Systems and techniques for performing authentication operations using wireless communication
By using contactless cards to provide input mode and combining multi-factor authentication, vulnerabilities in data and private information security on mobile devices are solved, achieving higher security and protection effects.
Patent Information
- Application Number
- CN202380080018.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2022-11-18
- Filing Date
- 2023-11-16
- Publication Date
- 2025-06-27
AI Technical Summary
The prior art has vulnerabilities in ensuring the security of data and private information on mobile devices, and attackers can circumvent security measures by stealing passwords or intercepting authentication data.
By using contactless cards to provide input mode, safe verification is performed using multi-factor authentication. The specific method includes detecting the communication mode of the contactless card using a short-range communication antenna of the mobile device and determining a matching condition of the mode to the verified mode through the processor to enable or prevent operation.
Improves the security of the computing environment, makes it more difficult for attackers to steal and gain access, and enhances the protection of data and private information.
Smart Images

Figure CN120226031A_ABST
Abstract
Description
Background Art
[0001] As the popularity of user devices such as mobile phones continues to rise, ensuring that access to data and private information is securely provided and maintained on user devices remains an issue. For example, in order to access a mobile device or an application running on a mobile device, it is usually necessary to authenticate the user before providing access. However, attackers attempt to circumvent security measures (e.g., by performing a man-in-the-middle attack) by stealing passwords and eavesdropping on users during the registration and authentication processes. Thus, an attacker may attempt to intercept data that can be used to infer the identity of a user, a user device, or a server computer, such as a public key. An attacker may also attempt to intercept authentication data, such as a password or a response to an invitation. The intercepted data may be used to track the user's device or may be used for illegal purposes. The embodiments discussed herein are directed to providing additional security measures that are more difficult for an attacker to steal and gain access to. Summary of the Invention
[0002] Embodiments generally relate to systems and methods for performing authentication operations using a wireless interface. In one example, a system may perform a method that includes detecting, via a first short-range communication antenna of a mobile device, one or more communications with a non-contact card based on the non-contact card entering a communication range of the first short-range communication antenna of the mobile device; detecting, via a second short-range communication antenna of the mobile device, one or more different communications with the non-contact card based on the non-contact card entering a communication range of the second short-range communication antenna of the mobile device, wherein the first short-range communication antenna and the second short-range communication antenna are different antennas; determining, by a processor of the mobile device, a pattern in the one or more communications and the one or more different communications; determining, by the processor, that the pattern matches a verified pattern; and enabling, by the processor, operation execution in response to the pattern matching the verified pattern.
[0003] Embodiments may also include an apparatus that includes a first short-range communication antenna, a second short-range communication antenna, a memory configured to store instructions, and a processor coupled to the memory, the first short-range communication antenna, and the second short-range communication antenna, the processor configured to process the instructions. When the instructions are executed by the processor, the instructions cause the processor to detect a pattern of communications received by the first short-range communication antenna, the second short-range communication antenna, or both, determine that the pattern matches a verified pattern to perform an operation, and perform the operation based on the pattern matching the verified pattern.
[0004] In another example, an embodiment can include a memory, a storage device, or a computer-readable medium that includes instructions that, when executed by a processor, cause the processor to receive two or more communications from a contactless card via a first near-field communication (NFC) antenna, a second NFC antenna, or both, determine a pattern in the two or more communications, compare the pattern to a verified pattern, determine whether the pattern matches the verified pattern, enable an operation to be performed in response to the pattern matching the verified pattern, and block the operation from being performed in response to the pattern not matching the verified pattern. BRIEF DESCRIPTION OF THE DRAWINGS
[0005] To facilitate identification of any particular element or discussion of an action, one or more of the most significant digits in a reference number is called the figure number in which the element is first introduced.
[0006] Figure 1 Shows one aspect of the subject matter in accordance with one embodiment.
[0007] Figure 2 Shows one aspect of the subject matter in accordance with one embodiment.
[0008] Figure 3 Shows a contactless card 102 in accordance with one embodiment.
[0009] Figure 4 Shows a transaction card component 400 in accordance with one embodiment.
[0010] Figure 5 Shows a sequence flow 500 in accordance with one embodiment.
[0011] Figure 6 Shows a data structure 600 in accordance with one embodiment.
[0012] Figure 7 Is a schematic diagram of a key system according to an example embodiment.
[0013] Figure 8 Is a flowchart of a method for generating a password according to an example embodiment.
[0014] Figure 9 Shows one aspect of the subject matter in accordance with one embodiment.
[0015] Figure 10 Shows one aspect of the subject matter in accordance with one embodiment.
[0016] Figure 11 Shows an example of a client device 104 in accordance with an embodiment.
[0017] Figure 12An example of a system 1200 is shown according to an embodiment.
[0018] Figure 13 An example of a routine 1300 is shown according to an embodiment.
[0019] Figure 14 An example of a sequence flow 1400 is shown according to an embodiment.
[0020] Figure 15 Routine 1500 is shown according to an embodiment.
[0021] Figure 16 Routine 1600 is shown according to an embodiment.
[0022] Figure 17 Routine 1700 is shown according to an embodiment.
[0023] Figure 18 Computer architecture 1800 is shown according to one embodiment.
[0024] Figure 19 A communications architecture 1900 is shown according to one embodiment. DETAILED DESCRIPTION
[0025] Embodiments generally relate to improving security in computing environments by providing an input pattern using a contactless card. As described above, mobile devices are becoming more and more common. The potential for hackers to steal or access user devices has never been higher. Today's devices include security measures that require users to enter a password, PIN, or pattern to access the device. However, these measures are flawed. A hacker can easily steal or obtain a password, PIN, or pattern by visually observing a user entering the security measure.
[0026] The embodiments discussed herein are superior to these and other measures by enabling security measures to be entered in a manner that is not easily observable by an attacker. Specifically, embodiments enable users to enter a pattern of inputs using their contactless cards (such as debit cards, credit cards, rewards cards, etc.) by discretely interacting with a mobile device. A user can provide a pattern of inputs by "tapping" a contactless card on or near one or more antennas already provided in a mobile device. As will be discussed in more detail in the following description, the pattern can include various characteristics of each input, such as which antenna to use, the length of the taps, the length between taps, the sequence of taps, etc.
[0027] In an embodiment, "tap" authentication can be used with additional authentication using a contactless card to create a multi-factor authentication security measure using a single object (e.g., a card). As described throughout the specification, the contactless card itself can be used as a token (e.g., something you have), and the data on the card can be authenticated. Thus, the contactless card can provide data to a device that can be authenticated. The user can then use the card to provide input on the device as part of the multi-factor authentication process. In some instances, providing data and tapping can occur in real time. For example, the device can be configured to perform one or more read operations during tapping and register each "tap" to detect a pattern. These and additional details will be discussed in the following description.
[0028] Figure 1 A data transmission system 100 is shown according to an example embodiment. As discussed further below, the system 100 may include a contactless card 102, a client device 104, a network 106, and a server 108. Figure 1 A single instance of a component is shown, but system 100 may include any number of components.
[0029] The system 100 may include one or more contactless cards 102, which are explained further below. In some embodiments, the contactless card 102 may wirelessly communicate with a client device 104 using NFC, for example.
[0030] System 100 may include client device 104, which may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, a computer device or a communication device, including, for example, a server, a network appliance, a personal computer, a workstation, a phone, a handheld PC, a personal digital assistant, a thin client, a fat client, an Internet browser, or other device. Client device 104 may also be a mobile device; for example, a mobile device may include a iPhone, iPod, iPad or running Apple Any other mobile device running Microsoft Any device running Google Mobile OS operating system, and / or any other smartphone, tablet or similar wearable mobile device.
[0031] The client device 104 may include a processor and a memory, and it should be understood that the processing circuitry may include additional components, including a processor, a memory, an error and parity / CRC checker, a data encoder, an anti-collision algorithm, a controller, a command decoder, security primitives, and tamper-resistant hardware, as required to perform the functions described herein. The client device 104 may also include a display and an input device. The display may be any type of device for presenting visual information, such as a computer monitor, a flat panel display, and a mobile device screen, including a liquid crystal display, a light-emitting diode display, a plasma panel, and a cathode ray tube display. The input device may include any device for typing information into the user device that is available and supported by the user device, such as a touch screen, a keyboard, a mouse, a cursor control device, a touch screen, a microphone, a digital camera, a video recorder, or a camcorder. These devices may be used to type information and interact with the software and other devices described herein.
[0032] In some examples, the client device 104 of the system 100 may execute one or more applications, such as software applications, that enable, for example, network communication with one or more components of the system 100, and the transfer and / or receipt of data.
[0033] The client device 104 may communicate with one or more servers 108 via one or more networks 106 and may operate with the server 108 as a corresponding front-end to back-end pair. The client device 104 may, for example, transmit one or more requests from a mobile device application executing on the client device 104 to the server 108. One or more requests may be associated with retrieving data from the server 108. The server 108 may receive one or more requests from the client device 104. Based on the one or more requests from the client device 104, the server 108 may be configured to retrieve the requested data from one or more databases (not shown). Based on receiving the requested data from the one or more databases, the server 108 may be configured to transmit the received data to the client device 104, where the received data is in response to the one or more requests.
[0034] System 100 may include one or more networks 106. In some examples, network 106 may be a wireless network, a wired network, or one or more of any combination of a wireless network and a wired network, and may be configured to connect client device 104 to server 108. For example, network 106 may include one or more of the following: fiber optic network, passive optical network, cable network, internetwork, satellite network, wireless local area network (LAN), global system for mobile communications, personal communications service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11 networking family, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, and / or the like.
[0035] In addition, network 106 may include, but is not limited to, telephone lines, fiber optics, IEEE Ethernet 802.3, wide area network, wireless personal area network, LAN, or a global network such as the Internet. In addition, network 106 may support an internetwork, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 106 may also include one network or any number of the exemplary types of networks mentioned above, operating either as a stand-alone network or in cooperation with each other. Network 106 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 106 may translate into one or more protocols of network devices or translate from other protocols into one or more protocols of network devices. Although network 106 is depicted as a single network, it should be appreciated that, according to one or more examples, network 106 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network.
