System and method for dynamic data generation and cryptographic card authentication

By using processors and memory in the authentication system to dynamically generate virtual card numbers and security codes, the problem of static card numbers being easily attacked and data transmission security risks is solved, and higher security and transaction efficiency are achieved.

CN120051789APending Publication Date: 2025-05-27CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202380073535.9
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2022-08-17
Filing Date
2023-08-14
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

In the prior art, the generated virtual card number is static and is easily brutally attacked by malicious actors, resulting in security vulnerabilities. In addition, data transmission without encryption or protection is vulnerable to malicious attacks, increasing security risks.

Method used

By using processors and memory in the authentication system, virtual card numbers and dynamic security codes are generated. The system receives an authentication request, maps and generates a virtual card number and a dynamic security code based on multiple parameters of the unique identifier, counter, session key and main account serial number, and sends it to complete the authentication request.

Benefits of technology

By dynamically generating virtual card numbers and security codes, the risk of brute-force attacks of static card numbers is reduced, the security of data transmission is enhanced, and the obstacles to system resource consumption and transaction efficiency are avoided.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120051789A_ABST
    Figure CN120051789A_ABST
Patent Text Reader

Abstract

Systems and methods for authentication may include an authentication system. The authentication system may include a processor and a memory. The memory may contain a unique identifier, a counter, a session key, and a PAN sequence number. The processor may be configured to receive an authentication request. The processor may be configured to, in response to an authentication request, generate a virtual card number and a dynamic security code based on a mapping with a plurality of parameters of a password, the plurality of parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN sequence number. The processor may be configured to send the virtual card number and the dynamic security code to complete the authentication request.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross - Reference to Related Applications

[0002] This application claims priority to U.S. Patent Application No. 17 / 890,077, filed on August 17, 2022, the disclosure of which is incorporated herein by reference in its entirety. Technical Field

[0003] This disclosure relates to systems and methods for dynamic data generation and cryptographic card authentication. Background Art

[0004] Electronic and card - based transactions are becoming increasingly common. These transactions typically involve the use of a card that communicates with a point - of - sale device, a server, or other devices. It is necessary to protect such communications from interception and unauthorized access. Virtual card numbers can provide a way for users to use an account without exposing the underlying account number.

[0005] Currently, the generated virtual card numbers are static in nature and thus vulnerable to malicious actors. For example, malicious actors seeking unauthorized account access and abuse of account information may perform brute - force attacks on static virtual card numbers, which results in security vulnerabilities.

[0006] In addition, unencrypted or otherwise unprotected data transmissions are vulnerable to malicious attacks, data interception, and may have other vulnerabilities, leading to increased security risks and an increased risk of account or card abuse. These risks may be further increased by using contactless cards that communicate wirelessly with other devices.

[0007] Measures taken to address security risks may consume system resources and impede operational efficiency. For a large number of transactions, the consumption of system resources and the hindrance of transaction efficiency may increase, which may result in failed transaction executions or unsatisfactory performance.

[0008] These and other deficiencies exist. Accordingly, there is a need to securely and dynamically generate data and perform card authentication cryptographically. Summary of the Invention

[0009] Embodiments of the present disclosure provide an authentication system. The authentication system may include a processor and a memory. The memory may contain a unique identifier, a counter, a session key, and a Primary Account Number (PAN) serial number. The processor may be configured to receive an authentication request. The processor may be configured to, in response to the authentication request, generate a virtual card number and a dynamic security code based on a mapping of a plurality of parameters with a password, the plurality of parameters including at least one selected from the group consisting of the unique identifier, the counter, the session key, and the PAN serial number. The processor may be configured to send the virtual card number and the dynamic security code to complete the authentication request.

[0010] Embodiments of the present disclosure provide an authentication method. The method may include receiving an authentication request. The method may include: in response to the authentication request, a processor generates a virtual card number and a dynamic security code based on a mapping of a plurality of parameters of a password, the plurality of parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a PAN serial number. The method may include: the processor sends the virtual card number and the dynamic security code to complete the authentication request.

[0011] Embodiments of the present disclosure provide a computer-accessible non-transitory medium including computer-executable instructions that, when executed on a processor, perform a process including the steps of: receiving an authentication request; in response to the authentication request, generating a virtual card number and a dynamic security code based on a mapping of a plurality of parameters of a password, the plurality of parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a PAN serial number; and sending the virtual card number and the dynamic security code to complete the authentication request. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] Various embodiments of the present disclosure and other objects and advantages can be better understood by reference to the following description and in conjunction with the accompanying drawings.

[0013] Figure 1 An authentication system according to an exemplary embodiment is depicted.

[0014] Figure 2A It is an illustration of a first device according to an exemplary embodiment.

[0015] Figure 2B It is an illustration of a contact pad of a first device according to an exemplary embodiment.

[0016] Figure 3 An authentication method according to an exemplary embodiment is depicted.

[0017] Figure 4A A sequence diagram of an authentication process according to an exemplary embodiment is depicted.

[0018] Figure 4B A sequence diagram of an authentication process according to an exemplary embodiment is depicted.

[0019] Figure 4C A sequence diagram of an authentication process according to an exemplary embodiment is depicted.

[0020] Figure 5 An authentication method according to an exemplary embodiment is depicted. DETAILED DESCRIPTION

[0021] The following description of embodiments provides non - limiting representative examples of reference numerals to specifically describe the features and teachings of different aspects of the present disclosure. The described embodiments should be considered capable of being implemented separately from or in combination with other embodiments in the description of the embodiments. A person of ordinary skill in the art reading the description of the embodiments should be able to learn and understand the different described aspects of the present disclosure. The description of the embodiments should contribute to an understanding of the present disclosure to such an extent that other embodiments not specifically covered but within the knowledge of a person of ordinary skill in the art after reading the description of the embodiments will be understood to be consistent with the application of the present disclosure.

[0022] The systems and methods disclosed herein are capable of providing and using dynamic card verification values for generated virtual card numbers. This implementation provides a controlled utilization of these parameters and can only be refreshed when the card is actually in possession. By doing so, the security vulnerabilities associated with virtual card numbers can be reduced. For example, the risks of brute - force attacks and fraud in card - not - present transactions can be reduced, including but not limited to secure verification transactions, authorized access transactions, and other non - e - commerce transactions.

[0023] In addition, the systems and methods disclosed herein allow for the avoidance of phishing attacks, prevention of replay attacks, and authorized interception of data through encrypted data communication. Therefore, the risks of these vulnerabilities and other vulnerabilities can be reduced.

[0024] The disclosed systems and methods facilitate the execution of transactions, improve transaction efficiency, and effectively utilize system resources. These benefits become increasingly important as the volume of transactions increases.

[0025] In addition, the systems and methods disclosed herein achieve these benefits without degrading the user experience. By enhancing the user experience, users will be more likely to participate in more secure transactions.

[0026] Figure 1 An authentication system 100 is shown. System 100 may include a first device 105, a second device 110, a network 115, a server 120, and a database 125. Although Figure 1 a single instance of the components of system 100 is shown, system 100 may include any number of components.

[0027] System 100 may include a first device 105. The first device 105 may include a contactless card, a contact-based card, a networked computer, or other devices described herein. As referred to herein, a networked computer may include, but is not limited to, a computer device or a communication device, including, for example, a server, a network device, a personal computer, a workstation, a telephone, a handheld PC, a personal digital assistant, a contactless card, a thin client, a fat client, an Internet browser, a kiosk, a tablet computer, a terminal, a mobile device, a wearable device, a client device, or other devices. As further explained below in Figures 2A - 2B , the first device 105 may include one or more processors 102 and a memory 104. The memory 104 may include one or more applets 106 and one or more counters 108. Each counter 108 may include a counter value. The memory 104 may include counter values, transmission data, unique identifiers, applet version numbers, serial numbers, and a plurality of keys.

