System and method for device binding authentication
By leveraging the GPU to generate device fingerprints on mobile devices and combining them with NFC and WebGL APIs, the problem of device-specific data access and integrated verification is solved, enabling reliable association between devices and users and enhanced authentication security.
Patent Information
- Application Number
- CN202480031461.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-03-08
- Filing Date
- 2024-03-07
- Publication Date
- 2025-12-05
AI Technical Summary
Existing technologies make it difficult to generate and integrate device-specific data in an authentication system, hindering the application of device fingerprint data in user authentication and affecting the reliable association between devices and users and authentication security.
By leveraging the graphics processing unit (GPU) of mobile devices to generate device fingerprints, combined with Near Field Communication (NFC) and Web Graphics Library (WebGL) APIs, and rendering image hash identifiers for device binding authentication, the authentication process of One-Time Password (OTP) cards is enhanced.
It provides a strength factor for device binding authentication, which enhances the security of electronic transactions, simplifies the authentication process between devices and users, and improves the reliability and security of authentication.
Smart Images

Figure CN121079710A_ABST
Abstract
Description
Cross-reference to related applications
[0001] This application claims priority to U.S. Patent Application No. 18 / 118,987, filed March 8, 2023, the disclosure of which is incorporated herein by reference in its entirety. Technical Field
[0002] This disclosure generally relates to secure electronic authentication, and more specifically, to device signature generation based on a graphics processing unit for providing user equipment authentication. Background Technology
[0003] As device manufacturers continue to restrict access to information specific to device configuration and operation, generating unique device identifiers that can be permanently associated with a particular device initiating a secure electronic transaction becomes increasingly difficult. These unique characteristics can be used to verify devices in consecutive authentication transactions. Blocking access to device-specific data hinders the integration of device fingerprint data into user authentication systems and processes—data used for reliable identification of the source device as a verification factor—thus impeding efforts to enhance access verification security by associating devices with a particular user's previous authentication transactions.
[0004] These and other shortcomings exist. Therefore, there is a need for a device signature and / or fingerprint calculation system and process that is both accessible and easily integrated into the user authentication process. Summary of the Invention
[0005] Embodiments of this disclosure provide a system, method, and a non-transitory computer-accessible medium thereon storing computer-executable instructions for implementing a device binding authentication system and process. In some aspects, the technology described herein relates to a method for enhancing one-time password (OTP) card authentication based on the computation of a digital signature associated with the operation of a graphics processing unit (GPU) of a mobile and / or computing device, and providing the computed GPU-based device fingerprint as authentication data for verifying the identity of the transaction originating device and / or the transaction user. The method includes: receiving an authentication message from a contactless card via near field communication (NFC) transmission, the authentication message corresponding to a user authentication request, operated to provide raw image data associated with an image to a mobile browser running on the mobile device; rendering the image associated with the raw image data via the mobile browser using a Web Graphics Library (WebGL) application programming interface (API); generating an image hash identifier from the rendered image data generated by the mobile browser using the WebGL API, the image hash identifier corresponding to the user authentication request; mapping the image hash identifier with a graphics processing unit (GPU) associated with the mobile device for binding the mobile device to the authentication message provided by the NFC transmission from the contactless card; comparing the image hash identifier received from the mobile device by an authentication server with one or more previously stored hash identifiers associated with one or more previous user authentication requests; and verifying the mobile device based on determining a match between the image hash identifier received from the mobile device in response to a user authentication request and one or more previously stored hash identifiers associated with one or more previous user authentication requests.
[0006] In some aspects, the techniques described herein relate to a method in which an authentication message includes a Uniform Resource Locator (URL) pointing to an image hosted on a web server, and a mobile device, in response to receiving the URL, is operated to retrieve raw image data from the web server. The raw image data associated with the image can be retrieved from the web server via URL redirection. In some embodiments, the URL may include embedding instructions for redirecting to multiple images to be periodically rotated, the multiple images being stored on the web server. Alternatively, the multiple images may be stored on one or more different web servers.
[0007] In some aspects, the technology described herein relates to a method in which raw image data is stored in a Near Field Communication Data Exchange Format (NDEF) file on a contactless card. This NDEF file also includes an image identifier corresponding to the Multipurpose Internet Mail Extensions (MIME) media type of the image, facilitating rendering of the image via a mobile browser with a Web Graphics Library (WebGL) application programming interface (API). The NDEF file can be transferred directly from the contactless card to the mobile device for rendering via NFC transmission. Regarding the above scenario, the NFC transmission of the authentication message can be initiated by an NFC reader application running on the mobile device performing an NFC read of the contactless card.
[0008] In some embodiments, raw image data can be read directly from a contactless card by a website via Web Near Field Communication (WebNFC) and transmitted via a network connection from a web server hosting the WebNFC-enabled website to a mobile browser on a mobile device for rendering. The raw image data may be associated with a high-entropy mode to exaggerate GPU differences in the rendered output (e.g., rendered image data). According to some embodiments, the image can be rendered by the mobile browser in a fixed-size framebuffer to prevent variations in the rendered image data due to different screen resolutions.
[0009] In some aspects, the technology described herein relates to a multi-factor authentication system based on integrating device binding functionality with an OTP authentication card. This system includes computer hardware configured to: provide first image data associated with an image to a mobile browser running on a user's mobile device, the first image data being received from a contactless card associated with the user as part of an authentication message in response to a user authentication request; render an image from the first image data using WebGL functionality associated with the mobile browser to generate second image data; generate an image hash identifier from the second image data; map the image hash identifier with a graphics processing unit (GPU) associated with the mobile device to bind the mobile device to the authentication message transmitted from the contactless card; have an authentication server compare the image hash identifier received from the mobile device with one or more previously stored hash identifiers associated with one or more previous user authentication requests; and have the authentication server verify the mobile device based on determining a match between the image hash identifier received from the mobile device in response to a user authentication request and one or more previously stored hash identifiers associated with one or more previous user authentication requests.
[0010] In some aspects, the technology described herein relates to a system in which the system is further configured to encode a Uniform Resource Locator (URL) pointing to an image hosted on a web server into an authentication message, the URL instructing a mobile browser to retrieve first image data from the web server. The URL may include embedding instructions for redirecting to multiple images to be periodically rotated, the multiple images being stored on the web server.
[0011] In some respects, the technology described herein relates to a system in which first image data is stored on a contactless card and transmitted to a mobile device via NFC transmission from the contactless card for rendering. The NFC transmission also includes an image identifier corresponding to the Multipurpose Internet Mail Extensions (MIME) media type of the image to facilitate rendering of the image via the WebGL functionality of a mobile browser.
