• The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
Menu
  • The Four Hundred
  • Subscribe
  • Media Kit
  • Contributors
  • About Us
  • Contact
  • nuBridges Calls for Tokenization Standards

    March 2, 2010 Alex Woodie

    Security software vendor nuBridges yesterday called for the formation of an industry group to create official standards for tokenization. The company says standards are needed to ensure the security of data, to reduce vendor lock-in, and to ensure the long-term viability of this relatively new form of data security. nuBridges, which is exhibiting and presenting at the RSA Security conference this week, also unveiled a new release of its tokenization product, called Protect Token Manager.

    Tokenization is advanced form of encryption that is gaining traction among retailers, payment gateways, and banks as a result of the PCI security mandate. The technology works by replacing sensitive data, such as a credit card number, with randomly generated index keys, or “tokens,” that point toward the actual credit card number stored in a central database. Organizations that adopt tokenization reduce the risk of unintended information disclosure by storing sensitive data in fewer places, and also lower their storage requirements (because keys are smaller than encrypted data).

    While the concept behind tokenization is well accepted, the actual implementations of tokenization vary from customer to customer, and vendor to vendor, according to Gary Palgon, vice president of product management at nuBridges.

    “There are different models developing out there for tokenization, and it’s causing the beginning of difficulties for companies that actually are implementing it,” Palgon tells IT Jungle.

    Palgon has two main concerns about the course that tokenization is taking. For starters, the lack of interoperability among tokenization providers decreases a customer’s ability to adapt its systems in the future, and increases vendor lock in. Palgon’s second big concern is that the way some vendors are implementing tokenization is not secure.

    The fact that tokenization could cause data to be less secure should set off alarm bells for anybody considering this technology. According to Palgon, companies that use algorithms to generate tokens en masse may be defeating the whole purpose of tokenization.

    “Let’s suppose that you’re generating tokens, and lets suppose the algorithm that you use to generate the tokens would add 1. So the first token was 1, the second token was 2,” Palgon says. “That may seem well and good. But what happens if I’m a company that’s generating credit card numbers? As I tokenize those credit card numbers, I’m getting a pattern, 1-2-3-4, and a pattern defeats the whole purpose of a token. The whole concept behind tokenization is to make information worthless. If there’s a pattern behind it, it’s worth something.”

    It’s somewhat rare for a company that is at the forefront of an industry, as nuBridges is with tokenization, to call for open standards. After all, the company is doing a decent business writing one-off connections between customers’ business applications and Protect Token Manager. Changing from a black-box, proprietary connection model to an open standards model could jeopardize nuBridges’ foothold and allow customers to leave for another provider.

    But as Palgon sees it, without standards in place for the breadth of tools in this category–encryption, key management, and tokenization–customers will not be happy with the results, and overall health of this segment of the security business will falter.

    “What we’re trying to do, effectively, is get together with our competitors and say, ‘For the success of our joint customers, certain things over time need to be interoperable,'” Palgon says. “Then we can differentiate on different features and functionality outside of that.”

    While PCI is driving the adoption of tokenization today, the data security technology is expected to be much more widely adopted in the future, as organizations realize they must protect all personally identifiable information (PII), not to mention personal health information (PHI).

    “From a long term strategic standpoint, we need to iron this out here in the next two years before the massive adoptions,” Palgon says. “Credit card data only represents about 6 percent of the breached data out there. We’re putting all this money and effort into protecting credit card numbers, but the bigger pot of gold of information out there is all this other data. We need standards in place to go after the bigger problems out there, which is the overall PII and PHI.”

    The working name nuBridges has given to this group is the Tokenization Standards Organization. So far, nuBridges has invited about 15 vendors in the business to join the group, which the company envisions being hosted by one of the popular standards bodies, such as IEEE or OASIS. Palgon will be busy meeting with prospective members this week at the RSA conference, and hopefully the formal group and its founding charter members will be announced sometime this spring.

    So, what does Palgon expect to come out of a standards body? For starters, a solid definition of tokenization would be nice. “Even the basic definitions aren’t out there. There are multiple definitions” of what constitutes a token, he says. “None of us will have the exact answer. We’ll have to work it though together.”

    A new tokenization protocol, per se, is not in the mix at this point, as existing protocols such as Web services and message queuing technologies will likely suffice for interoperability and integration needs, Palgon says.

    nuBridges also announced Protect Token Manager release 1.3, which added more granular control over the encryption key lifecycle; consistency with Key Management Interoperability Protocol (KMIP) standards; pre-configured templates for UK National Insurance Numbers and Canadian Social Insurance Numbers; enhanced surveillance of client, user, and administrative activities; and better LDAP integration.

