System and method for card simulation on wearable devices

By integrating a contactless card emulation system into wearable devices and utilizing near-field communication and encryption methods, the security risks of wearable devices in high-risk transactions and identity verification are resolved, enabling fast and secure card emulation data transmission and synchronization.

CN121127804APending Publication Date: 2025-12-12CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032666.7
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-03-14
Filing Date
2024-03-12
Publication Date
2025-12-12

AI Technical Summary

Technical Problem

Wearable devices pose security risks when performing high-risk transactions and identity verification, and are vulnerable to the theft and access to sensitive information by unauthorized users.

Method used

By integrating a contactless card emulation system into wearable devices, near-field communication technology is used for user authentication and card emulation data transmission. Encryption methods are combined to ensure information security, including processor verification of authentication credentials and storage of card emulation data.

Benefits of technology

It improves the security of wearable devices in high-risk transactions and identity verification, reduces the risk of unauthorized user theft and information leakage, and enables fast and secure card emulation synchronization and desynchronization.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121127804A_ABST
    Figure CN121127804A_ABST
Patent Text Reader

Abstract

Systems and methods for card simulation on a wearable device are provided. An exemplary system includes a contactless card and a wearable device. A communication field between the contactless card and the wearable device may be opened. The wearable device may receive data from the contactless card. The wearable device may emulate the applet of the contactless card, allowing the wearable device to use the applet information to complete transactions that would otherwise require the contactless card.
Need to check novelty before this filing date? Find Prior Art

Description

Cross Reference to Related Applications

[0001] This application claims priority to U.S. Patent Application No. 18 / 121,462, filed March 14, 2023, the disclosure of which is incorporated by reference herein in its entirety. TECHNICAL FIELD

[0002] The present disclosure relates to systems and methods for using contactless cards when interacting with wearable devices. BACKGROUND

[0003] Wearable devices are becoming increasingly popular among consumers. These devices, such as smartwatches, are attractive to consumers because they are able to perform many of the same functions as other non-wearable smart devices: text messaging, audio calls, scheduling, fitness tracking, and financial transactions. The functionality of wearable devices is more efficient in many ways than other smart devices, such as cell phones, because wearable devices are less cumbersome. For example, a wearable device worn on a user’s wrist can stay on the user for long periods of time, whereas a non-wearable device, such as a smart phone, can be misplaced or forgotten.

[0004] Recent advancements in wearable device technology allow users to perform high-risk transactions, such as high-value purchases, using their wearable devices. As another example, users can use their wearable devices to confirm their identity in order to gain access to their apartment, workplace, or other secure areas. As technology continues to advance, users will rely more on their wearable devices to perform more complex, higher-risk tasks.

[0005] The demand for wearable smart devices is increasing. As the functionality of wearable devices becomes more complex, there is a need for secure methods to perform these functions. Performing vulnerable tasks using wearable devices can pose many security risks to users. For example, a wearable device can be stolen by an unauthorized user and used to purchase expensive items. As another example, an unauthorized user can attempt to access a user’s sensitive personal or business information by accessing the user’s wearable device.

[0006] These deficiencies and other deficiencies exist. Therefore, a need exists to provide systems and methods that overcome these deficiencies to authenticate users in a secure and efficient manner. SUMMARY

[0007] Aspects of the present disclosure include systems and methods for card emulation on a wearable device. Generally, the following embodiments describe a secure access system and method that includes a wearable device and a contactless card. As an example embodiment, a user can tap their contactless card to their wearable device, allowing the wearable device to emulate information stored on the contactless card. Through a short-range communication field, the wearable device and the contactless card can securely share information, with little chance of interference by an unauthorized party.

[0008] Near Field Communication (NFC) requires the user to bring the physical card in close contact with the wearable device. This requirement increases the security of the exchange of information between the device and the card. Furthermore, due to the speed of the transaction, it greatly limits the risk of inadvertently sharing sensitive information to an unauthorized party.

[0009] Furthermore, an example embodiment for encryption is provided. The encryption method can generally be described as key diversification, where the sending device and the receiving device are equipped with the same master key, but independently derive the session key needed to decrypt the secret information. This embodiment of encryption increases the security of the systems and methods of the present disclosure.

[0010] Embodiments of the present disclosure provide a secure access system between a wearable device and a contactless card, the system comprising: a memory and a processor. The processor is configured to: open a communication field, and transmit an authentication request to the card after opening the communication field. The processor can receive authentication credentials from the card after transmitting the authentication request, and then verify the authentication credentials. The processor can then transmit a request for card emulation data after verifying the authentication credentials, and receive the card emulation data from the card. The processor can then store the card emulation data on the memory and emulate the card.

[0011] Embodiments of the present disclosure provide a secure access method between a wearable device and a contactless card, the method comprising the steps of: opening a communication field; transmitting an authentication request to the card after opening the communication field; receiving authentication credentials from the card after transmitting the authentication request; verifying the authentication credentials; transmitting a request for card emulation data after verifying the authentication credentials; receiving the card emulation data from the card; storing the card emulation data on a memory; and emulating the card.

[0012] Embodiments of the present disclosure provide a non-transitory computer readable medium between a wearable device and a contactless card, comprising computer executable instructions that, when executed on a processor, perform steps comprising opening a communication field, then transmitting an authentication request to the card after opening the communication field; receiving an authentication credential from the card upon transmitting the authentication request. The processor can then validate the authentication credential and transmit a request for card emulation data upon validating the authentication credential. Next, the processor can receive the card emulation data from the card and store the card emulation data on a memory. Next, the processor can emulate the card.

[0013] Further features and advantages of the disclosed systems and methods will be explained in more detail below with reference to specific example embodiments illustrated in the appended drawings. BRIEF DESCRIPTION OF DRAWINGS

[0014] For a more complete understanding of the present application, reference is now made to the following descriptions taken in connection with the accompanying drawings in which:

[0015] Figure 1 is a block diagram illustrating a system according to example embodiments.

[0016] Figure 2A is a block diagram illustrating a contactless card according to example embodiments.

[0017] Figure 2B is a block diagram illustrating a contact pad of a contactless card according to example embodiments.

[0018] Figure 3 is a diagram illustrating a contactless card and a wearable device according to example embodiments.

