Comments on authentication using contactless cards
By combining contactless cards and authentication servers, and utilizing cryptographic algorithms and transaction record verification, the problem of difficulty in verifying the authenticity of reviews is solved, the authenticity verification and reward mechanism of reviews are realized, and the credibility of reviews is improved.
Patent Information
- Application Number
- CN202080013777.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Priority Date
- 2019-07-17
- Filing Date
- 2020-07-09
- Publication Date
- 2025-10-10
- Estimated Expiration
- 2040-07-09
AI Technical Summary
Users cannot trust the authenticity of reviews because fake reviews affect sales, and existing technology cannot effectively verify the authenticity of reviews.
By using a contactless card, cryptographic algorithms and private keys to generate encrypted data, combined with decryption and transaction record verification on the authentication server, the transaction records between the user and the review entity are confirmed to ensure the authenticity of the review.
It improves the validity and authenticity of reviews, ensures that only users who have actually conducted transactions can submit verified reviews, and provides rewards or incentives to enhance the credibility of reviews.
Smart Images

Figure CN113439284B_ABST
Abstract
Description
Technical Field
[0001] Embodiments herein relate generally to computing platforms and, more particularly, to providing authentication reviews using contactless cards.
[0002] Related applications
[0003] This application claims priority to U.S. Patent Application No. 16 / 514,094, entitled “VERIFIED REVIEWS USING A CONTACTLESS CARD,” filed on July 17, 2019. The contents of the aforementioned application are incorporated herein by reference in their entirety. Background Art
[0004] Users often write reviews of products, services, restaurants, and the like. Such reviews are often a valuable source of user opinion that can be used to improve the quality of the associated offering. However, because positive reviews can have an impact on sales, fake reviews are often posted to boost sales. Similarly, fake reviews can be posted to negatively impact competitor sales. Consequently, users often cannot trust reviews because there is uncertainty about whether the review was written by someone who dined at the restaurant or used the product or service. Summary of the Invention
[0005] Embodiments disclosed herein provide systems, methods, articles of manufacture, and computer-readable media for providing verified reviews using contactless cards. According to one example, an application may receive an instruction to generate a review for an entity, including one or more of a merchant and a service provider. The application may output an instruction to tap a contactless card against a device. An application programming interface (API) of the application may receive encrypted data from a communication interface of the contactless card, the encrypted data generated by the contactless card using a cryptographic algorithm, a customer identifier, and a private key stored in a memory of the contactless card. The application API may send to an authentication server associated with the contactless card: (i) the encrypted data, (ii) the application instruction, and (iii) an entity identifier associated with the entity. The application API may receive an instruction from the authentication server instructing the authentication server to: (i) decrypt the encrypted data using a copy of the private key stored on the server to obtain a customer identifier, and (ii) determine, based at least in part on the entity identifier and the decrypted customer identifier, that the contactless card was used to make a purchase with the entity. The application may allow the generation of the review based on the instruction received from the authentication server. The application may publish the review to one or more review platforms associated with the application.
[0006] According to another example, the authentication server may receive an instruction from a review application to generate a review for an entity, the entity comprising one or more of a merchant and a service provider. The authentication server may receive from the review application an application programming interface (API) of the review application encrypted data received from a contactless card and an entity identifier associated with the entity, the encrypted data being based on a cryptographic algorithm, a client identifier, and a private key. The authentication server may decrypt the encrypted data using a copy of the private key stored by the server to obtain the client identifier. The authentication server may determine that the contactless card was used to make a purchase from the entity based at least in part on the entity identifier and the decrypted client identifier. The authentication server may send permission to the application to generate the review and to receive the review from the application. The authentication server may then publish the review to one or more review platforms associated with the application. BRIEF DESCRIPTION OF THE DRAWINGS
[0007] Figures 1A-1B An embodiment of a system for providing authenticated reviews using a contactless card is illustrated.
[0008] Figures 2A-2C An embodiment of providing authenticated reviews using a contactless card is illustrated.
[0009] Figures 3A-3B An embodiment of providing authenticated reviews using a contactless card is illustrated.
[0010] Figure 4 An embodiment of a first logic flow is illustrated.
[0011] Figure 5 An embodiment of the second logic flow is illustrated.
[0012] Figure 6 An embodiment of the third logic flow is illustrated.
[0013] Figure 7 An embodiment of the fourth logic flow is illustrated.
[0014] Figure 8 An embodiment of a computing architecture is illustrated.
[0015] Figures 9A-9B An example contactless card is illustrated. DETAILED DESCRIPTION
[0016] Embodiments disclosed herein provide techniques for securing reviews of verifications using a contactless card. Generally, a user can attempt to provide a review of an entity, such as a restaurant, merchant, and / or service provider, via a review platform. The review platform can be a website and / or a dedicated application having an application programming interface (API) that can communicate with a server associated with a contactless card. During the review generation and / or submission process, the user can be prompted to tap their contactless card to their computing device. The API can communicate with the contactless card to receive encrypted data generated by the contactless card using a private key and a cryptographic algorithm. The API can provide the encrypted data to the server along with other review data, e.g., an identifier of the entity that is the subject of the review. The server can attempt to decrypt the encrypted data generated by the contactless card. If the server is able to decrypt the encrypted data, the server can verify the encrypted data. The server can then determine whether the card was used to make a payment for a transaction between the user and the entity being reviewed. For example, the server can attempt to identify a transaction record in a transaction log that indicates the contactless card was used to make a payment for a transaction between the user and the entity being reviewed. If the server identifies such a transaction record, the server can verify that the user in fact transacted with the entity.
[0017] The server can then notify the API that the encrypted data was verified and that the transaction record was verified. The API can allow the user to complete submission of the verified review using the review platform. Once submitted, the verified review is published to the review platform with an indication that the review was verified, e.g., the user in fact ate at the restaurant, made a payment for services provided by the service provider, etc. Further, the API can send an indication of the submitted review to the contactless card, which can store the indication in the memory of the contactless card. When the user subsequently visits the entity, a POS device of the entity can receive the stored indication from the memory of the contactless card. The POS device, upon receiving the indication from the contactless card, can provide a reward, discount, or another incentive to the user.
[0018] Advantageously, embodiments disclosed herein improve the validity and authenticity of user-submitted reviews by confirming that the review user in fact transacted with the subject entity of the review. Further, the verification performed by the authentication server provides safeguards to ensure that an authorized user of a physical card is requesting to submit a review. Further, by providing a secure API to communicate with the contactless card and / or server, embodiments disclosed herein provide a secure, portable solution that can be used with any review platform.
[0019] Generally referring to the symbols and nomenclature used in this article, one or more parts of the following detailed description can be presented in terms of program processes executed on a computer or computer network. These process descriptions and representations are used by those skilled in the art to most efficiently convey the essence of their work to other technical personnel in the field. A process is generally conceived here as a self-consistent sequence of operations that leads to a desired result. These operations are those that require physical manipulation of physical quantities. Typically, although not necessarily, these quantities take the form of electrical, magnetic, or optical signals that can be stored, transmitted, combined, compared, and otherwise manipulated. Mainly due to common reasons, it sometimes proves convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all of these terms and similar terms will be associated with appropriate physical quantities and are merely convenient labels applied to these quantities.
