Secure authentication based on identity data stored in a contactless card

CN113316784BActive Publication Date: 2026-09-11CAPITAL ONE SERVICES LLC
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202080007261.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2019-12-24
Filing Date
2020-11-23
Publication Date
2026-09-11
Estimated Expiration
2040-11-23

AI Technical Summary

Technical Problem

此外,不同的系统可能需要不同类型的附加信息来进行身份验证,使得常规的解决方案对于许多用户是不实用的

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113316784B_ABST
    Figure CN113316784B_ABST
Patent Text Reader

Abstract

Systems, methods, articles of manufacture, and computer-readable media for secure authentication based on identity data stored in a contactless card associated with an account. An application can receive an indication specifying to perform an operation. The application can receive encrypted data from the card, the encrypted data being based on a cryptographic algorithm, a customer identifier, and a private key. The application can receive an indication that an authentication server verified the encrypted data based on the private key for the card. The application can determine a type of data required to authorize the operation. The application can receive data from the card including passport data or driver's license data. The application can determine that the data satisfies a rule for authorizing the operation, and authorize performance of the operation based on the authentication server verifying the encrypted data and the data satisfying the at least one rule.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related applications

[0002] This application claims priority to U.S. Patent Application No. 16 / 726,385, filed December 24, 2019, entitled "Secure Authentication Based on Identity Data Stored in an Acontactless Card". The entire contents of the foregoing application are incorporated herein by reference. Technical Field

[0003] The embodiments described herein generally relate to computing platforms, and more specifically, to secure authentication using contactless cards that store identity data. Background Technology

[0004] Authentication is a critical task for modern computing systems. Conventional methods may require users to provide additional information, such as one-time passwords (OTPs), when attempting to access a computing system or execute electronic transactions. However, security vulnerabilities may exist in these solutions. For example, OTPs can be intercepted and used to gain unauthorized access. Furthermore, different systems may require different types of additional information for authentication, making conventional solutions impractical for many users. Summary of the Invention

[0005] The embodiments disclosed herein provide systems, methods, articles of manufacture, and computer-readable media for secure authentication based on identity data stored in contactless cards. In one example, an application may receive an instruction specifying the execution of an operation associated with an account. The application may receive encrypted data from the contactless card associated with the account, the encrypted data being based on a cryptographic algorithm, a customer identifier, and a private key for the contactless card. The application may receive an instruction from an authentication server specifying that an authentication server verify the encrypted data based on the private key for the contactless card. The application may determine the type of authentication data required to authorize the operation. The application may receive a first data element from the contactless card based on the determined authentication data type, the first data element including passport data or driver's license data. The application may determine that the first data element satisfies at least one rule for authorizing the operation. The application may authorize the execution of the operation based on the received instruction from the designated authentication server to verify the encrypted data and the determination that the first data element satisfies the at least one rule for authorizing the operation. Attached Figure Description

[0006] Figure 1A-1B Examples of systems for performing secure authentication based on identity data stored in contactless cards are illustrated.

[0007] Figure 2A-2C An example is illustrated where a contactless card is tapped onto a computing device to provide secure authentication based on identity data stored in the contactless card.

[0008] Figures 3A-3C An example is illustrated where a contactless card is tapped onto a computing device to provide secure authentication based on identity data stored in the contactless card.

[0009] Figures 4A-4B Example of a contactless card.

[0010] Figure 5 An example illustrating an implementation of the first logical flow is provided.

[0011] Figure 6 An example illustrating a second logic flow is provided.

[0012] Figure 7 An example illustrating a third logic flow is provided.

[0013] Figure 8 An example is provided to illustrate an implementation of the computing system. Detailed Implementation

[0014] The embodiments disclosed herein provide techniques for secure authentication using identity data stored in contactless cards. Generally, contactless cards can store various types of information about a user, such as driver's license information, passport information, Social Security number, and / or any other biographical information. The user can then attempt to perform actions such as making a purchase, transferring funds via an application running on a mobile device, requesting a credit extension via said application, etc. The application can determine the type of authentication data required for the authorized operation. For example, rules can specify that transferring funds via said application requires authentication based on passport data stored in the contactless card. Therefore, the application can determine that passport data as the type of authentication data.

[0015] The user can then tap the contactless card onto the mobile device to initiate a secure authentication process. Once tapped, the contactless card generates encrypted data and sends it to the application. The encrypted data can be generated based on a cryptographic algorithm, a customer identifier, and an encryption key used for the contactless card. The application can then send the encrypted data to an authentication server for authentication. The server can then use a local copy of the encryption key used for the contactless card to decrypt the encrypted data to obtain the customer identifier, thereby authenticating the encrypted data. The server can then send an instruction for authentication of the encrypted data to the application.

[0016] The application can then process passport data. In some embodiments, the contactless card sends passport data along with an encrypted customer identifier to the application. In other embodiments, the contactless card sends passport data after another tap on the mobile device. To process the passport data, the application can perform any number of operations. For example, passport data stored on the contactless card may include an image of the user's passport. In such an example, the application may instruct the user to use the mobile device to capture an image depicting their face. Once captured, the application can compare the images to determine the similarity between them. If the similarity exceeds a similarity threshold level specified in a rule, the application can authenticate the user and / or verify the user's identity. The application can then authorize the execution of the operation based on a received instruction from a designated authentication server to verify the encrypted data and the determination that the similarity of the images exceeds the similarity threshold level. For example, a user may be allowed access to the application's interface to transfer funds from one account to another.

[0017] Advantageously, the embodiments disclosed herein improve the security of all devices and associated data. For example, the security of applications and / or data is improved by requiring verification of encrypted data generated by contactless cards when accessing applications and / or data. As another example, the security of such operations and associated assets is improved by requiring verification of encrypted data before performing an operation (e.g., making a purchase, extending credit, etc.).

[0018] The notation and nomenclature used herein generally refer to the process of a program executing on a computer or computer network, as detailed in the description herein. These process descriptions and representations are used by those skilled in the art to most effectively communicate the substance of their work to others skilled in the art. A process herein is generally conceived as a self-consistent sequence of operations that leads to a desired result. These operations are those that require physical manipulation of physical quantities. Typically, though not always, these quantities take the form of electrical, magnetic, or optical signals that can be stored, transmitted, combined, compared, and otherwise manipulated. It is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc., primarily for common use. However, it should be noted that all these terms and similar terms will be associated with the appropriate physical quantities and are merely convenient labels applied to those quantities.

[0019] Furthermore, these manipulations are frequently referred to in terms commonly associated with mental operations performed by human operators, such as addition or comparison. However, such capabilities of human operators are not necessary, or in most cases undesirable, in any of the operations described herein that form part of one or more embodiments. Instead, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by computer programs stored therein, written in accordance with the teachings herein, and / or include devices specifically constructed for the desired purpose or for the digital computer. The various embodiments also relate to devices or systems for performing these operations. These devices may be specifically constructed for the desired purpose. The necessary structures for the various such machines will be apparent from the given description.

