System and method for managing password using contactless card

By generating encrypted data through NFC communication between the contactless card and the user's device and comparing it with the server, the problem of insufficient security of CVV ​​verification is solved, and a more secure password management process is realized.

CN121153052APending Publication Date: 2025-12-16CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202480032164.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Priority Date
2023-03-13
Filing Date
2024-03-11
Publication Date
2025-12-16

AI Technical Summary

Technical Problem

Existing technology has security limitations when users forget their online account passwords, and CVV authentication is needed to manage passwords with more secure authentication factors.

Method used

Using contactless cards as authentication factors, the user equipment communicates with the contactless cards via NFC to generate and verify ciphertext. The server then compares the stored ciphertext with the data to authenticate the user and complete password management related operations.

Benefits of technology

It provides a more secure password management method than CVV, reduces the risk of contactless card information being stolen, and improves the security and reliability of user authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121153052A_ABST
    Figure CN121153052A_ABST
Patent Text Reader

Abstract

A method includes receiving, by a server, a message from a user device of a user indicating a forgetting password for an online account of the user; verifying, by the server, the at least one contactless card associated with the online account; transmitting, by the server, a first notification to the user equipment requesting the user to tap the at least one contactless card to the user equipment; receiving, by the server, the generated ciphertext from the user equipment, wherein the generated ciphertext is generated by at least one contactless card; comparing, by the server, the generated ciphertext with a stored ciphertext associated with the at least one contactless card; and in response to a determination that the generated ciphertext matches the stored ciphertext, transmitting, by the server to the user device, a second notification indicating that the user is authenticated to perform an action related to the forgotten password.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Cross Reference to Related Applications

[0002] This application claims priority to U.S. Patent Application Serial No. 18 / 120,847, filed March 13, 2023, the disclosure of which is incorporated herein in its entirety by reference. TECHNICAL FIELD

[0003] The present disclosure relates generally to data security, and more particularly, to systems and methods for password management using a contactless card as one authentication factor in multi-factor authentication. BACKGROUND

[0004] Data security and transaction integrity are of paramount importance to businesses and consumers. When a customer forgets his / her password for an online account associated with a merchant and desires to reset the password, the merchant can authenticate the customer by requiring the customer to provide additional information known to the customer, such as a card verification value (CVV) associated with a credit card stored in the online account.

[0005] While the use of CVVs is a common item of additional information used when a customer forgets his / her password, data security and anti-fraud creation requires more comparable or even more secure options for customers to retrieve their passwords and / or reset them.

[0006] These and other deficiencies exist. Accordingly, there is a need to provide systems and methods that overcome these deficiencies to manage passwords using more secure factors. SUMMARY

[0007] Aspects of the disclosed technology include systems and methods for password management using a contactless card, such as using a contactless card as one authentication factor in multi-factor authentication.

[0008] Embodiments of the present disclosure provide a method for password management using a contactless card. The method includes receiving, by a server, a message from a user device of a user indicating a forgotten password for an online account of the user; verifying, by the server, at least one contactless card associated with the online account; transmitting, by the server, a first notification to the user device requesting the user to tap the at least one contactless card to the user device; receiving, by the server, a generated cryptogram from the user device, wherein the generated cryptogram is generated by the at least one contactless card; comparing, by the server, the generated cryptogram to a stored cryptogram associated with the at least one contactless card; and responsive to a determination that the generated cryptogram matches the stored cryptogram, transmitting, by the server, a second notification to the user device indicating that the user is authenticated to perform an action related to the forgotten password.

[0009] Embodiments of the present disclosure provide a system for password management using contactless cards. The system includes a server. The server can be configured to receive, from a user device of a user, a message indicating a forgotten password for an online account of the user; verify at least one contactless card associated with the online account; transmit, to the user device, a first notification requesting the user to tap the at least one contactless card to the user device; receive, from the user device, generated ciphertext, wherein the generated ciphertext is generated by the at least one contactless card; compare the generated ciphertext to stored ciphertext associated with the at least one contactless card; and in response to a determination that the generated ciphertext matches the stored ciphertext, transmit, to the user device, a second notification indicating that the user is authenticated to perform an action related to the forgotten password.

[0010] Embodiments of the present disclosure provide a non-transitory computer readable medium comprising instructions for password management using contactless cards, the instructions, when executed on a computer device, perform actions comprising: receiving, from a user device of a user, a message indicating a forgotten password for an online account of the user; verifying at least one contactless card associated with the online account; transmitting, to the user device, a first notification requesting the user to tap the at least one contactless card to the user device; receiving, from the user device, generated ciphertext, wherein the generated ciphertext is generated by the at least one contactless card; comparing the generated ciphertext to stored ciphertext associated with the at least one contactless card; and in response to a determination that the generated ciphertext matches the stored ciphertext, transmitting, to the user device, a second notification indicating that the user is authenticated to perform an action related to the forgotten password.

[0011] Further features of the disclosed system and method, and advantages provided by the same, are explained in more detail below with reference to specific example embodiments illustrated in the appended drawings. BRIEF DESCRIPTION OF DRAWINGS

[0012] Figure 1 is a diagram of a system for managing passwords using contactless cards in accordance with example embodiments.

[0013] Figure 2 is a sequence diagram of interactions between components of the system in Figure 1 in accordance with example embodiments.

[0014] Figure 3A is a contactless card used in managing passwords in accordance with example embodiments.

[0015] Figure 3B is a diagram of a processor of a contactless card in Figure 3A in accordance with example embodiments.

[0016] Figure 4is a flowchart of a method for managing passwords using a contactless card according to example embodiments.

[0017] Figure 5 is a diagram of another system for managing passwords using a contactless card according to example embodiments.

[0018] Figure 6 is a sequence diagram of the interaction between components of the system in Figure 5

[0019] Figure 7 is a flowchart of a method for managing passwords using a contactless card according to example embodiments. DETAILED DESCRIPTION

[0020] The description of the following embodiments is provided as non-limiting representative examples with reference to numbers in order to particularly describe features, teachings and advantages of different aspects of the present invention. The described embodiments are to be considered as being capable of being implemented separately, or in combination with other embodiments from the description of the embodiments, and the features, teachings and advantages of any embodiment can be interchangeably combined with the features, teachings and advantages of any other embodiment. A person of ordinary skill in the art reviewing the description of the embodiments will learn and understand the different described aspects of the present invention. The description of the embodiments will facilitate the understanding of the present invention to such an extent that other implementations, not specifically covered but within the knowledge of a person skilled in the art upon reading the description of the embodiments, will be understood as being in accordance with the application of the present invention.

[0021] Furthermore, embodiments can be combined in any suitable manner. A person of ordinary skill in the art will recognize that embodiments can be practiced without one or more of the specific features, teachings or advantages of an embodiment. In other instances, additional features, teachings or advantages can be recognized in certain embodiments that can not be present in all embodiments. A person of ordinary skill in the art will understand that the described features, teachings and advantages of any embodiment can be interchangeably combined with the features, teachings and advantages of any other embodiment.

[0022] Example embodiments of the present disclosure provide systems and methods for authenticating a user using a contactless card as one authentication factor for managing passwords. The present invention allows a user to use information he / she has about a contactless card to complete a high risk authentication transaction (e.g., password management in the present disclosure). Thus, a user can recover and / or reset a password he / she forgot when having an NFC-enabled device (such as a mobile phone) that can read a contactless card as an authentication factor for authenticating the user.

[0023] ​This disclosure can be implemented in systems similar to CVV verification systems, and can be a low-cost alternative to CVV that can span so many business lines using contactless payment cards. The present invention provides systems and methods that are more secure than using CVV because non-payment-related contactless card information is unlikely to be obtained or known by others.

[0024] Customer experience improvements could include allowing contactless cards to be used with or without another login (e.g., logging into a banking app to read the contactless card), such as on Android devices. ® Instant Apps, iOS ® Authentication sessions within the app, long-press push notifications, and / or tapping contactless cards (e.g., in a pull-down gesture) are all part of the same experience. These actions can be initiated within an NFC session, within the banking app context itself, and / or directly in response to a notification received on the device.

[0025] In this disclosure, contactless cards can be used as an authentication method, where users can authenticate via web, tablets, non-NFC-based devices, call centers, interactive voice response (IVR), and CapitalOne. ® ENO ® Primary actions (such as high-risk transactions like PIN retrieval and / or PIN reset) can be performed on virtual assistants, bank branches, or any other channel used for customer service. In some examples, interactions with contactless cards can be initiated on NFC-enabled mobile devices using communications such as deeply linked SMS, mobile app notifications, push notifications, emails, or any other channel that can be received on the user's device.

[0026] Figure 1 A system 100 for authenticating a user using a contactless card as an authentication factor for password management, according to an example embodiment, is shown. As discussed further below, system 100 may include user equipment 120, server 130, database 140 communicating via network 150, and contactless card 160 communicating signalically with user equipment 120. Although Figure 1 A single instance of the component is shown, but system 100 may include any number of components.

