Digital service persistent authentication based on non-contact card positioning

By employing contactless cards and key diversification technology with client devices, along with periodic status messages, continuous authentication is achieved, resolving the issue of frequent user authentication, improving user experience, and enhancing security.

CN122490495APending Publication Date: 2026-07-31CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
CAPITAL ONE SERVICES LLC
Filing Date
2020-07-10
Publication Date
2026-07-31

AI Technical Summary

Technical Problem

Existing digital service authentication methods require users to re-authenticate frequently, leading to a decline in user experience and posing security risks.

Method used

When a contactless card approaches a client device, continuous authentication is achieved using key diversification technology and periodic status messages. This ensures that the contactless card continues to provide authentication when it is active; otherwise, service access is terminated.

Benefits of technology

It reduces the number of user authentication attempts, improves the user experience, and enhances the security of card data, ensuring that access to digital services is only continuously authorized while the contactless card remains active.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN122490495A_ABST
    Figure CN122490495A_ABST
Patent Text Reader

Abstract

Various embodiments typically involve providing continuous authentication of users to digital services based on the activity of contactless cards located near computing devices running digital services. For example, a series of periodic status messages can be provided between the client device and the contactless card to verify whether the contactless card remains active, wherein authorization to access the digital services continues while the contactless card is active, and continued authorization to access the digital services is terminated when the contactless card is inactive.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application of the invention patent application with application number 202080065774.6, application date July 10, 2020, entitled "Continuous Authentication of Digital Services Based on Contactless Card Positioning".

[0002] Cross-references to related applications

[0003] This application claims priority to U.S. Patent Application Serial No. 16 / 516,243, filed July 18, 2019, entitled "CONTINUOUS AUTHENTICATION FORDIGITAL SERVICES BASED ON CONTACTLESS CARD POSITIONING". The entire contents of the aforementioned patent application are incorporated herein by reference. Technical Field

[0004] The embodiments described herein generally relate to computing platforms, and more specifically, to providing continuous authentication to digital services when a contactless card is located near a computing device. Background Technology

[0005] When accessing services such as digital wallets, websites, networks, and applications, user authentication is usually required. Common authentication methods include password authentication, iris authentication, facial recognition, voice authentication, fingerprint authentication, vein authentication, and pre-defined gesture authentication.

[0006] For security reasons, these authentication methods limit how long an authenticated user can remain logged into the service. However, requiring users to constantly re-authenticate to avoid logging out can lead to excessive user focus and effort, resulting in a degraded user experience. Summary of the Invention

[0007] The embodiments disclosed herein provide systems, methods, articles of art, and computer-readable media for providing continuous authentication to digital services based on contactless cards near a computing device. According to one example, a system may include processor circuitry; and a memory storing instructions that, when executed by the processor circuitry, cause the processor circuitry to: receive a request for access to a digital service via an application executing on the processor circuitry; receive, via the application, a first authentication based on verification of a first set of encrypted data associated with a user account; request a second authentication via the application from a contactless card; and, in response to activation of the contactless card, receive a second set of encrypted data from a communication interface of the contactless card via a card reader of a client device, the second set of encrypted data being generated based on a cryptographic algorithm and a diversified key stored in the memory of the contactless card, wherein the contactless card is activated by the client device when the contactless card is located near the client device, and wherein the second set of encrypted data is associated with the user account. The system also includes instructions that, when executed by the processor circuitry, cause the processor circuitry to receive, via the application, a second authentication of the user account based on the second set of encrypted data from the server; in response to the first and second authentications of the user account, authorize access to the digital service via the application; and continuously provide a series of periodic status messages via the application between the client device and the contactless card to verify whether the contactless card remains active, wherein authorization to access the digital service continues while the contactless card is active, and wherein authorization to access the digital service is terminated when the contactless card is inactive.

[0008] According to another example, a method includes receiving a request to access a digital service via an application executing on the processor circuitry; receiving, via the application, a first authentication based on verification of a first set of encrypted data associated with a user account; and requesting a second authentication from a contactless card via the application. The method may further include receiving, in response to activation of the contactless card, a second set of encrypted data from a communication interface of the contactless card via a card reader of a client device, the second set of encrypted data being generated based on a cryptographic algorithm and a plural key stored in the memory of the contactless card, wherein the contactless card is activated by the client device when the contactless card is positioned near the client device, and wherein the second set of encrypted data is associated with the user account. The method may further include receiving a second verification of the user account based on the second set of encrypted data from a server via the application; authorizing access to the digital service via the application in response to the first and second verifications of the user account; and continuously providing a series of periodic status messages via the application between the client device and the contactless card to verify whether the contactless card remains active, wherein authorization to access the digital service continues while the contactless card is active, and wherein authorization to access the digital service is terminated when the contactless card is inactive.

[0009] According to another example, a non-transitory computer-readable storage medium contains computer-readable program code executable by processor circuitry to cause the processor circuitry to receive a request for access to a digital service via an application executing on the processor circuitry; receive, via the application, a first authentication based on verification of a first set of encrypted data associated with a user account; and request a second authentication from a contactless card via the application. The computer-readable program code executable by the processor circuitry can also cause the processor circuitry to receive a second set of encrypted data from the communication interface of the contactless card via a card reader of a client device in response to activation of the contactless card. The second set of encrypted data is generated based on a cryptographic algorithm and a pluralistic key stored in the memory of the contactless card. The contactless card is activated by the client device when it is positioned near the client device, and the second set of encrypted data is associated with the user account. The computer-readable program code executable by the processor circuitry can also enable the processor circuitry to receive, via the application, a second authentication of the user account based on the second set of encrypted data from the server; in response to the first and second authentications of the user account, authorize access to the digital service via the application; and continuously provide a series of periodic status messages via the application between the client device and the contactless card to verify whether the contactless card remains active, wherein authorization to access the digital service continues while the contactless card is active, and wherein authorization to access the digital service is terminated when the contactless card is inactive. Attached Figure Description

[0010] Figure 1 An embodiment of a system for providing continuous authentication to digital services is shown.

[0011] Figure 2-3 An embodiment for providing continuous authentication to digital services based on contactless cards near a computing device is shown.

[0012] Figures 4A-4B An example of a contactless card is shown.

[0013] Figure 5A A side view of an embodiment of the overlay on a client device is shown.

[0014] Figure 5B It shows Figure 5A An end view of an embodiment of the overlay on a client device.

[0015] Figure 6 An example of a logical flow for providing continuous authentication to digital services is shown.

[0016] Figure 7 An example of a computing architecture is shown.