[0019] Figure 4 is a flowchart illustrating a method according to example embodiments.

[0020] Figure 5 is a flowchart illustrating a cryptographic method according to example embodiments.

[0021] Figure 6 is a flowchart illustrating a sequence according to example embodiments.

[0022] Figure 7 is a flowchart illustrating a sequence according to example embodiments. DETAILED DESCRIPTION

[0023] Example embodiments of the present application will now be described in order to explain the various features of the present application. The embodiments described herein are not intended to limit the scope of the present application, but rather are intended to provide examples of components, uses, and operation of the present application.

[0024] Furthermore, the described features, advantages, and characteristics of the embodiments can be combined in any suitable manner and the features, advantages, and characteristics of any one embodiment can be interchanged with those of any other embodiment. As will be realized, the embodiments can be practiced without some or all of the specific features, advantages, or characteristics set forth herein. In other instances, additional features and advantages set forth in certain embodiments can be realized and incorporated into some or all of the embodiments.

[0025] The flow and block diagrams in the drawings show the architectural, functional, and operational views of possible implementations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flow and block diagrams can represent a module, segment, or portion of instructions, which includes one or more executable instructions for implementing the specified logical function(s). In some alternative implementations, the functions noted in the blocks can occur out of the order noted in the figures. For example, two blocks shown in succession can in fact be executed substantially concurrently or the blocks can sometimes be executed in the reverse order, depending upon the functionality involved. It will also be noted that each block of the block diagrams and / or flowchart illustrations, and combinations of blocks in the block diagrams and / or flowchart illustrations, can be implemented by special purpose hardware-based systems that perform the specified functions or acts, or combinations of special purpose hardware and computer instructions.

[0026] Many user devices can emulate a card to complete a transaction. For example, a smart mobile device can emulate a credit card or debit card to pay for a coffee at a kiosk. Thus, card emulation allows a user to pay for goods and services without needing to carry their physical card. However, handheld user devices such as mobile devices, laptops, or tablets can be too bulky or too easy to misplace. Thus, the present embodiments provide a solution: user authentication and card emulation on a wearable device.

[0027] The present embodiments describe a system and method of authenticating a user via a wearable device and a card. The wearable device can open a communication field, such as a near field communication (NFC) field. The user can then move their contactless card into the communication field near the wearable device. The card can communicate authentication credentials to the wearable device. After authenticating the user, the wearable device can then request card emulation data from the card. As a non-limiting example, the card emulation data can include payment information, expiration data, and a security code. The card can communicate the emulation data to the wearable device, and the wearable device can store the emulation data in its memory. Thus, the user can emulate the card to make payments.

[0028] To add another layer of security, the wearable device can automatically unsynchronize with the card emulation data when the device is removed from the user. For example, a user can remove the wearable device when they get home from work. Once removed, the wearable device stops emulating the card. To restart emulation, the user can perform authentication again. This allows the user to quickly and securely unsynchronize and resynchronize the wearable device with the card emulation data.

[0029] Figure 1 is a diagram illustrating a system 100 in accordance with example embodiments. The system 100 can include a contactless card 110, a wearable device 120, a server 130, a network 140, and a database 150.

[0030] The system 100 can include one or more contactless cards 110, which are further explained below with reference to Figure 2A and Figure 2B In some embodiments, the contactless card 110 can wirelessly communicate with the wearable device 120 and / or the server 130 utilizing NFC in the example.

[0031] The system 100 can include a wearable device 120. The wearable device 120 can be a computer-enabled wearable device. Example computer-enabled wearable devices include, but are not limited to, an Apple Watch® or any other wearable device running the Apple iOS® operating system, a Garmin Vivoactive® or any other computer-enabled wearable device produced by Garmin, a Fitbit Versa® or any other computer-enabled wearable device produced by Fitbit, a Samsung Galaxy Watch® or any other computer-enabled wearable device produced by Samsung, or any other computer-enabled wearable device running the Google Android® operating system. As further examples, computer-enabled wearable devices can include, but are not limited to, computer-enabled watches, computer-enabled wristbands, computer-enabled eyewear, computer-enabled jewelry, computer-enabled clothing, and implantable computer-enabled devices.

[0032] The wearable device 120 can include a processor 121, a memory 122, and an application 123. The processor 121 can be a processor, microprocessor, or other processor, and the user device 120 can include one or more of these processors. The processor 121 can include processing circuitry, which can contain additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware to perform the functions described herein as needed.

[0033] The processor 121 can be coupled to the memory 122. The memory 122 can be read only memory, write-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and the wearable device 120 can include one or more of these memories. Read only memory can be factory programmable to be read only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-many memory can be programmed at one point in time after the memory chip leaves the factory. Once the memory is programmed, it can not be rewritten, but it can be read many times. Read / write memory can be programmed and reprogrammed many times after leaving the factory. It can also be read many times. The memory 122 can be configured to store one or more software applications, such as the application 123, as well as other data, such as a user's private data and financial account information.

[0034] The application 123 can include one or more software applications, such as a mobile application and a web browser, including instructions for execution on the wearable device 120. In some examples, the wearable device 120 can execute one or more applications, such as software applications, that enable, for example, network communication with one or more components of the system 100, sending and / or receiving data, and performing the functions described herein. Upon execution by the processor 121, the application 123 can provide the functionality described in this specification, specifically, implementing and performing the steps and functions of the process flows described below. These processes can be implemented in software, such as software modules, for execution by a computer or other machine. The application 123 can provide a graphical user interface (GUI) through which a user can view and interact with other components and devices within the system 100. The GUI can be formatted as a web page in, for example, hypertext markup language (HTML), extensible markup language (XML), or any other suitable form for presentation on a display device according to the application used by the user to interact with the system 100.

[0035] The wearable device 120 can also include a display 124 and an input device 125. The display 124 can be any type of device for presenting visual information, such as computer monitors, flat panel displays, and mobile device screens, including liquid crystal displays, light emitting diode displays, plasma panels, and cathode ray tube displays. The input device 125 can include any device that is available and supported by the wearable device 120 for inputting information into the wearable device 120, such as touchscreens, keyboards, mice, cursor control devices, touchscreens, microphones, digital cameras, video recorders, or camcorders. These devices can be used to input information and interact with the software and other devices described herein.