[0020] Furthermore, these manipulations are often referred to in terms typically associated with mental operations performed by a human operator, such as adding or comparing. However, such capabilities of a human operator are not necessary, or in most cases desirable, for any of the operations described herein that form part of one or more embodiments. Instead, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by computer programs written in accordance with the teachings herein and stored therein, and / or include devices specially constructed for the desired purpose or digital computers. Various embodiments also relate to devices or systems for performing these operations. These devices can be specially constructed for the desired purpose. The required structure of each of these machines will be apparent from the description given.
[0021] Reference is now made to the accompanying drawings, in which like reference numerals are used throughout to refer to like elements. In the following description, for illustrative purposes, numerous specific details are set forth to provide a thorough understanding thereof. However, it may be apparent that novel embodiments can be implemented without these specific details. In other cases, well-known structures and devices are shown in block diagram form to facilitate their description. The present invention encompasses all modifications, equivalents, and alternatives within the scope of the claims.
[0022] Figure 1AA schematic diagram depicts an exemplary system 100 consistent with the disclosed embodiments. As shown, system 100 includes one or more contactless cards 101, one or more computing devices 110, an authentication server 120, and one or more review platforms 140. Contactless card 101 represents any type of payment card, such as a credit card, debit card, ATM card, gift card, etc. Contactless card 101 may include one or more communication interfaces 107, such as a radio frequency identification (RFID) chip configured to communicate with computing device 110 via NFC, the EMV standard, or other short-range wireless communication protocols. Although NFC is used as an example communication protocol, the present disclosure is equally applicable to other types of wireless communication, such as the EMV standard, Bluetooth, and / or Wi-Fi. Computing device 110 represents any type of network-enabled computing device, such as a smartphone, tablet, wearable device, laptop, portable gaming device, mobile device, workstation, desktop computer, server, etc. Server 120 and review platform 140 represent any type of computing device, such as a server, workstation, computing cluster, cloud computing platform, virtualized computing system, etc.
[0023] Computing device 110 may be controlled by an instance of an operating system (OS, not depicted). Example operating systems include OS, and Operating system. As shown, the memory 111 of the computing device 110 includes a review application 113, which includes one or more application programming interfaces (APIs) 114. The review application 113 allows users to generate reviews 141 for publications on one or more review platforms 140. Using the API 114, the review application 113 can allow users to submit verified (or confirmed) reviews. Generally speaking, the API 114 can facilitate communication with the contactless card 101 and / or the server 120 to confirm that the contactless card 101 is used to pay for a transaction with the entity that is the subject of the review, thereby providing a verified review. The entity object of the review can include, but is not limited to, a restaurant, a merchant, a service provider, or any other type of business that one or more users may wish to provide a review for. As described in more detail below, the review application 113 and the API 114 can be used to confirm that the user has actually conducted a transaction with the entity, for example, eaten at the target restaurant, paid for services provided by the target service provider, made a purchase from the target merchant, and so on.
[0024] In some embodiments, the review application 113 may be a dedicated application (e.g., a mobile OS application) provided by an entity associated with one or more review platforms 140. In other embodiments, the functionality provided by the review application 113 and / or API 114 may be integrated into other platforms (such as one or more web pages and / or services provided by the review platform 140). In such embodiments, a user may use a web browser (not depicted) or other application to access the web pages and / or services provided by the review platform 140. The embodiments are not limited in these contexts.
[0025] In general, a user of the review application 113 can specify that a review of an entity be generated. For example, a user can access a page about a restaurant at which they recently dined in the review application 113 and specify that the review application 113 be used to generate a new review of the restaurant. In response, the review application 113 can output a notification on the computing device 110 specifying that the contactless card 101 be tapped against the computing device 110, thereby bringing the contactless card 101 close enough to the card reader 118 of the computing device 110 to enable data transfer (e.g., NFC data transfer, Bluetooth data transfer, etc.) between the communication interface 107 of the contactless card 101 and the card reader 118 of the computing device 110. The applet 103 executed on the processor (not depicted) of the contactless card 101 can then generate and send encrypted data 105 to the computing device 110 via the communication interface 107 of the contactless card 101. For example, the applet 103 of the contactless card 101 can use a cryptographic algorithm to generate a cryptographic payload of encrypted data 105 based at least in part on a private key 104 stored in the memory 102 of the contactless card 101. In such an embodiment, the private key 104 and another piece of data (e.g., a customer identifier, an account identifier, etc.) can be provided as input to the cryptographic algorithm, which outputs encrypted data 105. In general, the applet 103 can use any type of cryptographic algorithm and / or system to generate encrypted data 105, and the use of a specific cryptographic algorithm as an example herein should not be considered a limitation of the present disclosure. In some embodiments, the applet 103 can use key diversification techniques to perform encryption to generate encrypted data 105. Examples of key diversification techniques are described in U.S. patent application 16 / 205,119, filed on November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety.
[0026] In some embodiments, API 114 of review application 113 may send an instruction to contactless card 101 specifying the generation of encrypted data 105. In other embodiments, applet 103 generates encrypted data 105 without requiring instructions from API 114. In some embodiments, API 114 of review application 113 may send an entity identifier (ID) 115 to applet 103. Entity identifier 115 may be any identifier that uniquely identifies an entity (e.g., a restaurant for which a user selected to write a review). In some such embodiments, applet 103 determines whether the received entity identifier matches (or is similar to) one or more entity identifiers in transaction log 106. Transaction log 106 may store details describing one or more recent transactions completed using contactless card 101. If the received entity identifier is a match, applet 103 may determine that the user completed a transaction with the entity (e.g., dined at the restaurant) and generate encrypted data 105. If the received entity identifier is not a match, applet 103 may refrain from generating encrypted data 105 because applet 103 cannot verify that the user completed the transaction with the entity. However, in some embodiments, applet 103 may generate encrypted data 105 even if entity ID 115 does not match any portion of transaction log 106 .
[0027] Once generated, applet 103 can send the encrypted data 105 to the API 114 of the comment application 113 of computing device 110, for example, via NFC. In some embodiments, applet 103 can also send the data describing one or more transactions from transaction log 106 to comment application 113. In some embodiments, comment application 113 can confirm whether there is a match between the entity ID 115 of the entity object of the comment and the transaction log 106. If the match exists, comment application 113 can allow the comment of verification to be generated. However, in some such embodiments, comment application 113 can request confirmation (and / or verification) to server 120 before allowing the comment of verification to be submitted to comment platform 141. The confirmation and / or verification of the request can generally allow comment application 113 to confirm that the user has in fact carried out a transaction with the entity being commented on, for example, eaten at a restaurant, used a service, etc.
[0028] Generally speaking, the API 114 of the review application 113 can send the encrypted data 105, the entity ID 115, and the application ID 116 to the authentication application 123 of the authentication server 120 via the network 130. The application ID 116 can uniquely identify the review application 113 and / or the associated review platform 140. This can facilitate a lookup using the entity ID 115 associated with the review application 113 and the entity ID in the entity data 125, where the entity ID in the entity data 125 can be used in the transaction data 126. The authentication server 120 can then attempt to decrypt the encrypted data 105 and determine whether the transaction data 126 reflects that the contactless card 101 was used to pay for the transaction with the subject entity.