[0036] System 100 may include one or more servers 108. In some examples, server 108 may include one or more processors coupled to a memory. Server 108 may be configured as a central system, server, or platform for controlling and invoking various data at different times to perform multiple workflow actions. Server 120 may be configured to connect to one or more databases. Server 108 may be connected to at least one client device 104.
[0037] Figure 2 A data transmission system according to an example embodiment is shown. System 200 may include a transmitter or transmitting device 204 and a receiver or receiving device 208 that communicates, for example, via network 206 with one or more servers 202. The transmitter or transmitting device 204 may be related to the above reference Figure 1is the same as or similar to the client device 110 discussed above. The receiver or receiving device 208 can be the same as or similar to the Figure 1 client device 110 discussed above. The network 206 can be the same as the Figure 1 network 115 discussed above. The server 202 can be the same as or similar to the Figure 1 server 120 discussed above. Although Figure 2 a single instance of the components of the system 200 is shown, the system 200 can include any number of the shown components.
[0038] When using symmetric cryptographic algorithms, such as encryption algorithms, hash-based message authentication code (HMAC) algorithms, and ciphertext-based message authentication code (CMAC) algorithms, it is important that the key remains secret between the party that initially processes the data protected using the symmetric algorithm and key and the party that receives and processes the data using the same cryptographic algorithm and the same key.
[0039] It is also important that the same key is not used too many times. If the key is used or reused too frequently, the key may be compromised. Each time the key is used, it provides additional data samples for an attacker, which are processed by the cryptographic algorithm using the same key. The more data processed using the same key the attacker has, the greater the likelihood that the attacker can discover the key value. Frequently used keys can be included in a variety of different attacks.
[0040] In addition, each time a symmetric cryptographic algorithm is executed, it can reveal information about the key used during the symmetric cryptographic operation, such as side-channel data. Side-channel data can include minute power fluctuations that occur when the cryptographic algorithm is executed while using the key. Measurements can be made on the side-channel data sufficient to reveal enough information about the key to allow the attacker to recover the key. Exchanging data using the same key will repeatedly reveal the data processed by the same key.
[0041] However, by limiting the number of times a particular key will be used, the amount of side-channel data that an attacker can collect is limited, and thus the exposure to such and other types of attacks is reduced. As further described herein, the parties participating in a cryptographic information exchange (e.g., the sender and the receiver) can independently generate keys from an initial shared master symmetric key combined with a counter value, and thus periodically replace the shared symmetric key being used in cases where it is necessary to resort to any form of key exchange to keep the parties in sync. By periodically changing the shared secret symmetric key used by the sender and the receiver, the attacks described above become impossible.
[0042] Return to reference Figure 2, the system 200 can be configured to implement key diversification. For example, a sender and a receiver may expect to exchange data (e.g., original sensitive data) via the respective devices 204 and 208. As explained above, although a single instance of the transmitting device 204 and the receiving device 208 may be included, it should be understood that one or more transmitting devices 204 and one or more receiving devices 208 may be involved as long as each party shares the same shared secret symmetric key. In some examples, the transmitting device 204 and the receiving device 208 may be equipped with the same master symmetric key. Further, it should be understood that any party or device holding the same secret symmetric key may perform the function of the transmitting device 204, and similarly any party holding the same secret symmetric key may perform the function of the receiving device 208. In some examples, the symmetric key may include a shared secret symmetric key that remains secret to all parties other than the transmitting device 204 and the receiving device 208 participating in the exchange of secure data. It should also be understood that both the transmitting device 204 and the receiving device 208 may be equipped with the same master symmetric key, and a portion of the data exchanged between the transmitting device 204 and the receiving device 208 includes at least a portion of data that may be referred to as a counter value. The counter value may include a number that changes each time data is exchanged between the transmitting device 204 and the receiving device 208.
[0043] The system 200 may include one or more networks 206. In some examples, the network 206 may be a wireless network, a wired network, or one or more of any combination of a wireless network and a wired network, and may be configured to connect one or more transmitting devices 204 and one or more receiving devices 208 to the server 202. For example, the network 206 may include one or more of the following: fiber optic network, passive optical network, cable network, internetwork, satellite network, wireless LAN, global system for mobile communications, personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11 network family, Bluetooth, NFC, RFID, Wi-Fi, and / or the like.
[0044] In addition, network 206 can include, but is not limited to, telephone lines, optical fibers, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Additionally, network 206 can support interconnected networks, wireless communication networks, cellular networks, or the like, or any combination thereof. Network 206 can also include one network or any number of the exemplary types of networks mentioned above, operating either as stand-alone networks or in cooperation with each other. Network 206 can utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 206 can translate into one or more protocols of network devices or from other protocols into one or more protocols of network devices. Although network 206 is depicted as a single network, it should be appreciated that, according to one or more examples, network 206 can include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network.
[0045] In some examples, one or more transmitting devices 204 and one or more receiving devices 208 can be configured to communicate with each other and transmit and receive data without going through network 206. For example, communication between one or more transmitting devices 204 and one or more receiving devices 208 can occur via at least one of NFC, Bluetooth, RFID, Wi-Fi, and / or the like.
[0046] At block 210, when the transmitting device 204 is preparing to process sensitive data using symmetric cryptographic operations, the sender can update a counter. Additionally, the transmitting device 204 can select an appropriate symmetric cryptographic algorithm, which can include at least one of a symmetric encryption algorithm, an HMAC algorithm, and a CMAC algorithm. In some examples, the symmetric algorithm for processing the diversification value can include any symmetric cryptographic algorithm needed to generate a symmetric key of a desired length as needed. Non-limiting examples of symmetric algorithms can include symmetric encryption algorithms such as 3DES or AES128; symmetric HMAC algorithms such as HMAC-SHA-256; and symmetric CMAC algorithms such as AES-CMAC. It should be understood that if the output of the selected symmetric algorithm does not generate a key of sufficient length, techniques such as processing multiple iterations of the symmetric algorithm with different input data and the same master key can produce multiple outputs that can be combined as needed to produce a key of sufficient length.
[0047] At block 212, the transfer device 204 may take a selected cryptographic algorithm and use the master symmetric key to process the counter value. For example, the sender may select a symmetric encryption algorithm and use a counter that is updated with each conversation between the transfer device 204 and the receiving device 208. The transfer device 204 may then use the master symmetric key to encrypt the counter value using the selected symmetric encryption algorithm, thereby creating a diversified symmetric key.
[0048] In some examples, the counter value may not be encrypted. In these examples, at block 212, the counter value may be transferred between the transfer device 204 and the receiving device 208 without encryption.
[0049] At block 214, the diversified symmetric key may be used to process sensitive data before sending the result to the receiving device 208. For example, the transfer device 204 may encrypt the sensitive data using a symmetric encryption algorithm that uses the diversified symmetric key, where the output includes protected encrypted data. The transfer device 204 may then transfer the protected encrypted data along with the counter value to the receiving device 208 for processing.
[0050] At block 216, the receiving device 208 may first take the counter value and then perform the same symmetric encryption using the counter value as the input to the encryption and the master symmetric key as the key for the encryption. The output of the encryption may be the same diversified symmetric key value created by the sender.
[0051] At block 218, the receiving device 208 may then take the protected encrypted data and decrypt the protected encrypted data using a symmetric decryption algorithm and the diversified symmetric key.
[0052] At block 220, as a result of decrypting the protected encrypted data, the original sensitive data may be revealed.
[0053] The next time sensitive data needs to be sent from the sender to the receiver via the respective transfer device 204 and receiving device 208, a different counter value may be selected to generate a different diversified symmetric key. By processing the counter value using the master symmetric key and the same symmetric encryption algorithm, both the transfer device 204 and the receiving device 208 can independently generate the same diversified symmetric key. This diversified symmetric key (instead of the master symmetric key) is used to protect the sensitive data.
[0054] As explained above, both the transmitting device 204 and the receiving device 208 each initially possess a shared master symmetric key. The shared master symmetric key is not used to encrypt the original sensitive data. Since the diversified symmetric key is independently created by both the transmitting device 204 and the receiving device 208, it is never transmitted between the two parties. Therefore, an attacker cannot intercept the diversified symmetric key, and the attacker never sees any data processed using the master symmetric key. Only the counter value is processed using the master symmetric key, rather than the sensitive data. As a result, reduced side-channel data about the master symmetric key is revealed. Additionally, the operations of the transmitting device 204 and the receiving device 208 can be governed by the following symmetry requirement: how often to create new diversified values and thus new diversified symmetric keys. In one embodiment, new diversified values and thus new diversified symmetric keys can be created for each exchange between the transmitting device 204 and the receiving device 208.
[0055] In some examples, the key diversification value can include a counter value. Other non-limiting examples of the key diversification value include: a random nonce generated each time a new diversified key is needed, a random nonce sent from the transmitting device 204 to the receiving device 208; the full value of the counter value sent from the transmitting device 204 and the receiving device 208; a portion of the counter value sent from the transmitting device 204 and the receiving device 208; a counter independently maintained by the transmitting device 204 and the receiving device 208 but not sent between the two devices; a one-time password exchanged between the transmitting device 204 and the receiving device 208; and a cryptographic hash of the sensitive data. In some examples, one or more portions of the key diversification value can be used by the parties to create multiple diversified keys. For example, the counter can be used as the key diversification value. Further, a combination of one or more of the exemplary key diversification values described above can be used.
[0056] In another example, a portion of the counter can be used as the key diversification value. If multiple master key values are shared between the parties, multiple diversified key values can be obtained by the systems and processes described herein. New diversified values, and thus new diversified symmetric keys, can be created as often as needed. In the most secure case, a new diversified value can be created for each exchange of sensitive data between the transmitting device 204 and the receiving device 208. In effect, this can create a one-time use key, such as a one-time use session key.
