Dynamic Security Code Generation for Card Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Card Not Present (CNP) transactions are vulnerable to fraudulent activities due to the static nature of security codes, which can be easily acquired and used by malicious parties, despite the inclusion of Card Verification Value (CVV) for security enhancement.

Innovation Solution

A method and device for dynamically generating a security code for card transactions by receiving a user request, sending a time request to an external time source, determining the authenticity of the time message, and computing the dynamic security code based on the received time and a stored key, which is then displayed on the device, optionally only if the message is authentic.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a card with a dynamic code generator and display is used, then security is improved, but the cost of the card increases

Engineering Contradiction:
ImprovesecurityVSAvoidcost of card
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The dynamic code generation functionality is extracted from the card itself and placed in an external electronic device. The card retains only its basic functions while the security code generation is performed externally using the card's identifier and a time value, eliminating the need for expensive display components in the card.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An external electronic device acts as an intermediary between the card and the transaction system. This intermediary device performs the dynamic security code generation by combining the card identifier with a time value, providing enhanced security without modifying the card's physical structure or adding costly components to it.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Device complexity

If a static CVV is used, then the card structure remains simple, but the card becomes vulnerable to fraudulent CNP transactions

Engineering Contradiction:
Improvecard structureVSAvoidsecurity against fraud
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The security code transitions from a static CVV printed on the card to a dynamic code that changes over time. The dynamic security code is generated by combining the card identifier with a time value obtained from an external source, ensuring that the code is valid only for a specific time period and cannot be reused for future transactions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security parameter changes from a fixed static value to a time-dependent dynamic value. By incorporating the time value into the security code generation process, the system ensures that the security code evolves over time, preventing fraudulent use of captured codes while maintaining simplicity in the card's physical structure.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If time-based dynamic codes are implemented, then future fraud is prevented, but the system complexity increases

Engineering Contradiction:
Improveprevention of future fraudVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The external electronic device serves multiple functions: it stores the card identifier, obtains time values from external sources, generates dynamic security codes, and displays them to the user. This multi-functional approach consolidates the complexity into a single device that the user already possesses, rather than requiring separate specialized components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system uses readily available resources to generate security codes. The electronic device utilizes its existing processor and display, obtains time from any external time source (such as network time protocols), and automatically generates the security code without requiring additional specialized hardware or manual intervention, thereby managing complexity through self-service capabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11526880B2Dynamic security code for a card transaction
Publication Date: 2022.12.13 IDEMIA FRANCE SAS
  • US11526880B2 patent drawing
  • US11526880B2 patent drawing
  • US11526880B2 patent drawing

AI summary

An electronic device generates a dynamic security code for a card transaction, e.g. a card not present transaction. The electronic device receives a user request to generate a dynamic security code. The electronic device sends a time request to a time source and receives a message including a time from the time source. The electronic device determines an authenticity of the message containing the time and computes the dynamic security code based on the time received in the message and a key stored at the electronic device. The electronic device causes the dynamic security code to be displayed on a display of the electronic device. The electronic device may be capable of computing a dynamic security code for a plurality of different cards. The electronic device may be a smart phone, a tablet, or a personal computer.