[0017] The accompanying drawings are not necessarily drawn to scale. The drawings are merely illustrative and not intended to depict specific parameters of this disclosure. The drawings are intended to describe exemplary embodiments of this disclosure and are therefore not to be considered as limiting the scope. For clarity, certain elements in some figures may be omitted or not shown to scale. Furthermore, some reference numerals may be omitted in some figures. Detailed Implementation

[0018] This embodiment will now be described more fully below with reference to the accompanying drawings, some of which are illustrated. The subject matter of this disclosure may be embodied in many different forms and should not be construed as limited to the embodiments set forth herein. These embodiments are provided so that this disclosure will be thorough and complete and will fully convey the scope of the subject matter to those skilled in the art. In the drawings, the same numerals always refer to the same elements.

[0019] The embodiments disclosed herein provide continuous authentication of contactless cards based on proximity to a client device such as a mobile device or personal computer. In some embodiments, continuous activation allows the contactless card to authenticate to digital services as long as it remains near the reader of the client device. For example, a series of periodic “heartbeats” or status messages can be provided between the client device and the contactless card to verify that the contactless card remains active, wherein authorization to access digital services continues while the contactless card is active, and authorization to access digital services is terminated when the contactless card is inactive.

[0020] In some embodiments, a cover on the device or client device may be used to receive and position the contactless card relative to the client device. Specifically, the cover may include a slot or socket near the card reader positioning on the mobile device. While the contactless card is held within the cover, it can be continuously activated by the electromagnetic field of the client device. This continuous activation, as long as the contactless card remains within the cover, allows it to authenticate with digital services. Removing the contactless card from the cover may cause the electromagnetic field to disappear, thereby terminating authentication with digital services.

[0021] Advantageously, using "heartbeats" or status messaging to provide continuous authentication makes it easier for users to interact with digital services. For example, a user can authenticate once and remain logged into digital services based on that authentication as long as the contactless card remains active. This enhances the security of card data by reducing the number of times users must enter authentication information.

[0022] By generally referring to the symbols and terminology used herein, one or more parts of the detailed description below can be presented according to program procedures executed on a computer or computer network. Those skilled in the art use these process descriptions and representations to most effectively convey the substance of their work to those skilled in the art. A process herein is generally considered to be a self-consistent sequence of operations that leads to a desired result. These operations are those that require physical manipulation of physical quantities. Typically, while not strictly necessary, these quantities are in the form of electrical, magnetic, or optical signals that can be stored, transmitted, combined, compared, and otherwise manipulated. It is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc., primarily for common use. However, it should be noted that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.

[0023] Furthermore, these manipulations are often referred to using terms such as addition or comparison, which are typically associated with mental operations performed by a human operator. However, in any of the operations described herein that form part of one or more embodiments, such an ability of a human operator is not necessary or desirable in most cases. Instead, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by computer programs stored therein, written in accordance with the teachings of this document, and / or include devices or digital computers specifically constructed for the desired purpose. The various embodiments also relate to devices or systems for performing these operations. These devices can be specifically constructed for the desired purpose. The required structures of the various such machines will be apparent from the given description.

[0024] Referring now to the accompanying drawings, wherein the same reference numerals are used throughout to refer to the same elements. In the following description, numerous specific details are set forth for purposes of explanation to provide a thorough understanding thereof. However, it will be apparent that novel embodiments can be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form for ease of description. The intention is to cover all modifications, equivalents, and substitutions within the scope of the claims.

[0025] Figure 1A schematic diagram of an exemplary system 100 consistent with the disclosed embodiments is shown. As shown, system 100 includes one or more contactless cards 101, one or more client devices 110, and one or more servers 120. The contactless card 101 represents any type of identification and / or payment card, such as a credit card, debit card, ATM card, gift card, etc. The contactless card 101 may include one or more chips (not shown), such as a radio frequency identification (RFID) chip, configured to communicate with the client device 110 wirelessly via NFC, EMV standards, or other short-range protocols. Although NFC is used as an example communication protocol, this disclosure is equally applicable to other types of wireless communications, such as EMV standards, Bluetooth, and / or Wi-Fi. The client device 110 represents any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop computer, portable gaming device, etc. The server 120 represents any type of computing device, such as a server, workstation, computing cluster, cloud computing platform, virtualized computing system, etc.

[0026] As shown in the figure, the memory 102 of the contactless card may include card data 103, a counter 104, a master key 105, a diversity key 106, a unique customer identifier 107, and account data storage 108. Card data 103 typically includes account-related information, such as information used to process payments using the contactless card 101. For example, card data 103 may include account number, expiration date, billing address, and card verification value (CVV). The account number can be any type of account, such as a primary account (PAN), a virtual account, and / or a token generated based on the PAN. Other types of account numbers may be considered, and the use of account numbers or other types of card data 103 should not be considered a limitation of this disclosure. Card data 103 may also include name, billing address, mailing address, and other account-related information. As described in more detail herein, the contactless card 101 may provide card data 103 and / or records from account number 108 to an account application 113 to provide authentication / access to digital service 114.

[0027] As shown in the figure, the memory 111 of the client device 110 includes an instance of an operating system (OS) 112. Example operating systems 112 include Android® OS, iOS®, Linux®, and Windows® operating systems. As shown, OS 112 may include an account application 113, a digital service 114, one or more other applications 115, and a clipboard 116. In embodiments where the digital service is a banking application or website, the account application 113 may allow the user to perform various account-related operations, such as viewing account balances, purchasing items, and processing payments. Initially, the user must authenticate using authentication credentials to access the account application 113. For example, authentication credentials may include a username and password, biometric credentials, etc. As will be described in more detail below, in order to access the account application 113 and / or the digital service 114, the user must also meet a secondary authentication based on data exchanged between the client device 110 and the contactless card 101.

[0028] Digital service 114 may include one or more services, including but not limited to client device applications (e.g., banking, social media, music streaming, games, etc.), websites, messaging services (e.g., email, text, etc.), and many other things. The embodiments described herein are not limited in this context. In some embodiments, digital service 114 is associated with account application 113. For example, digital service 114 may be installed on client device 110 and may operate in conjunction with account application 113.

[0029] As shown in the figure, server 120 includes a data storage 124 and a storage 122 for account data. Account data 124 may include account-related data for one or more users and / or accounts. Account data 124 may include at least a master key 105, a counter 104, a customer ID 107, an associated contactless card 101, the account holder's name, the account billing address, one or more mailing addresses, one or more card numbers, and biometric information for each account. Storage 122 may include instances of card data 103, counter 104, master key 105, and diversity key 106 from the management application 123 and one or more accounts from account data 124.

[0030] System 100 is configured to implement key diversification to protect data, which may be referred to herein as key diversification technology. Typically, server 120 (or another computing device) and contactless card 101 may be equipped with the same master key 105 (also called a master symmetric key). More specifically, each contactless card 101 is programmed with a different master key 105, which has a corresponding pair in server 120. For example, when manufacturing contactless card 101, a unique master key 105 may be programmed into the memory 102 of contactless card 101. Similarly, the unique master key 105 may be stored in the account data 124 of server 120 in the records of customers associated with contactless card 101 (and / or stored in different secure locations). The master key 105 can be kept secret from all parties except contactless card 101 and server 120, thereby enhancing the security of system 100.

