First

“Encryption is a process that jumbles personal data into unreadable letters and numbers every time a credit card is swiped….

…Any info about that credit card going forward … none of the credit card information is stored, it’s the token that is stored.”

“Encryption fundamentally is a math algorithm, but it’s a very complicated math algorithm,” Roman said during a recent telephone interview. The information can only be deciphered with a key.

“When an encrypted signal is sent to the intended party, the intended party’s encryption has a key to decrypt and read the message and display it on the screen in readable alpha numerics,” Roman said. “It’s built into the receiving end of each encryption software.”

Encryption jumbles information as it’s transmitted from one system to the other, but it doesn’t necessarily account for data that’s being stored. That’s where tokenization comes in, said Chainrai Waney, an IT consultant who’s worked in data center operations for more than 25 years.

When that card is swiped there’s some sort of a front-end application that generates a token (a line of random numbers) that has nothing to do with that credit card number,” he said. “Any info about that credit card going forward … none of the credit card information is stored, it’s the token that is stored.”
 
A token is a globally unique identifier, generated randomly, and it only has meaning to the sender who provides it and to the processing center that’s purchased it, Roman said.

Noble has yet to adopt tokenization, Garrido said. The company is waiting for payment processors to make the next move.

“They’ve talked about being able to take the data out of the property,” he said. In other words, the processing companies would store the data and send a token back to vendors. No definitive solution has yet been approved, however.   ‘

For more:  http://www.hospitalitynet.org/external/4048209.html

(Visited 37 times, 1 visits today)

Comments Off on Hospitality Industry Information Security: The Key To Cyber-Security Is Adopting Encryption AND Tokenization, But Payment Processors Must Adopt Standards First

Filed under Crime, Insurance, Liability, Risk Management, Theft, Training

Comments are closed.