The rise of the Card Security Code
Cyril LALO
Founder & CEO @ ellipse inc. - web:ellipse.la - Completing the EMV evolution with EVC, the EMV integrated Dynamic Card Security Code Technology
From remote transaction outlier to most vital card data
Over the past 20 years, Card Security Codes (also known as CVC2, CVV2) usage has greatly expanded from confirming genuine cardholders to securing eCommerce transactions, eWallet enrollments, and profile management, to name just a few. The Card Security Code has become the initial verification key on which the security of recurring or future transactions depends.
?This evolution has rendered the Card Security Code the most important piece of card data.
Until recently, the imprinted CVV or CVC value remained identical during the entire three-to-five-year lifetime of the card.
The advent of the Dynamic Card Security Code at the card level has brought a necessary, overdue technology update.
Little known facts about the Card Security Code
The Card Security Code is a 3 or 4 digit number imprinted on the front or the back of a payment card.
As opposed to other information on the card, the effectiveness of the Card Security Code relies on the PCI-DSS rule prohibiting its storage. Merchants who require the Card Security Code for Card Non Present transactions are prohibited to store it once the individual transaction has been authorized.?Therefore, if a database of transactions is compromised, the Card Security Code will not be among the compromised material and the stolen payment card numbers is rendered less useful.
Even for merchants who charge customers’ payment cards on a recurring basis, the Card Security Code is used to verify the initial transaction and the merchant may rely on this verification for future transactions for which the Card Security Code will not be required.
Increased usage & applications of the Card Security Code
领英推荐
As depicted in the graphic above, with the increasing reliance on the Card Security Code by the eCommerce ecosystem and the payment industry, it has come to be utilized as a nearly universal identifier, and the gatekeeper to downstream services and transactions.
The Card Security Code’s critical role in securing Card Not Present transactions its expansion into user identity verification, and resulting sharp increase in the volume of CVV verification requests led to the recent introduction of the Dynamic Card Security Code.
Refreshing the Card Security Code for the digital era
Despite their longevity as a long-time security feature of payment cards, Card Security Codes do have limitations and have become vulnerable to technological innovation. For example, the ubiquity of camera-enabled smartphones has made it easier for opportunistic fraudsters to photograph the front and back of a cardholder’s payment card and use it for fraudulent Card Not Present transactions. In most cases the cardholder has no reason to be aware of this theft of card information because the card is still in his or her possession. Moreover, because the Card Security Code is static, the stolen card information can be used and reused for fraudulent purposes until fraud is discovered by the card holder or the card issuer.
Now that the Card Security Code has evolved in the digital arena beyond securing?CNP transactions to become a trusted identity credential, changing it from a static to a dynamic format at the card level greatly reduces the opportunity for unauthorized reuse. Once the Card Security Code value is updated, issuers can identify older or expired values and decline transactions accordingly.
Though it is now asked to do far more than the use case for which it was originally intended, more than two decades later the Card Security Code remains the most important data on the payment card and by migrating to a digital format, it is evolving to become even more effective at deterring compromised card data.
Co-fondateur chez Freemindtronic SL | Expert en Cyber sécurité et s?reté par systèmes embarqués sans contact (NFC)
3 年En 2017, j'ai con?u des produits et services qui permettent de sécuriser tous les types de cartes bancaires qui utilisent le code de sécurité #CVV ou #CVC. Très efficace et sans surco?t de frais liés aux cartes bancaires à CVC dynamique, l'internaute n'a plus besoin d'avoir physiquement inscrit le CVV sur sa carte bancaire. Il peut tout simplement l'effacer. Avantageusement l'internaute n'a plus besoin de sauvegarder les informations de cartes bancaires sur les sites e-commerces. Ce qui a pour effet de ne pas être cyber victime de vol d'informations de cartes bancaires. Une technologie #fintech disponible en marque blanche, sous licence de brevets. L'internaute sauvegarde les informations de ses cartes bancaires dans un module de sécurité matérielle #NFC et peut réaliser ses achats en ligne en toute sécurité. Il utilise le module pour se connecter automatiquement, sans contact, à son compte e-commerce puis réalise également sans contact le paiement par carte bancaire en utilisant le module. Cas d'usages sécurisés : L'utilisateur de ce module peut ainsi gérer par exemple les cartes bancaires d'autres personnes don il a la charge. Il peut alors réaliser des paiements avec les informations des cartes bancaires de tiers (grands parents, personnes sous tutelle...). De plus, de la même manière, le module gère également des cartes d'authentification telles que les cartes de fidélité. Ces dernières incluent souvent des cartes de crédit privées de commer?ant. Ainsi, par ce biais ce type de module s'étend à la sécurité pour les achats de biens et de services chez les commer?ants. J'ai rédigé un article au sujet de la compliance PCI DSS de notre solution. https://www.dhirubhai.net/pulse/cold-wallet-nfc-gestionnaires-de-cartes-bancaires-pci-jacques-gascuel/ C'est une solution #GreenTech efficace aujourd'hui, compatible avec la technologie #EviCypher gardien de secrets médaille d'or 2021 des inventions internationales de Genève. Cette technologie de protection des cartes bancaires est également présente dans les produits #Keepser de l'entreprise Andorrane Keepser Group, dont le fondateur est Monsieur joseph collado. #PCIDSS #Cardsecuritycode #MadeinAndorra #MadeinFrance #Safety #Security #Freemindtronic #Contactless #Autologin #Autofill