[0027] User device 120 can be used by a user to initiate and / or execute transactions with server 130, for retrieving and / or resetting passwords. User device 120 can be configured to present a user interface from which the user can log in to, for example, their bank or credit card account to access their transaction reports and / or financial information stored in database 140 on server 130. The user interface can also be configured to perform data communication with contactless card 160. User device 120 can be configured to display the merchant's website on the user interface in response to the user's selection to access the merchant's website.

[0028] User equipment 120 may be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, networked appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, a network-enabled computer device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system from Apple®, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0029] User equipment 120 may include a processor 121, memory 122, applications 123, a display 124, and an input device 125. Processor 121 may be a processor, microprocessor, or other processor, and user equipment 120 may include one or more of these processors. Processor 121 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0030] Processor 121 may be coupled to memory 122. Memory 122 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and user equipment 120 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once-read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 122 may be configured to store one or more software applications (such as application 123) and other data (such as private and personal information).

[0031] Application 123 may include one or more software applications that include instructions for execution on user equipment 120. In some examples, user equipment 120 may execute one or more applications, such as software applications, that enable, for example, network communication with one or more components of system 100, transmit and / or receive data, and perform the functions and process flows described herein, such as presenting an account login interface to a user of user equipment 120 and reading contactless card 160. After execution by processor 121, application 123 may provide the functions described herein, specifically, perform and execute the steps and functions in the process flows described herein. These processes may be implemented in software, such as software modules, for execution by a computer or other machine. Application 123 may provide a graphical user interface (GUI) through which a user can view and interact with other components and devices within system 100. The GUI can be formatted as, for example, a web page in HyperText Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form, for presentation on a display device according to the application used by the user to interact with the system 100.

[0032] User equipment 120 may also include a display 124 and an input device 125. The display 124 can be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 125 may include any device available and supported by user equipment 120 for typing information into user equipment 120, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to type information and interact with the software and other devices described herein, such as selecting options to create an online account with a merchant.

[0033] Server 130 may be associated with an institution, merchant, or service provider (such as a financial institution) and may be configured to communicate with user equipment 120. The institution associated with server 130 may issue contactless cards 160 to users and thus authenticate users based on contactless cards 160.

[0034] Server 130 may be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, networked appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, a network-enabled computer device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0035] Server 130 may include processor 131, memory 132, and application 133. Processor 131 may be a processor, microprocessor, or other processor, and server 130 may include one or more of these processors. Processor 131 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0036] Processor 131 may be coupled to memory 132. Memory 132 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and server 130 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once-read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 132 may be configured to store one or more software applications (such as application 133) and other data (such as a user's financial account information and contactless card information).

[0037] Application 133 may include one or more software applications, such as a card authentication module, including instructions for execution on server 130. In some examples, server 130 may implement one or more applications, such as software applications, that enable, for example, network communication with one or more components of system 100, transmit and / or receive data, and perform the functions and process flows described herein. Once executed by processor 131, application 133 may provide the functions described herein, specifically, implement and execute the steps and functions in the process flows described herein. For example, the card authentication module of application 133 may be implemented to perform user authentication based on contactless card 160. These processes may be implemented in software, such as software modules, for execution by a computer or other machine. Application 133 may provide a GUI through which a user can view and interact with other components and devices within system 100. The GUI may be formatted as, for example, a web page in Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form for presentation on a display device according to the application used by the user to interact with system 100.

[0038] Server 130 may also include a display 134 and an input device 135. Display 134 may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input device 135 may include any device available and supported by server 130 for typing information into server 130, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to type information and interact with the software and other devices described herein.

[0039] Database 140 may be one or more databases configured to store data, including but not limited to user's private information, user's financial account, contactless card information, online merchant account information, user's transactions, and merchant records indicating corresponding merchants. Database 140 may include relational databases, non-relational databases, or other database implementations and any combination thereof, including multiple relational databases and non-relational databases. In some examples, database 140 may include a desktop database, a mobile database, or an in-memory database. Furthermore, database 140 may be hosted internally by server 130 or externally by server 130, such as by a server, by a cloud-based platform, or in any storage device that communicates data with server 130.

[0040] System 100 may include one or more networks 150. In some examples, network 150 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect user equipment 120, server 130, and database 140. For example, network 150 may include one or more of the following: fiber optic network, passive optical network, cable network, Internet network, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n, and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, and / or the like.

[0041] Additionally, network 150 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Furthermore, network 150 may support the Internet, wireless communication networks, cellular networks, or similar networks, or any combination thereof. Network 150 may also include a single network, or any number of exemplary types of networks mentioned above, operating as independent networks or collaborating with each other. Network 150 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 150 may be converted to or from other protocols to one or more protocols of network devices. While network 150 is depicted as a single network, it should be understood that, according to one or more examples, network 150 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network. Network 150 may also include or be configured to create one or more front channels (which may be publicly accessible and whose communication is observable) and one or more secure back channels (which would be not publicly accessible and whose communication is unobservable).

[0042] In some examples, communication between server 130 and user equipment 120 using network 150 may occur using one or more front channels and one or more secure back channels. A front channel may be a communication protocol employing a publicly accessible and / or insecure communication channel, such that communication sent to server 130 and / or user equipment 120 may originate from any other device, whether known or unknown to server 130 and / or user equipment 120, as long as that device possesses the address of server 130 and / or user equipment 120 (e.g., network address, Internet Protocol (IP) address). Exemplary front channels include, but are not limited to, the Internet, open networks, and other publicly accessible communication networks. In some examples, communication sent using a front channel may be subject to unauthorized observation by another device. In some examples, front channel communication may include Hypertext Transfer Protocol (HTTP) Secure Socket Layer (SSL) communication, HTTP Secure (HTTPS) communication, and browser-based communication with servers or other devices.

[0043] A secure backchannel can be a communication protocol employing a secure and / or publicly inaccessible communication channel. Secure backchannel communication sent to server 130 and / or user equipment 120 does not originate from any single device, but rather from only a selected number of parties. In some examples, the selected number of devices may include known, trusted, or otherwise previously authorized devices. Exemplary secure backchannels include, but are not limited to, closed networks, private networks, virtual private networks, offline private networks, and other dedicated communication networks. In some examples, communication sent using a secure backchannel may not be subject to unauthorized observation by another device. In some examples, secure backchannel communication may include Hypertext Transfer Protocol (HTTP) Secure Sockets Layer (SSL) communication, HTTP Secure (HTTPS) communication, and browser-based communication with servers or other devices.

[0044] The contactless card 160 can be any type of card, such as a security card, payment card, ID card, and the like. The contactless card 160 can be issued by financial institutions to users for identity verification of their bank accounts.

[0045] The contactless card 160 can be configured to transmit encrypted text to the user equipment 120 when it is tapped. The user equipment 120 can be configured to read the encrypted text from the contactless card 160 after it enters the communication field of the user equipment 120. The user equipment 120 can then transmit the encrypted text to the server 130. The server 130 can be configured to verify the encrypted text by searching the database 140.

[0046] The contactless card 160 can perform authentication and many other functions, including potentially requiring the user to carry a separate physical token (in addition to the contactless card 160). By employing a contactless interface, the contactless card 160 can provide a method for interaction and communication between the user's device (such as a mobile phone or user device 120) and the card itself. For example, the Europay, Mastercard, and Visa (EMV) protocols, which underpin many credit card transactions, include authentication processes sufficient for the Android® operating system, but present challenges for iOS®, which is more restrictive regarding near-field communication (NFC) use as it can only be used in read-only mode. An exemplary embodiment of the contactless card 160 described herein utilizes NFC technology. The contactless card 160 may include a substrate 162 and a contact pad 164. Details of the example contactless card will be provided later. Figure 3A and Figure 3B As described in the text.

[0047] Figure 2An example sequence diagram 200 illustrates the interaction between components of a system 100 according to an example embodiment. Figure 2 Can be quoted and Figure 1 The same or similar components shown include user equipment, servers, databases, and contactless cards.

[0048] When a user forgets the password for his / her online account (such as a bank's financial account), the user can use user device 120 to send a message to server 130 at step 210 indicating that the user has forgotten the password for his / her online account. Server 130 can manage the user's online account.

[0049] Upon receiving a message from user equipment 120, at step 215, server 130 may, for example, use the phone number associated with user equipment 120 to search database 140 to verify at least one contactless card associated with the user's online account.

[0050] To authenticate the user, at step 225, server 130 may send a first notification to user device 120, requesting the user to tap contactless card 160. The first notification may be a short message service (SMS) message with a link that will open a mobile application or mobile application process on user device 120, from which the contactless card 160 can be read in the mobile application.