[0020] Referring now to the accompanying drawings, similar reference numerals are consistently used to denote similar elements. In the following description, numerous specific details are set forth for illustrative purposes in order to provide a thorough understanding thereof. However, it may be apparent, however, that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate their description. The invention encompasses all modifications, equivalents, and substitutions within the scope of the claims.

[0021] Figure 1A A schematic diagram depicts an exemplary system 100 consistent with the disclosed embodiments. As shown, system 100 includes one or more contactless cards 101, one or more mobile computing devices 110, and an authentication server 120. The contactless card 101 represents any type of payment card, such as a credit card, debit card, ATM card, gift card, etc. The contactless card 101 may include one or more communication interfaces 133, such as a radio frequency identification (RFID) chip configured to communicate with computing device 110 via NFC, EMV standards, or other short-range protocols in wireless communication. Although NFC is used as an example communication protocol, this disclosure is equally applicable to other types of wireless communication, such as EMV standards, Bluetooth, and / or Wi-Fi. The mobile device 110 represents any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop, portable gaming device, etc. The authentication server 120 represents any type of computing device, such as a server, workstation, computing cluster, cloud computing platform, virtualized computing system, etc.

[0022] As shown, the contactless card's memory 102 includes an applet 103, a counter 104, a master key 105, a diversity key 106, a unique customer identifier (ID) 107, passport data 108, driver's license data 109, and other user data 131. The applet 103 is executable code configured to perform the operations described herein. The counter 104, master key 105, diversity key 106, and customer ID 107 are used to provide security in the system 100, which is described in more detail below. Passport data 108 represents the electronic passport of the user associated with the contactless card 101. Passport data 108 can include any amount and type of data. For example, passport data 108 can include text data describing different attributes of the passport and / or user (e.g., name, date of birth, passport number, passport issuance date, passport expiry date, issuing country, etc.), and image data (e.g., one or more images of the passport itself, images of the user included in the passport, etc.). Customer ID 107, passport data 108, driver's license data 109, and other user data 131 can be collectively referred to as "identity data" in this document.

[0023] Driver's license data 109 represents one or more driver's licenses held by a user associated with the contactless card. Similar to passport data 108, driver's license data 109 can include any amount and type of data. For example, driver's license data 109 can include barcodes (or other computer-readable markers) that encode different attributes of the driver's license and / or the user (e.g., name, date of birth, license number, license issuance date, expiry date, issuing state, etc.), text data (and / or barcodes) representing these attributes, and / or image data (e.g., one or more images of the driver's license, an image of the user included in the driver's license, etc.). Other user data 131 represents other data describing the user. For example, other user data 131 can include Social Security numbers, images or data representing the user's biometric identifier, other identification cards, loyalty program information, etc. In some embodiments, passport data 108, driver's license data 109, and other user data 131 are encrypted.

[0024] As shown, the memory 111 of the mobile device 110 includes an instance of an operating system (OS) 112. The instance operating system 112 includes... and Operating System. As shown, OS 112 includes Account Application 113. Account Application 113 allows users to perform various account-related operations, such as viewing account balances, purchasing items, and processing payments. Account Application 113 can further control access permissions for different functions provided by Account Application 113 and / or other applications 114. Generally, users can authenticate using authentication certificates to access certain features of Account Application 113. For example, authentication certificates may include usernames (or logins) and passwords, biometric certificates (e.g., fingerprints, facial ID, etc.), etc.

[0025] According to various embodiments, a user may request and / or attempt to perform an operation. The operation may include any type of operation, such as making a purchase using contactless card 101, accessing certain features of account application 113, performing various account-related operations using account application 113, and / or accessing other applications 114 (or any features thereof). Other applications 114 represent any type of computing application, such as a web browser, messaging application, word processing application, social media application, etc. For example, a user may expect to use account application 113 to transfer funds from their account to another account. The use of a specific operation as a reference example herein is not a limitation of this disclosure, as this disclosure is equally applicable to any other type of operation.

[0026] For the authorization request to be executed (e.g., the previous example of transferring funds), system 100 must authenticate and / or verify the user's identity. To authenticate the user's identity, the embodiments disclosed herein may utilize contactless card 101. More specifically, once the user requests to perform the operation (or otherwise access restricted resources), account application 113 may output a notification instructing the user to tap contactless card 101 against device 110. Generally, once contactless card 101 is brought within communication range of communication interface 118 of device 110, contactless card 101's app 103 may generate encrypted data, such as an encrypted customer ID 132, as part of the authentication process required for the authorization request. To enable the transfer of NFC data between contactless card 101 and mobile device 110, account application 113 may communicate with contactless card 101 when contactless card 101 is sufficiently close to communication interface 118 of mobile device 110. Communication interface 118 can be configured to read from and / or communicate with communication interface 133 of contactless card 101 (e.g., via NFC, Bluetooth, RFID, etc.). Therefore, example communication interface 118 includes an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.

[0027] As described, system 100 is configured to perform key diversification to protect data, which may be referred to herein as key diversification technology. Generally, server 120 (or another computing device) and contactless card 101 can be assigned the same master key 105 (also referred to as the master symmetric key). More specifically, each contactless card 101 is programmed with a different master key 105 corresponding to it in server 120. For example, when contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of contactless card 101. Similarly, the unique master key 105 may be stored in the account data 124 of server 120 in the records of customers associated with contactless card 101 (and / or stored in a different secure location, such as a hardware security module (HSM) 125). The master key can be kept confidential from all parties except contactless card 101 and server 120, thereby enhancing the security of system 100. In some embodiments, the app 103 of the contactless card 101 can use the master key 105 and data as input to a cryptographic algorithm to encrypt and / or decrypt data (e.g., customer ID 107, passport data 108, driver's license data 109, and / or other user data 131). For example, encrypting customer ID 107 with the master key 105 yields an encrypted customer ID 132. Similarly, the authentication server 120 can use the corresponding master key 105 to encrypt and / or decrypt data associated with the contactless card 101.

[0028] In other embodiments, the master key 105 of the contactless card 101 and server 120 can be combined with a counter 104 to enhance security using key diversification. The counter 104 includes a value synchronized between the contactless card 101 and server 120. The counter value 104 can include a number that changes each time data is exchanged between the contactless card 101 and server 120 (and / or the contactless card 101 and mobile device 110). When ready to send data (e.g., to server 120 and / or mobile device 110), the contactless card 101 can increment the counter value 104. The contactless card 101 can then provide the master key 105 and the counter value 104 as input to a cryptographic algorithm that generates a diversified key 106 as output. The cryptographic algorithm can include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cryptographic message authentication code (CMAC) algorithms, etc. Non-limiting examples of cryptographic algorithms may include symmetric encryption algorithms such as 3DES or AES128; symmetric HMAC algorithms such as HMAC-SHA-256; and symmetric CMAC algorithms such as AES-CMAS. Examples of key diversification techniques are described in more detail in U.S. Patent Application 16 / 205,119, filed November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety.