[0028] The first device 105 may include a communication interface 107. The communication interface 107 may include communication capabilities with a physical interface and a contactless interface. For example, the communication interface 107 may be configured to communicate with a physical interface, such as swiping a card through a card-swipe interface or inserting a card chip reader found on an automated teller machine (ATM) or other devices configured to communicate through a physical interface. In other examples, the communication interface 107 may be configured to establish contactless communication with a card-reading device via short-range wireless communication methods such as near field communication (NFC), Bluetooth, Wi-Fi, radio frequency identification (RFID), and other forms of contactless communication. As Figure 1 shown, the communication interface 107 may be configured to communicate directly with a second device 110, a server 120, and / or a database 125 via a network 115.

[0029] The first device 105 may communicate data with any number of components of the system 100. For example, the first device 105 may transmit data to the second device 110 and / or the server 120 via the network 115. The first device 105 may transmit data to the database 125 via the network 115. In some examples, the first device 105 may be configured to transmit data via the network 115 after entering one or more communication fields of any device. Non-limitingly, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof.

[0030] System 100 may include a second device 110. The second device 110 may include one or more processors 112 and a memory 114. The memory 114 may be a transient and / or non-transient memory and may include one or more applications (including but not limited to application 116). The second device 110 may communicate data with any number of components of the system 100. For example, the second device 110 may transmit data to the server 120 via the network 115. The second device 110 may transmit data to the database 125 via the network 115. Without limitation, the second device 110 may be a networked computer. The second device 110 may also be a mobile device; for example, the mobile device may include an iPhone, iPod, iPad from or any other mobile device running the Apple operating system, any device running Microsoft's mobile operating system, any device running Google's operating system and / or any other smart phone, tablet or similar wearable mobile device.

[0031] The second device 110 may include processing circuitry and may contain additional components required to perform the functions described herein, including processors, memories, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware. The second device 110 may also include a display and an input device. The display may be any type of device for presenting visual information, such as a computer monitor, a flat panel display, and a mobile device screen, including a liquid crystal display, a light emitting diode display, a plasma panel, and a cathode ray tube display. The input device may include any device for inputting information into the user device, which is available and supported by the user device, such as a touch screen, a keyboard, a mouse, a cursor control device, a touch screen, a microphone, a digital camera, a video camera, or a portable video camera. These devices may be used to input information and interact with the software and other devices described herein.

[0032] System 100 may include network 115. In some examples, network 115 may be a wireless network, a wired network, or any combination of one or more of a wireless network and a wired network, and may be configured to connect to any one component of system 100. For example, the first device 105 may be configured to connect to the server 120 via network 115. In some examples, network 115 may include a fiber optic network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communications service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short messaging service, a time-division multiplexing-based system, a code-division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n, and 802.11g, Bluetooth, NFC, RFID, Wi-Fi, etc.

[0033] In addition, network 115 may include, but is not limited to, a telephone line, fiber optic, IEEE Ethernet 902.3, a wide area network, a wireless personal area network, a LAN, or a global network such as the Internet. In addition, network 115 may support an Internet network, a wireless communication network, a cellular network, etc., or any combination thereof. Network 115 may also include one network, or any number of the above-exemplified types of networks, operating independently or in cooperation with each other. Network 115 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 115 may convert other protocols into one or more protocols of network devices, or from other protocols into one or more protocols of network devices. Although network 115 is depicted as a single network, it should be understood that, according to one or more examples, network 115 may include multiple interconnected networks, such as the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, and a home network.

[0034] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors 122 coupled to a memory 124. Server 120 may be configured as a central system, server, or platform that controls and invokes various data at different times to perform multiple workflow actions. Server 120 may be configured to connect to a first device 105. Server 120 may communicate data with applet 106 and / or application 116. For example, server 120 may communicate data with applet 106 via one or more networks 115. The first device 105 may communicate with one or more servers 120 via one or more networks 115 and may operate as a corresponding front-end to back-end pair with server 120. The first device 105 may, for example, send one or more requests to server 120 from applet 106 executing thereon. The one or more requests may be associated with obtaining data from server 120. Server 120 may receive the one or more requests from the first device 105. Based on the one or more requests from applet 106, server 120 may be configured to obtain the requested data. Server 120 may be configured to send the received data to applet 106, the received data in response to the one or more requests.

[0035] In some examples, server 120 may be a dedicated server computer such as a blade server, or may be a personal computer, laptop, notebook computer, palmtop computer, network computer, mobile device, wearable device, or any processor-controlled device capable of supporting system 100. Although Figure 1 a single server 120 is shown, it should be understood that other embodiments may use multiple servers or multiple computer systems to support users as needed or desired, and may also use backup or redundant servers to prevent network downtime in the event of a failure of a particular server.

[0036] Server 120 may include an application that includes instructions for execution thereon. For example, the application may include instructions for execution on server 120. The application of server 120 may communicate with any component of system 100. For example, server 120 may execute one or more applications that are capable of, for example, network and / or data communication with one or more components of system 100 and sending and / or receiving data. By way of non-limitation, server 120 may be a networked computer. As described herein, a networked computer may include, but is not limited to, a computer device or communication device, including, for example, a server, network device, personal computer, workstation, telephone, handheld PC, personal digital assistant, contactless card, thin client, fat client, Internet browser, or other device. Server 120 may also be a mobile device; for example, a mobile device may include components from iPhone, iPod, iPad, or any other mobile device running the Apple operating system, any device running Microsoft's mobile operating system, any device running Google's operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0037] As required to perform the functions described herein, server 120 may include processing circuitry and may contain additional components, including a processor, memory, error and parity / CRC checker, data encoder, anti-collision algorithm, controller, command decoder, security primitive, and tamper-resistant hardware. Server 120 may also include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input devices may include any device for inputting information into the user device, which is available and supported by the user device, such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder, or portable camera. These devices may be used to input information and interact with the software and other devices described herein.

[0038] System 100 may include one or more databases 125. Databases 125 may include relational databases, non-relational databases, or other database implementations and any combination thereof including multiple relational and non-relational databases. In some examples, databases 125 may include desktop databases, mobile databases, or in-memory databases. Additionally, databases 125 may be internally hosted by any component of system 100, such as first device 105 or server 120, or databases 125 may be externally hosted by a cloud-based platform to any component of system 100, such as first device 105 or server 120, or externally hosted in any storage device that communicates data with first device 105 and server 120. In some examples, databases 125 may communicate data with any number of components of system 100. For example, server 120 may be configured to obtain the requested data sent by applet 106 from database 125. Server 120 may be configured to transmit the received data from database 125 to applet 106 via network 115, the received data in response to one or more requests sent. In other examples, applet 106 may be configured to send one or more requests for the requested data from database 125 via network 115.

[0039] In some examples, the exemplary processes of the present disclosure described herein may be performed by a processing device and / or a computing device (e.g., a computer hardware device). Such a processing / computing device may be, for example, all or a part of a computer / processor, or include, but not be limited to, a computer / processor, which may include, for example, one or more microprocessors, and use instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device). For example, the computer-accessible medium may be a part of the memory of the first device 105, the second device 110, the server 120, and / or the database 125, or other computer hardware devices.

[0040] In some examples, a computer-accessible medium may be provided (e.g., as described above, such as storage devices like hard disks, floppy disks, memory sticks, CD-ROMs, RAMs, ROMs, etc., or a collection thereof) (e.g., in communication with the processing device). The computer-accessible medium may contain executable instructions thereon. Additionally or alternatively, a storage device may be provided separately from the computer-accessible medium, which may provide instructions to the processing device to configure the processing device to perform certain exemplary processes, procedures, and methods, e.g., as described above.

[0041] The processor 102 may be configured to receive an authentication request. In some examples, the processor 102 may be configured to receive an authentication request from any device, which includes but is not limited to the client device 110. In other examples, the application 116 of the client device 110 may be configured to receive an authentication request from the processor 122 of the server 120. The application 116 of the client device 110 may be configured to perform one or more reads of a first device 105 such as a card. For example, the application 116 may be configured to perform a read such as a near-field communication read of a tag of the first device 105. In some examples, the application 116 may be configured to read information including a unique identification number associated with the first device, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), or a shared secret. In some examples, the application 116 may be configured to read a password generated using one or more cryptographic algorithms. The password may be dynamically generated in response to an authentication request as described herein. In some examples, the shared secret may be a number known or derived by the server 120 and / or the client device 110 and stored on the first device 105. The shared secret may be included in the password calculation (e.g., used in a password operation and by a cryptographic algorithm), but is not transmitted between any devices.

