Dynamic Verification Value Gateway for Payment Fraud Prevention
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current payment transaction systems lack sufficient security, particularly for card-not-present transactions, as fraudsters can exploit static verification values, necessitating costly modifications to issuer computers to enhance fraud prevention.
Innovation Solution
The introduction of dynamic verification values (dCVV2) generated by an IP Gateway server, which are verified and replaced with static verification values (CVV2) within the transaction process, ensuring authentication without requiring changes to issuer computer systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If static verification values (CVV2) are used in payment transactions, then transaction processing is simple and issuer computers do not require modifications, but security is insufficient and fraudsters can exploit these static values
Solution Approach 1:
The patent transforms the static verification value (CVV2) into a dynamic verification value (dCVV2) that changes with each transaction. The dCVV2 is generated by the IP Gateway server based on the primary account number and transaction-specific data, making it unique for each transaction rather than static across multiple transactions. This dynamic approach enhances security while maintaining compatibility with existing issuer computer systems.
Solution Approach 2:
The patent introduces an IP Gateway server as an intermediary between the merchant system and the issuer computer. This intermediary generates and validates the dynamic verification values, performing the security enhancement function without requiring modifications to the issuer computer systems. The gateway acts as a mediator that translates between the dynamic verification approach and the static verification expectations of legacy systems.
2Reliability
If dynamic verification values (dCVV2) are implemented to prevent fraud, then transaction security is enhanced, but it requires costly modifications to all issuer computers
Solution Approach 1:
The IP Gateway server serves as an intermediary that implements the dynamic verification value generation and validation logic without requiring changes to issuer computer systems. The gateway receives authorization requests, generates or validates dCVV2 values, and forwards processed requests to the issuer, thereby isolating the security enhancement from the legacy issuer systems.
Solution Approach 2:
The patent creates a copy of the verification value validation function in the IP Gateway server, which generates and validates dCVV2 values independently of the issuer computer systems. This copying approach allows the security enhancement to be implemented in a separate system component rather than requiring modifications to the original issuer systems.
3Reliability
If verification value validation is performed at the issuer computer level, then security is maximized, but system complexity and modification requirements increase
Solution Approach 1:
The IP Gateway server acts as an intermediary that performs the verification value validation function, transferring this responsibility from the issuer computer level to the payment processing network level. The gateway validates the dCVV2 against the primary account number and transaction data, maintaining verification accuracy without increasing issuer system complexity.
Data Source
AI summary
Systems and methods for validating and processing payment transactions are disclosed. In the embodiments of the invention a first authorization request message and a first verification value are received at a server computer. The verification value is validated and a second authorization request message with a second verification value is generated. The first verification value may be a dynamic value and the second verification value may be static value. The second verification value is associated with portable device used to perform a transaction and it is what the issuer computers of the portable device expect to receive as part of an authorization request message in a payment transaction.