[0029] Figure 1B The following illustrates an embodiment in which authentication application 123 of authentication server 120 processes data received from review application 113. As described, authentication application 123 may attempt to verify encrypted data 105. For example, authentication application 123 may attempt to decrypt encrypted data 105 using a copy of private key 104 stored in memory 122 of authentication server 120. Private key 104 may be identical to the private key 104 stored in memory 102 of contactless card 101, where each contactless card 101 is manufactured to include a unique private key 104 (and authentication server 120 stores a corresponding copy of each unique private key 104). Therefore, authentication application 123 may successfully decrypt encrypted data 105, thereby verifying encrypted data 105. Although private key 104 is depicted as being stored in memory 122, private key 104 may be stored elsewhere, such as in a secure element and / or a hardware security module (HSM). In such an embodiment, the secure element and / or HSM may decrypt the encrypted data 105 using the private key 104 and cryptographic functions.
[0030] For example, a customer identifier associated with contactless card 101 can be used to generate encrypted data 105. In such an example, authentication application 123 can use private key 104 of authentication server 120 to decrypt encrypted data 105. If the decryption result yields the customer identifier associated with contactless card 101 in account data 124, authentication application 123 verifies encrypted data 105. If authentication application 123 cannot decrypt the encrypted data to yield the expected result (e.g., the customer identifier of the account associated with contactless card 101), authentication application 123 does not verify encrypted data 105.
[0031] Once authentication application 123 successfully decrypts encrypted data 105, authentication application 123 can then determine whether transaction data 126 includes a record indicating that contactless card 101 was used to pay for a transaction with the entity selected by the user for review. For example, authentication application 123 can determine whether a transaction record in transaction data 126 includes the contactless card's account number and the entity ID 115 of the entity (e.g., the restaurant being reviewed). If such a transaction record exists, authentication application 123 can send an indication of confirmation 127 to computing device 110. Confirmation 127 can generally reflect that authentication application 123 verified encrypted data 105 (by decrypting encrypted data 105) and that contactless card 101 was used to make a purchase with the entity being reviewed. Confirmation 127 can further serve as permission to generate and / or publish the review. However, if encrypted data 105 was not decrypted and / or the record in transaction data 126 is not recognized, authentication application 123 can refrain from generating the confirmation and / or send a failure status to review application 113. In some embodiments, confirmation 127 may be stored in account data 124 for an account associated with contactless card 101. In some embodiments, confirmation 127 includes metadata attributes such as the time of the confirmation, the time of the identified transaction, entity ID 115, application ID 116, etc.
[0032] In some embodiments, authentication application 123 may determine whether the date of the transaction record in transaction data 126 is within a time threshold before generating confirmation 127. For example, if the transaction date is 100 days ago and the time threshold is one week, authentication application 123 may determine that the transaction record is not valid based on the threshold and refrain from sending confirmation 127 to computing device 110. In some embodiments, authentication application 123 may parse entity ID 115 against entity data 125 to determine that the transaction identifier is used to identify the associated entity in transaction data 126. Similarly, in some embodiments, authentication application 123 may receive transaction log 106 from computing device 110 and, before generating confirmation 127, confirm that transaction log 106 for contactless card 101 reflects the transaction associated with entity ID 115. Furthermore, in some embodiments, authentication application 123 may maintain a counter associated with contactless card 101. The counter may reflect how many reviews the user associated with contactless card 101 has attempted to submit. If the counter exceeds a threshold, authentication application 123 may refrain from verifying encrypted data 105 and / or searching transaction data 126, thereby preventing users from submitting an excessive number of reviews and / or submitting programmatically generated reviews.
[0033] The API 114 of the review application 113 may receive a confirmation 127 from the server 120 indicating that the user conducted a transaction with the entity associated with the entity ID 115. In response, the review application 113 may allow the user to write and / or submit a verified review 141-1 for the entity associated with the entity ID 115 to the review platform 140. If the server 120 does not send the confirmation 127 (and / or the API 114 receives an indication of a rejection and / or failure status from the server 120), the review application 113 may refrain from allowing the user to submit a verified review. In some such embodiments, the review application 113 may allow the user to submit a general review that is not marked as a verified review. The review platform 140 and / or the review application 113 may use any suitable means (such as using graphics, text, images, etc.) to distinguish between general reviews and / or verified reviews within the reviews 141. The review application 113 may further send an indication of the review 141-1 to the server 120, which may store the indication of the published review in the account data 124 for the review user.
[0034] Once review 141-1 is submitted to the review platform, review application 113 may output instructions to tap contactless card 101 toward computing device 110. Once contactless card 101 is brought within communication range of computing device 110, API 114 may send review confirmation 108 to contactless card 101, which stores review confirmation 108 in memory 102. In some embodiments, review confirmation 108 is the same as confirmation 127 received from server 120. In other embodiments, review confirmation 108 is different from confirmation 127 received from the server. For example, review confirmation 108 may include additional metadata describing review 141-1, such as a timestamp when the review was published, an identifier of the associated user, the entity ID 115 of the entity object of the review, any metadata of confirmation 127, whether the review was favorable or unfavorable, etc.
[0035] The review application 113 and / or the merchant device may receive the review confirmation 108 from the contactless card 101 at a later time. Doing so may allow the review application 113 and / or the merchant device to provide the user with a reward, discount, and / or other incentive for publishing a review associated with the review confirmation. In some embodiments, the review application 113 may output an instruction to submit an additional review. In some such embodiments, the review application 113 may identify other entities in the transaction log 106 and output a notification requesting the user to submit a verified review for the entity identified in the transaction log 106.
[0036] In one embodiment, review application 113 may send review 141-1 to authentication application 123 in response to receiving confirmation 127. Authentication application 113 may then send review 141-1 to review platform 140 for publication.
[0037] Figure 2A 2 is a schematic diagram 200 depicting an example embodiment of tapping a contactless card 101 to provide a verified review via a review application 113. As shown, the review application 113 outputs a graphical user interface (GUI) for submitting a verified review for an example entity "Entity ABC". The GUI includes a rating field 201 for providing a rating. The rating can be a numeric rating, a star rating, a text-based rating, or any other type of rating. The GUI further includes a comment field 202 that allows a user to provide a comment related to the rating. The GUI may further include additional elements, such as fields for providing images, videos, etc. The specific type and format of the example verified review should not be considered a limitation of the present disclosure, as the present disclosure applies equally to all types of reviews.
[0038] In one embodiment, the user can provide input in fields 201-202 and select submit button 203 to submit the review to review platform 140. In response, review application 113 can output notification 204 specifying that contactless card 101 is tapped toward computing device 110. Once contactless card 101 is tapped toward computing device 110, the small application 103 of contactless card 101 can generate encrypted data 105. In some embodiments, small application 103 can represent multiple small applications stored in contactless card 101. In such an embodiment, contactless card 101 can select the small application 103 associated with the review of convenience verification. The selected small application 103 can then generate the data necessary for the review of convenience verification (e.g., encrypted data 105), and / or provide additional data necessary for the review of convenience verification (e.g., transaction log 106).
[0039] Once generated, applet 103 may send encrypted data 105 to computing device 110 via communication interface 107. In some embodiments, applet 103 may send transaction log 106 along with encrypted data 105 to computing device 110. As described, in some embodiments, applet 103 may receive entity ID 115 from API 114. In such embodiments, applet 103 may determine whether transaction log 106 includes a record reflecting that contactless card 101 was used as part of a transaction for the entity associated with entity ID 115 before generating encrypted data 105. API 114 of review application 113 may send encrypted data 105, transaction log 106, entity ID 115, and / or application ID 116 to authentication server 120. In some embodiments, receipt of application ID 116 instructs authentication server 120 to perform operations associated with the verified review (e.g., verifying encrypted data 105 and searching transaction data 126 for matching transactions).
