Dynamic Payment Card Account Number Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional payment card security techniques, such as separate signatures and pre-authorization phases, are inadequate and introduce significant modifications to authentication infrastructure and processing delays.
Innovation Solution
A dynamic secure payment card system that uses a time-based or event-based one-time password algorithm to vary a portion of the payment card number, eliminating the need for separate signatures and pre-authorization phases by generating a dynamic account number based on a seed and trigger source, which is then processed by a server to determine a corresponding static account number.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a separate signature is used for authentication, then security is improved, but device complexity and infrastructure modification requirements increase
Solution Approach 1:
The patent merges the authentication signature functionality directly into the account number itself. Instead of using a separate signature field, the account number is dynamically generated by combining a static portion with a variable portion that serves as the authentication signature. This integration eliminates the need for separate signature infrastructure while maintaining security.
Solution Approach 2:
The account number is given multiple functions: it serves both as the identifier and as the authentication signature. The dynamic account number incorporates the variable portion that acts as the signature, allowing the same data element to perform both identification and authentication functions, thereby reducing infrastructure complexity.
2Reliability
If a separate pre-authorization phase is used for every transaction, then security is improved, but processing time increases
Solution Approach 1:
The patent performs preliminary action by pre-computing and storing the static portion of the account number and the cryptographic key material in the payment card before transactions occur. During transactions, the variable portion is dynamically generated using the stored static portion and current transaction parameters, eliminating the need for time-consuming pre-authorization phases while maintaining security.
Solution Approach 2:
The account number transitions from a static value to a dynamic value that changes with each transaction. The variable portion is regenerated based on current transaction parameters, allowing the system to maintain security through dynamic values without requiring separate pre-authorization phases, thereby reducing processing time.
3Reliability
If the entire account number is made dynamic, then security is improved, but ease of operation and compatibility with existing systems decreases
Solution Approach 1:
The patent segments the account number into a static portion and a variable portion. The static portion remains unchanged and maintains compatibility with existing system databases and infrastructure. The variable portion is dynamically generated for each transaction to provide authentication. This segmentation allows the system to maintain compatibility while improving security.
Solution Approach 2:
Different portions of the account number have different properties: the static portion provides stability and compatibility, while the variable portion provides dynamic authentication. This local differentiation allows the system to maintain ease of operation with existing infrastructure while achieving improved security through the dynamic component.
Data Source
AI summary
A payment card comprises a processor, a trigger source coupled to the processor, and a display for outputting at least a portion of a dynamic account number under control of the processor responsive to the trigger source. The dynamic account number is determined based at least in part on a seed stored in the payment card and an output of the trigger source. In an illustrative embodiment, the dynamic account number is generated utilizing a time-based or event-based one-time password algorithm. For example, in a time-based embodiment, the trigger source may comprise a time of day clock, with the dynamic account number being determined based at least in part on the seed and a current value of the time of day clock. In an event-based embodiment, the trigger source may comprise an event counter, with the dynamic account number being determined based at least in part on the seed and a current value of the event counter.


