ShieldConex® IFrame SDK

Field Name

Tokenized Value

Detokenized Value

Decrypted P2PE Payload Data Response

The Process Payload endpoint extracts parameters from a device payload and decrypts track data with the Decryptx service. It also parses the decrypted data and attaches the extracted data to the response object.

P2PE Encrypted Payload

Enable Animation

ShieldConex® Orchestration IFrame-Based Use Case

Overview

ShieldConex® Orchestration is a vaultless secure data exchange API that provides and incorporates the powerful capabilities of ShieldConex® Tokenization (pass-through tokenization).

It provides a more powerful solution than the offerings on the market, relying on the client being integrated and certified with the endpoint provider.

For CNP use (eCommerce or MO/TO), a ShieldConex® token is detokenized by ShieldConex®, and the cardholder data is reinserted into the message and sent to the processor for approval. The response from the processor is proxied back to the client.

By using our embedded iframe approach to protect user interactions, you can avoid PCI and other compliance issues by working only with Bluefin tokens.

Sensitive payment data, PII and PHI can be captured within the iframe, meaning that you avoid the need to handle this data in your systems. Instead, our iframe solution immediately tokenizes the sensitive data.

All tokens are made available in one Bluefin API call, and can be used as-is for processor API interactions via the ShieldConex® Orchestration API.

Sensitive data is collected safely using the ShieldConex® iframe. The client retrieves tokenized data, and using ShieldConex® Orchestration, the tokens - along with additional payload elements - are sent for detokenization. This secure processing mode ensures that the client never directly handles sensitive data.

📘 Non-PCI Data Support

While ShieldConex and ORCA are most commonly used to protect PCI-scoped payment data, the same architecture and workflows can be applied to non-PCI sensitive data, including PII.

If required by the merchant, ORCA and SCX can tokenize, encrypt, and securely route PII data independently of payment data, using the same onboarding, orchestration, and processing model.

ShieldConex® Orchestration PointConex Demo

Overview

ShieldConex® Orchestration is a vaultless secure data exchange API that provides and incorporates the powerful capabilities of Decryptx® PCI-validated Point-to-Point Encryption (P2PE).

It provides a more powerful solution than the offerings on the market, relying on the client being integrated and certified with the endpoint provider.

This could be an EMV integration with a payment processor that transmits a lot of data to the payment processor. ShieldConex® Orchestration handles only the specific fields that require actioning, leaving all other data untouched.

Bluefin offers the PointConex integration with a wide range of Bluefin-P2PE certified devices.

For the full list of P2PE-certified devices, refer to Bluefin Supported PCI-Validated P2PE Devices.

📘 Terminology

In the POIntConex term, POI stands for Point of Interaction device that represents the hardware and software of the Point of Sale systems.

PointConex is a bundle solution supporting payment terminal decryption and orchestration to the payment processor (target destination).

This bundle consists of:

  • POI (Point of Interaction) device (terminal)

    • Our Orchestration API also handles encrypted cardholder information (e.g. PAN) from third-party sources (such as payment terminals). As with the tokenization use cases, using our Decryptx® service, you can incorporate device payload parsing in an ORCA. Once again, you are freed from PCI compliance costs because you can send encrypted data via the Orchestration API, which we then decrypt for you in real time and send onto the processor. At no stage does decrypted data enter your systems.
  • ShieldConex® Orchestration

    • The P2PE encrypted payload is sent to the ShieldConex® ORCA via ORCA API.
    • Forwarding the decrypted P2PE payload to the payment processor endpoint, securely over the TLS protocol.
    • The response is proxied back to the client.
    • Orchestrations can apply encryption to payment processor responses before returning them to the merchant/POS systems. This enables response-side protection and normalization workflows, preventing any sensitive data to ever enter the merchant envinroment.
  • Decryptx® P2PE Solution

    • P2PE Data encryption, extraction, and decryption: Decryptx® Parser + Decryptx®
    • Decryptx® P2PE employs advanced encryption methods like SRED to secure cardholder data at the point of interaction/sale. By integrating ShieldConex® Orchestration, Decryptx® efficiently decrypts P2PE payloads in accordance with processor specifications, facilitating seamless authorization processing. This robust combination ensures PCI compliance and safeguards sensitive information throughout the payment processing journey.

The Bluefin P2PE-enabled payment terminals provide support for the following card entry methods:

IDTECH

  • Magnetic stripe (swipe)
  • Keyed/manual entry

Ingenico (RBA) Payloads

  • Keyed/manual entry
  • Magnetic stripe (swipe)
  • Contactless

Miura

  • Magnetic stripe (swipe)
  • EMV (chip and PIN)
  • Contactless
  • Keyed/manual entry

WisePad 2

  • Magnetic stripe (swipe)
  • Keyed/manual entry
  • EMV (Contact & Contactless)

📘 Terminal Payloads and ORCA Workflow


In order to simulate the card read/entry and P2PE encryption, we have included all the sample encrypted payloads extracted from a number of P2PE enabled payment terminals.

Select one of the P2PE encrypted payloads based your preferred payment terminal. The payment terminal reads the card (in accordance with the card entry method) and encrypts it on hardware level via methods like SRED, outputting the P2PE encrypted payload similar to the ones below.

Then, click on the "Initate ORCA Workflow" button where the interactive visual workflow will be showcased, breaking down each Bluefin service involved before Bluefin ShieldConex ORCA forwards the payment data to the payment processor - safeguarding sensitive information throughout the payment processing journey.

This workflow is simulated via our certification system in real-time and is ready to be integrated for the merchant system.

P2PE Encrypted Payload

Enable Animation