[0029] Continuing with the example of key diversification, the contactless card 101 can then use a diversified key 106 and data as input to a cryptographic algorithm to encrypt data (e.g., customer ID 107 and / or any other data, such as passport data 108, driver's license data 109, and / or other user data 131). For example, encrypting customer ID 107 with a diversified key 106 yields an encrypted customer ID 132.

[0030] Regardless of the encryption technology used, the contactless card 101 can then send encrypted data (e.g., encrypted customer ID 132) to the account application 113 of the mobile device 110 (e.g., via NFC connection, Bluetooth connection, etc.). The account application 113 of the mobile device 110 can then send the encrypted customer ID 132 to the server 120 via network 130. In at least one embodiment, the contactless card 101 sends a counter value 104 along with the encrypted data. In such an embodiment, the contactless card 101 can send either an encrypted counter value 104 or an unencrypted counter value 104.

[0031] Once received, authentication application 123 can authenticate the encrypted customer ID 132. For example, authentication application 123 can attempt to decrypt the encrypted customer ID 132 using a copy of the master key 105 stored in the memory 122 of authentication server 120. In another example, authentication application 123 can provide the master key 105 and a counter value 104 as inputs to a cryptographic algorithm that generates a diversified key 106 as output. The resulting diversified key 106 can correspond to a diversified key 106 of contactless card 101, which can be used to decrypt the encrypted customer ID 132.

[0032] Regardless of the decryption technique used, authentication application 123 can successfully decrypt the encrypted customer ID 132, thereby verifying the encrypted customer ID 132 (e.g., by comparing the resulting customer ID 107 with the customer ID stored in account data 124, and / or based on an indication of successful decryption using keys 105 and / or 106). Although keys 105 and 106 are depicted as being stored in memory 122, keys 105 and 106 can be stored elsewhere, such as in a secure element and / or HSM 125. In such an embodiment, the secure element and / or HSM 125 can use keys 105 and / or 106 and cryptographic functions to decrypt the encrypted customer ID 132. Similarly, the secure element and / or HSM 125 can generate a variety of keys 106 based on the master key 105 and counter value 104, as described above.

[0033] However, if authentication application 123 cannot decrypt the encrypted customer ID 132 to obtain the expected result (e.g., customer ID 107 of the account associated with contactless card 101), then authentication application 123 does not verify the encrypted customer ID 132. In such an example, authentication application 123 sends a failed verification indication to account application 113. Accordingly, account application 113 can refuse to execute the requested operation to maintain account security.

[0034] Figure 1BThis illustration shows an embodiment where authentication application 123 has decrypted the encrypted customer ID 132, thereby verifying (or authenticating) the encrypted data. As shown, authentication application 123 sends verification 134 to mobile device 110, where verification 134 indicates that authentication application 123 has successfully decrypted the encrypted customer ID 132. In response to receiving verification 134, account application 113 can refer to rule 115 to determine what (if any) additional authentication steps are required. Rule 115 may generally specify multiple different authentication rules and / or thresholds for different requested operations. The rules may be based on the type of requested operation. For example, for transferring funds, rule 115 may need to perform additional authentication based on additional data elements such as passport data 108 and / or driver's license data 109.

[0035] In the example where additional authentication is based on passport data 108, account application 113 may output an instruction specifying a user to tap contactless card 101 on mobile device 110. Account application 113 may then instruct contactless card 101 to send passport data 108. In response, contactless card 101 may send passport data 108 to account application 113. In some embodiments, passport data 108 may be encrypted. In such an embodiment, account application 113 may send the encrypted passport data 108 to server 120 for decryption (e.g., based on keys 105 and / or 106), and server 120 may then send the decrypted passport data 108 to account application 113. In another embodiment, the user may provide input to account application 113 for decrypting the encrypted passport data 108.

[0036] Furthermore, account application 113 can instruct the user to use camera 119 to capture an image depicting themselves. Account application 113 can then compare the captured image with passport images in passport data 108 to determine the similarity of the person depicted in each image. If account application 113 determines that the similarity of the person depicted in the image exceeds the threshold similarity specified in rule 115, account application 113 can authorize the requested operation. The user can then continue using account application 113 to complete the funds transfer.

[0037] As described, in another example, rule 115 may require authentication based on driver's license data 109. Account application 113 can then output an instruction specifying that a user taps contactless card 101 on mobile device 110. Account application 113 can then instruct contactless card 101 to send driver's license data 109. In response, contactless card 101 can send driver's license data 109 to account application 113. In some embodiments, driver's license data 109 can be encrypted. Otherwise, account application 113 can restrict the execution of the operation (e.g., by restricting access to the graphical user interface (GUI) of account application 113 for transferring funds). In such an embodiment, account application 113 can send the encrypted driver's license data 109 to server 120 for decryption, and server 120 then sends the decrypted driver's license data 109 to account application 113.

[0038] Similar to passport-based authentication, account application 113 can then instruct the user to use camera 119 to capture an image depicting themselves. Account application 113 can then compare the captured image with driver's license images in driver's license data 109 to determine the similarity of the person depicted in each image. If account application 113 determines that the similarity of the person depicted in the image exceeds the threshold similarity specified in rule 115, account application 113 can authorize the requested operation. Otherwise, account application 113 can restrict the execution of the operation (e.g., by restricting access to the GUI of account application 113 for transferring funds). The user can then continue using account application 113 to complete the fund transfer.

[0039] While image-based authentication is used as an example, other data elements can be used for the authorization request. For instance, account application 113 can determine whether the name on the passport and / or driver's license matches the name on the account associated with contactless card 101. As another example, account application 113 can determine whether the data encoded in driver's license data 109 is readable. As yet another example, account application 113 can determine whether the date of birth in the passport and / or driver's license matches a known date of birth (e.g., the date of birth specified in account data 124 for the account associated with contactless card 101). In yet another example, the Social Security number stored in other user data 131 can be compared with the known Social Security number of the user associated with the account. If a matching name and / or Social Security number is found, account application 113 can authorize the attempted operation. Otherwise, account application 113 can reject the attempted operation.