[0040] Authentication application 123 may then attempt to decrypt encrypted data 105 using private key 104 associated with contactless card 101. If authentication application 123 cannot decrypt the encrypted data to obtain the expected result (e.g., a customer identifier of an account associated with contactless card 101, etc.), authentication application 123 does not verify encrypted data 105 and does not confirm the transaction in transaction data 126. If authentication application 123 decrypts the encrypted data to obtain the expected result (e.g., a customer identifier of an account associated with contactless card 101), authentication application 123 verifies encrypted data 105 and determines whether the transaction in transaction data 126 reflects that contactless card 101 was used to pay for (at least a portion of) a transaction for the entity associated with entity ID 115. If the transaction is recognized and encrypted data 105 is verified, authentication application 123 may generate a confirmation and send the confirmation to API 114 of review application 113. In some embodiments, if authentication application 123 identifies a transaction in transaction data 126, authentication application 123 may determine whether the date of the identified transaction is within a threshold for generating a verified review before generating a confirmation.
[0041] Figure 2B210 is a diagram illustrating an embodiment in which the authentication application 123 verifies the encrypted data 105 and sends a confirmation to the API 114 of the review application 113. The review application 113 may then allow the user to write and / or submit a verified review. The user may then submit the verified review, which may then be stored as a review 141 on the review platform 140. The user may then edit the review 141 if desired. Other users may also view the verified review in the reviews 141 via the review application 113 and / or other applications.
[0042] Figure 2C 220 is a diagram illustrating an embodiment in which a verified review is published to reviews 141 of review platform 140. As shown, review application 113 may provide a link 205 allowing the user to view the verified review. Review application 113 may also output instructions to tap contactless card 101 against device 110. Doing so allows API 114 to submit review confirmation 108 to contactless card 101. Contactless card 101 may store review confirmation 108 in memory 102, thereby allowing review confirmation 108 to be used for rewards, incentives, and the like at a later time.
[0043] Figure 3A 3 is a schematic diagram 300 illustrating an example of using a contactless card 101 at a physical point of sale (POS) device 301. POS device 301 represents any type of computing device, such as a card reader device, a smartphone, a tablet computer, a desktop computer, a POS terminal, a server, a workstation, a laptop computer, etc. As shown, POS device 301 instructs a user to tap their contactless card 101 toward POS device 301. The user can bring contactless card 101 within communication range of POS device 301, which can cause applet 103 to send review confirmation 108 to POS device 301. In some embodiments, contactless card 101 is inserted into a card reader of POS device 301, and review confirmation 108 is sent via the card reader.
[0044] In response, POS device 301 can analyze review confirmation 108 to determine whether the associated review qualifies the user to receive a reward or other incentive. For example, POS device 301 can determine whether the entity ID 115 associated with review confirmation 108 matches the entity ID associated with the entity that provided POS device 301. As another example, POS device 301 can determine whether the timestamp associated with review confirmation 108 indicates that review confirmation 108 is within a time threshold for providing rewards for reviews. More generally, POS device 301 confirms that the user has published a verified review 141 for the entity on review platform 140 based at least in part on review confirmation 108.
[0045] Figure 3B 310 is a schematic diagram illustrating an embodiment in which a POS device 301 confirms that a user has published a comment 141 for verification of an entity on a comment platform 140, at least in part based on the comment confirmation 108 received from the memory 102 of a contactless card 101. As shown, the POS device 301 outputs one or more rewards to a customer based on the comment confirmation 108 identified. The user can then select a desired reward. Once selected, the POS device 301 can process the selected reward. If the selected reward is applicable to a previous transaction (e.g., a refund for a previous purchase), the POS device 301 can send the instruction of the refund to an appropriate server (e.g., server 120). If the selected reward is for future transactions, the POS device 301 can store the instruction of the selected reward in the user profile of the user. In some embodiments, the POS device 301 stores the instruction of the selected reward in the memory 102 of the contactless card 101 and / or the memory 111 of the computing device 110. Doing so allows POS device 301 to recognize the reward in memory 102 of contactless card 101 and / or memory 111 of computing device 110 at a later time and automatically provide the reward to the user at that time.
[0046] although Figure 3A -3C depicts an embodiment in which contactless card 101 is tapped against POS device 301, but the embodiments are not limited in this context. For example, in some embodiments, contactless card 101 may be tapped against computing device 110 instead of POS device 301. Figure 3A In such an embodiment, contactless card 101 may send review confirmation 108 to computing device 110. Review application 113 may then send review confirmation 108 to POS device 301. POS device 301 may then analyze review confirmation 108 to determine whether the associated review qualifies the user to receive a reward or other incentive. Any reward may be sent by POS device 301 to computing device 110 and / or review application 113 for display (e.g., via a communication with Figure 3B Once selected, an indication of the reward may be stored in memory 111 of computing device 110. Similarly, computing device 110 may send an indication of the selected reward to POS device 301, which may store the indication of the selected reward in a user profile for the user.
[0047] Figure 4Embodiments of the logical flow 400 are illustrated. The logical flow 400 can be representative of some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 400 can include some or all of the operations of providing a review of a verification using a contactless card. Embodiments are not limited in this context.
[0048] As shown, the logical flow 400 begins at block 405, where a user of a review application 113 executing on a computing device 110 attempts to provide a review of an entity. As described, the entity can be any type of merchant and / or service provider. For example, the user can attempt to provide a review of a taxi service. At block 410, the review application 113 can output a notification specifying that the computing device 110 be tapped with a contactless card 101 to provide a verified review. At block 415, the contactless card 101 is tapped to the computing device 110, which can cause the applet 103 of the contactless card 101 to generate encrypted data 105. As described, the applet 103 can use a private key 104, a cryptographic algorithm, and another piece of data (e.g., a customer ID) to generate the encrypted data 105. In some embodiments, prior to generating the encrypted data 105, the applet 103 determines whether a transaction in the transaction log 106 reflects that the contactless card 101 was used to make a payment for a transaction associated with the entity ID 115 received from the review application 113. At block 420, the applet 103 sends the encrypted data 105 to the API 114 of the device 110. The applet 103 can optionally send the transaction log 106 to the device 110 along with the encrypted data 105.
[0049] At block 425, the API 114 of the review application 113 can receive the encrypted data 105 and / or the transaction log 106 from the contactless card 101. At block 430, the review application 113 can provide the entity ID 115 of the entity and the application ID 116 of the review application 113 to the API 114 of the review application 113. At block 435, the API(s) 114 of the review application 113 can send the encrypted data, the entity ID 115, and the application ID 116 to the authentication server 120. At block 440, the authentication application 123 can attempt to decrypt the encrypted data 105 using the private key 104 associated with the contactless card 101 stored by the server 120. If the authentication application 123 decrypts the encrypted data 105 to generate an expected result (e.g., a customer identifier associated with the contactless card 101 stored in the account data 124), the authentication application 123 can verify the encrypted data.
[0050] At block 445, authentication application 123 may identify a previous transaction between contactless card 101 and entity ID 115 in transaction data 126. This allows authentication application 123 to confirm that the user did in fact conduct business with the entity for which the user wishes to submit a review. For example, by identifying a record in transaction data 126 indicating that contactless card 101 was used to pay for taxi services provided by a taxi service entity, authentication application 123 may confirm that the user is in fact a paying customer of the taxi service. At block 450, authentication application 123 may send an indication of the confirmation to device 110. The confirmation may generally indicate that the encrypted data was verified and / or that a valid transaction was identified in transaction data 126.
