System and method for encrypted context switching authentication between website and mobile device

By displaying a custom hyperlink on the payment checkout screen of the merchant website, combining authentication applications on mobile devices and contactless cards, automated authentication and transmission of sensitive user information is achieved, and the problems of cumbersome and error-prone in manual input of information in the prior art are solved, and streamlined and secure network transmission is achieved.

CN120019400APending Publication Date: 2025-05-16CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380071649.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-08
Filing Date
2023-08-07
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When the prior art realizes the secure transmission of sensitive user information, relying on the user to manually input information, it is prone to human errors and cumbersome, making it difficult to achieve streamlined and secure network transmission.

Method used

By displaying a custom hyperlink on the payment checkout screen of the merchant website, activate the network interface, triggering a context switch authentication scheme, and using authentication applications and contactless cards on mobile devices to achieve automated authentication and transmission of sensitive user information.

Benefits of technology

It realizes streamlined and secure transmission of sensitive user information, reduces the possibility of human error, simplifies user operation processes, and improves the security and efficiency of transmission.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120019400A_ABST
    Figure CN120019400A_ABST
Patent Text Reader

Abstract

Systems and methods for implementing automated systems and processes to facilitate reduced and secure delivery of authenticated user data over a network. The process may be initiated via activation of a custom hyperlink displayed on the network interface. A custom hyperlink is operatively integrated with an encryption and authentication provision system to trigger one or more data collection and / or authentication operations that can automatically retrieve authenticated user information in a secure manner. One aspect of security relates to an authentication scheme implemented by context switching between a mobile browser initiated http / https session and one or more data collection and / or authentication functionality provided by one or more applications stored on a user mobile device. The secure data retrieval process may also be supplemented by means of encrypted exchange of request and / or response messages implemented by back-end integration with the encryption and authentication provision system.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS

[0002] This application claims priority to U.S. Patent Application No. 17 / 883,232 filed on August 8, 2022, the entire contents of which are incorporated herein by reference. Technical Field

[0003] The present disclosure relates to systems and methods for providing authentication credentials and authentication user information over a network, and more particularly, to systems and methods for providing authentication based on encryption context switching. Background Art

[0004] From systems and applications storing sensitive data resources to systems and applications requesting authenticated sensitive user data, the streamlined and secure network transmission of authenticated user-related data remains a major challenge, particularly for the secure and efficient implementation of electronic transactions. Several routines have been designed to provide secure access to sensitive and / or private information for authenticating the source of information prior to retrieving and transmitting the sensitive and / or private information. However, in many cases involving the exchange of user private identity information (PII) and / or payment credential information (PCI), the verification process relies on manually entering the user PII and PCI directly into a spreadsheet provided by the merchant system prior to initiating the transaction requested by the user. In this case, the user will manually enter several pieces of information, which are then verified against pre-authenticated user information (e.g., information stored by the corresponding financial institution). This implementation is cumbersome and prone to human error because it requires the user to collect the required data and manually enter it into a spreadsheet. These and other drawbacks exist. Summary of the invention

[0005] One aspect of the present disclosure relates to an automated process for facilitating streamlined and secure delivery and / or retrieval of authenticated user-related information over a network. The process can be initiated via activation of a custom hyperlink displayed on a network interface (such as a payment checkout screen). For example, a custom hyperlink displayed on a payment checkout screen of a merchant website can be operatively integrated with an external encryption and authentication provider system and process on the back end to trigger one or more data collection and / or authentication operations that facilitate authenticated retrieval of sensitive user information in a secure manner.

[0006] One aspect of the security functionality associated with the above-described systems and processes relates to an authentication scheme facilitated via a context switch between an HTTP and / or HTTPS session initiated at a (mobile) browser (e.g., initiated from a mobile device via standard network access over the Internet) and one or more data collection and / or authentication functions provided by one or more applications stored on the respective user mobile devices. Thus, the context switch authentication scheme enables streamlined and secure retrieval of an authorization response from an authenticated user prior to initiating delivery of the requested (sensitive) user information to a requesting merchant system and / or server (e.g., a server and / or device initiating a request for sensitive user data). The secure user data retrieval process may also be supplemented by encrypted exchange of request and / or response messages enabled by back-end integration of the transaction (merchant) website with external encryption and authentication providing systems and processes.

[0007] In some embodiments, one or more applications stored on the user's mobile device may initiate the collection and authentication of the requested (sensitive) user data (e.g., user PII and / or PCI data). One or more applications (e.g., associated with data collection and authentication operations) may be called according to one or more instructions encoded in the universal link. In response to a request for sensitive user data originating from a remote merchant system and / or server, a universal link may be generated and transmitted to the mobile user device. The user data request message may be generated by the remote merchant system upon activation of a custom link (e.g., a custom hyperlink) on a payment processing web interface incorporated into the merchant system (e.g., a user clicks on a custom link to complete an online transaction initiated via a mobile browser session). The request message may then be transmitted to an authentication server (associated with an external encryption and authentication providing system and process) and from there communicated to the user's mobile device in the form of a universal link generated, for example, by the authentication server.

[0008] The universal link may include one or more instructions to prompt the user to provide one or more authentication inputs using a mobile user device. The one or more authentication inputs captured by the user's mobile device may then be sent back to the corresponding authentication server for verification. Once verified, the requested sensitive user data (based on authorization from the authenticated user) may be communicated to the (transaction) merchant system and / or server via an encrypted backend communication link (e.g., implemented via a backend integration of the merchant system with authentication and encryption providing systems and processes). The requested (authenticated) user data may then be automatically populated on an electronic transaction form provided by the merchant system as part of an online payment interface to facilitate online payment transactions.

