Dynamic CVV Generation for Card Not Present Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current credit card systems lack effective security measures for Card Not Present (CNP) transactions, making them vulnerable to fraud as static CVV codes can be compromised, leading to unauthorized remote transactions.

Innovation Solution

A computing system generates a dynamic CVV code through a series of statistical manipulations based on a timestamp, initial code, and personal data, using a predefined formula to create a secret key, which is then used to produce a dynamic CVV code that can be verified by an authentication server, enhancing security by ensuring the code's validity and possession of the card.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a static CVV code is used on the card, then the card can be used for in-person transactions with simple verification, but the CVV can be compromised by unauthorized users who see the card, leading to fraud in remote transactions

Engineering Contradiction:
Improveverification simplicityVSAvoidsecurity against fraud
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms the static CVV code into a dynamic code that changes over time. The CVV is no longer fixed on the card but is generated dynamically based on a secret key, timestamp, and other parameters. This dynamic nature ensures that even if an unauthorized user observes the CVV at one moment, it becomes invalid after a short time period, thereby resolving the security vulnerability while maintaining operational simplicity through automated generation and verification processes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the fundamental parameter of the CVV code from static to dynamic by introducing time-dependency and cryptographic transformation. The CVV code is now a function of multiple parameters including secret key, timestamp, and card-specific data, rather than a fixed value. This parameter transformation allows the system to maintain ease of operation while dramatically improving security against fraud in remote transactions

Inventive Principle:
Principle #35Parameter changes

2Reliability

If the CVV code is made dynamic and time-dependent, then security against fraud is improved, but the complexity of generating and verifying the code increases

Engineering Contradiction:
Improvesecurity against fraudVSAvoidcode generation and verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements self-service by enabling the CVV code to be automatically generated and verified without manual intervention. The cardholder's device automatically generates the dynamic CVV using the secret key and timestamp, and the authentication server independently verifies it using the same algorithm. This automation eliminates the need for complex manual verification procedures, reducing operational complexity while maintaining high security standards

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system incorporates feedback mechanisms where the authentication server verifies the dynamically generated CVV and provides confirmation or rejection of the transaction. This feedback loop ensures that the increased complexity of dynamic CVV generation is offset by automated verification processes, maintaining system reliability while managing complexity through structured interaction between the cardholder's device and the authentication server

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20240144285A1Systems and methods for generating a dynamic CVV and/or pin
Publication Date: 2024.05.02 TICARD PAYMENT SECURITY SOLUTIONS LTD
  • US20240144285A1 patent drawing
  • US20240144285A1 patent drawing

AI summary

A system and method for generating a dynamic Card Verification Value (CVV) code or Personal Identification Number (PIN) code. When a user wishes to perform a financial transaction with a merchant, a mobile application associated with a transaction card generates a dynamic CVV or PIN based on a timestamp, a fixed code and personal user data. The user supplies the received, dynamic CVV or PIN to the merchant. The merchant sends a transaction record of the financial transaction to a clearing server of a financial institute associated with the transaction card. An authentication module within the clearing server, verifies and authenticates the dynamic CVV or PIN and replaces it with the original, fixed CVV or PIN for validation of the financial transaction.