[0051] Once the review application 113 receives confirmation from the server 120, the review application 113 may allow the verified review to be published. In some embodiments, the review application 113 may disable certain GUI components to restrict the generation and / or submission of reviews until confirmation is received from the server 120. For example, the review application 113 may disable Figures 2A-2B 1-202 until confirmation is received. As another example, the review application 113 may not allow the user to provide input to fields 201-202 until confirmation is received. At block 455, the review application 113 receives input specifying publication of the verified review to the review platform. The review application 113 may then send the review to the review platform 140 along with an indication that the review is a verified review. The review platform 140 may then store the verified review (including the indication that the review is verified) in reviews 141. The user may then view the verified review, for example, by using the review application 113.
[0052] At block 460, one or more APIs of the review application 113 may send an indication of the published review to the contactless card 101, which may store the indication in the memory 102. For example, a review confirmation 108 specifying that a user wrote a verified review of a taxi service may be sent to the contactless card 101. At block 465, the contactless card 101 may store the indication of the published review in the memory 102 of the contactless card 101.
[0053] Figure 5 An embodiment of a logic flow 500 is illustrated. Logic flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, logic flow 500 may include some or all of the operations of verifying a review based at least in part on data generated by a contactless card. The embodiments are not limited in this context.
[0054] As shown, logic flow 500 begins at block 505, where authentication application 123 receives data from one or more APIs 114 of review application 113. For example, authentication application 123 may receive encrypted data 105 generated by contactless card 101, transaction log 106 for contactless card 101, entity ID 115, and / or application ID 116 as part of a request to confirm a verified review. At block 510, authentication application 123 attempts to decrypt encrypted data 105 using server 120's private key 104 to obtain the customer ID associated with the contactless card. At block 515, authentication application 123 may search transaction data 126 to identify transactions between contactless card 101 and the entity ID. For example, if entity ID 115 is associated with a restaurant, authentication application 123 may identify records in transaction data 126 indicating that contactless card 101 was used to pay for a meal at that restaurant.
[0055] At block 520, the authentication application 123 determines whether the time associated with the transaction identified at block 515 exceeds a time limit (or threshold). For example, the authentication application 123 may have a 10-day threshold for transactions. If the identified transaction occurred within 10 days, the authentication application 123 may confirm the verified comment for the transaction. Otherwise, the authentication application 123 may deny the verified comment for the transaction. At block 525, the authentication application 123 determines whether the comment limit has been exceeded by the current comment. As described, the authentication application 123 may maintain a comment counter associated with the contactless card 101. If the comment counter is incremented based on the current comment so that the counter exceeds the limit, the authentication application 123 may deny the verified comment for the transaction. Otherwise, the authentication application 123 may deny the verified comment for the transaction.
[0056] At block 530, the authentication application 123 can reject the validated comment, and / or suppress sending the validation to the comment application 113. For example, the authentication application 123 can reject the validated comment based on a determination that the encrypted data 105 was not decrypted, that the transaction was not identified in the transaction data 126, or that the time and / or comment limits were exceeded. Doing so allows the comment application 113 to limit the user from publishing the validated comment. Additionally and / or alternatively, the comment application 113 can allow the user to publish the comment, but not provide a validated status for the comment. At block 535, the authentication application 123 can send an indication of approval (e.g., validation) of the requested validated comment to the comment application 113. For example, the authentication application 123 can successfully decrypt the encrypted data 105, identify one or more transactions in the transaction data 126, and determine that the identified transactions do not exceed the time limit and / or the comment limit. As another example, the authentication application 123 can further determine that the transactions exist in the received transaction log 106 of the contactless card 101. Doing so allows the authentication application 123 to validate the requested comment as not fraudulent based on the decryption of the encrypted data and the identification of recent transactions between the user and the entity.
[0057] Figure 6 An embodiment of the logic flow 600 is illustrated. The logic flow 600 can be representative of some or all of the operations executed by one or more embodiments described herein. For example, the logic flow 600 can include some or all of the operations of using a contactless card for validating a comment. Embodiments are not limited in this context.
[0058] As shown, the logic flow 600 begins at block 605, where the comment application 113 identifies one or more transactions in the transaction log 106 received from the contactless card 101. At block 610, the comment application 113 can determine that the transactions in the transaction log 106 indicate that the contactless card 101 was used to make a payment for a transaction with the entity that the user is attempting to publish a validated comment for. For example, an entity ID for the entity can be specified in the transaction log 106. At block 615, the comment application 113 determines that the transactions identified at block 610 are within a time threshold. For example, the comment application 113 can determine that the transactions have timestamps indicating that the transactions are within 3 days, while the time threshold is 30 days. The comment application 113 can make the determinations at blocks 610-615 before at least sending the encrypted data 105 to the server 120 for verification. The verification can occur as described above, and the user can optionally submit the validated comment based on a validation received from the server 120 by the comment application 113.
[0059] At block 620, the review application 113 may identify a transaction with the second entity in the transaction log 106 received from the contactless card 101. At block 625, the review application 113 may output a notification requesting the user to write a review for the second entity. The user may then decide to write a review for the second entity, which may be verified using the contactless card 101 as described herein.
[0060] Figure 7 An embodiment of a logic flow 700 is illustrated. Logic flow 700 may represent some or all of the operations performed by one or more embodiments described herein. For example, logic flow 700 may include some or all of the operations of providing a reward based on an indication of a published review stored on a contactless card. The embodiments are not limited in this context.
[0061] As shown, logic flow 700 begins at block 705, where a merchant device (such as POS device 301) outputs an indication that a contactless card 101 has been tapped toward and / or inserted into the POS device 301. At block 710, the POS device 301 receives data from the contactless card 101. For example, the applet 103 may send one or more review confirmations 108 stored in memory 102 to the POS device 301. At block 715, the merchant device identifies an indication that a user has submitted a verified review of an entity associated with the POS device 301. For example, the POS device 301 may compare the entity ID 115 in the received review confirmation 108 and determine that the entity ID 115 is associated with the entity that provided the POS device 301.
[0062] At block 720, POS device 301 outputs one or more rewards, discounts, and / or incentives for display. For example, POS device 301 may offer discounts on future purchases, upgrades for future purchases, and / or refunds on previous purchases. At block 725, POS device 301 receives the selection of one or more rewards output at block 720. For example, a user may select an upgraded hotel room for their next stay. At block 730, POS device 301 applies the selected reward to the user's account. For example, POS device 301 may store an instruction to upgrade the user's room during their next hotel stay. At block 735, upon determining that the reward selected at block 725 is a refund for a previous purchase, POS device 301 sends an instruction to refund the previous purchase. For example, if the user selected a 5% discount on a previous purchase totaling $100, POS device 301 may send an instruction to server 120 to refund $5 to the account associated with contactless card 101.