[0012] According to some embodiments, the first image data may correspond to the original image data with a high-entropy pattern to exaggerate the GPU differences when generating the second image data, which corresponds to the rendered image data.
[0013] In some aspects, the technology described herein relates to a non-transitory computer-accessible medium comprising instructions executed by a computer hardware device, wherein, when executing the instructions, the computer hardware device is configured to perform a program comprising the following steps: receiving an authentication message from a contactless card via near field communication (NFC) transmission, the authentication message corresponding to a user authentication request, by a mobile device, and being operated to provide raw image data associated with an image to a mobile browser running on the mobile device; rendering an image associated with the raw image data using a Web Graphics Library (WebGL) application programming interface (API) via the mobile browser; generating an image hash identifier from the rendered image data generated by the mobile browser using the WebGL API, the image hash identifier corresponding to the user authentication request; mapping the image hash identifier with a graphics processing unit (GPU) associated with the mobile device to provide a binding between the mobile device and the authentication message provided by the NFC transmission from the contactless card; comparing the image hash identifier received from the mobile device by an authentication server with one or more previously stored hash identifiers associated with one or more previous user authentication requests; and verifying the mobile device based on determining a match between the image hash identifier received from the mobile device in response to a user authentication request and one or more previously stored hash identifiers associated with one or more previous user authentication requests.
[0014] In some aspects, the technology described herein relates to a non-transitory computer-accessible medium, further comprising instructions for encoding a Uniform Resource Locator (URL) pointing to an image hosted on a web server into an authentication message, the URL instructing a mobile browser to retrieve first image data from the web server. In some embodiments, the non-transitory computer-accessible medium may also include instructions for redirecting to a plurality of images to be periodically rotated.
[0015] In some respects, the technology described herein relates to a non-transitory computer-accessible medium, and also includes instructions for rendering an image directly from an NFC transmission received from a contactless card, the NFC transmission including raw image data and a Multipurpose Internet Mail Extensions (MIME) media type associated with the image and stored on the contactless card. Attached Figure Description
[0016] Figure 1 Exemplary system implementations of an authentication process with device binding according to some embodiments of the present disclosure are shown.
[0017] Figure 2 An overview of mobile browser operation based on image hash identifier generation device fingerprinting according to some embodiments of the present disclosure is shown.
[0018] Figure 3 A device binding authentication method based on GPU device fingerprinting facilitated by an image URL transmitted from a contactless card via NFC, according to an exemplary embodiment of the present disclosure, is illustrated.
[0019] Figure 4 A device binding authentication method based on a GPU-based device fingerprint calculated from image data directly retrieved from a contactless card, according to an exemplary embodiment of the present disclosure, is illustrated.
[0020] Figure 5 An exemplary embodiment of the present disclosure illustrates a GPU-based mobile device verification process based on direct NFC reading of a contactless card by a website using WebNFC and network transmission of input image data to the mobile device.
[0021] Figure 6 A flowchart illustrating an exemplary process for device binding authentication according to an exemplary embodiment of the present disclosure is shown, including the acquisition of input image data for generating and verifying a GPU-based device signature.
[0022] Figure 7 A timing diagram is shown for GPU-based device binding authentication using an image URL transmitted via NFC, according to an exemplary embodiment of this disclosure.
[0023] Figure 8A timing diagram is shown for GPU-based device-binding authentication using raw image data stored on a contactless card, according to an exemplary embodiment of the present disclosure.
[0024] Figure 9 A block diagram of an exemplary system according to an exemplary embodiment of the present disclosure is shown. Detailed Implementation
[0025] The following description of the embodiments provides non-limiting, representative examples of referenced figures to specifically describe the features and teachings of different aspects of the invention. Based on the description of the embodiments, the described exemplary embodiments will be considered capable of being implemented alone or in combination with other embodiments, and the features and teachings of any embodiment can be interchangeably combined with the features and teachings of any other embodiment. Those skilled in the art who read the description of the exemplary embodiments will learn and understand the different descriptive aspects of the invention. The description of the exemplary embodiments is intended to facilitate an understanding of the invention to the extent that other implementations not specifically covered but within the knowledge of those skilled in the art upon reading the description of the exemplary embodiments will be understood to be consistent with the application of the invention.
[0026] Furthermore, the features, advantages, and characteristics described in the exemplary embodiments can be combined in any suitable manner. Those skilled in the art will recognize that exemplary embodiments can be practiced without one or more specific features or advantages of the exemplary embodiments. In other cases, additional features and advantages that may not be present in all exemplary embodiments may be recognized in some exemplary embodiments. Those skilled in the art will understand that the features, advantages, and characteristics described in any exemplary embodiment can be combined interchangeably with the features, advantages, and characteristics of any other exemplary embodiment.
[0027] One aspect of the proposed system and process relates to a device-binding authentication method that leverages the unique computational flow of a graphics processing unit (GPU) to derive a device signature and / or fingerprint for verifying the source device. More specifically, the invention utilizes an NFC-based connection of a cryptographic OTP authentication card to provide an input image read by an NFC reader for processing on a mobile device. This image will correspond to a high-entropy pattern to exaggerate GPU differences in the rendered output. The output of the image processing buffer associated with a browser application (equipped with a WebGL API) running on the mobile device can then be hashed and used as a device identifier for a specific mobile device. The proposed device-binding method can be readily integrated with a cryptographic OTP authentication process to enhance the authentication strength of the OTP card authentication signal by verifying the identity of the card reader device with high determinism.
[0028] The proposed solution provides an authentication strength factor (based on using a GPU-based device signature as a device verification signal) without requiring additional authentication by the user. This has inherent value in secure electronic transaction processing. Furthermore, by leveraging the NFC nature of the encrypted OTP authentication process, the process of this invention can be operationally integrated with contactless OTP card technology. This will enhance the strength of the authentication process through a verifiable GPU signature associated with the source device.
[0029] Figure 1 An exemplary system implementation 100 of an authentication process with device binding functionality based on GPU fingerprinting (e.g., providing a unique processing signature associated with a specific GPU) is illustrated. In some embodiments, the GPU fingerprinting process may be implemented to determine a device signature of client device 108 (e.g., based on an operational signature associated with the device's GPU). The GPU fingerprinting process 102 may be implemented as part of a WebGL-supplemented mobile browser represented by application 118 on client device 108, such as... Figure 1 As shown.
