首页> 外文学位 >Multi-Step Tokenization of Automated Clearing House Payment Transactions
【24h】

Multi-Step Tokenization of Automated Clearing House Payment Transactions

机译:自动清算所付款交易的多步骤标记化

获取原文
获取原文并翻译 | 示例

摘要

Since its beginnings in 1974, the Automated Clearing House (ACH) network has grown into one of the largest, safest, and most efficient payment systems in the world. An ACH transaction is an electronic funds transfer between bank accounts using a batch processing system.;Currently, the ACH Network moves almost $43 trillion and 25 billion electronic financial transactions each year. With the increasing movement toward an electronic, interconnected and mobile infrastructure, it is critical that electronic payments work safely and efficiently for all users. ACH transactions carry sensitive data, such as a consumer's name, account number, tax identification number, account holder name, address, or social security number.;ACH fraud consists of the theft of funds through the Automated Clearing House financial transaction network (Accounts Receivable & Order-to-Cash Network, 2012). If the transactions are intercepted by fraudulent activities, either during transit or during rest, the sensitive customer data can be used to steal the transferred funds, which can cause financial and reputational damage to ACH network participants and consumers.;Even though the National Automated Clearing House Association (NACHA) requires ACH participants to use commercially reasonable encryption and authentication procedures, the risks associated with employee error or negligence, physical theft, and insider theft of data remain substantial. The ACH network that handles 40 billion transactions annually has consumer and corporate financial information. As the ACH network emerges as a prominent payment channel, proactive steps must be taken to guarantee consumer safety.;The primary research question "How can opportunities to commit ACH fraud by insiders be inhibited by masking sensitive data in the ACH transactions life cycle?" is addressed employing design science research methodology with special focus on this specific question: Will use of Multi-step tokens in life cycle of ACH transactions lower the risk of sensitive data exposure?;To demonstrate the extent to which the Multi-step tokens in the life cycle of ACH transactions lower the risk of sensitive data exposure, the following two sub-questions will be answered: • How to model and simulate sensitive data exposure risk in current ACH transaction life cycle? • How to model and simulate sensitive data exposure risk in the multi-step tokenized ACH transaction life cycle?;The research findings through proof of concept simulations confirm that sensitive consumer personal identifiable information shared in ACH network can be made more secure from insider threat opportunities by multi-step tokenization of ACH data. In the to-be system, the real account number will not be used to post the actual financial transaction. Only tokenized account number will be used by RDFI (Receiving Depository Financial Institution) to post the financial transaction. Even if the ODFI (Originating Depository Financial Institution) initiate the financial transaction using real account number, RDFI will reject the transaction back to the originator to resend the transaction using the token value. For the same account number, RDFI will have different token values based on SEC (Standard Entry Class) code, origin, ODFI, transaction type etc. The account token value will be generated only if ODFI sends a token request separately to RDFI in a multi-step manner.;The research findings suggest that multi-step tokenization can be used to generate and validate unique transaction path as a function of the transaction origin number, originating depository financial institution, Standard Entry class, Receiving depository financial institution and account number. Even if the account or token value gets misplaced, the data will be of no use to the person having the information. The cipher can be further strengthened by including additional unique ACH data elements. The findings stem from proof of concept development and testing of conceptual, empirical and simulated models of current ACH network, insider breach scenarios, and multi-step tokenized systems. The study findings were augmented by running different model scenarios and comparing the outputs for breaches, network traffic and costs. The study findings conclude with an implementation proposal of the findings in the ACH network and opportunities for further research on the topic.
机译:自1974年成立以来,自动票据交换所(ACH)网络已发展成为世界上最大,最安全,最高效的支付系统之一。 ACH交易是使用批处理系统在银行帐户之间进行的电子资金转帐。当前,ACH网络每年转移近43万亿美元和250亿笔电子金融交易。随着向电子,互连和移动基础架构的发展,电子支付对所有用户安全有效地运行至关重要。 ACH交易携带敏感数据,例如消费者的姓名,帐号,税号,账户持有人姓名,地址或社会保险号.ACH欺诈包括通过自动清算所金融交易网络盗窃资金(应收账款) &Order-to-Cash Network,2012年)。如果交易在运输过程中或休息期间被欺诈活动拦截,则敏感的客户数据可用于窃取已转移的资金,这可能对ACH网络参与者和消费者造成财务和声誉损失。房屋协会(NACHA)要求ACH参与者使用商业上合理的加密和认证程序,与员工错误或疏忽,物理失窃以及内部数据失窃相关的风险仍然很大。每年处理400亿笔交易的ACH网络拥有消费者和公司的财务信息。随着ACH网络逐渐成为重要的支付渠道,必须采取积极措施来确保消费者安全。主要研究问题“如何通过掩盖ACH交易生命周期中的敏感数据来抑制内部人进行ACH欺诈的机会?”通过使用设计科学研究方法论来解决此问题,并特别关注以下特定问题:在ACH交易的生命周期中使用多步骤令牌会降低敏感数据暴露的风险吗? ACH交易的生命周期降低了敏感数据暴露的风险,将回答以下两个子问题:•如何在当前ACH交易生命周期中建模和模拟敏感数据暴露的风险? •如何在多步骤令牌化ACH交易生命周期中建模和模拟敏感数据暴露风险?;通过概念验证模拟的研究结果证实,ACH网络中共享的敏感的消费者个人可识别信息可以使内部威胁机会更加安全通过ACH数据的多步骤标记化。在准系统中,真实帐号将不会用于过帐实际的财务交易。 RDFI(接收存款金融机构)将仅使用记号化的帐号来过帐金融交易。即使ODFI(原始存托金融机构)使用真实帐号发起金融交易,RDFI也会拒绝将交易退回给发起人以使用令牌值重新发送交易。对于相同的帐号,RDFI将基于SEC(标准进入类别)代码,来源,ODFI,交易类型等而具有不同的令牌值。仅当ODFI以多种方式分别向RDFI发送令牌请求时,才会生成帐户令牌值。研究发现表明,可以使用多步骤令牌化来生成和验证唯一的交易路径,该路径取决于交易来源编号,发起存款金融机构,标准入账类别,接收存款金融机构和帐号。即使帐户或令牌的值放错了位置,该数据对于拥有信息的人也毫无用处。通过包含其他唯一的ACH数据元素,可以进一步加强密码。该发现源自概念验证的证明以及对当前ACH网络,内部违规情况和多步骤标记化系统的概念,经验和模拟模型的测试。通过运行不同的模型场景并比较违规,网络流量和成本的输出,可以增加研究结果。研究结果以ACH网络中研究结果的实施方案和有关该主题的进一步研究机会为结尾。

著录项

  • 作者

    Alexander, Privin.;

  • 作者单位

    University of South Florida.;

  • 授予单位 University of South Florida.;
  • 学科 Information technology.;Finance.;Management.
  • 学位 D.B.A.
  • 年度 2017
  • 页码 452 p.
  • 总页数 452
  • 原文格式 PDF
  • 正文语种 eng
  • 中图分类
  • 关键词

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号