[0051] Upon receiving the first notification and by clicking the link included in the first notification, the user can use user equipment 120 to send an NFC prompt and / or query to contactless card 160 at step 230. User equipment 120 may include an NFC interface configured to establish NFC communication with other NFC-enabled devices (e.g., contactless card 160 in this embodiment). In some of these embodiments, the NFC interface of user equipment 120 may be or include an NFC receiver configured to selectively activate a magnetic field for use when establishing near-field communication with an NFC transmitter. The NFC interface of user equipment 120 is configured to establish NFC communication when a passive NFC tag or other NFC-enabled device is brought into the magnetic field and within the NFC communication range of user equipment 120. The NFC interface of user equipment 120 is specifically configured to communicate with NFC-enabled card 160 when contactless card 160 is brought into the communication range of user equipment 120 (e.g., when contactless card 160 is tapped by the user to user equipment 120). As used herein, a tap of the contactless card 160 on the user equipment 120 may not indicate physical contact between the contactless card 160 and the user equipment 120. A tap of the contactless card 160 on the user equipment 120 may indicate that the contactless card 160 has entered the NFC communication field of the user equipment 120.

[0052] In response, after the contactless card 160 enters the NFC communication field of the user equipment 120, at step 235, the contactless card 160 transmits NFC response information (e.g., generated ciphertext) to the user equipment 120, which can be used by the server 130 to authenticate the user. The NFC response information may be, or include, security information encrypted by the contactless card 160 using a card-specific private key known only to the card account administrator (e.g., the server 130). The ciphertext may be stored in the memory of the contactless card 160. The ciphertext includes a unique identifier for the contactless card 160.

[0053] At step 240, user equipment 120 transmits NFC response information (generated ciphertext) to server 130. At step 245, server 130 receives the generated ciphertext from user equipment 120. Server 130 verifies the generated ciphertext through its card authentication module, decrypts the ciphertext, and extracts the unique identifier of contactless card 160. When server 130 receives the ciphertext, it can decrypt it after verification. Server 130 can then extract the unique identifier of the contactless card 160 uniquely associated with the user. At step 245, server 130 can verify the unique identifier of contactless card 160 by searching database 140 to compare the generated ciphertext with stored ciphertext in database 140. Then, at step 255, server 130 can authenticate the user based on the unique identifier of contactless card 160, for example, by determining that the generated ciphertext matches the stored ciphertext. In other words, server 130 can use contactless card 160 as an authentication factor to authenticate users based on the unique identifier of contactless card 160.

[0054] In some embodiments, server 130 may also require the user to enter a personal identification code / number (PIN) as a second authentication factor. Alternatively, server 130 may require the user to enter a one-time passcode (OTP) as a third authentication factor, which is randomly generated by server 130 and transmitted to user device 120 in a text message.

[0055] At step 265, server 130 may send a second notification to user equipment 120, indicating that the authentication result using contactless card 160 as the authentication factor has been determined, i.e., the user has been authenticated to perform password-related actions. Once the user is authenticated using contactless card 160 as the authentication factor, the user can perform password-related actions through user equipment 120. In this document, password-related actions may include, but are not limited to, resetting the password, changing the password, retrieving the password, and the like.

[0056] The second notification may include a clickable link from which the user can reset, change, or retrieve their online account password. The second notification may be delivered via the application programming interface (API) of server 130. The second notification may include at least one selected from a group of deeply linked Short Message Service (SMS) messages, mobile app notifications, push notifications, or emails. Password-related actions may also include at least one selected from a group of logging into the online account with a temporary password and resetting the online account password.

[0057] As described above, when a user initiates an event or transaction with the server using their user device for password management, the user can be instructed to use a mobile application installed on their user device to read a contactless card as an authentication factor.

[0058] Figure 3A The contactless card 300 is described, which can be used in Figure 1 In System 100, users are authenticated using this as an authentication factor. Figure 1 The contactless card 160 in the document may be the contactless card 300 described herein. The contactless card 300 is configured to communicate with the user equipment 120 of system 100. The contactless card 300 may include a payment card, such as a credit card, debit card, or gift card, issued by a service provider 305 (such as a bank associated with server 130) displayed on the front or back of the contactless card 300. In some examples, the contactless card 300 is not a payment card and may include, but is not limited to, ID cards, membership cards, and transportation cards. In some examples, the contactless card 300 may include a dual-interface contactless payment card.

[0059] The contactless card 300 may include a substrate 310, which may include a single layer or one or more laminates made of plastic, metal, and other materials. Exemplary substrates include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 300 may have physical properties conforming to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card 300 may otherwise conform to the ISO / IEC 14443 standard. However, it should be understood that the contactless card 300 according to this disclosure may have different properties, and this disclosure does not require the contactless card 300 to be implemented as a payment card.

[0060] The contactless card 300 may also include identification information 315 displayed on the front and / or back of the contactless card 300, and a contact pad 320. The contact pad 320 may be configured to establish contact with another communication device, such as a user equipment, smartphone, laptop computer, desktop computer, or tablet computer. The contactless card 300 may also include processing circuitry, an antenna, and other components. These components may be located behind the contact pad 320 or elsewhere on the substrate. The contactless card 300 may also include a magnetic stripe or magnetic tape, which may be located on the back of the contactless card 300.

[0061] Figure 3B An example contact pad 320 of a contactless card 300 is shown. The contact pad 320 of the contactless card 300 may include processing circuitry 325 for storing and processing information, including a processor 330 and a memory 335. It should be understood that the processing circuitry 325 may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0062] Memory 335 can be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 300 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once / read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once programmed, the memory cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times.

[0063] In some embodiments, memory 335 may also store public and private card encryption keys. In some embodiments, the private and public encryption keys may be permanently hardwired into memory 335. In various embodiments, memory 335 may store instructions for generating encrypted information and transmitting it to a receiving device (e.g., user equipment 120). Such encrypted information may be or include encrypted verification blocks or signatures, which may be used to authenticate and verify the presence of card 300 during transaction processing. In some embodiments, the encrypted information will be unique for a specific communication (e.g., a specific NFC transmission performed by card 300).

[0064] Memory 335 can be configured to store one or more applets 340, one or more counters 345, and a unique customer identifier 350. The one or more applets 340 may include one or more software applications, such as Java Card applets, configured to run on one or more contactless cards and perform the functions and process flows described herein. However, it should be understood that the one or more applets 340 are not limited to Java Card applets and may instead be any software application operable on a contactless card or other device with limited memory. The one or more counters 345 may include numeric counters sufficient to store integers. The unique customer identifier 350 may include a unique alphanumeric identifier assigned to a user of the contactless card 300, and this identifier may distinguish the user of the contactless card 300 from other contactless card users. In some examples, the customer identifier 350 may identify both the customer and the account assigned to that customer, and may also identify the contactless card 300 associated with the customer's account.

[0065] The processor 330 and memory 335 elements of the foregoing exemplary embodiments have been described with reference to the contact pad 320, but this disclosure is not limited thereto. It should be understood that these elements may be implemented outside the contact pad 320, or implemented completely separately from it, or implemented as additional elements other than the processor 330 and memory 335 elements located within the contact pad 320.

[0066] In some examples, the contactless card 300 may include one or more antennas 355. The one or more antennas 355 may be placed within the contactless card 300 and surrounding the processing circuitry 325 of the contact pad 320. For example, the one or more antennas 355 may be integrated with the processing circuitry 325, and the one or more antennas 355 may be used in conjunction with an external boost coil. As another example, the one or more antennas 355 may be external to the contact pad 320 and the processing circuitry 325.

[0067] In one embodiment, the coil of the contactless card 300 can act as the secondary of an air-core transformer. A terminal (such as user equipment 120) can communicate with the contactless card 300 by cutting off power or amplitude modulation. The contactless card 300 can infer data transmitted from the terminal using gaps in the power connection of the contactless card, which can be functionally maintained by one or more capacitors. The contactless card 300 can return communication by switching the load or load modulation on the coil of the contactless card. Load modulation can be detected in the coil of the terminal by interference.

[0068] As explained above, the contactless card 300 can be built on a software platform (such as a JavaCard) that operates on a smart card or other device with limited memory, and one or more applications or applets (applets 340) can be securely implemented. Applets can be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. Applets can be configured to respond to one or more requests from a reader (such as a mobile NFC reader (user device 120)), such as a near-field data exchange request, and generate an NDEF message that includes a password-secured OTP encoded as an NDEF text tag.

[0069] The contactless card 300 can be configured to communicate with the user equipment 120 via a communication interface configured to establish communication with the user equipment 120. The communication interface can be configured for contact-based communication, in which case the interface may have electrical circuitry and contact pads on the surface of the card 300 for establishing direct electrical communication between the card 300 and the user equipment 120. Alternatively or additionally, the communication interface can be configured for contactless communication with the user equipment 120. In this embodiment, the communication interface may be or include an NFC communication interface configured to communicate with other NFC communication devices when the card 300 is within a predetermined NFC range. In some embodiments, the card 300 may include a second communication interface configured to establish short-range communication with the user equipment 120 via Bluetooth or other short-range communication methods. In this embodiment, the card 300 may have a short-range communication antenna included in or connected to the short-range communication interface. The card 300 may also include a power management system for managing power distribution during NFC transactions.

