用于存储信用卡详细信息的安全 DataVault - PCI DSS

发布于 2024-09-14 01:06:54 字数 156 浏览 13 评论 0原文

我一直在阅读一些文章,其中描述了使用 Datavault 和标记化来减轻 PCI DSS 负担。

我的问题是,是否有任何公司提供安全地存储信用卡信息等数据以换取令牌,并且他们是否提供通过验证自己并向他们提供令牌来查看数据的能力?

此设置符合 PCI DSS 要求吗?

I have been reading a few articles which describe using a Datavault and tokenisation to reduce PCI DSS burden.

My question is, are there any companies that offer to store data like credit card information securely in exchange for a token and do they offer the ability to then view the data by authenticating yourselves and providing a a token back to them?

Would this setup be PCI DSS compliant?

如果你对这篇内容有疑问,欢迎到本站社区发帖提问 参与讨论,获取更多帮助,或者扫码二维码加入 Web 技术交流群。

扫码二维码加入Web技术交流群

发布评论

需要 登录 才能够评论, 你可以免费 注册 一个本站的账号。

评论(3

孤云独去闲 2024-09-21 01:06:54

您所指的公司通常称为支付服务提供商(或 PSP),例如 SagePay、PayPal、Authorize.net 等。

这些公司通常不仅仅充当数据存储,它们还允许授权和结算卡支付。您只在您这边存储一个token id,并根据需要使用该token id来请求授权/结算/退款等。从 PCI 合规提供商那里获取卡详细信息是不可能的,因为这会损害他们的 PCI 合规性。

单独使用 PSP 不会神奇地使您符合 PCI 标准,但它会使其变得更加容易,因为它消除了与存储卡详细信息相关的所有负担。不过,您仍然需要遵守 PCI 的一些领域,主要涉及将卡详细信息传输到 PSP。

The companies you're referring to are commonly called Payment Service Providers (or PSP's) and examples would be SagePay, PayPal, Authorize.net etc.

These companies generally don't just act as a datastore, they also allow authorization and settlement of the card payment. You store only a token id on your side, and use the token id to request authorization/settlement/refund etc as required. Getting the card details back from the PCI compliant provider is not possible as it would compromise their PCI compliance.

Using a PSP alone will not magically make you PCI compliant, but it will make it significantly easier, as it removes all the burden associated with storing of card details. You will still have areas of PCI that you will need to comply with though, mainly regarding transmission of card details to the PSP.

水染的天色ゝ 2024-09-21 01:06:54

贝宝怎么了?它们在全球范围内得到认可,利用它们为您带来优势。他们有 SDK 允许与 Paypal 处理服务器交互......

@KSS:好吧,很公平,但一方面,你会减轻自己在安全方面的负担,这将被额外费用的成本所抵消,额外费用,另一方面,管理信用卡处理存储的安全问题......这就是 Paypal 所做的,当然费用可能会很昂贵,但从长远来看,这会为您节省安全头痛和悲伤的成本(这可以运行数千美元,获得认证、安全证书、正常运行时间、服务器成本等)

What happened to PayPal? They are recognized globally, use them to your advantage. They have the SDK's to allow interaction with the Paypal processing server...

@KSS: ok, fair enough, but you would be removing yourself the burden in terms of security which would be offsetted by the cost of the additional fees, on one hand, additional fees, on the other, security issues governing storage of credit card processing....that's what Paypal does, sure the fees may be expensive but that would long-term save you the cost of security headaches and grief (which can run into thousands of USD, getting certified, security certificates, uptime, server costs etc)

失与倦" 2024-09-21 01:06:54

Spreedly 等第三方服务可以为您提供帮助。但关键是你看不到原始卡数据。一旦您这样做(查看),您就处于完全 PCI 合规范围,并且消除了您在使用第三方服务进行令牌化时所考虑的大部分价值主张。 Spreedly 确实有一个 PMD 产品,它可以让您将原始 CC 数据传递到您指定的第三方 API,以便解决问题。

There are third party services like Spreedly that can help you. However the key point is that you can't see the raw card data. Once you do that (view it) you're in full PCI compliance scope with removes a large part of the value proposition that you had in mind when using a third party service to do tokenization. Spreedly does have a PMD offering which will let you pass the raw CC data to a third party API you designate so that may solve the problem.

~没有更多了~
我们使用 Cookies 和其他技术来定制您的体验包括您的登录状态等。通过阅读我们的 隐私政策 了解更多相关信息。 单击 接受 或继续使用网站,即表示您同意使用 Cookies 和您的相关数据。
原文