[0063] Figure 8 An embodiment of an exemplary computing architecture 800 is illustrated, and the computing architecture 800 includes a computing system 802 that can be suitable for implementing various embodiments as described above. In various embodiments, the computing architecture 800 can include or be implemented as a part of an electronic device. In some embodiments, the computing architecture 800 can represent a system that implements one or more components of the system 100, for example. In some embodiments, the computing system 802 can represent, for example, a contactless card 101, a computing device 110, an authentication server 120, and / or a review platform 140 of the system 100. Similarly, the computing system 802 can represent a POS device 301. The embodiments are not limited in this context. More generally, the computing architecture 800 is configured to implement all logic, applications, systems, methods, devices, and functionality described herein with reference to Figures 1-9.
[0064] As used herein, the terms "system," "component," and "module" are intended to refer to a computer-related entity, whether hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by exemplary computing architecture 800. For example, a component can be, but is not limited to, a process running on a computer processor, a computer processor, a hard drive, multiple storage drives (of optical and / or magnetic storage media), an object, executable instructions, an execution thread, a program, and / or a computer. For example, both an application running on a server and the server can be components. One or more components can reside within a process and / or execution thread, and components can be localized on a single computer and / or distributed between two or more computers. Furthermore, components can be coupled to each other via various types of communication media to coordinate operations. Such coordination can involve a one-way or two-way exchange of information. For example, components can transmit information in the form of signals transmitted via a communication medium. Such information can be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, further embodiments may alternatively employ data messages. Such data messages can be sent over various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.
[0065] The computing system 802 includes various common computing elements, such as one or more processors, multi-core processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to implementation via the computing system 802.
[0066] like Figure 8As shown, computing system 802 includes processor 804, system memory 806, and system bus 808. Processor 804 can be any of a variety of commercially available processors, including, but not limited to, and processor; application, embedded, and security processors; and and Processor; IBM and Cell processor; Core Core(2) and Dual microprocessors, multi-core processors, and other multi-processor architectures may also be used as the processor 804 .
[0067] The system bus 808 provides an interface for system components, including, but not limited to, the system memory 806 to the processor 804. The system bus 808 may be any of several types of bus structures that may be further interconnected to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures. Interface adapters may be connected to the system bus 808 via a slot architecture. Example slot architectures may include, but are not limited to, Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), and the like.
[0068] The system memory 806 may include various types of computer-readable storage media in the form of one or more higher-speed memory units, such as read-only memory (ROM), random-access memory (RAM), dynamic RAM (DRAM), double-data-rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory (such as ferroelectric polymer memory), austenitic memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, device arrays (such as redundant array of independent disks (RAID) drives), solid-state memory devices (e.g., USB memory, solid-state drives (SSDs), and any other type of storage medium suitable for storing information. Figure 8In the illustrated embodiment shown, system memory 806 may include non-volatile memory 810 and / or volatile memory 812. A basic input / output system (BIOS) may be stored in non-volatile memory 810.
[0069] The computing system 802 may include various types of computer-readable storage media in the form of one or more slower memory units, including an internal (or external) hard disk drive (HDD) 814, a magnetic floppy disk drive (FDD) 816 that reads from or writes to a removable magnetic disk 818, and an optical drive 820 that reads from or writes to a removable optical disk 822 (e.g., a CD-ROM or DVD). The HDD 814, FDD 816, and optical drive 820 may be connected to the system bus 808 via an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. The HDD interface 824 for external drive implementations may include at least one or both of a universal serial bus (USB) and an IEEE 1394 interface technology. The computing system 802 is generally configured to implement all of the logic, systems, methods, devices, and functionality described herein with reference to Figures 1-9.
[0070] The drives and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-readable instructions, etc. For example, several program modules can be stored in the drives and memory units 810, 812, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836. In one embodiment, the one or more application programs 832, other program modules 834, and program data 836 can include, for example, various applications and / or components of the system 100, such as applet 103, private key 104, encrypted data 105, transaction log 106, review application 113, API 114, authentication application 123, account data 124, entity data 125, transaction data 126, review platform 140, and / or reviews 141.
[0071] A user can enter commands and information into the computing system 802 through one or more wire / wireless input devices, e.g., a keyboard 838 and a pointing device, such as a mouse 840. Other input devices can include a microphone, an infrared (IR) remote control, a radio-frequency (RF) remote control, a game pad, a stylus pen, a card reader, a dongle, a fingerprint reader, gloves, a graphic tablet, a joystick, a keyboard, a retina reader, a touch screen (e.g., capacitive, resistive, etc.), a trackball, a trackpad, a sensor, a stylus, etc. These and other input devices are often connected to the processing unit 804 through an input device interface 842 that is coupled to the system bus 808, but can be connected by other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, etc.
[0072] A monitor 844 or other type of display device is also connected to the system bus 808 via an interface, such as a video adaptor 846. The monitor 844 can be internal or external to the computing system 802. In addition to the monitor 844, a computer typically includes other peripheral output devices, such as speakers, printers, etc.
[0073] The computing system 802 can operate in a networked environment using logical connections to one or more remote computers, such as a remote computer 848. The remote computer 848 can be a workstation, a server computer, a router, a personal computer, portable computer, microprocessor-based entertainment appliance, a peer device or other common network node, and typically includes many or all of the elements described relative to the computing system 802, although, for purposes of brevity, only a memory / storage device 850 is illustrated. The logical connections depicted include wire / wireless connectivity to a local area network (LAN) 852 and / or larger networks, e.g., a wide area network (WAN) 854. Such LAN and WAN networking environments are commonplace in offices and companies, and facilitate enterprise-wide computer networks, such as intranets, all of which can connect to a global communications network, e.g., the Internet. In embodiments, the network 130 of FIG. 1 is one or more of the LAN 852 and the WAN 854.
[0074] When used in a LAN networking environment, the computing system 802 is connected to the LAN 852 through a wire / wireless communication network interface or adaptor 856. The adaptor 856 can facilitate wire / wireless communications to the LAN 852, which can further include a wireless access point disposed therein for communicating with the wireless functionality of the adaptor 856.
[0075] When used in a WAN networking environment, the computing system 802 can include a modem 858, or be connected to a communications server on the WAN 854, or have other means for establishing communications over the WAN 854, such as through the Internet. The modem 858, which can be internal or external to a wired and / or wireless device, is connected to the system bus 808 via the input device interface 842. In a networked environment, program modules described with respect to the computing system 802, or portions thereof, can be stored in the remote memory / storage device 850. It will be appreciated that the network connections shown are exemplary and other means of establishing a communications link between the computers may be used.
[0076] The computing system 802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operatively configured for wireless communications (e.g., IEEE 802.16 over-the-air modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth, among other technologies. TM Wireless technology. Therefore, communication can be a predefined structure like a conventional network, or simply a peer-to-peer communication between at least two devices. Wi-Fi networks use radio technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connections. Wi-Fi networks can be used to connect computers to each other, to the Internet, and to wired networks (which use IEEE 802.3 related media and functions).
[0077] Figure 9A The illustration illustrates a contactless card 101, which may include a payment card, such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 902, which is displayed on the front or back of the card 101. In some examples, the contactless card 101 is not related to a payment card and may include, but is not limited to, an identification card. In some examples, the payment card may include a dual-interface contactless payment card. The contactless card 101 may include a substrate 910, which may include a single layer or one or more laminated layers composed of plastic, metal, or other materials. Example substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, platinum, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card may otherwise conform to the ISO / IEC 14443 standard. However, it is understood that a contactless card 101 according to the present disclosure may have different characteristics, and the present disclosure does not require the contactless card to be implemented in a payment card.
