Dynamic Security Code Generation for Card Fraud Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security code systems for prepaid, debit, and credit cards are vulnerable to Card-Not-Present fraud, as static security codes can be stolen and reused, leading to increased fraudulent activities and costs associated with managing fraud cases and replacing counterfeit cards.

Innovation Solution

A Dynamic Security Code System that generates and updates security codes dynamically, either by a server or on-card algorithms, providing limited-use dynamic security code values that can be validated through existing payment card infrastructures, reducing the need for card replacement and infrastructure changes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security codes are used on payment cards, then the card payment infrastructure remains simple and existing, but the system becomes vulnerable to Card-Not-Present fraud and requires card replacement when compromised

Engineering Contradiction:
Improvesecurity against fraudVSAvoidcard infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security codes that change over time or after a certain number of uses, transforming the static security code into a dynamic one. This is achieved through an on-card algorithm that generates new security codes based on a secret key and counter, allowing the code to evolve without requiring physical card replacement or complex infrastructure changes

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security code parameter is changed dynamically through mathematical algorithms that generate new codes based on a secret key and counter value. This allows the security code to transform from a fixed value to a changing value, improving security while maintaining compatibility with existing card readers and payment systems

Inventive Principle:
Principle #35Parameter changes

2Reliability

If time-based dynamic security codes with real-time clock and battery are implemented, then security is improved, but the card becomes more fragile, expensive, and has limited lifetime

Engineering Contradiction:
Improvesecurity against fraudVSAvoidcard manufacturing cost and complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent extracts and removes the battery and real-time clock components from the card, keeping only the essential algorithmic functionality. The security code generation is achieved through a purely mathematical process using a secret key and counter stored on the card, eliminating the need for power sources and time-keeping hardware

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

Instead of using expensive components like batteries and real-time clocks, the patent employs a simple algorithmic approach that generates dynamic security codes through mathematical operations. This creates a more durable, cheaper, and maintenance-free solution that doesn't rely on consumable components

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If time-based dynamic security codes are implemented, then security is improved, but the system becomes prone to desynchronization with the server

Engineering Contradiction:
Improvesecurity against fraudVSAvoidsynchronization between card and server
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent implements a feedback mechanism where the server validates the security code generated by the card and provides confirmation. The card and server both maintain the same secret key and counter, ensuring they generate identical security codes without requiring complex time synchronization. The counter increments with each use, providing automatic state synchronization through the transaction process itself

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP3497646A1Prepaid, debit and credit card security code generation system
Publication Date: 2019.06.19 ELLIPSE WORLD INC

AI summary

This invention is a comprehensive "Dynamic Security Code" ("DSC") System ("DSC System") that can change the security code of a prepaid, debit, or credit card ("Payment Card"). In an effort to thwart Card-Not-Present ("CNP") fraud, the DSC System provides dynamic security code values ("DSC Values") that have a limited use. The DSC Values provided by this DSC System can be calculated by various methodologies and can be used within existing standard payment card infrastructures. The DSC System can also be used with other form factors and in other environments not related to payments such as balance inquiries. The DSC Values can be calculated by a DSC Generator Server or on the card itself.