Method and system for generating dynamic card verification value for processing transaction

The method and system enhance transaction security by generating and delivering dynamic CVV codes through near-field communication, addressing the vulnerability of card-not-present transactions.

JP2025135004APending Publication Date: 2025-09-17COMPOSECURE LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025113731
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2020-11-19
Filing Date
2025-07-04
Publication Date
2025-09-17

AI Technical Summary

Technical Problem

Card-not-present transactions are more vulnerable to fraud due to the static nature of traditional CVV codes, necessitating the development of more secure methods for generating dynamic CVV codes.

Method used

A method and system that utilizes near-field communication between a transaction card and a mobile device to generate and deliver a dynamic CVV code via a secure communication network, enabling authentication through a dCVV generation processor.

Benefits of technology

Enhances transaction security by providing a dynamic CVV code that changes frequently, reducing fraud risks in online transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025135004000001_ABST
    Figure 2025135004000001_ABST
Patent Text Reader

Abstract

To provide systems, methods, transaction cards, mobile devices, processors, and computer memory programmed with machine-readable instructions, for providing a dynamic Card Verification Value (dCVV) to a user of a transaction card.SOLUTION: A mobile device associated with the user and with the transaction card initiates a non-payment near field communication (NFC) with the transaction card, receives a message from the transaction card in the non-payment NFC communication, transmits a prompt to an IP address or web address over a global computer information network, and receives a secure communication containing the dCVV from a server accessible from the IP address or web address in response to the prompt. The dCVV code is then provided to the user. In embodiments, the non-payment NFC may be initiated via a card tap, a user interface, or a communication from a website.SELECTED DRAWING: Figure 1
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Provisional Patent Application No. 63 / 115,888, entitled "Method and System for Generating Dynamic Card Verification Values ​​for Processing Transactions," filed November 19, 2020, the contents of which are incorporated herein by reference. [Background technology]

[0002] Various types of financial transactions are known to use transaction cards (such as, but not limited to, credit cards, debit cards, smart cards, etc.). Increasingly, transactions are conducted using online portals over global computer information networks (e.g., the Internet), such as on Amazon.com, that do not have access to the physical transaction card to process the transaction with, for example, a point-of-sale (POS) card reader that reads information from a magnetic stripe on the card, an IC chip via physical contact with a card reader, or a radio frequency identification (RFID) chip through contactless interaction or "tap." Such transactions conducted entirely online, often referred to as "card-not-present transactions," are generally more vulnerable to fraud than transactions conducted with a physical card present (in which case the retailer may have the ability to check photo ID as part of the verification step).

[0003] Currently, transaction cards typically have a "card verification value" (CVV) code (e.g., a three-digit number for VISA or MasterCard, or a four-digit number for American Express), typically printed on the back of the card, which retailers can request as proof that the card is actually in the possession of the individual performing a card-not-present transaction. CVV can also be referred to as "CVV2" (second generation card verification value), "CVC" (card verification code), or "CSC" ("card security code"), and the use of such codes is commonly referred to as card verification methods ("CVMs") and, therefore, as "CVM codes" or "CVM numbers." For ease of naming, "CVV" is used herein as a generic term without being limited to any particular type of code.

[0004] Unfortunately, associated information associated with a card can sometimes be compromised along with the CVV. One measure to prevent fraud has been to provide a CVV that changes frequently. As used herein, the term "static CVV" refers to a CVV that does not change essentially, such as a printed code on the back of a transaction card, and is only changed when a new physical card is issued. As used herein, the term "dynamic CVV" refers to a CVV that changes more frequently than when a new physical card is issued. In some instances, the CVV may be changed after every transaction to prevent the CVV used in an initial transaction from being fraudulently obtained and then used fraudulently in a subsequent transaction. In other instances, the dynamic CVV is not limited to a period or frequency of dynamic changes, but may be changed less frequently, such as on a regular basis (e.g., daily, weekly, hourly, monthly, upon request, etc.).

[0005] Some cards may have a display built into the card that is configured to display the dynamic CVV, such as an LED, LCD, liquid paper, or other electronic display. Other cards may be combined with a mobile device in which application software (e.g., an application) stored in a computer memory and readable by a processor, the application software comprising machine-readable instructions for causing the processor to perform various method steps, can be programmed to provide the dynamic CVV to the cardholder via an application associated with the transaction card.

[0006] Once the dynamic CVV is provided as part of a transaction (e.g., by entering transaction information through an Internet portal on a website hosted by an Internet retailer), the remainder of the transaction can be conducted in the same manner as is known for using a static CVV, including verifying the dynamic CVV as provided during the transaction against a stored CVV associated with the card number. While various methods of generating CVVs are known, transaction card issuers are constantly seeking ways to make transactions more secure to prevent fraud. Accordingly, there is a need in the art for new methods and systems for processing transactions that use dynamic CVVs. Summary of the Invention

[0007] One aspect of the invention includes a method for providing a dynamic card verification value (dCVV) to a user of a transaction account associated with a transaction device, such as a transaction card. A mobile device associated with the user and the transaction account initiates a non-payment communication, such as near-field communication (NFC), with the transaction card, receives a message from the transaction card in the non-payment communication, sends a prompt to an IP address or web address over a global computer information network, and receives a secure communication containing the dCVV in response to the prompt. The dCVV code is then provided to the user visually, audibly, or tactilely, such as via the mobile device. The dCVV can originate from a server accessible from the IP address or web address and associated with a dCVV generation processor configured to generate a dCVV code in response to the prompt. The mobile device can be connected to the Internet.