[0036] The system 100 can include a server 130. The server 130 can be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, network appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, thick clients, Internet browsers, mobile devices, kiosks, contactless cards, or other computer devices or communication devices. For example, the network-enabled computer device can include an iPhone, iPod, iPad from Apple®, any other mobile device running the Apple iOS® operating system, any device running the Microsoft Windows® mobile operating system, any device running the Google Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0037] The server 130 can include a processor 131, a memory 132, and an application 133. The processor 131 can be a processor, microprocessor, or other processor, and the server 130 can include one or more of these processors. The processor 131 can include processing circuitry, which can contain additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware to perform the functions described herein as needed.

[0038] The processor 131 can be coupled to the memory 132. The memory 132 can be read-only memory, write-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and the server 130 can include one or more of these memories. Read-only memory can be factory programmable to be read-only or one-time programmable. One-time programmability provides the opportunity for a write once and then read many times. Write-many memory can be programmed at one point in time after the memory chip is shipped from the factory. Once the memory is programmed, it can not be rewritten, but can be read many times. Read / write memory can be programmed and reprogrammed many times after it is shipped from the factory. It can also be read many times. The memory 132 can be configured to store one or more software applications, such as the application 133, as well as other data, such as a user's private data and financial account information.

[0039] The applications 133 can include one or more software applications including instructions for execution on the server 130. In some examples, the server 130 can execute one or more applications, such as software applications, that enable, for example, network communication with one or more components of the system 100, sending and / or receiving data, and performing the functions described herein. When executed by the processor 131, the applications 133 can provide the functionality described in this specification, specifically implementing and performing the steps and functions in the processing flows described below. For example, the applications 133 can be implemented to perform receiving web form data from the user device 120 and the storage device 160, maintaining a network session between the user device 120 and the storage device 160, and screening private data received from the user device 120 and the storage device 160. Such processes can be implemented in software, such as software modules, for execution by a computer or other machine. The applications 133 can provide a GUI through which a user can view and interact with other components and devices within the system 100. The GUI can be formatted as a web page in, for example, hypertext markup language (HTML), extensible markup language (XML), or any other suitable form for rendering on a display device according to the application used by the user to interact with the system 100.

[0040] The server 130 can also include a display 134 and an input device 135. The display 134 can be any type of device for presenting visual information, such as a computer monitor, a flat panel display, and a mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 135 can include any device for inputting information to the server 130 that is available and supported by the server 130, such as a touchscreen, a keyboard, a mouse, a cursor control device, a touchscreen, a microphone, a digital camera, a video recorder, or a camcorder. These devices can be used to input information and interact with the software and other devices described herein.

[0041] Further, network 140 can include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Moreover, network 140 can support an Internet network, a wireless communication network, or a cellular network, among others, or any combination thereof. Network 140 can also include one network, or any number of the above exemplary types of networks, operating as standalone networks, or in cooperation with one another. Network 140 can utilize one or more protocols of the network element or elements to which they are communicatively coupled. Network 140 can translate one or more protocols of the network devices to or from other protocols. While network 140 is depicted as a single network, it should be appreciated that, according to one or more examples, network 140 can include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network. Network 140 can also include or be configured to create one or more front channels, which can be publicly accessible and through which communications can be observable, and one or more secure back channels, which can not be publicly accessible and through which communications can not be observable.

[0042] System 100 can include database 150. Database 150 can be one or more databases configured to store data, including but not limited to a user's private data, a user's financial accounts, a user's identity, a user's transactions, and authenticated and unauthenticated documents. Database 150 can include a relational database, a non-relational database, or other database implementations, and any combination thereof, including multiple relational databases and non-relational databases. In some examples, database 150 can include a desktop database, a mobile database, or an in-memory database. Further, database 150 can be hosted internally by server 130, or can be hosted externally to server 130, such as by a server, a cloud-based platform, or any storage device in data communication with server 130.

[0043] In some examples, example procedures of the present disclosure described herein can be performed by a processing device and / or a computing device (e.g., a computer hardware device). Such a processing and / or computing device can be, for example, all or a portion of a computer and / or processor, or include but not limited to a computer and / or processor that can include, for example, one or more microprocessors, and use instructions stored in non-transitory computer-accessible media (e.g., RAM, ROM, hard drives, or other storage devices) on the computer. For example, the computer-accessible media can be a portion of the memory of the non-contact card 110, the user device 120, the server 130, the network 140, and the database 150, or other computer hardware devices.

[0044] In some examples, a computer-accessible medium (e.g., a storage device such as a hard disk, a floppy disk, a memory stick, a CD-ROM, a RAM, a ROM, etc., or a collection thereof) (e.g., in communication with the processing device) can be provided. The computer-accessible medium can have executable instructions embodied thereon. Additionally or alternatively, a storage device can be provided separate from the computer-accessible medium, which can provide instructions to the processing device to configure the processing device to perform certain example procedures, processes, and methods, for example, as described above.

[0045] Figure 2A A non-contact card 200 according to example embodiments is shown. The non-contact card 200 can include a payment card, such as a credit card, a debit card, or a gift card, issued by a service provider 205 displayed on the front or back of the card 200. In some examples, the payment card can include a dual interface non-contact payment card. In some examples, the non-contact card 200 is not associated with a payment card, and can include, but is not limited to, an identification card, a membership card, a loyalty card, a transportation card, and an access card.

[0046] The non-contact card 200 can include a substrate 210, which can include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Example substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the non-contact card 200 can have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, and the non-contact card can otherwise conform to the ISO / IEC 14443 standard. However, it should be understood that the non-contact card 200 according to the present disclosure can have different characteristics, and the present disclosure does not require that the non-contact card be implemented in a payment card.

[0047] The contactless card 200 can also include identification information 215 displayed on the front and / or back of the card, and a contact pad 220. The contact pad 220 can be configured to establish contact with another communication device, such as a user device, a smartphone, a laptop, a desktop computer, a smartwatch, some other wearable device, or a tablet. The contactless card 200 can also include processing circuitry, antennas, and other components not shown in FIG. 2. These components can be located behind the contact pad 220 or elsewhere on the substrate 210. The contactless card 200 can also include a magnetic stripe or tape, which can be located on the back of the card Figure 2A (not shown in FIG. 2).

