Dynamic Verification Value Generation for Mobile Phone Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current dynamic card verification value (dCVV) processes in wireless transactions are vulnerable to interception and can be compromised due to the use of simplistic dynamic data elements, such as counters, which can be intercepted and decoded, leading to potential fraud.

Innovation Solution

A method involving recursive data string alteration using encryption and uniquely derived keys to generate dynamic verification values for transaction authentication, eliminating the need for counters and enhancing security by creating complex, changing data strings for each transaction.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a counter is used as a dynamic data element in dCVV generation, then the verification process can be simplified, but the security is weakened because the counter can be intercepted and decoded

Engineering Contradiction:
ImprovedCVV generation processVSAvoidtransaction security
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent changes the parameter used for dynamic verification from a simple counter to a complex data string that undergoes recursive alteration. Each transaction uses a different data string that is transformed through encryption and manipulation processes, making it impossible to predict or intercept the verification value. This resolves the contradiction by replacing the simple counter (easy to implement but insecure) with a complex data transformation system (more complex but secure).

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements dynamics by making the verification value change in a non-linear, unpredictable manner with each transaction. Instead of simply incrementing a counter, the system recursively alters data strings through encryption and transformation operations. This dynamic, unpredictable transformation prevents interception and decoding attempts, resolving the security issue while maintaining verification functionality.

Inventive Principle:
Principle #15Dynamics

2Ease of manufacture

If a simple counter is used for dynamic verification, then the implementation is easier, but the counter can be determined by unauthorized persons

Engineering Contradiction:
ImprovedCVV system implementationVSAvoidunauthorized determination of counter
Core Design Contradiction:
Ease of manufactureVSObject-affected harmful factors

Solution Approach 1:

The patent introduces an intermediary transformation layer between the transaction data and the verification value. Instead of directly using a counter, the system encrypts and recursively alters the data string through multiple transformation steps. This intermediary process prevents unauthorized persons from directly determining the verification value, as they would need to break the encryption and understand the complex transformation algorithm. The system maintains ease of implementation by using standard cryptographic operations while providing strong protection against unauthorized determination.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS8954353B2Mobile phone including dynamic verification value
Publication Date: 2015.02.10 VISA USA INC
  • US8954353B2 patent drawing
  • US8954353B2 patent drawing
  • US8954353B2 patent drawing

AI summary

A method for forming a dynamic verification value. The method includes altering a first data string to form a second data string, and forming a first dynamic verification value using at least a portion of the second data string. The first dynamic verification value is used to authenticate a phone in a first transaction. The second data string is used to form a third data string. A second dynamic verification value is formed using at least a portion of the third data string. The second dynamic verification value is used to authenticate the phone in a second transaction.