[0040] In at least one embodiment, a small application 103 of the contactless card 101 can use keys 105 and / or 106 to generate digital signatures (not depicted) for passport data 108 and / or driver's license data 109. The corresponding digital signature can then be used to sign the passport data 108 and / or driver's license data 109. The contactless card 101 can then send the digital signature along with the passport data 108 and / or driver's license data 109 to an account application 113, which in turn sends the digital signature to an authentication server 120. The authentication application 123 can also decrypt the digital signature using a public key associated with the contactless card 101 and stored by the server 120. If the digital signature is verified, the authentication application 123 can send a successful verification indication to the account application 113, which can allow the operation to proceed based on the verification of the digital signature. If the digital signature is not verified, the account application 113 can restrict the operation.

[0041] Despite Figure 1A-1B The process is described as occurring in a single tap operation, but in response to a single tap on the contactless card 101 of the mobile device 101, passport data 108 and / or driver's license data 109 may be sent together with an encrypted customer ID 132.

[0042] Furthermore, in some embodiments, users can obtain new and / or updated identification information, such as passports, driver's licenses, etc. In such embodiments, account application 113 can receive new and / or updated versions of passport data 108, driver's license data 109, and / or other user data 131, for example, from authentication server 120. In such embodiments, account application 113 can send data received from server 120 to contactless card 101, and app 103 can store the received data in memory 102.

[0043] Figure 2A This is a schematic diagram 200 depicting an example embodiment of providing secure authentication by tapping a contactless card 101 based on identity data stored in the contactless card 101. As shown, an account application 113 can receive a request to perform an operation. Continuing with the previous example, the request could be to transfer funds from one account to another. In response, the account application 113 can output an instruction to tap the contactless card 101 onto the device 110. Once the user taps the contactless card 101 onto the mobile device 110, the applet 103 of the contactless card 101 generates an encrypted customer ID 132. The applet 103 can then send the encrypted customer ID 132 to the mobile device 110, for example, via NFC. Once received, the account application 113 can send the encrypted customer ID 132 to the authentication application 123.

[0044] The authentication application 123 may then attempt to decrypt the encrypted customer ID 132 using the master key 105 and / or a diversified key 106 associated with the contactless card 101. If the authentication application 123 cannot decrypt the encrypted customer ID 132 to obtain the expected result (e.g., account customer ID 107, etc.), the authentication application 123 does not verify the encrypted customer ID 132 and notifies the account application 113 of the failed verification. The account application 113 may then refuse to initiate a funds transfer request. If the authentication application 123 successfully decrypts the encrypted customer ID 132 to obtain the expected result (e.g., account customer ID 107, etc.), the authentication application 123 verifies the encrypted customer ID 132 and sends an indication of verification of the encrypted customer ID 132 to the account application 113.

[0045] In response to receiving verification from authentication application 123, account application 113 can refer to rule 115 to determine which type of data is required for the authorized funds transfer request. For example, rule 115 may specify that the funds transfer requires verification of the encrypted customer ID 132 and verification based on passport data 108. In at least one embodiment, the data type specified by rule 115 is based on the type of operation requested (e.g., funds transfer). Generally, rule 115 may specify different security levels for different types of transactions (e.g., verification of passport data 108 is required for higher-risk operations, while verification of passport data 108 is not required for lower-risk operations).

[0046] Account application 113 can output another instruction to tap contactless card 101 on device 110. Account application 113 can instruct contactless card 101 to send passport data 108. App 103 can then send passport data 108 to mobile device 110, for example, via NFC.

[0047] like Figure 2B As shown in schematic 210, account application 113 can then output an instruction to the user to capture an image depicting their face. The user can then use camera 119 to capture an image depicting their face. Account application 130 can then compare the captured image with passport images in passport data 108 to determine the similarity of the person depicted in each image. If account application 113 determines that the similarity of the person depicted in the image exceeds the threshold similarity specified in rule 115, account application 113 can authorize the requested funds transfer operation. Otherwise, account application 113 can reject the requested funds transfer operation and restrict access to the GUI for performing funds transfers by account application 113. Figure 2BIn the example depicted, if the similarity exceeds a threshold, account application 113 allows the requested transfer to proceed. The user can then continue using the corresponding GUI of account application 113 to complete the fund transfer.

[0048] Figure 3A This is a schematic diagram 300 illustrating an example embodiment of providing secure authentication by tapping a contactless card 101 based on identity data stored in the contactless card 101. As described, the contactless card 101 can be used as a form of payment for purchases, and the system 100 can use the identity data stored in the contactless card to provide secure authentication when processing payments. Although face-to-face transactions are depicted as a reference example, this disclosure is equally applicable to online transactions.

[0049] As shown, as part of the requested purchase, the merchant device 301 displays an indication on display 302 that a specified age-restricted item has been identified, and the customer's age must be provided to complete the requested purchase. Merchant device 301 refers to any type of device capable of processing payments, such as a card reader device, smartphone, tablet computer, desktop computer, point-of-sale (POS) terminal, server, workstation, laptop computer, etc. Merchant device 301 includes a communication interface 303 configured to communicate via NFC, Bluetooth, RFID, and / or Wi-Fi. Therefore, merchant device 301 can communicate with contactless card 101 and / or mobile device 110. In some embodiments, the communication interface 118 of mobile device 110 operates in NFC card emulation mode to mimic contactless card 101 and makes payments for transactions via merchant device 301.

[0050] Therefore, account application 113 can receive an instruction from merchant device 301 specifying that verification of the customer's age is required. Account application 113 can then output an instruction to tap contactless card 101 onto device 110. Once the customer taps contactless card 101 onto mobile device 110, applet 103 of contactless card 101 generates an encrypted customer ID 132. Applet 103 can then send the encrypted customer ID 132 to mobile device 110, for example, via NFC. Figures 3A-3C In the embodiment depicted, the contactless card 101 also encrypts the driver's license data 109 and sends it along with the encrypted customer ID 132 to the mobile device 110. Once received, the account application 113 can send the encrypted customer ID 132 and driver's license data to the authentication application 123. The authentication application 123 can then decrypt the encrypted customer ID 132 to verify it. The authentication application 123 can further decrypt the driver's license data 109.

[0051] Figure 3B This illustration describes an embodiment where account application 113 receives an indication from authentication application 123 that an encrypted customer ID 132 has been verified. Account application 113 may further receive decrypted driver's license data 109 from authentication application 123. Account application 113 (and / or authentication application 123) may read driver's license data 109 to determine the customer's age (e.g., based on the difference between the current date and the date of birth specified in driver's license data 109). If the determined age exceeds the minimum age for purchasing age-restricted items, account application 113 sends a verification indication 310 to merchant device 301. In some embodiments, account application 113 sends the relevant driver's license data 109 (e.g., date of birth) to merchant device 301. This allows merchant device 301 to independently verify that the customer is of the required age to purchase age-restricted items.