[0048] Figure 2B A contact pad of a contactless card according to an example embodiment is shown.

[0049] As Figure 2B shown, the contact pad 220 can include processing circuitry 225 for storing and processing information, including a microprocessor 111 and a memory 112. It should be understood that the processing circuitry 225 can contain additional components, including processors, memories, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware to perform the functions described herein as needed.

[0050] The memory 112 can be read-only memory, write-once read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 200B can include one or more of these memories. Read-only memory can be factory programmable to be read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once / read-many memory can be programmed at one point in time after the memory chip is shipped from the factory. Once the memory is programmed, it can not be rewritten but can be read many times. Read / write memory can be programmed and reprogrammed many times after it is shipped from the factory. It can also be read many times.

[0051] The memory 112 can be configured to store one or more applets 113, one or more counters 114, and a customer identifier 115. The one or more applets 113 can include one or more software applications configured to execute on the one or more contactless cards, such as Java Card applets. However, it should be understood that the applets 113 are not limited to Java Card applets, but can be any software application operable on a contactless card or other device having limited memory. The one or more counters 114 can include a digital counter sufficient to store an integer. The customer identifier 115 can include a unique alphanumeric identifier assigned to a user of the contactless card 110, and the identifier can distinguish the user of the contactless card from other contactless card users. In some examples, the customer identifier 115 can identify a customer and an account assigned to the customer, and can also identify a contactless card associated with the customer account.

[0052] The processor and memory elements of the preceding example embodiments are described with reference to a contact pad, but the present disclosure is not so limited. It should be understood that these elements can be implemented external to the pad 220, or can be completely separate from the pad 220, or as other elements located in addition to the processor 111 and memory 112 elements within the contact pad 220.

[0053] In some examples, the contactless card 110 can include one or more antennas 255. The one or more antennas 255 can be placed within the contactless card 110 and surround the processing circuitry 225 of the contact pad 220. For example, the one or more antennas 255 can be integrated with the processing circuitry 225, and the one or more antennas 255 can be used with an external boost coil. As another example, the one or more antennas 255 can be external to the contact pad 220 and the processing circuitry 225.

[0054] In embodiments, the coil of the contactless card 110 can act as a secondary of a hollow transformer. The terminal can communicate with the contactless card 110 by cutting power or amplitude modulation. The contactless card 110 can use a gap in the power connection of the contactless card to infer data transmitted from the terminal, which can be functionally maintained by one or more capacitors. The contactless card 110 can communicate by switching a load on the coil of the contactless card or load modulation. The load modulation can be detected in the terminal coil by interference.

[0055] As described above, the contactless card 110 can be built on a software platform that can operate on a smart card or other device with limited memory, such as a JavaCard, and can securely execute one or more applications or applets. An applet can be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet can be configured to respond to one or more requests from a reader, such as a mobile NFC reader, such as a near field data exchange request, and produce an NDEF message that includes a cryptographically secure OTP encoded as an NDEF text tag.

[0056] Figure 3 is a schematic diagram illustrating a wearable device and a contactless card in a communication field, according to an example embodiment.

[0057] The schematic diagram 300 illustrates a wearable device 305, a communication field 310, and a contactless card 315. The wearable device 305 can include a wearable smart device, such as a smart watch. The wearable device will be discussed further with reference to Figure 1 The communication field 305 can include Bluetooth, NFC, radio frequency identification (RFID), and / or Wi-Fi, among others. Reference is made to Figure 2A and Figure 2B The contactless card 315 is explained further.

[0058] The wearable device 305 enters the communication field 310. The communication field 310 can open in response to a request from a card, a server, or another user device or merchant device. As another non-limiting example, the communication field 310 can open in response to the wearable device 305 approaching the contactless card 315. The user can then place the contactless card 315 within the communication field 305. Once the wearable device 305 and the contactless card 315 are within the communication field 310, the wearable device 305 can authenticate the identity of the user with one or more authentication credentials from the contactless card 315. In addition, the contactless card 315 can transfer card emulation data to the wearable device 305. Non-limitingly, data and / or applets stored on the contactless card 315 can be transferred to the wearable device 305. The data and / or applets can be stored in a memory of the wearable device 305. With the data and / or applets stored on the wearable device 305, the wearable device 305 can emulate the contactless card 315 to conduct transactions. The emulation can be implemented by a processor of the wearable device 305, a processor associated with a server, or some other processor.

[0059] While the diagram 300 illustrates only one contactless card, it is understood that the wearable device 305 can interact with multiple contactless cards. The wearable device 305 can emulate one or more contactless cards 315 via analog data communicated over the communication field 310.

[0060] Figure 4 is a flowchart illustrating a method 400 according to example embodiments.

[0061] The method 400 can begin with action 405, in which the wearable device can open a communication field. This action can be performed by a processor associated with the wearable device. The communication field can be opened in response to a request from a server, a different user device, or the wearable device or a merchant device. The opened communication field can include Bluetooth, NFC, radio frequency identification (RFID), and / or Wi-Fi, among others. In other embodiments, the processor associated with the wearable device can open the communication field in response to being in proximity to one or more contactless cards. In other embodiments, the communication field can be opened in response to a command entered by the user through one or more software applications on the wearable device.

[0062] In action 410, an authentication request can be transmitted to the contactless card. This action can be performed by a processor associated with the wearable device. The processor can be associated with a separate server. The authentication request is for authenticating the identity of the user. It is understood that other authentication request(s) can be sent and can request different authentication credentials, such as a biometric, a password, a personal identification number (PIN), or some other multi-factor authentication.

[0063] In action 415, the wearable device can receive an authentication credential from the contactless card. The contactless card can transmit the authentication credential over the communication field. The authentication credential can be configured to satisfy the authentication request. The authentication credential can include, but is not limited to, a unique customer identifier, a counter value, or some other unique information. In some embodiments, the authentication credential can be a cryptographic message authentication code (MAC), in which case the contactless card and the wearable device will perform a diversified key exchange. Further reference Figure 5 The diversified key exchange is discussed. In action 420, the authentication credential is verified. This action can be performed by the wearable device or the server.