[0008] In some embodiments, the message received by the mobile device from the transaction card is configured to cause the mobile device to open a module of application software, the application software being programmed with the web address or IP address to which the prompt in step (c) is directed. In other embodiments, the message received by the mobile device from the transaction card includes the web address or IP address.

[0009] In some embodiments, the mobile device can initiate the non-payment communication after an interaction between the mobile device and the transaction instrument, such as a tap (e.g., a card tap) with the transaction instrument on the mobile device. In some embodiments, the mobile device can initiate the non-payment communication through a user interface of a module of the application software. In some embodiments, the mobile device receives a prompt from a web page generated by the web page in response to input of information on the web page, the prompt from the web page causing the mobile device to send the non-payment communication.

[0010] The method may further comprise a user of the transaction equipment providing the dCVV code as part of the transaction information to a transaction portal via a global computer information network, and may further comprise a transaction processor associated with the transaction portal communicating the transaction information, including the dCVV code, to a payment transaction clearinghouse (an institution for settling transactions), which then typically authenticates the transaction, such as by verifying that the dCVV code provided by the cardholder matches the dCVV code generated by the dCVV generation processor.

[0011] Another aspect of the invention is a system for processing a transaction using a transaction device. The system includes a transaction device (such as a transaction card) having a device passive proximity communication interface (e.g., a near field communication (NFC) interface), a device memory, and a device processor; a mobile device having a mobile device memory, a mobile device processor, a mobile device user interface, a mobile device proximity coupled device interface (e.g., the NFC interface), and a telecommunications interface configured to connect to a global computer information network; and a computer server connected to or in communication with an IP address or web address and connected to a dCVV code generation processor. Instructions contained in the device memory and readable by the device processor are configured to, when triggered by a first non-payment communication, cause the device proximity communication interface to return a message via a second non-payment communication. The mobile device memory includes instructions contained therein and readable by the mobile device processor that are configured to cause the mobile device to initiate a first non-payment communication from the mobile device to the transaction equipment, receive a message from the transaction equipment via a second non-payment communication from the transaction equipment to the mobile device, and, in response to receiving the message from the transaction equipment, send a prompt from the telecommunications interface to an IP address or web address over a global computer information network. The computer server is configured to, in response to receiving the prompt from the mobile device, cause the dCVV code generation processor to generate a dynamic card verification value (dCVV) code. The computer server is further configured to send a secure communication to the mobile device over the global computer information network that includes the dynamic CVV code.

[0012] The system may further include a transaction portal accessible from the global computer information network and configured to receive transaction information including the dynamic CVV via the global computer information network. A transaction processor in communication with the transaction portal and configured to process payment transactions may be configured to receive the transaction information including the dynamic CVV code from the transaction portal and communicate the transaction information to a payment transaction clearinghouse via the global computer information network. A payment transaction clearinghouse connected to the global computer information network and in communication with the transaction processor and a computer server connected to the dCVV code generation processor may include computer memory and a computer processor. The payment transaction clearinghouse is configured to receive the transaction information from the transaction processor via the global computer information network, authenticate the transaction by verifying that the dCVV code provided with the transaction information matches the dCVV generated by the dCVV code generation processor, and communicate an authentication verification to the transaction processor via the global computer information network.

[0013] In some embodiments, the message received by the mobile device from the transaction equipment can be configured to cause the mobile device to open an application software module, the application software being programmed with a web address or IP address to which the prompt in step (c) is directed. In some embodiments, the message received by the mobile device from the transaction card includes a web address or IP address. In some embodiments, the mobile device is configured to initiate a non-payment communication in response to an interaction between the mobile device and the equipment, such as a card tap on the mobile device. In some embodiments, the mobile device is configured with instructions to cause the mobile device to initiate a non-payment communication in response to receiving a prompt from a user interface. In some embodiments, a web page containing machine-readable instructions resident on a computer processor is configured to trigger the mobile device to initiate a payment communication in response to inputting information on the web page.

[0014] Yet another aspect of the invention includes a mobile device comprising a memory, a processor, a user interface, a proximity-coupled communications interface (e.g., a near field communication (NFC) interface), a telecommunications interface configured to connect to a global computer information network, and at least one of a display, a sound generator, and a tactile stimulus generator. The processor-readable instructions contained in the memory are configured to cause the mobile device to perform the steps of: initiating a non-payment communication with a transaction equipment associated with the mobile device; receiving a second non-payment communication from the transaction equipment including the NFC message; in response to receiving the NFC message, sending a prompt to an IP address or web address via the global computer information network; receiving a secure communication from the IP address or web address including the dCVV code; and communicating the dCVV code visually via the display, audibly via the sound generator, or tactilely via the tactile stimulus generator.