[0030] In some embodiments, the device signature used to facilitate device binding authentication can be implemented as a function of an image rendering process associated with a specific GPU (e.g., GPU 116). The image rendering process associated with GPU 116 can be executed on an input image 133 retrieved from an image storage device (e.g., image hosting server 130). Figure 1 As shown, the GPU fingerprint calculation process 102 can be implemented as part of a browser with WebGL extensions running on a client device 108 (e.g., a mobile device associated with a user). The exemplary system implementation 100 also includes a network 106, an authentication server 110, a database 109, and an image hosting device / server 130. Although Figure 1 A single instance of a component of system 100 is shown, but system 100 may include any number of components.
[0031] Authentication server 110 may include one or more processors 111 and memory 112. Memory 112 may include one or more applications, such as application 114. According to exemplary embodiment 100, device signature verification process 119 may be implemented as part of application 114 stored on authentication server 110. Authentication server 110 may communicate data with any number of components of system 100. For example, authentication server 110 may be configured as a central system, server, or platform to control and invoke various data at different times to perform multiple workflow actions, such as verification of device signature 120, which is calculated by process 102 running on client device 108 and transmitted to authentication server for verification. Authentication server 110 may be configured to connect to client device 108 and image hosting device 130. Client device 108 may communicate data with application 114 running device signature verification process 119. For example, client device 108 may communicate data with application 114 and image hosting device 130 via one or more networks 106. Authentication server 110 may, for example, transmit one or more requests to client device 108 from application 114 running on it. One or more requests may be associated with retrieving device signature 120 from client device 108. Client device 108 may receive one or more requests from authentication server 110. Without limitation, authentication server 110 may be a network-enabled computer. As described herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, network equipment, personal computers, workstations, telephones, handheld PCs, personal digital assistants, contactless cards, thin clients, fat clients, internet browsers, kiosks, tablets, terminals, ATMs, or other devices. Authentication server 110 may also be a mobile device; for example, a mobile device may include Apple®'s iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.
[0032] The authentication server 110 may include processing circuitry and may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, to perform the functions described herein as needed. The authentication server 110 may also include display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any available and supported device for inputting information to the authentication server, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or camcorder. These devices can be used to input information and interact with the software and other devices described herein.
[0033] The information used by the device signature verification process 119, for example, running on the authentication server 110, may include one or more user authentication data (associated with the target user account) provided by the client device 108 via the network 106 and / or one or more stored device signature records (calculated based on image 133), and correspond to a previous device authentication attempt initiated from the client device 108 and transmitted to the authentication server 110 via the network 106.
[0034] In some examples, network 106 can be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and can be configured to connect to any component of system 100. For example, authentication server 110 can be configured to connect to client device 108 via network 106. In some examples, network 106 can include one or more of the following: fiber optic network, passive optical network, cable network, Internet, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, IEEE 802.15.1, IEEE 802.11n and IEEE 802.11g, Bluetooth, NFC, radio frequency identification (RFID) and / or Wi-Fi.
[0035] Furthermore, network 106 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Additionally, network 106 may support the Internet, wireless communication networks, cellular networks, and any combination thereof. Network 106 may also include one network, or any number of networks of the aforementioned exemplary types, operating as independent networks or collaborating with each other. Network 106 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 106 may convert one or more protocols of network devices to other protocols, or convert from other protocols to one or more protocols of network devices. Although network 106 is depicted as a single network, it should be understood that, depending on one or more examples, network 106 may include multiple interconnected networks, such as, for example, the Internet, service provider networks, cable television networks, corporate networks (such as credit card association networks), and home networks.
[0036] like Figure 1 As shown in the exemplary system implementation 100, client device 108 may include one or more processors 115 coupled to GPU 116 and memory 117. Client device 108 may be configured as a central system, server, or platform to control and invoke various data at different times to perform multiple workflow actions. Client device 108 may be configured to connect to any component of system 100 via network 106. Client device 108 may be a dedicated server computer, such as a blade server, or may be a personal computer, laptop computer, notebook computer, handheld computer, network computer, mobile device, wearable device, or any device capable of supporting processor control of system 100. Although Figure 1 A single client device 108 is shown, but it should be understood that other embodiments may use multiple servers or multiple computer systems to support users as needed or desired, and backup or redundant servers may also be used to prevent network downtime in the event of a failure of a particular server.
[0037] Client device 108 can communicate data with image hosting device / server 130 and the processor 111 of authentication server 110. For example, client device 108 can communicate data with the processor 111 of authentication server 110 via one or more networks 106. Authentication server 110 can send one or more requests to client device 108. One or more requests can be associated with retrieving data from client device 108 and can be generated in response to an authentication request from a source device (e.g., client device 108). Client device 108 can receive one or more requests from any component of authentication server 110. Client device 108 can be configured to transmit the requested data to the processor 111 of authentication server 110.
[0038] Client device 108 may include processor 115. Processor 115 may be, for example, one or more microprocessors. Processor 115 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, to perform the functions described herein as needed.
[0039] Client device 108 may include one or more applications 118, which include instructions for execution thereon. For example, the applications may reside in memory 117 of client device 108 and may include instructions for execution on client device 108. Applications 118 of client device 108 may communicate with any component of system 100. For example, client device 108 may execute one or more applications capable of, for example, network and / or data communication with one or more components of system 100 and sending and / or receiving data. Without limitation, client device 108 may be a network-enabled computer. As described herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, network equipment, personal computers, workstations, telephones, handheld PCs, personal digital assistants, contactless cards, thin clients, fat clients, internet browsers, or other devices. The functionality associated with client device 108 can also be implemented on mobile devices; for example, mobile devices may include Apple®’s iPhone, iPod, iPad or any other mobile device running Apple’s iOS® operating system, any device running Microsoft’s Windows® mobile operating system, any device running Google’s Android® operating system and / or any other smartphone, tablet or similar wearable mobile device.
[0040] Client device 108 may include processing circuitry and may include additional components, including a processor, GPU, memory, error and parity / CRC checker, data encoder, anti-collision algorithm, controller, command decoder, security primitives, and tamper-proof hardware, to perform the functions described herein as needed. Client device 108 may also include display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device available and supported by the client device for inputting information, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or camcorder. These devices can be used to input information and interact with the software and other devices described herein.