[0064] In act 425, a request for card emulation data can be transmitted to the contactless card. This act can be performed by a processor associated with the wearable device or the server. The request for card emulation data can be transmitted over the communication field. In some embodiments, the wearable device can retain the same communication field from acts 405-430. In other embodiments, the wearable device can open a first communication field to receive the authentication credential, then close the first communication field, and then open a second communication field to receive the card emulation data. In other embodiments, the wearable device can transmit the request for card emulation data to the server over a wireless network.

[0065] In act 430, the wearable device can receive the card emulation data. The card emulation data can be transmitted directly from the contactless card. In other embodiments, the wearable device can receive the card emulation data from the server. The card emulation data can include, but is not limited to, a primary account number (PAN), a card verification value (CVV), a security code, expiration data, a cardholder name, and a service provider. Upon receiving the card emulation data, in act 435, the wearable device can store the card emulation data in its memory. This act can be performed by a process associated with the wearable device. In act 440, the wearable device can emulate a card via the card emulation data. In some embodiments, the wearable device can emulate the card to complete a consumer transaction, open a locker, or otherwise complete a payment or security verification of a user’s identity. It should be understood that in other embodiments, the transaction can include, but is not limited to: accessing a secure area, such as a house or dwelling, a car, a locker, a workplace, a safe, a storage unit, or other secure area; depositing or withdrawing funds or performing other transactions at an ATM, bank, or other financial institution; making a consumer purchase; paying for a service; checking in for a reservation associated with a restaurant, dining experience, entertainment service, travel, or other consumer experience.

[0066] Figure 5 is a flowchart of a key diversification method 500 according to examples of the present disclosure.

[0067] In some examples, a sender and a recipient can wish to exchange data via a sending device and a receiving device. In some embodiments, the sending device is a contactless card and the receiving device is a wearable device and / or a server. As noted above, it should be understood that one or more sending devices and one or more receiving devices can be involved so long as the parties share the same shared secret symmetric key. In some examples, the sending device and the receiving device can be equipped with the same primary symmetric key. In other examples, the sending device can be equipped with a diversified key created using the primary key. In some examples, the symmetric key can include a shared secret symmetric key that is kept secret from all parties other than the sending device and the receiving device that are involved in exchanging secure data. It should also be understood that a portion of the data exchanged between the sending device and the receiving device includes at least a portion of data that can be referred to as a counter value. The counter value can include a number that changes each time data is exchanged between the sending device and the receiving device.

[0068] The sending device and the receiving device can be configured to communicate via NFC, Bluetooth, RFID, and / or Wi-Fi, among others. The sending device and the receiving device can be network-enabled computer devices. In some examples, the sending device can include a contactless card and the receiving device can include a server. In other examples, the receiving device can include a user device or a user device application.

[0069] The method 500 can begin at step 505. In step 505, the sending device and the receiving device can be equipped with the same primary key, such as the same primary symmetric key. When the sending device is ready to process sensitive data with symmetric cryptography, the sending device can update a counter. Further, the sending device can select an appropriate symmetric cryptographic algorithm, which can include at least one of a symmetric encryption algorithm, an HMAC algorithm, and a CMAC algorithm. In some examples, the symmetric algorithm used to process the diversified value can include any symmetric cryptographic algorithm used to generate a diversified symmetric key of a desired length as needed. Non-limiting examples of symmetric algorithms can include symmetric encryption algorithms such as 3DES or AES 128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC.

[0070] In step 510, the sending device can employ the selected cryptographic algorithm and process the counter value 114 using the master symmetric key. For example, the sender can select a symmetric encryption algorithm and use a counter that is updated with each session between the sending device and the receiving device. The counter 114 can comprise a numeric counter sufficient to store an integer. The sending device can increment the counter one or more times. In step 515, the sending device generates two session keys: an ENC (encryption) session key and a MAC (message authentication code) session key. The sending device can encrypt the counter value using the master symmetric key with the selected symmetric encryption algorithm to create the session keys.

[0071] In step 520, the sending device generates a MAC from the counter 114, the unique customer identifier 340, and the shared secret MAC session key. The customer identifier 115 can comprise a unique alphanumeric identifier assigned to the user of the contactless card and that distinguishes the user of the contactless card from other contactless card users. In some examples, the customer identifier 115 can identify the customer and an account assigned to the customer and can also identify the contactless card associated with the customer's account.

[0072] In step 525, the sending device encrypts the MAC with the ENC session key. After encryption, the MAC can become a cryptogram. In some examples, cryptographic operations other than encryption can be performed and multiple cryptographic operations can be performed using diversified symmetric keys before the protected data is transmitted.

[0073] In some examples, the MAC cryptogram can be a digital signature used to authenticate user information. Other digital signature algorithms, such as public key asymmetric algorithms, for example, the Digital Signature Algorithm and the RSA algorithm, or zero-knowledge protocols, can be used to perform this authentication.

[0074] In step 530, the sending device transmits the cryptogram to the receiving device. The cryptogram can include the applet information 113, the unique customer identifier 115, the counter value 114, and the encrypted MAC. In step 535, the receiving device verifies the cryptogram. In act 540, the receiving device generates its own UDK (unique diversified key) using the unique customer identifier 115 and the master key. The unique customer identifier is derived from the verified cryptogram. Recall that the receiving device is already provisioned with the master key.

[0075] In act 545, the receiving device generates two session keys: an ENC (encryption) session key and a MAC (message authentication code) session key. The receiving device can generate these session keys from the UDK and the counter value. The counter value can be derived from the cryptogram.

[0076] In act 550, the receiving device decrypts the MAC from the cryptogram sent by the sending device using the session key. The encrypted output can be the same diversified symmetric key value created by the sender. For example, the receiving device can independently create its own first and second diversified session key copies using the counter. The receiving device can then use the second diversified session key to decrypt the protected data to reveal the output of the MAC created by the sending device. The receiving device can then use the first diversified session key to process the resulting data through the MAC operation.

[0077] In act 555, the receiving device verifies the MAC with the MAC session key generated in act 515. The receiving device can verify the MAC with the unique customer identifier and the counter value.

[0078] In Figure 6 Method 600 describes the unsyncing of a wearable device according to exemplary embodiments.