[0009] The universal link may correspond to a universal resource indicator (URI) (e.g., a hyperlink, a universal resource locator (URL), or other data resource indicator), and may also include components for identifying a target destination (e.g., a web server that manages a merchant website from which the request came) and a specific user transaction session to which the data corresponding to the user PII and / or PCI will apply. The URI may also include a deep link to an authentication function available on a mobile user device. The authentication function may be provided by an authentication application stored on the user's mobile device. When invoked according to instructions encoded in the deep link, the authentication application may initiate retrieval of one or more authentication inputs via the mobile user device to verify the request for sensitive user data and subsequently transmit it to the merchant system to facilitate the specific user transaction session.

[0010] Therefore, the security-sensitive data retrieval process may include: providing a custom link on an interface of a website, wherein the website is integrated with authentication features provided by an external authentication system (e.g., external to a transaction initiating web server); generating a universal link in response to a user selection of the custom link, the universal link comprising: a website identifier that identifies the website where the user selects to activate the custom link; a unique anonymous user identifier generated by the website to track a specific user session; an identifier of an authentication application for implementing a context switching authentication scheme, the authentication application being associated with the external authentication system and stored on a user device from which the website is accessed; transmitting the universal link to the user device, wherein the universal link launches the authentication application, prompting the user to perform one or more authentication actions and / or inputs; transmitting, by the user device, the one or more authentication inputs to a corresponding authentication server for verification; and, after verifying the one or more authentication inputs, transmitting one or more requested user data to be automatically filled in on the interface of the website.

[0011] According to some embodiments of the present disclosure, user authentication information required to authenticate an authorized response of a user (e.g., one or more authentication inputs associated with a context switching authentication scheme) can be provided by a contactless card having an integrated processor and memory that stores user identification and / or authentication information as near field communication (NFC) transmittable data (e.g., NFC Data Exchange Format (NDEF)). The user authentication information can then be captured directly by a reader component of a mobile user device and transmitted to an authentication server for verification. Thus, one or more authentication inputs can be provided by a single user action that brings the contactless card into NFC range of a mobile device (e.g., by tapping the contactless card on a reader of a user's mobile device) to initiate direct reading and subsequent verification of the user authentication information stored on the contactless card as NFC transmittable data.

[0012] In some embodiments, one or more data records corresponding to sensitive user data (e.g., user PII and / or PCI data) may be stored directly on the integrated memory of the contactless card as NFC transferable data. In response to a request for sensitive user information, one or more data records may then be read from the contactless card (initiated by the authentication application) using a user mobile device running a corresponding reader application and sent directly to a remote merchant server for automatic filling on an appropriate payment screen. In some embodiments, the requested user data read from the contactless card by a reader device incorporated into the user mobile device may be transmitted by the user mobile device to the authentication server for verification. Upon successful verification, the user information (securely retrieved directly from the contactless card) may then be sent to the requesting (merchant) server.

[0013] In some embodiments, network communication messages between the merchant server and the authentication server may be communicated via an encrypted communication link facilitated by back-end integration between the (remote) merchant server and encryption and authentication providing systems and processes. In some embodiments, the secure user data retrieval process may occur over a public network using public and / or private encryption processes. BRIEF DESCRIPTION OF THE DRAWINGS

[0014] Various embodiments of the present disclosure, as well as other objects and advantages, may be best understood by referring to the following description taken in conjunction with the accompanying drawings.

[0015] Figure 1 An exemplary system implementation for authentication data delivery using context switch authentication with encryption backend integration based on user-entered credentials according to some embodiments of the present disclosure is shown.

[0016] Figure 2 An exemplary system implementation for authentication data transfer using NFC-transferred credentials from a contactless card using context switch authentication with cryptographic backend integration according to some embodiments of the present disclosure is shown.

[0017] Figure 3 An exemplary system implementation for authentication data transfer using context switching between a website and an NFC-enabled contactless card according to some embodiments of the present disclosure is shown.

[0018] Figure 4A A contactless card according to some embodiments of the present disclosure is shown.

[0019] Figure 4B Contact pads of a contactless card according to some embodiments of the present disclosure are shown.

[0020] Figure 5An operational flow chart of an exemplary context switching authentication process between a website and a mobile application based on user-entered credentials according to some embodiments of the present disclosure is shown.

[0021] Figure 6 A timing diagram for automatically populating an electronic form with authentication data transmitted from an NFC-enabled contactless card is shown in accordance with some embodiments of the present disclosure.

[0022] Figure 7 is an illustration of an exemplary block diagram of an exemplary system according to some embodiments of the present disclosure. DETAILED DESCRIPTION

[0023] The following description of the embodiments provides non-limiting representative examples of reference numbers to specifically describe the features and teachings of different aspects of the present invention. The described embodiments should be considered as being able to be implemented separately or in combination with other embodiments in the description of the embodiments. A person of ordinary skill in the art who reviews the description of the embodiments should be able to learn and understand the different described aspects of the present invention. The description of the embodiments should promote the understanding of the present invention so that other implementations known to those skilled in the art who read the description of the embodiments but not specifically covered are understood to be consistent with the application of the present invention.

[0024] Some embodiments of the present disclosure relate to an encryption and authentication provisioning system and process, which is implemented by configuring a secure backend encryption system with a context switching authentication scheme in such a way that sensitive data resources (e.g., user PII and / or PCI) can be securely delivered and / or retrieved directly over a public network (such as the Internet). In some embodiments, the encrypted exchange of request and response messages between the requesting merchant system and the encryption and authentication system can be implemented via a backend integration of a merchant website with an externally provided encryption and authentication system and process.