[0041] System implementation 100 may include one or more databases 109. The one or more databases 109 may include relational databases, non-relational databases, or other database implementations and any combination thereof, including multiple relational databases and non-relational databases. In some examples, database 109 may include a desktop database, a mobile database, or an in-memory database. Furthermore, one or more databases 109 may be hosted internally by any component of system 100, such as authentication server 110 and / or client device 108. One or more databases 109 may also be hosted externally by a cloud-based platform to any component of system 100, or hosted in any storage device that communicates data with authentication server 110 and client device 108. In some examples, database 109 may communicate data with any number of components of system 100. For example, client device 108 may be configured to retrieve data requested by processor 111 of authentication server 110 from database 109. Client device 108 may be configured to transmit data received from database 109 to processor 111 via network 106, the received data being a response to one or more transmitted requests. In other examples, processor 111 may be configured to transmit one or more requests for requested data to database 109 via network 106.
[0042] Figure 2This document provides an overview of an exemplary mobile browser operation that generates a device fingerprint based on a hashed image identifier. The hashed image identifier can be computed by processing the rendered image data associated with the input image using a cryptographic hash function. The mobile browser's rendering process can leverage the mobile device's graphics processing unit (GPU) via integrated WebGL functionality. WebGL is an application programming interface (API) for graphics rendering that can be fully controlled by the web browser. The WebGL specification allows internet browsers to access the GPU on the device, enabling the GPU to be incorporated into graphics computations performed by the web browser running on the mobile device. This facilitates GPU hardware-accelerated architectures where graphics processing is performed directly by browser applications. The output of the WebGL-complemented image rendering process corresponds to rendered image data (e.g., a digital image), which can be stored in a framebuffer (e.g., a portion of read-access memory containing the complete frame data intended for output to the display). In GPU-accelerated computation, the raw image data can be loaded into the GPU. Whenever the rendering process encounters a computationally intensive part of the code, that part of the code can be loaded and run on the GPU.
[0043] Differences in operating system type and version, as well as other software and hardware variations and performance characteristics, can cause GPUs to execute different computational paths and different sets of operations when rendering images. This can lead to differences in pixel output associated with the reproduction of compressed images. If the input image being rendered corresponds to a high-entropy data pattern that is very difficult to compress, the differences in the GPU's pixel output can be particularly exaggerated.
[0044] In some embodiments, information about the WebGL version and information about the operating system version can be extracted based on specific pixel outputs during the image rendering process and encoded into a hash identifier calculated on the rendered image data. The hash identifier can then be used as a device fingerprint. Figure 2 An overview of an exemplary process for enhancing one-time password (OTP) card authentication using GPU-based device binding is provided. Exemplary process 200 utilizes NFC data transmission 202 from a contactless card 204 to a computing device (e.g., a mobile device 206) to facilitate the image rendering process of a mobile internet browser 208 running on the mobile device 206. Figure 2 The operation of the mobile browser 208 is further illustrated, which generates a device fingerprint from rendered image data processed by a cryptographic hash function. The image rendering process performed by the mobile browser 208 can be combined with WebGL functionality to utilize the graphics processing unit (GPU) of the mobile device (206) during image rendering, thereby inserting the processing signature of the corresponding GPU into the rendered image data.
[0045] The operation for a mobile browser performing GPU-assisted rendering of an input image using the WebGL API is illustrated in Figure 210. Based on the process shown in Figure 210, an image processing signature can be derived and used as a device fingerprint of a computing device (e.g., mobile device 206). As described above, this process can be invoked in response to a Near Field Communication (NFC) transmission 202 from a contactless card 204. The NFC transmission 202 may include an authentication message that includes a Uniform Resource Locator (URL) pointing to an image (e.g., raw image data) to be retrieved by the mobile browser 208. In some embodiments, the authentication message transmitted via the NFC transmission 202 may include the raw image data locally stored on an NFC tag of the contactless card.
[0046] The authentication message transmitted from the contactless card 204 can be received by the NFC reader 210 and passed to the mobile device 206 for processing. The NFC reader 210 can be integrated into the mobile device 206. In some embodiments, such as scenarios where NFC reading applications and / or capabilities are unavailable on computing and / or mobile devices, WebNFC functionality can be encoded in a website to enable direct reading of the contactless card 204 via a website launched, for example, on a personal computer (PC) terminal. Regarding... Figure 3 , Figure 4 and Figure 5 Various embodiments for transferring raw image data 212 to a computing device by utilizing the NFC reading capability of a contactless (OTP) card 204 are further discussed.
[0047] Return to reference Figure 2 Once the browser application (208) receives the raw image data 212, whether directly from the NFC transmission 202 or via a URL encoded therein, the browser can utilize the computing resources provided by the graphics processing unit (GPU) to process and render the image. GPU functionality can be accessed via the WebGL API 214 incorporated into the browser application 208.
[0048] The output of the image rendering process (e.g., rendered image data 218) can be written to frame buffer 215. Frame buffer 215 can store the rendered image data 218 that can be displayed as a digital image. The contents 216 of frame buffer 215 can then be hashed using a cryptographic hash function 220 to generate an image hash identifier 222. As previously mentioned, the raw image data 212 can be associated with a high-entropy data pattern to exaggerate GPU differences in the rendered output (218). In some embodiments, frame buffer 215 can correspond to a fixed-size buffer to prevent variations in the rendered image data 218 due to different screen resolutions associated with the computing / mobile device 206.
[0049] By utilizing different computational streams of the GPU, the image rendering process 210 can generate output (e.g., rendered image data 218) with a unique device-specific signature. Therefore, hashing the rendered image data provides a hash identifier 222, which can be used as a GPU-based device fingerprint to verify the source device. The hash identifier 222 (interchangeably referred to as the image hash identifier) can then be mapped to the GPU of the mobile device 206 and used as the GPU-based device fingerprint of the mobile device 206. The GPU-based device fingerprint 222 can then be transmitted to an authentication server (e.g., a backend authentication server 224) storing one or more user device fingerprint records 226 associated with previous authentication requests initiated by the contactless card 204 via the mobile device 206 for verification. In some embodiments, the generated GPU-based device fingerprint can be integrated into the operation of the contactless OTP authentication card (e.g., contactless card 204) to add a strength factor to the OTP card authentication signal.
[0050] In some examples, the exemplary processes described herein can be performed by a computer hardware device. Such a computer hardware device may be, for example, all or part of a computer and / or processor, or include, but is not limited to, a computer and / or processor that may include, for example, one or more microprocessors, and uses instructions stored on a non-transitory computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device). For example, the computer-accessible medium may be part of the memory and / or other computer hardware device of the systems and devices described herein.