[0079] In act 605, the wearable device can receive card emulation data. The card emulation data can be received from a contactless card, a server, or other user device. In act 610, the wearable device can store the card emulation data in its memory.

[0080] In act 615, the user removes the wearable device from their person. Upon being removed, the wearable device can unsync with the card emulation in act 620. This ensures that the wearable device cannot emulate a card after being removed from the user. In other embodiments, the wearable device can unsync with the user or card emulation data in other ways, including but not limited to: after a predetermined amount of time; the wearable device has performed a predetermined number of transactions; an attempt at an expensive transaction; and / or an attempt at a certain predetermined transaction.

[0081] Figure 7 FIG. 7 is a flowchart illustrating a method 700 according to exemplary embodiments.

[0082] Method 700 can begin in act 705, where the wearable device can open a communication field. This act can be performed by a processor associated with the wearable device. The communication field can be opened in response to a request from a server, a different user device, or the wearable device or a merchant device. The opened communication field can include Bluetooth, NFC, radio frequency identification (RFID), and / or Wi-Fi, among others. In other embodiments, the processor associated with the wearable device can open the communication field in response to being in proximity to one or more contactless cards. In other embodiments, the communication field can be opened in response to a command entered by the user through one or more software applications on the wearable device.

[0083] In act 710, an authentication request can be transmitted to the contactless card. This act can be performed by a processor associated with the wearable device. The processor can be associated with a separate server. The authentication request is for authenticating the identity of the user. It should be understood that other authentication request(s) can be sent and can request different authentication credentials, such as a biometric, a password, a PIN, or some other multi-factor authentication.

[0084] In act 715, the wearable device can receive authentication credentials from the contactless card. The contactless card can transmit the authentication credentials over the communication field. The authentication credentials can be configured to satisfy the authentication request. The authentication credentials can include, but are not limited to, a unique customer identifier, a counter value, or some other unique information. In some embodiments, the authentication credentials can be a cryptographic message authentication code (MAC), in which case the contactless card and the wearable device will perform a diversified key exchange. Further reference is made to Figure 5 The diversified key exchange is discussed.

[0085] In act 720, the authentication credentials are verified. This act can be performed by the wearable device or the server. For example, the wearable device can transmit the authentication credentials to the server over a wireless network, and then the server can verify the credentials, and then the server can return a verification message to the user device.

[0086] In act 725, a request for card emulation data can be transmitted to the contactless card. This act can be performed by a processor associated with the wearable device or the server. The request for card emulation data can be sent over the communication field. In some embodiments, the wearable device can retain the same communication field from acts 705-730. In other embodiments, the wearable device can open a first communication field to receive the authentication credentials, then close the first communication field, and then open a second communication field to receive the card emulation data. In other embodiments, the wearable device can transmit the request for card emulation data to the server over a wireless network.

[0087] In act 730, the wearable device can receive the card emulation data. The card emulation data can be transmitted directly from the contactless card. In other embodiments, the wearable device can receive the card emulation data from the server. The card emulation data can include, but is not limited to, a primary account number (PAN), a card verification value (CVV), a security code, expiration data, a cardholder name, and a service provider.

[0088] Upon receiving the card emulation data, the wearable device can store the card emulation data in its memory in act 735. This act can be performed by a process associated with the wearable device. The wearable device can emulate the card via the card emulation data. In some embodiments, the wearable device can emulate the card to complete, without limitation, a consumer transaction, withdrawal or deposit of cash, opening of a locker, and / or otherwise completing a payment or security verification of a user's identity. The wearable device can emulate the card using a cardlet of the card. The cardlet can be added to a contactless card to provide an OTP for multi-factor authentication (MFA) in various mobile application-based use cases. The cardlet can be configured to respond to one or more requests from a reader, such as a mobile NFC reader, such as a near field data exchange request, and produce an NDEF message that includes a cryptographically secure OTP encoded as an NDEF text tag.

[0089] In act 740, the wearable device can de-synchronize with the card emulation. De- synchronization can occur as a result of one or more acts, including, without limitation: removal of the wearable device from the user; passage of a predetermined amount of time; the wearable device leaving a particular geographic area; the card emulation reaching a certain number of uses, transactions, or payments; and manual de-synchronization of the card via one or more software applications on one or more user devices. These non-limiting examples are referred to as de-synchronization events. The wearable device can be configured to de-synchronize only upon removal from the user. In other words, as long as the wearable device is worn by the user, the wearable device can be configured to remain synchronized with the user and / or the card emulation data.

[0090] In act 745, the wearable device can re-synchronize with the card emulation data. Re- synchronization can require re-authenticating the user, including, without limitation, one or more different authentication credentials, such as an OTP, a biometric, a PIN, a password, or other authentication factors. It will be appreciated that these factors can also be used for the first authentication credentials. The need to re-authenticate the user to re-synchronize the card emulation data ensures the security of the wearable device.

[0091] In some aspects, the technology described herein relates to a system for secure access between a wearable device and a contactless card, the system comprising: a memory; and a processor, wherein the processor is configured to: open a communication field; transmit an authentication request to the card after opening the communication field; receive an authentication credential from the card after transmitting the authentication request; verify the authentication credential; transmit a request for card emulation data after verifying the authentication credential; receive the card emulation data from the card; store the card emulation data on the memory; and emulate the card.

[0092] In some aspects, the technology described herein relates to a system, wherein the wearable device is a smartwatch.

[0093] In some aspects, the technology described herein relates to a system, wherein the wearable device can perform a transaction with card emulation data, the transaction comprising at least one selected from a group of transactions associated with an automated teller machine (ATM), a bank, or other financial institution.

[0094] In some aspects, the technology described herein relates to a system, wherein the transaction is one or more secure transactions conducted at a place of business, a residence, or other private institution.

[0095] In some aspects, the technology described herein relates to a system, wherein the wearable device continues to emulate card information as long as the wearable device remains worn.

[0096] In some aspects, the technology described herein relates to a system, wherein the wearable device is further configured to retain card information upon the wearable device being de-synchronized from the user.

[0097] In certain aspects, the technology described herein relates to a method of secure access between a wearable device and a contactless card, the method comprising the steps of: opening a communication field; transmitting an authentication request to the card upon opening the communication field; receiving an authentication credential from the card upon transmitting the authentication request; verifying the authentication credential; transmitting a request for card emulation data upon verifying the authentication credential; receiving the card emulation data from the card; storing the card emulation data on a memory; and emulating the card.