[0025] According to the above embodiment, the process can be dynamically triggered upon activation of a custom (checkout) link (e.g., an actionable button and / or icon) displayed on a web interface (e.g., a payment checkout screen) of a transaction (merchant) server. The custom link is associated with a back-end integration of a transaction merchant website with an external encryption system configured with a context switch authentication function, which is initiated upon activation of the custom link. The external encryption system configured with the context switch authentication function may refer to a system and / or process that is implemented externally relative to the transaction merchant system but provides functionality accessible to the merchant system via a back-end integration with a service providing system. Therefore, for the purposes of this disclosure, the encryption and authentication providing system may be interchangeably referred to as an "external encryption and authentication system" and / or an "external authentication system."

[0026] As described, the above functionality (corresponding to encrypted and authenticated delivery and / or retrieval of sensitive user data) can be accessed upon activation of a custom checkout link displayed, for example, on a payment checkout screen of a merchant website. In some embodiments, in addition to activating the custom link, the user may also be requested to enter some initial identification information, such as an email address, in order to generate a request for a secure data delivery process. The initial user identification information may then be transmitted to an authentication server (associated with a backend integration) along with a request for sensitive user information (e.g., user PII and PCI). The receiving (authentication) server may use the initial user identification information as a search index to identify and collect relevant and / or requested user information. In some embodiments, the receiving (authentication) server may use the initial user identification information to determine a device identifier associated with, for example, a user mobile device, and one or more application identifiers corresponding to one or more data collection and / or authentication applications stored on the user mobile device.

[0027] The set of identifiers associated with the user's mobile device and the corresponding mobile application can be incorporated into a universal resource indicator (URI), such as a universal link, a universal resource locator (URL), or other indicator, generated by, for example, a URI generation process running on a receiving (authentication) server. According to some embodiments, the URI generation process can be run on the authentication server. In some embodiments, the URI generation process can be run on a remotely located URI generation server that is communicatively coupled to the authentication server. The URI generation process can integrate one or more mobile application identifiers corresponding to one or more data collection and / or authentication applications stored on the user's mobile device into the generated universal link. The generated universal link can then be transmitted to the user device (as identified by the user's mobile device identifier). The universal link can also include instructions to launch one or more identified mobile applications on the user's mobile device to facilitate context switch authentication for requesting and / or retrieving sensitive user information.

[0028] Figure 1 An exemplary encryption and authentication provisioning system (100) (interchangeably referred to as "authentication system" (100) for purposes of this disclosure) for enabling authorized delivery of sensitive user data that is verified based on one or more user authentication inputs provided for authorized delivery is shown. Figure 1, the acquisition of one or more user authentication inputs (102) can be achieved by context switching between a mobile browser session (103) initiated from the user mobile device (101) and an authentication application (104) stored on the user mobile device (101). The user mobile device (101) can then transmit the one or more user authentication inputs to the authentication server (110) for verification. After verifying the one or more authentication inputs provided in association with the data transfer authorization response, the requested sensitive user information can be transmitted to a remote destination server (e.g., merchant server 120) via an encrypted backend communication channel (130) (e.g., via a backend integration of the merchant server (120) with the authentication and encryption providing system and process (100)).

[0029] The authentication server (110) may include, for example, one or more server-side applications (113) corresponding to a data collection application (114) and / or an authentication application (115). The authentication server may be communicatively coupled to a user device (e.g., mobile device 101) and responsive to one or more communications from one or more (client) applications (e.g., authentication application 104) stored on the user mobile device (101). The authentication server (110) may also be communicatively coupled to multiple remote merchant systems via back-end integration of the remote merchant systems with the authentication system (100) described above. As described above, the authentication process may be based on a context switch between a browser session (103) initiated by a web browser running on the user mobile device 101 and an authentication function provided by an external authentication system 100. The authentication server (110) may also be connected to a database (e.g., database 140) that may be used to store one or more user personally identifiable information (PII) and / or payment credential information (PCI) of multiple users. Although Figure 1 A single instance of a component is shown, but system 100 may include any number of components.

[0030] Return to reference Figure 1, the context switch authentication process may be initiated by a universal link transmission (117) to a user mobile device (101). The universal link (118) may be generated by an authentication server (110) in response to a data request message (116) received from a remote merchant server (120). The data request message (116) may correspond to a request for sensitive user data (1) triggered by a user selection of a custom link (121) at a web interface (122) of a transaction merchant server (120). The requested sensitive user data may correspond to, for example, one or more user data records required to process a payment transaction at a web interface of a merchant website. In addition to the request for sensitive user data (1), the data request message (116) may also include a merchant website identifier (2), an anonymous unique user session identifier (3) (for identifying a specific user transaction session on the merchant website), and initial user identification information (4) (e.g., an email address provided by the user at the web interface 122 of the merchant server 120). The data request (116) may then be transmitted to the authentication server (110) via a backend encrypted communication link (130). In response, the authentication server (110) initiates a context switch (authentication) scheme to map the data request for the sensitive user information with an authorization response from the authenticated user (e.g., based on verifying one or more user authentication inputs 102) before authorizing transmission of the requested sensitive user data to the remote merchant server.