[0070] The contactless card 300 can be configured to transmit encrypted text to the user equipment 120 when it is tapped. The user equipment 120 can be configured to read the encrypted text from the contactless card 300 after the contactless card 300 enters the communication field of the user equipment 120. The user equipment 120 can then transmit the encrypted text to the server 130. The server 130 can be configured to verify the encrypted text by searching the database 140.

[0071] In some embodiments, the ciphertext can be generated by the contactless card 300 as follows. When an authentication request is received, a counter 345 can increment. When executed by the processor 330, the applet 340 can use a key combined with the count to generate two session keys (e.g., one for encryption (ENC) and one for a message authentication code (MAC)). The applet 340 can generate the MAC using the MAC session key via the count, a unique customer identifier (pUID) 350, a shared secret, and / or the applet version number of the applet 340. The applet 340 can encrypt the MAC using the ENC session key to generate ciphertext. The applet 340 can transmit the applet version number, pUID, count, and encrypted MAC (ciphertext) to the user equipment 120. It should be understood that comparable operations can be performed upon receipt of the ciphertext.

[0072] Figure 4 A flowchart is shown for an example method 400 for managing passwords using contactless cards as authentication factors, according to an example embodiment. Figure 4 Can be quoted and Figure 1 The components shown in Figure 3, whether identical or similar, include user equipment, servers, databases, and contactless cards. Method 400 can be implemented in system 100 and may include, but is not limited to, the following steps.

[0073] When a user forgets the password for his / her online account (e.g., a bank's financial account), the user can use a user device (e.g., user device 120) to send a message to a server (e.g., server 130) indicating that the user has forgotten the password for his / her online account. The server may be associated with a bank and configured to manage users' online accounts. Therefore, at step 405, the server can receive from the user device the message indicating that the user has forgotten the password for his / her online account.

[0074] Upon receiving the message from the user device, at step 410, the server may, for example, search a database (e.g., database 140) using the phone number associated with the user device to verify that at least one contactless card (e.g., contactless card 160 / 300) is associated with the user's online account.

[0075] To authenticate the user, at step 415, the server may send a first notification to the user device, requesting the user to tap at least one contactless card. The first notification may be a Short Message Service (SMS) message with a link that will open a mobile application or mobile application process on the user device, from which the contactless card can be read in the mobile application.

[0076] Upon receiving a first notification and by clicking a link included in the first notification, a user can use their user equipment to send an NFC prompt / query to a contactless card. The user equipment may include an NFC interface configured to establish NFC communication with other NFC-enabled devices (e.g., contactless cards 160 / 300 in this embodiment). In some of these embodiments, the user equipment's NFC interface may be or include an NFC receiver configured to selectively activate a magnetic field used when establishing near-field communication with an NFC transmitter. The user equipment's NFC interface is configured to establish NFC communication when a passive NFC tag or other NFC-enabled device is brought into the magnetic field and within the user equipment's NFC communication range. The user equipment's NFC interface is specifically configured to communicate with an NFC-enabled card when a contactless card is brought into the user equipment's communication range (e.g., when contactless card 160 / 300 is tapped by the user to user equipment 120). As used herein, a tap of the contactless card to the user equipment may not indicate physical contact between the contactless card and the user equipment. A tap of the contactless card to the user equipment may indicate that the contactless card has entered the user equipment's NFC communication field.

[0077] In response, after the contactless card enters the NFC communication field of the user device, the contactless card transmits NFC response information (e.g., generated ciphertext) to the user device, which can be used by the server to authenticate the user. The NFC response information may be, or include, secure information encrypted by the contactless card using a card-specific private key known only to the card account administrator (e.g., server 130). The ciphertext may be stored in the contactless card's memory. The ciphertext includes the contactless card's unique identifier.

[0078] The user equipment transmits the NFC response information (the generated ciphertext) to the server. At step 420, the server receives the generated ciphertext from the contactless card from the user equipment. At step 425, the server can compare the generated ciphertext with stored ciphertext stored in a database (e.g., database 140). The stored ciphertext can be generated by the server as follows: the server generates two UDK keys for the card (one for encryption and one for authentication) using the pUID and two bin-level master keys (one for encryption and one for authentication); the server generates two session keys (one for encryption and one for authentication) from the two UDK keys and a counter; and the server uses the authentication session key to generate the stored ciphertext.

[0079] At step 430, the server determines that the generated ciphertext matches the stored ciphertext. For example, the server decrypts the MAC message from the generated ciphertext using the encryption session key and verifies the MAC using the authentication (MAC) session key with the same information (e.g., pUID, count, shared secret). Alternatively, the server can verify the generated ciphertext by decrypting it and extracting the unique identifier of the contactless card (via the server's card authentication module). When the server receives the generated ciphertext, it can decrypt it after verification. The server can then extract the unique identifier of the contactless card uniquely associated with the user. The server can verify the unique identifier of the contactless card by searching a database to compare the generated ciphertext with stored ciphertexts in the database. The server can then authenticate the user based on the unique identifier of the contactless card, for example, by determining that the generated ciphertext matches the stored ciphertext. That is, the server can authenticate the user using the contactless card as an authentication factor based on the unique identifier of the contactless card.

[0080] In some embodiments, the server may also require the user to enter a personal identification number (PIN) as a second authentication factor. Alternatively, the server may require the user to enter a one-time password (OTP) as a third authentication factor, which is randomly generated by the server and transmitted to the user device in a text message.

[0081] At step 435, the server may send a second notification to the user device, indicating that the authentication result using the contactless card as the authentication factor has been determined, i.e., the user has been authenticated to perform actions related to the forgotten password. Once the user has been authenticated by the server using the contactless card as the authentication factor, the user can perform password-related actions through the user device. Password-related actions may include, but are not limited to, resetting the password, changing the password, retrieving the password, receiving a temporary password from the server, logging into an online account using a temporary password, and similar actions.

[0082] The second notification may include a clickable link from which the user can reset, change, or retrieve their online account password. The second notification may be delivered via the server's application programming interface (API). The second notification may include at least one selected from a group of deeply linked Short Message Service (SMS) messages, mobile app notifications, push notifications, or emails. Password-related actions may also include at least one selected from a group of logging into the online account with a temporary password and resetting the online account password.

[0083] Figure 5 A system 500 for authenticating users using contactless cards as an authentication factor for password management, according to an example embodiment, is shown. As discussed further below, system 500 may include user equipment 510, call center equipment 520, server 530, database 540 communicating via network 550, and contactless card 560 communicating signalically with user equipment 510. Although Figure 5 A single instance of the component is shown, but system 500 can include any number of components.

[0084] User equipment 510 can be used by a user to initiate and / or execute transactions with call center equipment 520, such as calling the customer service center associated with call center equipment 520. User equipment 510 can be configured to present a user interface from which the user can log in to, for example, their bank or credit card account to access their transaction reports and / or financial information stored in database 540 on server 530. The user interface can also be configured to perform data communication with contactless card 560. User equipment 510 can be configured to display the merchant's website on the user interface in response to the user's selection to access the merchant's website.

[0085] User equipment 510 may be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, networked appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, a network-enabled computer device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system from Apple®, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0086] User equipment 510 may include a processor 511, memory 512, application 513, display 514, and input device 515. Processor 511 may be a processor, microprocessor, or other processor, and user equipment 510 may include one or more of these processors. Processor 511 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0087] Processor 511 may be coupled to memory 512. Memory 512 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and user equipment 510 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once-read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 512 may be configured to store one or more software applications (such as application 513) and other data (such as private and personal information).

[0088] Application 513 may include one or more software applications that include instructions for execution on user equipment 510. In some examples, user equipment 510 may execute one or more applications, such as software applications, that enable, for example, network communication with one or more components of system 500, transmit and / or receive data, and perform the functions and process flows described herein, such as presenting an online website to a user of user equipment 510 and reading contactless card 560. After execution by processor 511, application 513 may provide the functions described herein, specifically, perform and execute the steps and functions in the process flows described below. These processes may be implemented in software, such as software modules, for execution by a computer or other machine. Application 513 may provide a graphical user interface (GUI) through which a user can view and interact with other components and devices within system 500. The GUI may be formatted as, for example, a webpage in Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form for presentation on a display device according to the application used by the user to interact with system 500.

[0089] User equipment 510 may also include a display 514 and an input device 515. The display 514 can be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 515 may include any device available and supported by user equipment 510 for typing information into user equipment 510, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to type information and interact with the software and other devices described herein, such as selecting the option to create an online account with a merchant.

[0090] Call center equipment 520 can be associated with a merchant or bank with which a user conducts transactions (such as password management or online purchases from a merchant) via user equipment 510. Call center equipment 520 can also be associated with a call / service center to which a user can make calls to initiate transactions (such as discussing product / service issues). Call center equipment 520 can also be associated with a bank branch where a user can conduct transactions and interact with bank employees. If call center equipment 520 is associated with a merchant, it can be configured to store online merchant accounts and present shopping interfaces and / or login interfaces on which users can conduct transactions with the merchant or log in to their online accounts.