[0015] Yet another aspect of the invention includes a transaction equipment having a passive proximity communications interface, a memory, and a processor. The memory contains processor-readable instructions configured to, when triggered by a first non-payment communication from a mobile device, cause the passive proximity communications interface to return a message via a second non-payment communication. The message comprises an IP address or web address, or instructions for opening an application software module on the mobile device, the application software configured with the IP address or web address. The transaction equipment may further include a contactless payment module, in which case the memory may further include processor-readable instructions for causing the contactless payment module to perform one or more payment communications with a transaction card reader. The transaction equipment may have a first separate memory or memory portion, a first separate processor or processing portion, and a first separate passive proximity communications interface configured to perform the first and second non-payment communications, and a second separate memory or memory portion, a second separate processor or processing portion, and a second separate passive proximity communications interface configured to perform the one or more payment communications. In an embodiment, the transaction device may be a transaction card, and the contactless payment module may be a dual interface (DI) module having contacts for physical contact with a card reader. The card may further include a magnetic stripe, a machine-readable code, a human-readable indicia comprising information required to perform a payment transaction, or a combination thereof. The human-readable indicia may include embossed, printed, or laser-coded alphanumeric information. The card may have at least one layer comprising metal, ceramic, or glass.

[0016] Yet another aspect of the invention comprises a method for initiating a dynamic card verification value (dCVV) code request, the method comprising the steps of providing a transaction device as described herein, receiving a first non-payment communication, and returning a message via a second non-payment communication, the IP address or web address connecting itself to a system configured to generate and return a dCVV in response to a prompt.

[0017] Yet another aspect of the invention is a dynamic card verification value (dCVV) code generation system including a computer server connected to or in communication with a unique IP address or web address on a global computer information network, a dCVV code generation processor connected to the computer server, and a communications interface configured to send a secure communication over the global computer information network. In response to receiving a prompt from a mobile device via the IP address or web address, the system is configured to cause the dCVV code generation processor to generate a dCVV code and to send the secure communication including the dCVV code in a secure communication over the global computer information network to a secure location accessible to the cardholder. The dCVV code generation system can also be configured to send the secure communication including the dCVV code to the mobile device. The system can be configured to receive the prompt via a first type of communications protocol and send the secure communication via a second type of communications protocol.

[0018] Yet another aspect of the invention includes a method for providing a dynamic card verification value (dCVV) code, the method comprising providing a dCVV code generation system accessible via an IP address or web address as described herein, receiving a prompt from a mobile device, generating a dCVV code, and transmitting a secure communication to a secure location.

[0019] Yet another aspect of the invention includes a non-transitory computer memory medium comprising machine-readable instructions that cause a mobile device to perform the following method steps: associate a transaction account and a transaction instrument with the mobile device; initiate a first non-payment communication with the transaction instrument using a communications interface embedded in the mobile device; receive a second non-payment communication from a transaction card containing a message; send a prompt via the telecommunications interface of the mobile device to an IP address or web address over a global computer information network; receive a secure communication from the IP address or web address containing a dCVV code; and communicate the dCVV code visually via a display, audibly via a sound generator, or tactilely via a tactile stimulus generator embedded in the mobile device. In some embodiments, at least a portion of the memory is embedded in the mobile device. In some embodiments, at least a portion of the memory is embedded in a server accessible by the mobile device over a global computer information network. The machine-readable instructions can include instructions corresponding to application software configured to store the IP address or web address. The machine-readable instructions may also include instructions for initiating a non-payment communication in response to an interaction between the mobile device and the transaction instrument, such as in response to tapping (e.g., card tapping) of the transaction instrument on the mobile device. The machine-readable instructions may also include instructions for causing the mobile device to initiate a non-payment communication in response to receiving a prompt from a user interface. [Brief explanation of the drawings]

[0020] [Figure 1] FIG. 1 illustrates an exemplary system embodiment in accordance with the present invention.

[0021] [Figure 2] FIG. 2 shows a flowchart of an exemplary method embodiment according to the present invention. DETAILED DESCRIPTION OF THE INVENTION

[0022] Referring now to FIG. 1 , an example system 100 for processing transactions using a transaction card 110 is shown. The example transaction card 110 is shown exploded, with various components internal and external to the card schematically illustrated. The locations of the various components are not limited to those shown. The transaction card 110 includes a card near field communication (NFC) interface 112, a card memory 114, and a card processor 116. The card memory 114 and the card processor 116 may be securely combined on a single “secure element” chip. The aforementioned electronic components may be stored on one or more integrated circuit (IC) chips embedded in the card. In some embodiments, one or more of the card memory 1114, the card processor 1116, and the NFC interface 1112 may be provided as separate and distinct from the NFC interface 112, the card memory 114, and the card processor 116. In one embodiment, memory 1114, processor 1116, and NFC interface 1112 may be provided for performing card-present physical payment transactions, and memory 1114, processor 116, and NFC interface 112 may be provided for performing non-payment transactions in accordance with method embodiments, such as card-not-present financial transactions, as discussed further herein. In other embodiments, card memory 114, card processor 116, and NFC interface 112 may be configured to process both payment and non-payment transactions. In yet other embodiments, memory 1114 may be a separate portion of memory 114, processor 1116 may be co-located with processor 116 on a single dual-processor chip, and a single NFC interface 112 controllable by both processors 1116 and 116 may be provided with appropriate spacing between memory portion 1114 and the rest of memory 114 so that a security breach in memory 114 does not result in a path to breaching memory portion 1114.

