Devices using contactless cards and methods for generating virtual card numbers
Through contactless card authentication and near-field communication, users can set personalized restrictions on virtual card numbers, solving the problem of inflexible restrictions in existing technologies and enabling secure and convenient use of virtual card numbers.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2020-11-23
- Publication Date
- 2026-04-03
AI Technical Summary
Existing virtual card number restrictions are inflexible and lack personalization, making it difficult to configure secure and flexible restrictions based on the recipient.
With contactless card authentication, users can personalize the restrictions on virtual card numbers, such as merchant, amount, time period and location restrictions, and write the card number to a blank card or send it to the recipient's device via near field communication to ensure security.
It enables flexible and personalized restriction settings for virtual card numbers, improves security and ease of use, ensures that restrictions are set by authorized users, and is suitable for various point-of-sale systems.
Smart Images

Figure CN114846495B_ABST
Abstract
Description
[0001] Related applications
[0002] This application claims priority to U.S. Patent Application 16 / 726,210, filed December 23, 2019, entitled "Card Issuance with Restricted Virtual Numbers". The contents of the above application are incorporated herein by reference in their entirety. Background Technology
[0003] A virtual credit card is a virtual credit card number typically used for online shopping and one-off transactions. A virtual card number can be a randomly generated number associated with a physical credit card. Depending on the issuing institution, a maximum fee can be set for the virtual number, and in some cases, a validity period of up to one year from the date of creation can be set. To online merchants, a virtual card number looks no different from any other credit card.
[0004] While card issuers can set basic restrictions associated with virtual card numbers, such as maximum charge amount and validity period, it is necessary for the issuing user to set specific, personalized restrictions for the recipient in a secure manner. Summary of the Invention
[0005] Various embodiments involve applying one or more restrictions to a virtual card number via contactless card authentication and generating the card number for use by a recipient. The one or more restrictions can be specifically personalized for the recipient and may include, for example, merchant restrictions, amount restrictions, time period restrictions, or location restrictions. The generated virtual card number, along with the applied one or more restrictions, can be used in various ways, such as writing the number to a blank card, sending the number directly to the recipient's computing device, etc., all via near-field communication. Attached Figure Description
[0006] Figure 1A An example data transmission system according to one or more embodiments is shown.
[0007] Figure 1B A sequence diagram for providing authenticated access is shown according to one or more embodiments.
[0008] Figure 2 An example system using a contactless card is shown according to one or more embodiments.
[0009] Figure 3A An example contactless card according to one or more embodiments is shown.
[0010] Figure 3B An example contact pad for a contactless card according to one or more embodiments is shown.
[0011] Figure 4An example process for generating virtual card numbers and associated restrictions according to one or more embodiments is shown.
[0012] Figure 5 An example flow of one-touch authentication according to one or more embodiments is shown.
[0013] Figure 6 An example flow is shown for writing a virtual card number to a blank card via a user computing device and using the card via a recipient computing device, according to one or more embodiments.
[0014] Figure 7 An example process for transferring a virtual card number between two computing devices is shown according to one or more embodiments.
[0015] Figure 8 Example card applets and applet communication according to one or more embodiments are shown.
[0016] Figure 9 An example flowchart according to one or more embodiments is shown. Detailed Implementation
[0017] Various embodiments generally involve generating virtual card numbers in a personalized and secure manner and applying one or more restrictions to the card numbers. In examples, the issuing user can set personalized restrictions for the recipient of the virtual card number, such as merchant restrictions, amount restrictions, time period restrictions, location restrictions, etc. For example, a user (e.g., a parent) might want to leave $30 for a nanny for dinner, but the $30 must be spent at a specific pizza restaurant. In another case, a user (e.g., a business owner) might want to give an employee $5,000 to buy supplies, but the payment is limited to two hours and must be made at a specific vendor.
[0018] To create a virtual card number with one or more restrictions, a user can open a software application (e.g., a banking application) and select an icon for generating the virtual card number. According to an embodiment, the user can use the software application to select one or more restrictions to apply to the card number. The user can then perform one-touch authentication (which may also be referred to herein as "one-touch contactless card authentication") via a contactless card belonging to the user to finally determine and apply the selected restrictions and generate the virtual card number.
[0019] In the example, when generating a virtual card number, the number (with selected one or more application restrictions) can be written onto a blank unlock card via a software application and activated for use at any point-of-sale system. According to a further embodiment, the virtual card number can be sent from a first computing device to a second computing device, for example, from a user computing device to a recipient computing device. The first and second computing devices can be near-field communication (NFC) enabled devices, and the virtual card number can be sent via NFC.
[0020] As will be further described below, one-touch contactless card authentication can be a highly secure way to verify a user's identity, ensuring, for example, that restrictions are actually set by the user and not a fraudster. Furthermore, since contactless cards are often used as payment tools to "fund" or top up virtual card numbers, one-touch authentication ensures that the user is actually the one who authorized the creation and top-up of the virtual card number.
[0021] According to an embodiment, one-touch contactless card authentication may involve a user placing a contactless card near a designated area of a user's computing device (e.g., a smartphone), tapping the contactless card against that designated area, or bringing the contactless card close to that designated area. The user's computing device may detect the contactless card via Near Field Communication (NFC) and receive one or more PINs from the contactless card. Information contained in the PIN, which identifies the true owner of the contactless card, can be compared or matched with the relevant authentication information of the user logged into the banking application. If they match, successful user authentication can be confirmed.
[0022] As mentioned above, in previous solutions, the restrictions imposed on virtual card numbers were inflexible and impersonal. The embodiments and examples described herein overcome the shortcomings of previous solutions and are superior to them because users can easily and conveniently personalize and customize one or more restrictions on virtual card numbers based on the recipient of the number. Furthermore, users can write virtual card numbers onto blank unlocked cards via their computing devices and activate the cards for use by the recipient at various point-of-sale systems. Additionally, users can advantageously transmit virtual card numbers from their computing devices to the recipient's computing devices via near-field communication. In summary, the application of one or more restrictions and the generation of virtual card numbers can be performed in a highly secure and reliable manner via one-touch contactless card authentication.
[0023] Referring now to the accompanying drawings, wherein the same reference numerals are used throughout to refer to the same elements. In the following description, numerous specific details are set forth for purposes of explanation in order to provide a thorough understanding thereof. However, it will be apparent that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form for ease of description. It is intended to cover all modifications, equivalents, and substitutions within the scope of the claims.