[0091] Call center equipment 520 may be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, networked appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, a network-enabled computer device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system from Apple®, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0092] Call center device 520 may include a processor 521, memory 522, and application 523. Processor 521 may be a processor, microprocessor, or other processor, and call center device 520 may include one or more of these processors. Processor 521 may include processing circuitry that may contain additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0093] Processor 521 may be coupled to memory 522. Memory 522 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and call center device 520 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once-read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 522 may be configured to store one or more software applications (such as application 523) and other data (such as a user's shopping and financial account information).

[0094] Application 523 may include one or more software applications, including instructions for execution on call center equipment 520. In some examples, call center equipment 520 may implement one or more applications, such as software applications, that enable, for example, network communication with one or more components of system 500, transmit and / or receive data, and perform the functions and process flows described herein. After being executed by processor 521, application 523 may provide the functions described herein, specifically, implement and execute the steps and functions in the process flows described below. For example, application 523 may be implemented to perform user authentication or send an authentication request to server 530 to authenticate a user. Application 523 may also be implemented to process transactions for users who can shop online from merchants or access online banking accounts at banks. These processes may be implemented in software, such as software modules, for execution by a computer or other machine. Application 523 may provide a GUI through which users can view and interact with other components and devices within system 500. The GUI can be formatted as, for example, a webpage in Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form, for presentation on a display device according to the application used by the user to interact with the system 500.

[0095] Call center equipment 520 may also include a display 524 and an input device 525. The display 524 can be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 525 may include any device available and supported by call center equipment 520 for typing information into the call center equipment 520, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to type information and interact with the software and other devices described herein.

[0096] Server 530 can be associated with an organization (such as a financial institution) and can be configured to communicate with call center equipment 520 and user equipment 510. The organization associated with server 530 can issue contactless cards 560 to users and can therefore authenticate users based on contactless cards 560.

[0097] Server 530 may be a network-enabled computer device. Exemplary network-enabled computer devices include, but are not limited to, servers, networked appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, a network-enabled computer device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system from Apple®, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0098] Server 530 may include processor 531, memory 532, and application 533. Processor 531 may be a processor, microprocessor, or other processor, and server 530 may include one or more of these processors. Processor 531 may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.

[0099] Processor 531 may be coupled to memory 532. Memory 532 may be read-only memory, write-once-read-many memory, or read / write memory, such as RAM, ROM, and EEPROM, and server 530 may include one or more of these memories. Read-only memory can be factory-programmable to read-only or one-time programmable. One-time programmability provides the opportunity to write once and then read many times. Write-once-read-many memory can be programmed at a point in time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. Memory 532 may be configured to store one or more software applications (such as application 533) and other data (such as a user's financial account information and contactless card information).

[0100] Application 533 may include one or more software applications, such as a card authentication module, including instructions for execution on server 530. In some examples, server 530 may implement one or more applications, such as software applications, that enable, for example, network communication with one or more components of system 500, transmit and / or receive data, and perform the functions and process flows described herein. After being executed by processor 531, application 533 may provide the functions described herein, specifically, implement and execute the steps and functions in the process flows described below. For example, the card authentication module of application 533 may be implemented to perform user authentication based on contactless card 560. These processes may be implemented in software, such as software modules, for execution by a computer or other machine. Application 533 may provide a GUI through which a user can view and interact with other components and devices within system 500. The GUI may be formatted as, for example, a webpage in Hypertext Markup Language (HTML), Extensible Markup Language (XML), or any other suitable form for presentation on a display device according to the application used by the user to interact with system 500.

[0101] Server 530 may also include a display 534 and an input device 535. Display 534 may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input device 535 may include any device available and supported by server 530 for typing information into server 530, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or portable video camera. These devices can be used to type information and interact with the software and other devices described herein.

[0102] Database 540 may be one or more databases configured to store data, including but not limited to user's private information, user's financial account, contactless card information, online merchant account information, user's transactions, and merchant records indicating corresponding merchants. Database 540 may include relational databases, non-relational databases, or other database implementations and any combination thereof, including multiple relational databases and non-relational databases. In some examples, database 540 may include a desktop database, a mobile database, or an in-memory database. Furthermore, database 540 may be hosted internally by server 530 or externally by server 530, such as by a server, by a cloud-based platform, or in any storage device that communicates data with server 530.

[0103] System 500 may include one or more networks 550. In some examples, network 550 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect call center equipment 520, user equipment 510, server 530, and database 540. For example, network 550 may include one or more of the following: fiber optic network, passive optical network, cable network, Internet network, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.55b, 802.55.5, 802.55n, and 802.55g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, and / or the like.

[0104] Additionally, network 550 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Furthermore, network 550 may support the Internet, wireless communication networks, cellular networks, or similar networks, or any combination thereof. Network 550 may also include a network, or any number of exemplary types of networks mentioned above, operating as independent networks or collaborating with each other. Network 550 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 550 may be converted to or from other protocols to one or more protocols of network devices. Although network 550 is depicted as a single network, it should be understood that, depending on one or more examples, network 550 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network. Network 550 may also include or be configured to create one or more front channels (which would be publicly accessible and whose communications would be observable) and one or more secure back channels (which would not be publicly accessible and whose communications would be unobservable).

[0105] In some examples, communication between call center device 520, server 530, and user device 510 using network 550 may occur using one or more front channels and one or more secure back channels. A front channel may be a communication protocol employing a publicly accessible and / or insecure communication channel, such that communication sent to call center device 520, server 530, and / or user device 510 may originate from any other device, whether known or unknown to call center device 520, server 530, and / or user device 510, as long as that device possesses the address (e.g., network address, Internet Protocol (IP) address) of call center device 520, server 530, and / or user device 510. Exemplary front channels include, but are not limited to, the Internet, open networks, and other publicly accessible communication networks. In some examples, communication sent using a front channel may be subject to unauthorized observation by another device. In some examples, front channel communication may include Hypertext Transfer Protocol (HTTP) Secure Sockets Layer (SSL) communication, HTTP Secure (HTTPS) communication, and browser-based communication with servers or other devices.

[0106] A secure backchannel can be a communication protocol employing a secure and / or publicly inaccessible communication channel. Secure backchannel communications sent to call center device 520, server 530, and / or user device 510 do not originate from any single device, but rather from only a selected number of parties. In some examples, the selected number of devices may include known, trusted, or otherwise previously authorized devices. Exemplary secure backchannels include, but are not limited to, closed networks, private networks, virtual private networks, offline private networks, and other dedicated communication networks. In some examples, communications sent using a secure backchannel are not subject to unauthorized observation by another device. In some examples, secure backchannel communications may include Hypertext Transfer Protocol (HTTP) Secure Sockets Layer (SSL) communications, HTTP Secure (HTTPS) communications, and browser-based communications with servers or other devices.

[0107] The contactless card 560 can be any type of card, such as a security card, payment card, ID card, and the like. The contactless card 560 can be issued by financial institutions to users for identity verification of their bank accounts.

[0108] The contactless card 560 can be configured to transmit ciphertext to the user equipment 510 when it is tapped. The user equipment 510 can be configured to read the ciphertext from the contactless card 560 after it enters the communication field of the user equipment 510. The user equipment 510 can then transmit the ciphertext to the server 530. The server 530 can be configured to verify the ciphertext by searching the database 540.

[0109] The contactless card 560 can perform authentication and many other functions, including potentially requiring the user to carry a separate physical token (in addition to the contactless card 560). By employing a contactless interface, the contactless card 560 can provide a method for interaction and communication between the user's device (such as a mobile phone or user device 510) and the card itself. For example, the Europay, Mastercard, and Visa (EMV) protocols, which underpin many credit card transactions, include authentication processes sufficient for the Android® operating system, but present challenges for iOS®, which is more restrictive regarding Near Field Communication (NFC) use as it can only be used in read-only mode. An exemplary embodiment of the contactless card 560 described herein utilizes NFC technology. The contactless card 560 may include a substrate 562 and a contact pad 564. Details of the example contactless card are provided in... Figure 3A and Figure 3B The description is in the middle.

[0110] Figure 6An example sequence diagram 600 illustrates the interaction between components of a system 500 according to an example embodiment. Figure 6 Can be quoted and Figure 5 The same or similar components shown include user equipment, call center equipment, servers, databases, and contactless cards.

[0111] When a user forgets the password for his / her online account (such as a bank's financial account), at step 605, the user can contact call center device 520 using user device 510, informing the user that he / she has forgotten the password for his / her online account. For example, the user can call call center device 520.

[0112] At step 610, upon receiving a telephone call from user equipment 510, call center equipment 520 may send a first authentication / notification request to user equipment 510, requesting the user to tap contactless card 560 onto user equipment 510. Contactless card 560 may be used as an authentication factor to authenticate the user.

[0113] The first notification request may be a Short Message Service (SMS) message with a link that will open a mobile application or mobile application process on user device 510, from which the contactless card 560 can be read in the mobile application.