[0031] The master key 105 can be used in conjunction with counter 104 to enhance security through key diversification. Counter 104 includes a value synchronized between contactless card 101 and server 120. The value of counter 104 can include a number that changes each time data is exchanged between contactless card 101 and server 120 (and / or contactless card 101 and client device 110). To enable NFC data transfer between contactless card 101 and client device 110, account application 113 can communicate with contactless card 101 when contactless card 101 is sufficiently close to reader 118 of client device 110. Reader 118 can be configured to read from and / or communicate with contactless card 101 (e.g., via NFC, Bluetooth, RFID, etc.). Therefore, example reader 118 may include an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.

[0032] For example, a user can bring the contactless card 101 close to the client device 110, thereby bringing the contactless card 101 sufficiently close to the reader 118 of the client device 110 to enable NFC data transfer between the contactless card 101 and the reader 118 of the client device 110. In some embodiments, the client device 110 can trigger the reader 118 via an application programming interface (API) call. Additionally and / or alternatively, the client device 110 can trigger the reader 118 based on periodically polling the reader 118. More generally, the client device 110 can use any feasible method to trigger the reader 118 for communication. In some embodiments, the contactless card 101 can be powered / activated in response to a magnetic field from the client device 110.

[0033] After communication is established between the client device 110 and the contactless card 101, the contactless card 101 can generate a Message Authentication Code (MAC) password. In some examples, this may occur when the contactless card 101 is read by the account application 113. Specifically, this may occur when a Near Field Data Exchange (NDEF) tag is read (e.g., NFC reading), which may be created according to the NFC Data Exchange format. For example, a reader such as the account application 113 and / or the reader 118 can send a message with the applet ID of the applet generating the NDEF, such as an applet selection message. After confirming the selection, a series of file selection messages can be sent, followed by a file read message. For example, this sequence may include "Select function file", "Read function file", and "Select NDEF file". At this time, the value of the counter 104 maintained by the contactless card 101 can be updated or incremented, followed by "Read NDEF file". At this time, a message can be generated, which may include a header and a shared secret. A session key can then be generated. The MAC password can be created from the message, which may include a header and a shared secret. The MAC cipher can then be concatenated with one or more random data blocks, and the MAC cipher and random number (RND) can then be encrypted using a session key. Afterward, the cipher and header can be concatenated, encoded in ASCII hexadecimal, and returned in NDEF message format (in response to a "Read NDEF File" message). In some examples, the MAC cipher can be sent as an NDEF tag, and in other examples, the MAC cipher can be included in a Uniform Resource Indicator (e.g., as a format string). The contactless card 101 can then send the MAC cipher to client device 110, which can then forward the MAC cipher to server 120 for authentication, as described below. However, in some embodiments, client device 110 can authenticate the MAC cipher. The embodiments described herein are not limited to this context.

[0034] More generally, when ready to send data (e.g., to server 120 and / or client device 110), contactless card 101 can increment the value of counter 104. Contactless card 101 can then provide the master key 105 and the value of counter 104 as input to a cryptographic algorithm that produces a diversity key 106 as output. The cryptographic algorithm can include encryption algorithms, hash-based message authentication code (HMAC) algorithms, password-based message authentication code (CMAC) algorithms, etc. Non-limiting examples of cryptographic algorithms can include symmetric encryption algorithms such as 3DES or AES128; symmetric HMAC algorithms such as HMAC-SHA-256; and symmetric CMAC algorithms such as AES-CMAC. Contactless card 101 can then use the diversity key 106 to encrypt data (e.g., customer identifier 107 and any other data). Contactless card 101 can then send the encrypted data (e.g., encrypted customer ID 109) to the account application 113 of client device 110 (e.g., via NFC connection, Bluetooth connection, etc.). The account application 113 of client device 110 can then send encrypted data to server 120 via network 130. In at least one embodiment, contactless card 101 sends the value of counter 104 along with the encrypted data. In such an embodiment, contactless card 101 can send either the value of encrypted counter 104 or the value of unencrypted counter 104.

[0035] Upon receiving the encrypted customer ID 109, the management application 123 of server 120 can perform the same symmetric encryption using the value of counter 104 as the input for encryption and the master key 105 as the key for encryption. As described above, the value of counter 104 can be specified in the data received from client device 110, or the value of counter 104 can be maintained by server 120 to enable key diversification for contactless card 101. The encrypted output can be the same diversification key value 106 created by contactless card 101. Management application 123 can then use diversification key 106 to decrypt the encrypted customer ID 109 received via network 130, thereby revealing the data sent by contactless card 101 (e.g., at least customer identifier 107). This allows management application 123 to verify the data sent by contactless card 101 via client device 110, for example, by comparing the decrypted customer ID 107 with the customer ID in account data 124 of the account.

[0036] Although counter 104 is used as an example, other data can be used to secure communication between contactless card 101, client device 110, and / or server 120. For example, counter 104 can be replaced with a random number (generated each time a new diversity key 106 is needed), the full value of the counter sent from contactless card 101 and server 120, a portion of the counter value sent from contactless card 101 and server 120, a counter maintained independently by contactless card 101 and server 120 but not sent between them, a one-time password exchanged between contactless card 101 and server 120, and a cryptographic hash of the data. In some examples, parties can use one or more portions of diversity key 106 to create multiple diversity keys 106.

[0037] As shown in the figure, server 120 may include one or more Hardware Security Modules (HSMs) 125. For example, one or more HSMs 125 may be configured to perform one or more cryptographic operations as disclosed herein. In some examples, one or more HSMs 125 may be configured as a dedicated security device configured to perform one or more cryptographic operations. HSMs 125 may be configured such that keys are never disclosed outside of HSMs 125, but are maintained within HSMs 125. For example, one or more HSMs 125 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 125 may be contained within server 120 or may communicate with server 120.

[0038] As described above, key diversification technology can be used to perform secure operations using contactless card 101. For example, once management application 123 verifies the encrypted customer ID 109 using key diversification, management application 123 can send the account number, expiration date, and / or the CVV associated with the account to account application 113 on client device 110. Management application 123 may also include other information (e.g., first name, last name, mailing address, billing address, other account information, etc.). The account number can be a PAN, a virtual account, and / or a PAN-generated token. Account application 113 can decrypt (if encrypted) the received data and provide the account number, expiration date, billing address, and / or CVV to the API of digital service 114.

