GLOBAL PAYMENTS KNOWLEDGEISO 20022 / SWIFT / SEPA / MT / MX

Wallets & Alternative Rails / Learning brief

How network tokenisation protects a card

Your notes

What this means in plain language

Network tokenisation replaces a card's real number with a device- or merchant-specific stand-in, the DPAN, that only the network can turn back into the real account. Because the token carries domain controls, a copied token is close to worthless outside the device and merchant it was minted for. This is how a stored card can be safer than the number printed on the plastic.

Network tokenisation replaces a card's real number (the PAN, or primary account number) with a stand-in called a DPAN (device primary account number) that only the card network can turn back into the real account. The DPAN is bound to a specific device and, through domain controls, to the context it was minted for, and every payment carries a one-time cryptogram that proves the token is being used on its own device. Because of that binding, a token copied by an attacker is close to worthless away from the device and merchant it belongs to: presenting it elsewhere fails the domain check. This is why a card stored as a token can be safer than the number printed on the plastic — the value moves from keeping the number secret to controlling where and how the token may be used.

Three things to remember

  1. 01

    A DPAN is a real, separate number; the network's token vault holds the mapping back to the underlying PAN, and the issuer still authorises on the real account.

  2. 02

    Domain controls and a per-transaction cryptogram, not secrecy, are what make a stolen token hard to reuse.

  3. 03

    The remaining weak point is enrolment: adding someone else's card to an attacker's device, which is why issuers apply step-up authentication when a card is first provisioned.

Where you would use this

USE CASE 01

A fraud team decides where to concentrate controls, focusing on the provisioning step rather than on protecting the token in transit.

USE CASE 02

An issuer designs its step-up authentication for card enrolment into a wallet, since that is where provisioning fraud lands.

USE CASE 03

A merchant storing cards on file evaluates a network token as a safer alternative to holding the raw PAN.

Put the idea into a real situation

(SYNTHETIC / TRAINING ONLY) Maya Chen provisions her Bank Alfa card into her phone. Bank Alfa applies a step-up check, then the network's token service issues a DPAN and stores the DPAN-to-PAN mapping in its vault. Suppose an attacker later captures that DPAN. When they try to use it from a different device, the payment carries no valid device cryptogram and fails the token's domain check, so it is declined — the number alone buys them nothing. The real exposure was never the token in flight; it was the enrolment moment, which is why Bank Alfa authenticated Maya before the DPAN was ever activated.

Evidence & review

REVIEWED 2026-07-18

Card network tokenisation for device wallets and merchant card-on-file; the mechanics apply across schemes, though naming differs.

What this brief simplifies: Cryptogram generation and key management are described in outline, not in cryptographic detail. Scheme-specific token vault operations are generalised. The DPAN and all card values are synthetic.

Sources for this brief3
  1. Market practiceMarch 2003 edition

    A glossary of terms used in payments and settlement systemsCPSS (now CPMI), Bank for International Settlements · Definitions: payment token, tokenisation

    Standard definitions for payment, clearing, and settlement terminology used across BIS committee reports and referenced by glossary entries on this site. · Checked 2026-07-12

    Terminology has evolved since this edition; newer CPMI publications refine some definitions.

  2. Official requirement

    PSD2 and the RTS on strong customer authentication and secure communicationEuropean Banking Authority · RTS on SCA: dynamic linking and possession factors

    Governs open banking access in the European Union, including payment initiation and account information services offered by third-party providers, and the requirement for strong customer authentication. · Checked 2026-07-13

    Referenced from the European Banking Authority's public summaries, guidelines, and technical standards on payment services.

  3. Simplified educational illustration

    Payments Signal editorial teaching modelsPayments Signal · Token-requestor and domain-control framing; synthetic examples

    This site's own simplified teaching models. · Checked 2026-07-12

    Used wherever diagrams, scenarios, figures, or example values are didactic constructions rather than sourced facts; every such use carries a simplifications disclosure. All people, companies, banks, and list entries in examples are fictional.

Learn this properly

Related briefs

Digital wallets, explained: pass-through versus staged

A digital wallet is a container for a way to pay, but not all wallets work alike. Pass-through wallets present a tokenised version of an existing card so the payment runs on the card rails; staged wallets take an in-wallet payment first, then pay the merchant separately. Knowing which kind you are looking at explains who the merchant is really paid by, where the funds pause, and what the device actually stores.

READ BRIEF

PSP, gateway, acquirer: who does what

Merchants meet a crowd of intermediaries with overlapping names: gateway, payment service provider, acquirer, payment facilitator. Each does a distinct job. The gateway carries the transaction, the acquirer holds the scheme licence and the money, and a payment facilitator lets small merchants trade under its own umbrella. Untangling the roles tells you who is accountable when something breaks.

READ BRIEF

Payment orchestration and routing

An orchestration layer sits above a merchant's payment providers and decides, per transaction, which one to use, when to retry, and whether to cascade a declined attempt to a second provider. It is a router, not a rail: it moves no money itself. Used with care it lifts approval rates; used carelessly it retries a payment the customer already abandoned.

READ BRIEF
COMMUNITY SIGNAL

Discuss this learning page

Share an operational observation or ask a concrete payments question. Your name and message are public; your email remains private.

NEXT QUESTION REVIEWMonday, 27 Jul, 8:00 amMonday answer runs use source-supported educational material. Some questions may need owner review.
WHAT ARE YOU SHARING?

Public discussion

LOADING

Loading the discussion…