[0114] Upon receiving a first notification request and by clicking a link included in the request, the user can use user equipment 510 to send an NFC prompt / query to contactless card 560 at step 615. User equipment 510 may include an NFC interface configured to establish NFC communication with other NFC-enabled devices (contactless card 560 in this embodiment). In some of these embodiments, the NFC interface of user equipment 510 may be or include an NFC receiver configured to selectively activate a magnetic field for use when establishing near-field communication with an NFC transmitter. The NFC interface of user equipment 510 is configured to establish NFC communication when a passive NFC tag or other NFC-enabled device is brought into the magnetic field and within the NFC communication range of user equipment 510. The NFC interface of user equipment 510 is specifically configured to communicate with contactless card 560 when card 560 is brought into the communication range of user equipment 510 (e.g., when contactless card 560 is tapped by the user to user equipment 510). As used herein, a tap of the contactless card 560 onto the user equipment 510 does not necessarily indicate physical contact between the contactless card 560 and the user equipment 510. A tap of the contactless card 560 onto the user equipment 510 may indicate that the contactless card 560 has entered the NFC communication field of the user equipment 510.

[0115] In response, after the contactless card 560 enters the NFC communication field of the user equipment 510, the contactless card 560 transmits NFC response information (e.g., ciphertext) to the user equipment 510 at step 620, which can be used by the server 530 to authenticate the user. The NFC response information may be or include, for example, security information encrypted by the contactless card 560 using a card-specific private key known only to the card account administrator (e.g., the server 530). The ciphertext may be stored in the memory of the contactless card 560. The ciphertext includes a unique identifier for the contactless card 560. The ciphertext is generated by the contactless card and is referred to herein as generated ciphertext.

[0116] At step 625, user equipment 510 transmits the generated ciphertext to call center equipment 520. At step 630, call center equipment 520 transmits the NFC response information (the generated ciphertext) to server 530. At step 635, server 530 receives the generated ciphertext from the contactless card from call center equipment 520 and can compare the generated ciphertext with stored ciphertext stored in a database (e.g., database 540). The stored ciphertext can be generated by the server as follows: the server generates two UDK keys for the card (one for encryption and one for authentication) using the pUID and two bin-level master keys (one for encryption and one for authentication); the server generates two session keys (one for encryption and one for authentication) from the two UDK keys and a counter; and the server uses the authentication session key to generate the stored ciphertext.

[0117] At step 640, server 530 determines that the generated ciphertext matches the stored ciphertext. For example, server 530 decrypts the MAC message from the generated ciphertext using the encryption session key and verifies the MAC using the authentication (MAC) session key with the same information (e.g., pUID, count, shared secret). Alternatively, server 530 can verify the generated ciphertext by decrypting it and extracting the unique identifier of the contactless card (via server 530's card authentication module). When server 530 receives the generated ciphertext, it can decrypt it after verification. Server 530 can then extract the unique identifier of the contactless card 560 uniquely associated with the user. Server 530 can verify the unique identifier of the contactless card 560 by searching database 540 to compare the generated ciphertext with the stored ciphertext in database 540. Server 530 can then authenticate the user based on the unique identifier of the contactless card 560, for example, by determining that the generated ciphertext matches the stored ciphertext. In other words, server 530 can use contactless card 560 as an authentication factor to authenticate users based on the unique identifier of contactless card 560.

[0118] In some embodiments, server 530 may also require the user to enter a personal identification number (PIN) as a second authentication factor. Alternatively, server 530 may require the user to enter a one-time password (OTP) as a third authentication factor, which is randomly generated by server 530 and transmitted to user device 510 in a text message.

[0119] At step 645, server 530 may send a message to call center device 520 notifying the user that they have been authenticated. At step 650, call center device 520 may send a second notification to user device 510, indicating that the authentication result using contactless card 560 as the authentication factor has been determined, i.e., the user has been authenticated to perform actions related to a forgotten password. Once the user has been authenticated by server 530 using contactless card 560 as the authentication factor, the user can perform password-related actions through the user device. Password-related actions may include, but are not limited to, resetting a password, changing a password, retrieving a password, receiving a temporary password from the server, logging into an online account using a temporary password, and similar actions.

[0120] The second notification may include a clickable link from which the user can reset, change, or retrieve their online account password. The second notification may be delivered via the application programming interface (API) of the call center device 520. The second notification may include at least one selected from a group of deeply linked Short Message Service (SMS) messages, mobile app notifications, push notifications, or emails. Password-related actions may also include at least one selected from a group of logging into the online account with a temporary password and resetting the online account password.

[0121] As described above, when a user initiates an event or transaction with another device (e.g., call center device 520) using their user device, the user can be instructed to use a mobile application installed on their user device to read a contactless card as an authentication factor (e.g., for multi-factor authentication) to authenticate the user. For example, a user might call a call center associated with the call center device because they have questions about their account, such as a forgotten password, to verify the user. An SMS with a link to open the mobile application or the mobile application process can be sent to the user through the user device, and the user will be able to read the contactless card within the mobile application. The contactless card data will then be returned to the call center device, allowing the call center to verify the user using the contactless card through a server.

[0122] Figure 7 A flowchart of an example method 700 for managing passwords using contactless cards as authentication factors, according to an example embodiment, is shown. Figure 7 Can be quoted and Figure 5The same or similar components shown include user equipment, call center equipment, servers, databases, and contactless cards. Method 700 can be implemented in system 500 and may include, but is not limited to, the following steps.

[0123] When a user forgets the password for their online account (such as a financial account or merchant shopping account), the user can use their user device to call the customer service center associated with the call center device. In those example embodiments, the user using the user device initiates the interaction with the call center device (makes a phone call). Upon receiving a phone call from the user device, the call center device can send a message to the server indicating that the user has forgotten their online account password. Therefore, at step 705, the server receives the message from the call center device indicating that the online account password has been forgotten.

[0124] Upon receiving a message from the call center device, at step 710, the server may, for example, search a database (e.g., database 540) using the phone number associated with the user device to verify that at least one contactless card (e.g., contactless card 560) is associated with the user's online account.

[0125] To authenticate the user, at step 715, the server may send a message to the call center device requesting the user to tap at least one contactless card onto the user device. At least one contactless card can be used as an authentication factor for authenticating the user. The call center device may then send a first notification request to the user device, requesting the user to tap at least one contactless card onto the user device. The first notification may be a Short Message Service (SMS) message with a link that will open a mobile application or mobile application process on the user device, from which the contactless card can be read within the mobile application.

[0126] Upon receiving a first notification request and by clicking the link included in the request, the user can use the user equipment to send an NFC prompt / query to the contactless card. The user equipment may include an NFC interface configured to establish NFC communication with other NFC-enabled devices (contactless card 560 in this embodiment). In some of these embodiments, the user equipment's NFC interface may be or include an NFC receiver configured to selectively activate a magnetic field used when establishing near-field communication with an NFC transmitter. The user equipment's NFC interface is configured to establish NFC communication when a passive NFC tag or other NFC-enabled device is brought into the magnetic field and within the user equipment's NFC communication range. The user equipment's NFC interface is specifically configured to communicate with an NFC-enabled card when the card is brought into the user equipment's communication range (e.g., when contactless card 560 is tapped by the user to user equipment 510). As used herein, a tap of the contactless card to the user equipment may not indicate physical contact between the contactless card and the user equipment. A tap of the contactless card to the user equipment may indicate that the contactless card has entered the user equipment's NFC communication field.

[0127] In response, after the contactless card enters the NFC communication field of the user device, the contactless card transmits NFC response information (e.g., ciphertext) to the user device, which can be used by the server to authenticate the user. The NFC response information may be or include, for example, security information encrypted by the contactless card using a card-specific private key known only to the card account administrator (e.g., server 530). The ciphertext may be stored in the contactless card's memory. The ciphertext includes the contactless card's unique identifier. The ciphertext is generated by the contactless card and is referred to herein as the generated ciphertext.

[0128] The user equipment transmits the generated ciphertext to the call center device. The call center device transmits the NFC response information (the generated ciphertext) to the server. Therefore, at step 720, the server receives the generated ciphertext of the contactless card from the call center device, and at step 725, the generated ciphertext can be compared with the stored ciphertext stored in a database (e.g., database 540). The stored ciphertext can be generated by the server as follows: the server generates two UDK keys for the card (one for encryption and one for authentication) using the pUID and two bin-level master keys (one for encryption and one for authentication), the server generates two session keys (one for encryption and one for authentication) from the two UDK keys and a counter, and the server uses the authentication session key to generate the stored ciphertext.

[0129] At step 730, the server determines that the generated ciphertext matches the stored ciphertext. For example, the server decrypts the MAC message from the generated ciphertext using the encryption session key and verifies the MAC using the authentication (MAC) session key with the same information (e.g., pUID, count, shared secret). Alternatively, the server can verify the generated ciphertext by decrypting it and extracting the unique identifier of the contactless card (via the server's card authentication module). When the server receives the generated ciphertext, it can decrypt it. The server can then extract the unique identifier of the contactless card uniquely associated with the user. The server can verify the unique identifier of the contactless card by searching a database to compare the generated ciphertext with stored ciphertexts in the database. The server can then authenticate the user based on the unique identifier of the contactless card, for example, by determining that the generated ciphertext matches the stored ciphertext. That is, server 530 can authenticate the user using the contactless card as an authentication factor based on the unique identifier of the contactless card.

