Dynamic Verification Value Generation for Mobile Phone Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current dynamic card verification value (dCVV) processes in wireless transactions are vulnerable to interception and can be compromised due to the use of simplistic dynamic data elements, such as counters, which can be intercepted and decoded, leading to potential fraud.
Innovation Solution
A method involving recursive data string alteration using encryption and uniquely derived keys to generate dynamic verification values for transaction authentication, eliminating the need for counters and enhancing security by creating complex, changing data strings for each transaction.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a counter is used as a dynamic data element in dCVV generation, then the verification process can be simplified, but the security is weakened because the counter can be intercepted and decoded
Solution Approach 1:
The patent changes the parameter used for dynamic verification from a simple counter to a complex data string that undergoes recursive alteration. Each transaction uses a different data string that is transformed through encryption and manipulation processes, making it impossible to predict or intercept the verification value. This resolves the contradiction by replacing the simple counter (easy to implement but insecure) with a complex data transformation system (more complex but secure).
Solution Approach 2:
The patent implements dynamics by making the verification value change in a non-linear, unpredictable manner with each transaction. Instead of simply incrementing a counter, the system recursively alters data strings through encryption and transformation operations. This dynamic, unpredictable transformation prevents interception and decoding attempts, resolving the security issue while maintaining verification functionality.
2Ease of manufacture
If a simple counter is used for dynamic verification, then the implementation is easier, but the counter can be determined by unauthorized persons
Solution Approach 1:
The patent introduces an intermediary transformation layer between the transaction data and the verification value. Instead of directly using a counter, the system encrypts and recursively alters the data string through multiple transformation steps. This intermediary process prevents unauthorized persons from directly determining the verification value, as they would need to break the encryption and understand the complex transformation algorithm. The system maintains ease of implementation by using standard cryptographic operations while providing strong protection against unauthorized determination.
Data Source
AI summary
A method for forming a dynamic verification value. The method includes altering a first data string to form a second data string, and forming a first dynamic verification value using at least a portion of the second data string. The first dynamic verification value is used to authenticate a phone in a first transaction. The second data string is used to form a third data string. A second dynamic verification value is formed using at least a portion of the third data string. The second dynamic verification value is used to authenticate the phone in a second transaction.