[0031] As previously described, the context switching (authentication) scheme can be initiated by transmitting (117) a universal link to the user mobile device (101). The universal (link) can include an application identifier for identifying a target application (e.g., authentication application 104) stored on the user mobile device (102), and encoded instructions for invoking the target (authentication) application. The authentication application (104), when invoked according to one or more instructions encoded in the universal link, can initiate retrieval of one or more authentication inputs (102) via the user mobile device (101). The one or more authentication inputs (102) captured by the user mobile device (101) can then be sent back to the corresponding authentication application and / or process (115) for verification. Once verified, the authentication signal (118) can trigger the data collection application and / or process (114) to retrieve the requested sensitive user data and transmit it to the remote merchant server (120) via a response message (119). The response message may be sent to the merchant system / server via an encrypted backend communication link (130) implemented via a backend integration of the merchant server (120) with the authentication system 100. The specific user transaction session may then be identified (e.g., based on an anonymous unique user session identifier (3) included in the response message 119), and the requested user data (e.g., user PII and / or PCI) may be automatically populated on an electronic transaction form provided by the merchant server as part of an online payment interface implemented via a backend integration with the authentication system 100. The user PCI data may correspond to a primary account number (PAN) and / or credit / debit card data. In some embodiments, a merchant-specific virtual credit card number (VCN) may be generated in response to the data request message (116) and subsequently provided in the response message (119) as the user PCI data.

[0032] The encrypted network communications exchanged between the remote merchant server (120) and the authentication server (110) may be conducted via an encrypted backend communication link (130). The encrypted network communications may correspond to the subsequent transmission of a data request message (116) from the remote merchant server (120) and a response message (119) by the authentication server (110). In some embodiments, the above communications may be conducted over a public network using a public / private encryption routine. In some embodiments, the communications between the merchant server and the authentication server may be implemented using a shared secret encryption scheme.

[0033] In some embodiments, the target application associated with the application identifier encoded in the universal link may correspond to a data collection application integrated with authentication functionality provided by an external authentication system. In some embodiments, the data collection application may be operatively coupled with a different authentication application stored separately on the user device (101). The data collection application may collect user PII and PCI information (which may be stored in part or in whole on one or more of the user mobile device (101), a corresponding authentication server (110), and / or one or more external / internal data repositories (e.g., database 140)) and, upon confirming (via an authentication confirmation signal (118) from the authentication application) the validity of the request for sensitive user information, transmit the sensitive user information to the merchant website for automatic population on the payment checkout screen. The authentication confirmation signal (118) may correspond to an authorization response from the authenticated user.

[0034] In some embodiments, the authentication scheme for authenticating a user authorization response to transfer sensitive user data to a remote entity may correspond to confirming that a user authorized to transfer sensitive user information is in possession of or in proximity to a verifiable device associated with a transacting user (e.g., the user initiated a transaction by clicking on a custom checkout link provided on a payment screen of a merchant website). The verifiable user device may be provided in the form of a contactless card having an integrated processor and memory that stores user identification / authentication information as near field communication (NFC) transmittable data.

[0035] Thus, one aspect of the proposed system and method relates to an authentication scheme involving a uniquely configured contactless card having an integrated NFC tag storing NFC-transmittable user authentication data (e.g., readable by a mobile device having a reader component and running a corresponding application). Figure 4A and Figure 4B The specific structure, configuration and operation of the contactless card are described, including its integrated processor, memory and NFC functionality, and secure methods for storing sensitive information as NFC transferable data. Figure 2 An exemplary system implementation (200) for context switching authentication using the above-mentioned contactless card is shown.

[0036] Figure 2 An exemplary system (200) is shown for implementing the automatic delivery of encrypted user data, aided by an authentication scheme implemented through a context switch between a network session (103) and a contactless card (201). The described context switch authentication scheme implements a single authentication action involving the contactless card (201) providing a valid authentication confirmation signal (118) for authorizing the delivery of sensitive user information (e.g., via a response message 119) to a (requesting) remote network server (120). Figure 2 You can quote the above about Figure 1 The same or similar components and operations are explained.

[0037] like Figure 2 As shown, an exemplary context switch authentication implementation (200) utilizes a contactless card (201) having a symmetric encrypted NFC channel (203) to a user mobile device (110) for encrypted transmission of user authentication data 202 (stored as NDEF data on the contactless card (201)). The user authentication data (202) retrieved from the contactless card (201) via the encrypted NFC transmission (202) can be provided to an authentication application (104) running on the user mobile device (110). For example, when a reader (124) of the user mobile device (110) moves into NFC proximity of the contactless card (201), the encrypted NFC channel (203) can be activated, and vice versa. The encrypted authentication data (202) received by the authentication application (104) can be decrypted using a symmetric key shared between the contactless card (201) and a corresponding reader application (e.g., authentication application 104) running on the user mobile device (101). The authentication data may then be transmitted to a corresponding authentication application / process (115) running on the authentication server (110) for verification. Upon verification (represented by a verification signal (118) from the authentication application (115) to the data collection process 114 running on the authentication server 110), the sensitive user information may be provided (e.g., via a response message 119 transmitted over an encrypted backend communication channel 130) to a (requesting) remote merchant server (120) to, for example, facilitate a user payment transaction.

[0038] One aspect of the present disclosure relates to automatically transferring sensitive user data directly from a contactless card, such as Figure 3 The automatic data transfer process corresponding to the secure transmission of user information directly from the contactless card (301) to the remote merchant server (120) can be facilitated by a context switch between the user network session (103) and the NFC reader function (e.g., provided by an application / process (105) running on the mobile device).