[0057] Figure 3Shows an example configuration of a contactless card 102, which may include a contactless card, a payment card, such as a credit card, a debit card, or a gift card, issued by a service provider as shown by a service provider mark 302 on the front or back of the contactless card 102. In some examples, the contactless card 102 has nothing to do with a payment card and may include, but is not limited to, an identity card. In some examples, the transaction card may include a dual-interface contactless payment card, a reward card, and so on. The contactless card 102 may include a substrate 308, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 102 may have physical characteristics in the ID-1 format compliant with the ISO / IEC 7816 standard, and the transaction card may otherwise comply with the ISO / IEC 14443 standard. However, it should be understood that the contactless card 102 according to the present disclosure may have different characteristics, and the present disclosure does not require the transaction card to be implemented in a payment card.
[0058] The contactless card 102 may further include identification information 306 and contact pads 304 displayed on the front and / or back of the card. The contact pads 304 may include one or more pads and are configured to establish contact with another client device (such as an ATM), a user device, a smartphone, a laptop, a desktop computer, or a tablet computer) via the transaction card. The contact pads may be designed according to one or more standards (such as the ISO / IEC 7816 standard) and implement communication according to the EMV protocol. The contactless card 102 may further include processing circuitry, an antenna, and other components, as will be Figure 4 discussed further in. These components may be located behind the contact pads 304 or elsewhere on the substrate 308, such as in different layers of the substrate 308, and may be electrically and physically coupled to the contact pads 304. The contactless card 102 may further include a magnetic stripe or tape, which may be located on the back of the card ( Figure 3 not shown). The contactless card 102 may further include a near-field communication (NFC) device coupled to an antenna capable of communicating via the NFC protocol. The embodiments are not limited to this manner.
[0059] As Figure 2As shown, the contact pad 304 of the contactless card 102 may include processing circuitry 416 for storing, processing, and transferring information, and the processing circuitry includes a processor 402, a memory 404, and one or more interfaces 406. It should be understood that the processing circuitry 416 may include additional components, including processors, memories, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tampering hardware, as required to perform the functions described herein.
[0060] The memory 404 may be read-only memory, write-once read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 102 may include one or more of these memories. The read-only memory may be factory-programmable as read-only or one-time programmable. The one-time programmability provides an opportunity to write once and then read many times. The write-once / read-many memory may be programmed at some point after the memory chip has left the factory. Once the memory is programmed, it cannot be rewritten, but can be read many times. The read / write memory may be programmed and reprogrammed many times after leaving the factory. The read / write memory may also be read many times after leaving the factory. In some instances, the memory 404 may be encrypted memory that utilizes an encryption algorithm performed by the processor 402 on the encrypted data.
[0061] The memory 404 may be configured to store one or more applets 408, one or more counters 410, a customer identifier 414, and an account number 412, and the account number may be a virtual account number. The one or more applets 408 may include one or more software applications configured to execute on one or more contactless cards, such as A Card applet. However, it should be understood that the applet 408 is not limited to a Java Card applet, but can be any software application operable on a contactless card or other device with limited memory. One or more counters 410 may include digital counters sufficient to store integers. The customer identifier 414 may include a unique alphanumeric identifier assigned to the user of the contactless card 102, and this identifier may distinguish the contactless card user from other contactless card users. In some examples, the customer identifier 414 may identify both the customer and the account assigned to the customer, and may also identify the contactless card 102 associated with the customer account. As previously described, the account number 412 may include thousands of single-use virtual account numbers associated with the contactless card 102. The applet 408 of the contactless card 102 may be configured to manage the account number 412 (e.g., configured to select the account number 412, mark the selected account number 412 as used) and transmit the account number 412 to the mobile device for autofill by the autofill service.
[0062] The processor 402 and memory elements of the foregoing exemplary embodiments are described with reference to the contact pad 304, but the present disclosure is not limited thereto. It should be understood that these elements may be implemented outside the contact pad 304 or completely separated therefrom, or implemented as additional elements other than the processor 402 and memory 404 elements located within the contact pad 304.
[0063] In some examples, the contactless card 102 may include one or more antennas 418. One or more antennas 418 may be placed within the contactless card 102 and around the processing circuitry 416 of the contact pad 304. For example, one or more antennas 418 may be integrated with the processing circuitry 416, and one or more antennas 418 may be used with an external boost coil. As another example, one or more antennas 418 may be external to the contact pad 304 and the processing circuitry 416.
[0064] In an embodiment, the coil of the contactless card 102 may act as the secondary coil of an air-core transformer. The terminal may communicate with the contactless card 102 by cutting off the power supply or amplitude modulation. The contactless card 101 may use the gap in the power connection of the contactless card to infer the data transmitted from the terminal, and this gap may be functionally maintained by one or more capacitors. The contactless card 102 may communicate back by switching the load on the contactless card coil or load modulation. The load modulation may be detected by interfering with the coil in the terminal. More generally, using the antenna 418, processor 402, and / or memory 404, the contactless card 101 provides a communication interface for communication via NFC, Bluetooth, and / or Wi-Fi communication.
[0065] As explained above, the contactless card 102 can be built on a software platform operable on a smart card or other device with limited memory, such as JavaCard, and one or more applications or applets can be securely executed. The applet 408 can be added to the contactless card to provide a one-time password (OTP) for multifactor authentication (MFA) in various mobile application-based use cases. The applet 408 can be configured to respond to one or more requests (such as a near-field data exchange request) from a reader (such as a mobile NFC reader (e.g., a mobile device or a point-of-sale terminal)), and generate an NDEF message including a cryptographically secure OTP encoded as an NDEF text tag.
[0066] An example of an NDEF OTP is an NDEF short record layout (SR = 1). In such an example, one or more applets 408 can be configured to encode the OTP as an NDEF type 4 well-known type text tag. In some examples, the NDEF message can include one or more records. In addition to the OTP record, the applet 408 can be configured to add one or more static tag records.
[0067] In some examples, one or more applets 408 can be configured to emulate an RFID tag. The RFID tag can include one or more polymorphic tags. In some examples, different cryptographic data is presented each time the tag is read, which can indicate the reliability of the contactless card. Based on one or more applets 408, the NFC reading of the tag can be processed, the data can be transmitted to a server, such as a server of a banking system, and the data can be verified at the server.
[0068] In some examples, the contactless card 102 and the server can include certain data such that the card can be correctly identified. The contactless card 102 can include one or more unique identifiers (not shown). The counter 410 can be configured to increment each time a read operation occurs. In some examples, each time data is read from the contactless card 102 (e.g., by a mobile device), the counter 410 is transmitted to the server for verification, and it is determined whether the counter 410 is equal to the server's counter (as part of the verification).
[0069] One or more counters 410 may be configured to prevent replay attacks. For example, if a password has been obtained and replayed, the password is immediately rejected if the counter 410 has been read or used or otherwise ignored. If the counter 410 has not been used, it may be replayed. In some examples, the counter incremented on the card is different from the counter incremented for a transaction. The contactless card 101 cannot determine the application transaction counter 410 because there is no communication between the applets 408 on the contactless card 102.
[0070] In some examples, the counter 410 may become out of sync. In some examples, in response to an accidental read of an initiated transaction, such as reading at an angle, the counter 410 may be incremented, but the application does not process the counter 410. In some examples, when the mobile device 10 wakes up, NFC may be enabled, and the device 110 may be configured to read available tags, but does not take action in response to the read.
[0071] To keep the counter 410 in sync, an application, such as a background application, may be executed that is configured to detect when the mobile device 110 wakes up and synchronize with the server of the banking system to indicate the read that occurred due to the detection, and then move the counter 104 forward. In other examples, a hashed one-time password may be utilized such that an out-of-sync window can be accepted. For example, if within a threshold of 10, the counter 410 may be configured to move forward. But if within a different number of thresholds, such as within 10 or 1000, then a request for performing resynchronization may be processed, which requests the user via one or more applications to tap, gesture, or otherwise indicate one or more times via the user's device. If the counter 410 increases in the appropriate order, it is possible to know that the user has done so.
[0072] The key diversification techniques described herein with reference to the counter 410, the master key, and the diversified key are an example of encryption and / or decryption key diversification techniques. Such example key diversification techniques should not be considered a limitation of the present disclosure, as the present disclosure is equally applicable to other types of key diversification techniques.
[0073] During the creation process of the contactless card 102, two cryptographic keys may be uniquely assigned to each card. The cryptographic keys may include symmetric keys that may be used in both the encryption and decryption of data. The Triple DES (3DES) algorithm may be used by EMV and is implemented by the hardware in the contactless card 102. By using a key diversification process, one or more keys may be derived from the master key based on uniquely identifiable information for each entity that requires a key.
[0074] In some examples, to overcome the potential vulnerability of the 3DES algorithm, a session key (such as a unique key for each session) can be derived instead of using the master key, and the unique card-derived key and counter can be used as diversification data. For example, each time the contactless card 101 is used in an operation, a different key can be used to create a Message Authentication Code (MAC) and perform encryption. This results in a three-layer cipher. The session key can be generated by one or more applets and derived using an application transaction counter with one or more algorithms (as defined in EMV 4.3 Book 2 A1.3.1 Common Session Key Derivation).
[0075] Furthermore, the increment for each card can be unique and assigned either through personalization or algorithmically through some identification information. For example, odd-numbered cards can be incremented by 2, and even-numbered cards can be incremented by 5. In some examples, the increment can also vary in terms of sequential reads such that a card can be incremented in a repeating sequence of 1, 3, 5, 2, 2,.... The specific sequence or algorithmic sequence can be defined during personalization or in one or more processes derived from the unique identifier. This can make it more difficult for a replay attacker to generalize from a small number of card instances.
[0076] The authentication message can be delivered in hexadecimal ASCII format as the content of a text NDEF record. In another example, the NDEF record can be encoded in hexadecimal format.
[0077] Figure 5 is a timing diagram showing an example sequence for providing authenticated access in accordance with one or more embodiments of the present disclosure. The sequence flow 500 can include a contactless card 102 and a client device 104, and the client device 104 can include an application 502 and a processor 504.
[0078] At line 508, the application 502 communicates with the contactless card 102 (e.g., after being brought near the contactless card 102). The communication between the application 502 and the contactless card 102 can involve the contactless card 102 being close enough to a reader (not shown) of the client device 104 to enable NFC data transfer between the application 502 and the contactless card 102.