[0023] Physical (card present) financial transactions can be performed via a point-of-sale (POS) card reader (not shown) that reads information from the payment module 10. The payment module 10 may be a dual interface (DI) integrated circuit IC chip, as is well known in the art, operable to provide payment information to the card reader either through physical contact with the card reader through contacts accessible from the surface of the card, or through contactless communication with a radio frequency identification (RFID) chip included in the module.

[0024] As shown, front surface 111 of card 110 also bears printed, embossed, or laser-etched indicia forming the card number and the cardholder's name. Back surface 113 of card 110 (shown rotated 180 degrees about axis A for illustrative purposes) displays magnetic stripe 12 and machine-readable code 14, which may be a barcode, QR code, or any code known in the art. While not shown, the card may have other features / characteristics commonly found on cards, such as, but not limited to, a security hologram, a photo of the cardholder, a signature stripe, a biometric reader, a display screen, decorative features, etc. Additional human- and / or machine-readable indicia may also be provided, such as issuing financial institution information (e.g., bank name), card branding (e.g., VISA®, AMERICAN EXPRESS®, MASTERCARD®, etc.), expiration date, membership club information, affinity information (e.g., branding associated with a university, sports team, charitable cause, etc.), etc. The various functions / features shown on card 110 are not limited to any particular location. Without being limited to any particular type of card, an example card may comprise at least one layer that is metal, ceramic, and / or glass, such as the composites shown in one or more co-pending applications owned by CompoSecure, Inc., a common assignee of the present application.

[0025] As described further herein, the machine-readable instructions contained in the card memory are readable by the card processor and, when triggered by an incoming non-payment NFC communication 132, are configured to cause the card NFC interface to return information 133 via an outgoing non-payment NFC communication 136. The NFC communication may take the form of an NFC Data Exchange Format (Ndef) message. The information 133 may include information identifying an IP address or web address 134, or the information may cause a module of application software (i.e., an “application”) to be opened on the mobile device that can provide a web or IP address. The card memory 114 may also include instructions to cause the card processor 116 to perform operational steps for conducting a financial transaction (e.g., for providing card information to a card reader as a payment NFC communication or in response to appropriate prompts via contacts on the card), or discrete memory and processor may be associated with functionality for conducting a financial transaction, with the memory 114 and processor 116 dedicated solely to executing the method and system for generating a dynamic CVV (dCVV) as described herein.

[0026] Mobile device 120 (e.g., a cellular telephone, tablet, handheld computer, etc., with NFC capabilities) has mobile device memory 122, mobile device processor 124, mobile device user interface 126 (e.g., without limitation, a touchscreen, voice command capabilities, virtual keyboard capabilities), mobile device display 127 (which may include a majority of the surface area of ​​the device), mobile device NFC interface 128, and telecommunications interface 129 configured to connect to a global computer information network 130. A mobile device is typically associated with a transaction card by the cardholder downloading application software (the "application") associated with the card's issuer (e.g., VISA®, AMERICAN EXPRESS®, MASTERCARD®, a financial institution such as a bank, credit union, brokerage firm, etc.), entering information, and performing other processes that associate the application and device with the card and cardholder. As will be appreciated by those skilled in the art, application software utilized on a mobile device may include a "thin" portion that resides in the mobile device's local computer memory and a "thick" portion that resides "in the cloud" (e.g., on a server accessible to the mobile device via the global computer information network 130). The application software comprises machine-readable instructions contained in a memory that, when read by a machine, cause a processor to perform corresponding method steps.

[0027] The instructions contained in the mobile device memory 122 are readable by the mobile device processor 124 and are configured, when triggered via the user interface 126, to cause the mobile device 120 to perform certain method steps as described herein, including initiating a non-payment NFC communication 132 with the transaction card (outgoing from the mobile device and into the card), receiving information 133 including an IP address or web address 134 from the transaction card via a non-payment NFC communication 136 from the transaction card (outgoing from the card but into the mobile device), and sending a prompt 138 to the IP address or web address via the global computer information network 130.

[0028] In embodiments in which information 133 (e.g., an Ndef message) sent from the card to the mobile device opens an application, all cards can be programmed to send the same Ndef message, and each application can be configured to include unique information corresponding to the web or IP address to which the prompt 138 is directed. In other embodiments, the secure elements 114, 116 can be personalized with unique IP addresses communicated as information 133 in the Ndef message. In some embodiments, the NFC communication 132 can be triggered by an interaction between the card and the mobile device, such as a card tap that causes the phone to sense the RFID chip on the card and trigger the initial NFC communication. In application-driven embodiments, the user can first open an application on the mobile device and have the application send a non-payment NFC communication 132 to the card. In other embodiments, the user can trigger a non-payment NFC communication by entering information on a web page (e.g., a checkout web page where payment information is entered), which causes the mobile device to send a communication that triggers the mobile device to initiate a non-payment NFC communication to the card.