[0042] Processor 102 may be configured to generate a virtual card number and a dynamic security code in response to an authentication request, based on a mapping to a plurality of parameters of a password, the plurality of parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a primary account number (PAN) serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number may include up to a total of 16 digits, but is not limited thereto. Similarly non - restrictively, the dynamic security code may include a card verification value. For example, the card verification value may include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non - zero.

[0043] Processor 102 may be configured to send data in response to a read (such as a first read) after entering one or more communication fields of any device (including but not limited to the second device 110). For example, processor 102 may be configured to send a password after first entering the first communication field of the second device 110. Non - restrictively, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. Upon request, the password may be received via a Near Field Communication Data Exchange Format (NDEF) reader. Processor 102 may be configured to send the password. In some examples, processor 102 may be configured to encrypt the password before its transmission. For example, processor 102 may be configured to generate a plurality of session keys such as a first session key and a second session key using a secret key in combination with a counter. A message authentication code (MAC) may be generated with the first session key. The MAC may be encrypted with the second session key before its transmission for decryption and verification. The processor 122 of the server 120 may be configured to generate a unique derived key using a unique identifier and a master key. The processor of the server 120 may be configured to generate a session key based on the unique derived key and a counter. The processor 122 of the server 120 may be configured to decrypt the encrypted MAC based on the password. The processor 122 of the server 120 may be configured to verify the MAC using the session key.

[0044] Processor 102 may be configured to send the password via the communication interface 107. For example, processor 102 may be configured to send the password to one or more applications such as application 116. In some examples, processor 102 may be configured to send the password to application 116 that includes instructions for execution on the second device 110. Processor 102 may be configured to update the counter value after the transmission of the password.

[0045] In some examples, the processor 122 of the server 120 may be configured to receive a password sent by the processor 102 which is sent by the processor 112. The application 116 of the client device 110 may be configured to send the password to the processor 122 of the server 120 via the processor 102. The processor 122 of the server 120 may be configured to decrypt the password.

[0046] The processor 102 may also be configured to limit the virtual card number to limited use. In other examples, it should be understood that the processor 122 of the server 120 may be configured to perform any number of operations performed by the processor 102 of the first device 105. For example, the processor 102 may be configured to limit the virtual card to single use or any number of uses not exceeding a threshold number of times. Additionally, the processor may be configured to limit the virtual card number to be used restrictedly for one type of transaction, a specific merchant, merchant category, and / or transactions at or near a specific location or to exclude one type of transaction, a specific merchant, merchant category, and / or transactions at or near a specific location. By way of non-limitation, the processor may be configured to determine the limitation based on an evaluation of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0047] In some examples, the processor 102 may be configured to select one or more digits of the password via one or more cryptographic algorithms to generate a virtual card number. For example, the processor 102 may be configured to select the first digit of the password. In another example, the processor 102 may be configured to select the last digit of the password. In another example, the processor 102 may be configured to select any one or more digits and / or any one or more digit sequences between the first digit and the last digit of the password. In another example, the processor 102 may be configured to select any combination of the digits of the password.

[0048] In some examples, the processor 122 of the server 120 may be configured to select one or more digits of the password to generate a virtual card number. In some examples, a digit sequence may be selected. The processor 122 may be configured to generate the virtual card number after successful verification of the password and / or customer data (such as customer identifier, transaction data). The processor 122 may be configured to send the virtual card number to the first device 105.

[0049] In some examples, the processor 102 of the first device 105 may be configured to select a sequence of one or more digits between the first and last digits of a password. In such examples, the processor 122 of the server 120 may be configured to maintain a bitmap to define the sequence order used during dynamic virtual card number generation and verification. The bitmap may be maintained at the virtual card number system level or at the record level.

[0050] In some examples, the processor 102 may also be configured to limit the virtual card number within a time window. For example, the processor 102 may be configured to limit the use of the virtual card number to a time window range including a first value and a second value. In some examples, the processor 102 may be configured to limit the use of the dynamic security code within the time window. Additionally, the processor 102 may be configured to invalidate the dynamic security code if it is not used within the time window. Non-limitingly, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0051] Thus, when the user is prompted to enter the virtual card number and the dynamic security code, including but not limited to providing information via the application 116 of the second device 110 to a website to process a transaction, the processor 102 of the first device 105 may enter the communication field of the device to send this information, along with the password, to the device. In this way, the application 116 of the second device 110 may be configured to send the password including a counter to the processor 122 of the server 120. The processor 122 of the server 120 may be configured to allow the dynamic security code and the virtual card number within a specified time window until the counter is adjusted. Thus, this implementation can limit the use of the virtual card number, and this requires the physical card itself and the dynamic security code.

[0052] In addition, the processor 102 may also be configured to synchronize the counter with the server during the time window. For example, the processor 102 may be configured to adjust the counter. In some examples, the processor 102 may be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In other examples, the processor 102 may be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The incrementing and / or decrementing may be determined by the processor 102 according to a sequence. For example, the processor 102 may be configured to increment the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of brute force attacks. For example, the processor 102 may be configured to decrement the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of brute force attacks. It should also be understood that the sequence may be selected by the processor to avoid increasing the processing load on the first device 105. In this way, one or more cryptographic algorithms may be configured to generate a sufficiently high entropy value for the dynamic security code, which may reduce the possibility of brute force attacks. Therefore, the processor 122 of the server 120 may be configured to record the adjusted (such as incremented or decremented) card counter so as to associate it with the dynamic security code and the virtual card number, and also avoid desynchronization with the first device 105. In the case where the processor 102 of the first device 105 does not enter the communication field of the second device 110 (such as the aforementioned tap, swipe, or wave), the dynamic security code and the virtual card number generated by the card will not be sent, and thus the authentication request will not be compliant.

[0053] The dynamic generation of the security code may be possible only after the processor 120 of the server 120, for example, successfully verifies the password. In addition, integration with the application 116 of the second device 110 may also be required before the security code is generated.

[0054] The processor 102 may also be configured to encrypt the virtual card number and the dynamic security code using a session key (such as the generated session key described herein). After successfully verifying the password and / or customer data, the mobile application 116 may be configured to display the virtual card number and the dynamic security code. Successful verification may be required before the virtual card number and the dynamic security code are displayed and / or used. The display and / or use of the virtual card number and the dynamic security code may be limited to authorized applications and devices such as the application 116 and the server 120. The decryption of the virtual card number and the dynamic security code may be controlled by the hardware security modules of the second device 110 and the server 120 and / or the management and integration application programming interfaces.

[0055] The processor 102 can be configured to send a virtual card number and a dynamic security code to complete an authentication request. For example, the processor 102 can be configured to send a virtual card number and a dynamic security code in response to the scanning of a Quick Response (QR) code. In some examples, the processor 102 can be configured to send a virtual card number and a dynamic security code via a notification. Non-limitingly, the notification can include at least one selected from the group consisting of a pop-up notification, a Short Message Service, and a QR code. The notification can be displayed by an application 116 of the second device 110.

[0056] In some examples, the processor 102 can also be configured to encrypt the virtual card number and the dynamic security code before transmission. The processor 102 can be configured to perform the encryption using a session key such as the generated session key described herein. The display and / or use of the virtual card number and the dynamic security code are only allowed after the password and / or customer data have been successfully verified and are restricted to authorized applications and devices such as the application 116 and the server 120. The decryption of the virtual card number and the dynamic security code can be controlled by the hardware security modules of the second device 110 and the server 120 and / or the management and integration application programming interfaces.

[0057] Figure 2A and 2B shows one or more first devices 200. As explained above with reference to Figure 1 The first device 200 can refer to the same or similar components of the first device 105. Although Figure 2A and 2B illustrates a single instance of the components of the first device 200, any number of components can be used.