[0078] The contactless card 101 may also include identification information 915 and contact pads 920, with the identification information 915 displayed on the front and / or back of the card. The contact pads 920 may be configured to establish contact with another communication device, such as a mobile device 90, a user device, a smartphone, a laptop, a desktop computer, or a tablet computer. The contactless card 101 may also include processing circuitry, an antenna, and a Figure 9A Other components not shown in the figure. These components can be placed behind the contact pads 920 or elsewhere on the substrate 910. The contactless card 101 can also include a magnetic stripe or magnetic tape that can be placed on the back of the card (in the Figure 9A not shown).
[0079] like Figure 9B As shown, contact pads 920 of contactless card 101 may include processing circuitry 925 for storing and processing information, the processing circuitry 925 including a microprocessor 930 and memory 102. It is understood that processing circuitry 925 may include additional components necessary to perform the functions described herein, including processors, memories, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware.
[0080] Memory 102 may be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and contactless card 101 may include one or more of these memories. Read-only memory may be factory-programmable to read-only or one-time programmable. One-time programmable memory provides the opportunity to write once and then read multiple times. Write-once / read-many memory can be programmed at a point in time after the memory chip has left the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can also be read multiple times after leaving the factory.
[0081] The memory 102 may be configured to store one or more applets 103, private keys 104, encrypted data 105, transaction logs 106, one or more review confirmations 108, and one or more customer (or user) identifiers (IDs) 907. The one or more applets 103 may include one or more software applications configured to execute on one or more contactless cards, such as Card applet. However, it is understood that applet 103 is not limited to the Java Card applet, but can be any software application operable on contactless card or other devices with limited memory. Customer ID 907 can comprise the unique alphanumeric identifier of the user assigned to contactless card 101, and this identifier can distinguish the user of contactless card and other contactless card users. In some examples, customer ID 907 can identify the customer and the account assigned to this customer, and can further identify the contactless card that is associated with the customer's account. In certain embodiments, applet 103 can use customer ID 907 to produce encrypted data 105 together with private key 104 as the input of cryptographic algorithm.
[0082] The processor and memory elements of the aforementioned exemplary embodiments are described with reference to the contact pads, but the present disclosure is not limited thereto. It is understood that these elements may be implemented external to the pad 920, or completely separate from it, or as further elements disposed within the contact pad 920 in addition to the processor 930 and memory 102.
[0083] In some examples, contactless card 101 may include one or more antennas 955. The one or more antennas 955 may be positioned within contactless card 101, surrounding processing circuitry 925 on contact pads 920. For example, the one or more antennas 955 may be integrated with processing circuitry 925, or the one or more antennas 955 may be used in conjunction with an external starting coil. As another example, the one or more antennas 955 may be external to contact pads 920 and processing circuitry 925.
[0084] In an embodiment, the coil of the contactless card 101 can act as the secondary of an air core transformer. The terminal can communicate with the contactless card 101 by cutting off power or amplitude modulation. The contactless card 101 can use the gap to infer data sent from the terminal when the contactless card is connected to a power source, and the power connection can be functionally maintained by one or more capacitors. The contactless card 101 can return communication by switching the load on the coil of the contactless card or load modulation. Load modulation can be detected in the coil of the terminal by interference. More generally, using the antenna 955, the processing circuit system 925 and / or the memory 102, the contactless card 101 provides a communication interface for communicating via NFC, Bluetooth and / or Wi-Fi communication.
[0085] As explained above, contactless card 101 can be built on smart card or other devices (such as JavaCard) with limited memory and can operate on software platform, and one or more applications or applet can be executed safely.Applet can be added to contactless card to provide the one-time password (OTP) of the multi-factor authentication (MFA) under the use case for various based on mobile applications.Applet can be configured to respond to one or more requests (such as near field data exchange request) from reader (such as mobile NFC reader (for example, the card reader 118 of device 110)), and generate NDEF message, this message comprises OTP that is encoded as NDEF text tag, that is safe on the password.
[0086] Various embodiments can be realized using hardware elements, software elements or the combination of the two.The example of hardware elements can include processors, microprocessors, circuits, circuit elements (for example, transistors, resistors, capacitors, inductors etc.), integrated circuits, application specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets etc.The example of software can include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, processes, software interfaces, application program interfaces (APIs), instruction sets, computing codes, computer codes, code segments, computer code segments, words, values, symbols or any combination thereof.Determine whether embodiments use hardware software and / or software elements to realize that can change according to any number of factors, such as desired computing rate, power level, heat resistance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed and other design or performance constraints.
[0087] One or more aspects of at least one embodiment may be implemented with representative instructions stored on a machine-readable medium, which represent various logics within a processor that, when read by a machine, cause the machine to make logic that performs the technology described herein. Such representations (referred to as "IP cores") may be stored on tangible machine-readable media and supplied to various customers or manufacturing facilities to be loaded into machines that make the logic or processor. Some embodiments may, for example, be implemented using a machine-readable medium or article that can store instructions or instruction sets that, if executed by a machine, can cause the machine to perform methods and / or operations according to an embodiment. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. The machine-readable medium or article may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disk read only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewritable (CD-RW), optical disk, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital versatile disks (DVDs), magnetic tape, magnetic cartridges, etc. The instructions may include any suitable code implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc.
[0088] The foregoing description of example embodiments has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the disclosure to the precise form disclosed. Many modifications and variations are possible in light of the present disclosure. It is intended that the scope of the present disclosure be limited not by this detailed description, but rather by the claims appended hereto. Future applications filed claiming priority to the present application may claim the disclosure in various ways and may generally include any combination of one or more limitations as variously disclosed or otherwise illustrated herein.
Claims
1. A method for verifying a review, comprising: receiving, by an application executing on a processor of the device, a request to post a review of an entity to a review platform; disabling, by the application, a presentation element of a graphical user interface (GUI) of the application; outputting, by the application, an instruction to tap a contactless card against the device to allow the request; receiving, by the application, encrypted data from the contactless card; sending, by the application, to an authentication server: (i) the encrypted data, (ii) an application indication of the application, and (iii) an entity identifier associated with the entity; receiving, by the application, from the authentication server an instruction directing the authentication server to: (i) decrypt the encrypted data, and (ii) determine that the contactless card is for use in making a purchase with an entity; allowing, by the application, a request to publish a review based on an indication received from the authentication server; receiving, by the application, input comprising a review of an entity; enabling, by the application, a submission element of a GUI based on an indication received from the authentication server; as well as The review is published to the review platform by the application based on the instruction received from the authentication server.
2. The method of claim 1 , further comprising, before allowing the request: receiving, from the contactless card, transaction data for one or more previous transactions in which payment information was provided using the contactless card; and A determination is made that the entity identifier is specified in transaction data of the one or more previous transactions, wherein the application allows the request based at least in part on the determination that the entity identifier is specified in transaction data of the one or more previous transactions.
3. The method according to claim 2, further comprising: identifying, by the application, an entity identifier for a second entity in transaction data relating to the one or more previous transactions; and An indication is generated, via the application output, of a review of the second entity.
4. The method according to claim 1, wherein The submit element, when enabled, is used to submit a comment for publication.
5. The method according to claim 4, wherein The application publishes the comment based on activation of a submit element of the GUI.
6. The method according to claim 1, further comprising: A review confirmation is sent to the contactless card via the application, the review confirmation specifying that the review has been posted to the review platform.