[0052] Figure 3C This illustration describes an embodiment where account application 113, based on authentication application 123's verification of the encrypted customer ID 132 and the customer's age, instructs the user to tap the contactless card 101 on mobile device 110 to complete payment for a purchase. Communication interface 118 of mobile device 110, operating in NFC card emulation mode, allows the contactless card 101's app 103 to send payment information (e.g., card number, expiration date, and / or card verification value (CVV)) to account application 113. In some embodiments, the payment information includes the encrypted customer ID 132, which is sent by account application 113 to server 120 for verification. Once verified, account application 113 sends the received payment information as payment data 311 to merchant device 301. Merchant device 301 can then use the received payment data 311 to process the transaction.

[0053] Figure 4AThe example illustrates a contactless card 101, which may include a payment card, such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 405 displayed on the front or back of the card. In some examples, the contactless card 101 is not a payment card and may include, but is not limited to, an identification card. In some examples, the payment card may include a dual-interface contactless payment card. The contactless card 101 may include a substrate 410, which may include a single layer or one or more laminates composed of plastics, metals, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, platinum, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card may otherwise conform to the ISO / IEC 14443 standard. However, it is understood that the contactless card 101 according to this disclosure may have different characteristics, and this disclosure does not require the implementation of a contactless card in a payment card.

[0054] The contactless card 101 may also include identification information 415 and a contact pad 420, with the identification information 415 displayed on the front and / or back of the card. The contact pad 420 may be configured to establish contact with another communication device, such as a mobile device 40, user device, smartphone, laptop computer, desktop computer, or tablet computer. The contactless card 101 may also include a processing circuitry, an antenna, and... Figure 4A Other components not shown. These components can be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 may also include a magnetic stripe or magnetic tape that can be located on the back of the card. Figure 4A (Not shown in the image).

[0055] like Figure 4B As shown, the contact pad 420 of the contactless card 101 may include a processing circuitry 425 for storing and processing information. The processing circuitry 425 includes a microprocessor 420 and a memory 102. It is understood that the processing circuitry 425 may include additional components necessary to perform the functions described herein, including a processor, memory, error and parity / CRC checkers, a data encoder, anti-collision algorithms, a controller, a command decoder, security primitives, and tamper-proof hardware.

[0056] Memory 102 can be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM. Contactless card 101 may include one or more of these memories. Read-only memory can be factory-programmable for read-only or one-time programmable. One-time programmable provides the opportunity to write once and then be read multiple times. Write-once / read-many memory can be programmed at a point in time after the memory chip has left the factory. Once programmed, the memory cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can also be read multiple times after leaving the factory.

[0057] The memory 102 can be configured to store one or more applets 103, a counter 104, a master key 105, a multi-key 106, one or more customer (or user) IDs 107, passport data 108, driver's license data 109, and other user data 131. The one or more applets 103 may include one or more software applications configured to execute on one or more contactless cards, such as... Card applet. However, applet 103 is understood to be not limited to Java card applets, but can be any software application operable on contactless cards or other devices with limited memory. Customer ID 107 may include a unique alphanumeric identifier assigned to the user of contactless card 101, which can distinguish the user of contactless card from other contactless card users. In some examples, customer ID 107 can identify both the customer and the account assigned to that customer, and can further identify the contactless card associated with the customer's account. In some embodiments, applet 103 can use customer ID 107 with keys 105 and / or 106 as input to a cryptographic algorithm to generate an encrypted customer ID 132.

[0058] The processor and memory elements of the foregoing exemplary embodiments are described with reference to the contact pad, but this disclosure is not limited thereto. It is understood that these elements may be implemented outside of the pad 420, or completely separate from it, or as further elements disposed within the contact pad 420 in addition to the processor 430 and memory 102.

[0059] In some examples, the contactless card 101 may include one or more antennas 455. The one or more antennas 455 may be placed within the contactless card 101, around the processing circuitry 425 of the contact pad 420. For example, the one or more antennas 455 may be integrated with the processing circuitry 425, or they may be used in conjunction with an external start-up coil. As another example, the one or more antennas 455 may be external to the contact pad 420 and the processing circuitry 425.

[0060] In an embodiment, the coil of the contactless card 101 can act as the secondary of an air-core transformer. Terminals can communicate with the contactless card 101 by cutting off power or amplitude modulation. The contactless card 101 can infer data transmitted from the terminals using a gap when the contactless card is connected to power, the power connection being functionally maintained by one or more capacitors. The contactless card 101 can transmit communication back by switching the load or load modulation on the coil of the contactless card. Load modulation can be detected in the coil of the terminals by interference. More generally, using antenna 455, processing circuitry 425, and / or memory 102, the contactless card 101 provides a communication interface for communication via NFC, Bluetooth, and / or Wi-Fi.

[0061] As described above, the contactless card 101 can be built on a software platform operable on a smart card or other device with limited memory (such as a JavaCard), and one or more applications or mini-applications can be securely executed. Mini-applications can be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based usage scenarios. The mini-application can be configured to respond to one or more requests (such as a near-field data exchange request) from a reader (such as a mobile NFC reader (e.g., communication interface 118 of device 110)) and generate an NDEF message that includes a password-secure OTP encoded as an NDEF text tag.

[0062] Operation of the disclosed embodiments can be further described with reference to the following drawings. Some of the drawings may include logical flows. Although such drawings presented herein may include specific logical flows, it will be appreciated that such logical flows merely provide examples of how general functionality as described herein can be implemented. Furthermore, the given logical flows do not necessarily have to be executed in the order presented unless otherwise indicated. Additionally, the given logical flows can be implemented using hardware elements, software elements executed by a processor, or any combination thereof. The embodiments are not limited in this context.

[0063] Figure 5Examples of logical flow 500 are illustrated herein. Logical flow 500 may represent some or all of the operations performed in one or more embodiments described herein. For example, logical flow 500 may include some or all of the operations of using contactless card 101 to provide secure authentication based on identity data stored in contactless card 101. Embodiments are not limited in this context.

[0064] As shown, the logic flow 500 begins at block 505, where account application 113 receives a request to perform an operation. As described, the requested operation may be received based on input from a user of account application 113, an external source (e.g., merchant device 301), one of other applications 114, or any other source. The request may be related to, for example, but not limited to, the use of account application 113, the use of other applications 114, operations related to the account associated with contactless card 101, and / or transactions. More generally, the request may be received after the user provides authentication credentials required to access the account in account application 113. At block 510, the user taps contactless card 101 on mobile device 110, causing mini-application 103 of contactless card 101 to generate an encrypted customer ID 132 and send the encrypted customer ID 132 to mobile device 110.