[0039] Figure 3 Possibly referenced above Figure 1 and Figure 2The same or similar components explained above. In an exemplary embodiment (300), a configuration involving a contactless card (301) and a user mobile device (101) can be used to enable direct delivery of user PII and / or PCI data from a contactless card to a remote merchant server (120). Referring to the exemplary system implementation (300), a target (mobile) application (105) corresponding to an application identifier encoded in a URI transmission 117 (e.g., a universal link 117) to a mobile device (101) can be automatically invoked on the mobile device (102) when the universal link transmission (117) is received by the user mobile device. In an exemplary embodiment (300), the target application (105) can correspond to an NFC reader application for activating a reader function of the mobile device (e.g., causing the user device to simply act as a reader) to enable collection of sensitive user information 302 (e.g., user PII and / or PCI data) stored directly on the contactless card (301) (e.g., via NFC tapping of the contactless card on the user mobile device). In this way, the user's PII and / or PCI that needs to be populated on the payment checkout or account registration screen can be directly retrieved from the contactless card (301) storing the NFC transmittable user PII and / or PCI information (302) via NFC tap. The user information received from the contactless card (301) by the mobile application (105) via NFC transmission can then be transmitted to the authentication process / application (115) on the authentication server (110) for verification (e.g., verifying that the user data retrieved from the card (301) matches the initial user identification data (4) incorporated into the data request message (116)).

[0040] According to some embodiments, the transmission of user data (302) from a contactless card (301) to a receiving application / process (105) on a mobile user device (101) may be facilitated via a symmetrically encrypted NFC link (203). The symmetric encryption may be associated with a public private encryption key shared between the contactless card (301), the target application (105), and the authentication application 115 on the authentication server (110). The user data (302) retrieved by the mobile (target) application (105) via a direct NFC read of the card (301) by the reader component (124) of the mobile device (101) may then be decrypted using the shared private key and verified by the authentication application (115) based on a correct match with the initial user identification data (4) in the data request message (116). Upon successful authentication, an authentication confirmation signal (118) may be sent to the mobile application (105) to trigger a response message (119) including the requested user data, which may be transmitted to a remote network server (120) via an encrypted network connection to, for example, facilitate an online payment transaction. In some embodiments, the response message (119) may be generated directly by the mobile application in response to the confirmation authentication signal (118) from the authentication server (110). The response message (119) may be transmitted by the mobile application (105) to the remote merchant server via an encrypted communication channel (130) associated with a backend integration of the merchant server / system (120) with a system implementation (300). According to some embodiments, the response message (119) may be encrypted with a public key of the destination merchant system (120) and transmitted to the remote merchant server (120) via a network session (103). This corresponds to data transfer (123) facilitated by the network session 103 over a public network 127, as described in detail in detail in the accompanying drawings. Figure 3 As shown. The user data may then be automatically populated on the web interface (122) of the merchant website / web server (120). In some embodiments, a VCN generation process (303), for example, running on the authentication server (110), may be invoked in response to a data request message (116) from the remote merchant system (120). Thus, a merchant-specific VCN may be generated and transmitted to the mobile application (105) along with the authentication confirmation signal (118) to be provided to the remote merchant system (120) along with the user PII data.

[0041] Figure 4A and Figure 4B An exemplary contactless card 400 is shown. Figure 4A and Figure 4B A single instance of components of card 400 is shown, but any number of components may be used.

[0042] Card 400 may be configured to communicate with one or more components of system 100. Card 400 may include a contact-based card (e.g., a card read by sliding a magnetic stripe or inserting a chip reader) or a contactless card, and card 400 may include a payment card, such as a credit card, a debit card, or a gift card. Figure 4A As shown, card 400 may be issued by a service provider designated 405 shown on the front of card 400 (and / or the back of card 400). In some examples, the payment card may include a dual-interface contactless payment card. In some examples, card 400 is not related to a payment card and may include, but is not limited to, an ID card, a membership card, and a transportation card.

[0043] Card 400 may include substrate 410, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, card 400 may have physical characteristics of an ID-1 format that conforms to the ISO / IEC 7810 standard, and card 400 may otherwise conform to the ISO / IEC 14443 standard. However, it should be understood that a card 400 according to the present disclosure may have different characteristics, and the present disclosure does not require implementation in a payment card.

[0044] The card 400 may also include identification information 415 displayed on the front and / or back of the card, and the card 400 may also include a contact pad 420. The contact pad 420 may be configured to establish contact with another communication device, including but not limited to a user device, a smartphone, a laptop, a desktop, or a tablet. The card 400 may also include processing circuitry, an antenna, and Figure 4A Other components not shown in the figure. These components can be located behind the contact pad 420 or elsewhere on the substrate 410.

[0045] The service provider designation 405 may include the name and logo of the service provider and may also include information about the service provider including, but not limited to, phone number, address, instructions for handling if the card 400 is lost or damaged, and other information. The service provider designation 405 may also include an image or graphic design.

[0046] Identification information 415 may include, but is not limited to, account number, name, expiration date, phone number, nickname, and other information. In some examples, identification information 415 may also include an image or graphic design. For example, identification information 415 may include an image, picture, drawing, or logo of the user.

[0047] like Figure 4B As shown, Figure 4AThe contact pads 420 may include processing circuitry 425 for storing and processing information, including a processor 430 (such as a microprocessor) and memory 435. It should be understood that the processing circuitry 425 may contain additional components necessary to perform the functions described herein, including processors, memories, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tampering hardware.

[0048] Memory 435 may be a read-only memory, a write-once read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and card 400 may include one or more of these memories. The read-only memory may be a factory-programmable read-only memory or a one-time programmable memory. One-time programmability provides the opportunity to write once and then read multiple times. The write-once / read-many memory may be programmed at a certain point in time after the memory chip leaves the factory. Once the memory is programmed, it may not be rewritten, but it may be read multiple times. The read / write memory may be programmed and reprogrammed multiple times after leaving the factory. It may also be read multiple times.