[0024] Figure 1A An example data transmission system according to one or more embodiments is illustrated. As discussed further below, system 100 may include a contactless card 105, a client device 110, a network 115, and a server 120. Although Figure 1A A single instance of the component is shown, but system 100 may include any number of components.
[0025] System 100 may include one or more contactless cards 105, which will be referred to below. Figure 3A and Figure 3B To explain further. In some embodiments, the contactless card 105 may, in this example, utilize NFC to communicate wirelessly with the client device 110.
[0026] System 100 may include client device 110, which may be a network-enabled computer. As mentioned herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, network equipment, personal computers, workstations, telephones, smartphones, handheld PCs, personal digital assistants, thin clients, thick clients, internet browsers, or other devices. Client device 110 may also be a mobile computing device, such as one from… iPhone, iPod, iPad, or running Apple software Any other suitable device running the operating system, or running Microsoft... Any device running the Mobile operating system, or running Google... Any device with an operating system and / or any other suitable mobile computing device, such as a smartphone, tablet, or similar wearable mobile device.
[0027] Client device 110 may include a processor and memory, and it is understood that the processing circuitry may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, to perform the functions described herein as necessary. Client device 110 may also include display and input devices. The display can be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any devices for inputting information to the user device that are usable and supported by the user device, such as touchscreens, keyboards, mice, cursor control devices, touchscreens, microphones, digital cameras, video recorders, or camcorders. These devices can be used to input information and interact with the software and other devices described herein.
[0028] In some examples, the client device 110 of system 100 may execute one or more applications, such as software applications, which are capable of communicating over a network with one or more components of system 100 and sending and / or receiving data.
[0029] Client device 110 can communicate with one or more servers 120 via one or more networks 115 and can perform operations in a corresponding front-end to back-end pair with server 120. Client device 110 can, for example, issue one or more requests to server 120 through a mobile device application running on client device 110. The one or more requests can be associated with retrieving data from server 120. Server 120 can receive one or more requests from client device 110. Based on one or more requests from client device 110, server 120 can be configured to retrieve the requested data from one or more databases (not shown). Based on the received requested data from one or more databases, server 120 can be configured to send the received data to client device 110 in response to one or more requests.
[0030] System 100 may include one or more networks 115. In some examples, network 115 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect client devices 110 to server 120. For example, network 115 may include one or more of the following: fiber optic network, passive optical network, cable network, Internet network, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, etc.
[0031] Furthermore, network 115 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Additionally, network 115 may support Internet networks, wireless communication networks, cellular networks, and any combination thereof. Network 115 may also include one network or any number of networks of the above exemplary types, operating as independent networks or cooperating with each other. Network 115 may utilize one or more protocols of one or more network elements communicatively coupled thereto. Network 115 may be converted to or converted from other protocols to one or more protocols of network devices. Although network 115 is shown as a single network, it should be understood that, according to one or more examples, network 115 may be multiple interconnected networks, such as the Internet, a service provider's network, a cable television network, a corporate network (e.g., a credit card association network), and a home network.
[0032] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to memory. Server 120 may be configured as a central system, server, or platform to control and invoke various data at different times to perform multiple workflow actions. Server 120 may be configured to connect to one or more databases. Server 120 may connect to at least one client device 110.
[0033] Figure 1B An example timing diagram for providing authenticated access is shown according to one or more embodiments. The diagram may include a contactless card 105 and a client device 110, which may include an application 122 and a processor 124. Figure 1B You can refer to, for example Figure 1A Similar components are shown.
[0034] In step 102, application 122 communicates with contactless card 105 (e.g., after bringing it close to contactless card 105). Communication between application 122 and contactless card 105 may involve contactless card 105 being sufficiently close to a card reader (not shown) of client device 110 to enable NFC data transfer between application 122 and contactless card 105.
[0035] In step 104, after communication is established between the client device 110 and the contactless card 105, the contactless card 105 generates a Message Authentication Code (MAC) password. In some embodiments, this can occur when the application 122 reads the contactless card 105. Specifically, this can occur when reading (e.g., NFC reading) a Near Field Data Exchange (NDEF) tag that can be created according to the NFC Data Exchange Format.
[0036] For example, a reader such as application 122 can send messages, such as a mini-program selection message, with the mini-program ID of the mini-program that generated the NDEF. Upon confirmation of selection, a sequence of selected file messages can be sent, followed by a read file message. For example, this sequence could include "Select function file," "Read function file," and "Select NDEF file." At this time, a counter value maintained by contactless card 105 can be updated or incremented, followed by "Read NDEF file." A message can then be generated, which may include a header and a shared secret. A session key can then be generated. A MAC cipher can be created from the message, which may include a header and a shared secret. The MAC cipher can then be concatenated with one or more random data blocks, and the MAC cipher and random number (RND) can be encrypted using the session key. Afterward, the ciphertext and header can be concatenated, encoded into ASCII hexadecimal, and returned in NDEF message format (in response to the "Read NDEF file" message).
[0037] In some embodiments, the MAC cipher may be transmitted as an NDEF tag, and in other examples, the MAC cipher may be included along with a Uniform Resource Indicator (e.g., as a format string).
[0038] In some examples, application 122 can be configured to send a request to contactless card 105 that includes instructions to generate a MAC password.
[0039] In step 106, the contactless card 105 sends the MAC password to the application 122. In some examples, the MAC password transmission occurs via NFC; however, the invention is not limited thereto. In other examples, the communication may occur via Bluetooth, Wi-Fi, or other wireless data communication methods.
[0040] In step 108, application 122 transmits the MAC password to processor 124. In step 112, processor 124 verifies the MAC password according to instructions from application 122. For example, the MAC password can be verified as described below.
[0041] In some examples, MAC password verification can be performed by a device other than client device 110, such as server 120 that communicates with client device 110 (e.g., Figure 1A (As shown). For example, processor 124 can output a MAC password to transmit to server 120, which can verify the MAC password.
[0042] In some examples, a MAC cipher can be used as a digital signature for verification. Other digital signature algorithms, such as public-key asymmetric algorithms (e.g., the Digital Signature Algorithm and RSA algorithm), or zero-knowledge protocols, can be used to perform this verification.
