First factor contactless card authentication system and method

AU2026205251A1Pending Publication Date: 2026-07-23CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
AU2026205251
Authority / Receiving Office
AU · AU
Patent Type
Applications
Current Assignee / Owner
Filing Date
2026-07-02
Publication Date
2026-07-23

Smart Images

  • Figure 00000036_0000
    Figure 00000036_0000
  • Figure 00000037_0000
    Figure 00000037_0000
  • Figure 00000038_0000
    Figure 00000038_0000
Patent Text Reader

Abstract

20 26 20 52 51 02 J ul 2 02 6 A B S T R A C T 2 0 2 6 2 0 5 2 5 1 0 2 J u l 2 0 2 6
Need to check novelty before this filing date? Find Prior Art

Claims

1. A method for authorizing accesses to applications by clients includes the steps of: receiving a request to access an application from a first client device;identifying a client associated with the first client device;validating authenticity of the request by forwarding a notification of the request to a second client device associated with the client;receiving a response from the second client device, the response comprising authentication information comprising a username and a dynamic password retrieved by the second client device from a contactless card associated with the client;comparing the username and dynamic password retrieved by the second client device against an expected username and expected dynamic password for the client;responsive to a match between the username and the expected username and the dynamic password and the expected dynamic password, authenticating the request and launching the application at the first client device; andupdating and storing the dynamic password associated with the client.

2. The method of claim 1 wherein the first client device and the second client device comprise different devices and the second client device is used to authenticate the request made by the first client device.

3. The method of claim 2 wherein the step of launching the application includes the steps of building a communication link between a web session associated with the request and the second client device to enable the second client device to forward an authentication to the web session to launch the application.

4. The method of claim 2 wherein the step of launching the application includes the step of monitoring second client device communications to detect an approval of the request and selectively launching the application in response to detection of the approval.

5. The method of claim 1 wherein the first client device and the second client device comprise the same device.2026205251   02 Jul 20266. The method of claim 1 further comprising the steps of registering the first client device and second client device to the client.

7. The method of claim 1 further comprising the steps of binding the contactless card to the second client device.

8. The method of claim 5 wherein at least the username is encoded using one or more of a SHA-2 hash algorithm, a Triple Data Encryption Algorithm, a symmetric Hash Based Message Authentication (HMAC) algorithm and a symmetric cypher-based message authentication code (CMAC) algorithm.

9. The method of claim 1 further including the step of prompting the client to retrieve the username and dynamic password from the contactless card associated with the client.

10. The method of claim 1 wherein the dynamic password relates to a counter maintained by the client and related to a number of times that the username is retrieved from the contactless card.

11. A system for controlling accesses to applications clients includes:a processor;an interface configured to receive an authentication request from a second client device associated with a client to authenticate an access request, made by a first client device associated with the client, for access to an application, the authentication request including a cryptogram provided by a contactless card to the second client device, the cryptogram comprising a username and a dynamic password; a non-transitory storage medium comprising a client table comprising at least one entry for at least one client, the at least one entry including an expected username and an expected dynamic password for the client; program code stored on the non-transitory storage medium and operable when executed upon by the processor to:selectively approve the authentication request in response to a first match between the username and the expected username and to a second match between the dynamic password and the expected dynamic password; andin response to an approval of the authentication request, updating the expected dynamic password for the client.2026205251   02 Jul 202612. The system of claim 11 wherein the first client device and the second client device comprise different devices and the second client device is used to authenticate requests made by the first client device.

13. The system of claim 11 wherein the first client device and the second client device comprise the same device.

14. The system of claim 11 wherein the program code is further configured to register the first client device and second client device to the client.

15. The system of claim 11 wherein the program code is further configured to bind the contactless card to the second client device.

16. The system of claim 11 wherein at least part of the username is encoded, and the program code is further configured to decode the username using one or more of a SHA-2 hash algorithm, a Triple Data Encryption Algorithm, a symmetric Hash Based Message Authentication (HMAC) algorithm and a symmetric cypher-based message authentication code (CM AC) algorithm.

17. The system of claim 11 wherein the program code is further configured to prompt the client to retrieve the username and dynamic password from the contactless card associated with the client.

18. The system of claim 11 wherein the at least one entry of the client table includes a master key and a counter associated with the client, and wherein the program code is further configured to:generate a diversified key for the client in response to the counter and master key for the client; anddecrypt the cryptogram using the diversified key.

19. The system of claim 18 wherein the dynamic password is associated with the counter.

20. A method for authorizing access to an application by a client includes the steps of:2026205251   02 Jul 2026receiving a request to access an application from a first device associated with a client; identifying the client associated with the first device;validating authenticity of the request by forwarding a notification of the request to a second device associated with the client including generating a prompt for display on the second device requesting an authentication input from the client;receiving the authentication input from the second device, the authentication input including one or more of a biometric input, a query input and a contactless card cryptogram token input comprising a username and dynamic password retrieved by the second device from a contactless card associated with the client; comparing the authentication input against expected authentication input for the client; andresponsive to a match between the authentication input and the expected authentication input, enabling access to the application by the first device.