[0079] At line 506, after communication has been established between the client device 104 and the contactless card 102, the contactless card 102 generates a Message Authentication Code (MAC) password. In some examples, this can occur when the contactless card 102 is read by the application 502. Specifically, this can occur during the reading of a Near Field Data Exchange (NDEF) tag (such as an NFC read), which can be created according to the NFC Data Exchange Format. For example, a reader application (such as the application 502) can transmit a message with the applet ID of an NDEF-producing applet, such as an applet selection message. Upon confirmation of the selection, a sequence of a select file message followed by a read file message can be transmitted. For example, the sequence can include "Select Function File", "Read Function File", and "Select NDEF File". At this point, the counter value held by the contactless card 102 can be updated or incremented, which can then be followed by "Read NDEF File". At this point, a message can be generated, which can include a header and a shared secret. A session key can then be generated. The MAC password can be created from the message, which can include the header and the shared secret. The MAC password can then be concatenated with one or more random data blocks, and the MAC password and the Random Number (RND) can be encrypted using the session key. Thereafter, the password and the header can be concatenated and encoded as ASCII hexadecimal and returned in the NDEF message format (in response to the "Read NDEF File" message).
[0080] In some examples, the MAC password can be transmitted as an NDEF tag, and in other examples, the MAC password can be included with a Uniform Resource Indicator (e.g., as a formatted string). In some examples, the application 502 can be configured to transmit a request to the contactless card 102 that includes instructions for generating the MAC password.
[0081] At line 510, the contactless card 102 sends the MAC password to the application 502. In some examples, the transmission of the MAC password occurs via NFC; however, the present disclosure is not limited to this. In other examples, such communication can occur via Bluetooth, Wi-Fi, or other wireless data communication means. At line 512, the application 502 passes the MAC password to the processor 504.
[0082] At online 514, the processor 504 verifies the MAC password according to the instructions of the application 122. For example, the MAC password can be verified as explained below. In some examples, the verification of the MAC password can be performed by a device other than the client device 104 (such as a server of a banking system that communicates data with the client device 104). For example, the processor 504 can output the MAC password for transmission to the server of the banking system, and the server of the banking system can verify the MAC password. In some examples, for verification purposes, the MAC password can act as a digital signature. Other digital signature algorithms, such as public key asymmetric algorithms (e.g., digital signature algorithms and RSA algorithms) or zero-knowledge protocols, can be used to perform such verification.
[0083] Figure 6 Shows the NDEF short record layout (SR = 1) data structure 600 according to an example embodiment. One or more applets can be configured to encode the OTP as a text label of the NDEF type 4 well-known type. In some examples, the NDEF message can include one or more records. The applet can be configured to add one or more static label records in addition to the OTP record. Exemplary labels include, but are not limited to, label type: well-known type, text, encoding English (en); applet ID: D2760000850101; function: read-only access; encoding: the authentication message can be encoded as ASCII hexadecimal; type-length-value (TLV) data can be provided as personalized parameters that can be used to generate the NDEF message. In an embodiment, the authentication template can include a first record with a well-known index for providing actual dynamic authentication data.
[0084] Figure 7 Shows a diagram of a system 700 configured to implement one or more embodiments of the present disclosure. As explained below, during the contactless card creation process, two cryptographic keys can be uniquely assigned to each card. The cryptographic keys can include symmetric keys that can be used in both the encryption and decryption of data. The triple DES (3DES) algorithm can be used by EMV and is implemented by hardware in the contactless card. By using the key diversification process, one or more keys can be derived from the master key based on the uniquely identifiable information for each entity that requires a key.
[0085] Regarding master key management, each part of a portfolio in which one or more applets are published may require two issuer master keys 702, 726. For example, a first master key 702 may include an issuer password generation / authentication key (Iss-Key-Auth), and a second master key 726 may include an issuer data encryption key (Iss-Key-DEK). As further explained herein, the two issuer master keys 702, 726 are diversified into card master keys 708, 720, which are unique for each card. In some examples, the network profile record ID (pNPR) 522 and / or the derived key index (pDKI) 724, as background data, can be used to identify which issuer master keys 702, 726 are to be used in cryptographic processes for authentication. A system that performs authentication can be configured to retrieve the values of pNPR 722 and pDKI 724 for a contactless card at the time of authentication.
[0086] In some examples, to increase the security of the solution, a session key (such as a unique key for each session) can be derived, but instead of using the master key, a unique card-derived key and a counter can be used as diversification data, as explained above. For example, each time the card is used in an operation, a different key can be used to create a message authentication code (MAC) and perform encryption. Regarding session key generation, the key used to generate a password and encrypt data in one or more applets can include a session key based on the card-unique keys (Card-Key-Auth 708 and Card-Key-Dek 720). The session keys (Aut-Session-Key 732 and DEK-Session-Key 710) can be generated by one or more applets and derived by using the application transaction counter (pATC) 704 and one or more algorithms. To fit the data into one or more algorithms, only the 2 least significant bytes of the 4-byte pATC 704 are used. In some examples, the four-byte session key derivation method can include: F1 := PATC (lower 2 bytes) || 'F0' || '00' || PATC (4 bytes) F1 := PATC (lower 2 bytes) || '0F' || '00' || PATC (4 bytes) SK := {(ALG(MK)[F1]) || ALG(MK)[F2]}, where ALG can include 3DES ECB, and MK can include the card-unique derived master key.
[0087] As described herein, one or more MAC session keys can be derived using the lower two bytes of the pATC 704 counter. At each tap of the contactless card, the pATC 704 is configured to be updated, and the card master keys Card-Key-AUTH 508 and Card-Key-DEK 720 are further diversified into the session keys Aut-Session-Key 732 and DEK-Session-KEY 710. The pATC 704 can be initialized to zero at the time of personalization or applet initialization. In some examples, the pATC counter 704 can be initialized at or before personalization and can be configured to increment by 1 each time an NDEF is read.
[0088] Further, the update for each card can be unique and can be assigned via personalization or algorithmically assigned via the pUID or other identification information. For example, odd-numbered cards can increment or decrement by 2, and even-numbered cards can increment or decrement by 5. In some examples, the update can also vary in terms of sequential reads such that one card can increment in the order of 1, 3, 5, 2, 2, … repeated. The specific sequence or algorithmic sequence can be defined at the time of personalization or in one or more procedures derived from the unique identifier. This can make it more difficult for replay attackers to generalize from a small number of card instances.
[0089] The authentication message can be delivered as the content of a text NDEF record in hexadecimal ASCII format. In some examples, only the authentication data and an 8-byte random number followed by the MAC of the authentication data can be included. In some examples, the random number can be before the cipher A and can be one block length. In other examples, there may be no restriction on the length of the random number. In further examples, the total data (i.e., the random number plus the cipher) can be a multiple of the block size. In these examples, additional 8-byte blocks can be added to match the block produced by the MAC algorithm. For another example, if the algorithm employed uses 16-byte blocks, an even multiple of that block size can be used, or the output can be padded automatically or manually to a multiple of that block size.
[0090] The MAC can be performed by the functional key (AUT-Session-Key) 732. The data specified in the cipher can be processed using the javacard.signature method: ALG_DES_MAC8_ISO9797_1_M2_ALG3 to be relevant to the EMV ARQC verification method. The key used for this calculation can include the session key AUT-Session-Key 732, as explained above. As explained above, the lower two bytes of the counter can be used to diversify one or more MAC session keys. As explained below, the AUT-Session-Key 732 can be used for the MAC data 706, and the resulting data or cipher A 714 and the random number RND can be encrypted using the DEK-Session-Key 710 to create the cipher B or output 718 sent in the message.
[0091] In some examples, one or more HSM commands can be processed for decryption such that the final 16 bytes (binary, 32 bytes hexadecimal) can include 3DES symmetric encryption using the CBC mode, where the zero IV of the random number is followed by the MAC authentication data. The key used for this encryption can include the session key DEK-Session-Key 710 derived from the Card-Key-DEK 720. In this case, the ATC value used for session key derivation is the least significant byte of the counter pATC 704.
[0092] The following format represents a binary version example embodiment. Further, in some examples, the first byte can be set to ASCII 'A'.
[0093]
[0094]
[0095] Another exemplary format is shown below. In this example, the tag can be encoded in hexadecimal format.
[0096]
[0097]
[0098] The UID field of the received message can be extracted to derive the card master keys (Card-Key-Auth 1308 and Card-Key-DEK 1320) for that particular card from the master keys Iss-Key-AUTH 902 and Iss-Key-DEK 1326. Using the card master keys (Card-Key-Auth 908 and Card-Key-DEK 1320), the counter (pATC) field of the received message can be used to derive the session keys (Aut-Session-Key 1332 and DEK-Session-Key 1310) for that particular card. The ciphertext B 1318 can be decrypted using the DEK-Session-KEY, which yields the ciphertext A 1314 and the RND, and the RND can be discarded. The UID field can be used to look up the shared secret of the contactless card, and the shared secret along with the version, UID, and pATC fields of the message can be processed by a cryptographic MAC using the recreated Aut-Session-Key to create a MAC output, such as MAC’. If MAC’ is the same as the ciphertext A 1314, this indicates that both message decryption and MAC checking have passed. Then the pATC can be read to determine if it is valid.
[0099] During an authentication session, one or more cryptographic MACs can be generated by one or more applications. For example, one or more cryptographic MACs can be generated as 3DES MACs using the ISO9797-1 algorithm 3 with method 2 padding via one or more session keys, such as Aut-Session-Key 732. The input data 706 can take the following form: version (2), pUID (8), pATC (4), shared secret (4). In some examples, the numbers in parentheses can include the length in bytes. In some examples, the shared secret can be generated by one or more random number generators, which can be configured to ensure that the random numbers are unpredictable through one or more security processes. In some examples, the shared secret can include a random 4-byte binary number injected into the card at a personalized time known to the authentication service. During the authentication session, the shared secret can not be provided to the mobile application from one or more applets. Method 2 padding can include adding a mandatory 0x‘80’ byte to the end of the input data, and adding 0x‘00’ bytes that can be added to the end of the resulting data until an 8-byte boundary is reached. The resulting cryptographic MAC can include 8 bytes in length.