[0051] In some examples, a computer-accessible medium (e.g., storage devices such as hard disks, floppy disks, memory sticks, CD-ROMs, RAM, ROMs, etc., or combinations thereof, as described herein) may be provided (e.g., for communication with a computer hardware device). The computer-accessible medium may contain executable instructions thereon. Alternatively or separately, a storage device may be provided separately from the computer-accessible medium, which may provide instructions to the computer hardware device. The instructions may configure the computer hardware device to perform certain exemplary programs, processes, and methods, for example, as described above.
[0052] Figure 3 An exemplary implementation of GPU-based (mobile) device authentication is illustrated, initiated by an NFC transmission of an image URL 301 from a contactless card 302 to facilitate a GPU-based device signature for a computing mobile device 304. In some embodiments, the computed device signature / fingerprint can be used as an authentication factor in a multi-factor authentication process (e.g., such as...). Figure 3The multi-factor authentication connection 330 (as indicated in the connection) is used to verify electronic data access requests and / or merchant transactions initiated by using contactless card 302 and mobile device 304.
[0053] Return to reference Figure 3 The computation of the GPU-based device signature can be performed via NFC reader 306 (e.g., using a corresponding reader application running on mobile device 304). Figure 3 (Not shown) An NFC read of an authentication record stored on a contactless card 302 is initiated. The authentication record transmitted via NFC may include an image URL 301 pointing to an image data file (e.g., raw image data) to be retrieved by the mobile device 304. Once retrieved by the mobile device 304, the URL may be passed to a browser application 308 running on the mobile device. In some embodiments, the initial URL request message from the mobile browser 308 may be redirected to a target server hosting the image (e.g., storing the raw image data). This is illustrated by the initial URL request / response communication 310 between the mobile device 304 and the destination identified by the URL (e.g., server 312). The image 318 can then be retrieved from the hosting server (e.g., authentication server 314). The authentication server 314 may also store one or more data records 316 corresponding to a previous hash identifier of the image 318 associated with a previously successful authentication attempt (using a device fingerprint) initiated from the mobile device 304.
[0054] refer to Figure 3The original image data 319 (associated with image 318) can be retrieved from authentication server 314 and processed by mobile browser 308 running on mobile device 304 to generate rendered image data in framebuffer 320. The framebuffer data can then be hashed through cryptographic hashing process 322 to generate an image hash identifier 324, which can be used as a GPU-based device fingerprint of mobile device 304. Image hash identifier 324 can be sent to authentication server 314 for comparison with a previously stored image hash identifier 316 associated with a previous device authentication attempt using mobile device 304. If the comparison with the previously stored image hash identifier produces a match, indicating that the same device was used in the previous authentication attempt, device verification response 326 can be generated and sent to authentication request server 328. The device verification response 326 may correspond to a standalone authentication response, or it may be incorporated as part of a multi-factor authentication (e.g., multi-factor authentication connection 330) along with other encrypted user identification data that may be stored on the contactless card 302 and transmitted along with the device signature 324. Therefore, integrating the GPU-based device fingerprint (e.g., 324) into the cryptographic authentication process associated with the OTP authentication card (e.g., 302) facilitates the multi-factor authentication connection 330 between the mobile device (initiated by the contactless card 302) and the target server 328.
[0055] In some embodiments, the contactless card 302 may correspond to an OTP contactless card with a unique configuration having an integrated processor 331 and an NFC tag 332 storing NFC-transferable user authentication data (e.g., readable by a mobile device with a reader component and running a corresponding application). The contactless card 302 may also include a counter 333, also known as an Application Transaction Counter (ATC), for tracking OTP transactions initiated by the contactless card, and one or more applets 334 for facilitating the generation of OTP authentication passwords. In some embodiments, the transaction counter value may be updated for each OTP transaction initiated by the contactless card.
[0056] In some embodiments, the URL may include embedding instructions for rendering multiple images to be periodically rotated. The multiple images may be stored on a specified web server and / or multiple different servers.
[0057] Figure 4An exemplary embodiment 400 is illustrated, in which raw image data is stored directly on a contactless card 402, for example, as a Near Field Communication Data Exchange Format (NDEF) file 403. In embodiment 400, NFC transmission 406 may correspond to the raw image data and an image identifier, corresponding to the Multipurpose Internet Mail Extensions (MIME) media type stored on the contactless card 402 as an NDEF file 403. In response to bringing the contactless card into the NFC range of a mobile device with an operable NFC reader (e.g., tapping the contactless card on the mobile device's reader), the NDEF file, including the raw image data and the image MIME type, is transmitted to the mobile device's reader 405. Upon receiving NFC transmission 406, the raw image data 407 may be passed to and processed by a mobile browser running on the mobile device 404 to generate rendered image data in a frame buffer 410. The frame buffer data 412 is then hashed by a cryptographic hashing process 414 to generate an image hash identifier 416, which can be used as a GPU-based device fingerprint. A hashed image identifier is transmitted to authentication server 418 for comparison with a stored record 420, which corresponds to a previously stored hash identifier of an NDEF image file 403 associated with a previous device authentication attempt initiated from mobile device 404. If a match is determined, indicating that the same device was used in the previous authentication attempt, a device verification response 422 is generated and transmitted to, for example, authentication request server 424. The device verification response 422 may be provided as a separate device binding authentication signal associated with mobile device 404 and / or together with other encrypted user identification data that may be stored on contactless card 402 and transmitted with mobile device fingerprint 416 as part of multi-factor authentication 426. This can then facilitate a multi-factor authentication connection 428 to destination server 424 based on the authentication pairing of contactless card 402 and mobile device 404.
[0058] Figure 5An exemplary embodiment is shown for a scenario supporting an NFC application in which a mobile device (e.g., mobile device 502) may not have NDEF reading capability and / or be used to establish an NFC link with a contactless card 504. In this scenario, the Web Near Field Communication (WebNFC) API 509 can be used to retrieve an input image 506 (e.g., raw image data and image MIME type) from the contactless card 504 via a direct NFC read 507 of the contactless card through an authentication website 508. WebNFC is a low-level API that provides the website with the ability to read and write to nearby NFC devices. The authentication website 508 (enabled by WebNFC) can be provided by an authentication server 510 and accessed, for example, via a browser application running on a personal computer 512. The input image data 506 can then be transmitted from the authentication server 510 to the user mobile device via a network connection 517 established between the authentication server 510 and the user mobile device (e.g., via network transmission 516). Subsequently, image data retrieved (directly from the contactless card) by the verification website (e.g., via the WebNFC process) can be sent to the registered mobile device (e.g., mobile device 514 associated with the user) for rendering. The rendered image data 518 can then be read directly from a browser and hashed (e.g., via a cryptographic hash function 519) to generate an image hash identifier 520. The image hash identifier 520, representing the digital fingerprint associated with mobile device 514, is transmitted to authentication server 510 for verification against a previous authentication record 522. If a match is determined, authentication server 510 can determine that the received message has not been spoofed by a different device (e.g., different from mobile device 514) used by a hacker to facilitate a fraudulent user verification process, and subsequently transmits a device verification response 524 to the authentication request entity (e.g., merchant server 526).