[0065] In box 515, account application 113 can receive an encrypted customer ID 132 from contactless card 101. Account application 113 can then send the encrypted customer ID 132 received from contactless card 101 to authentication server 120. Server 120 can attempt to decrypt the encrypted customer ID 132 as described herein. In box 520, account application 113 receives from server 120 an indication that the encrypted customer ID 132 has been verified by decryption of the encrypted customer ID 132.

[0066] In box 525, account application 113 determines the type of request. In box 530, account application 113 determines the type of verification data required for the type of authorization operation specified in rule 115. For example, passport data 108 can be specified as the verification data required by rule 115. In box 530, the user taps contactless card 101 on mobile device 110. This instructs applet 103 of contactless card 101 to send passport data 108 to mobile device 110. In box 535, account application 113 can receive additional data (e.g., passport data 108) from contactless card 101.

[0067] At box 540, account application 113 may receive additional data from contactless card 101. At box 545, account application 113 may process the data received at box 540. For example, account application 113 may perform any age verification, account verification, and / or authentication specified by rule 115. As another example, account application 113 and / or authentication server 120 may verify the digital signature of the received data. At box 550, account application 113 determines that the processed data satisfies rule 115. At box 555, account application 113 allows the execution of the requested operation based on server 120's verification of the encrypted customer ID 132 and the determination that the processed data received at box 535 satisfies rule 115. At box 560, the requested operation may be performed, for example, by the user and / or by account application 113.

[0068] Figure 6 Examples of logical flow 600 are illustrated herein. Logical flow 600 may represent some or all of the operations performed in one or more embodiments described herein. For example, logical flow 600 may include some or all of the operations of providing authentication based on passport data 108 stored in contactless card 101. Embodiments are not limited in this context.

[0069] As shown, the logic flow 600 begins at block 610, where the account application 113 determines, based on the type of requested operation, that rule 115 requires passport-based verification. At block 620, the account application 113 outputs an instruction to the user to capture an image that at least describes the user's face. At block 630, the account application 113 receives an image captured by the camera 119 of the mobile device 110. At block 640, the account application 113 compares the captured image received at block 630 with one or more images associated with the passport in the passport data 108 and determines that the similarity of the person depicted in each image exceeds the similarity threshold level specified in rule 115. At block 650, based on the determination at block 640, the account application 113 determines that the user depicted in the captured image matches the person depicted in the passport image in the passport data 108. In box 660, account application 113 allows the execution of the requested operation based at least in part on the matching and / or determination of similarity between the user depicted in the captured image and the person depicted in the passport image of passport data 108, which exceeds the threshold specified in rule 115.

[0070] Although logic flow 600 is related to the image in passport data 108, logic flow 600 is equally applicable to image-based verification using the user's image in driver's license data 109. Therefore, account application 113 can determine whether the user in the captured image matches the user depicted in driver's license data 109. Embodiments are not limited to these contexts.

[0071] Figure 7 Examples of logical flow 700 are illustrated herein. Logical flow 700 may represent some or all of the operations performed in one or more embodiments described herein. For example, logical flow 700 may include some or all of the operations of providing authentication based on driver's license data 109 stored in contactless card 101. Embodiments are not limited in this context.

[0072] As shown, the logic flow 700 begins at block 710, where account application 113 receives an instruction from merchant device 301 that age verification is required to purchase age-restricted items. At block 720, account application 113 receives driver's license data 109 from contactless card 101 based on tapping card 110 onto mobile device 110. At block 730, account application 113 processes driver's license data 109 to determine the age of the associated person, for example, based on a date of birth included in the driver's license data.

[0073] At block 740, account application 113 determines that the person identified at block 730 exceeds a minimum age threshold. At block 750, account application 113 sends an indication that the person's age exceeds the threshold. Additionally and / or alternatively, account application 113 may send age and / or driver's license data 109 to merchant device 301 for processing and verification. At block 760, account application 113 receives payment data from contactless card 101 in response to tapping it on mobile device 110. At block 770, account application 113 sends the payment data to merchant device 301. At block 780, merchant device 301 may use the received payment data to process the transaction. In some embodiments, merchant device 301 sends a payment confirmation to account application 113.

[0074] Figure 8 Examples of exemplary computing architecture 800 are illustrated, including a computing system 802 that can be adapted to implement the various embodiments described above. In various embodiments, computing architecture 800 may include or be implemented as part of an electronic device. In some embodiments, computing architecture 800 may represent, for example, a system implementing one or more components of 100. In some embodiments, computing system 802 may represent, for example, a contactless card 101, a mobile device 110, and an authentication server 120 of system 100. Embodiments are not limited in this context. More generally, computing architecture 800 is configured to implement all the logic, applications, systems, methods, devices, and functionalities described herein with reference to Figures 1-7.

[0075] As used herein, the terms “system,” “component,” and “module” are intended to refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing architecture 800. For example, a component can be, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives (of optical and / or magnetic storage media), an object, executable instructions, an execution thread, a program, and / or a computer. For example, both an application running on a server and the server itself can be components. One or more components may reside within a process and / or execution thread, and components may be locally located on a single computer and / or distributed across two or more computers. Furthermore, components can be coupled to each other via various types of communication media to coordinate operation. This coordination can involve one-way or two-way exchange of information. For example, components can transmit information in the form of signals transmitted via a communication medium. This information can be implemented as signals dispatched to various signal lines. In such dispatch, each message is a signal. However, further embodiments may alternatively employ data messages. Such data messages can be sent via various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0076] The computing system 802 includes various common computing elements, such as one or more processors, multi-core processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to the implementation of the computing system 802.

[0077] like Figure 8 As shown, the computing system 802 includes a processor 804, a system memory 806, and a system bus 808. The processor 804 can be any of a variety of commercially available processors, including, but not limited to, [various types of processors]. and processor; Application, embedded, and security processors; and and Processors; IBM and Cell processor; Core(2) and Processors; and similar processors. Dual-microprocessors, multi-core processors, and other multi-processor architectures can also be used as processors 804.

[0078] System bus 808 provides interfaces for system components, including, but not limited to, system memory 806 to processor 804. System bus 808 can be any of several types of bus structures that can be further interconnected to memory buses (with or without memory controllers), peripheral buses, and local buses using any of a variety of commercially available bus architectures. Interface adapters can be connected to system bus 808 via a time-slot architecture. Example time-slot architectures may include, but are not limited to, Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Microchannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extended) (PCI(X)), PCI Express, PCMCIA, etc.

[0079] System memory 806 may include various types of computer-readable storage media in the form of one or more higher-speed memory cells, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), dual data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory (such as ferroelectric polymer memory), austenite memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic cards or optical cards, device arrays (such as redundant independent disk array (RAID) drives), solid-state memory devices (e.g., USB storage, solid-state drives (SSDs), and any other type of storage media suitable for storing information. Figure 8 In the illustrated embodiment, system memory 806 may include non-volatile memory 810 and / or volatile memory 812. The Basic Input / Output System (BIOS) may be stored in non-volatile memory 810.

