Dynamic CVV Generation Using One-Time Passwords for Card Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current identity verification and financial transaction systems rely on static CVV codes, which do not provide strong assurance of card possession and are vulnerable to misuse, especially in online transactions.

Innovation Solution

Integration of a one-time password (OTP) generator into credit/debit cards to generate a dynamic CVV, which can be used as a security code for transactions, eliminating the need for a separate OTP token and enhancing security by ensuring the card is present during authentication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a static CVV code is used for authentication, then the system is simple to implement, but the security against unauthorized transactions is weak

Engineering Contradiction:
Improvesecurity against unauthorized transactionsVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies dynamics by transforming the static CVV code into a dynamic one that changes over time. The system generates new CVV codes periodically or per-transaction, making each code valid only for a specific time window or single use. This dynamic approach ensures that even if a CVV is intercepted, it becomes invalid after use, significantly improving security against unauthorized transactions while maintaining system manageability through automated code generation and rotation.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent implements parameter changes by modifying the CVV code characteristics - specifically making the code value changeable over time rather than fixed. The system alters the CVV parameter dynamically based on time, usage count, or transaction context. This parameter transformation from static to dynamic resolves the contradiction by enhancing security through code variability while the automated management of these changes prevents excessive system complexity.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If a separate OTP token is required for authentication, then the security assurance is enhanced, but the ease of operation is reduced

Engineering Contradiction:
Improveassurance of card possessionVSAvoidtransaction convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies merging by integrating the OTP generation functionality directly into the credit/debit card itself. Instead of requiring a separate physical token or device, the card incorporates a microprocessor and memory that can generate and store dynamic CVV codes. This consolidation combines the card and OTP token functions into a single device, maintaining the security benefits of dynamic authentication while eliminating the need for users to carry and coordinate multiple separate authentication devices, thereby improving ease of operation.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements multi-functionality by enabling the credit/debit card to perform both its traditional payment function and the additional function of generating dynamic authentication codes. The card's microprocessor can generate CVV codes for online transactions, and the card itself can serve as the authentication token. This universal design allows the single card to fulfill multiple security roles, enhancing card possession assurance while simplifying the user experience by eliminating the need for separate OTP tokens.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If a dynamic CVV is generated using OTP, then the security for online transactions is improved, but the device complexity increases

Engineering Contradiction:
Improvetransaction securityVSAvoidcard structure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies self-service by enabling the card to generate its own dynamic CVV codes autonomously without requiring external authentication devices or complex user interactions. The microprocessor within the card automatically generates and manages the OTP-based CVV codes, storing them in onboard memory. This self-service capability allows the card to perform authentication functions independently, improving transaction security through dynamic code generation while avoiding the need for additional external security devices that would increase overall system complexity.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9501774B2Method and apparatus for using at least a portion of a one-time password as a dynamic card verification value
Publication Date: 2016.11.22 BANK OF AMERICA CORP
  • US9501774B2 patent drawing
  • US9501774B2 patent drawing
  • US9501774B2 patent drawing

AI summary

Method and apparatus for using at least a portion of a one-time password as a dynamic card verification value (CVV) are disclosed. A credit/debit card is able to generate a dynamic card verification value (CVV). Such a card may also include an indication that the dynamic CVV is to be used as a security code for purchasing or other transactions. A card-based financial transaction can be authorized in accordance with the use of a dynamic CVV by receiving a transaction authorization request for a specific credit/debit card, wherein the transaction authorization request includes a dynamic CVV. The dynamic CVV can be compared to at least a portion of a one-time password generated for the specific credit/debit card, and a transaction authorization can be sent to the merchant or vendor when the dynamic CVV matches all or a portion of the one-time password.