[0029] As depicted herein, communications from one element to another in Figure 1 are shown as going directly from one component to another, but it should be understood that because each of the devices is connected through the illustrated nodes (indicated by the black dots attached to the lines emanating from each device) that are connected to a "global computer information network" (a presently non-limiting example of which is commonly referred to as the "Internet" or "World Wide Web") 130, communications can travel from one connected device to another through various switches, relays, servers, nodes, etc., and can include, without limitation, wired and wireless communications using any of a variety of protocols known in the art. Communications can be encrypted for security purposes.

[0030] The computer server 140 includes a processor 142 for generating a dynamic card verification value (dCVV), such as, for example, "1234" or "931," shown in the figure as "####," but not limited to any number of digits. While the code is typically a numeric code, the code is not so limited and may be, for example, any code formed from alphanumeric characters or a combination of alphanumeric characters and special characters (e.g., #, $, %, &, @, etc.). The computer server 140 is connected to or in communication with the IP address or web address 134 and, in response to a prompt 138 from the mobile device, is programmed with instructions to cause the dCVV generation processor 142 to generate a dCVV code and send a secure communication 146 containing the dynamic CVV code to the mobile device via the IP address or web address over the global computer information network 130. The term "secure communication" typically refers to an encrypted text message, encrypted email, or encrypted communication sent over the Internet, decrypted by a device or carrier, and presented by an application on a mobile device associated with the transaction card. The secure communication is typically sent over a cellular telephone network, without being limited to any particular technology (e.g., GSM, CDMA, LTE, etc.) or generation (e.g., 4G, 5G, etc.), such as, but not limited to, via Short Messaging Service (SMS) or via an XML message sent over a Secure Sockets Layer (SSL) connection with authentication (e.g., using a digital certificate). In contrast, the prompt received by the server 140 from the mobile device can use a different communication protocol, such as Hypertext Transfer Protocol (HTTP), or any standard communication protocol over the Internet, such as HTTP over Transport Layer Security (TLS), or SSL. While the secure communication containing the dCVV is sent to the mobile device in some embodiments, the invention is not so limited.The secure communication containing the dCVV can be sent to any secure location accessible to the cardholder. By way of non-limiting example, the communication can be sent to an email address or to a designated mobile device that is different from the initiating mobile device.

[0031] A point-of-sale (POS) transaction portal 180 connected to the transaction processor 150 and the global computer information network 130 is configured to receive transaction information 162, including the dCVV, from the cardholder transaction input device 160 as part of a card-not-present transaction via the global computer information network and send the transaction information to the transaction processor. The transaction processor 150, connected to the global computer information network 130 (either separate from the POS transaction portal 180 or co-located with the POS transaction portal 180), is configured to receive input transaction information 162, including the dCVV code, relayed by the POS transaction portal from the cardholder transaction input device 160 and cause the transaction information 162 to be communicated via the global computer information network to a payment transaction clearinghouse 170. The payment transaction clearinghouse 170 is in communication with the transaction processor 150 and the computer server 140 via the global computer information network 130 (or via any means known in the art) and includes a computer memory 172 and a computer processor 174. The payment transaction clearinghouse is configured to receive transaction information from the transaction processor via a global computer information network, authenticate the transaction by verifying that the dCVV code provided with the transaction information matches the dCVV code generated by the dCVV generation processor, and send authentication verification 176 to the transaction processor via the global computer information network.

[0032] In typical operation, cardholder transaction input device 160 typically accesses POS transaction portal 180 via a global computer information network. While shown as a laptop computer, cardholder transaction input device 160 may include a mobile device (which may, but is not necessarily, be the same mobile device 120 used to perform other steps in the method), a computer, a tablet, a kiosk, a telephone interface including a human operator assisted interface in which a human transfers information verbally transmitted over the telephone to an internet connected device, an automated interface with voice recognition and / or activated by touch-tone prompts, a gaming system, or any device now known in the art or in the future that can receive input of transaction information via a card not present transaction. It should be noted that, while specifically tailored for card-not-present transactions, the invention is not limited thereto, and there may be situations in which the cardholder transaction input device 160 may be a typical card reader known in the art (e.g., capable of reading information from a physical card via payment NFC communications, or via an RFID chip, contact chip reader, magnetic stripe reader, barcode reader, etc.) associated with a user interface for receiving input comprising a dCVV. As used herein, the term "cardholder" is not limited to an authorized user of a card, but refers to any person who performs a transaction using a transaction card and dynamic CVV.

