JR/T 0149-2016 in English
VALIDChina financial mobile payment-Payment tokenization specification
- Issued on:2016-11-09
- Implemented on:2016-11-09
- File Format:PDF
- Delivery:Via email within 1~3 business days
$582.00
本标准提出了支付标记化技术的基本架构,规定了应用支付标记化技术的系统接口、安全、风险控制等要求。
本标准适用于从事支付标记化系统建设或服务运营的商业银行、非银行支付机构、支付转接清算机构、商户等机构。
Introduction
Core Framework of Payment Tokenization Technology
This standard builds a payment tokenization system with Token Service Provider (TSP) as the core, and replaces the original payment account with payment token to achieve sensitive information protection. The technical architecture includes three key roles:
| Roles | Responsibilities | Typical entities |
|---|---|---|
| TSP | Token generation/verification/lifecycle management | Commercial banks, UnionPay, NetsUnion |
| TR | Token application and delivery | Acquirers, Merchants |
| PA Issuer | Original account verification | Issuing banks, payment institutions |
Key technology implementation requirements
1. Token generation specifications
Token adopts a 13-34-bit three-segment structure: class=instrument>TIN(6-12 digits)+custom digits+check code, global uniqueness must be guaranteed. Example encoding rules:
Application case: A bank generates a token for a credit card transaction as 489001XXXXXX1234, where 489001 is the TIN and 1234 is the check code.
2. Domain control management mechanism
The use scope of Token is limited through five-dimensional domain control parameters:
- Transaction channel: ATM/mobile phone/PC and other multi-channel permission bitmap control
- Merchant range: Single merchant or multiple merchant identification
- Amount limit: Not exceeding the original account transaction limit
- Number of uses: The maximum number of transactions can be set
- Validity period: Must be earlier than the original account expiration date
Security compliance points
1. Data transmission protection
According to clause 10.4.6 of the standard, all sensitive information transmission must meet the following requirements:
- Use commercial encryption algorithms certified by the National Cryptography Administration
- Communication links use TLS 1.2+ protocol
- Message integrity check (MAC value)
2. Client security requirements
Standard 10.4.13 clearly stipulates that mobile clients need to:
| Security measures | Implementation requirements |
|---|---|
| Operation environment detection | Identify ROOT/jailbroken devices and block transactions |
| Sensitive information storage | Prohibit plain text storage of passwords/payment tokens |
| Input verification | Filter special character injection |
Implementation suggestions
1. System construction path
Institutions are recommended to advance in three stages:
- Infrastructure construction period (3-6 months): Complete TSP system architecture design and pass PCI DSS certification
- Pilot operation period (6-12 months): Select low-risk scenarios such as QR code payment for verification
- Full promotion period: Gradually expand to high-sensitivity scenarios such as online consumption and cross-border payment
2. Risk control strategy
It is recommended to establish a hierarchical risk control model:
| Risk level | Countermeasures | Token validity period |
|---|---|---|
| Low risk | Only SMS verification | ≤1 year |
| Medium risk | Biometric recognition + device binding | ≤30 days |
| High risk | Multi-factor authentication + limit | Single validity |
Industry practice: A payment institution implements a dynamic Token mechanism in the App, generating a unique Token for each transaction, effectively curbing man-in-the-middle attacks.

Loading PDF document...
Error loading PDF. Please make sure the file is valid and try again.
We also recommend
-

JR/T 0323-2024 in English
Digital Finance Remote Audio-Video Mobile Banking Technology Specification
2024-12-11 -

JR/T 0025.5-2010 in English
China financial integrated circuit card specifications.Part 5:Debit/credit application card specification
2010-04-30 -

JR/T 0078-2014 in English
Interbank Market Data Interface
2014-01-16 -

JR/T 0093.6-2015 in English
China Financial Mobile Payment Remote Payment Application Part 6: Security Service Technical Specifications Based on Security Element (SE)
2015-12-22 -

JR/T 0067-2011 in English
Securities and Futures Industry Information System Security Level Protection Evaluation Requirements (Trial)
2011-12-22 -

JR/T 0288-2023 in English
Technical Specifications for Bank Electronic Vouchers
2023-07-25 -

JR/T 0237-2021 in English
Overall technical requirements for financial big data platforms
2021-12-29