[0049] Memory 435 can be configured to store one or more applet programs 440, one or more counters 445 and customer identifier 450. One or more applet programs 440 can include one or more software applications configured to be executed on one or more contact-based cards or contactless cards, such as Java card applet programs. However, it should be understood that applet programs 440 are not limited to Java card applet programs, but can be any software application that can be operated on contact-based cards or contactless cards or other devices with limited memory. One or more counters 445 can include digital counters that are sufficient to store integers. Customer identifier 450 can include a unique alphanumeric identifier assigned to the user of card 400, and the identifier can distinguish the user of contactless card from other contactless card users. In some examples, customer identifier 450 can identify the customer and the account assigned to the customer, and can also identify the contactless card associated with the customer account.

[0050] The processor and memory elements of the above exemplary embodiments are described with reference to the contact pads, but the present disclosure is not limited thereto. It should be understood that these elements can be implemented outside the contact pads 420, can be completely separated from the contact pads, or can be implemented as other elements other than the processor 430 and memory 435 elements located in the contact pads 420.

[0051] In some examples, card 400 may include one or more antennas 455. One or more antennas 455 may be placed within card 400 and around processing circuit 425 of contact pad 420. For example, one or more antennas 455 may be integrated with processing circuit 425, and one or more antennas 455 may be used with an external booster coil. As another example, one or more antennas 455 may be external to contact pad 420 and processing circuit 425.

[0052] In an embodiment, the coil of the card 400 can act as the secondary of an air-core transformer. The terminal can communicate with the card 400 by cutting off power or amplitude modulation. The card 400 can use the gap in the card's power connection to infer data transmitted from the terminal, which can be functionally maintained by one or more capacitors. The card 400 can communicate by switching the load on the card coil or load modulation. Load modulation can be detected in the terminal coil by interference.

[0053] Figure 5 An operational overview of a context switch authentication process according to some embodiments of the present disclosure is provided. Figure 5 , the process may be initiated at (502) by activating a custom (checkout) link presented on an online payment interface of a merchant website. The custom link may be associated with a back-end processing option provided via an external authentication system. In response to a user selection of the custom link on the online payment interface of the merchant website, process 500 may proceed to step (504) for generating a data request message and transmitting it to the external authentication system via a back-end encrypted channel for processing. The data request message may include a request for user PII and / or PCI data, as well as a component for identifying the merchant website and a specific user transaction session associated with the selection of the custom link.

[0054] An authentication server associated with the external authentication system may receive the incoming data request message via a designated encrypted channel associated with a backend integration of the merchant website. At (506), the authentication server may locate a device identifier associated with the user's mobile device based on information included in the data request message and generate a universal link that encodes the identifier to a target application stored on the user's mobile device. The universal link may include additional information, such as information included in the data request message, and instructions for invoking a target mobile application that may correspond to a mobile authentication application.

[0055] At (508), the universal link is transmitted to the user's mobile device associated with the device identifier that may be included in the data request message. At (510), the user is prompted to enter one or more authentication inputs using the mobile device via the mobile authentication application. At (512), the one or more authentication inputs provided via the user's mobile device are verified by the authentication server, and at (514), the requested user PII and / or PCI data is transmitted to the merchant website via a backend encrypted channel and subsequently applied to a specific user transaction session (e.g., auto-filled on an online payment interface displaying the custom link).

[0056] Figure 6 An exemplary timing diagram (600) is shown relating to an automated process for securely retrieving sensitive user information that is verified based on one or more user authentication data that is securely stored as NFC transmittable data on an integrated memory of a contactless card (601) and retrieved by a user mobile device (602) via an encrypted NFC channel (603) established between the contactless card (601) and the user mobile device (602). The information may then be transmitted to an authentication server (604) via a wireless network connection (605) for verification. Upon verification, the sensitive user information may be provided to a requesting merchant server (606) via an encrypted backend communication channel (607) (e.g., implemented via a backend integration of the merchant server (606) with an authentication and encryption providing system and process).

[0057] The process may be initiated in response to a data request message (608) regarding sensitive user information required to facilitate a particular user transaction. The data request message (608) is generated by the merchant server (606) in response to activation of a custom link presented on a web interface of the merchant server 606 and transmitted to the authentication server (604). The data request message (608) may also include an anonymous unique user session identifier, a merchant website / web server identifier, and initial user identification information. In response to the data request message (608), the authentication server may generate a URI (e.g., a universal link) and transmit the URI (612) to the user mobile device (602).

[0058] The URI may include encoded instructions and an identifier for invoking an authentication application stored on a user mobile device. Upon invocation, according to the instructions in the URI, the mobile authentication application may prompt the user to initiate an NFC read of the contactless card (601) via a reader unit of the user mobile device (602). At (615), the user authentication data in NDEF stored on the contactless card (601) is read by the user mobile device (602), for example, by tapping the contactless card to a reader of the user mobile device to initiate an NFC transfer. An authentication server (604) is used to verify the user authentication data at (617), the authentication server may retrieve the requested sensitive user information at (618), and transmit the requested sensitive user information to the requesting merchant server (606) via an encrypted communication link (607) at (620) - in some cases, the user PCI data may correspond to a primary account number, which may be provided to the requesting merchant server as part of the requested information via the encrypted communication channel (607). However, in some embodiments, operations (618) related to retrieving sensitive user information (e.g., collecting user PII data) may also involve generating a merchant-specific virtual credit card number (VCN) mapped to the user's primary account, which may be provided in the transmission (620) as a substitute for the user's PAN. At (622), the received (sensitive) user information is automatically populated on the appropriate transaction form provided by the merchant server (606).