[0130] In some embodiments, the server may also require the user to enter a personal identification number (PIN) as a second authentication factor. Alternatively, the server 530 may require the user to enter a one-time password (OTP) as a third authentication factor, which is randomly generated by the server and transmitted to the user device in a text message.

[0131] At step 735, the server may send a second notification to the call center device, informing the user that they have been authenticated to perform an action related to the forgotten password. The call center device may send a message to the user device indicating that the authentication result using a contactless card as the authentication factor has been determined, i.e., the user has been authenticated by the server using a contactless card as the authentication factor, and can then perform password-related actions through the user device. Password-related actions may include, but are not limited to, resetting a password, changing a password, retrieving a password, receiving a temporary password from the server, logging into an online account using a temporary password, and similar actions.

[0132] The message to the user's device may include a clickable link from which the user can reset, change, or retrieve their online account password. This message can be delivered via the call center device's application programming interface (API). The message may include at least one selected from a group of deeply linked Short Message Service (SMS) messages, mobile app notifications, push notifications, or emails. Password-related actions may also include at least one selected from a group of logging into the online account with a temporary password and resetting the online account password.

[0133] In some embodiments, the user equipment can receive push notifications using a contactless card as an authentication factor from a call center device or server. The user can tap the push notification and hold their finger for a relatively long duration, enabling the user to tap the contactless card more quickly and instantly. This eliminates an additional step the user must take and reduces friction and time, allowing the user to act more quickly.

[0134] In some embodiments, a user may be prompted to log in to a mobile application installed on the user's device for reading contactless cards, such as Face ID. In other embodiments, a user may not be prompted to log in to a mobile application installed on the user's device for reading contactless cards.

[0135] In some embodiments, the phone call can occur between a user device and an interactive voice response (IVR) device and / or system. For example, a user can use their user device to call an IVR system, following prompts to select and enter the initial information needed to identify who they are. The user can then trigger a push notification to their user device based on a task or action they wish to perform on the IVR system (e.g., changing and / or resetting a forgotten password), and this push notification will activate a contactless card tap for authentication factors. The systems and methods disclosed herein can use authentication factors to allow users to perform riskier transactions (e.g., resetting a forgotten password). This opens a pathway, instead of requiring a trip to a physical agent, for the user to perform the task or action within the IVR experience.

[0136] As described, this disclosure provides a method for password management using contactless cards. The method may include: receiving a message from a user's user device indicating that the user's online account has forgotten its password; verifying at least one contactless card associated with the online account; transmitting a first notification from the server to the user device requesting the user to tap at least one contactless card onto the user device; receiving generated ciphertext from the user device, wherein the generated ciphertext is generated by at least one contactless card; comparing the generated ciphertext with stored ciphertext associated with at least one contactless card; and, in response to the determination that the generated ciphertext matches the stored ciphertext, transmitting a second notification from the server to the user device instructing the user to be authenticated to perform an action related to the forgotten password. The user device may be a Near Field Communication (NFC) enabled device. The stored ciphertext may be stored in a database communicating with the server. The generated ciphertext may be generated by at least one contactless card based on the unique identifier of at least one contactless card. The method may further include: decrypting the generated ciphertext by the server; extracting a unique customer identifier associated with at least one contactless card from the decrypted generated ciphertext by the server; verifying the unique customer identifier by the server; and authenticating the user by the server using the unique customer identifier. The at least one contactless card may include a processor and memory, the memory storing an app for generating the generated ciphertext, the generated ciphertext containing the unique customer identifier of at least one contactless card. The memory of the at least one contactless card may also contain a counter value and a key, and the processor of the at least one contactless card may be configured to execute the app to generate the generated ciphertext using the counter value, the key, and the unique customer identifier. The processor of the at least one contactless card may be configured to execute the app to update the counter value. The second notification may include at least one selected from a group of deeply linked Short Message Service (SMS) messages, mobile app notifications, push notifications, or emails. Actions related to a forgotten password include at least one selected from a group of logging into an online account with a temporary password and resetting the password for the online account.

[0137] This disclosure also provides a system for password management using contactless cards. The system may include a server. The server may be configured to: receive from a user's user device a message indicating that the user's online account has been forgotten; verify at least one contactless card associated with the online account; transmit a first notification to the user device requesting the user to tap at least one contactless card onto the user device; receive generated ciphertext from the user device, wherein the generated ciphertext is generated by at least one contactless card; compare the generated ciphertext with stored ciphertext associated with at least one contactless card; and, in response to a determination that the generated ciphertext matches the stored ciphertext, transmit a second notification to the user device instructing the user to be authenticated to perform an action related to the forgotten password. The user device may be at least one selected from the group consisting of mobile phones, laptop computers, tablet computers, and desktop computers. The at least one contactless card may be at least one selected from the group consisting of credit cards, debit cards, and gift cards. The server may also be configured to: receive a card verification code (CVC) from at least one contactless card and authenticate the user based on the CVC. The second notification may include a temporary password for the online account. The generated ciphertext can be generated by at least one contactless card based on a counter value contained in at least one contactless card. The second notification may include a clickable link from which the user can reset their online account password. The server can also be configured to verify the counter value of at least one contactless card. The second notification can be delivered via an application programming interface (API).

[0138] This disclosure provides a non-transitory computer-readable medium. The non-transitory computer-readable medium includes instructions for password management using contactless cards, which, when executed on a computer device, perform actions including: receiving from a user's user equipment a message indicating that the user's online account has been forgotten; verifying at least one contactless card associated with the online account; transmitting a first notification to the user equipment requesting the user to tap at least one contactless card onto the user equipment; receiving generated ciphertext from the user equipment, wherein the generated ciphertext is generated by at least one contactless card; comparing the generated ciphertext with stored ciphertext associated with at least one contactless card; and, in response to a determination that the generated ciphertext matches the stored ciphertext, transmitting a second notification to the user equipment instructing the user to be authenticated to perform actions related to the forgotten password.

[0139] As used herein, the term "contactless card" is not limited to a specific type of card. Further, this disclosure is not limited to cards for a specific purpose (e.g., payment cards, gift cards, ID cards, membership cards, transportation cards, access cards), cards associated with a specific type of account (e.g., credit accounts, debit accounts, membership accounts), or cards issued by a specific entity (e.g., commercial entities, financial institutions, government entities, social clubs). Rather, it should be understood that this disclosure includes cards for any purpose, account associated with, or issued by any entity.

[0140] As used herein, the term “account” or “online account” is not limited to a particular type of account. Rather, the term “account” or “online account” can refer to an account for any purpose, including but not limited to credit accounts, debit accounts, membership accounts, loyalty accounts, rewards accounts, savings accounts, checking accounts, brokerage accounts, retirement accounts, service accounts, subscription accounts, utility accounts, and government accounts.

[0141] In some examples, the exemplary processes described herein can be performed by a processing device and / or a computing device (e.g., a computer hardware device). Such a processing / computing device may be, for example, all or part of a computer / processor, or includes, but is not limited to, a computer / processor that may include, for example, one or more microprocessors and uses instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard disk drive, or other storage device). For example, the computer-accessible medium may be a contactless card, user equipment, call center equipment, a server, a database, and / or part of the memory of another computer hardware device.

[0142] In some examples, a computer-accessible medium (e.g., storage devices such as hard disks, floppy disks, memory sticks, CD-ROMs, RAM, ROMs, etc., or combinations thereof, as described above) may be provided (e.g., to communicate with a processing device). The computer-accessible medium may contain executable instructions thereon. Alternatively or separately, the storage device may be disposed separately from the computer-accessible medium, which may provide instructions to the processing device to configure the processing device to perform certain exemplary programs, processes, and methods, for example, as described above.

[0143] It should be noted further that the systems and methods described herein can be tangibly embodied in one or more physical media, such as, but not limited to, compact discs (CDs), digital versatile discs (DVDs), floppy disks, hard disks, read-only memory (ROM), random access memory (RAM), and other physical media capable of storing data. For example, data storage devices may include random access memory (RAM) and read-only memory (ROM), which can be configured to access and store data and information, as well as computer program instructions. Data storage devices may also include storage media or other suitable types of memory (e.g., such as RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), disks, optical disks, floppy disks, hard disks, removable magnetic tape cassettes, flash drives, and any type of tangible and non-transitory storage media), wherein files including operating systems, applications including, for example, web browser applications, email applications and / or other applications, and data files may be stored. Data storage devices for network-enabled computer systems may include electronic information, files, and documents stored in various ways, including, for example, flat files, indexed files, hierarchical databases, relational databases such as databases created and maintained with software from, for example, Oracle® Corporation, Microsoft® Excel files, Microsoft® Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage devices (which may include online or cloud storage devices), or any other storage mechanism. Furthermore, these diagrams illustrate various components (e.g., servers, computers, processors, etc.). Functions described as performing at various components can be performed at other components, and the various components can be combined or separated. Other modifications are also possible.