[0058] The first device 200 may be configured to communicate with one or more components of the system 100. The first device 200 may include a contact-based card or a contactless card, which may include a payment card issued by a service provider 205 and displayed on the front or back of the contactless card 200, such as a credit card, a debit card, or a gift card. In some examples, the contactless card 200 is not related to a payment card and may include, but is not limited to, an identification card, a membership card, an access card, and a transportation card. The contactless card 200 may include a substrate 210, which may include a single layer or one or more laminated layers made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 200 may have physical characteristics in the ID-1 format compliant with the ISO / IEC 7810 standard, and the contactless card may otherwise comply with the ISO / IEC 14443 standard. However, it should be understood that the contactless card 200 according to the present disclosure may have different characteristics, and the present disclosure does not require the implementation of the contactless card in a payment card.

[0059] The contactless card 200 may further include identification information 215 displayed on the front and / or back of the card, as well as contact pads 220. The contact pads 220 may be configured to establish contact with another communication device (including but not limited to a user device, a smartphone, a laptop, a desktop, or a tablet). The contactless card 200 may further include a processing circuit, an antenna, and Figure 2A other components not shown in Figure 2A . These components may be located behind the contact pads 220 or elsewhere on the substrate 210. The contactless card 200 may further include a magnetic stripe or a magnetic tape, which may be located on the back of the card (

[0060] As Figure 2B shown, Figure 2A the contact pads 220 may include a processing circuit 225 for storing and processing information, which includes a processor 230 such as a microprocessor and a memory 235. It should be understood that the processing circuit 225 may include additional components required to perform the functions described herein, and the additional components include a processor, a memory, an error and parity / CRC checker, a data encoder, an anti-collision algorithm, a controller, a command decoder, security primitives, and anti-tampering hardware.

[0061] The memory 235 can be a read-only memory, a write-once read-many memory, or a read / write memory (such as RAM, ROM, and EEPROM), and the contactless card 200 can include one or more of these memories. The read-only memory can be a factory-programmable read-only memory or a one-time programmable memory. The one-time programmability provides an opportunity to write once and then read many times. The write-once / read-many memory can be programmed at some point after the memory chip leaves the factory. Once the memory is programmed, it may not be rewritten, but it may be read many times. The read / write memory can be programmed and reprogrammed many times after leaving the factory. It may also be read many times.

[0062] The memory 235 can be configured to store one or more applets 240, one or more counters 245, and a customer identifier 250. The one or more applets 240 can include one or more software applications such as Java Card applets configured to execute on one or more contactless cards. However, it should be understood that the applets 240 are not limited to Java Card applets, but can be any software application operable on a contactless card or other device with limited memory. The one or more counters 245 can include digital counters sufficient to store integers. The customer identifier 250 can include a unique alphanumeric identifier assigned to the user of the contactless card 200, and this identifier can distinguish the user of the contactless card from other contactless card users. In some examples, the customer identifier 250 can identify a customer and the account assigned to that customer, and can also identify the contactless card associated with the customer account.

[0063] The processor and storage elements of the foregoing exemplary embodiments are described with reference to the contact pad, but the present disclosure is not limited thereto. It should be understood that these elements can be implemented external to the contact pad 220, or can be completely separated from the contact pad, or can be implemented as other elements outside the processor 230 and memory 235 elements located within the contact pad 220.

[0064] In some examples, the contactless card 200 can include one or more antennas 255. The one or more antennas 255 can be placed within the contactless card 200 and surround the processing circuit 225 of the contact pad 220. For example, the one or more antennas 255 can be integrated with the processing circuit 225, and the one or more antennas 255 can be used with an external boost coil. As another example, the one or more antennas 255 can be external to the contact pad 220 and the processing circuit 225.

[0065] In one embodiment, the coil of the contactless card 200 can act as the secondary of an air-core transformer. The terminal can communicate with the contactless card 200 by cutting off the power or amplitude modulation. The contactless card 200 can use the gap in the power connection of the contactless card to infer the data sent from the terminal, which can be functionally maintained by one or more capacitors. The contactless card 200 can communicate by switching the load on the coil of the contactless card or load modulation. The load modulation may be detected by interference in the terminal coil.

[0066] Figure 3 Depicts an authentication method 300. Figure 3 May refer to Figure 2A And Figure 2B The same or similar components of the system 100 and the first device 200.

[0067] At block 310, the method may include: receiving an authentication request by a processor. The processor may belong to the first device, which includes but is not limited to a card, a server, or a client device. In some examples, the processor may be configured to receive an authentication request from any device including but not limited to a mobile device.

[0068] At block 320, the method may include: verifying and approving the authentication request by a processor. This may be performed by any method described herein.

[0069] At block 330, method 300 may include: generating a virtual card number and a dynamic security code by a processor in response to the authentication request, based on a mapping of multiple parameters with a password, the multiple parameters including at least one parameter selected from the group of a unique identifier, a counter, a session key, and a PAN serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number may include up to a total of 16 digits, but is not limited thereto. Similarly non-restrictively, the dynamic security code may include a card verification value. For example, the card verification value may include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non-zero.

[0070] The processor can be configured to send data in response to a read (such as a first read) after entering one or more communication fields of any device. For example, the processor can be configured to send a password after first entering the first communication field of the device. Non - restrictively, each input can be associated with a tap, a swipe, a wave, and / or any combination thereof. The password can be received via a Near Field Communication Data Exchange Format (NDEF) read upon request. The processor can be configured to send the password. In some examples, the processor can be configured to encrypt the password before its transmission. For example, the processor can be configured to generate multiple session keys such as a first session key and a second session key using a secret key in combination with a counter. A MAC can be generated using the first session key. The MAC can be encrypted with the second session key before its transmission for decryption and verification. The server can be configured to generate a unique derived key using a unique identifier and a master key. The server can be configured to generate a session key based on the unique derived key and the counter. The server can be configured to decrypt the encrypted MAC based on the password. The server can be configured to verify the MAC using the session key.

[0071] The processor can be configured to send the password via a communication interface. For example, the processor can be configured to send the password to one or more applications. In some examples, the processor can be configured to send the password to an application that includes instructions for execution on a second device. The processor can be configured to update the counter value after the transmission of the password.

[0072] In some examples, the server can be configured to receive the password sent by the processor. The application of the client device can be configured to have the processor send the password to the server. The server can be configured to decrypt the password.

[0073] At block 340, method 300 can include restricting the virtual card number to limited use. For example, the processor can be configured to restrict the virtual card to single - use or any number of uses not exceeding a threshold number. Additionally, the processor can be configured to restrict the virtual card number to be used restrictively for one type of transaction, a specific merchant, a merchant category, and / or transactions at or near a specific location or to exclude one type of transaction, a specific merchant, a merchant category, and / or transactions at or near a specific location. Non - restrictively, the processor can be configured to determine the restrictions based on an assessment of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0074] In some examples, the processor may be configured to select one or more digits of a password via one or more cryptographic algorithms to generate a virtual card number. For example, the processor may be configured to select the first digit of the password. In another example, the processor may be configured to select the last digit of the password. In another example, the processor may be configured to select any one or more digits and / or any one or more sequences of digits between the first and last digits of the password. In another example, the processor may be configured to select any combination of the digits of the password.

[0075] In some examples, the processor may also be configured to limit the virtual card number within a time window. For example, the processor may be configured to limit the use of the virtual card number within a time window range including a first value and a second value. In some examples, the processor may be configured to limit the use of a dynamic security code within a time window. Additionally, the processor may be configured to invalidate the dynamic security code if it is not used within the time window. Non - restrictively, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0076] Thus, when the user is prompted to enter the virtual card number and the dynamic security code, including but not limited to providing information via a mobile application to a website to process a transaction, the card can enter the communication field of the device and send this information, along with the password, to the device. In this way, the application of the device may be configured to send the password, including a counter, to the server. The server may be configured to allow the dynamic security code and the virtual card number within a specified time window until the counter is adjusted. Thus, this implementation allows for limiting the use of the virtual card number, and this requires the physical card itself and the dynamic security code.