[0059] Figure 7 A block diagram of an exemplary embodiment of a system according to the present disclosure is shown. For example, the exemplary processes according to the present disclosure described herein may be performed by a processing device and / or computing device (e.g., a computer hardware device) 705. Such a processing device and / or computing device 705 may be, for example, all or part of a computer / processor 710, or include, but are not limited to, a computer / processor 710, which may include, for example, one or more microprocessors and use instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard drive, or other storage device).

[0060] like Figure 7 As shown, for example, a computer-accessible medium 715 (e.g., a storage device such as a hard disk, a floppy disk, a memory stick, a CD-ROM, a RAM, a ROM, etc., or a collection thereof, as described above) may be provided (e.g., in communication with the processing device 705). The computer-accessible medium 715 may contain executable instructions 720. Additionally or alternatively, a storage device 725 may be provided separately from the computer-accessible medium 715, which may provide instructions to the processing device 705 so as to configure the processing device to perform the exemplary processes, procedures, and methods, for example, as described above.

[0061] In addition, the exemplary processing device 705 may be equipped with or include an input / output port 735, which may include, for example, a wired network, a wireless network, the Internet, an intranet, a data collection probe, a sensor, etc. Figure 7 As shown, the exemplary processing device 705 can communicate with an exemplary display device 730, which according to certain exemplary embodiments of the present disclosure can be a touch screen configured to input information to the processing device in addition to outputting information from the processing device. In addition, the exemplary display device 730 and / or the storage device 725 can be used to display and / or store data in a user-accessible format and / or a user-readable format.

[0062] As used herein, the term "card" is not limited to a specific type of card. More specifically, it is understood that, unless otherwise specified, the term "card" may refer to a contact-based card, a contactless card, or any other card. It is further understood that the present disclosure is not limited to cards with specific purposes (e.g., payment cards, gift cards, identification cards, membership cards, transportation cards, access cards), cards associated with specific types of accounts (e.g., credit accounts, debit accounts, membership accounts), or cards issued by specific entities (e.g., commercial entities, financial institutions, government entities, social clubs). On the contrary, it should be understood that the present disclosure includes cards with any purpose, account association, or issuing entity.

[0063] The systems and methods described herein can provide secure retrieval of sensitive user information, or enable streamlined communication and processing of sensitive user information, for example, to facilitate secure electronic transactions. Once a valid authorization response from an authenticated user is established, the automated data retrieval and delivery systems and processes can allow, but are not limited to, financial transactions (e.g., credit and debit card transactions), account management transactions (e.g., card refresh, card replacement, and new card addition transactions), membership transactions (e.g., join and leave transactions), access point transactions (e.g., building access and secure store access transactions), transportation transactions (e.g., ticketing and boarding transactions), and other transactions.

[0064] As used herein, Personally Identifiable Information (PII) may include any sensitive data, including financial data (e.g., account information, account balances, account activity), personal and / or personally identifiable information (e.g., social security number, home or work address, date of birth, telephone number, email address, passport number, driver's license number), access information (e.g., passwords, security codes, authorization codes, biometric data), and any other information that a user may wish to avoid disclosure to unauthorized persons.

[0065] The present disclosure is not limited by the specific embodiments described in this application, which are intended to illustrate various aspects. Obviously, many modifications and changes can be made without departing from its spirit and scope. In addition to those listed herein, functionally equivalent methods and devices within the scope of the present disclosure can be apparent from the above representative descriptions. Such modifications and changes are intended to fall within the scope of the attached representative claims. The present disclosure is only limited by the terms of the attached representative claims and the full range of equivalents enjoyed by such representative claims. It should also be understood that the terms used herein are only used to describe specific embodiments and are not intended to be limited.

[0066] It is further noted that the systems and methods described herein may be tangibly embodied in one or more physical media, such as, but not limited to, compact disks (CDs), digital versatile disks (DVDs), floppy disks, hard disks, read-only memories (ROMs), random access memories (RAMs), and other physical media capable of storing data. For example, data storage may include random access memories (RAMs) and read-only memories (ROMs), which may be configured to access and store data and information as well as computer program instructions. Data storage may also include storage media or other suitable types of memory (e.g., such as RAMs, ROMs, programmable read-only memories (PROMs), erasable programmable read-only memories (EPROMs), electrically erasable programmable read-only memories (EEPROMs), magnetic disks, optical disks, floppy disks, hard disks, removable ink cartridges, flash drives, any type of tangible and non-transitory storage media) in which files including an operating system, applications including, for example, web browser applications, email applications, and / or other applications, and data files may be stored. The data storage of a network-enabled computer system may include electronic information, files, and documents stored in a variety of ways, including, for example, flat files, indexed files, hierarchical databases, relational databases, such as from, for example, Corporation's software creates and maintains databases, Excel files, Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage (which may include online or cloud storage), or any other storage mechanism. In addition, these figures illustrate various components (e.g., servers, computers, processors, etc.) separately. Functions described as being performed at various components may be performed at other components, and various components may be combined or separated. Other modifications are also possible.

[0067] In the foregoing description, various embodiments have been described with reference to the accompanying drawings. However, it will be apparent that various modifications and changes may be made thereto, and that additional embodiments may be implemented, without departing from the broader scope of the invention as set forth in the following claims. Accordingly, the description and drawings should be regarded as illustrative rather than restrictive.