7. The method according to claim 6, further comprising: receiving, via the application, from the contactless card, a review confirmation that a specified review has been posted to the review platform; sending, by the application, a confirmation of the received review to a point-of-sale device associated with the entity, the review confirmation specifying that the review has been published to a review platform; and The application receives, from the point of sale device, an indication of a reward for at least one of: (i) the purchase, and (ii) a subsequent purchase based on the review confirmation.
8. The method according to claim 2, further comprising: receiving, by the application, a second request to publish a review of a second entity to the review platform; receiving, by the application, second encrypted data from the contactless card; sending, by the application, to the authentication server: (i) the second encrypted data, (ii) an application identifier of the application, and (iii) an entity identifier associated with the second entity; The application determines whether a time associated with the identified transaction exceeds a time limit. If the identified transaction is within the time limit, the application may confirm the verification review for the transaction. Otherwise, the application rejects the confirmation verification review for the transaction.
9. The method according to claim 8, wherein The application maintains a comment counter associated with the contactless card and may reject the comment for the transaction confirmation verification if the comment counter is incremented based on the current comment so that the counter exceeds a limit.
10. A device comprising: processor; and a memory storing instructions that, when executed by the processor, cause the processor to: receiving, by an application executing on the processor, a request to publish a review of an entity to a review platform; disabling, by the application, a presentation element of a graphical user interface (GUI) of the application; outputting, by the application, an instruction to tap a contactless card against the device to allow the request; receiving, by the application, encrypted data from the contactless card; sending, by the application, to an authentication server: (i) the encrypted data, (ii) an application indication of the application, and (iii) an entity identifier associated with the entity; receiving, by the application, from the authentication server an instruction directing the authentication server to: (i) decrypt the encrypted data, and (ii) determine that the contactless card is for use in making a purchase with an entity; allowing, by the application, a request to publish a review based on an indication received from the authentication server; receiving, by the application, input comprising a review of an entity; enabling, by the application, a submission element of a GUI based on an indication received from the authentication server; as well as The review is published to the review platform through the application based on the instruction received from the authentication server.
11. The apparatus of claim 10, the memory storing instructions that, when executed by the processor, cause the processor, before granting the request: receiving, from the contactless card, transaction data for one or more previous transactions in which payment information was provided using the contactless card; and A determination is made that the entity identifier is specified in transaction data of the one or more previous transactions, wherein the application allows the request based at least in part on the determination that the entity identifier is specified in transaction data of the one or more previous transactions.
12. The apparatus of claim 11 , the memory storing instructions that, when executed by the processor, cause the processor to: identifying, by the application, an entity identifier for a second entity in transaction data relating to the one or more previous transactions; and An indication is generated, via the application output, of a review of the second entity.
13. The apparatus according to claim 10, wherein The submit element, when enabled, is used to submit a comment for publication.
14. The apparatus according to claim 13, wherein The application publishes the comment based on activation of a submit element of the GUI.
15. The apparatus of claim 10, the memory storing instructions that, when executed by the processor, cause the processor to: sending, via the application, a review confirmation to the contactless card, the review confirmation specifying that the review has been posted to the review platform; receiving, via the application, from the contactless card, a review confirmation that a specified review has been posted to the review platform; sending, by the application, a confirmation of the received review to a point-of-sale device associated with the entity, the review confirmation specifying that the review has been published to a review platform; and An indication of a reward for at least one of: (i) the purchase, and (ii) a subsequent purchase is received from the point of sale device via the application based on review confirmation.
16. The apparatus of claim 11 , the memory storing instructions that, when executed by the processor, cause the processor to: receiving, by the application, a second request to publish a review of a second entity to the review platform; receiving, by the application, second encrypted data from the contactless card; sending, by the application, to the authentication server: (i) the second encrypted data, (ii) an application identifier of the application, and (iii) an entity identifier associated with the second entity; The application determines whether a time associated with the identified transaction exceeds a time limit. If the identified transaction is within the time limit, the application may confirm the transaction verification review. Otherwise, the application rejects the transaction confirmation verification review.
17. The apparatus according to claim 16, wherein The application maintains a comment counter associated with the contactless card and is capable of rejecting the comment for transaction confirmation verification if the comment counter is incremented based on the current comment such that the counter exceeds a limit.
18. A computer-readable storage medium comprising instructions that, when executed by a processor of a device, cause the processor to: receiving, by the application, a request to publish a review of an entity to a review platform; disabling, by the application, a presentation element of a graphical user interface (GUI) of the application; outputting, by the application, an instruction to tap a contactless card against the device to allow the request; receiving, by the application, encrypted data from the contactless card; sending, by the application, to an authentication server: (i) the encrypted data, (ii) an application indication of the application, and (iii) an entity identifier associated with the entity; receiving, by the application, from the authentication server an instruction directing the authentication server to: (i) decrypt the encrypted data, and (ii) determine that the contactless card is for use in making a purchase with an entity; allowing, by the application, a request to publish a review based on an indication received from the authentication server; receiving, by the application, input comprising a review of an entity; enabling, by the application, a submission element of a GUI based on an indication received from the authentication server; as well as The review is published to the review platform by the application based on the instruction received from the authentication server.
19. The computer-readable storage medium according to claim 18, wherein The instructions further cause the processor, before granting the request: receiving, from the contactless card, transaction data for one or more previous transactions in which payment information was provided using the contactless card; and A determination is made that the entity identifier is specified in transaction data of the one or more previous transactions, wherein the application allows the request based at least in part on the determination that the entity identifier is specified in transaction data of the one or more previous transactions.
20. The computer-readable storage medium of claim 19, wherein the instructions further cause the processor to: identifying, by the application, an entity identifier for a second entity in transaction data relating to the one or more previous transactions; and An indication is generated, via the application output, of a review of the second entity.
21. The computer-readable storage medium of claim 18, wherein: The submit element, when enabled, is used to submit a comment for publication.
22. The computer-readable storage medium of claim 21, wherein: The application publishes the comment based on activation of a submit element of the GUI.
23. The computer-readable storage medium of claim 18, wherein the instructions further cause the processor to: A review confirmation is sent to the contactless card via the application, the review confirmation specifying that the review has been posted to the review platform.
24. The computer-readable storage medium of claim 23, wherein the instructions further cause the processor to: receiving, via the application, from the contactless card, a review confirmation that a specified review has been posted to the review platform; sending, by the application, a confirmation of the received review to a point-of-sale device associated with the entity, the review confirmation specifying that the review has been published to a review platform; and An indication of a reward for at least one of: (i) the purchase, and (ii) a subsequent purchase is received from the point of sale device via the application based on review confirmation.
25. The computer-readable storage medium of claim 19, wherein the instructions further cause the processor to: receiving, by the application, a second request to publish a review of a second entity to the review platform; receiving, by the application, second encrypted data from the contactless card; sending, by the application, to the authentication server: (i) the second encrypted data, (ii) an application identifier of the application, and (iii) an entity identifier associated with a second entity; The application determines whether a time associated with the identified transaction exceeds a time limit. If the identified transaction is within the time limit, the application may confirm the verification review for the transaction. Otherwise, the application rejects the confirmation verification review for the transaction.
Citation Information
Patent Citations
Systems and methods for cryptographic authentication of contactless cards
US10581611B1
Payment Card with Integrated Chip
US20130041823A1
System, method, and article for mobile payment and personal identification
US20160283946A1