Verification Token for Dynamic Credit Card Verification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The credit card industry faces challenges in preventing fraud, particularly with skimming in static magnetic stripe transactions and the increased vulnerability of contactless transactions, where skimmers can intercept data wirelessly without physical access to the card.

Innovation Solution

A verification token system that reads identification information from portable consumer devices and securely transmits it to a validation entity for a device verification value (dCVV), using encryption, hashing, or signing to prevent unauthorized access and fraud, while maintaining user convenience.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If static magnetic stripe data is used for transactions, then ease of operation is improved, but security is worsened due to skimming vulnerability

Engineering Contradiction:
Improveease of transactionVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent transforms static magnetic stripe data into dynamic verification values that change with each transaction. The dCVV is generated dynamically based on transaction-specific parameters, making each transaction unique and preventing skimming attacks that rely on copying static data.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system changes the verification parameter from a static magnetic stripe pattern to a dynamically generated dCVV that varies with each transaction. This parameter change ensures that even if one transaction's data is compromised, it cannot be used for future transactions.

Inventive Principle:
Principle #35Parameter changes

2Ease of operation

If contactless wireless transactions are implemented, then ease of operation is improved, but security is worsened due to increased skimming vulnerability

Engineering Contradiction:
Improveease of transactionVSAvoidskimming risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies dynamic verification values to contactless transactions, ensuring that the wireless transmission contains unique, transaction-specific data rather than reusable static information. This dynamic approach prevents skimmers from capturing and replaying wireless signals.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary generation and verification of dCVV before the actual transaction occurs. This preliminary anti-action ensures that the transaction data is already protected against skimming attempts, as the verification value is validated before being transmitted wirelessly.

Inventive Principle:
Principle #9Preliminary anti-action

3Reliability

If dCVV is securely received and used, then security is improved, but device complexity is worsened

Engineering Contradiction:
ImprovesecurityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the dCVV generation and verification functions into the existing payment processing system. By integrating these security functions with the transaction processing infrastructure, the system achieves enhanced security without requiring separate complex systems for each function.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system introduces an intermediary verification process where the dCVV is generated by one component and verified by another, with the payment processing network acting as a mediator. This intermediary approach distributes complexity across multiple components rather than concentrating it in a single device.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10387871B2Integration of verification tokens with mobile communication devices
Publication Date: 2019.08.20 VISA INTERNATIONAL SERVICE ASSOCIATION
  • US10387871B2 patent drawing
  • US10387871B2 patent drawing
  • US10387871B2 patent drawing

AI summary

Apparatuses, methods, and systems pertaining to the verification of portable consumer devices are disclosed. In one implementation, a verification token is communicatively coupled to a computer by a USB connection so as to use the computer's networking facilities. The verification token reads identification information from a user's portable consumer device (e.g., credit card) and sends the information to a validation entry over a communications network using the computer's networking facilities. The validation entity applies one or more validation tests to the information that it receives from the verification token. If a selected number of tests are passed, the validation entity sends a device verification value to the verification token, and optionally to a payment processing network. The verification token may enter the device verification value into a CVV field of a web page appearing on the computer's display, or may display the value to the user using the computer's display.