[0059] In some embodiments, a WebNFC-enabled website 508 can be launched directly on a mobile device 514 to facilitate NFC-based retrieval of image data from a contactless card 504 via a direct NFC read 507.
[0060] As described above, the WebNFC function can be encoded in a website to enable a WebNFC-enabled website, activated on a computing and / or mobile device associated with the user, to directly read the contactless card 504. In some embodiments, the WebNFC function can be encoded in a merchant website to enable a WebNFC-enabled merchant website, activated on a computing and / or mobile device associated with the user, to directly read the contactless card 504. The input image data can then be read directly from the contactless card by the merchant web server (via the WebNFC-enabled merchant website) and transmitted to the mobile device associated with the phone number provided by the user initiating the transaction. The image can then be rendered by a mobile browser (using the WebGL API) running on the mobile device, and the hash identifier of the rendered image is transmitted back to the merchant web server. The merchant web server can then transmit the hash identifier (e.g., a device fingerprint) to an authentication server for verification against a previous authentication record. If a match is determined, the authentication server can send a device verification response to the merchant web server.
[0061] Figure 6 An exemplary flowchart 600 for generating and verifying GPU-based mobile device fingerprints is shown. The exemplary process 600 can be initiated by acquiring an input image (e.g., raw image data rendered by a WebGL-enabled browser running on the mobile device). Acquisition of the raw image data can be facilitated by an NFC transfer from a contactless card, as shown in step 602. Acquisition of the raw image data by the mobile device can be implemented by any of the operations described in steps 602.1, 602.2, or 602.3. For example, an NFC transfer from a contactless card to a mobile device reader may include a URL pointing to a server hosting the raw image data (e.g., step 602.1). Alternatively, an NFC transfer from a contactless card to a mobile device reader may include the actual raw image data stored together with an image identifier in an NDEF file on the contactless card (e.g., step 602.2). NFC transfers can also be initiated using WebNFC between a website and a contactless card and transmitted to the mobile device via a network connection (e.g., step 602.3).
[0062] After retrieving the original image data in step 602, at step 604, the retrieved image data is rendered by the corresponding mobile browser using a WebGL procedure. Then, at step 606, the output of the image rendering procedure associated with the specific GPU signature is hashed to generate an image hash identifier representing a GPU-based device fingerprint. Then, at step 608, the image hash identifier (e.g., a mobile device fingerprint) can be transmitted to an authentication server for verification. The authentication server may store records corresponding to previous hash identifiers of the input image associated with a previous authentication attempt. At step 610, the verification process may involve matching the received image hash identifier against one or more previously stored image hash identifiers (e.g., previous authentication records). In some embodiments, the comparison may involve a recently stored device fingerprint record. If a positive match is determined at step 610, the mobile device is authenticated as a valid user device at step 612, and device factor authentication can be added to the OTP authentication process associated with the contactless card. If no match is determined at step 610, a device mismatch notification can be generated at step 614 and transmitted back to the authentication requester and / or the transmitting mobile device.
[0063] Figure 7 The timing associated with an exemplary GPU-based device verification process 700 is illustrated. The exemplary process 700 corresponds to a URL-directed acquisition of an input image (e.g., raw image data from a contactless card 702) by a mobile device 704 communicatively coupled to a redirection server 706 and / or an authentication server 708. The computed GPU-based device fingerprint can then be used as an authentication factor to verify electronic data access requests initiated from the mobile device 704 and / or user transactions with a security system (e.g., a merchant server 710). The exemplary process 700 can be triggered by a reader component (a corresponding reader application with the mobile device 704) via an NFC-based reading of the image URL (e.g., a URL pointing to a raw image data file). The reading operation can be initiated, for example, by tapping the contactless card 702 on the reader of the mobile device 704. According to some embodiments, the initial URL request can be redirected (e.g., as indicated in request / response communication 714) to a target server, such as the authentication server 708, that can host the image data file. This is illustrated by communication 716 between the mobile device 704 and the redirection destination (e.g., authentication server 708) for obtaining raw image data to be processed on the user's mobile device 704.
[0064] The raw image data retrieved from the hosting server (e.g., authentication server 708) can then be rendered by a client browser application running on the mobile device to generate rendered image data, as shown in operation 717. The contents of the framebuffer associated with the output of the image rendering process (e.g., a WebGL process of the mobile browser) can then be hashed by a cryptographic hashing process (e.g., operation 718) to generate an image hash identifier, which can be used as a GPU-based device signature and / or fingerprint. The image hash identifier is transmitted (as indicated in transmission 720) to authentication server 708 for comparison with a previously stored image hash identifier associated with a previous device authentication attempt using mobile device 704.
[0065] After a successful match with one or more previously identified hash identifiers is determined during the verification process 722, the mobile device is verified by the authentication server 708. Following successful verification of the mobile device 704 by the authentication server 708, a device authentication message 724 may be transmitted to the authentication request entity (e.g., merchant server 710) as a standalone device authentication response and / or as part of a multi-factor authentication process supplemented with other encrypted user identification data. This message may be stored on the contactless card 702 and transmitted to the authentication server along with the device signature (e.g., image hash identifier 720) for verification.
[0066] Figure 8 The timing associated with an exemplary GPU-based device authentication process 800 is illustrated. The exemplary process 800 corresponds to the direct acquisition of an input image (e.g., raw image data from the contactless card 802) by a mobile device 804 via an NFC proximity link 805 established between a contactless card 802 and the user's mobile device 804. The mobile device 804 may also be communicatively coupled to an authentication server 806. The raw image data retrieved directly from the contactless card 802 can then be rendered by a client browser application running on the mobile device 804 to generate rendered image data, as indicated in operation 810. The contents of the framebuffer associated with the output of the image rendering process (e.g., a WebGL process of a mobile browser) can then be hashed by a cryptographic hashing process (e.g., operation 812) to generate an image hash identifier, which can be used as a GPU-based device signature and / or fingerprint. The image hash identifier is transmitted (indicated by transmission 813) to the authentication server 806 for comparison with a previously stored image hash identifier associated with a previous device authentication attempt using the mobile device 804.
