Multi-Token Transaction Card for Token Replacement After Compromise

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Transaction cards with visible account identifiers are vulnerable to fraud, leading to the need for card replacement and associated costs, and storing actual account information poses security threats.

Innovation Solution

Transaction cards store a first token on a chip and display a second token electronically, allowing transactions with the first token even if the second is compromised, and the second token can be replaced without replacing the card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If account identifier is embossed or printed on the transaction card for easy access, then ease of operation is improved, but security is worsened due to vulnerability to fraud

Engineering Contradiction:
Improveease of access to account informationVSAvoidfraud vulnerability
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent uses a token as a copy or representation of the account identifier. The token can be displayed on the card in various forms (embossed, printed, magnetic stripe, barcode, QR code) and serves the same function for transactions while not revealing the actual account identifier, thus maintaining ease of operation while improving security

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The token acts as an intermediary between the account identifier and the external world. Instead of exposing the real account identifier, the system uses tokens that can be presented for transactions. The tokenization service mediates between the cardholder's account and the merchants, allowing transactions without revealing sensitive information

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a new transaction card is issued to replace a compromised card, then security is improved, but loss of time and productivity deteriorate due to card replacement waiting period

Engineering Contradiction:
ImprovesecurityVSAvoidcard replacement waiting time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system pre-provisions multiple tokens on the transaction card before any compromise occurs. When a token is compromised, a replacement token is already available on the card, allowing immediate use without waiting for card reissuance. This preliminary preparation of backup tokens eliminates the time loss associated with card replacement

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

When a token is compromised, the system discards (deactivates) the compromised token and recovers functionality by activating a pre-existing replacement token on the same card. This allows the cardholder to continue using the same physical card without interruption, avoiding the time loss of waiting for a new card

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If multiple tokens are provisioned on the transaction card for redundancy, then reliability is improved, but device complexity worsens

Engineering Contradiction:
Improvetransaction continuityVSAvoidtoken management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The transaction card's processor automatically manages multiple tokens without requiring user intervention. The system autonomously provisions tokens, determines which tokens are compromised, activates replacement tokens, and updates displays. This self-service automation reduces the perceived complexity for users while maintaining high reliability through multiple tokens

Inventive Principle:
Principle #25Self-service

4Productivity

If actual account identifier is stored on the transaction card for fast transactions, then productivity is improved, but security worsens due to information theft risk

Engineering Contradiction:
Improvetransaction speedVSAvoidinformation theft risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system stores tokens as copies of the account identifier on the transaction card instead of the actual account identifier. These token copies enable fast transactions just like the real account number would, but they do not reveal sensitive information if the card is compromised. The tokenization service maps these copies back to the actual account identifier only when needed for backend processing

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3596683B1Replacing token on a multi-token user device
Publication Date: 2026.02.18 VISA INTERNATIONAL SERVICE ASSOCIATION
  • EP3596683B1 patent drawingFigure 1
  • EP3596683B1 patent drawingFigure 2
  • EP3596683B1 patent drawingFigure 3

AI summary

Embodiments of the invention are directed to methods, systems, and devices for replacing a token on a user device, such as a transaction card. The transaction card includes tokens representing an actual account identifier which is not visible on the transaction card. The transaction card may store a first token on a and include a digital display that displays a second token. When the first token or the second token is compromised, the compromised token is replaced without replacing the transaction card. When the second token is compromised, the compromised token is replaced with a new replacement second token using an electronic device. The replacement second token replaces the old second token on the digital display. After the second token is compromised and before the replacement second token is provisioned on the transaction card, the transaction card may still be used for transactions using other tokens provisioned on the card.