[0039] In another embodiment, card data 103 is read directly from contactless card 101, which is useful when client device 110 is not connected to server 120. For example, account application 113 and / or digital service 114 may output instructions to bring contactless card 101 close to client device 110. In one embodiment, once contactless card 101 is brought near client device 110, contactless card 101 sends card data 103 to client device 110. In another embodiment, once contactless card 101 is brought near client device 110, account application 113 instructs contactless card 101 to send card data 103 to client device 110. In one example, contactless card 101 sends card data 103 (including one or more of account number, expiry date, CVV value, and account holder name) to client device 110 via NDEF file (e.g., via NFC, Bluetooth, and / or RFID). In another example, contactless card 101 uses the EMV protocol to send card data 103. In an example using the EMV protocol, card data 103 sent using the EMV protocol includes account number, expiry date, and account holder name. The contactless card 101 can then use the EMV protocol to send card data 103 to account application 113. In this example using the EMV protocol, account application 113 can receive CVV values ​​from contactless card 101 (e.g., CVV received from an NDEF file via NFC reading) and / or from management application 123 of server 120. However, in some embodiments, the EMV protocol can be used to send CVV values ​​directly from contactless card 101. Account application 113 can then provide card data 103 (e.g., account number, expiry date, and / or CVV) to the API of digital service 114.

[0040] Regardless of the technology used to provide card data 103 and / or account 108 to digital service 114, account application 113 and / or OS 112 can manage the data provided to digital service 114. For example, card data 103 and / or account 108 can remain in digital service 114 as long as contactless card 101 is active, such as when located near client device 110. This maintains access / authentication to digital service 114. As another example, card data 103 and / or account 108 can remain in digital service 114 after card data 103 and / or account 108 have been used to make a purchase.

[0041] Furthermore, account application 113 and / or digital service 114 can copy the account to clipboard 116 of the OS. Clipboard 116 stores data that can be copied and / or pasted within OS 112. For example, clipboard 116 can locally store data that will be pasted into fields on client device 110, and the user can use commands and / or gestures available within OS 112 to input / paste data stored in clipboard 116. For example, copying the account to clipboard 116 allows the user to use commands and / or gestures available within OS 112 to paste the account into the corresponding form field. Additionally, digital service 114 can output a notification specifying the due date and CVV while copying the account to clipboard 116. This allows the user to manually enter the due date and CVV into the corresponding form field while the notification is still present in the view. In some embodiments, account application 113 and / or digital service 114 can also copy the due date, billing address, and / or CVV to clipboard 116, thereby allowing the due date, billing address, and / or CVV to be pasted into the corresponding form field.

[0042] Figure 2 This is a schematic diagram 200 illustrating an example embodiment for providing continuous authentication to digital service 214 based on a contactless card 201 in proximity to a client device such as a mobile device 210. The mobile device 210 may be a smartphone or a tablet computer, although this is not limiting. In other embodiments, the client device may be a laptop computer, a desktop computer, or a self-service terminal. For example, the client device may be a laptop computer with an internal or external reader for communicating with the contactless card 201. The embodiments described herein are not limited to this context.

[0043] In this non-limiting example, digital service 214 could be a banking application stored in the memory of mobile device 210. A user could physically bring contactless card 201 close to mobile device 210. Power derived from electromagnetic field 227 of mobile device 210 could then be used to activate one or more chips and / or chip modules (not shown) of contactless card 201. More specifically, contactless card 201 is operatively capable of receiving electromagnetic field 227 and converting it into a suitable voltage to power other components of contactless card 201. For example, electromagnetic field 227 could be converted to power an RFID chip configured to communicate with mobile device 210 via, for example, NFC, EMV standards, or other short-range protocols in wireless communication.

[0044] When a user initially attempts to log in to his / her account, the login credentials received by API 221 of digital service 214 are transmitted to server 220 as the first set of encrypted data 216. The first set of encrypted data 216 can be associated with user account 228, which in turn is associated with the data storage of account data 224.

[0045] Then, server 220 can, for example, manage application 123 ( Figure 1 The first set of encrypted data 216 is compared with the customer identifier in the account data 224 of the user account 228, thereby validating or invalidating the data accordingly. If there is a positive match, the first authentication / verification 230 is then provided to the mobile device 210.

[0046] Next, digital service 214 can request a second authentication 232 from contactless card 201. In some embodiments, contactless card 201 has previously been activated based on electromagnetic field 227 received from client device 201. In other embodiments, contactless card 201 may be inactive, in which case it needs to be activated to complete the request for second authentication 232. For example, the user may not have previously positioned contactless card 201 near mobile device 210, or the position of contactless card 201 relative to the card reader 218 of mobile device 210 may result in insufficient communication signal strength from contactless card 201. In either case, mobile device 210 may display a prompt to the user via a graphical user interface (GUI). For example, a notification may instruct the user to place contactless card 201 in physical contact with the rear surface of mobile device 210. In other embodiments, the notification may provide feedback on the strength of electromagnetic field 227 and / or the signal strength of contactless card 201.

[0047] Once the contactless card 201 is activated, the card reader 218 of the mobile device 201 can receive a second set of encrypted data 234 from the communication interface 236 of the contactless card 201. In some embodiments, the second set of encrypted data 234 may be generated based on an encryption algorithm and a variety of keys stored in the memory of the contactless card 201. The second set of encrypted data 234 is associated with the user account 228.

[0048] Server 220 can then receive a second set of encrypted data 234 from mobile device 210, compare it with the customer identifier in account data 224 of user account 228, and thus validate or invalidate the data accordingly. If a match is confirmed, a second authentication / verification 238 is then provided to mobile device 210. Access to digital service 214 can then be provided, for example, through account application 213, in response to the first verification 230 and the second verification 238 of user account 228.

[0049] Once a user successfully logs into digital service 214, authorized access to digital service 214 can continue while contactless card 201 remains active. To achieve this, account application 213 can cause a series of periodic heartbeats or status messages 250 to be provided between mobile device 210 and contactless card 201 to verify that contactless card 201 is still active. In some embodiments, status messages 250 can be a series of requests or "pings" to contactless card 201, resulting in a communication response via antenna 229 of contactless card 201. For example, status messages 250 can trigger card reader 218 of contactless card 201 via application programming interface (API) calls. However, status messages 250 can also trigger card reader to communicate using any feasible method. If it is determined that contactless card 201 is inactive, such as when contactless card 201 does not receive any communication response, authorized access to digital service 214 can be terminated.

[0050] Status message 250 may be sent unencrypted or encrypted, signed, or otherwise protected. In some embodiments, status message 250 may include one or more authentication messages, such as reports regarding the activity / inactivity status of contactless card 201. Furthermore, status message 250 may be associated with first authentication 230 and / or second authentication 238.

[0051] In some embodiments, status message 250 may include sending any type of command or query, securely or publicly, receiving a response from contactless card 201, and then evaluating the response to determine if it falls within the expected parameter range. In other embodiments, mobile device 210 may include timer 252 configured to periodically send status message 250. Digital service 214 may be continuously accessible until account application 213 determines that the signal strength of contactless card 201 is below a predetermined threshold, for example, when contactless card 201 is removed from mobile device 210 or mobile device 210 enters sleep mode. In some embodiments, account application 213 may prevent mobile device 210 from entering sleep mode while contactless card 201 is active.