[0098] In some aspects, the technology described herein relates to a method, wherein the authentication credential is at least one selected from a group of a unique customer identifier and a counter value.

[0099] In some aspects, the technology described herein relates to a method, wherein the card emulation data comprises at least one selected from a group of a primary account number (PAN), a card verification value (CVV), and a security code.

[0100] In some aspects, the technology described herein relates to a method, wherein the card emulation is performed via a software application associated with the processor.

[0101] In some aspects, the technology described herein relates to a method, wherein the communication field comprises at least one selected from a group of a near field communication field (NFC), Bluetooth, and a radio frequency identification (RFID) field.

[0102] In some aspects, the technology described herein relates to a method, wherein the method further comprises the step of: de-synchronizing the wearable device from the card emulation upon occurrence of one or more predetermined de-synchronization events.

[0103] In some aspects, the technology described herein relates to a non-transitory computer readable medium containing computer executable instructions that, when executed by a wearable device comprising a processor, configure the computer hardware apparatus to perform a procedure comprising: opening a communication field; after opening the communication field, transmitting an authentication request to a card; after transmitting the authentication request, receiving an authentication credential from the card; verifying the authentication credential; after verifying the authentication credential, transmitting a request for card emulation data; receiving the card emulation data from the card; storing the card emulation data on a memory; and emulating the card.

[0104] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the wearable device is a smart watch.

[0105] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the procedure further comprises the step of performing one or more financial transactions at an automated teller machine (ATM), a bank, or other financial institution.

[0106] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the procedure further comprises the step of performing one or more secure transactions at a place of business, a residence, or other private institution.

[0107] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the verifying of the authentication credential comprises transmitting the authentication credential by the wearable device to one or more servers, and receiving by the wearable device from the one or more servers a verification message indicating that the authentication credential has been verified.

[0108] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the procedure further comprises the step of the wearable device continuing to emulate the card information as long as the wearable device remains worn.

[0109] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the procedure further comprises the step of retaining the card information after the wearable device is de-synchronized with the user.

[0110] In some aspects, the technology described herein relates to a non-transitory computer readable medium, wherein the procedure further comprises the step of re-synchronizing the wearable device.

[0111] After the card emulation data is stored in act 735, when the user wants to re-synchronize the wearable device, the wearable device can simply retrieve the card emulation data. In other embodiments, the wearable device can still want to retrieve the card emulation data from a server or some other user device.

[0112] While embodiments of the application have been described herein in the context of particular implementations in particular environments for particular purposes, those of ordinary skill in the art will appreciate that its usefulness is not limited thereto and that the embodiments of the application can be advantageously implemented in other relevant environments for similar purposes. Thus, the application should not be limited by the foregoing description, but only by the scope of the claims appended hereto and equivalents thereof.

[0113] As used herein, user information, personal information, and sensitive information can include any information related to a user, such as private information and non-private information. Private information can include any sensitive data, including financial data (e.g., account information, account balances, account activity), personal information / personal identifying information (e.g., social security numbers, home or work addresses, birth dates, phone numbers, email addresses, passport numbers, driver’s license numbers), access information (e.g., passwords, security codes, authorization codes, biometric data), and any other information that a user can wish to avoid disclosing to unauthorized persons. Non-private information can include any data that is publicly known or not intended to be kept secret.

[0114] In the present application, various embodiments have been described in connection with the accompanying drawings. However, it will be readily apparent to those skilled in the art that various modifications and changes can be made therein without departing from the broader scope of the application as set forth in the claims that follow. The

[0115] The present application is not to be limited to the specific embodiments described herein, which are intended for illustration purposes only. Many modifications and variations within the spirit and scope of the present application will be apparent to those skilled in the art from this representative description. This representative description is intended to cover any and all adaptations or variations of the present application and includes equivalents thereof within the scope of the claims. The present application is limited only by the claims appended hereto and equivalents thereof within the full scope of the claims.

[0116] As used herein, the terms “card” and “contactless card” are not limited to a particular type of card. Rather, it is understood that, unless otherwise specified, the term “card” can refer to a contact-based card, a contactless card, or any other card. It is also understood that the present disclosure is not limited to a card having a particular purpose (e.g., a payment card, a gift card, an identification card, or a membership card), a card associated with a particular type of account (e.g., a credit account, a debit account, a membership account), or a card issued by a particular entity (e.g., a financial institution, a government entity, or a social club). Rather, it is understood that the present disclosure includes a card having any purpose, account association, or issuing entity.

[0117] It should also be noted that the systems and methods described herein can be tangibly embodied in one or more physical media, such as, but not limited to, an optical disc (CD), a digital versatile disc (DVD), a floppy disk, a hard drive, a read-only memory (ROM), a random access memory (RAM), and other physical media capable of storing data. For example, data storage can include random access memory (RAM) and read-only memory (ROM), which can be configured to access and store data and information and computer program instructions. Data storage can also include storage media or other suitable types of memory (e.g., such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard drives, removable cartridges, flash drives, any type of tangible and non-transitory storage medium), in which files including operating systems, application programs including, for example, web browser applications, email applications, and / or other applications, and data files can be stored. Data storage of a network-enabled computer system can include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases such as databases created and maintained with software from, for example, Oracle®, Microsoft® Excel files, Microsoft® Access files, solid state storage devices (which can include flash arrays, hybrid arrays, or server-side products), enterprise storage (which can include online or cloud storage), or any other storage mechanism. Furthermore, the figures show various components (e.g., servers, computers, processors, etc.) separately. The functions described as being performed at the various components can be performed at other components, and the various components can be combined or separated. Other modifications can also be made.

[0118] Computer readable program instructions described herein can be downloaded to respective computing / processing devices from a computer readable storage medium or to an external computer or external storage device via a network, for example, the Internet, a local area network, a wide area network and / or a wireless network. The network can comprise copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer readable program instructions from the network and forwards the computer readable program instructions for storage in a computer readable storage medium within the respective computing and / or processing device.