[0043] It will be understood that in some examples, contactless card 105 can initiate communication after the contactless card is brought close to client device 110. For example, contactless card 105 can send a message to client device 110, such as indicating that communication has been established. Thereafter, application 122 of client device 110 can continue to communicate with the contactless card in step 102, as described above.
[0044] Figure 2 An example system 200 using a contactless card is shown. System 200 may include a contactless card 205, one or more client devices 210, a network 215, servers 220 and 225, one or more hardware security modules 230, and a database 235. Although Figure 2 A single instance of the component is shown, but system 200 may include any number of components.
[0045] System 200 may include one or more contactless cards 205, which are described below in relation to Figure 3A and Figure 3BFurther explanation. In some examples, the contactless card 205 can wirelessly communicate with the client device 210, such as via NFC communication. For example, the contactless card 205 may include one or more chips, such as an RFID chip, configured to communicate via NFC or other short-range protocols. In other embodiments, the contactless card 205 may communicate with the client device 210 in other ways, including but not limited to Bluetooth, satellite, Wi-Fi, wired communication, and / or any combination of wireless and wired connections. According to some embodiments, the contactless card 205 may be configured to communicate via NFC with the reader 213 of the client device 210 (also referred to herein as an NFC reader, NFC card reader, or reader) when the contactless card 205 is within range of the reader 213. In other examples, communication with the contactless card 205 may be accomplished through a physical interface, such as a Universal Serial Bus interface or a card swipe interface.
[0046] System 200 may include client device 210, which may be a network-enabled computer. As mentioned herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, network equipment, personal computers, workstations, mobile devices, telephones, handheld PCs, personal digital assistants, thin clients, thick clients, internet browsers, or other devices. One or more client devices 210 may also be mobile computing devices; for example, mobile devices may include devices from… iPhone, iPod, iPad, or running Apple software Any other mobile device running the operating system, or running Microsoft... Any device running the Mobile operating system, or running Google... Any device with an operating system and / or any other smartphone or similar wearable mobile device. In some examples, client device 210 can be associated with reference to... Figure 1A or Figure 1B The client device described is the same as or similar to 110.
[0047] Client device 210 can communicate with one or more servers 220 and 225 via one or more networks 215. Client device 210 can, for example, send one or more requests to one or more servers 220 and 225 via application 211 executing on client device 210. The one or more requests can be associated with retrieving data from one or more servers 220 and 225. Servers 220 and 225 can receive one or more requests from client device 210. Based on the one or more requests from client device 210, one or more servers 220 and 225 can be configured to retrieve the requested data from one or more databases 235. Based on the requested data received from one or more databases 235, one or more servers 220 and 225 can be configured to send the received data to client device 210 in response to the one or more requests.
[0048] System 200 may include one or more Hardware Security Modules (HSMs) 230. For example, one or more HSMs 230 may be configured to perform one or more cryptographic operations as disclosed herein. In some examples, one or more HSMs 230 may be configured as dedicated security devices configured to perform one or more cryptographic operations. HSMs 230 may be configured such that keys are never disclosed outside of HSMs 230, but are maintained within HSMs 230. For example, one or more HSMs 230 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 230 may be included within servers 220 and 225, or may communicate with servers 220 and 225.
[0049] System 200 may include one or more networks 215. In some examples, network 215 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect client devices 210 to servers 220 and / or 225. For example, network 215 may include one or more of the following: fiber optic networks, passive optical networks, cable networks, cellular networks, Internet networks, satellite networks, wireless LANs, Global System for Mobile Communications (GSMO), personal communication services, personal area networks (PANs), wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time-division multiplexing-based systems, code-division multiple access-based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n, and 802.11g, Bluetooth, NFC, RFID, Wi-Fi, and / or any combination thereof. As a non-limiting example, communication from contactless card 205 and client device 210 may include NFC communication, cellular networks between client device 210 and the operator, and the Internet between the operator and the backend.
[0050] Furthermore, network 215 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, local area networks, or global networks such as the Internet. Additionally, network 215 may support Internet networks, wireless communication networks, cellular networks, and any combination thereof. Network 215 may also include one network or any number of networks of the above exemplary types, operating as independent networks or cooperating with each other. Network 215 may utilize one or more protocols of one or more network elements communicatively coupled thereto. Network 215 may be converted to or converted from other protocols to one or more protocols of network devices. Although network 215 is shown as a single network, it should be understood that, depending on one or more examples, network 215 may include multiple interconnected networks, such as the Internet, service provider networks, cable television networks, corporate networks (e.g., credit card association networks), and home networks.
[0051] In various examples according to this disclosure, the client device 210 of system 200 may execute one or more applications 211 and includes one or more processors 212 and one or more card readers 213. For example, one or more applications 211, such as software applications, may be configured to, for example, enable network communication with one or more components of system 200 and to send and / or receive data. It should be understood that, although... Figure 2Only a single instance of the components of client device 210 is shown, but any number of devices 210 can be used. Reader 213 can be configured to read from and / or communicate with contactless card 205. In conjunction with one or more applications 211, reader 213 can communicate with contactless card 205. In this example, reader 213 may include circuitry or circuit components, such as an NFC reader coil, which generates a magnetic field to allow communication between client device 210 and contactless card 205.
[0052] Application 211 of any client device 210 can communicate with contactless card 205 using short-range wireless communication (e.g., NFC). Application 211 can be configured to interface with card reader 213 of client device 210, which is configured to communicate with contactless card 205. It should be noted that those skilled in the art will understand that a distance of less than 20 cm is consistent with the range of NFC.
[0053] In some embodiments, application 211 communicates with contactless card 205 via an associated reader (e.g., card reader 213).
[0054] In some embodiments, card activation can occur without user authentication. For example, contactless card 205 can communicate with application 211 via NFC through card reader 213 of client device 210. This communication (e.g., tapping the card near card reader 213 of client device 210) allows application 211 to read the data associated with the card and perform activation. In some cases, a tap can activate or launch application 211, and then initiate one or more actions or communication with account server 225 to activate the card for subsequent use. In some cases, if application 211 is not installed on client device 210, tapping the card near card reader 213 can initiate the download of application 211 (e.g., navigating to an application download page). After installation, tapping the card can activate or launch application 211, and then initiate (e.g., via application or other backend communication) card activation. Once activated, the card can be used for various transactions, including commercial transactions.
