IP Library Granted Patent US 9,477,959
Granted Patent B2
US 9,477,959 · App. 15/008,056 · Granted Oct 25, 2016

Method and apparatus for using at least a portion of a one-time password as a dynamic card verification value

Inventor: James M. Ashfield (Midlothian, VA)
Assignee: BANK OF AMERICA CORPORATION
G06Q20/4018G06Q20/3821G06Q20/409
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,477,959
App. No.
15/008,056
Granted
Oct 25, 2016
Kind
B2
Abstract

Method and apparatus for using at least a portion of a one-time password as a dynamic card verification value (CVV) are disclosed. A credit/debit card is able to generate a dynamic card verification value (CVV). Such a card may also include an indication that the dynamic CVV is to be used as a security code for purchasing or other transactions. A card-based financial transaction can be authorized in accordance with the use of a dynamic CVV by receiving a transaction authorization request for a specific credit/debit card, wherein the transaction authorization request includes a dynamic CVV. The dynamic CVV can be compared to at least a portion of a one-time password generated for the specific credit/debit card, and a transaction authorization can be sent to the merchant or vendor when the dynamic CVV matches all or a portion of the one-time password.

Claims (48)

1. An apparatus for authorizing a transaction, wherein the transaction involves a credit/debit card,

wherein the credit/debit card comprises:

a visual display;

a speaker;

one or more input devices positioned on the credit/debit card configured to receive as an input a challenge response, wherein the one or more input devices comprise two or more of buttons corresponding to a plurality of alpha-numeric characters;

a processor in communication with the one or more input devices positioned on the credit/debit card, wherein the processor is configured to:

generate a challenge;

present, via the visual display and the speaker of the credit/debit card, the challenge;

receive, via the plurality of buttons on the credit/debit card, a challenge response comprising alpha-numeric characters; and

determine whether or not the challenge response received into the credit/debit card is successful; and

a one-time password generator automatically generating a one-time password or value based at least partially on receiving the challenge response into the credit/debit card and determining that the challenge response is successful,

wherein the apparatus comprises:

means for receiving a transaction authorization request associated with the transaction involving the credit/debit card, wherein the transaction authorization request comprises a prompt for a card verification value (CVV) for authenticating the transaction;

means for presenting, via the visual display and the speaker of the credit/debit card, the one-time password, wherein a portion of the one-time password comprises a dynamic card verification value (CVV) for authenticating the transaction;

means for comparing the dynamic CVV generated by the credit/debit card to at least a portion of an externally generated one-time password for the credit/debit card; and

means for sending a transaction authorization involving the credit/debit card if the dynamic CVV generated by the credit/debit card matches the at least a portion of an externally generated one-time password for the credit/debit card.

2. The apparatus of claim 1 further comprising means for sending a transaction denial when the dynamic CVV does not match the at least a portion of the one-time password.

3. The apparatus of claim 1 wherein the at least a portion of the one-time password comprises three digits of a six-digit one-time password.

4. The apparatus of claim 1 further comprising:

means for separating the dynamic CVV from credit/debit card data;

means for validating the credit/debit card data; and

means for merging the dynamic CVV with the credit/debit card data to produce the transaction authorization.

5. The apparatus of claim 3 further comprises a united authentication server wherein the means for comparing of the dynamic CVV to the three digits of the six-digit one-time password is accomplished using a united authentication server.

6. The apparatus of claim 1 wherein the dynamic CVV is based at least partially on the challenge response input by the user into the credit/debit card.

7. A system for authorizing a transaction, wherein the transaction involves a credit/debit card,

wherein the credit/debit card comprises:

a visual display;

a speaker;

one or more input devices positioned on the credit/debit configured to receive as an input a challenge response, wherein the one or more input devices comprise two or more-buttons corresponding to a plurality of alpha-numeric characters;

a processor in communication with the one or more input devices positioned on the credit/debit card, wherein the processor is configured to:

generate a challenge;

present, via the visual display and the speaker of the credit/debit card, the challenge;

receive, via the plurality of buttons on the credit/debit card, a challenge response comprising alpha-numeric characters; and

determine whether or not the challenge response received into the credit/debit card is successful; and

a one-time password generator automatically generating a one-time password or value based at least partially on receiving the challenge response into the credit/debit card and determining that the challenge response is successful,

wherein the system comprises:

a card approval server configured to receive a transaction authorization request associated with a transaction involving the credit/debit card, wherein the transaction authorization request comprises a prompt for a card verification value (CVV) for authenticating the transaction;

the visual display and the speaker of the credit/debit card to present the one-time password, wherein a portion of the one-time password comprises a dynamic card verification value (CVV) for authenticating the transaction;

an intermediate server configured to identify the dynamic CVV from a static CVV and to separate the dynamic CVV from credit/debit card data;

a database interconnected with the card approval server and the intermediate server and configured to validate the credit/debit card data; and

an authentication server interconnected with the intermediate server and configured to compare the dynamic CVV with at least a portion of an externally generated one-time password to authenticate the dynamic CVV.

8. The system of claim 7 wherein the database further comprises:

a credit card database; and

a debit card database.

9. The system of claim 7 wherein the intermediate server is disposed within a middleware layer.

10. The system of claim 7 wherein the at least a portion of the one-time password comprises three digits of a six-digit one-time password.

11. The system of claim 10 further comprising a united authentication server wherein the comparing of the dynamic CVV to the three digits of the six-digit one-time password is accomplished.

12. The system of claim 7 wherein the dynamic CVV is based at least partially on the challenge response input by the user into the credit/debit card.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 27, 2016
From: ASHFIELD, JAMES M.
To: BANK OF AMERICA CORPORATION
Reel/Frame 037600/0482 →
Continuity (2)
Continuation 11559931 · Nov 15, 2006
Related Publication 20160217471A1 · Jul 28, 2016