[0119] Computer readable program instructions for carrying out operations of the present application can be assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine dependent instructions, microcode, firmware instructions, state-setting data, or any combination of source code or object code in any combination of one or more programming languages including an object oriented programming language such as Java, Smalltalk, or C++ and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer readable program instructions can execute entirely on the user's computer, partly on the user's computer, as a stand-alone software package, partly on the user's computer and partly on a remote computer or entirely on the remote computer or server. In the latter scenario, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection can be made to an external computer (for example, through the Internet using an Internet Service Provider). In some embodiments, electronic circuitry including, for example, programmable logic circuitry, field-programmable gate array (FPGA), or programmable logic array (PLA) can execute the computer readable program instructions by utilizing state information of the computer readable program instructions to personalize the electronic circuitry, in order to perform aspects of the present application.

[0120] These computer readable program instructions can be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data processing apparatus, create means for implementing the functions specified in the flowchart block or blocks. These computer readable program instructions can also be stored in a computer readable storage medium that can direct a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer readable storage medium having instructions stored therein comprises an article of manufacture including

[0121] The computer readable program instructions can also be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer implemented process such that the instructions which execute on the computer, other programmable apparatus or other device implement the functions specified in the flowchart block or blocks.

[0122] Implementations of the various techniques described herein can be implemented in digital electronic circuitry, or in computer hardware, firmware, software, or in combinations of them. Implementations can be implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, e.g., in a machine-readable storage device or in a propagated signal, for execution by, or to control the operation of, data processing apparatus, e.g., a programmable processor, a computer, or multiple computers. A computer program, such as the computer program(s) described above, can be written in any form of programming language, including compiled or interpreted languages, and can be deployed in any form, including as a stand-alone program or as a module, component, subroutine, or other unit suitable for use in a computing environment. A computer program can be deployed to be executed on one computer or on multiple computers at one site or distributed across multiple sites and

[0123] Method steps can be performed by one or more programmable processors executing a computer program to perform functions by operating on input data and generating output. Method steps also can be performed by, and an apparatus can be implemented as, special purpose logic circuitry, e.g., an FPGA (field programmable gate array) or an ASIC (application-specific integrated circuit).

[0124] The foregoing description of exemplary embodiments provides non-limiting representative examples citing reference numerals referring to features and teachings of different aspects of the present application. The described embodiments are to be considered in a non-limiting sense as being separable from or combinable with other embodiments described in the description of embodiments. Those of ordinary skill in the art having the benefit of the description of embodiments should be able to learn and understand the different described aspects of the present application. The description of embodiments is to facilitate understanding of the present application to the extent that other implementations not specifically covered but within the knowledge of those of ordinary skill in the art reading the description of embodiments will be understood to be consistent with the application.

Claims

1. A secure access system between a wearable device and a contactless card, the system comprising: a memory; and a processor, wherein the processor is configured to: open a communication field; after opening the communication field, transmit an authentication request to a card; after transmitting the authentication request, receive authentication credentials from the card; verify the authentication credentials; after verifying the authentication credentials, transmit a request for card emulation data; receive card emulation data from the card; store the card emulation data on the memory; and emulate the card.

2. The system of claim 1, wherein, The wearable device is a smartwatch.

3. The system of claim 1, wherein, The wearable device is capable of performing transactions with the card emulation data, the transactions comprising at least one selected from a group of transactions associated with an automated teller machine (ATM), a bank, or other financial institution.

4. The system of claim 3, wherein, The transactions are one or more secure transactions at a place of business, a residence, or other private institution.

5. The system of claim 1, wherein, The wearable device continues to emulate card information as long as the wearable device remains worn.

6. The system of claim 1, wherein, The wearable device is further configured to retain the card information after the wearable device is unsynchronized with a user.

7. A secure access method between a wearable device and a contactless card, the method comprising the steps of: opening a communication field; after opening the communication field, transmitting an authentication request to a card; after transmitting the authentication request, receiving authentication credentials from the card; verifying the authentication credentials; after verifying the authentication credentials, transmitting a request for card emulation data; receiving card emulation data from the card; storing the card emulation data on a memory; and emulating the card.

8. The method of claim 7, wherein, The authentication credentials are at least one selected from a group of a unique customer identifier and a counter value.

9. The method of claim 7, wherein, The card emulation data comprises at least one selected from a group of a primary account number (PAN), a card verification value (CVV), and a security code.

10. The method of claim 7, wherein, The card emulation is performed via a software application associated with the processor.

11. The method of claim 7, wherein, The communication field comprises at least one selected from a group of a near communication field (NFC), Bluetooth, and a radio frequency identification (RFID) field.

12. The method of claim 7, wherein, The method further comprises the steps of: after one or more predetermined unsynchronization events occur, unsynchronizing the wearable device with the card emulation.

13. A non-transitory computer readable medium containing computer executable instructions that, when executed by a wearable device comprising a processor, configure the computer hardware device to perform a program, comprising: opening a communication field; after opening the communication field, transmitting an authentication request to a card; after transmitting the authentication request, receiving authentication credentials from the card; verifying the authentication credentials; after verifying the authentication credentials, transmitting a request for card emulation data; receiving card emulation data from the card; storing the card emulation data on a memory; and emulating the card.

14. The non-transitory computer-readable medium of claim 13, wherein, The computer wearable device is a smartwatch.

15. The non-transitory computer-readable medium of claim 13, wherein, The program further comprises the step of performing one or more financial transactions at an automated teller machine (ATM), a bank, or other financial institution.

16. The non-transitory computer-readable medium of claim 13, wherein, The program further comprises the step of performing one or more secure transactions at a place of business, a residence, or other private institution.

17. The non-transitory computer-readable medium of claim 13, wherein, The verification of the authentication credentials comprises: transmitting, by the wearable device, authentication credentials to one or more servers, and receiving, by the wearable device from the one or more servers, a verification message indicating that the authentication credentials have been verified.

18. The non-transitory computer-readable medium of claim 13, wherein, The program further includes the step of the wearable device continuing to emulate card information as long as the wearable device remains worn.

19. The non-transitory computer-readable medium of claim 13, wherein, The program further includes the step of the wearable device retaining the card information after the wearable device is unsynchronized with the user.

20. The non-transitory computer-readable medium of claim 19, wherein, The program further includes the step of resynchronizing the wearable device.