[0052] Figure 3 This is a schematic diagram 300 illustrating an example embodiment for providing continuous authentication to digital service 314 based on a contactless card 301 near a mobile device 310. Schematic diagram 300 may be similar to schematic diagram 200 described above. Therefore, for the sake of brevity, only certain aspects of schematic diagram 300 will be described below.

[0053] As shown in the figure, schematic diagram 300 may include a second client device 311, such as a personal computer. In this non-limiting example, digital service 314 may be a bank website operated / displayed on the second client device 311. Account application 313 may be located on the second client device 311. In other embodiments, account application 313 may be part of mobile device 310. In yet another embodiment, account application 313 may be distributed between mobile device 310 and the second client device 311.

[0054] When a user initially attempts to log in to his / her account, login credentials received by digital service 314 are transmitted to server 320 as a first set of encrypted data 316 that can be associated with the user's user account 328. Server 320 can then compare the first set of encrypted data 316 with a customer identifier in the user account's account data 324, for example, via a management application, thereby validating or invalidating the data accordingly. In the case of a positive match, first authentication / verification 330 is then provided from server 320 to second client device 311.

[0055] Digital service 314 can then request a second authentication 332 from contactless card 301. In some embodiments, the second authentication 332 request can be transmitted directly to mobile device 310, or it can be sent to server 320 for later transmission to mobile device 310. Contactless card 301 may have previously been activated based on magnetic field 327 received from client device 301. In other embodiments, contactless card 301 may be inactive, in which case activation of contactless card 301 is required to complete the request for second authentication 332.

[0056] Once the contactless card 301 is activated, the card reader 318 of the mobile device 301 can receive a second set of encrypted data 334 from the communication interface 336 of the contactless card 301. In some embodiments, the second set of encrypted data 334 may be generated based on an encryption algorithm and a variety of keys stored in the memory of the contactless card 301. The second set of encrypted data 334 is associated with a user account 328.

[0057] Then, server 320 can receive a second set of encrypted data 334 from mobile device 310, compare it with the customer identifier in account data 324 of user account 328, and thus validate or invalidate the data accordingly. If a match is confirmed, a second authentication / verification 338 is then provided to the second client device 311. Access to digital service 314 can then be granted, for example, by account application 313 in response to the first verification 330 and the second verification 338 of user account 328.

[0058] Once a user successfully logs into digital service 314, authorized access to digital service 314 can continue while contactless card 301 remains active. To achieve this, account application 213 can cause a series of periodic heartbeats or status messages 250 to be provided between mobile device 310 and contactless card 301 to verify whether contactless card 301 is still active. In some embodiments, status message 350 or the output of a status message (e.g., contactless card active / inactive) can be transmitted to server 320 and then to second client device 311. In some embodiments, status message 350 can be transmitted directly to second client device 311. If it is determined that contactless card 301 is inactive, authorized access to digital service 314 can be terminated.

[0059] Figure 4A An exemplary contactless card 401 is shown, which can be a payment card, such as a credit card, debit card, and / or gift card. As shown, the contactless card 401 can be issued by a service provider 405 displayed on the front or back of the card 401. In some examples, the contactless card 401 is not a payment card and can include, but is not limited to, an identification card. In some examples, the payment card can include a dual-interface contactless payment card. The contactless card 401 can include a substrate 410, which can include a single layer or one or more layers made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 401 can have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card can additionally conform to the ISO / IEC 14443 standard. However, it should be understood that the contactless card 401 according to this disclosure may have different characteristics, and this disclosure does not require the contactless card to be implemented in the form of a payment card.

[0060] The contactless card 401 may also include identification information 415 displayed on the front and / or back of the card and a contact pad 420. The contact pad 420 may be configured to establish communication with another communication device (e.g., client device 110). Figure 1 Communication with user equipment, smartphones, laptops, desktop computers, or tablets. The contactless card 401 may also include processing circuitry, an antenna, and... Figure 4A Other components not shown. These components may be located behind the contact piece 420 or elsewhere on the substrate 410. The contactless card 401 may also include a magnetic stripe or magnetic tape, which may be located on the back of the card. Figure 4A (Not shown in the image).

[0061] like Figure 4B As shown, the contact pad 420 of the contactless card 401 may include processing circuitry 425 for storing and processing information, which includes a microprocessor 430 and a memory 102. It is understood that the processing circuitry 425 may include other components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware necessary to perform the functions described herein.

[0062] Memory 102 can be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 401 may include one or more of these memories. A read-only memory can be factory-programmed to read-only or can be programmed once. The one-time programming function provides the opportunity to write once and then read multiple times. A write-once-read-many memory can be programmed at some point after the memory chip leaves the factory. Once programmed, memory 102 cannot be rewritten, but it can be read multiple times. A read / write memory can be programmed and reprogrammed multiple times after leaving the factory. A read / write memory can also be read multiple times after leaving the factory.

[0063] Memory 102 may be configured to store one or more applets 440, one or more counters 104, a customer identifier 107, and a virtual account 108. One or more applets 440 may include one or more software applications configured to execute on one or more contactless cards, such as Java Card® applets. However, it should be understood that applet 440 is not limited to Java Card applets, but may include any software application that can run on a contactless card or other device with limited memory. One or more counters 104 may include numeric counters sufficient to store integers. The customer identifier 107 may include a unique alphanumeric identifier assigned to a user of the contactless card 401, distinguishing the user of this contactless card from users of other contactless cards. In some examples, the customer identifier 107 may identify a customer and the account assigned to that customer, and may further identify the contactless card 401 associated with the customer's account. In some embodiments, the account 108 may include thousands of one-time-use virtual accounts associated with the contactless card 401.

[0064] The processor and memory elements of the exemplary embodiments described above are based on the contact patch, but this disclosure is not limited thereto. It should be understood that these elements may be implemented outside of the contact patch 420 or completely separate from the contact patch 420, or implemented as other elements besides the processor 430 and memory 402 located within the contact patch 4420.

[0065] In some examples, the contactless card 401 may include one or more antennas (not shown). Generally, by using the antenna, processing circuitry 425, and / or memory 102, the contactless card 401 can provide a communication interface for communication via NFC, Bluetooth, and / or Wi-Fi. In some embodiments, the antenna may be placed within the contactless card 401 and around the processing circuitry 425 of the contact patch 420. The antenna may be integrated with the processing circuitry 425, and one or more antennas may be used in conjunction with an external boost coil. As another example, the antenna may be located external to the contact patch 420 and the processing circuitry 425. As described above, the antenna may transmit a response to a status message to indicate whether the contactless card 401 is active. In the absence of a communication response received from the antenna, authorized access to one or more digital services may be terminated.