[0100] In some examples, a benefit of encrypting an unshared random number as a first block along with a MAC password is that it serves as an initialization vector when using the CBC (Block chaining) mode of a symmetric encryption algorithm. This allows for "scrambling" from block to block without having to pre-establish a fixed or dynamic IV.
[0101] By including the application transaction counter (pATC) as part of the data included in the MAC password, the authentication service can be configured to determine whether the value conveyed in the plaintext data has been tampered with. Additionally, by including a version in one or more of the passwords, it is difficult for an attacker to purposefully distort the application version to attempt to degrade the strength of the password solution. In some examples, the pATC can start at zero and be incremented by 1 each time one or more applications generate authentication data. The authentication service can be configured to track the pATC used during an authentication session. In some examples, when the authentication data uses a pATC that is equal to or lower than a previous value received by the authentication service, this can be interpreted as an attempt to replay an old message, and the authenticated message can be rejected. In some examples, in the case where the pATC is greater than the previously received value, this can be evaluated to determine whether it is within an acceptable range or threshold, and if it exceeds the range or threshold or is outside of the range or threshold, the authentication can be considered a failure or unreliable. In MAC operation 712, data 706 is processed by MAC using Aut-Session-Key 732 to produce an encrypted MAC output (Cipher A) 714.
[0102] To provide additional protection against brute force attacks on keys exposed on the card, it is desirable for the MAC password 714 to be encrypted. In some examples, the data or password A 714 to be included in the ciphertext can include: a random number (8), a password (8). In some examples, the numbers in parentheses can include the length in bytes. In some examples, the random number can be generated by one or more random number generators that can be configured to ensure the random number is unpredictable through one or more secure processes. The key used to encrypt the data can include a session key. For example, the session key can include the DEK-Session-Key 710. In the encryption operation 716, the data or password A 714 and the RND are processed using the DEK-Session-Key 510 to produce the encrypted data, i.e., the password B 718. The data 714 can be encrypted using 3DES in cipher block chaining mode to ensure that an attacker must run any attack across all of the ciphertext. As a non-limiting example, other algorithms such as the Advanced Encryption Standard (AES) can be used. In some examples, an initialization vector of 0x‘000000000000000000’ can be used. Any attacker attempting to brute force the key used to encrypt the data will not be able to determine when the correct key has been used because the correctly decrypted data will not be distinguishable from the incorrectly decrypted data due to its random appearance.
[0103] To authenticate a service for verifying one or more passwords provided by one or more applets, the following data must be communicated in plaintext from the one or more applets to the mobile device during an authentication session: a version number, which is used to determine the password method used and the message format for verifying the password, which enables the method to be changed in the future; a pUID, which is used to retrieve password assets and derive a card key; and a pATC, which is used to derive a session key for the password.
[0104] Figure 8 A method 800 for generating a password is shown. For example, at block 802, a network profile record ID (pNPR) and a derived key index (pDKI) can be used to identify which issuer master keys are used in the encryption process for authentication. In some examples, the method can include performing an authentication to retrieve the values of the pNPR and pDKI for a contactless card at the time of authentication.
[0105] At block 804, the issuer master key can be diversified by combining it with the card unique ID number (pUID) and the PAN serial number (PSN) of one or more applets (e.g., a payment applet).
[0106] At block 806, Card-Key-Auth and Card-Key-DEK (unique card key) can be created by diversifying the issuer master key to generate a session key (which can be used to generate a MAC password).
[0107] At block 808, the keys used to generate passwords and encrypt data in one or more applets can include the session keys of block 1030 based on the card unique keys (Card-Key-Auth and Card-Key-DEK). In some examples, these session keys can be generated by one or more applets and derived by using pATC, resulting in the session keys Aut-Session-Key and DEK-Session-Key.
[0108] Figure 9 An exemplary process 900 showing key diversification according to one example is depicted. Initially, the sender and receiver can be equipped with two different master keys. For example, the first master key can include a data encryption master key, and the second master key can include a data integrity master key. The sender has a counter value that can be updated at block 902, and other data that can be securely shared with the receiver, such as the data to be protected.
[0109] At block 904, the counter value can be encrypted by the sender using the data encryption master key to generate a data encryption-derived session key, and the counter value can also be encrypted by the sender using the data integrity master key to generate a data integrity-derived session key. In some examples, the entire counter value or a portion of the counter value can be used during the two encryptions.
[0110] In some examples, the counter value may not be encrypted. In these examples, the counter value can be transmitted in plaintext between the sender and the receiver, i.e., without encryption.
[0111] At block 906, the data to be protected is processed in a cryptographic MAC operation by the sender using the data integrity session key and a cryptographic MAC algorithm. The protected data (including plaintext and shared secrets) can be used to generate a MAC using one of the session keys (AUT-Session-Key).
[0112] At block 908, the data to be protected can be encrypted by the sender using the data encryption-derived session key in combination with a symmetric encryption algorithm. In some examples, the MAC is combined with an equal amount of random data, for example, every 8-byte length, and then encrypted using the second session key (DEK-Session-Key).
[0113] At block 910, the encrypted MAC is transmitted from the sender to the receiver, along with information sufficient to identify additional secret information (such as a shared secret, master key, etc.), for password verification.
[0114] At block 912, the receiver uses the received counter value to independently derive two derived session keys from the two master keys as explained above.
[0115] At block 914, the data encryption derived session key is used in conjunction with a symmetric decryption operation to decrypt the protected data. Then additional processing of the exchanged data will occur. In some examples, after the MAC is extracted, it is desirable to recreate and match the MAC. For example, when verifying a password, it can be decrypted using an appropriately generated session key. The protected data can be reconstructed for verification. The MAC operation can be performed using an appropriately generated session key to determine if it matches the decrypted MAC. Since the MAC operation is an irreversible process, the only way to verify is to attempt to recreate it from the source data.
[0116] At block 916, the data integrity derived session key is used in conjunction with a cryptographic MAC operation to verify that the protected data has not been modified.
[0117] Some examples of the methods described herein can advantageously determine when successful authentication has occurred when the following conditions are met. First, the ability to verify the MAC indicates that the derived session keys are correct. The MAC can only be correct if decryption is successful and the correct MAC value is produced. Successful decryption can indicate that the correctly derived encryption key was used to decrypt the encrypted MAC. Since the derived session keys are created using master keys known only to the sender (e.g., the transmitting device) and the receiver (e.g., the receiving device), it can be trusted that the contactless card that originally created and encrypted the MAC is authentic. Additionally, the counter values used to derive the first session key and the second session key can be shown to be valid and can be used to perform authentication operations.
[0118] Thereafter, the two derived session keys can be discarded, and the next iteration of the data exchange will update the counter value (returning to block 902), and (at block 910) a new set of session keys can be created. In some examples, the combined random data can be discarded.
[0119] Figure 10Method 800 for card activation according to an example embodiment is shown. For example, card activation can be accomplished by a system including a card, a device, and one or more servers. The contactless card, device, and one or more servers can refer to the same or similar components as previously explained, such as contactless card 102, client device 104, and server.
[0120] In block 1002, the card can be configured to dynamically generate data. In some examples, the data can include information such as an account number, a card identifier, a card verification value, or a phone number, which can be transmitted from the card to the device. In some examples, one or more portions of the data can be encrypted via the systems and methods disclosed herein.
[0121] In block 1004, one or more portions of the dynamically generated data can be transferred to an application of the device via NFC or other wireless communication. For example, tapping the card near the device can allow the application of the device to read one or more portions of the data associated with the contactless card. In some examples, if the device does not include an application to assist with card activation, tapping the card can direct the device or prompt the customer to go to a software application store to download the associated application to activate the card. In some examples, the user can be prompted to gesture, place, or orient the card adequately towards the surface of the device, such as placing it at an angle or flat on, near, or close to the surface of the device. In response to the adequate posture, placement, and / or orientation of the card, the device can continue to transfer one or more encrypted portions of the data received from the card to one or more servers.
[0122] In block 1006, one or more portions of the data can be transferred to one or more servers, such as a card issuer server. For example, one or more encrypted portions of the data can be transmitted from the device to the card issuer server for activation of the card.
[0123] In block 1008, one or more servers may decrypt one or more encrypted portions of data via the systems and methods disclosed herein. For example, one or more servers may receive encrypted data from a device and may decrypt it in order to compare the received data to record data accessible to the one or more servers. If a resulting comparison by the one or more servers of one or more decrypted portions of the data yields a successful match, the card may be activated. If a resulting comparison by the one or more servers of one or more decrypted portions of the data yields an unsuccessful match, one or more processes may occur. For example, in response to a determination of an unsuccessful match, the user may be prompted to again tap, swipe, or wave the card. In such a case, there may be a predetermined threshold including the number of attempts allowed for the user to be granted activation of the card. Alternatively, the user may receive a notification, such as a message on his or her device indicating an unsuccessful attempt at card verification, and call, email, or text the associated service to assist with activating the card; or another notification, such as a phone call on his or her device indicating an unsuccessful attempt at card verification, and call, email, or text the associated service to assist with activating the card; or another notification, such as an email indicating an unsuccessful attempt at card verification, and call, email, or text to the associated service to assist with activating the card.
[0124] In block 1010, one or more servers may transmit a return message based on successful activation of the card. For example, the device may be configured to receive an output from one or more servers indicating successful activation of the card by the one or more servers. The device may be configured to display a message indicating successful activation of the card. Once the card has been activated, the card may be configured to abort dynamically generated data in order to avoid fraudulent use. In this manner, the card may not be activated thereafter, and the one or more servers are notified that the card has been activated.
[0125] As previously mentioned, some embodiments may involve performing authentication operations using a client device such as a mobile device or phone. Figure 1-10 Typically involves performing authentication using a contactless card based on information on the card and the fact that the user is in possession of the card. Thus, the contactless card satisfies the "something you have" aspect of the authentication operation. Additional embodiments discussed herein include using the contactless card 102 in combination with the client device 104 to perform authentication via "something you know".