[0077] In addition, the processor can also be configured to synchronize the counter with the server during the time window. For example, the processor can be configured to adjust the counter. In some examples, the processor can be configured to increment the counter with a virtual card number and a dynamic security code during the time window. In other examples, the processor can be configured to decrement the counter with a virtual card number and a dynamic security code during the time window. The incrementing and / or decrementing can be determined by the processor according to a sequence. For example, the processor can be configured to increment the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of brute-force attacks. For example, the processor can be configured to decrement the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of brute-force attacks. It should also be understood that the sequence can be selected by the processor to avoid increasing the processing load on the card. In this way, one or more cryptographic algorithms can be configured to generate a high enough entropy value for the dynamic security code, which can reduce the possibility of brute-force attacks. Therefore, the server can be configured to record the adjusted (such as incremented or decremented) counter of the card to associate it with the dynamic security code and the virtual card number, and also avoid desynchronization with the card. In the case where the card does not enter the communication field (such as the aforementioned tap, swipe, or wave), the dynamic security code and the virtual card number generated by the card cannot be sent, and thus result in non-compliance of the authentication request.

[0078] At block 350, method 300 can include: sending, by a processor, a virtual card number and a dynamic security code to complete an authentication request. For example, the processor can be configured to send a virtual card number and a dynamic security code to complete an authentication request. For example, the processor can be configured to send a virtual card number and a dynamic security code in response to the scanning of a QR code. In some examples, the processor can be configured to send a virtual card number and a dynamic security code via a notification. Non-limitingly, the notification can include at least one selected from the group consisting of a pop-up notification, a short message service, and a QR code. The notification can be displayed by the device.

[0079] Figure 4A Sequence diagram 400 depicting an authentication process according to an exemplary embodiment is shown. Figure 4A Reference can be made to system 100, Figure 2A and Figure 2B the first device 200 of Figure 3 and the same or similar components of method 300 of

[0080] At step 401, the processor may be configured to receive one or more requests. The processor may belong to a first device, which includes but is not limited to a card (or other first device), a server, or a client device, or a combination thereof. In some examples, the processor may be configured to receive an authentication request from any device including but not limited to a client device. The request may be sent from the processor of a server to the processor or application of an intermediate device such as a client device, which may in turn be configured to send the authentication request to the processor of the card.

[0081] At step 402, the processor or application of the client device may be configured to perform one or more reads. For example, the processor or application may be configured to perform a read such as a near field communication read on a tag of the card. Other information that may be read includes a unique identification number associated with the card, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), a shared secret, and a password. In some examples, the password may be generated by the card that includes the read data, and the password may be generated using the read data and / or one or more cryptographic algorithms. In some examples, the shared secret may include a number known or derived by the application and / or the server and stored on the card. The shared secret may be used to generate a password and / or perform password operations using one or more cryptographic algorithms. In some examples, the processor or application of the client device may be configured to display a notification or otherwise prompt for the read.

[0082] At step 403, the processor may be configured to generate a virtual card number and a dynamic security code based on a mapping of multiple parameters of the read data, the multiple parameters including, for example, a password that includes at least one selected from the group of a unique identifier, a counter, a session key, and a PAN serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number may include up to a total of 16 digits, but is not limited thereto. Similarly non - restrictively, the dynamic security code may include a card verification value. For example, the card verification value may include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non - zero.

[0083] In other examples, the processor may receive a virtual card number generated by another device such as a card, a server, or a client device. The virtual card number may be generated upon successful authentication of the received information based on information received from the card (e.g., a unique identifier, a counter, a shared secret). In some examples, the shared secret may be a number known or derived by the server and / or the client device and stored on the first device. The shared secret may be included in password calculations (e.g., used in password operations and by cryptographic algorithms), but is not transmitted between any devices.

[0084] The virtual card number can be generated using an initial or default security code value (such as a security code of zero). The virtual card number can be stored in a virtual card number database and sent to a processor. The virtual card number can be encrypted, for example, using a session key before being transmitted. After receiving the virtual card number, the processor can decrypt the virtual card number and generate a dynamic security code.

[0085] The processor can be configured to send data in response to a read (such as a first read) after entering one or more communication fields of any device. For example, the processor can be configured to send a password after first entering a first communication field of a device. Non - restrictively, each input can be associated with a tap, a swipe, a wave, and / or any combination thereof. Upon request, the password can be received via a Near Field Communication Data Exchange Format (NDEF) reader. The processor can be configured to send the password. In some examples, the processor can be configured to encrypt the first password before its transmission. For example, the processor can be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key in combination with a counter. A MAC can be generated using the first session key. The MAC can be encrypted with the second session key before its transmission for decryption and verification. The server can be configured to generate a unique derived key using a unique identifier and a master key. The server can be configured to generate a session key based on the unique derived key and the counter. The server can be configured to decrypt the encrypted MAC based on the password. The server can be configured to verify the MAC using the session key.

[0086] The processor can be configured to send the password via a communication interface. For example, the processor can be configured to send the password to one or more applications. In some examples, the processor can be configured to send the password to an application that includes instructions for execution on a second device. The processor can be configured to update the counter value after the transmission of the password.

[0087] In some examples, the server can be configured to receive the password sent by the processor. An application of a client device can be configured to send the password to the server via the processor. The server can be configured to decrypt the password.

[0088] At step 404, the processor may be configured to limit the virtual card number to limited use. For example, the processor may be configured to limit the virtual card to single use or any number of uses not exceeding a threshold number of times. Additionally, the processor may be configured to limit the virtual card number to be used restrictively for one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location or to exclude one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location. By way of non-limiting example, the processor may be configured to determine the limitations based on an assessment of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0089] At step 405, the processor may be configured to select one or more digits of a password via one or more cryptographic algorithms to generate the virtual card number. For example, the processor may be configured to select the first digit of the password. In another example, the processor may be configured to select the last digit of the password. In another example, the processor may be configured to select any one or more digits and / or any one or more sequences of digits between the first and last digits of the password. In another example, the processor may be configured to select any combination of the digits of the password.

[0090] In some examples, the processor may also be configured to limit the virtual card number within a time window. For example, the processor may be configured to limit the use of the virtual card number to a range between a first value and a second value within the time window. In some examples, the processor may be configured to limit the use of the dynamic security code within the time window. Additionally, the processor may be configured to invalidate the dynamic security code if it is not used within the time window. By way of non-limiting example, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0091] Thus, when the user is prompted to enter a virtual card number and a dynamic security code, including but not limited to providing information via a mobile application to a website to process a transaction, the card can enter the communication field of the device to send this information, along with the password, to the device. In this way, the application of the device can be configured to send a password including a counter to the server. The server can be configured to allow the dynamic security code and the virtual card number within a specified time window until the counter is adjusted. Thus, this implementation allows restricting the use of the virtual card number and requires the physical card itself and the dynamic security code. Additionally, the processor can be configured to restrict the virtual card number to be used restrictively for one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location or exclude one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location. Non-limitingly, the processor can be configured to determine the restrictions based on an assessment of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0092] Furthermore, the processor can also be configured to synchronize the counter with the server during the time window. For example, the processor can be configured to adjust the counter. In some examples, the processor can be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In other examples, the processor can be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The incrementing and / or decrementing can be determined by the processor according to a sequence. For example, the processor can be configured to increment the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of a brute-force attack. For example, the processor can be configured to decrement the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of a brute-force attack. It should also be understood that the sequence can be selected by the processor to avoid increasing the processing load on the card. In this way, one or more cryptographic algorithms can be configured to generate a sufficiently high entropy value for the dynamic security code, which can reduce the possibility of a brute-force attack. Thus, the server can be configured to record the adjusted (such as incremented or decremented) counter of the card to associate it with the dynamic security code and the virtual card number and also avoid desynchronization with the card. In the case where the card does not enter the communication field (such as the aforementioned tap, swipe, or wave), the dynamic security code and the virtual card number generated by the card will not be sent and will thus result in a non-compliance of the authentication request.

[0093] At step 406, the processor may be configured to send a virtual card number and a dynamic security code to complete the authentication request. For example, the processor may be configured to send the virtual card number and the dynamic security code in response to a scan of a QR code. In some examples, the processor may be configured to send the virtual card number and the dynamic security code via a notification. Non-limitingly, the notification may include at least one selected from the group consisting of a pop-up notification, a short message service, and a QR code.