    Protect Token Manager runs natively on i/OS as well as other platforms, and starts at around $50,000. For more information on the Tokenization Standards Organization or Protect Token Manager, contact nuBridges through its Web site at www.nubridges.com.

    RELATED STORIES

    i OS Security Vendors Tap nuBridges for Encryption and Tokenization

    nuBridges Pushes ‘Tokenization’ with New Encryption Tool



                         Post this story to del.icio.us
                   Post this story to Digg
        Post this story to Slashdot

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Tags:

    Sponsored by
    Maxava

    Migrate IBM i with Confidence

    Tired of costly and risky migrations? Maxava Migrate Live minimizes disruption with seamless transitions. Upgrading to Power10 or cloud hosted system, Maxava has you covered!

    Learn More

    Share this:

    • Reddit
    • Facebook
    • LinkedIn
    • Twitter
    • Email

    Sponsored Links

    Northeast User Groups Conference:  20th Annual Conference, April 12 - 14, Framingham, MA
    DRV Technologies:  SpoolFlex automatically converts reports to user friendly PC formats - FREE trial!
    COMMON:  Join us at the annual 2010 conference, May 3 - 6, in Orlando, Florida

    IT Jungle Store Top Book Picks

    Easy Steps to Internet Programming for AS/400, iSeries, and System i: List Price, $49.95
    The iSeries Express Web Implementer's Guide: List Price, $49.95
    The System i RPG & RPG IV Tutorial and Lab Exercises: List Price, $59.95
    The System i Pocket RPG & RPG IV Guide: List Price, $69.95
    The iSeries Pocket Database Guide: List Price, $59.00
    The iSeries Pocket SQL Guide: List Price, $59.00
    The iSeries Pocket Query Guide: List Price, $49.00
    The iSeries Pocket WebFacing Primer: List Price, $39.00
    Migrating to WebSphere Express for iSeries: List Price, $49.00
    Getting Started With WebSphere Development Studio Client for iSeries: List Price, $89.00
    Getting Started with WebSphere Express for iSeries: List Price, $49.00
    Can the AS/400 Survive IBM?: List Price, $49.00
    Chip Wars: List Price, $29.95

    Intelliden Snapped Up by IBM for Network Management Variable Program Calls in Free-Format RPG

    Leave a Reply Cancel reply

Volume 10, Number 9 -- March 2, 2010
THIS ISSUE SPONSORED BY:

New Generation Software
PowerTech
DRV Technologies
Profound Logic Software
VAULT400

Table of Contents

  • CNX Offers Free Community Edition of Valence Web 2.0 App
  • Altova Adds DB2/400 Support to XML Development Tools
  • nuBridges Calls for Tokenization Standards
  • InstallAnywhere Utility Updated with Significant New Features
  • TN5250 for Android Available from Mochasoft
  • The 400 School Takes to the Web with ‘Virtual Classroom’ for i/OS
  • Pat Townsend Now Shipping Encryption Key Software
  • IBM and Ricoh Unveil Printer Management Tool
  • Capitalware Provides Encryption for WebSphere MQ Connections
  • VAI Lands Two More Customers for S2K 5.0

Content archive

  • The Four Hundred
  • Four Hundred Stuff
  • Four Hundred Guru

Recent Posts

  • Public Preview For Watson Code Assistant for i Available Soon
  • COMMON Youth Movement Continues at POWERUp 2025
  • IBM Preserves Memory Investments Across Power10 And Power11
  • Eradani Uses AI For New EDI And API Service
  • Picking Apart IBM’s $150 Billion In US Manufacturing And R&D
  • FAX/400 And CICS For i Are Dead. What Will IBM Kill Next?
  • Fresche Overhauls X-Analysis With Web UI, AI Smarts
  • Is It Time To Add The Rust Programming Language To IBM i?
  • Is IBM Going To Raise Prices On Power10 Expert Care?
  • IBM i PTF Guide, Volume 27, Number 20

Subscribe

To get news from IT Jungle sent to your inbox every week, subscribe to our newsletter.

Pages

  • About Us
  • Contact
  • Contributors
  • Four Hundred Monitor
  • IBM i PTF Guide
  • Media Kit
  • Subscribe

Search

Copyright © 2025 IT Jungle