[0055] According to some embodiments, the contactless card 205 may include a virtual payment card. In those embodiments, the application 211 can retrieve information associated with the contactless card 205 by accessing a digital wallet implemented on the client device 210, wherein the digital wallet includes the virtual payment card. In some examples, the virtual payment card data may include one or more statically or dynamically generated virtual card numbers.
[0056] Server 220 may include a web server communicating with database 235. Server 225 may include an account server. In some examples, server 220 may be configured to verify one or more credentials from contactless card 205 and / or client device 210 by comparing them with one or more credentials in database 235. Server 225 may be configured to authorize one or more requests from contactless card 205 and / or client device 210, such as payments and transactions.
[0057] Figure 3A One or more contactless cards 300 are shown, which may include payment cards, such as credit cards, debit cards, or gift cards, issued by a service provider 305 displayed on the front or back of the card 300. In some embodiments, the contactless card 300 is independent of the payment card and may include, but is not limited to, an identity card. In some embodiments, the payment card may include a dual-interface contactless payment card. The contactless card 300 may include a substrate 310, which may include a single layer or one or more laminates made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium oxide, palladium, gold, carbon, paper, and biodegradable materials. In some embodiments, the contactless card 300 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card may additionally conform to the ISO / IEC 14443 standard. However, it is understood that the contactless card 300 according to this disclosure may have different characteristics, and this disclosure does not require the implementation of a contactless card in a payment card.
[0058] The contactless card 300 may also include identification information 315 displayed on the front and / or back of the card and a contact pad 320. The contact pad 320 can be configured to establish a connection with another communication device, such as a user equipment, smartphone, laptop, desktop computer, or tablet. The contactless card 300 may also include processing circuitry, an antenna, and... Figure 3A Other components not shown. These components may be located behind the contact pad 320 or elsewhere on the substrate 310. The contactless card 300 may also include a magnetic stripe or magnetic tape, which may be located on the back of the card. Figure 3A (Not shown in the image).
[0059] like Figure 3B As shown, Figure 3AContact pad 320 may include processing circuitry 325 for storing and processing information, including microprocessor 330 and memory 335. It should be understood that processing circuitry 325 may include additional components, including a processor, memory, error and parity / CRC checker, data encoder, anti-collision algorithm, controller, command decoder, security primitives, and tamper-proof hardware, to perform the functions described herein.
[0060] Memory 335 can be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and contactless card 300 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once / read-many memory can be programmed at some point after the memory chip leaves the factory. Once the memory is programmed, it may not be overwritten, but it may be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times.
[0061] The memory 335 can be configured to store one or more applets 340, one or more counters 345, one or more diversity keys 347, and a customer identifier 350. The one or more applets 340 may include one or more software applications configured to execute on one or more contactless cards, such as a Java Card applet. However, it should be understood that the applet 340 is not limited to... The Card app can be any software application that operates on a contactless card or other device with limited memory. One or more counters 345 may include a digital counter sufficient to store integers. As further described below, one or more diversity keys 347 may be used to encrypt various information, such as information about a user or customer (e.g., customer identifier 450), to generate passwords that may be sent, for example, to a mobile device for at least one authentication purpose. The customer identifier 350 may include a unique alphanumeric identifier assigned to a user of the contactless card 300, and this identifier may distinguish the user of the contactless card from other contactless card users. In some embodiments, the customer identifier 350 may identify a customer and the account assigned to that customer, and may further identify the contactless card associated with the customer's account.
[0062] The processor and memory elements of the foregoing exemplary embodiments are described with reference to the contact pad, but the invention is not limited thereto. It should be understood that these elements may be implemented outside of or completely separated from the contact pad 320, or may be additional elements besides the processor 330 and memory 335 elements located within the contact pad 320.
[0063] In some embodiments, the contactless card 300 may include one or more antennas 355. The one or more antennas 355 may be positioned within the contactless card 300 and around the processing circuitry 325 of the contact pad 320. For example, the one or more antennas 355 may be integrated with the processing circuitry 325, and the one or more antennas 355 may be used in conjunction with an external boost coil. As another example, the one or more antennas 355 may be external to the contact pad 320 and the processing circuitry 325.
[0064] In one embodiment, the coil of the contactless card 300 can act as the secondary winding of an air-core transformer. The terminal can communicate with the contactless card 300 by disconnecting the power supply or by amplitude modulation. The contactless card 300 can infer data transmitted from the terminal using gaps in the power connection of the contactless card, which can be functionally maintained by one or more capacitors. The contactless card 300 can communicate back by switching the load on the coil of the contactless card or by load modulation. Load modulation is detected in the terminal coil by interference.
[0065] As described above, the contactless card 300 can be built on a software platform that operates on smart cards or other devices with limited memory, such as JavaCard, and one or more applications or applets can be executed securely first. Applets can be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The appletter can be configured to respond to one or more requests from a reader (e.g., an NFC reader), such as a near-field data exchange request, and generate an NDEF message that includes an encrypted secure OTP encoded as an NDEF text tag.
[0066] In the example, when ready to send data (e.g., to a mobile device, to a server, etc.), the contactless card 300 may increment the counter value of one or more counters 345. The contactless card 300 can then provide a master key (which may be a unique key stored on the card 300) and the counter value as input to a cryptographic algorithm that produces a diversification key as output, which may be one of the diversification keys 347. It should be understood that the master key and the counter value are also stored in the memory of the device or component receiving data from the contactless card 300 so that the data can be decrypted using the diversification key used by the card to encrypt the transmitted data. The cryptographic algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cryptographic message authentication code (CMAC) algorithms, etc. Non-limiting examples of cryptographic algorithms may include symmetric encryption algorithms such as 3DES or AES128; symmetric HMAC algorithms such as HMAC-SHA-256; and symmetric CMAC algorithms such as AES-CMAC. The contactless card 300 can then use a multivariate key to encrypt data (e.g., customer identifier 350 and any other data), the multivariate key taking the form of one or more passwords that can be sent to a mobile device, for example as an NFC Data Exchange Format (NDEF) message. The contactless card 300 can then send the encrypted data (e.g., the password) to the mobile device, which can then use the multivariate key (e.g., a multivariate key generated by the mobile device using a counter value and a master key stored in its memory) to decrypt the password.