[0144] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to a corresponding computing and / or processing device, or downloaded via a network (e.g., the Internet, a local area network, a wide area network, and / or a wireless network) to an external computer or external storage device. This network may include copper transmission cables, optical fiber transmission, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing and / or processing device receives the computer-readable program instructions from the network and forwards them to a computer-readable storage medium within the corresponding computing and / or processing device.

[0145] Computer-readable program instructions used to perform the operations of this invention may be assembly instructions, instruction-set-architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages ​​such as Java, Smalltalk, or C++, and conventional procedural programming languages ​​such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made with an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, electronic circuits including, for example, programmable logic circuits, field-programmable gate arrays (FPGAs), or programmable logic arrays (PLAs) can be personalized by implementing computer-readable program instructions using state information of computer-readable program instructions to perform aspects of the present invention.

[0146] These computer-readable program instructions may be provided to a processor of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions, when executed by the processor of the computer or other programmable data processing apparatus, create means for performing the functions specified herein. These computer-readable program instructions may also be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other equipment to operate in a manner such that the computer-readable storage medium having the instructions stored therein includes an article of writing comprising instructions for performing aspects of the functions specified herein.

[0147] Computer-readable program instructions may also be loaded onto a computer, other programmable data processing apparatus or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus or other device to produce a computer-implemented process, such that the instructions, when executed on the computer, other programmable apparatus or other device, perform the function specified herein.

[0148] Implementations of the various techniques described herein can be carried out in digital electronic circuits, or in computer hardware, firmware, software, or combinations thereof. Implementations can be carried out as computer program products, i.e., computer programs tangibly embodied in an information carrier (e.g., in a machine-readable storage device or in a propagating signal) for execution or control of the operation of a data processing apparatus (e.g., a programmable processor, a computer, or multiple computers). Computer programs, such as one or more computer programs described above, can be written in any form of programming language (including compiled or interpreted languages) and can be deployed in any form (including as a standalone program or as a module, component, subroutine, or other unit suitable for use in a computing environment). Computer programs can be deployed to be executed on a single computer at a single site or on multiple computers distributed across multiple sites and interconnected by a communication network.

[0149] The method steps can be executed by one or more programmable processors that implement computer programs to perform functions by manipulating input data and generating output. The method steps can also be executed by special-purpose logic circuitry, and the apparatus can be implemented as special-purpose logic circuitry, such as an FPGA (Field-Programmable Gate Array) or an ASIC (Application-Specific Integrated Circuit).

[0150] Throughout this disclosure, the following terms take at least the meaning explicitly associated herein, unless the context clearly specifies otherwise. The term “or” is intended to mean an inclusive “or”. Furthermore, the terms “a,” “an,” and “the” are intended to mean one or more, unless otherwise stated or clearly indicated from the context to the singular form.

[0151] Numerous specific details have been set forth in this specification. However, it should be understood that implementations of the disclosed technology can be practiced without these specific details. In other instances, well-known methods, structures, and techniques have not been shown in detail so as not to obscure the understanding of this description. References to “some examples,” “other examples,” “an example,” “example,” “various examples,” “an embodiment,” “an embodiment,” “some embodiments,” “example embodiments,” “various embodiments,” “an implementation,” “implementation,” “example implementation,” “various implementations,” “some implementations,” etc., indicate that one or more implementations of the disclosed technology thus described may include specific features, structures, or characteristics, but not every implementation must include specific features, structures, or characteristics. Furthermore, the repeated use of the phrases “in an example,” “in an embodiment,” or “in an implementation” does not necessarily refer to the same example, embodiment, or implementation, although it may be the same.

[0152] As used herein, unless otherwise stated, the ordinal adjectives “first,” “second,” “third,” etc., used to describe common objects only indicate different instances of similar objects being referred to, and are not intended to imply that the objects described in this way must be in a given order, whether in time, space, ranking, or any other way.

[0153] While some embodiments of the disclosed technology have been described in conjunction with what are currently considered the most practical and various implementations, it should be understood that the disclosed technology is not limited to the disclosed embodiments, but rather is intended to cover various modifications and equivalent arrangements included within the scope of the appended claims. Although specific terms are used herein, they are used only in a general and descriptive sense and not for limiting purposes.

[0154] This written description uses examples to disclose certain embodiments of the disclosed technology, including best practices, and also enables any person skilled in the art to practice certain embodiments of the disclosed technology, including making and using any device or system and performing any incorporated methods. The patentable scope of certain embodiments of the disclosed technology is defined in the claims and may include other examples that would occur to a person skilled in the art. These other examples are intended to be within the scope of the claims if they have structural elements that are not indistinguishable from the literal language of the claims, or if they include equivalent structural elements that are not substantially different from the literal language of the claims.

Claims

1. A method for password management using a contactless card, comprising: The server receives a message from the user's user device indicating that the user has forgotten the password for their online account; The server verifies at least one contactless card associated with the online account; The server sends a first notification to the user equipment, requesting the user to tap the at least one contactless card onto the user equipment. The server receives generated ciphertext from the user equipment, wherein the generated ciphertext is generated by the at least one contactless card; The server compares the generated ciphertext with the stored ciphertext associated with the at least one contactless card. and In response to the determination that the generated ciphertext matches the stored ciphertext, the server sends a second notification to the user equipment, instructing the user to be authenticated to perform an action related to the forgotten password.

2. The method according to claim 1, wherein, The user equipment is a device that enables Near Field Communication (NFC).

3. The method according to claim 1, wherein, The stored ciphertext is stored in a database that communicates with the server.

4. The method according to claim 1, wherein, The generated ciphertext is generated by the at least one contactless card based on the unique identifier of the at least one contactless card.

5. The method according to claim 1, further comprising: The server then decrypts the generated ciphertext. The server extracts a unique customer identifier associated with the at least one contactless card from the decrypted ciphertext. The server verifies the unique customer identifier; and The server authenticates the user using the unique customer identifier.

6. The method according to claim 1, wherein, The at least one contactless card includes a processor and a memory, the memory storing an application program for generating the generated ciphertext, the generated ciphertext containing a unique customer identifier for the at least one contactless card.

7. The method according to claim 6, wherein: The memory of the at least one contactless card also contains a counter value and a key, and The processor of the at least one contactless card is configured to execute the applet to generate the generated ciphertext using the counter value, the key, and the unique customer identifier.

8. The method according to claim 7, wherein, The processor of the at least one contactless card is configured to execute the applet to update the counter value.

9. The method according to claim 1, wherein, The second notification includes at least one selected from a group consisting of short message service (SMS) messages with deep links, mobile app notifications, push notifications, or emails.

10. The method according to claim 1, wherein, Actions related to the forgotten password include at least one selected from the group of logging into the online account with a temporary password and resetting the password of the online account.

11. A system for password management using contactless cards, comprising a server configured to: Receive a message from the user's user device indicating that the user has forgotten the password for their online account; Verify at least one contactless card associated with the online account; A first notification is sent to the user equipment, requesting the user to tap the at least one contactless card onto the user equipment; Receive generated ciphertext from the user equipment, wherein the generated ciphertext is generated by the at least one contactless card; The generated ciphertext is compared with the stored ciphertext associated with the at least one contactless card; and In response to the determination that the generated ciphertext matches the stored ciphertext, a second notification is sent to the user equipment, instructing the user to be authenticated to perform an action related to the forgotten password.

12. The system according to claim 11, wherein, The user equipment is at least one selected from the group consisting of mobile phones, laptop computers, tablet computers and desktop computers.

13. The system according to claim 11, wherein, The at least one contactless card is selected from at least one of the group consisting of credit cards, debit cards, and gift cards.

14. The system according to claim 11, wherein, The server is also configured to: Receive the card verification code (CVC) from at least one contactless card, and The user is authenticated based on CVC.

15. The system according to claim 11, wherein, The second notification includes a temporary password for the online account.

16. The system according to claim 11, wherein, The generated ciphertext is generated by the at least one contactless card based on the counter value contained in the at least one contactless card.

17. The system according to claim 11, wherein, The second notification includes a clickable link from which the user can reset the password for the online account.

18. The system according to claim 11, wherein, The server is also configured to verify the counter value of the at least one contactless card.

19. The system according to claim 11, wherein, The second notification is transmitted via an application programming interface (API).

20. A non-transitory computer-readable medium comprising instructions for password management using a contactless card, the instructions, when executed on a computer device, performing actions including: Receive a message from the user's user device indicating that the user has forgotten the password for their online account; Verify at least one contactless card associated with the online account; A first notification is sent to the user equipment, requesting the user to tap the at least one contactless card onto the user equipment; Receive generated ciphertext from the user equipment, wherein the generated ciphertext is generated by the at least one contactless card; The generated ciphertext is compared with the stored ciphertext associated with the at least one contactless card; and In response to the determination that the generated ciphertext matches the stored ciphertext, a second notification is sent to the user equipment, instructing the user to be authenticated to perform an action related to the forgotten password.