Claims

1. A method for facilitating automatic delivery of authentication user information based on context switch authentication, the method comprising: Providing a custom link on an interface of a website, wherein the website is integrated with authentication functionality provided by an external authentication system; In response to a user selection of the custom link, a universal link is generated, wherein the universal link includes: a website identifier that identifies the website where the custom link was selected by the user to be activated, a unique anonymous user identifier that is generated by the website to track a specific user session, and an identifier for an authentication application associated with the external authentication system, wherein the authentication application is stored on a user device from which the website is accessed; transmitting the universal link to the user device, wherein the universal link is configured to launch the authentication application that prompts a user to perform an authentication action, the authentication action comprising carrying a contactless card with a near field communication (NFC) tag within a near field communication (NFC) range of the user device, the NFC tag storing one or more user identity and payment credential information as NFC transmittable data; One or more user identity and credential information retrieved from the contactless card via NFC is transmitted to be automatically populated on an interface of the website.

2. The method according to claim 1, wherein: The universal link includes an identifier for a data collection application having a deep link to an authentication functionality provided by the external authentication system, wherein the authentication functionality is integrated into the data collection application.

3. The method according to claim 2, wherein: The authentication functionality is provided by an authentication application stored on the user device and operatively coupled to the data collection application.

4. The method according to claim 2, wherein: The user identity and credential information is collected by the data collection application and transmitted to the requesting website after verifying the user authentication information retrieved from the contactless card via NFC.

5. The method according to claim 1, wherein: The website identifier and unique anonymous user identifier information in the universal link are used to identify a specific user session associated with the authentication action.

6. The method according to claim 1, wherein: The authentication action further includes at least one selected from the group of inputting login credentials into the authentication application and confirming identity by inputting a temporary one-time password, the temporary one-time password being sent to the user device as at least one selected from the group of text and voice.

7. The method according to claim 1, wherein: The user identity and credential information transmitted from the contactless card to the authentication application on the user device via NFC is encrypted using symmetric encryption.

8. The method according to claim 7, wherein: One or more user identity and credential information transmitted by the user device to the website is encrypted using a public key cryptographic process, wherein the user identity and credential information is decrypted prior to automatically populating an interface of the website.

9. The method according to claim 1, wherein: If the authentication app is not installed on the user device, the universal link is encoded to redirect the user to an app store to download the authentication app.

10. An authentication system for realizing automatic retrieval of authentication user information based on context switching authentication, the system comprising: A link generation server, which is communicatively coupled to one or more network servers via a network, the link generation computer is configured to: displaying a custom link on an interface of a website associated with each of the one or more network servers, wherein the website is integrated with authentication functionality provided by the authentication system; In response to a user selection of the custom link, a universal link is generated, wherein the universal link includes: a website identifier that identifies the website where the custom link was selected by the user to be activated, A unique anonymous user identifier generated by the website to track a specific user session, and An identifier for an authentication application associated with the authentication system, wherein the authentication Verify that the application is stored on the user device from which the website is accessed; transmitting the universal link to the user device, the universal link launching the authentication application to prompt the user to perform an authentication action, the authentication action comprising carrying a contactless card with an NFC tag within a near field communication (NFC) range of the user device, the NFC tag storing one or more user identities and credential information as NFC transmittable data; One or more user identity and credential information retrieved from the contactless card via NFC transmission is communicated by the authentication application running on the user device to be automatically populated on an interface of the website.

11. The authentication system according to claim 10, wherein: The universal link is configured with an identifier for a data collection application, the data collection application having a deep link to an authentication functionality provided by the authentication system, wherein the authentication functionality is integrated in the data collection application.

12. The authentication system according to claim 11, wherein: The authentication functionality is provided by an authentication application stored on the user device and operatively coupled to the data collection application.

13. The authentication system according to claim 11, wherein: The system is configured to collect user identity and credential information using the data collection application and authenticate the delivery of user identity and payment credential information to the website based on verification of user authentication information retrieved from the contactless card via the NFC transmission.

14. The authentication system according to claim 10, wherein: The authentication system is configured to identify a specific user session associated with the authentication action based on the website identifier and the unique anonymous user identifier information in the universal link.

15. The authentication system according to claim 10, wherein: The authentication system is also configured for one or more authentication actions, including one or more of: entering login credentials into the authentication application, and confirming identity by entering a temporary one-time password, which is sent to the user device as one of a text message, a voice message, and a pop-up notification.

16. The authentication system according to claim 10, wherein: The authentication system is further configured to encrypt the user identity and credential information transmitted from the contactless card via NFC using a symmetric encryption scheme.

17. The authentication system according to claim 10, wherein: The authentication system is also configured to encrypt, using a public key encryption scheme, the user identity and credential information transmitted to the website where the custom link is selected by the user to be activated.

18. A non-transitory computer-readable medium comprising instructions for execution by a computer hardware device, wherein: When executing the instructions, the computer hardware device is configured to perform a process including: Displaying a custom link on a website interface, wherein the website is integrated with an authentication function provided by an external authentication system; In response to a user selection of the custom link, a universal link is generated, the universal link comprising: a website identifier identifying the website in which the custom link was selected by the user to be activated; A unique anonymous user identifier generated by the website to track a specific user session; an identifier for an authentication application associated with the external authentication system, wherein the authentication application is stored on a user device from which the website is accessed; transmitting the universal link to the user device, wherein the universal link launches the authentication application that prompts a user to perform an authentication action, the authentication action comprising carrying a contactless card with a near field communication (NFC) tag within a near field communication (NFC) range of the user device, the NFC tag storing one or more user identities and credential information as NFC transmittable data; One or more user identity and credential information retrieved from the contactless card via NFC transmission is transmitted by the user device to be automatically populated on an interface of a website in which the custom link is selected by the user to be activated.

19. The non-transitory computer readable medium of claim 19, wherein: The non-transitory computer-readable medium also includes instructions for encrypting user identity and payment credential information transmitted from the contactless card via NFC to an authentication application on the user device with symmetric encryption using a symmetric encryption scheme.