[0094] At step 407, after receiving the virtual card number and the dynamic security code from the processor of the card, the processor of the device may display a notification. In some examples, the notification may be displayed for only a period of time, and / or based on whether the user has been logged into an account for a period of time and / or whether the user has participated in an active session after logging into the account. The virtual card number and the dynamic security code may be stored in the memory of the device.

[0095] Figure 4B Sequence diagram 410 depicts an authentication process according to an exemplary embodiment. Figure 4B Reference may be made to the same or similar components of system 100, Figure 2A and Figure 2B the first device 200, Figure 3 method 300, and Figure 4A sequence diagram 400.

[0096] At step 411, the processor may be configured to request authentication. The processor may belong to a first device, which includes but is not limited to a card (or other first device), a server, or a client device, or a combination thereof. In some examples, the processor may be configured to send an authentication request to any device including but not limited to an application of a client device. In some examples, the request may be sent from the processor of a server to the processor or application of an intermediate device such as a client device, which may in turn be configured to send the authentication request to the processor of the card and / or perform a card read.

[0097] At step 412, the processor or application of the client device can be configured to perform one or more reads. For example, the processor or application of the client device can be configured to perform a read such as a near field communication read on a tag of the card to obtain read data. Other information that can be read and included in the read data includes a unique identification number associated with the card, counters (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), a PAN serial number, a shared secret, and a password. In some examples, the password can be generated by the card including the read data, and the password can be generated using the read data and / or one or more cryptographic algorithms. In some examples, the shared secret can include a number known or derived by the application and / or the server and stored on the card. The shared secret can be used to generate a password and / or perform password operations using one or more cryptographic algorithms. In some examples, the processor or application of the client device can be configured to display a notification or otherwise prompt for the read.

[0098] For example, the processor or application of the client device can be configured to send data in response to a read (such as a first read) after entering one or more communication fields of any device. For example, the processor can be configured to send a password after first entering the first communication field of the device. Non-limitingly, each input can be associated with a tap, a swipe, a wave, and / or any combination thereof. The password can be received via a near field communication data exchange format (NDEF) read upon request. The processor or application can be configured to send the password. In some examples, the processor can be configured to encrypt the first password before its transmission. For example, the processor or application can be configured to generate multiple session keys such as a first session key and a second session key using a secret key in combination with a counter. The MAC can be generated using the first session key. The MAC can be encrypted using the second session key before its transmission for decryption and verification.

[0099] At step 413, the processor or application of the client device can be configured to send the read data and a request for a virtual card number to the processor of the server. The processor of the server can be configured to receive the read data and the request for a virtual card number and decrypt the read data and the request for a virtual card number by any of the ways described herein if necessary. For example, the server can be configured to generate a unique derived key using the unique identifier and the master key. The server can be configured to generate a session key based on the unique derived key and the counter. The server can be configured to decrypt the encrypted MAC based on the password.

[0100] At step 414, the processor of the server can be configured to authenticate the read data. For example, the server can be configured to verify the MAC using a session key.

[0101] At step 415, the processor of the server can be configured to generate a virtual card number and a dynamic security code based on a mapping with multiple parameters of the read data, the multiple parameters including, for example, a password that includes at least one selected from the group of a unique identifier, a counter, a session key, and a PAN serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number can include up to a total of 16 digits, but is not limited thereto. Similarly non - restrictively, the dynamic security code can include a card verification value. For example, the card verification value can include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non - zero.

[0102] At step 416, the processor of the server can be configured to register the virtual card number with one or more payment authorization systems to enable the use of the virtual number. In some examples, the processor can also be configured to restrict the virtual card number to within a time window. For example, the processor can be configured to limit the use of the virtual card number to a time window range including a first value and a second value. In some examples, the processor can be configured to restrict the use of the dynamic security code within the time window. Additionally, the processor can be configured to invalidate the dynamic security code if it is not used within the time window. Non - restrictively, the time window range can include any number of seconds, minutes, hours, days, weeks, months, years, etc. Additionally, the processor can be configured to restrict the virtual card number to be used restrictively for one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location or to exclude one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location. Non - restrictively, the processor can be configured to determine the restrictions based on an evaluation of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0103] At step 417, the processor of the server can be configured to send the virtual card number and the dynamic security code to complete the authentication request. In some examples, the processor can be configured to send the virtual card number and the dynamic security code via a notification. Non - restrictively, the notification can include at least one selected from the group of a pop - up notification, a short message service, and a QR code.

[0104] After receiving the virtual card number and the dynamic security code from the processor of the server, the processor or application of the client device can display a notification. In some examples, the notification can be displayed for only a period of time, and / or based on whether the user has been logged into the account for a period of time and / or whether the user has participated in an active session after logging into the account. The virtual card number and the dynamic security code can be stored in the memory of the client device.

[0105] Figure 4C FIG. 420 is a sequence diagram depicting an authentication process according to an exemplary embodiment. Figure 4C Reference may be made to the same or similar components of system 100, Figure 2A and Figure 2B first device 200, Figure 3 method 300, Figure 4A sequence diagram 400, and Figure 4B sequence diagram 410.

[0106] At step 421, the processor can be configured to request authentication and a virtual card number. The processor can belong to a first device, which includes but is not limited to a card (or other first device), a server, or a client device, or a combination thereof. In some examples, the processor can be configured to send an authentication request and a request for a virtual card number to any device, including but not limited to an application of the client device and the processor of the card. In some examples, the request can be sent from the processor of the server to the processor or application of an intermediate device such as the client device, which can in turn be configured to send the authentication request to the processor of the card and / or perform a card read.

[0107] At step 422, the processor of the card can be configured to generate a virtual card number and a dynamic security code based on a mapping of multiple parameters of the read data, the multiple parameters including, for example, a password that includes at least one selected from the group of a unique identifier, a counter, a session key, and a PAN serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number can include up to a total of 16 digits, but is not limited thereto. Similarly non - restrictively, the dynamic security code can include a card verification value. For example, the card verification value can include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non - zero.

[0108] In some examples, the processor may also be configured to limit the virtual card number within a time window. For example, the processor may be configured to limit the use of the virtual card number between a time window range including a first value and a second value. In some examples, the processor may be configured to limit the use of the dynamic security code within the time window. Additionally, the processor may be configured to invalidate the dynamic security code if it is not used within the time window. Non - restrictively, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc. Further, the processor may be configured to limit the virtual card number to be restrictively used for one type of transaction, a specific merchant, merchant category, and / or transactions at or near a specific location or to exclude one type of transaction, a specific merchant, merchant category, and / or transactions at or near a specific location. Non - restrictively, the processor may be configured to determine the restrictions based on an evaluation of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0109] At step 423, the processor of the card may be configured to send the virtual card number and the dynamic security code to the server. In some examples, the virtual card number and the dynamic security code may be sent from the processor of the card to the processor or application of an intermediate device such as a client device, which may in turn be configured to send the virtual card number and the dynamic security code to the processor of the server.

[0110] In some instances, before transmission, the card may use the included data and / or one or more cryptographic algorithms to generate a password that includes the virtual card number, the dynamic security, and other data, where the other data includes a unique identification number associated with the card, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter, a PAN serial number), a shared secret, and a password. In some examples, the shared secret may include a number known or derived by the application and / or the server and stored on the card. The shared secret may be used to generate the password and / or perform password operations using one or more cryptographic algorithms.

[0111] In some examples, the processor of the card may be configured to encrypt the first password before transmission. For example, the processor may be configured to generate multiple session keys such as a first session key and a second session key using a secret key in combination with a counter. The MAC may be generated using the first session key. The MAC may be encrypted using the second session key before its transmission for decryption and verification.

[0112] The processor of the server can be configured to receive the read data and a request for a virtual card number, and decrypt the read data in any of the ways described herein when necessary. For example, the server can be configured to generate a unique derived key using a unique identifier and a master key. The server can be configured to generate a session key based on the unique derived key and a counter. The server can be configured to decrypt the encrypted MAC according to a password.

[0113] At step 424, the processor of the server can be configured to authenticate the read data. For example, the server can be configured to verify the MAC using the session key.