[0067] After a successful match with one or more previously identified hash identifiers is determined during the verification process 814, the mobile device is verified by the authentication server 806. Following successful verification of the mobile device 804 by the authentication server 806, a device authentication message 816 may be transmitted to the authentication request entity (e.g., merchant server 808) as a standalone device authentication response and / or as part of a multi-factor authentication process supplemented with other encrypted user identification data. This message may be stored on the contactless card 802 and transmitted to the authentication server along with the device signature (e.g., an image hash identifier 813) for verification.
[0068] Figure 9 Block diagrams illustrating exemplary embodiments of a system according to this disclosure are shown. For example, exemplary processes according to this disclosure may be performed by a computer hardware device 905. Such computer hardware device 905 may be, for example, all or part of a computer and / or processor 910, or include, but are not limited to, a computer and / or processor 910, which may include, for example, one or more microprocessors and uses instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device).
[0069] like Figure 9 As shown, for example, computer-accessible medium 915 (as described above) may include storage devices such as hard disks, floppy disks, memory sticks, CD-ROMs, RAM, ROMs, etc., or may provide a combination thereof (e.g., communicating with computer hardware device 905). Executable instructions 920 may be contained on computer-accessible medium 915. Alternatively or separately, storage device 925 may be provided separately from computer-accessible medium 915, and may provide instructions to processing device 905. For example, the instructions may configure computer hardware device to perform the exemplary programs, processes, and methods described above.
[0070] Furthermore, the exemplary computer hardware device 905 may be provided with or include an input / output port 935, which may include, for example, a wired network, a wireless network, the Internet, an intranet, a data collection probe, a sensor, etc. Figure 9 As shown, the exemplary computer hardware device 905 can communicate with the exemplary display device 930, which, according to certain exemplary embodiments of the present disclosure, can be a touchscreen configured to input information to the processing device, for example, in addition to outputting information from the processing device. Furthermore, the exemplary display device 930 and / or storage device 925 can be used to display and / or store data in a user-accessible and / or user-readable format.
[0071] As used herein, the term "card" is not limited to a particular type of card. Rather, it is understood that, unless otherwise stated, the term "card" can refer to a contact-based card, a contactless card, or any other card. It should also be understood that this disclosure is not limited to cards for a specific purpose (e.g., payment cards, gift cards, ID cards, membership cards, transportation cards, access cards), cards associated with a specific type of account (e.g., credit accounts, debit accounts, membership accounts), or cards issued by a specific entity (e.g., commercial entities, financial institutions, government entities, social clubs). Rather, it is understood that this disclosure includes cards for any purpose, account associated with, or issued by any entity.
[0072] The systems and methods described herein can provide secure retrieval of sensitive user information or enable simplified communication and processing of sensitive user information, for example, to facilitate secure electronic transactions. Once a valid authorization response has been established from an authenticated device and / or user, automated data retrieval and transmission systems and processes can permit, but are not limited to, financial transactions (e.g., credit and debit card transactions), account management transactions (e.g., card refresh, card replacement, and new card addition transactions), membership transactions (e.g., joining and leaving transactions), access point transactions (e.g., building access and secure storage access transactions), transportation transactions (e.g., ticketing and boarding transactions, and other transactions).
[0073] It should also be noted that the systems and methods described herein can be tangibly embodied in one or more physical media, such as, but not limited to, optical discs (CDs), digital versatile optical discs (DVDs), floppy disks, hard disks, read-only memory (ROM), random access memory (RAM), and other physical media for data storage. For example, a data storage device may include random access memory (RAM) and read-only memory (ROM), which can be configured to access and store data and information, as well as computer program instructions. A data storage device may also include storage media or other suitable types of memory (e.g., such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical discs, floppy disks, hard disks, removable magnetic tape, flash drives), and any type of tangible and non-transitory storage medium in which files including operating systems, applications including, for example, web browser applications, email applications and / or other applications, and data files can be stored. Data storage in network-enabled computer systems can include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases (such as databases created and maintained using software from, for example, Oracle®), Microsoft® Excel files, Microsoft® Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage (which may include online or cloud storage), or any other storage mechanism. Furthermore, the accompanying drawings illustrate various components (e.g., servers, computers, processors, etc.). Functions described as performing on various components can be performed on other components, and the various components can be combined or separated. Other modifications are also possible.
[0074] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing and / or processing device, or downloaded via a network to an external computer or external storage device, such as the Internet, a local area network (LAN), a wide area network (WAN), and / or a wireless network. This network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing and / or processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the corresponding computing and / or processing device.
[0075] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, or C++, and traditional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter case, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., via the Internet provided by an Internet service provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) may execute the computer-readable program instructions by utilizing state information from the computer-readable program instructions to personalize the electronic circuitry, thereby performing aspects of the invention.
[0076] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for performing the functions specified herein. These computer-readable program instructions may also be stored in a computer-readable storage medium that can instruct a computer, programmable data processing apparatus, and / or other device to operate in a certain manner, such that the computer-readable storage medium in which the instructions are stored includes an article of writing containing the instructions, which perform aspects of the functions specified herein.
[0077] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device, thereby producing a computer-implemented process, such that the instructions executed on the computer, other programmable apparatus or other device perform the function specified herein.
[0078] This disclosure is not limited to the specific embodiments described herein, which are intended to illustrate various aspects. Many modifications and variations may be apparent without departing from its spirit and scope. Functionally equivalent methods and apparatuses within the scope of this disclosure may be apparent from the foregoing representative descriptions, in addition to those methods and apparatuses listed herein. These modifications and variations are intended to fall within the scope of the appended representative claims. This disclosure is limited only by the terms of the appended representative claims and the full scope of their equivalents. It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only and is not intended to be limiting.
[0079] The foregoing description and related embodiments are given for illustrative purposes only. They are not exhaustive and do not limit the invention to the precise forms disclosed. Those skilled in the art will understand from the foregoing description that modifications and variations are possible in accordance with the above teachings, or can be obtained from the practice of the disclosed embodiments. For example, the described steps need not be performed in the same order or with the same degree of separation as discussed. Similarly, various steps may be omitted, repeated, or combined as needed to achieve the same or similar objectives. Therefore, the invention is not limited to the above embodiments, but is defined by the appended claims according to the full scope of their equivalents.