[0033] During the overall process of conducting a payment transaction, the cardholder transaction input device 160 is typically queried by the POS transaction portal 180 for transaction information 162, which may include any or all of the cardholder's name, card number, cardholder address information (including one or all of street address, house or unit number, city, state, county, and zip code), and optionally the cardholder's telephone number and dCVV. Providing the dCVV as part of the transaction information includes performing the steps of an example method 200 shown in FIG. 2, according to one embodiment of the invention.

[0034] At step 210 of method 200, the cardholder initiates a non-payment NFC communication between the transaction card 110 and a mobile device 120 connected to the Internet 130. At step 220, the card sends (and the mobile device receives) information 133 corresponding to an IP address or web address 134 from the transaction card 110 in the non-payment NFC communication, and at step 230, the mobile device 120 sends a prompt to the IP address or web address 134 via the Internet 130. At step 240, a dCVV generation processor connected to or in communication with the IP address or web address generates a dCVV code in response to the prompt. At step 250, the server sends a secure communication including the dCVV code to the mobile device, and the mobile device relays the dCVV number to the cardholder (e.g., by visually displaying the dCVV number, or by other means, e.g., audibly and / or tactilely via a Braille generator for individuals with visual and / or hearing impairments). The cardholder then provides the dCVV to the transaction processor (e.g., via cardholder transaction input device 160) in step 260. In step 270, the transaction processor communicates transaction information, including the cardholder-supplied dynamic CVV, to a payment transaction clearinghouse. In step 280, the payment transaction clearinghouse authorizes the transaction, which typically includes verifying that the cardholder-supplied dynamic CVV matches the dynamic CVV generated by the CVV generation processor.

[0035] To the extent reference is made herein to a "transaction card," suitable cards include those conforming to the ISO / IEC 7810 ID-1 standard, with lateral dimensions of 85.60 x 53.98 mm (3 3 / 8 inches x 2 1 / 8 inches), rounded corners with a radius of 2.88 to 3.48 mm (approximately 1 / 8 inch), and an overall thickness of 0.76 mm (1 / 32 inch), although the invention is not limited to cards having any particular size, shape, or aspect ratio. Similarly, while primarily described herein with reference to implementations using transaction cards, it should be understood that the methods and systems described herein can be implemented using devices other than cards. For example, any passive proximity integrated circuit (i.e., a circuit configured to return a signal in response to a query event, such as movement through a field, or in response to receiving a signal generated by a reader) readable by any proximity coupling device (i.e., a reader configured to generate a query event) can be used to perform the method steps. Thus, the role of a "transaction card" as described herein can be performed by any transaction device of any shape and size that has passive proximity circuitry configured to couple to a proximity coupling device and exchange messages as described herein. Thus, in addition to traditional "cards," passive transaction devices used in connection with various embodiments of the invention can include watches, rings, wristbands, jewelry, and key fobs, without being limited to any particular type of device. Accordingly, the use of the term "dynamic card verification value" and its abbreviation, dCVV, in the claims herein is not intended to limit the claimed invention solely to embodiments that use traditional transaction cards, and no such limitation should be inferred from the use of such term. Additionally, although discussed primarily herein in the context of NFC communications, the invention is not limited to any particular communication protocol or proximity for non-payment communications between a mobile device and a transaction device.Rather, any configuration of passive transaction equipment may be used to exchange messages as contemplated herein, using any method of communication between the mobile device and the transaction equipment.

[0036] Although the invention has been illustrated and described herein with reference to specific embodiments, the invention is not intended to be limited to the details shown. Rather, various modifications can be made in the details, within the scope and range of equivalents of the claims, without departing from the invention.

Claims

1. 1. A method for providing a dynamic card verification value (dCVV) to a user of a transaction equipment, comprising: (a) the user and a mobile device associated with an account associated with the transaction instrument initiating a non-payment communication with the transaction instrument; (b) the mobile device receiving a message from the transaction instrument in the non-payment communication; (c) the mobile device sending a prompt to an IP address or a web address over a global computer information network; (d) receiving, by the mobile device in response to the prompt, a secure communication including the dCVV code; (e) providing the dCVV to the user.

2. 10. The method of claim 1, wherein the transaction device is a transaction card.

3. 2. The method of claim 1, wherein the non-payment communication is near field communication (NFC).

4. 2. The method of claim 1, wherein the communication containing the dCVV originates from a server associated with a dCVV generation processor configured to generate the dCVV code.

5. 10. The method of claim 1, further comprising providing the dCVV code to the user via the mobile device.

6. 6. The method of claim 5, wherein the mobile device provides the dCVV code visually, audibly, or tactilely.

7. The method of claim 1, wherein the mobile device is connected to the Internet.

8. 2. The method of claim 1, wherein the message received by the mobile device from the transaction equipment is configured to cause the mobile device to open an application software module programmed at the web address or IP address to which the prompt in step (c) is directed.

9. 2. The method of claim 1, wherein the message received by the mobile device from the transaction equipment includes the web address or IP address.

10. 10. The method of claim 1, wherein the mobile device initiates the non-payment communication after an interaction between the mobile device and the transaction equipment.

11. 11. The method of claim 10, wherein the interaction between the mobile device and the transaction instrument is a tap on the mobile device.