[0126] For example, the contactless card 102 can be used with the client device 104 so that a user can provide a pattern or sequence to the client device 104 based on interacting the contactless card 102 with the client device 104. Specifically, the contactless card 102 can be used to "tap" or provide a communication or signal sequence to the client device 104 via wireless communication detected by one or more antennas of the client device 104. For example, the user can tap the contactless card 102 or bring it near the client device 104 two or more times, and each detection made by one or more antennas and one or more transceivers can be a pattern input. The pattern can be based on the number of inputs, the length of time of the inputs, the length of time between the inputs, or any combination thereof. The input pattern can be compared with an authentication pattern (whether it is local on the client device 104 or remote on the server) to determine if they match and if the input pattern is authentic.
[0127] In an embodiment, the pattern can be provided by a user interacting with a single antenna of the client device 104. However, an increasing number of client devices 104 are being provided with two or more antennas, which provides more pattern options and a higher level of security for generating patterns. Figure 11-17 These operations are generally involved and additional details are provided.
[0128] Figure 11 A rear view of the client device 104 and internal components represented by dashed lines is shown. In the configuration shown, the client device 104 includes two antennas (antenna 1102 and antenna 1104) and internal components 1108. However, the client device 104 can have a different number of antennas and still operate in accordance with the embodiments discussed herein. Additionally, Figure 11 A limited number of components are shown, and generally the client device 104 will include multiple circuits, chips, and other electronic components not shown. The back of the client device 104 can also include additional components or devices, such as a camera accessory 1106 and a speaker 1120. The embodiments are not limited in this manner.
[0129] In an embodiment, the component 1108 can include a processor 1110, a memory 1112, and one or more interfaces 1114. The memory 1112 can be configured to store computer instructions configured to be executed on the processor 1110. The instructions can be part of an application 1116 and an operating system 1118. However, the embodiments are not limited in this manner.
[0130] The processor 1110 can be any type of processor, microprocessor, circuit, circuit element (such as transistors, resistors, capacitors, inductors, etc.), integrated circuit, application specific integrated circuits (ASIC), programmable logic devices (PLD), digital signal processors (DSP), field programmable gate array (FPGA), multi-core processor, and so on.
[0131] In an embodiment, the memory 1112 can be any type of memory configured to store instructions to be processed by the processor 1110. Examples of the memory 1112 include volatile memory or non-volatile memory, removable memory or non-removable memory, erasable memory or non-erasable memory, writable memory or rewritable memory, and so on.
[0132] The client device 104 also includes one or more interfaces 1114. For example, one or more interfaces 1114 can include a WiFi interface, a Bluetooth interface, an NFC interface, a serial bus interface, a Universal Serial Bus (USB), etc. Embodiments are generally discussed with reference to wireless communication detection via one or more NFC antennas and one or more transceivers; however, embodiments are not limited to this manner. In some instances, other wireless antennas / transceivers can be configured to perform such detection, such as Bluetooth.
[0133] In an embodiment, the memory 1112 includes an application 1116 and an operating system 1118. The application 1116 can be any type of application configured to operate on the client device 104. Examples of applications can include social network applications, communication applications, business productivity applications (email / word processor / spreadsheet), storefront applications, banking applications, money transfer applications, game applications, and so on.
[0134] The application 1116 can be configured to operate in the operating system 1118 environment. The operating system 1118 can be operating system, Apple Windows Mobile operating system Etc. The operating system 1118 can be configured to provide services and instructions for executing software applications and enabling them to operate with the hardware. For example, the operating system 1118 can be configured to operate with transceiver / processor hardware to process detections via the antenna. In some instances, the operating system 1118 can provide data to the applications 1116 processed by the operating system 1118. The applications 1116 can also process data, including performing authentication of the data, communicating the data to other devices or servers, etc. In other instances, at least a portion of the operating system 1118 can be configured to perform one or more authentication steps, for example, in a secure computing environment. These and other details will become apparent in the following description.
[0135] Figure 12 An example of a system 1200 according to an embodiment is shown. The system 1200 includes a non-contact card 102 and a client device 104. In the example shown, a user can tap the non-contact card 102 onto or near one of the antennas of the client device 104 to provide an input. The user can generate a pattern by tapping the non-contact card 102 onto each of one or more antennas of the client device 104 in a specific manner.
[0136] For example, the non-contact card 102 can be tapped once onto the top antenna 1102 and the bottom antenna 1104 to provide a specific sequence that can be used to authenticate the user or perform another operation. Embodiments are not limited to a specific number of taps and / or a specific order. For example, the user can provide six taps, two taps 1202 onto or near the top antenna 1102, one tap 1202 onto or near the bottom antenna 1104, and three taps 1202 onto the top antenna 1102. Generally, the more taps 1202 there are, the more secure the pattern.
[0137] In addition, the pattern can also include the length of the tap 1202. For example, a tap 1202 that is longer than a specific time period can be considered a "long" tap, while a tap that is shorter than that time can be considered a "short" tap. The pattern can include a combination of "long" and "short" taps 1202 with any combination of antennas. In addition, embodiments are not limited to two lengths of taps (long / short); additional lengths can be considered, such as long, medium, short, etc. The time period can be predefined and known to the user, for example, ~1 second = short, ~>1 second - <~3 seconds = medium, >~3 seconds = long.
[0138] Similarly, the time periods between taps 1202 can be considered part of the pattern. For example, taps 1202 can be provided in quick succession (e.g., <~2 seconds), or there can be a longer time period between them (e.g., >~2 seconds). Thus, a user can provide 2 taps 1202 in quick succession and then wait a longer time to provide a third tap 1202. Similar to the length of the tap, the pattern can define any number of time lengths between taps, such as short, medium, and long. These different input types can be provided in any combination, e.g., the number of inputs, the sequence between multiple antennas, the length of the tap or input, and the length between taps or inputs, to create a pattern. In some embodiments, system 1200 may require a specific number and / or combination of tap types to ensure that the user meets minimum security requirements.
[0139] In certain instances, the input can be a user physically tapping the surface of client device 104 above the location of the antennas housed in the housing. In other instances, the input or tap may only require the non-contact card 102 to enter within a defined distance of client device 104 in a location near the antennas, e.g., a distance for performing an operation such as a read operation. During a single tap attempt, the non-contact card 102 can also be detected by more than one antenna. In these instances, the tap can be registered for the antenna with the strongest signal detection. The strength of the wireless signal can be based on timing measurements, signal strength measurements in polling mode, carrier frequency measurements, receive sensitivity in polling mode, measurements of load modulation (signal strength of the listener signal), etc.
[0140] In an embodiment, client device 104 can be configured to process each input including signal and communication data and determine a pattern for performing authentication or other operations. In one example, one of the applications 1116 can be configured to request the user to input a pattern using the non-contact card 102 and one or more antennas in client device 104. For example, the application can present a GUI interface and request the pattern to be input. The application receives one or more inputs provided by the non-contact card 102 being tapped and / or brought within the range of client device 104, determines the pattern, and compares the pattern with the stored authenticated pattern. If the pattern matches, the application can authenticate the user.
[0141] In certain instances, the application and / or the operating system can be configured to provide the input pattern to the server, and the server can perform authentication operations, e.g., determine that the pattern matches the stored / authenticated pattern. The pattern can be provided to the server based on the characteristics of each input. These characteristics can include which antenna performs the detection, the length of the detection, the length between detections, the order of detections, etc. In an embodiment, the data provided to the server can be encrypted using any type of encryption algorithm and key.
[0142] In an embodiment, a tap or input pattern can be used as single-factor authentication to enable a user to authenticate themselves. The authentication can enable the user to access an application or perform another operation. In some instances, the tap or input pattern can be one factor in multi-factor authentication. For example, the pattern can be used in combination with another input or factor, such as a biometric input, a password, a token, etc. In some instances, the pattern can be used in conjunction with authentication data provided by the contactless card 102 (as part of multi-factor authentication).
[0143] In some embodiments, the client device 104 can capture authentication data from the contactless card 102 as part of the input pattern. The client device 104 and / or the server can perform an authentication operation to authenticate the data and the input pattern to authenticate the user. As previously described, the authentication data can ensure that the user has the contactless card 102, and the pattern can ensure that the user knows the correct pattern. Figure 13 An example processing flow that can be performed by the client device 104 to perform authentication using the tap or input pattern is shown.
[0144] Figure 13 An example of a routine 1300 that can be performed according to an embodiment is shown. Specifically, the routine 1300 is an example of a routine that can be performed by a device to perform authentication to enable an operation.
[0145] At block 1302, the device can detect one or more signals received via one or more antennas. In one example, the one or more signals can be near field communication (NFC) signals detected by an antenna configured for NFC. The NFC signals may or may not include data. In some instances, the NFC signals can include authentication data; in some instances, the signals can include empty information or data. The device can detect the signals based on a load detected on circuitry such as a transceiver. As previously described, if a signal is detected by more than one antenna, the antenna with the highest signal strength and the associated transceiver can register the signal. In some instances, the signal strength can be greater than a threshold to be registered as a detected signal.
[0146] Each detected signal can have specific characteristics, including which antenna detected the signal, the length of the signal detection, the length of time between consecutive signals, etc. These characteristics can be used to determine a pattern in the signals. At block 1304, the device can determine the pattern of the one or more signals.
[0147] At decision block 1306, the device can determine whether the pattern matches the stored and / or authenticated pattern. Specifically, the device can compare the received pattern with the stored pattern to determine if they match. For example, it may be required that each characteristic of the received pattern match the characteristics of the stored / authenticated pattern. In some instances, the device can perform authentication. In some instances, the device sends the pattern to a server, and the server can authenticate the pattern and return a result.
[0148] If the pattern does not match the authenticated pattern, routine 1300 includes blocking the operation at block 1308. However, if the pattern matches the authenticated pattern, routine 1300 includes enabling the operation at block 1310. The operation can be any type of operation performed by the device or another device. For example, the operation can include obtaining access to an application, performing an operation within the application (accessing data / information), enabling another device to perform an operation (enabling a transaction), etc.
[0149] In some embodiments, the authentication result can be provided by the authenticating device to another device. For example, an indication of whether the pattern is authenticated can be provided to an application. The application or the server can provide the indication. Embodiments are not limited to this manner.
