Dynamic Verification Value Generation for Payment Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current payment systems lack sufficient security measures to prevent fraud during electronic transactions, as they primarily rely on static account information stored in debit or credit cards, which can be vulnerable to unauthorized access.

Innovation Solution

The implementation of a dynamic verification value system that generates a unique, complex verification value using a function-based algorithm, incorporating security values such as the primary account number, issuer secret phrase, and transaction details, which can be independently verified by issuers, enhancing transaction security without altering existing user experiences or merchant processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If static account information is used for payment transactions, then the system is simple and easy to operate, but the security against fraud is insufficient

Engineering Contradiction:
Improvetransaction securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent transforms the static CVV into a dynamic verification value that changes with each transaction. The verification value is generated dynamically using a function-based algorithm that incorporates transaction-specific parameters such as transaction ID, timestamp, and random numbers, making each verification value unique and valid only for a specific transaction, thereby enhancing security while maintaining system simplicity

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter state of the verification value from static to dynamic. Instead of using a fixed CVV stored on the card, the system generates verification values with varying parameters including transaction ID, timestamp, random numbers, and account information, ensuring that each verification value is unique and cannot be reused, thus improving security without significantly increasing complexity

Inventive Principle:
Principle #35Parameter changes

2Reliability

If dynamic verification values are generated using multiple security parameters, then fraud protection is enhanced, but the complexity of verification process increases

Engineering Contradiction:
Improvefraud protectionVSAvoidverification process simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements a self-service mechanism where the dynamic verification value is automatically generated by the cardholder's device using the function-based algorithm and local security parameters, then transmitted with the transaction request. The issuer's system automatically verifies the value by regenerating it using the same algorithm and comparing it, eliminating manual verification steps and maintaining ease of operation while enhancing fraud protection

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary generation of the dynamic verification value at the cardholder's device before the transaction is submitted to the issuer. This preliminary action ensures that the verification value is ready and valid when needed, and the issuer only needs to perform a simple regeneration and comparison operation, maintaining operational simplicity while achieving strong fraud protection

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8364594B2System and method including security parameters used for generation of verification value
Publication Date: 2013.01.29 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US8364594B2 patent drawing
  • US8364594B2 patent drawing
  • US8364594B2 patent drawing

AI summary

Systems and methods for generating a dynamic verification value for electronic payment transactions are disclosed. The dynamic verification value is generated via a function-based algorithm that accepts a plurality of security values as input. By selecting a set of security values from the plurality of the available security values, the level of complexity and security of the dynamic verification value can be adjusted and a unique security characteristic for the dynamic verification value is obtained. Also, the issuers of portable consumer devices are able to regenerate the dynamic verification value by inputting an issuer secret phrase into the same type of function-based algorithm that was used originally to generate the dynamic verification value.