[0114] At step 425, the processor of the server can be configured to register the virtual card number with one or more payment authorization systems to enable the use of the virtual number. In some examples, the processor can also be configured to limit the virtual card number to a time window. For example, the processor can be configured to limit the use of the virtual card number to a time window range including a first value and a second value. In some examples, the processor can be configured to limit the use of the dynamic security code in the time window. Additionally, the processor can be configured to invalidate the dynamic security code if it is not used within the time window. Non-limitingly, the time window range can include any number of seconds, minutes, hours, days, weeks, months, years, etc. Additionally, the processor can be configured to limit the virtual card number to be restrictedly used for one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location or exclude one transaction type, a specific merchant, merchant category, and / or transactions at or near a specific location. Non-limitingly, the processor can be configured to determine the limitation based on an assessment of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0115] At step 426, the processor of the server can be configured to send the virtual card number and the dynamic security code to complete the authentication request. In some examples, the processor can be configured to send the virtual card number and the dynamic security code via a notification. Non-limitingly, the notification can include at least one selected from the group of a pop-up notification, a short message service, and a QR code.

[0116] After receiving the virtual card number and the dynamic security code from the processor of the server, the processor or application of the client device can display a notification. In some examples, the notification can be displayed only for a period of time, and / or based on whether the user has logged in to the account for a period of time and / or whether the user has participated in an active session after logging in to the account. The virtual card number and the dynamic security code can be stored in the memory of the client device.

[0117] Figure 5Depicts an authentication method 500 according to an exemplary embodiment. Figure 5 Reference may be made to the system 100, Figure 2A and Figure 2B the first device 200 of Figure 3 the method 300 of Figure 4A the sequence diagram 400 of Figure 4B the sequence diagram 410 of Figure 4C and the same or similar components of the sequence diagram 420 of

[0118] At block 510, the method may include generating a password in response to an authentication request. For example, the processor may be configured to generate a password in response to an authentication request from an intermediate device or any other device. The processor may belong to a first device including but not limited to a card. In some examples, the processor may be configured to receive an authentication request from any device including but not limited to a mobile device. The processor may be configured to send data in response to a read (such as a first read) after entering one or more communication fields of any device. For example, the processor may be configured to send a password after first entering the first communication field of a device. Non - restrictively, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The password may be received via a Near Field Communication Data Exchange Format (NDEF) reader according to a request. The processor may be configured to send the password. In some examples, the processor may be configured to encrypt the password before its transmission. For example, the processor may be configured to generate multiple session keys such as a first session key and a second session key using a secret key in combination with a counter. A MAC may be generated using the first session key. The MAC may be encrypted with the second session key before its transmission for decryption and verification. The server may be configured to generate a unique derived key using a unique identifier and a master key. The server may be configured to generate a session key according to the unique derived key and the counter. The server may be configured to decrypt the encrypted MAC according to the password. The server may be configured to verify the MAC using the session key.

[0119] The processor may be configured to send the password via a communication interface. For example, the processor may be configured to send the password to one or more applications. In some examples, the processor may be configured to send the password to an application including instructions for execution on a second device. The processor may be configured to update the counter value after the transmission of the password.

[0120] In some examples, the server may be configured to receive the password sent by the processor. An application of a client device may be configured to send the password to the server via the processor. The server may be configured to decrypt the password.

[0121] At block 520, method 300 may include: generating, by a processor, a virtual card number and a dynamic security code based on a mapping of multiple parameters of a password, the multiple parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN serial number. In some examples, the initial value of the virtual card number is zero. The virtual card number may include up to a total of 16 digits, but is not limited thereto. Similarly non - restrictively, the dynamic security code may include a card verification value. For example, the card verification value may include up to a total of 3 digits. In other examples, the initial value of the virtual card number is non - zero.

[0122] In other examples, the processor may receive a virtual card number generated by another device (such as a card, a server, or a client device). The virtual card number may be generated based on information received from the card (e.g., a unique identifier, a counter, and a shared secret) upon successful authentication of the received information. The virtual card number may be generated with an initial or default security code value, e.g., the security code is zero. The virtual card number may be stored in a virtual card number database and sent to the processor. The virtual card number may be encrypted, e.g., via a session key, before transmission. After receiving the virtual card number, the processor may decrypt the virtual card number and generate a dynamic security code.

[0123] In some examples, the method may include restricting the virtual card number to limited use. For example, the processor may be configured to restrict the virtual card to single - use or any number of uses not exceeding a threshold number of times. Additionally, the processor may be configured to restrict the virtual card number to be used restrictively for one transaction type, a specific merchant, a merchant category, and / or transactions at or near a specific location or to exclude one transaction type, a specific merchant, a merchant category, and / or transactions at or near a specific location. Non - restrictively, the processor may be configured to determine the restrictions based on an evaluation of transaction history information, transaction frequency within a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0124] In some examples, the processor may be configured to select one or more digits of the password via one or more cryptographic algorithms to generate the virtual card number. For example, the processor may be configured to select the first digit of the password. In another example, the processor may be configured to select the last digit of the password. In another example, the processor may be configured to select any one or more digits and / or any one or more digit sequences between the first digit and the last digit of the password. In another example, the processor may be configured to select any combination of the digits of the password.

[0125] In some examples, another device, such as a card, server, or client device, may be configured to select one or more digits of a password to generate a virtual card number. The virtual card number may be generated after successful verification of the password and / or customer data (e.g., customer identifier, transaction data). The virtual card number may be sent to a processor.

[0126] At block 530, the method may include: restricting the virtual card number within a time window by a processor. For example, the processor may be configured to restrict the use of the virtual card number within a time window range including a first value and a second value. In some examples, the processor may be configured to restrict the use of a dynamic security code within the time window. Additionally, the processor may be configured to invalidate the dynamic security code if it is not used within the time window. Non-limitingly, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0127] Thus, when the user is prompted to enter the virtual card number and the dynamic security code, including but not limited to providing information via a mobile application to a website to process a transaction, the card may enter the communication field of the device and send this information, along with the password, to the device. In this way, the application of the device may be configured to send the password, including a counter, to the server. The server may be configured to allow the dynamic security code and the virtual card number within a specified time window until the counter is adjusted. Thus, this implementation allows restricting the use of the virtual card number, and this requires the physical card itself and the dynamic security code.

[0128] At block 540, the method may include: synchronizing a counter with a server by a processor during a time window. For example, the processor may be configured to adjust the counter. In some examples, the processor may be configured to increment the counter with a virtual card number and a dynamic security code during the time window. In other examples, the processor may be configured to decrement the counter with a virtual card number and a dynamic security code during the time window. The incrementing and / or decrementing may be determined by the processor according to a sequence. For example, the processor may be configured to increment the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of a brute force attack. For example, the processor may be configured to decrement the counter by an even number, an odd number, or a formula to provide higher security and prevent the possibility of a brute force attack. It should also be understood that the sequence may be selected by the processor to avoid increasing the processing load on the card. In this way, one or more cryptographic algorithms may be configured to generate a sufficiently high entropy value for the dynamic security code, which may reduce the possibility of a brute force attack. Thus, the server may be configured to record the adjusted (such as incremented or decremented) counter of the card to associate it with the dynamic security code and the virtual card number and also avoid desynchronization with the card. In the case where the card does not enter a communication field (such as the aforementioned tap, swipe, or wave), the dynamic security code and the virtual card number generated by the card will not be sent and thus result in a non-compliance of the authentication request.

[0129] At block 550, the method may include: sending, by the processor, a virtual card number and a dynamic security code to complete an authentication request. For example, the processor may be configured to send a virtual card number and a dynamic security code to complete an authentication request. For example, the processor may be configured to send a virtual card number and a dynamic security code in response to a scan of a QR code. In some examples, the processor may be configured to send a virtual card number and a dynamic security code via a notification. Non-limitingly, the notification may include at least one selected from the group consisting of a pop-up notification, a short message service, and a QR code. The notification may be displayed by the device.

