Dynamic Security Code System for Payment Card Fraud Protection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment card security systems are vulnerable to Card-Not-Present (CNP) fraud due to static security codes, which can be stolen and reused for fraudulent transactions, and existing dynamic code solutions are costly, fragile, and prone to desynchronization.

Innovation Solution

A Dynamic Security Code (DSC) System that generates and updates security codes dynamically, either by a server or on-card algorithms, allowing for secure, cost-effective, and robust protection against CNP fraud, compatible with existing payment infrastructure and usable in various transaction environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static security codes are used on payment cards, then the system is simple and compatible with existing infrastructure, but the system becomes vulnerable to Card-Not-Present (CNP) fraud

Engineering Contradiction:
Improvefraud protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic security codes that change over time or after a certain number of uses. The security code is no longer static but dynamically generated based on transaction context, time, or usage count, making each code unique and preventing reuse in fraudulent transactions.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The security code parameters are changed from static to dynamic. The code varies based on multiple parameters such as transaction timestamp, sequence number, or cryptographic keys, transforming the security mechanism from a fixed value to a multi-parameter dynamic system.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If time-based dynamic security codes with real-time clock and battery are implemented, then fraud protection is improved, but the card becomes more fragile, expensive, and has limited lifetime

Engineering Contradiction:
Improvefraud protectionVSAvoidmanufacturing cost and complexity
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent removes the battery and real-time clock components from the card. Instead of generating codes locally using time-based algorithms, the system extracts the time-synchronization function to an external server that provides time-based one-time passwords without requiring power sources in the card itself.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An external server acts as an intermediary between the card and the authentication system. The server handles time synchronization and code generation, mediating the authentication process without requiring complex hardware in the card. The card simply receives instructions and displays codes provided by the server.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If time-based dynamic security codes are used, then fraud protection is improved, but the system becomes prone to de-synchronization with the server

Engineering Contradiction:
Improvefraud protectionVSAvoidsynchronization stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The system implements feedback mechanisms where the server continuously synchronizes time with the card through periodic communications. The server can detect and correct time drift, and the card can request time synchronization during transactions, ensuring both parties operate with consistent time references.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The server performs preliminary time synchronization before generating security codes. By establishing an accurate time reference in advance and providing buffer time windows for code validation, the system prevents desynchronization issues before they affect authentication.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If security codes are printed on the card, then the system is simple to implement, but the codes can be stolen and reused for fraudulent transactions

Engineering Contradiction:
Improvesystem simplicityVSAvoidfraud vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The security code transitions from a static printed value to a dynamic displayed value that changes with each transaction or time period. The code is generated and displayed on an electronic display rather than being permanently printed, ensuring it cannot be stolen and reused.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

Instead of printing the security code directly on the card, the system uses an electronic display to show the code temporarily. This creates a transient copy that exists only during the display period, preventing physical copying or theft of the code.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10235674B2Method for a prepaid, debit and credit card security code generation system
Publication Date: 2019.03.19 ELLIPSE WORLD INC
  • US10235674B2 patent drawing
  • US10235674B2 patent drawing
  • US10235674B2 patent drawing

AI summary

This invention is a comprehensive “Dynamic Security Code” (“DSC”) System (“DSC System”) that can change the security code of a prepaid, debit, or credit card (“Payment Card”). In an effort to thwart Card-Not-Present (“CNP”) fraud, the DSC System provides dynamic security code values (“DSC Values”) that have a limited use. The DSC Values provided by this DSC System can be calculated by various methodologies and can be used within existing standard payment card infrastructures. The DSC System can also be used with other form factors and in other environments not related to payments such as balance inquiries. The DSC Values can be calculated by a DSC Generator Server or on the card itself.