[0080] The computing system 802 may include various types of computer-readable storage media in the form of one or more lower-speed memory units, including an internal (or external) hard disk drive (HDD) 814, a magnetic floppy disk drive (FDD) 816 that reads from or writes to a removable disk 818, and an optical disc drive 820 that reads from or writes to a removable optical disc 822 (e.g., a CD-ROM or DVD). The HDD 814, FDD 816, and optical disc drive 820 may be connected to the system bus 808 via an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. The HDD interface 824 for external drive implementation may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 802 is generally configured to implement all the logic, systems, methods, devices, and functionalities described herein with reference to Figures 1-7.

[0081] The drive and associated computer-readable medium provide volatile and / or non-volatile storage for data, data structures, computer-readable instructions, computer-executable instructions, etc. For example, several program modules may be stored in the drive and memory units 810, 812, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836. In one embodiment, the one or more application programs 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as applets 103, counters 104, master keys 105, multi-key combinations 106, customer IDs 107, passport data 108, driver's license data 109, other user data 131, encrypted customer IDs 132, operating system 112, account applications 113, other applications 114, authentication applications 123, and / or account data 124.

[0082] Users can input commands and information into the computing system 802 through one or more wired / wireless input devices (e.g., keyboard 838 and pointing devices such as mouse 840). Other input devices may include microphones, infrared (IR) remote controls, radio frequency (RF) remote controls, gamepads, styluses, card readers, dongles, fingerprint readers, gloves, graphics tablets, joysticks, keyboards, retinal readers, touchscreens (e.g., capacitive, resistive, etc.), trackballs, tracking pads, sensors, styluses, etc. These and other input devices are typically connected to the processor 804 via input device interface 842 coupled to system bus 808, but can be connected via other interfaces such as parallel ports, IEEE 1394 serial ports, game ports, USB ports, IR interfaces, etc.

[0083] A monitor 844 or other type of display device is also connected to the system bus 808 via an interface (such as a video adapter 846). The monitor 844 can be internal or external to the computing system 802. In addition to the monitor 844, the computer typically includes other peripheral output devices, such as speakers, printers, etc.

[0084] The computing system 802 can operate in a networked environment using logical connections via wired and / or wireless communications with one or more remote computers (such as remote computer 848). Remote computer 848 can be a workstation, server computer, router, personal computer, portable computer, microprocessor-based entertainment device, peer-to-peer device, or other common network node, and typically includes many or all of the elements described with respect to computing system 802; however, for the sake of brevity, only memory / storage device 850 is illustrated. The depicted logical connections include wired / wireless connections to a local area network (LAN) 852 and / or a larger network (e.g., a wide area network (WAN) 854). Such LAN and WAN networking environments are common in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which can connect to global communication networks, such as the Internet. In the embodiment, network 130 of FIG1 is one or more of LAN 852 and WAN 854.

[0085] When used in a LAN networking environment, the computing system 802 is connected to the LAN 852 via a wired and / or wireless communication network interface or adapter 856. The adapter 856 facilitates wired and / or wireless communication with the LAN 852, which may also include a wireless access point configured thereon for wireless functional communication with the adapter 856.

[0086] When used in a WAN networking environment, computing system 802 may include a modem 858, or a communication server connected to WAN 854, or other means for establishing communication over WAN 854 (such as via the Internet). The modem 858, which may be internal or external to a wired and / or wireless device, is connected to system bus 808 via input device interface 842. In a networking environment, program modules described with respect to computing system 802 or parts thereof may be stored in remote memory / storage device 850. It will be appreciated that the network connections shown are exemplary, and other means of establishing communication links between computers may be used.

[0087] The computing system 802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operatively configured in wireless communication (e.g., IEEE 802.16 air modulation techniques). This includes, among other technologies, at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth. TM Wireless technology. Therefore, communication can be a predefined structure like a regular network, or simply peer-to-peer communication between at least two devices. Wi-Fi networks use radio technology known as IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connectivity. Wi-Fi networks can be used to interconnect computers, connect computers to the internet, and connect to wired networks (which use IEEE 802.3 related media and functions).

[0088] Various embodiments can be implemented using hardware components, software components, or a combination of both. Examples of hardware components may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, processes, software interfaces, application programming interfaces (APIs), instruction sets, computational code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. Determining whether an embodiment is implemented using hardware, software, and / or software components can vary depending on any number of factors, such as desired computational speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.

[0089] One or more aspects of at least one embodiment can be implemented using representative instructions stored on a machine-readable medium, the instructions representing various logics within a processor that, when read by a machine, cause the machine to produce logic that performs the techniques described herein. Such a representation (referred to as an "IP core") can be stored on a tangible machine-readable medium and supplied to various customers or manufacturing facilities for loading into a manufacturing machine that produces the logic or processor. Some embodiments can be implemented, for example, using a machine-readable medium or article capable of storing instructions or instruction sets that, if executed by a machine, cause the machine to perform the methods and / or operations according to the embodiments. Such a machine can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. The machine-readable medium or article may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disc read-only memory (CD-ROM), compact disc recordable (CD-R), compact disc rewritable (CD-RW), optical disc, magnetic media, magneto-optical media, removable memory card or disc, various types of digital multifunction discs (DVD), magnetic tape, magnetic cartridge, etc. The instructions may include any suitable code implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc.

[0090] The foregoing description of the exemplary embodiments is presented for illustrative and descriptive purposes only. It is not intended to be exhaustive or to limit this disclosure to the precise form disclosed. Many modifications and variations are possible in light of this disclosure. It is intended that the scope of this disclosure is not limited by the detailed description herein, but rather by the claims appended thereto. Claims for priority of this application may be made in various ways to claim the disclosure and may generally include any set of one or more limitations as disclosed or otherwise shown herein.

Claims

1. A computer-implemented method, comprising: The application running on the device's processor receives requests to perform operations associated with the account; The application receives encrypted data from a contactless card associated with the account, wherein the encrypted data is based on a multi-key of the contactless card, wherein the multi-key is based on the card master key and a counter value of the contactless card; The application sends encrypted data to the authentication server. The application receives the decryption result from the authentication server. The application determines, based on the decryption result, that the authentication server decrypted the encrypted data based on the diversified key instance generated by the server, wherein the diversified key instance generated by the server is based on the card master key instance and counter value instance maintained by the server. The application determines the type of authentication data required to authorize the operation, wherein the required authentication data type is determined from among a plurality of authentication data types and based on at least one rule of the type of operation and the type used for the operation; The application receives a first data element from the contactless card based on a determined authentication data type, the first data element including a passport image or a driver's license image. The application determines that the first data element includes the required authentication data type and satisfies at least one rule for authorizing the operation; and The application authorizes the execution of the operation based on the determination that the decryption result and the first data element satisfy at least one rule for authorizing the operation; and The operation is performed by the application based on the authorization, wherein the operation includes one or more of the following: (i) viewing the attributes of the account, (ii) modifying the attributes of the account, (iii) accessing a page of the application, or (iv) processing a transaction using the contactless card.