[0066] As described above, the contactless card 401 can be built on a software platform (such as a JavaCard) that can run on a smart card or other device with limited memory, and can securely execute one or more applications or applets. In various mobile application-based use cases, an applet 440 can be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA). The applet 440 can be configured to respond to one or more requests (e.g., near-field data exchange requests) from a reader (e.g., a mobile NFC reader, such as the NFC reader of client device 110) and generate an NDEF message that includes an encrypted secure OTP encoded as an NDEF text tag.

[0067] An example of NDEF OTP is the NDEF short record layout (SR=1). In such an example, one or more applets 440 can be configured to encode the OTP into text tags known in NDEF Class 4. In some examples, an NDEF message may include one or more records. Applets 440 can be configured to add one or more static tag records in addition to the OTP record.

[0068] In some examples, one or more mini-programs 440 can be configured to simulate RFID tags. RFID tags can include one or more polymorphic tags. In some examples, different cipher data is presented each time a tag is read, which can indicate the authenticity of the contactless card. Based on one or more applications, NFC reading of the tags can be processed, and data can be sent to a server, such as server 120 (…). Figure 1 And the data can be verified on the server.

[0069] In some examples, the contactless card 401 and server 120 may include data that allows the contactless card 401 to be correctly identified. The contactless card 401 may include one or more unique identifiers, wherein a counter 104 may be configured to increment based on the identification of one or more unique identifiers each time a read operation occurs. In some examples, each time data is read from the contactless card 401 (e.g., by client device 110), the counter 104 is sent to the server for verification and to determine whether the counter values ​​104 are equal (e.g., as part of verification).

[0070] In some embodiments, during the creation process of the contactless card 401, two cryptographic keys can be uniquely assigned to each card. The cryptographic keys may include symmetric keys that can be used for encryption and decryption of data. The Triple DES (3DES) algorithm can be used by EMV, and it is implemented in hardware within the contactless card 101. By using a key diversification process, one or more keys can be derived from the master key based on uniquely identifiable information for each entity requiring a key.

[0071] In some examples, to overcome the potential vulnerabilities of the 3DES algorithm, session keys (e.g., unique keys for each session) can be derived instead of using a master key, a unique card-derived key, and a counter can be used as diversified data. For example, when a contactless card 401 is used each time in an operation, a different key can be used to create a Message Authentication Code (MAC) and perform encryption. This results in three layers of encryption. Session keys can be generated by one or more applets and derived by combining one or more algorithms with application transaction counters (as defined in EMV 4.3, Volume 2, A1.3.1, Public Session Key Derivation).

[0072] Furthermore, the increments of the contactless card 401 can be unique, either through personalized allocation or algorithmically assigned using some identification information. For example, odd-numbered cards can increment by 2, and even-numbered cards by 5. In some examples, the increments can also vary during sequential readings, allowing a card to increment sequentially by 1, 3, 5, 2, 2, ..., repeating in this manner. Specific sequences or algorithmic sequences can be defined during personalization or from one or more processes derived from unique identifiers. This makes it more difficult for replay attackers to generalize from a small number of card instances.

[0073] The authentication message can be transmitted as the content of a text NDEF record in hexadecimal ASCII format. In another example, the NDEF record can be encoded in hexadecimal format.

[0074] Figures 5A-5BA non-limiting embodiment of a cover 560 on a client device 510, such as a mobile device, is shown. The cover 560 may be a mobile device housing surrounding the client device 510. In some embodiments, the cover 560 may include an opening allowing a user to interact with a screen 562 of the client device 510. As shown, the cover 560 may include a slot or container 566 through an end wall 568 of the cover 560, wherein the container 566 is operable to receive a contactless card 501 therein. Once placed within the container 566, the contactless card 501 may be pre-positioned to enable communication with a card reader (not shown) of the client device 510. It should be understood that the size and position of the cover 560 (including the container 566) may vary depending on one or more characteristics of the client device 501 and / or the contactless card 501. As further shown, the container 566 and the contactless card 501 may be positioned along the back 570 of the client device 510. In some embodiments, the cover 560 may be transparent or opaque. The embodiments described herein are not limited in this context.

[0075] Figure 6 An embodiment of a logic flow 600 for providing continuous authentication to a digital service is illustrated. At block 601, the logic flow 600 may include receiving a request to access a digital service via an application executing on processor circuitry. In some embodiments, the digital service may include one or more services, including but not limited to client device applications (e.g., banking, social media, music streaming, games, etc.), websites, or messaging services (e.g., email, text, etc.). At block 603, the logic flow 600 may include receiving a first authentication via the application based on verification of a first set of encrypted data associated with a user account. In some embodiments, the first set of encrypted data is generated based on login credentials provided by the user to the digital service. At block 605, the logic flow 600 may include requesting a second authentication via the application to a contactless card.

[0076] In block 607, logic flow 600 may include receiving a second set of encrypted data from the communication interface of the contactless card via a card reader of the client device in response to the activation of the contactless card. The second set of encrypted data is generated based on a cryptographic algorithm and a plural key, which is stored in the memory of the contactless card. The contactless card is activated by the client device when it is positioned near the client device, and the second set of encrypted data is associated with a user account.

[0077] In box 609, logic flow 600 may include receiving a second authentication of a user account based on a second set of encrypted data from a server via an application. In box 611, logic flow may include authorizing access to digital services via an application in response to the first and second authentications of the user account. In box 613, logic flow may include continuously providing a series of periodic status messages via an application between a client device and a contactless card to verify whether the contactless card remains active, wherein authorization to access digital services continues while the contactless card is active, and wherein authorization to access digital services is terminated when the contactless card is inactive.

[0078] In some examples, the contactless card described herein can be placed on top of a device such as one or more computer kiosks or terminals to verify identity in response to the purchase of a transactional item, such as coffee. By using contactless cards, secure methods for verifying identity can be established within loyalty programs. This provides a way to securely verify identity in a manner different from simply scanning a bar card, for example, to receive rewards, coupons, offers, or other benefits. For instance, encrypted transactions can occur between the contactless card and the device, which can be configured to process one or more tap gestures. As described above, one or more applications can be configured to verify the user's identity. In some examples, data such as bonus points, loyalty points, reward points, healthcare information, etc., can be written back to the contactless card.

[0079] In some embodiments, the example authentication communication protocol may mimic the offline dynamic data authentication protocol of the EMV standard typically performed between transaction cards and point-of-sale devices, with some modifications. For example, because the example authentication protocol itself is not used to complete payment transactions with the issuing institution / payment processor, no data value is required, and authentication can be performed without involving a real-time online connection with the issuing institution / payment processor. As is known in the art, a point-of-sale (POS) system submits a transaction, including a transaction value, to the issuing institution. The issuing institution may approve or reject the transaction based on whether it recognizes the transaction value. Meanwhile, in some embodiments of this disclosure, transactions originating from client devices lack a transaction value associated with the POS system. Therefore, in some embodiments, a virtual transaction value (i.e., a value that the issuing institution recognizes and is sufficient to allow activation to occur) may be passed as part of the example authentication communication protocol. POS-based transactions may also be rejected based on the number of transaction attempts (e.g., transaction counter). Multiple attempts exceeding the buffer value may result in a soft rejection; a soft rejection requires further verification before accepting the transaction. In some implementations, the buffer value of the transaction counter may be modified to avoid rejecting legitimate transactions.