[0067] Figure 4 An example flow 400 for generating a virtual card number and associated restrictions according to one or more embodiments is illustrated. A user can open a banking application 402 (which may also be referred to herein as a "banking application") using a mobile computing device. As shown, the banking application 402 may at least display a welcome screen and an icon 406 for login. The user can log in to their account by entering a username and password, or can gain account access by any other suitable means, such as tapping the user's contactless card on the mobile computing device. It will be understood that login can be performed by tapping the user's contactless card and this operation can be performed in a manner similar to a one-touch authentication process, which will be further described below. It will also be understood that the banking application can be any software application, such as a mobile-based application, a native application, a web application, or a web browser.
[0068] After logging into a user's account, the banking application 402 can display and allow the user to select various account-related tasks, such as checking account balances, transferring funds between accounts, paying bills, and generating a virtual card number, as shown in icon 408. The user can select icon 408, as highlighted in the box, to generate a virtual card number and one or more associated restrictions. In some examples, if the recipient is also a bank customer, the user can also enter and identify the recipient of the virtual card number. It will be understood that the virtual card number can be topped up, funded, or linked to a user account that can be associated with the user's contactless card. In the examples, the user account can be a money account, checking account, credit card account, debit card account, digital wallet account, cryptocurrency account, etc.
[0069] As further shown, the banking application 402 can display possible restriction options 410. For example, the user can select the "Time" icon to set various types of time-related restrictions for the virtual card number, such as the validity period, the time period during which the virtual card number can be used, the specific date range within which the number will be activated, etc. The user can also select the "Merchant" icon, which can be used to set any type of merchant-related restriction, such as restricting the use of the virtual card number to specific stores, restaurants, suppliers, etc. In addition, the user can select the "Location" icon, which restricts the use of the virtual card number to a specific geographic location, such as a specific postal code, city, town, state, etc. Furthermore, as shown by the icons at the bottom, the "Amount" icon can be selected to set amount-related restrictions, such as reducing the currency amount to precise US dollars and cents (or any other currency) values. It will be understood that when the user selects any of the displayed restriction options 410, the user can manually enter the restriction and / or select pre-selected or pre-selected restrictions. Advantageously, in this way, the user can set one or more restrictions in a more personalized, flexible, and recipient-specific manner, which provides the user with more control over the virtual card number.
[0070] In some examples, the banking application 402 can make restriction recommendations for the user based on data related to the user and, where applicable, data related to the recipient. For instance, if a user has only a certain amount of money in their account and wants to use that money to top up or fund a virtual card number, an amount limit of no more than the available funds in the user's account can be recommended. In another instance, if the recipient is also a bank customer, financial data associated with the recipient can be analyzed to determine, for example, what kind of food the recipient prefers or the restaurants the user frequents, to recommend merchant or location restrictions.
[0071] In one example of restrictions, a user can generate a virtual card number for their daughter to use when dining with her friends at a restaurant on Main Street. The user can set various restrictions on the virtual card number: at least a merchant restriction of Main Street, a spending limit of 40, and a time restriction of three hours. As shown in the dashed box, the banking application 402 can display all selected restrictions and request the user to confirm the information is correct. If necessary, the user can modify the restrictions. After confirming the restrictions are correct, the user can select icon 412 to perform one-touch contactless card authentication to generate the virtual card number. In some examples, the one-touch authentication process can begin automatically after the user confirms the restrictions.
[0072] Figure 5 An example flow 500 for one-touch contactless card authentication according to one or more embodiments is illustrated. As described above, the example one-touch authentication flow 600 can, for example, be initiated when a user selects or presses a button to generate a card with... Figure 4 The selected virtual card number icon 412 is shown as the start time.
[0073] As shown in the figure, banking application 502 (which may be similar to or the same as banking application 402) may display a one-touch introductory screen 512 and relevant background information to enable the user to perform one-touch authentication. For example, the background information indicates that the user's contactless card has technology that can be used to perform operations requiring enhanced security, and further indicates that the card can be placed flat on the screen of the computing device to continue the authentication process. The user can select or press the "OK, understand" icon to continue.
[0074] In the example, when the user selects or presses the "OK, understand" icon, the banking application 502 can then display a designated area outlined by a dotted box, in which the user can place or tap the contactless card. It will be understood that the contactless card can be similar to or the same as the contactless card 300 described above. As mentioned above, it will also be understood that the contactless card used by the user for one-touch authentication can be a financial instrument used for "top-up" or "funding" a virtual card number.
[0075] Additionally, a one-touch authentication instruction 514 may be displayed, or alternatively, an icon or link to the one-touch instruction 514 may be provided. Instruction 514 may include at least step-by-step guidance for performing one-touch authentication. For example, the user may be instructed to select or press the "Read My Card" icon, and then place and tap the contactless card within the guide dotted lines of the "Place Card Here" box. When the "Read My Card" icon is pressed, the banking application 502 may further display an indication that the user's contactless card is ready to be scanned. In some examples, if the computing device cannot read the contactless card via NFC, the banking application 502 may instruct the user to retry the card scan. It will be understood that the contactless card can be placed anywhere on the user's computing device, such as the back or anywhere near the NFC reader, and not just the front of the device.
[0076] According to an embodiment, when a user's computing device detects a contactless card via NFC, the computing device can receive one or more passwords from the contactless card. It will be understood that a password can broadly refer to any encrypted text, data, or information. It will also be understood that one or more passwords can be received as an NFC Data Exchange Format (NDEF) message.
[0077] In the example, one or more received passwords may contain information that identifies the user or other relevant information indicating that the card belongs to a specific user. For example, card user information can be any type of data or information (e.g., ID number, customer number, etc.) that associates a contactless card with a user, which may be created or established when the contactless card is created for the user and / or at the back-end system when the user registers or applies to contactless services. The information contained in one or more received passwords can then be matched or compared with the user's relevant authentication information to verify the user's identity. Authentication information is any type of data or information (e.g., ID number, customer number, etc.) that identifies the user logged into the banking application.