[0080] Various preferred embodiments have been described in the foregoing description with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be implemented without departing from the broader scope of the invention as set forth in the following claims. Therefore, the description and drawings should be considered illustrative rather than restrictive.
Claims
1. A method for enhancing one-time password (OTP) card authentication with graphics processing unit (GPU) based device binding, the method comprising: receiving, by a mobile device from a contactless card via near field communication (NFC) transmission, an authentication message corresponding to a user authentication request, the authentication message being operative to provide raw image data associated with an image to a mobile browser running on the mobile device; rendering, by the mobile browser using a web graphics library (WebGL) application programming interface (API), an image associated with raw image data; generating, using the WebGL API, an image hash identifier from rendered image data generated by the mobile browser, the image hash identifier corresponding to the user authentication request; mapping, with a GPU associated with the mobile device, the image hash identifier for binding the mobile device to the authentication message provided by the NFC transmission from the contactless card; comparing, by an authentication server, the image hash identifier received from the mobile device with one or more previously stored hash identifiers associated with one or more previous user authentication requests; verifying, by the authentication server, the mobile device based on a determination of a match between the image hash identifier received from the mobile device responsive to the user authentication request and the one or more previously stored hash identifiers associated with the one or more previous user authentication requests.
2. The method of claim 1, wherein, the authentication message includes a uniform resource locator (URL) pointing to the image, the image being hosted on a web server, and the mobile device, in response to receiving the URL, is operative to retrieve raw image data from the web server.
3. The method of claim 2, wherein, the raw image data associated with the image is retrieved from the web server through a URL redirection.
4. The method of claim 3, wherein, the URL includes embedded instructions for redirecting to a plurality of images to be periodically rotated, the plurality of images being stored on the web server.
5. The method of claim 4, wherein, the plurality of images are stored on one or more different web servers.
6. The method of claim 1, wherein, the raw image data is stored in a near field communication data exchange format (NDEF) file on the contactless card, the NDEF file further including an image identifier of a multipurpose internet mail extensions (MIME) media type corresponding to the image for facilitating rendering of the image by the mobile browser WebGL API.
7. The method of claim 6, wherein, the NDEF file is transmitted from the contactless card to the mobile device via the NFC transmission for rendering.
8. The method of claim 6, wherein, the raw image data associated with the image is read directly from the contactless card by a web server via web near field communication (WebNFC) and transmitted to a mobile browser on the mobile device for rendering.
9. The method of claim 1, wherein, the transmission of the authentication message is initiated by an NFC reader application running on the mobile device performing an NFC read of the contactless card.
10. The method of claim 1, wherein, the raw image data includes a high-entropy pattern to exaggerate GPU differences when generating rendered image data.
11. The method of claim 1, wherein, The image is rendered by the mobile browser in a fixed size frame buffer to prevent variations in rendered image data due to different screen resolutions.
12. A multi-factor authentication system based on integrating a device binding function with a one-time password authentication card, the system comprising a computer hardware device configured to: provide first image data associated with an image to a mobile browser running on a user's mobile device, the first image data received from a contactless card associated with the user as part of an authentication message, in response to a user authentication request; render an image from the first image data using a web graphics library (WebGL) function associated with the mobile browser to generate second image data; generate an image hash identifier from the second image data; map the image hash identifier with a graphics processing unit (GPU) associated with the mobile device to bind the mobile device with the authentication message transmitted from the contactless card; compare, by an authentication server, the image hash identifier received from the mobile device with one or more previously stored hash identifiers associated with one or more previous user authentication requests; verify, by the authentication server, the mobile device based on a determination of a match between the image hash identifier received from the mobile device in response to the user authentication request and the one or more previously stored hash identifiers associated with one or more previous user authentication requests.
13. The system of claim 12, wherein, The system is further configured to encode a uniform resource locator (URL) pointing to the image hosted on a web server into the authentication message, the URL directing the mobile browser to retrieve the first image data from the web server.
14. The system of claim 13, wherein, The URL includes embedded instructions for redirecting to a plurality of images to be periodically rotated, the plurality of images stored on the web server.
15. The system of claim 12, wherein, The first image data is stored on the contactless card and transmitted to the mobile device via a NFC transmission from the contactless card for rendering, the NFC transmission further including an image identifier corresponding to a multipurpose internet mail extensions (MIME) media type of the image to facilitate rendering of the image by a WebGL function of the mobile browser.
16. The system of claim 12, wherein, The first image data corresponds to raw image data having a high-entropy pattern to exaggerate GPU differences when generating the second image data, the second image data corresponding to rendered image data.
17. A non-transitory computer-accessible medium comprising instructions for execution by computer hardware devices, wherein, The computer hardware device, when executing the instructions, is configured to perform a program comprising: receiving, by a mobile device, an authentication message from a contactless card via a near field communication (NFC) transmission, the authentication message corresponding to a user authentication request, operative to provide raw image data associated with an image to a mobile browser running on the mobile device; rendering, by the mobile browser, the image associated with the raw image data using a web graphics library (WebGL) application programming interface (API); generating an image hash identifier from rendered image data generated by the mobile browser using the WebGL API, the image hash identifier corresponding to the user authentication request; mapping the image hash identifier with a graphics processing unit (GPU) associated with the mobile device to provide a binding between the mobile device and the authentication message provided by the NFC transmission from the contactless card; comparing, by an authentication server, the image hash identifier received from the mobile device with one or more previously stored hash identifiers associated with one or more previous user authentication requests; verifying, by the authentication server, the mobile device based on a determination of a match between the image hash identifier received from the mobile device in response to the user authentication request and the one or more previously stored hash identifiers associated with one or more previous user authentication requests.
18. The non-transitory computer accessible medium of claim 17, further comprising instructions to encode a uniform resource locator (URL) pointing to an image hosted on a web server into the authentication message, the URL directing the mobile browser to retrieve the original image data from the web server.
19. The non-transitory computer accessible medium of claim 17, further comprising instructions to redirect to a plurality of images to be periodically rotated.
20. The non-transitory computer accessible medium of claim 17, further comprising instructions to render the image directly from the NFC transmission received from the contactless card, the NFC transmission including original image data and a multipurpose internet mail extensions (MIME) media type associated with the image and stored on the contactless card.