[0080] In some examples, contactless cards can selectively transmit information based on the receiving device. Once near, the contactless card can identify the device it is pointing to, and based on that identification, it can provide the appropriate data to that device. This advantageously allows the contactless card to send only the information necessary to complete an immediate action or transaction (such as payment or card authentication). By limiting data transmission and avoiding unnecessary data transfers, both efficiency and data security can be improved. Information identification and selective communication can be applied to a variety of scenarios, including card activation, balance transfers, account access attempts, commercial transactions, and fraud prevention.

[0081] As another example, continuous authentication can be applied to POS devices, including but not limited to self-service terminals, checkout cash registers, payment stations, or other terminals. Contactless cards can identify POS devices and send only the information necessary for the operation or transaction. For example, after identifying a POS device used to complete a commercial transaction, a contactless card can convey the payment information required to complete the transaction according to the EMV standard.

[0082] In some examples, the POS device involved in the transaction can request or specify additional information that will be provided by the contactless card, such as device-specific information, location-specific information, and transaction-specific information. For instance, once the POS device receives data communication from the contactless card, it can identify the contactless card and request additional information necessary to complete the operation or transaction.

[0083] In some examples, the POS device may be attached to an authorized merchant or other entity familiar with or accustomed to performing certain contactless card transactions. However, it should be understood that such an affiliation is not required to perform the described methods.

[0084] In examples such as shopping malls, grocery stores, and convenience stores, contactless cards can be placed on or near the client's device without having to open the app to indicate the desire or intent to use one or more of the following: reward points, loyalty points, coupons, offers, etc. This thus reveals the intent behind the purchase.

[0085] Figure 7 An embodiment of an exemplary computing architecture 800 is illustrated, which includes a computing system 802 that can be adapted to implement the various embodiments described above. In various embodiments, the computing architecture 800 may include an electronic device or be implemented as part of an electronic device. In some embodiments, the computing architecture 800 may, for example, represent a system 100 that implements one or more components of a system (…). Figure 1In some embodiments, computing system 802 may, for example, represent client device 110 and server 120 of system 100. The embodiments described herein are not limited in this context. More generally, computing architecture 800 is configured to implement the embodiments described herein. Figure 1-6 All logic, applications, systems, methods, devices, and functions described.

[0086] As used herein, the terms “system,” “component,” and “module” are intended to refer to computer-related entities, which can be hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing architecture 800. For example, a component can be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer. For example, an application running on a server and the server itself can both be components. One or more components can reside in a process and / or an execution thread, and components can reside on a single computer and / or be distributed across two or more computers. Furthermore, components can communicate and couple with each other through various types of communication media to coordinate operation. Coordination may involve one-way or two-way information exchange. For example, components can transmit information in the form of signals transmitted via a communication medium. This information can be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, other embodiments may alternatively employ data messages. Such data messages can be sent through various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0087] The computing system 802 includes various common computing elements, such as one or more processors, multi-core processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to those implemented by the computing system 802.

[0088] like Figure 7As shown, computing system 802 includes processor 804, system memory 806, and system bus 808. Processor 804 can be any of a variety of commercial computer processors, including but not limited to AMD® Athlon®, Duron®, and Opteron® processors; ARM® application and embedded security processors; IBM® and Motorola® DragonBall® and PowerPC® processors; IBM and Sony® Cell processors; Intel® Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors; and similar processors. Dual microprocessors, multi-core processors, and other multiprocessor architectures can also be used as processor 804.

[0089] System bus 808 provides interfaces for system components, including but not limited to system memory 806 and processor 804. System bus 808 can be any type of bus structure using any of the various commercial bus architectures, which can be further interconnected to memory bus (with or without memory controller), peripheral bus, and local bus. Interface adapters can be connected to system bus 808 via slot architecture. Example slot architectures can include, but are not limited to, Accelerated Graphics Port (AGP), Card Bus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extended) (PCI(X)), PCI Express, PCMCIA, etc.

[0090] System memory 806 may include various types of computer-readable storage media in the form of one or more high-speed storage cells, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash memory arrays), polymer memory such as ferroelectric polymer memory, osmium memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic cards or optical cards, drives for device arrays such as redundant arrays of independent disks (RAID), solid-state storage devices (e.g., USB storage, solid-state drives (SSDs)), and any other type of storage media suitable for storing information. Figure 7In the illustrated embodiment, system memory 806 may include non-volatile memory 810 and / or volatile memory 812. The Basic Input / Output System (BIOS) may be stored in non-volatile memory 810.

[0091] The computing system 802 may include various types of computer-readable storage media in the form of one or more low-speed storage units, including an internal (or external) hard disk drive (HDD) 814, a floppy disk drive (FDD) 816 for performing read and write operations on a removable disk 818, and an optical disc drive 820 for performing read and write operations on a removable optical disc 822 (e.g., a CD-ROM or DVD). The HDD 814, FDD 816, and optical disc drive 820 may be connected to the system bus 808 via an HDD interface 824, an FDD interface 826, and an optical disc drive interface 828, respectively. The HDD interface 824 for external drive implementation may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 802 is generally configured to implement the technologies described herein. Figure 1-6 All logic, systems, methods, devices, and functions described.

[0092] Drives and associated computer-readable media provide volatile and / or non-volatile storage for data, data structures, computer-executable instructions, etc. For example, multiple program modules may be stored in drive and memory units 810, 812, including an operating system 830, one or more applications 832, other program modules 834, and program data 836. In one embodiment, one or more applications 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as operating system 112, account application 113, digital service 114, other applications 115, clipboard 116, and management application 123.

[0093] Users can input commands and information into computing system 802 through one or more wired / wireless input devices (e.g., keyboard 838 and pointing devices such as mouse 840). Other input devices may include microphones, infrared (IR) remote controls, radio frequency (RF) remote controls, game controllers, styluses, card readers, dongles, fingerprint readers, gloves, graphics tablets, joysticks, keyboards, retinal readers, touchscreens (e.g., capacitive, resistive, etc.), trackballs, trackpads, sensors, styluses, etc. These and other input devices are typically connected to processor 804 via input device interface 842 coupled to system bus 808, but can be connected via other interfaces such as parallel ports, IEEE 1394 serial ports, game ports, USB ports, IR interfaces, etc.

[0094] A monitor 844 or other type of display device is also connected to the system bus 808 via an interface (such as a video adapter 846). The monitor 844 can be internal or external to the computing system 802. In addition to the monitor 844, the computer typically includes other peripheral output devices such as speakers, printers, etc.