[0078] In one example, the banking application 502 can be configured to use at least one key (e.g., a private key, a decryption key, or a key corresponding to a specific encryption-decryption scheme) to decrypt one or more PINs received from a contactless card. The banking application 502 can securely access or receive user-related authentication information from one or more remote computing devices (e.g., a back-end server). The authentication information may contain at least an identifier or any information indicating the identity of the user logged into the banking application 502. The banking application 502 can then determine whether the received authentication information matches the decrypted PIN information received from the contactless card to verify that the contactless card actually belongs to the user and / or verify that the user is indeed as claimed by the user.
[0079] In another example, banking application 502 may receive one or more PINs from a contactless card and send them to one or more remote computing devices, which may be secure backend servers, to perform PIN decryption and determine whether the information contained in the one or more PINs matches the user's associated authentication information. The one or more remote computing devices may then send an instruction or confirmation of user authentication to banking application 502. At least in this respect, most (if not all) of the authentication process can be performed at one or more secure remote computing devices, which may be advantageous in certain applications or use cases.
[0080] After successful user identity verification and authentication, the bank application 502 can display an indication that the contactless card has been read and the user's identity has been successfully verified. The user can then select or press the "Continue" icon, which allows the bank application 502 to generate a virtual card number with one or more restrictions.
[0081] In some examples, if, for instance, a virtual card number is sent to a third-party wallet (e.g., the recipient's third-party wallet), the banking application 502 may request the user's permission to share user-related data with the third-party service (e.g., the third-party wallet). User-related data may include the user's first name, middle name, last name, billing address, email address, phone number, card number, card expiration information, etc. Furthermore, in additional examples, the user is prompted to accept one or more terms and / or conditions related to forwarding the virtual card number to the third-party wallet. As shown, the user can select or press the "Accept" icon to continue. Afterward, the banking application 502 can generate a virtual card number with one or more application restrictions and prepare it for the recipient's use.
[0082] Although Figure 4 and Figure 5 The illustration shows a one-touch contactless card authentication process performed after the user selects one or more restrictions to apply to a virtual card number. However, in a further embodiment, the one-touch authentication process can be performed before the user selects restrictions. For example, a user might open a banking application and select an icon to generate a virtual card number. In this case, the user might be prompted to perform one-touch authentication before selecting restrictions and generating the virtual card number.
[0083] Figure 6An example flow 600 is illustrated, according to one or more embodiments, of writing a virtual card number to a blank card via a user computing device 601 and using the card via a recipient computing device 611. It will be understood that the user computing device 601 and the recipient computing device 611 can be any type of NFC-enabled or NFC-compatible device. After the user computing device 601 generates a virtual card number with one or more restrictions according to the above flow and / or procedure, the user can write the virtual card number (along with the associated restrictions) to an NFC-enabled blank unlock card.
[0084] As shown in the figure, the banking application 602 (which may also be similar to or identical to the banking applications 402 and 502 described above) may display an introductory screen and instructions or information regarding the writing process. For example, application 602 may instruct the writing of the generated virtual card number onto a blank card by placing the blank card within the guide dotted lines on the next screen. It will be understood that the blank card may be an NFC-enabled blank unlock card, which allows the secure reception of the virtual card number and associated restriction information from the user computing device 601 via near-field communication.
[0085] As further shown, the banking application 602 can display guide lines, allowing the user to place a blank card near or on the screen (or anywhere near the NFC reader of the user's computing device 601, such as the back or side of the device) and press or select icon 606 to write a virtual card number. When icon 606 is pressed or selected, the computing device 601 can detect the blank card via the NFC reader and associated NFC circuitry, and can write the virtual card number as an NFC Data Exchange Format (NDEF) tag onto the blank card. After the virtual card number is written onto the blank card, the card can be activated for use at any point-of-sale system or on any NFC-enabled device, details of which will be referenced below. Figure 8 Further description will make it clear that an activated card can be called an "active" card.
[0086] As shown in the figure, at the receiver computing device 611, the receiver can open the banking application 622 and tap the active card to receive, process, and use or spend a virtual card number. For example, after receiving the virtual card number after tapping the active card, the receiver computing device 611 can copy and paste, fill in, or automatically fill in the relevant payment information associated with the virtual card number on any web-based application or website (such as merchant website 642). It will be understood that any purchases or transactions made on website 642 are still subject to the restrictions set by the user as described above. In another example, a virtual card number can be added and provided to a third-party digital wallet. In yet another example, users can physically use active cards at many point-of-sale systems and on NFC-enabled devices (such as physical stores).
[0087] Figure 7 An example process 700 for transmitting a virtual card number from a user computing device 702 to a recipient computing device 704 according to one or more embodiments is illustrated. The user and recipient computing devices 702 and 704 can be NFC-enabled or NFC-compatible devices. As shown, the user device 702 can tap (or vice versa) against the recipient device 704 to transmit the virtual card number from the user device 702 to the recipient device 704 via near-field communication. Similar to the process of writing a virtual card number to a blank card, the virtual card number can be transmitted between at least two devices via a corresponding banking application.
[0088] After the virtual card number is transmitted, the receiving device 704 can consume the number in various ways. For example, as shown, the recipient can use a banking application 722 to process the virtual card number and copy and paste or populate character fields of a merchant's web-based application or website, according to user-set restrictions. In other examples, as further shown, the recipient can use a third-party wallet application 742 to provide the virtual card number to a third-party virtual wallet.
[0089] As an example, the virtual card number can be encrypted with a personal identification number (PIN) before being sent to the recipient's device (704). Therefore, the recipient may need to enter the PIN to use the virtual card number in a banking application (722 scenario), a third-party wallet application (742 scenario), or any other scenario.
[0090] Figure 8 Example card applets stored in memory 802 of a contactless card, according to one or more embodiments, and communication between them are illustrated. The contactless card may be the aforementioned NFC-enabled blank unlock card, which receives a virtual card number via an NDEF tag sent from a user computing device. In addition to memory 802, the contactless card may also include one or more processors or processing circuitry (not shown), similar to... Figure 3A and 3B The non-contact card 300 and its contact pad are shown.
