Card security code explained

thumb|The card security code is located on the back of Mastercard, Visa, Discover, Diners Club, and JCB credit or debit cards and is typically a separate group of three digits to the right of the signature stripthumb|On American Express cards, the card security code is a printed, not embossed, group of four digits on the front towards the right

A card security code (CSC; also known as CVC, CVV, or several other names) is a series of numbers that, in addition to the bank card number, is printed (but not embossed) on a credit or debit card. The CSC is used as a security feature for card not present transactions, where a personal identification number (PIN) cannot be manually entered by the cardholder (as they would during point-of-sale or card present transactions). It was instituted to reduce the incidence of credit card fraud. Unlike the card number, the CSC is deliberately not embossed, so that it is not read when using a mechanical credit card imprinter which will only pick up embossed numbers.

These codes are in slightly different places for different card issuers. The CSC for Visa, Mastercard, and Discover credit cards is a three-digit number on the back of the card, to the right of the signature box. The CSC for American Express is a four-digit code on the front of the card above the account number. See the figures to the right for examples.

CSC was originally developed in the UK as an eleven-character alphanumeric code by Equifax employee Michael Stone in 1995. After testing with the Littlewoods Home Shopping group and NatWest bank, the concept was adopted by the UK Association for Payment Clearing Services (APACS) and streamlined to the three-digit code known today. Mastercard started issuing CVC2 numbers in 1997 and Visa in the United States issued them by 2001. American Express started to use the CSC in 1999, in response to growing Internet transactions and card member complaints of spending interruptions when the security of a card has been brought into question.

Contactless card and chip cards may electronically generate their own code, such as or a dynamic CVV.

Naming

The codes have different names:

Types

There are several types of security codes and PVV (all generated from DES key in the bank in HSM modules using PAN, expiration date and service code):

Location

The card security code is typically the last three or four digits printed, not embossed like the card number, on the signature strip on the back of the card. On American Express cards, however, the card security code is the four digits printed (not embossed) on the front towards the right. The card security code is not encoded on the magnetic stripe but is printed flat.

Generation

The CSC for each card (form 1 and 2) is generated by the card issuer when the card is issued. It is calculated by encrypting the bank card number and expiration date (two fields printed on the card) with encryption keys known only to the card issuer, and decimalising the result (in a similar manner to a hash function).[9] [10] [11]

Benefits and limitations

As a security measure, merchants who require the CVV2 for "card not present" transactions are required by the card issuer not to store the CVV2 once the individual transaction is authorized.[12] This way, if a database of transactions is compromised, the CVV2 is not present and the stolen card numbers are less useful. Virtual terminals and payment gateways do not store the CVV2 code; therefore, employees and customer service representatives with access to these web-based payment interfaces, who otherwise have access to complete card numbers, expiration dates, and other information, still lack the CVV2 code.

The Payment Card Industry Data Security Standard (PCI DSS) also prohibits the storage of CSC (and other sensitive authorisation data) post transaction authorisation. This applies globally to anyone who stores, processes or transmits card holder data.[13] Since the CSC is not contained on the magnetic stripe of the card, it is not typically included in the transaction when the card is used face to face at a merchant. However, some merchants in North America, such as Sears and Staples, require the code. For American Express cards, this has been an invariable practice (for "card not present" transactions) in European Union (EU) countries like Ireland and the United Kingdom since the start of 2005. This provides a level of protection to the bank/cardholder, in that a fraudulent merchant or employee cannot simply capture the magnetic stripe details of a card and use them later for "card not present" purchases over the phone, mail order or Internet. To do this, a merchant or its employee would also have to note the CVV2 visually and record it, which is more likely to arouse the cardholder's suspicion.

Supplying the CSC code in a transaction is intended to verify that the customer has the card in their possession. Knowledge of the code proves that the customer has seen the card, or has seen a record made by somebody who saw the card.

Limitations include:

See also

Notes and References

  1. Web site: SafeKey Frequently Asked Questions American Express Canada. 2021-05-04. www.americanexpress.com.
  2. Web site: American Express® Card security features. live. https://web.archive.org/web/20201127205221/https://www.americanexpress.com/content/dam/amex/hk/en/staticassets/merchant/pdf/support-and-services/useful-information-and-downloads/GuidetoCheckingCardFaces.pdf. 2020-11-27. 2021-05-04. www.americanexpress.com.
  3. Web site: Card verification number (CVN) . 2023-07-02 .
  4. Web site: CIBC MasterCard - MasterCard SecureCode . 2012-07-12 . dead . https://web.archive.org/web/20140424011239/https://www.securesuite.net/cibc/tdsecure/spc_description.jsp?cycfg_affinity=mc . 24 April 2014 .
  5. Apple Pay £20 limit in the UK will 'change over time'. Wired UK. 2015-06-24. 2022-06-24.
  6. Web site: Breakthrough for mobile payments? Google Pay launched in Germany. Avira. 2018-07-17. 2022-06-24.
  7. Web site: Samsung Pay now allows Australian users to make high-value purchases without PIN. SamMobile. 2020-09-22. 2022-06-24.
  8. Web site: Card Security Features . Visa. https://web.archive.org/web/20120216145102/http://www.visa.ca/en/merchant/pdfs/security_features.pdf . 2012-02-16.
  9. Web site: 2012-09-18. VISA PIN Algorithms. 2021-06-18. www.ibm.com. en-us.
  10. Web site: z/OS Integrated Cryptographic Service Facility Application Programmer's Guide. IBM. March 2002. 209.
  11. Web site: z/OS Integrated Cryptographic Service Facility Application Programmer's Guide. IBM. March 2002. 258.
  12. Web site: Rules for Visa Merchants. doc. 1. 26 February 2013. https://web.archive.org/web/20140224171209/http://usa.visa.com/download/merchants/pdra_form_dec2006.doc. 24 February 2014. dead.
  13. Web site: Official Source of PCI DSS Data Security Standards Documents and Payment Card Compliance Guidelines . Pcisecuritystandards.org . 2011-12-25.
  14. Web site: Urban Legends Reference Pages: Visa Fraud Investigation Scam . 23 December 2003 . Snopes.com . 2011-12-25.
  15. Web site: How to guess credit card security codes . Ducklin . Paul . 5 December 2016 . naked security by SOPHOS . 8 December 2016 .