12. 10. The method of claim 1, wherein the mobile device initiates the non-payment communication through a user interface of an application software module.

13. 2. The method of claim 1, wherein the mobile device receives a prompt from the web page that is generated by the web page in response to input of information on the web page, causing the mobile device to send the non-payment communication.

14. 2. The method of claim 1, further comprising the step of: (f) the user of the transaction equipment providing the dCVV code as part of transaction information to a transaction portal via the global computer information network.

15. 15. The method of claim 14, further comprising: (g) a transaction processor associated with the transaction portal communicating the transaction information, including the dCVV code, to a payment transaction clearinghouse.

16. 16. The method of claim 15, further comprising: (h) the payment transaction clearinghouse authenticating the transaction, including verifying that the dCVV code provided by the cardholder matches the dCVV code generated by a dCVV generation processor.

17. 1. A system for processing transactions using a transaction device, comprising: a transaction device having a device passive communication interface, a device memory, a device processor, and instructions contained in the device memory and readable by the device processor, the instructions configured, when triggered by a first non-payment communication, to cause the device passive communication interface to return a message via a second non-payment communication; 1. A mobile device having a mobile device memory, a mobile device processor, a mobile device user interface, a mobile device communication interface configured to communicate with the passive communication interface of the transaction equipment, and a telecommunications interface configured to connect to a global computer information network, the mobile device memory having instructions contained therein and readable by the mobile device processor, the instructions causing the mobile device to: (a) initiating the first non-payment communication from the mobile device to the transaction equipment; (b) receiving the message from the transaction instrument via the second non-payment communication from the transaction instrument to the mobile device; and (c) a mobile device configured to cause a prompt to be transmitted from the telecommunications interface to an IP address or a web address over the global computer information network in response to receiving the message from the transaction card; a computer server connected to or in communication with the IP address or web address and connected to a dCVV code generation processor, the computer server configured to, in response to receiving the prompt from the mobile device, cause the dCVV code generation processor to generate a dynamic card verification value (dCVV) code, and further configured to send a secure communication to the mobile device over the global computer information network that includes the dynamic CVV code.

18. 20. The system of claim 17, wherein the transaction device comprises a transaction card.

19. 20. The system of claim 17, wherein the passive communication interface comprises a near field communication (NFC) interface, and the non-payment communication comprises an NFC communication.

20. 18. The system of claim 17, further comprising a transaction portal accessible from the global computer information network and configured to receive transaction information including the dynamic CVV via the global computer information network.

21. 21. The system of claim 20, further comprising a transaction processor in communication with the transaction portal and configured to process payment transactions, the transaction processor configured to receive the transaction information from the transaction portal, the transaction information including the dynamic CVV code, and communicate the transaction information to a payment transaction clearinghouse via the global computer information network.

22. 22. The system of claim 21, further comprising: a payment transaction clearinghouse connected to the global computer information network and in communication with the transaction processor and the computer server connected to the dCVV code generation processor, the payment transaction clearinghouse comprising computer memory and a computer processor, configured to receive the transaction information from the transaction processor via the global computer information network, authenticate the transaction by verifying that the dCVV code provided with the transaction information matches the dCVV code generated by the dCVV code generation processor, and send authentication verification to the transaction processor via the global computer information network.

23. 18. The system of claim 17, wherein the message received by the mobile device from the transaction equipment is configured to cause the mobile device to open a module of app software programmed at the web address or IP address to which the prompt in step (c) was directed.

24. 18. The system of claim 17, wherein the message received by the mobile device from the transaction equipment includes the web address or IP address.

25. 18. The system of claim 17, wherein the mobile device is configured to initiate the non-payment communication in response to an interaction between the mobile device and the transaction equipment.

26. 18. The system of claim 17, wherein the mobile device is configured to initiate the non-payment communication in response to a tap of the transaction instrument on the mobile device.

27. 20. The system of claim 17, wherein the mobile device is configured with instructions to cause the mobile device to initiate the non-payment NFC in response to receiving a prompt from a user interface.

28. 18. The system of claim 17, further comprising a web page containing machine-readable instructions resident on a computer processor, the web page configured to trigger the mobile device to initiate the non-payment communication in response to input of information on the web page.

29. 1. A mobile device, comprising: Memory and a processor; A user interface; a proximity coupling device interface; a telecommunications interface configured to connect to a global computer information network; at least one of a display, a sound generator, and a tactile stimulus generator; a memory readable by the processor and configured to read from the mobile device; (a) initiating a first non-payment communication with a transaction instrument associated with a transaction account associated with the mobile device; (b) receiving a second non-payment communication from the transaction equipment, the second non-payment communication including a message; (c) in response to receiving the message, sending a prompt to an IP address or a web address over a global computer information network; (d) receiving a secure communication from said IP address or web address, said secure communication including a dCVV code; (e) communicating the dCVV code visually via the display, audibly via the sound generator, or tactilely via the tactile stimulus generator.

30. 30. The mobile device of claim 29, wherein the proximity coupling device comprises a near field communication (NFC) interface.