[0095] Computing system 802 can operate in a networked environment using logical connections to one or more remote computers (e.g., remote computer 848) via wired and / or wireless communications. Remote computer 848 may be a workstation, server computer, router, personal computer, laptop computer, microprocessor-based entertainment device, peer-to-peer device, or other common network node, and typically includes many or all of the elements described with respect to computing system 802, although for brevity only memory / storage device 850 is shown. The depicted logical connections include wired / wireless connections to a local area network (LAN) 852 and / or a larger network, such as a wide area network (WAN) 854. Such LAN and WAN network environments are common in offices and companies and facilitate enterprise-wide computer networks, such as intranets, all of which can connect to global communication networks, such as the Internet. In embodiments, Figure 1 Network 130 is one or more of LAN 852 and WAN 854.

[0096] When used in a LAN network environment, the computing system 802 is connected to the LAN 852 via a wired and / or wireless communication network interface or adapter 856. Adapter 856 facilitates wired and / or wireless communication to the LAN 852, and the LAN 852 may also include a wireless access point configured thereon for communicating with the wireless functionality of adapter 856.

[0097] When used in a WAN network environment, computing system 802 may include a modem 858, or a communication server connected to WAN 854, or other means for establishing communication over WAN 854, such as via the Internet. Modem 858 may be an internal or external wired and / or wireless device connected to system bus 808 via input device interface 842. In a network environment, program modules or portions thereof shown with respect to computing system 802 may be stored in remote memory / storage device 850. It should be understood that the network connections shown are exemplary, and other means of establishing communication links between computers may be used.

[0098] The computing system 802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operable in wireless communication (e.g., IEEE 802.16 air modulation technology). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth™ wireless technologies. Therefore, communication can be a predefined structure like a traditional network, or simply self-organizing communication between at least two devices. Wi-Fi networks use radio technologies known as IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and fast wireless connectivity. Wi-Fi networks can be used to interconnect computers, connect to the Internet, and connect to wired networks (using IEEE 802.3 related media and functions).

[0099] Various embodiments can be implemented using a variety of hardware elements, software elements, or a combination of both. Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, APIs, instruction sets, computational code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. The determination of whether to implement an embodiment using hardware elements and / or software elements can vary depending on any number of factors, such as desired computational speed, power levels, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance limitations.

[0100] One or more aspects of at least one embodiment can be implemented by representative instructions stored on a machine-readable medium representing various logic within a processor, which, when read by a machine, instruct the machine to manufacture the logic to perform the techniques described herein. This representation, referred to as an "IP core," can be stored on a tangible machine-readable medium and provided to various customers or manufacturers for loading into manufacturing machines that manufacture the logic or processor. For example, some embodiments can be implemented using a machine-readable medium or article of manufacture that can store instructions or instruction sets that, when executed by a machine, cause the machine to perform the methods and / or operations according to the embodiments. Such a machine may, for example, include any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles of art may include, for example, any suitable type of memory cell, memory device, memory article, memory medium, storage device, storage item, storage medium and / or storage cell, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, optical disc read-only memory (CD-ROM), recordable optical disc (CD-R), rewritable optical disc (CD-RW), optical disc, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital universal disks (DVDs), magnetic tape, cassette tape, etc. Instructions may include, for example, any suitable type of code implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language, source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc.

[0101] The foregoing description of exemplary embodiments has been presented for illustrative and descriptive purposes and is not intended to be exhaustive or to limit the scope of this disclosure to the precise forms disclosed. Many modifications and variations are possible based on this disclosure. The scope of this disclosure is intended to be limited not by this detailed description but by the appended claims. Future applications claiming priority to this application may claim the disclosed subject matter in different ways and may generally include any one or more sets of limitations as disclosed or otherwise shown herein.

Claims

1. A system comprising: Processor circuitry; as well as A memory storing instructions that, when executed by the processor circuitry, cause the processor circuitry to: The application executing on the processor circuit receives requests to access digital services. The application receives a first authentication based on a first set of encrypted data associated with the user account. The application requests a second authentication from the contactless card. In response to the activation of the contactless card, a second set of encrypted data is received from the communication interface of the contactless card via the card reader of the client device. The second set of encrypted data is generated based on a cryptographic algorithm and a diversified key, which is stored in the memory of the contactless card. The contactless card is activated by the client device when it is positioned near the client device, and the second set of encrypted data is associated with the user account. The application receives a second verification of the user account based on the second set of encrypted data from the server. In response to the first and second verifications of the user account, access to the digital service is authorized through the application; The application continuously provides a series of periodic status messages between the client device and the contactless card to verify whether the contactless card remains active, wherein while the contactless card is active, access to the digital service continues to be authorized, and while the contactless card is inactive, access to the digital service is terminated.

2. The system according to claim 1, wherein the memory stores instructions that, when executed by the processor circuit, cause the application to determine that the contactless card is inactive when the signal strength of the contactless card is below a predetermined threshold.

3. The system according to claim 1, wherein the memory stores instructions that, when executed by the processor circuit, cause the application to activate the contactless card in response to the magnetic field of the client device.

4. The system of claim 1 further includes a second client device, wherein the application runs on the second client device.

5. The system of claim 1, wherein the client device is one of: a mobile device, a personal computer, and an external contactless card reader.

6. The system of claim 5, wherein the memory stores instructions that, when executed by the processor circuitry, cause the application to: The second authentication is requested directly from the mobile device; In response to the request for the second authentication, the second set of encrypted data is received from the communication interface of the contactless card; and The second set of encrypted data is sent to the server to receive the second verification of the user account based on the second set of encrypted data.

7. The system of claim 1, further comprising a physical cover located on the client device, the cover including a container operable to receive the contactless card, wherein the container is located near the card reader of the client device.

8. A method comprising: The application executing on the processor circuit receives requests to access digital services. The application receives a first authentication based on a first set of encrypted data associated with the user account. The application requests a second authentication from the contactless card. In response to the activation of the contactless card, a second set of encrypted data is received from the communication interface of the contactless card via the card reader of the client device. The second set of encrypted data is generated based on a cryptographic algorithm and a diversified key, which is stored in the memory of the contactless card. The contactless card is activated by the client device when it is positioned near the client device, and the second set of encrypted data is associated with the user account. The application receives a second verification of the user account based on the second set of encrypted data from the server. In response to the first and second verifications of the user account, access to the digital service is authorized through the application; as well as The application continuously provides a series of periodic status messages between the client device and the contactless card to verify whether the contactless card remains active, wherein while the contactless card is active, access to the digital service continues to be authorized, and while the contactless card is inactive, access to the digital service is terminated.

9. The method of claim 8, further comprising determining, by the application, that the contactless card is inactive when the signal strength of the contactless card is below a predetermined threshold.

10. The method of claim 8, further comprising activating the contactless card via the application in response to a magnetic field of the client device.