[0091] As shown in the figure, the card's memory 802 may include a security domain 804. Within the security domain 804, at least two independent applets 810 and 812 may exist, which may be different from each other and both reside in the same security domain 804. In the example, the contactless card can receive an NDEF tag from a user's computing device, and the first applet 810 can use or process the NDEF tag. Applet 810 can extract, export, or otherwise obtain a virtual card number and other related information, such as expiration information, one or more restrictions set by the user, and a card verification value (CVV). Applet 810 can then forward the virtual card number and related information to applet 812, making the contactless card active for use at a point-of-sale system or other NFC-enabled devices. In the example, a secure communication tunnel can be formed between the two applets 810 and 812 to forward or exchange virtual card numbers, which, along with new expiration dates, CVVs, one or more keys, become the primary account of the contactless card so that it can be used for shopping in stores. It will be understood that applet 810 could be a banking applet, while applet 812 could be a payment applet.
[0092] In a further example, the virtual card number can be encrypted with a PIN, requiring the recipient to enter or use a PIN to conduct any transaction via contactless card using the virtual card number.
[0093] Figure 9 An example flowchart 900 is shown according to one or more embodiments. Flowchart 900 relates to personalizing one or more restrictions associated with a virtual card number for the recipient and generating the virtual card number. It will be understood that the blocks of flowchart 900 and the features described therein do not need to be executed in any particular order. Furthermore, it will be understood that flowchart 900 and the features described therein can be executed or supported by one or more processors.
[0094] In box 902, the banking application may, for example, receive instructions or selections from the user to generate a virtual card number. In box 904, it can be determined whether one or more restrictions are associated with the virtual card number. As mentioned above, one or more restrictions can be selected and set by the user in a personalized manner for the recipient, which may include merchant restrictions, amount restrictions, time or period restrictions, and / or location restrictions. In some examples, the user does not set any restrictions on the virtual card number.
[0095] To apply any restrictions and generate a virtual card number, one-touch contactless card authentication can be performed. Advantageously, this ensures that it is the user who actually generates the card number and applies the restrictions. In box 906, the banking application can prompt the user to perform one-touch authentication. In the example, authentication is performed via the user's contactless card (which could be a payment tool used to fund or top up the virtual card number), and based on successful authentication, the user's identity can be verified.
[0096] As described above, the NFC reader of a user computing device can detect a user's contactless card and receive one or more PINs from it. These PINs can be used to determine whether the contactless card actually belongs to or is associated with the user. The PIN can be decrypted by the user computing device using a banking application via a multivariate key (a multivariate key derived from at least one counter value stored in memory and a master key) and matched against the user's relevant authentication information, which can be received from one or more secure remote computing devices (e.g., a server computer). In another example, the PIN can be sent to one or more secure remote computing devices, where decryption and matching of the information contained in the PIN against the user's authentication information can be performed. Based on this determination, user identity verification can be confirmed.
[0097] After successfully verifying the user's identity via one-touch authentication, in box 908, one or more restrictions (if any) selected and set by the user can be applied to the virtual card number. The banking application can then generate the virtual card number, which can be consumed in the various ways described above, such as writing to a physical contactless card, sending it to the recipient's computing device, etc. Furthermore, as mentioned above, one-touch authentication can be performed at any time during the number generation process, such as before the user selects and sets one or more restrictions.
[0098] While the above embodiments and examples relate to reader coils implemented in mobile computing devices, it will be understood that the power of any NFC reader installed in any type of device can be dynamically adjusted to improve NFC communication. Furthermore, the aforementioned NDEF message and corresponding payload may include message content or data related to various use cases of contactless cards, such as contactless card activation, user authentication, user verification, various transactions, sales, purchases, etc.
[0099] The components and features of the aforementioned devices can be implemented using any combination of discrete circuits, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures. Furthermore, the features of the devices can be implemented using microcontrollers, programmable logic arrays, and / or microprocessors, or, where appropriate, any combination thereof. Note that hardware, firmware, and / or software elements may be collectively referred to herein as “logic” or “circuit.”
[0100] At least one computer-readable storage medium may include instructions that, when executed, cause a system to perform any computer-implemented method described herein.
[0101] Some embodiments may be described using the expressions "an embodiment" or "embodiment" together with their derivatives. These terms mean that a particular feature, structure, or characteristic described in connection with that embodiment is included in at least one embodiment of this disclosure. The phrase "in one embodiment" appearing in various places throughout this specification does not necessarily refer to the same embodiment. Furthermore, unless otherwise stated, the foregoing features are considered to be used in any combination. Thus, any feature discussed individually may be used in combination with each other unless it is noted that these features are incompatible with each other.
[0102] Generally, reference is made to the notation and nomenclature used herein, and the detailed descriptions herein may be presented based on program procedures executed on a computer or computer network. Those skilled in the art use these procedural descriptions and representations to most effectively convey the substance of their work to those skilled in the art.
[0103] The program here is, and is generally considered, a self-consistent sequence of operations that leads to the desired result. These operations are physical operations that require physical quantities. Typically, while not strictly necessary, these quantities are in the form of electrical, magnetic, or optical signals that can be stored, transmitted, combined, compared, and otherwise manipulated. It is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc., primarily for common reasons. However, it should be noted that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.
[0104] Furthermore, the operations performed are typically referred to by terms such as addition or comparison, which are often associated with mental operations performed by a human operator. In any of the operations described herein that form part of one or more embodiments, this ability of a human operator is not required, or in most cases preferred. Instead, these operations are machine operations.
[0105] Some embodiments may be described using the terms “coupled” and “connected” along with their derivatives. These terms are not necessarily synonyms of each other. For example, some embodiments may be described using the terms “connected” and / or “coupled” to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term “coupled” may also mean that two or more elements are not in direct contact with each other, but still cooperate or interact with each other.
[0106] Various embodiments also relate to apparatus or systems for performing these operations. The apparatus may be specifically constructed for a desired purpose and may be selectively activated or reconfigured by a computer program stored in a computer. The processes described herein are not substantially related to any particular computer or other device. The necessary architecture for various such machines will become apparent from the given description.
[0107] It is important to emphasize that this abstract of the disclosure is provided to enable the reader to quickly determine the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Furthermore, as can be seen from the foregoing detailed description, various features are combined in a single embodiment to simplify the disclosure. This method of disclosure should not be construed as reflecting an intention that the claimed embodiments require more features than expressly recited in each claim. Rather, as reflected in the following claims, the subject matter of the invention lies in fewer than all features of a single disclosed embodiment. Therefore, the following claims are hereby incorporated into the detailed description, each claim being an independent, separate embodiment. In the appended claims, the terms “including” and “in which” are used as simple English equivalents to the corresponding terms “comprising” and “wherein,” respectively. Furthermore, the terms “first,” “second,” “third,” etc., are used merely as labels and are not intended to impose numerical requirements on their objects.