[0150] Figure 14 An example of sequence flow 1400 according to an embodiment is shown. In some instances, one or more authentications can be performed by a server, such as an authentication server maintained by a bank or a third-party authentication provider. In these instances, the client device can provide data for card communication to the server to perform an authentication operation, as will be discussed in more detail.
[0151] At 1402, the contactless card 102 can be tapped or brought near the client device 104 and exchange information with the client device 104. Line 1402 can represent multiple taps and communications between the contactless card 102 and the client device 104. As previously described, these taps may be in a certain pattern. In some instances, the authentication data stored on the contactless card 102 can also be provided to the client device 104 during these communications. The authentication data can be encrypted with a password and encrypted using the diversification key techniques described herein.
[0152] The communication between the contactless card 102 and the client device 104 can be NFC communication and comply with one or more NFC protocols. However, embodiments are not limited to this manner, and other wireless technologies can be used in the embodiments.
[0153] At 1404, the client device 104 can process the data and information received from the contactless card 102 and the tap pattern. For example, the client device 104 can determine the pattern provided by the user using the contactless card 102 and the characteristics corresponding to the tap. The client device 104 can encrypt the data and characteristics associated with the tap for secure communication to the server 108.
[0154] At 1406, the client device 104 can provide data corresponding to the tap to the server 108. In some instances, the client device 104 can provide only the encrypted pattern and characteristics for the server 108 to authenticate. In other instances, the client device 104 can provide the authentication data from the contactless card 102 to the server 108.
[0155] The client device 104 can provide data to the server 108 via one or more wireless and / or wired connections. In some embodiments, the server 108 can be hosted by a banking system, and the data can be communicated via communication with one or more application programming interfaces (APIs) hosted by the server 108. In other instances, the server 108 can be maintained and hosted by a third-party provider (such as a cloud computing provider), and the client device 104 can send data via one or more APIs hosted by the third-party server. The embodiments are not limited to this manner.
[0156] At 1408, the server 108 can perform one or more authentication operations to authenticate the tap pattern and, in some instances, authenticate the authentication data. The pattern of the tap can be compared with the stored and authenticated pattern of the tap associated with the user and the card. The comparison pattern can include comparing the characteristics of each tap with the stored characteristics. This can include comparing which antenna received the tap, the length of the tap, the time between taps, the sequence of taps, etc.
[0157] In addition, as described herein, the server 108 can authenticate the authentication data. Specifically, the server 108 can ensure that the counter maintained by the contactless card 102 generally matches the relevant counter maintained by the server 108. The server 108 can authenticate the data stored on the card, such as a token or a shared key.
[0158] At 1410, the server 108 can return the results of one or more authentication processes. The results include an indication as to whether the tap and / or the data is authenticated. The client device 104 can receive the indication and perform / block any operation that requires authentication.
[0159] The following Figure 15-17The corresponding descriptions generally discuss various processing flows in which a device can perform authentication of a user based on a provided tap pattern. Figure 15 An example of routine 1500 that can be performed by a mobile device according to an embodiment is shown.
[0160] In block 1502, routine 1500 detects one or more communications with a contactless card via a first short-range communication antenna of the mobile device based on the contactless card entering the communication range of the first short-range communication antenna of the mobile device. The short-range communication antenna can be an NFC antenna, which is configured to support NFC communication between the mobile device and other devices (such as contactless cards). The first short-range communication antenna can be located at a first position within the housing of the mobile device.
[0161] In block 1504, routine 1500 detects one or more different communications with the contactless card via a second short-range communication antenna of the mobile device based on the contactless card entering the communication range of the second short-range communication antenna of the mobile device, where the first short-range communication antenna and the second short-range communication antenna are different antennas. The second short-range communication antenna can also be an NFC antenna. It can be located at a second position, where the first position and the second position are different.
[0162] In block 1506, routine 1500 determines a pattern based on the one or more communications and the one or more different communications by a mobile device processor. The pattern can be based on characteristics of each communication, including sequence, length of the communication, time between communications, etc.
[0163] In block 1508, routine 1500 determines by the processor that the pattern matches a verified pattern. At block 1510, routine 1500 enables an operation by the processor in response to the pattern matching the verified pattern. The operation can include obtaining access to an application, performing an operation within the application, etc.
[0164] Figure 16 Another example routine 1600 that can be performed by a device such as a mobile device is shown.
[0165] In block 1602, routine 1600 detects a pattern of communications received by the first short-range communication antenna, the second short-range communication antenna, or both.
[0166] In block 1604, routine 1600 determines that the pattern matches a verified pattern to operate. As discussed, the device can determine whether the pattern matches based on characteristics of the pattern. In some instances, the device can perform detection and can authenticate the pattern. In other instances, the device can send the pattern to a server for authentication, and the embodiment is not limited to this manner.
[0167] In block 1606, routine 1600 performs an operation based on the pattern matching the verified pattern.
[0168] Figure 17 Shows another example of routine 1700, which can be executed by a device to authenticate a user via a tap of a contactless card.
[0169] In block 1702, routine 1700 receives two or more communications from a contactless card by a first near field communication (NFC) antenna and a second NFC antenna. The communications can be signals generated when the contactless card enters a predefined distance (e.g., ~10 centimeters (cm)) of one of the antennas. Each communication includes characteristics such as which antenna, the time of the signal length, the period between signals, etc.
[0170] In block 1704, routine 1700 determines a pattern in the two or more communications. Specifically, the device can determine the pattern based on the characteristics of each signal. In block 1706, routine 1700 compares the pattern with a verified pattern, e.g., compares the received characteristics with the stored characteristics.
[0171] In decision block 1708, routine 1700 determines whether the pattern matches the verified pattern. In block 1710, in response to the pattern matching the verified pattern, routine 1700 enables an operation to be performed. In block 1712, in response to the pattern not matching the verified pattern, routine 1700 prevents the operation from being performed.
[0172] Figure 18 Shows an embodiment of an exemplary computer architecture 1800 suitable for implementing the various embodiments described above. In one embodiment, computer architecture 1800 can include a portion of one or more of the systems or devices discussed herein, or be implemented as a portion of one or more of the systems or devices discussed herein.
[0173] As used in this application, the terms "system" and "component" are intended to refer to computer-related entities: hardware, combinations of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing computer architecture 1800. For example, a component can be, but is not limited to, a process running on a processor, a processor, a hard drive, multiple storage drives (of optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer. By way of illustration, both an application running on a server and the server can be components. One or more components can reside within a process and / or an execution thread, and components can be located on one computer and / or distributed between two or more computers. Further, components can be communicatively coupled to each other by various types of communication media to coordinate operations. This coordination can involve one-way or two-way information exchange. For example, components can pass information in the form of signals transmitted through the communication media. This information can be implemented as signals dispatched to various signal lines. In such an allocation, each message is a signal. However, further examples can alternatively employ data messages. Such data messages can be sent across various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.
[0174] The computing architecture 100 includes various common computing elements, such as one or more processors, multi-core processors, co-processors, memory units, chip sets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, the embodiments are not limited to being implemented by the computing architecture 100.
[0175] As Figure 18 shown, the computing architecture 100 includes a processor 1812, a system memory 1804, and a system bus 1806. The processor 1812 can be any of a variety of commercially available computer processors.
[0176] The system bus 1806 provides an interface for system components, including but not limited to the system memory 1804 to the processor 1812. The system bus 1806 can be any of a variety of bus structures, which can further use any of a variety of commercially available bus architectures, interconnected to a memory bus (with or without a memory controller), a peripheral bus, and a local bus. An interface adapter can be connected to the system bus 608 via a slot architecture. Example slot architectures can include but are not limited to Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (PCI), PCI (Extended) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), and similar architectures.
[0177] The computing architecture 100 may include or implement various articles of manufacture. An article of manufacture may include a computer-readable storage medium for storing logic. Examples of computer-readable storage media may include any tangible medium capable of storing electronic data, including volatile or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, and the like. Examples of logic may include executable computer program instructions implemented using any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, object-oriented code, visual code, and the like. Embodiments may also be at least partially implemented as instructions included in or on a non-transitory computer-readable medium that may be read and executed by one or more processors to enable performance of the operations described herein.
[0178] The system memory 1804 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, polymer memory such as ferroelectric polymer memory, ovonic memory, phase change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state storage devices (e.g., USB memory, solid-state drive (SSD)), and any other type of storage medium suitable for storing information. In Figure 18 the illustrative embodiment shown, the system memory 1804 may include non-volatile 1808 and / or volatile 1810. The basic input / output system (BIOS) may be stored in the non-volatile 1808.
[0179] The computer 1802 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive 1830, a disk drive 1816 for reading from or writing to a removable disk 1820, and an optical disk drive 1828 for reading from or writing to a removable optical disk 1832 (such as a CD-ROM or DVD). The hard disk drive 1830, the disk drive 1816, and the optical disk drive 1828 may be connected to the system bus 1806 via an HDD interface 1814, an FDD interface 1818, and an optical disk drive interface 1834, respectively. The HDD interface 1814 for an external drive implementation may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies.
[0180] The drives and the associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-executable instructions, and the like. For example, multiple program modules may be stored in the drives as well as in the non-volatile 1808 and volatile 1810, including an operating system 1822, one or more applications 1842, other program modules 1824, and program data 1826. In one embodiment, one or more applications 1842, other program modules 1824, and program data 1826 may include, for example, various applications and / or components of the system discussed herein.
[0181] The user may enter commands and information into the computer 1802 via one or more wired / wireless input devices (such as a keyboard 1850 and a pointing device such as a mouse 1852). Other input devices may include a microphone, an infrared (IR) remote control, a radio-frequency (RF) remote control, a gamepad, a stylus, a card reader, a dongle, a fingerprint reader, a glove, a graphics tablet, a joystick, a keyboard, a retina reader, a touch screen (such as capacitive, resistive, etc.), a trackball, a touchpad, a sensor, a stylus pen, and the like. These and other input devices are typically connected to the processor 1812 via an input device interface 1836 coupled to the system bus 1806, but may also be connected by other interfaces, such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, and the like.