[0130] In some aspects, the techniques described herein relate to an authentication system that includes: a processor; and a memory that contains a unique identifier, a counter, a session key, and a sequence number, where the processor is configured to: receive an authentication request, receive a password that includes one or more parameters, the one or more parameters including at least one parameter selected from the group consisting of a unique identifier, a counter, a session key, and a sequence number, in response to the authentication request, generate a virtual card number and a dynamic security code based on a mapping with the one or more parameters, and send the virtual card number and the dynamic security code to complete the authentication request.

[0131] In some aspects, the techniques described herein relate to an authentication system where the initial value of the virtual card number is zero.

[0132] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to limit the virtual card number to a single use for one type of transaction.

[0133] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to select one or more digits of a password via one or more cryptographic algorithms to generate a virtual card number.

[0134] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to limit the virtual card number within a time window.

[0135] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to synchronize a counter during the time window.

[0136] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to increment the counter with the virtual card number and a dynamic security code during the time window.

[0137] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to decrement the counter with the virtual card number and a dynamic security code during the time window.

[0138] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to: limit the use of the dynamic security code within a time window and invalidate the dynamic security code if it is not used within the time window.

[0139] In some aspects, the techniques described herein relate to an authentication system, wherein the processor is further configured to send the virtual card number and the dynamic security code in response to the scanning of a QR code.

[0140] In certain aspects, the techniques described herein relate to an authentication method, including: receiving, by a processor, an authentication request; receiving, by the processor, a password including one or more parameters, the one or more parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a serial number; generating, by the processor in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with the one or more parameters; and sending, by the processor, the virtual card number and the dynamic security code to complete the authentication request.

[0141] In some aspects, the techniques described herein relate to a method, wherein an initial value of the virtual card number is zero.

[0142] In some aspects, the techniques described herein relate to a method, further including limiting, by the processor, the virtual card number to a single use for one type of transaction.

[0143] In some aspects, the techniques described herein relate to a method that further includes a processor selecting one or more digits of a password via one or more cryptographic algorithms to generate a virtual card number.

[0144] In some aspects, the techniques described herein relate to a method that further includes a processor restricting the virtual card number within a time window.

[0145] In some aspects, the techniques described herein relate to a method that further includes a processor synchronizing a counter during the time window.

[0146] In some aspects, the techniques described herein relate to a method that further includes a processor incrementing the counter with the virtual card number and a dynamic security code during the time window.

[0147] In some aspects, the techniques described herein relate to a method that further includes a processor decrementing the counter with the virtual card number and a dynamic security code during the time window.

[0148] In some aspects, the techniques described herein relate to a method that further includes a processor sending the virtual card number and the dynamic security code via a notification that includes at least one selected from a pop-up notification, a short message service, and a QR code.

[0149] In some aspects, the techniques described herein relate to a computer-accessible non-transitory medium that includes computer-executable instructions that, when executed on a processor, perform a process that includes the steps of: receiving an authentication request; receiving a password that includes one or more parameters that include at least one parameter selected from the group of a unique identifier, a counter, a session key, and a serial number; in response to the authentication request, generating a virtual card number and a dynamic security code based on a mapping with the one or more parameters; and sending the virtual card number and the dynamic security code to complete the authentication request.

[0150] In the present disclosure, a card such as a contact-based card and a contactless card is mentioned. It should be understood that the present disclosure is not limited to a specific type of card, and on the contrary, the present disclosure includes contact-based cards, contactless cards, or any other cards. It should also be understood that the present disclosure is not limited to cards with a specific purpose (e.g., payment cards, gift cards, identity cards, membership cards, transportation cards, access cards), cards associated with a specific type of account (e.g., credit accounts, debit accounts, membership accounts), or cards issued by a specific entity (e.g., commercial entities, financial institutions, government entities, social clubs). On the contrary, it should be understood that the present disclosure includes cards with any purpose, account association, or issuing entity.

[0151] It should also be noted that the systems and methods described herein can be tangibly embodied in one or more physical media, such as but not limited to optical discs (CDs), digital versatile discs (DVDs), floppy disks, hard disks, read-only memories (ROMs), random access memories (RAMs), and other physical media capable of storing data. For example, a data storage can include a random access memory (RAM) and a read-only memory (ROM), which can be configured to access and store data and information as well as computer program instructions. The data storage can also include a storage medium or other suitable type of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical discs, floppy disks, hard disks, removable cartridge tapes, flash drives, any type of tangible and non-transitory storage medium), where files can be stored, including an operating system, applications including, for example, a web browser application, an email application, and / or other applications, and data files. The data storage of a networked computer system can include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases, such as databases created and maintained with software from, for example a database created and maintained with software from Corporation, Excel files, Access files, solid-state storage devices (which can include flash arrays, hybrid arrays, or server-side products), enterprise storage (which can include online or cloud storage), or any other storage mechanism. Additionally, the figures separately illustrate various components (e.g., servers, computers, processors, etc.). Functions described as being performed at various components can be performed at other components, and various components can be combined or separated. Other modifications can also be made.

[0152] In the foregoing specification, various embodiments have been described with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be implemented, without departing from the broader scope of the disclosure as set forth in the appended claims. Accordingly, the specification and drawings are to be regarded as illustrative rather than restrictive.

Claims

1. An authentication system, the authentication system comprises: a processor; and a memory, the memory containing a unique identifier, a counter, a session key and a serial number, wherein the processor is configured to: receive an authentication request, receive a password comprising one or more parameters, the one or more parameters including at least one selected from the group consisting of the unique identifier, the counter, the session key and the serial number, in response to the authentication request, generate a virtual card number and a dynamic security code based on a mapping with the one or more parameters, and send the virtual card number and the dynamic security code to complete the authentication request.

2. The authentication system according to claim 1, wherein the initial value of the virtual card number is zero.

3. The authentication system according to claim 1, wherein the processor is further configured to limit the virtual card number to single use for one type of transaction.

4. The authentication system according to claim 1, wherein the processor is further configured to select one or more digits of the password via one or more cryptographic algorithms to generate the virtual card number.

5. The authentication system according to claim 1, wherein the processor is further configured to limit the virtual card number within a time window.

6. The authentication system according to claim 5, wherein the processor is further configured to synchronize the counter during the time window.

7. The authentication system according to claim 6, wherein the processor is further configured to increment the counter with the virtual card number and the dynamic security code during the time window.

8. The authentication system according to claim 6, wherein the processor is further configured to decrement the counter with the virtual card number and the dynamic security code during the time window.

9. The authentication system according to claim 1, wherein the processor is further configured to: limit the use of the dynamic security code in a time window, and if not used within the time window, invalidate the dynamic security code.

10. The authentication system according to claim 1, wherein the processor is further configured to send the virtual card number and the dynamic security code in response to scanning of a QR code.

11. An authentication method, comprising: receiving, by a processor, an authentication request; receiving, by the processor, a password comprising one or more parameters, the one or more parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key and a serial number; generating, by the processor in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with the one or more parameters; and sending, by the processor, the virtual card number and the dynamic security code to complete the authentication request.

12. The method according to claim 11, wherein the initial value of the virtual card number is zero.

13. The method according to claim 11, further comprising limiting, by the processor, the virtual card number to single use for one type of transaction.

14. The method according to claim 11, further comprising selecting, by the processor, one or more digits of the password via one or more cryptographic algorithms to generate the virtual card number.

15. The method according to claim 11, further comprising restricting, by the processor, the virtual card number within a time window.

16. The method according to claim 15, further comprising synchronizing, by the processor, the counter during the time window.

17. The method according to claim 16, further comprising incrementing, by the processor, the counter with the virtual card number and the dynamic security code during the time window.

18. The method according to claim 16, further comprising decrementing, by the processor, the counter with the virtual card number and the dynamic security code during the time window.

19. The method according to claim 11, further comprising sending, by the processor, the virtual card number and the dynamic security code via a notification, the notification including at least one selected from the group consisting of a pop-up notification, a short message service, and a QR code.

20. A computer-accessible non-transitory medium, the non-transitory medium including computer-executable instructions that, when executed on a processor, perform a process including the following steps: Receiving an authentication request; Receiving a password including one or more parameters, the one or more parameters including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a serial number; In response to the authentication request, generating a virtual card number and a dynamic security code based on a mapping with the one or more parameters; And Sending the virtual card number and the dynamic security code to complete the authentication request.