2. The method according to claim 1, further comprising: The application receives a first image of a person captured by the image capture device of the device. The application compares the first image with the passport image or the driver's license image. as well as The application determines, based on the comparison results, that the similarity between the person in the passport image or the driver's license image and the person in the first image exceeds a similarity threshold.

3. The method according to claim 2, further comprising: A notification providing the first image is output through the application; as well as The first image is captured via an image capture device.

4. The method of claim 2, wherein, The passport image or the driver's license image is determined to satisfy at least one rule based on similarity exceeding the aforementioned similarity threshold.

5. The method of claim 2, wherein, The similarity threshold is based on at least one rule of the type of the operation and the type of the operation, and the method further includes: The application determines whether a person in the first image matches a person in the passport image based on similarity exceeding the similarity threshold.

6. The method of claim 1, wherein, When the first data element is received from the contactless card, it is encrypted, and the method further includes: The application sends an encrypted first data element to the authentication server; and The application receives an unencrypted version of the first data element from the authentication server.

7. The method according to claim 1, further comprising: The application receives the digital signature of the first data element from the contactless card. as well as The application verifies the digital signature based on the public key of the contactless card.

8. An apparatus comprising: processor; as well as The memory stores instructions that, when executed by the processor, cause the processor to perform the following steps: Receive requests to perform operations associated with the account; Encrypted data is received from a contactless card associated with the account, wherein the encrypted data is based on a multi-key of the contactless card, wherein the multi-key is based on the card master key and a counter value of the contactless card; The application sends encrypted data to the authentication server. Receive the decryption result from the authentication server; Based on the decryption result, it is determined that the authentication server decrypted the encrypted data based on the diversified key instance generated by the server, wherein the diversified key instance generated by the server is based on the card master key instance and counter value instance maintained by the server; Determine the type of authentication data required to authorize the operation, wherein the required authentication data type is determined from among a plurality of authentication data types and based on at least one rule of the type of operation and the type used for the operation; A first data element is received from the contactless card based on a determined authentication data type, the first data element including a passport image or a driver's license image; The first data element is determined to include the required authentication data type and to satisfy at least one rule for authorizing the operation; The execution of the operation is authorized based on the decryption result and the determination that the first data element satisfies at least one rule for authorizing the operation; and Perform the operation according to the authorization, wherein the operation includes one or more of the following: (i) viewing the attributes of the account, (ii) modifying the attributes of the account, (iii) accessing a page of the application, or (iv) processing a transaction using the contactless card.

9. The device of claim 8, wherein the memory stores instructions that, when executed by the processor, cause the processor to: Receive a first image of a person captured by the image capture device of the device; Compare the first image with the passport image or the driver's license image; as well as Based on the comparison results, it is determined that the similarity between the person in the passport image or the driver's license image and the person in the first image exceeds a similarity threshold, wherein the passport image or the driver's license image satisfies at least one rule based on the similarity exceeding the similarity threshold.

10. The device of claim 9, wherein the memory stores instructions that, when executed by the processor, cause the processor to: The output provides a notification of the first image; and The first image is captured via an image capture device.

11. The apparatus of claim 9, wherein, The similarity threshold is based on at least one rule of the type of operation and the type of operation, wherein the memory stores instructions that, when executed by the processor, cause the processor to: Based on similarity exceeding the aforementioned similarity threshold, the person in the first image is determined to match the person in the passport image.

12. The apparatus of claim 8, wherein, When the first data element is received from the contactless card, it is encrypted. The memory stores instructions that, when executed by the processor, cause the processor to: Send the encrypted first data element to the authentication server; and Receive an unencrypted version of the first data element from the authentication server.

13. A computer-readable storage medium comprising instructions that, when executed by a processor, cause the processor to perform the following operations: Receive requests to perform operations associated with the account; receiving encrypted data from a contactless card associated with the account, wherein, The encrypted data is based on the diverse keys of the contactless card, wherein the diverse keys are based on the card master key and the counter value of the contactless card; Send encrypted data to the authentication server; Receive the decryption result from the authentication server; Based on the decryption result, it is determined that the authentication server decrypted the encrypted data based on the diversified key instance generated by the server, wherein the diversified key instance generated by the server is based on the card master key instance and counter value instance maintained by the server; Determine the type of authentication data required to authorize the operation, wherein the required authentication data type is determined from among a plurality of authentication data types and based on at least one rule of the type of operation and the type used for the operation; A first data element is received from the contactless card based on a determined authentication data type, the first data element including a passport image or a driver's license image; The first data element is determined to include the required authentication data type and to satisfy at least one rule for authorizing the operation; The execution of the operation is authorized based on the decryption result and the determination that the first data element satisfies at least one rule for authorizing the operation; and The operation is performed based on the authorization, wherein the operation includes one or more of the following: (i) viewing the attributes of the account, (ii) modifying the attributes of the account, (iii) accessing a page of the application, or (iv) processing a transaction using the contactless card.

14. The computer-readable storage medium of claim 13, wherein, The instruction also causes the processor to: Receive the first image of a person captured by the image capture device; Compare the first image with the passport image or the driver's license image; as well as Based on the comparison results, it is determined that the similarity between the person in the passport image or the driver's license image and the person in the first image exceeds a similarity threshold.

15. The computer-readable storage medium of claim 14, wherein, The instruction also causes the processor to: The output provides a notification of the first image; and The first image is captured via an image capture device.

16. The computer-readable storage medium of claim 14, wherein, The passport image or the driver's license image is determined to satisfy at least one rule based on similarity exceeding the aforementioned similarity threshold.

17. The computer-readable storage medium of claim 14, wherein, The similarity threshold is based on the type of the operation and at least one rule for the type of the operation, wherein the instruction further causes the processor to: Based on similarity exceeding the aforementioned similarity threshold, the person in the first image is determined to match the person in the passport image.

18. The computer-readable storage medium of claim 13, wherein, When the first data element is received from the contactless card, it is encrypted, wherein the instruction further causes the processor to: Send the encrypted first data element to the authentication server; and Receive an unencrypted version of the first data element from the authentication server.

Citation Information

Patent Citations

  • Systems and methods for cryptographic authentication of contactless cards

    US10581611B1

  • Embedded secure element for authentication, storage and transaction within a mobile terminal

    CN103544599A

  • Face recognition system and face recognition method for vehicle

    CN108189804A