[0182] A monitor 1844 or other type of display device is also connected to the system bus 1806 via an interface (such as a video adapter 1846). The monitor 1844 may be internal or external to the computer 1802. In addition to the monitor 1844, a computer typically includes other peripheral output devices, such as speakers, printers, and the like.
[0183] Computer 1802 can operate in a networked environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computer 1848. Remote computer 1848 can be a workstation, server computer, router, personal computer, portable computer, microprocessor-based entertainment appliance, peer device, or other common network node, and typically includes many or all of the elements described relative to computer 1802, although for purposes of brevity only memory / storage device 1858 is shown. The depicted logical connections include wired / wireless connections to a local area network 1856 and / or a larger network, such as a wide area network 1854. Such LAN and WAN networking environments are commonplace in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which may be connected to a global communications network, such as the Internet.
[0184] When used in a local area network 1856 networked environment, computer 1802 is connected to local area network 1856 via a wired and / or wireless communication network interface or network adapter 1838. Network adapter 1838 can facilitate wired and / or wireless communication to local area network 1856, which may also include a wireless access point disposed thereon for communicating with the wireless functionality of network adapter 1838.
[0185] When used in a wide area network 1854 networked environment, computer 1802 can include a modem 1840, be connected to a communications server on wide area network 1854, or have other means for establishing communications on wide area network 1854, such as via the Internet. Modem 1840 can be an internal or external wired and / or wireless device connected to system bus 1806 via an input device interface 1836. In a networked environment, program modules or portions thereof depicted relative to computer 1802 can be stored in remote memory / storage device 1858. It will be appreciated that the network connections shown are exemplary and other means of establishing a communications link between computers can be used.
[0186] Computer 1802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 standard family, such as wireless devices operably configured in wireless communication (e.g., IEEE 802.11 air modulation techniques). Among other things, this includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth TMWireless technology. Thus, the communication can be a predefined structure like a conventional network or just an ad hoc communication between at least two devices. Wi-Fi networks use radio technologies called IEEE 802.11 (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connections. Wi-Fi networks can be used to connect computers to each other, to the Internet, and to wired networks (which use IEEE 802.3-related media and functions).
[0187] The various elements of the devices described previously herein can include various hardware elements, software elements, or a combination of both. Examples of hardware elements can include devices, logic devices, components, processors, microprocessors, circuits, processors, circuit elements (such as transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), memory units, logic gates, registers, semiconductor devices, chips, microchips, chip sets, etc. Examples of software elements can include software components, programs, applications, computer programs, application programs, system programs, software development programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, processes, software interfaces, application programming interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. However, determining whether an embodiment uses hardware elements and / or software elements to implement can vary according to any number of factors, such as the desired computing rate, power level, heat tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints, as desired for a given implementation.
[0188] Any combination of discrete circuitry, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures can be used to implement the components and features of the devices described above. Further, where appropriate, microcontrollers, programmable logic arrays, and / or microprocessors or any combination of the foregoing can be used to implement the features of the devices. It should be noted that hardware, firmware, and / or software elements can be collectively or individually referred to herein as "logic" or "circuitry".
[0189] Figure 19is a block diagram depicting an exemplary communication architecture 1900 suitable for implementing the various embodiments described previously. The communication architecture 1900 includes various common communication elements such as transmitters, receivers, transceivers, radios, network interfaces, baseband processors, antennas, amplifiers, filters, power supplies, and so on. However, the embodiments are not limited to implementation by the communication architecture 1900, and this communication architecture can be consistent with the systems and devices discussed herein.
[0190] As Figure 19 shown, the communication architecture 1900 includes one or more clients 1902 and a server 1904. The server 1904 can implement one or more of the functions and embodiments discussed herein. The clients 1902 and the server 1904 are operably connected to one or more corresponding client data stores 1906 and server data stores 1908, which can be used to store local information of the corresponding clients 1902 and server 1904, such as cookies and / or associated context information.
[0191] The clients 1902 and the server 1904 can use a communication framework 1910 to communicate information with each other. The communication framework 1910 can implement any well-known communication technologies and protocols. The communication framework 1910 can be implemented as a packet-switched network (e.g., a public network such as the Internet, a private network such as an enterprise intranet, etc.), a circuit-switched network (e.g., a public switched telephone network), or a combination of a packet-switched network and a circuit-switched network (with appropriate gateways and converters).
[0192] The communication framework 1910 can implement various network interfaces that are arranged to receive, transfer, and connect to communication networks. The network interfaces can be regarded as a special form of input / output (I / O) interfaces. The network interfaces can adopt connection protocols including but not limited to direct connection, Ethernet (such as thick, thin, twisted pair 10 / 100 / 1000Base T and the like), Token Ring, wireless network interfaces, cellular network interfaces, IEEE 802.7a-x network interfaces, IEEE 802.16 network interfaces, IEEE 802.20 network interfaces, and similar protocols. Further, multiple network interfaces can be used to participate in various communication network types. For example, multiple network interfaces can be adopted to allow communication through broadcast, multicast, and unicast networks. If processing requirements dictate greater speed and capacity, a distributed network controller architecture can similarly be adopted to aggregate, load balance, and otherwise increase the communication bandwidth required by the client 1902 and the server 1904. The communication network can be any one of and combinations of wired and / or wireless networks, including but not limited to direct interconnection, secure custom connections, private networks (such as enterprise intranets), public networks (such as the Internet), personal area networks (PANs), local area networks (LANs), metropolitan area networks (MANs), tasks operating as nodes on the Internet (OMNI), wide area networks (WANs), wireless networks, cellular networks, and other communication networks.
Claims
1. A computer-implemented method, comprising: Detecting, via a first short-range communication antenna of a mobile device, one or more communications with the contactless card based on the contactless card entering the communication range of the first short-range communication antenna of the mobile device; Detecting, via a second short-range communication antenna of the mobile device, one or more different communications with the contactless card based on the contactless card entering the communication range of the second short-range communication antenna of the mobile device, wherein the first short-range communication antenna and the second short-range communication antenna are different antennas; Determining, by a processor of the mobile device, a pattern in the one or more communications and the one or more different communications; Determining, by the processor, that the pattern matches a verified pattern; and Enabling, by the processor, operation execution in response to the pattern matching the verified pattern.
2. The computer-implemented method according to claim 1, wherein the pattern is based on the number of detections made by the first short-range communication antenna and the second short-range communication antenna.
3. The computer-implemented method according to claim 1, wherein the pattern is based on the sequence of detections made by the first short-range communication antenna and the second short-range communication antenna.
4. The computer-implemented method according to claim 1, wherein the pattern is based on the timing between each of the detections made by the first short-range communication antenna and the second short-range communication antenna.
5. The computer-implemented method according to claim 1, wherein determining whether the pattern matches the verified pattern is one factor in a multi-factor operation.
6. The computer-implemented method according to claim 1, wherein a second factor is authentication data of the contactless card, and the method comprises: Receiving, via the first short-range communication antenna or the second short-range communication antenna, data in at least one of the one or more communications detected by the first short-range communication antenna or the one or more communications detected by the second short-range communication antenna; And Before enabling execution of the operation, determining, by the processor, that the data matches verified data.
7. The computer-implemented method according to claim 1, wherein determining that the data matches the verified data comprises: Sending, by the processor, the data to a server to perform verification of the data matching the verified data; And Receiving, by the processor, a response indicating that the data is verified.
8. The computer-implemented method according to claim 1, wherein the operation comprises one of the following: accessing an application on the mobile device, logging in to an account, automatically filling data in a field, launching an application on the mobile device, providing verification to another device, providing a token to gain access to a door, or any combination thereof.
9. The computer-implemented method according to claim 1, wherein, The one or more communications detected by the first short-range communication antenna and the one or more communications detected by the second short-range communication antenna are near-field communications.
10. The computer-implemented method according to claim 9, wherein, Each of the near-field communications includes a successful read operation.
11. An apparatus, comprising: A first short-range communication antenna; A second short-range communication antenna; A memory configured to store instructions; and a processor coupled to the memory, the first short-range communication antenna, and the second short-range communication antenna, the processor being configured to process the instructions which, when executed, cause the processor to: detect a pattern of communications received by the first short-range communication antenna, the second short-range communication antenna, or both; determine that the pattern matches a verified pattern to perform an operation; and perform the operation based on the pattern matching the verified pattern.
12. The apparatus according to claim 11, wherein, The pattern includes at least one communication detected by the first short-range communication antenna and at least one communication detected by the second short-range communication antenna.
13. The apparatus according to claim 11, wherein the pattern is based on the timing between communications, the sequence of communications, the number of communications, or a combination thereof.
14. The apparatus according to claim 11, wherein the pattern is one factor in multi-factor authentication, and the data in one or more of the communications is another factor in multi-factor authentication.
15. The apparatus according to claim 14, wherein the instructions further cause the processor to: receive data in the one or more communications; send the data to a server to perform verification of the data matching verified data; and receive a response indicating that the data is verified.
16. A non-transitory computer-readable medium comprising instructions that, when executed by a processor, cause the processor to: receive two or more communications from a non-contact card by a first near field communication (NFC) antenna, a second NFC antenna, or both; determine a pattern in the two or more communications; compare the pattern with a verified pattern; determine whether the pattern matches the verified pattern; enable an operation to be performed in response to the pattern matching the verified pattern; and prevent an operation from being performed in response to the pattern not matching the verified pattern.
17. The non-transitory computer-readable medium according to claim 16, wherein the pattern includes at least one communication detected by the first NFC communication antenna and at least one communication detected by the second NFC communication antenna.
18. The non-transitory computer-readable medium according to claim 16, wherein the pattern is based on the timing between communications, the sequence of communications, the number of communications, or a combination thereof.
19. The non-transitory computer-readable medium according to claim 16, wherein the pattern is one factor in multi-factor authentication, and the data in one or more of the communications is another factor in multi-factor authentication.
20. The non-transitory computer-readable medium according to claim 16, wherein the processor is configured to: receive data in the one or more communications; send the data to a server to perform verification of the data matching verified data; and receive a response indicating that the data is verified.