An Upcycling Tokenization Method for Credit Card Numbers

Cyrius Nugier, Diane Leblanc-Albarel, Agathe Blaise, Agathe Blaise, Simon Masson, Simon Masson, Paul Huynh, Yris Piugie, Yris Piugie

2021

Abstract

Internet users are increasingly concerned about their privacy and are looking for ways to protect their data. Additionally, they may rightly fear that companies extract information about them from their online behavior. The so-called tokenization process allows for the use of trusted third-party managed temporary identities, from which no personal data about the user can be inferred. We consider in this paper tokenization systems allowing a customer to hide their credit card number from a webshop. We present here a method for managing tokens in RAM using a table. We refer to our approach as upcycling as it allows for regenerating used tokens by maintaining a table of currently valid tokens. We compare our approach to existing ones and analyze its security. Contrary to the main existing system (Voltage), our table does not increase in size nor slow down over time. The approach we propose satisfies the common specifications of the domain. It is validated by measurements from an implementation. By reaching 70 thousand tries per timeframe, we almost exhaust the possibilities of the “8-digit model” for properly dimensioned systems.

Download


Paper Citation


in Harvard Style

Nugier C., Leblanc-Albarel D., Blaise A., Masson S., Huynh P. and Piugie Y. (2021). An Upcycling Tokenization Method for Credit Card Numbers. In Proceedings of the 18th International Conference on Security and Cryptography - Volume 1: SECRYPT, ISBN 978-989-758-524-1, pages 15-25. DOI: 10.5220/0010508600150025


in Bibtex Style

@conference{secrypt21,
author={Cyrius Nugier and Diane Leblanc-Albarel and Agathe Blaise and Simon Masson and Paul Huynh and Yris Piugie},
title={An Upcycling Tokenization Method for Credit Card Numbers},
booktitle={Proceedings of the 18th International Conference on Security and Cryptography - Volume 1: SECRYPT,},
year={2021},
pages={15-25},
publisher={SciTePress},
organization={INSTICC},
doi={10.5220/0010508600150025},
isbn={978-989-758-524-1},
}


in EndNote Style

TY - CONF

JO - Proceedings of the 18th International Conference on Security and Cryptography - Volume 1: SECRYPT,
TI - An Upcycling Tokenization Method for Credit Card Numbers
SN - 978-989-758-524-1
AU - Nugier C.
AU - Leblanc-Albarel D.
AU - Blaise A.
AU - Masson S.
AU - Huynh P.
AU - Piugie Y.
PY - 2021
SP - 15
EP - 25
DO - 10.5220/0010508600150025