Point-to-point encryption (P2PE) provides the most secure and effective solution to protect sensitive cardholder data in combination with EMV and tokenization. P2PE can help reduce the cost and scope of PCI DSS and PA-DSS. Encrypted cardholder data has no value if stolen, as only Payabli and secured providers can decrypt the data.

How P2PE works

P2PE ensures that no cardholder data is exposed during a transaction by encrypting the data inside the card reader, terminal, or payment device. This encryption makes the data useless in the event of a skimming attack. Using the payment industry standard encryption algorithm, DUKPT (Derived Unique Key Per Transaction), a key is injected securely into each card reader or payment device when it’s manufactured. This key is then used to encrypt every transaction. Each transaction remains encrypted until received by Payabli, where it’s decrypted, then passed to the bank or processor for authorization via Payabli’s secure payment gateway.

  1. At the point of card acceptance, within the card reader or payment device, the card data is
    securely encrypted.
  2. After the data is encrypted, it can then be passed over standard public networks to the payment gateway and processor.
  3. When the data arrives in the secure data zone of Payabli’s PCI DSS certified payment gateway, it’s decrypted and
    passed to the bank processor for authorization.

P2PE benefits

  • Easy integration through the use of Payabli’s Quickstart Guide and Cloud Device API
  • Reduce scope, complexity and compliance cost of PCI DSS
  • Simplified PA-DSS for equipment manufacturers
  • Mitigate the risk of cardholder data fraud
  • Reduce financial liability
  • Reduce software development cost
  • Increased cardholder data protection
  • Simplified payment processing architecture