Temporal CVV2 Generation for Secure Online Transactions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems do not allow customers to use their new credit cards for online transactions before receiving the physical card, posing a fraud risk and limiting immediate purchasing capabilities.

Innovation Solution

A system and method that generates a Temporal CVV2, a temporary three-digit number associated with a card number, which includes a validity parameter, allowing customers to make purchases before the physical card arrives, using a crypto generation processor and secure encryption protocols.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If an instant display of credit card and CVV2 is provided when account is approved, then customer convenience and productivity are improved, but fraud risk increases

Engineering Contradiction:
Improvetransaction initiation speedVSAvoidfraud risk
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamics by transforming the static CVV2 into a dynamic temporal CVV2 that changes over time. The temporal CVV2 is generated with a validity period and expires automatically, making it useless for future fraudulent transactions. This resolves the contradiction by enabling immediate transaction capability while limiting the window for fraud through time-based validity.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent changes the parameter of CVV2 from static to temporal by adding a validity period parameter. The temporal CVV2 includes expiration time information that is verified during transaction processing. This parameter change allows immediate card usage while preventing fraud by ensuring the CVV2 is only valid within a specific time window.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If actual CVV2 is revealed along with PAN and expiry date, then customer convenience is improved, but security is worsened

Engineering Contradiction:
Improveonline purchase capabilityVSAvoiddata security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent creates a temporary copy of the CVV2 function rather than revealing the actual CVV2. The temporal CVV2 is a separate entity that mimics the authentication function but is distinct from the permanent card credentials. This allows customers to make online purchases without exposing the actual CVV2 stored on the physical card, maintaining security while enabling convenience.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent implements disposable temporal CVV2s that are generated for specific time periods or transactions and then expire. These temporary credentials are inexpensive to generate and replace, allowing the system to provide secure one-time or limited-use authentication codes that eliminate the need to store or repeatedly use the actual CVV2, thereby enhancing security while maintaining ease of operation.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

3Reliability

If Temporal CVV2 is generated for each transaction request, then fraud risk is reduced, but system complexity increases

Engineering Contradiction:
Improvefraud preventionVSAvoidcrypto processing infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-generating temporal CVV2s with embedded validity periods and transaction parameters before actual transactions occur. The system can pre-issue these temporary credentials to customers upon account approval, and the validation logic is pre-programmed into the crypto validation processor. This reduces fraud risk through pre-configured security measures while managing complexity through automated pre-processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements self-service through automated temporal CVV2 generation and validation. The crypto generation processor automatically creates temporal CVV2s with embedded expiration times, and the crypto validation processor automatically verifies them during transactions without requiring manual intervention. This automation reduces fraud risk through consistent application of security rules while managing system complexity through self-service processing.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11961088B2System and method for providing temporal card verification value (CVV) for secure online transaction processing
Publication Date: 2024.04.16 JPMORGAN CHASE BANK NA
  • US11961088B2 patent drawing
  • US11961088B2 patent drawing
  • US11961088B2 patent drawing

AI summary

An embodiment of the present invention is directed to a Temporal CVV2 of CVV, which may be represented as a temporary three digit number generated using unique credentials associated with a card product. According to an embodiment of the present invention, the Temporal CVV2 may be generated for each transaction request or other defined set of transactions based on one or more factors, including time period/limit, usage, fraud/risk considerations. With this solution, a customer may request a new Temporal CVV2 each time a purchase is initiated. This may include online purchases, e-commerce transactions, manual link and provision requests, customer authentication for servicing channels, etc. An embodiment of the present invention seeks to mitigate risk and provide a safer and secure solution for customers while providing flexibility to make various purchases before a new card arrives.