31. A transaction device comprising: a passive proximity circuit communication interface; Memory and a processor; 12. The transaction equipment according to claim 11, further comprising: instructions included in the memory, readable by the processor, and configured to, when triggered by a first non-payment communication from a mobile device, cause the passive proximity circuit communication interface to return a message via a second non-payment communication comprising information selected from an IP address or a web address, or instructions for opening an application software module configured with the IP address or the web address on the mobile device.

32. 32. The transaction device of claim 31, wherein the passive proximity circuit communication interface comprises a near field communication (NFC) interface.

33. 33. A transaction device according to claim 31 or 32, wherein the transaction device further comprises a contactless payment module.

34. 34. The transaction device of claim 33, wherein the memory further comprises instructions readable by the processor that cause the contactless payment module to perform one or more payment communications with a card reader.

35. 35. The transaction equipment of claim 34, wherein the equipment comprises one or more of a first separate memory or memory portion, a first separate processor or processing portion, and a first separate interface configured to effectuate the first and second non-payment communications, and one or more of a second separate memory or memory portion, a second separate processor or processing portion, and a second separate interface configured to effectuate the one or more payment communications.

36. 36. A transaction device according to any one of claims 31 to 35, wherein the transaction device comprises a transaction card.

37. 37. The transaction device of claim 36, wherein the transaction device comprises a transaction card, and the contactless module comprises a dual interface (DI) that also comprises contacts for physical connection to a card reader.

38. 38. The transaction device of claim 37, further comprising one or more of a magnetic stripe, a machine-readable code, and a human-readable indicia comprising information required to conduct a payment transaction.

39. 40. The transaction device of claim 38, wherein the human readable indicia comprises embossed, printed, or lasered alphanumeric information.

40. 40. The transaction device of any one of claims 36 to 39, wherein the transaction card comprises at least one layer comprising metal, ceramic, or glass.

41. 1. A method for initiating a dynamic card verification value (dCVV) code request, comprising: (a) providing a transaction device according to any one of claims 31 to 40; (b) receiving the first non-payment communication; (c) returning the message via the second non-payment communication; The method, wherein the IP address or web address connects to a system configured to generate and return the dCVV in response to a prompt.

42. 1. A dynamic card verification value (dCVV) code generation system, comprising: a computer server connected to or in communication with the unique IP address or web address via a global computer information network; a dCVV code generation processor connected to said computer server; 1. A system comprising: a communications interface configured to send secure communications over the global computer information network; The system is configured to, in response to receiving a prompt from a mobile device via the IP address or web address, cause the dCVV code generation processor to generate a dCVV code and transmit a secure communication including the dCVV code via secure communication over the global computer information network to a secure location accessible to the cardholder.

43. 43. The dCVV code generation system of claim 42, wherein the system is configured to transmit the secure communication including the dCVV code to the mobile device.

44. 44. The dCVV code generation system of claim 43, wherein the system is configured to receive the prompt via a first type of communication protocol and to send the secure communication via a second type of communication protocol.

45. 1. A method for providing a dynamic card verification value (dCVV) code, comprising: (a) providing the dCVV code generation system of any one of claims 42 to 44 accessible via said IP address or web address; (b) receiving the prompt from the mobile device; (c) generating the dCVV code; (d) transmitting said secure communication to said secure location.

46. A non-transitory computer memory medium comprising instructions, the instructions being machine-readable, and configured to include: (a) the method steps of associating a transaction account and a transaction instrument with the mobile device; (b) initiating a first non-payment communication with the transaction equipment using a communication interface embedded in the mobile device; (c) receiving a second non-payment communication from the transaction card, the second non-payment communication including a message; (d) transmitting a prompt via a telecommunications interface of the mobile device to an IP address or a web address over a global computer information network; (e) receiving a secure communication from said IP address or web address, said secure communication including a dCVV code; (f) communicating the dCVV code visually via a display, audibly via a sound generator, or tactilely via a tactile stimulus generator embedded in the mobile device.

47. 47. The non-transitory computer memory medium of claim 46, wherein the instructions comprise instructions for sending the first non-payment communication and the second non-payment communication as near field communication (NFC) communications.

48. 47. The non-transitory computer memory medium of claim 46, wherein at least a portion of the memory is embedded in the mobile device.

49. 47. The non-transitory computer memory medium of claim 46, wherein at least a portion of said memory is embedded in a server accessible by said mobile device over said global computer information network.

50. 47. The non-transitory computer memory medium of claim 46, wherein the instructions include instructions corresponding to application software configured to store the IP address or web address.

51. 47. The non-transitory computer memory medium of claim 46, wherein the instructions include instructions for initiating the non-payment communication in response to an interaction between the mobile device and the transaction equipment.

52. 52. The non-transitory computer memory medium of claim 51, wherein the instructions include instructions for initiating the first non-payment communication in response to tapping the transaction instrument on the mobile device.

53. 47. The non-transitory computer memory medium of claim 46, wherein the instructions include instructions for causing the mobile device to initiate the non-payment communication in response to receiving a prompt from a user interface.