Virtual Card Number Login Credentials for OTP-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional multi-factor authentication (MFA) systems, particularly two-factor authentication (2FA) systems, are vulnerable to compromise due to interception of one-time pins (OTPs), necessitating a more secure and robust authentication mechanism.

Innovation Solution

Implementing a virtual card number (VCN) as a login credential, which is processed through a credit card payment network with zero-dollar authorization, leveraging biometric data and machine learning for fraud detection, and customizable for one-time or multiple uses, providing additional layers of security.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional 2FA systems use OTP for authentication, then authentication capability is provided, but security is compromised when OTP is intercepted

Engineering Contradiction:
Improveauthentication securityVSAvoidOTP interception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtual card number (VCN) as an intermediary credential between the user and the authentication system. Instead of directly using OTP or traditional passwords, the VCN acts as a mediator that leverages the secure credit card authorization infrastructure to provide authentication, thereby eliminating the OTP interception vulnerability while maintaining authentication capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical OTP delivery and verification system with an electronic payment authorization system. By substituting the OTP mechanism with a VCN-based payment network authorization, the system leverages the inherent security of financial transaction networks to provide more robust authentication that cannot be easily intercepted or compromised.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If virtual card number is processed through credit card payment network with zero-dollar authorization, then authentication security is enhanced, but system complexity increases

Engineering Contradiction:
Improveauthentication securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent leverages the universal credit card payment network infrastructure to perform authentication functions. By making the authentication system multi-functional—using the same payment network for both financial transactions and security verification—the patent avoids creating a separate complex authentication infrastructure, thereby reducing overall system complexity while enhancing security.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system utilizes the self-service capabilities of the credit card payment network for authentication. The zero-dollar authorization process automatically verifies user credentials through the existing payment network security protocols without requiring additional manual verification steps or complex intermediary systems, thereby simplifying the authentication process while maintaining high security standards.

Inventive Principle:
Principle #25Self-service

3Reliability

If virtual card number is customized for one-time use or specific merchant, then fraud detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvefraud detection capabilityVSAvoidcard customization complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic virtual card numbers that can be customized for one-time use or specific merchants. These VCNs are not static but can be generated, modified, and revoked as needed based on authentication requirements. This dynamic approach enables flexible fraud detection and prevention without requiring complex permanent configurations, as the system adapts credentials in real-time based on usage patterns and security needs.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12450614B2Virtual card number as a login credential
Publication Date: 2025.10.21 CAPITAL ONE SERVICES LLC
  • US12450614B2 patent drawing
  • US12450614B2 patent drawing
  • US12450614B2 patent drawing

AI summary

Disclosed embodiments pertain to systems and methods related to user authentication with a virtual payment card. A virtual card number can be requested as a login credential for a user. A virtual card number can be transmitted through a credit card payment network to a financial institution that issued the virtual card for payment authorization. The user can subsequently be authenticated in response to a granted payment authorization by the financial institution. The financial institution can execute a machine learning model trained to infer fraud based on a usage pattern associated with a virtual card number. Granting or denying payment authorization can depend on a confidence score returned by the model regarding the likelihood of fraud. A virtual card number associated with authentication can include one or more distinguishing characteristics in one instance. Further, virtual card numbers can include use restrictions in time and location.