Dynamic Card Verification Value Authentication Using Segmented Counter Data
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In the credit card industry, skimming fraud persists, especially in wireless transactions, where magnetic stripe data can be easily intercepted and copied, and existing systems using encrypted dynamic card verification values face limitations due to character constraints and security vulnerabilities.
Innovation Solution
A method where only a portion of the dynamic data element, such as a counter value, is transmitted from a payment card or POS terminal to a backend computer, allowing for authentication by calculating candidate verification values and determining the authenticity of transactions, thereby reducing data transmission and enhancing security.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the complete counter value is transmitted in Track data, then the backend can accurately verify the dCVV, but the Track data exceeds the four-character limit and exposes the full counter value to potential interception
Solution Approach 1:
The patent divides the complete counter value into multiple segments, transmitting only a portion (e.g., last four digits) through Track data while keeping other segments secure in the portable device. This segmentation allows verification without exposing the full counter value, resolving the contradiction between verification accuracy and data exposure risk.
Solution Approach 2:
The patent extracts only the necessary portion of the counter value (specifically the last four digits) for transmission in Track data, separating this from the complete counter value that remains protected in the portable device. This extraction enables verification functionality while minimizing exposed information.
2Reliability
If the complete counter value is transmitted in clear text, then the backend can verify the dCVV, but an unauthorized person can intercept and use the counter value for fraudulent transactions
Solution Approach 1:
By segmenting the counter value and transmitting only a non-sensitive portion through Track data, the patent maintains authentication capability while reducing fraud risk. The segmented approach ensures that even if Track data is intercepted, the complete counter value cannot be reconstructed.
Solution Approach 2:
The patent applies preliminary anti-action by encrypting or protecting portions of the counter value before transmission, and by designing the verification process to work with segmented data. This preemptive protection prevents potential fraud before it can occur, rather than relying on post-interception detection.
3Productivity
If more characters are allocated to the counter data field, then the system can accommodate more transactions, but the available space for other data in Track data is reduced
Solution Approach 1:
The patent applies partial action by transmitting only the necessary four-character portion of the counter value through Track data, rather than the complete counter value that would be needed for unlimited transaction tracking. This partial transmission provides sufficient verification capability for the required transaction capacity while preserving space for other data elements.
Data Source
AI summary
A method and computer readable medium for conducting a transaction, comprising receiving a verification value and a portion of a dynamic data element, determining candidate dynamic data elements using the portion of the dynamic data element, calculating candidate verification values using candidate dynamic data elements, and determining if the received verification value matches any of the candidate verification values, wherein the transaction is thereafter authenticated if a candidate verification value matches a candidate verification value.


