An Upcycling Tokenization Method for Credit Card Numbers - INRIA - Institut National de Recherche en Informatique et en Automatique Accéder directement au contenu
Communication Dans Un Congrès Année : 2021

An Upcycling Tokenization Method for Credit Card Numbers

Résumé

Internet users are increasingly concerned about their privacy and are looking for ways to protect their data. Additionally, they may rightly fear that companies extract information about them from their online behavior. The so-called tokenization process allows for the use of trusted third-party managed temporary identities, from which no personal data about the user can be inferred. We consider in this paper tokenization systems allowing a customer to hide their credit card number from a webshop. We present here a method for managing tokens in RAM using a table. We refer to our approach as upcycling as it allows for regenerating used tokens by maintaining a table of currently valid tokens. We compare our approach to existing ones and analyze its security. Contrary to the main existing system (Voltage), our table does not increase in size nor slow down over time. The approach we propose satisfies the common specifications of the domain. It is validated by measurements from an implementation. By reaching 70 thousand tries per timeframe, we almost exhaust the possibilities of the "8-digit model" for properly dimensioned systems.
Fichier principal
Vignette du fichier
REDOCS_2020_Tokens (5).pdf (696.46 Ko) Télécharger le fichier
Origine : Fichiers produits par l'(les) auteur(s)

Dates et versions

hal-03220739 , version 1 (07-05-2021)

Identifiants

  • HAL Id : hal-03220739 , version 1

Citer

Cyrius Nugier, Diane Leblanc-Albarel, Agathe Blaise, Simon Masson, Paul Huynh, et al.. An Upcycling Tokenization Method for Credit Card Numbers. SECRYPT 2021 - 18th International Conference on Security and Cryptography, Jul 2021, Online, France. ⟨hal-03220739⟩
738 Consultations
462 Téléchargements

Partager

Gmail Facebook X LinkedIn More