Dynamic Security Code Generation for Card Transactions
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Card Not Present (CNP) transactions are vulnerable to fraudulent activities due to the static nature of security codes, which can be easily acquired and used by malicious parties, despite the inclusion of Card Verification Value (CVV) for security enhancement.
Innovation Solution
A method and device for dynamically generating a security code for card transactions by receiving a user request, sending a time request to an external time source, determining the authenticity of the time message, and computing the dynamic security code based on the received time and a stored key, which is then displayed on the device, optionally only if the message is authentic.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a card with a dynamic code generator and display is used, then security is improved, but the cost of the card increases
Solution Approach 1:
The dynamic code generation functionality is extracted from the card itself and placed in an external electronic device. The card retains only its basic functions while the security code generation is performed externally using the card's identifier and a time value, eliminating the need for expensive display components in the card.
Solution Approach 2:
An external electronic device acts as an intermediary between the card and the transaction system. This intermediary device performs the dynamic security code generation by combining the card identifier with a time value, providing enhanced security without modifying the card's physical structure or adding costly components to it.
2Device complexity
If a static CVV is used, then the card structure remains simple, but the card becomes vulnerable to fraudulent CNP transactions
Solution Approach 1:
The security code transitions from a static CVV printed on the card to a dynamic code that changes over time. The dynamic security code is generated by combining the card identifier with a time value obtained from an external source, ensuring that the code is valid only for a specific time period and cannot be reused for future transactions.
Solution Approach 2:
The security parameter changes from a fixed static value to a time-dependent dynamic value. By incorporating the time value into the security code generation process, the system ensures that the security code evolves over time, preventing fraudulent use of captured codes while maintaining simplicity in the card's physical structure.
3Reliability
If time-based dynamic codes are implemented, then future fraud is prevented, but the system complexity increases
Solution Approach 1:
The external electronic device serves multiple functions: it stores the card identifier, obtains time values from external sources, generates dynamic security codes, and displays them to the user. This multi-functional approach consolidates the complexity into a single device that the user already possesses, rather than requiring separate specialized components for each function.
Solution Approach 2:
The system uses readily available resources to generate security codes. The electronic device utilizes its existing processor and display, obtains time from any external time source (such as network time protocols), and automatically generates the security code without requiring additional specialized hardware or manual intervention, thereby managing complexity through self-service capabilities.
Data Source
AI summary
An electronic device generates a dynamic security code for a card transaction, e.g. a card not present transaction. The electronic device receives a user request to generate a dynamic security code. The electronic device sends a time request to a time source and receives a message including a time from the time source. The electronic device determines an authenticity of the message containing the time and computes the dynamic security code based on the time received in the message and a key stored at the electronic device. The electronic device causes the dynamic security code to be displayed on a display of the electronic device. The electronic device may be capable of computing a dynamic security code for a plurality of different cards. The electronic device may be a smart phone, a tablet, or a personal computer.