[0108] The examples of the disclosed architectures described above are included. It is certainly impossible to describe every possible combination of components and / or methods, but those skilled in the art will recognize that many further combinations and permutations are possible. Therefore, the novel architecture is intended to encompass all such changes, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. A device using a contactless card, comprising: Near field communication circuitry for receiving and transmitting data via NFC; Memory used to store instructions; as well as One or more processors coupled to the memory and operable to execute the instructions, which, when executed, cause the one or more processors to: Receive login information from a user for accessing a software application, and grant the user access rights to the software application based on the login information; The software application receives instructions or selections from the user to generate a virtual card number from the user's account. Determine whether one or more restrictions are associated with the generation of the virtual card number, wherein the one or more restrictions are input, set, or specified by the user; The user is authenticated by receiving one or more passwords from a first contactless card via NFC and decrypting the one or more passwords using a key generated based on a master key and a counter value stored in the memory; as well as Upon successful authentication and verification based on the user's identity, apply one or more restrictions to the virtual card number and generate the virtual card number. Detecting a second contactless card via NFC circuitry; and Write the virtual card number into the second contactless card.
2. The apparatus of claim 1, wherein the one or more restrictions include merchant restrictions, monetary restrictions, time period restrictions, and / or location restrictions.
3. The apparatus of claim 1, wherein the one or more processors are further configured to: The virtual card number is sent to the second contactless card in the NFC data exchange format NDEF tag.
4. The device according to claim 3, wherein the second contactless card includes at least a first mini-program and a second mini-program different from the first mini-program, the first mini-program and the second mini-program residing in the same security domain.
5. The apparatus of claim 4, wherein the first applet consumes or processes the NDEF tag and forwards the virtual card number to the second applet, thereby activating the second contactless card for use at the point of sale system, the virtual card number being encrypted with a personal identification number (PIN) such that the PIN is required to use the virtual card number.
6. The apparatus of claim 1, wherein the one or more processors are further configured to: Detecting NFC-compatible devices via the NFC circuit; and Send the virtual card number to the NFC-compatible device, and The virtual card number is encrypted using a personal identification number (PIN), making the PIN required to use the virtual card number.
7. The apparatus of claim 5, wherein the second contactless card is touched against an NFC-compatible device, and the NFC-compatible device at least reads the virtual card number to copy and paste or populate the virtual card number into one or more fields of a website or web-based application according to one or more restrictions set by the user.
8. The apparatus of claim 7, further comprising the one or more processors sending and providing the virtual card number to and providing it to a third-party digital wallet.
9. The apparatus of claim 3, further comprising the one or more processors securely transmitting expiration date and card verification value (CVV) information to the second contactless card via NFC.
10. The apparatus of claim 1, wherein the one or more processors are further configured to: The system prompts the user to confirm or modify one or more restrictions that the user entered, set, or specified prior to authentication, and receives confirmation or modification selection; and Based on the modification selection, the user is allowed to modify one or more of the restrictions.
11. The apparatus of claim 1, wherein the first contactless card includes a memory and processing circuitry, the processing circuitry being configured to execute instructions stored in the memory to send the one or more passwords as one or more NFC Data Exchange Format (NDEF) messages to an apparatus for performing the authentication and verification of the user's identity.
12. The apparatus of claim 4, wherein the second contactless card includes a memory and processing circuitry, the processing circuitry being configured to execute instructions stored in the memory to process and execute the first and second applets residing in the same security domain.
13. The apparatus of claim 3, wherein the second contactless card is a blank unlock card and belongs to the recipient of the generated virtual card number.
14. A method for generating a virtual card number, the method comprising: Receive login information from the user via a computing device for accessing software applications; The software application receives instructions or selections from the user to generate a virtual card number from the user's account. The user is authenticated via the computing device by receiving one or more passwords from a first contactless card belonging to the user via near field communication (NFC) and decrypting the one or more passwords using a key generated based on a master key and a counter value stored in memory. The computing device determines whether one or more restrictions are associated with the generation of the virtual card number, wherein the one or more restrictions are input, set, or specified by the user. Based on the determination, the virtual card number is applied to the virtual card number and the virtual card number is generated via the computing device; as well as (i) Detecting a second contactless card via NFC and writing the virtual card number into the second contactless card and / or (ii) sending the virtual card number to an NFC-compatible device different from the computing device.
15. The method of claim 14, wherein the authentication process further comprises: The contactless card is detected via NFC and one or more passwords are received from the contactless card, the one or more passwords including at least card user information; as well as Determine whether the card user information in one or more received passwords matches or corresponds to the user, and verify the user's identity based on the determination that the card user information matches or corresponds to the user.
16. The method of claim 14, wherein the one or more restrictions include merchant restrictions, monetary restrictions, time period restrictions, and / or location restrictions.
17. The method of claim 14, wherein the second contactless card is a blank unlock card and belongs to the recipient of the generated virtual card number.
18. A non-transitory computer-readable storage medium storing computer-readable program code, said computer-readable program code being executable by a processor to: Receive instructions or selections from the user to generate a virtual card number from the user's account; Receive one or more restrictions associated with the generation of the virtual card number; The user is authenticated by receiving one or more passwords from a first contactless card belonging to the user via Near Field Communication (NFC) and decrypting the one or more passwords using a key generated based on a master key and a counter value stored in memory. The authentication verifies the user's identity and applies one or more restrictions to the virtual card number; and Generate the virtual card number; Detecting a second contactless card via NFC circuitry; and Write the virtual card number into the second contactless card.
19. The non-transitory computer-readable storage medium of claim 18, wherein the one or more restrictions include merchant restrictions, monetary restrictions, time period restrictions, and / or location restrictions.
20. The non-transitory computer-readable storage medium of claim 18, wherein the user account is a money account, a checking account, a credit card account, a debit card account, a digital wallet account, or a cryptocurrency account.
Citation Information
Patent Citations
Systems and methods for cryptographic authentication of contactless cards
US10489781B1
One-tap payment using a contactless card
US10510074B1