Improving the sensitivity and readability of contactless cards
Patent Information
- Application Number
- CN202480085657.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-04
- Filing Date
- 2024-11-26
- Publication Date
- 2026-08-18
AI Technical Summary
然而,现有的碰即付终端(移动和/或固定)具有小而弱的现场读取器,这使得很难在卡和阅读器之间建立连接,从而阻碍了碰即付卡的使用
Smart Images

Figure CN122603337A_ABST
Abstract
Description
[0001] Cross-references to related applications
[0002] This application claims priority to U.S. Patent Application Serial No. 18 / 131,489, filed April 6, 2023, the entire disclosure of which is incorporated herein by reference. Technical Field
[0003] This disclosure relates generally to data processing, and more specifically to contactless cards, and even more specifically to improving the sensitivity and / or readability of contactless cards in various computing environments, such as, for example, including mobile and / or non-mobile devices that allow transactions to be performed using a tap. Background Technology
[0004] Tap-to-pay transactions have become one of the most popular methods of paying for goods and services. Tap-to-pay is based on Near Field Communication (NFC) technology, which can be embedded in credit cards, smartphones, and other mobile devices. This technology allows users to make credit card transactions by bringing their card and / or smartphone within a specific distance (or tapping) a specific area of the point-of-sale terminal, thus enabling the transmission of specific data for payment purposes. However, existing tap-to-pay terminals (mobile and / or fixed) have small and weak field readers, making it difficult to establish a connection between the card and the reader, thus hindering the use of tap-to-pay cards. Summary of the Invention
[0005] In some embodiments, the present subject matter relates to a computer-implemented method for improving the sensitivity and / or readability of contactless cards. The method may include receiving one or more signals from a first device using at least one processor, each of the signals being responsive to one or more transmissions generated and transmitted to the first device by a corresponding receiving coil of a plurality of receiving coils upon energization. The plurality of receiving coils may be communicatively coupled to at least one processor. The method may further include determining the signal strength of each of the signals received from the first device, identifying a first signal with the highest signal strength among the one or more signals based on the determined signal strength, selecting a first receiving coil corresponding to the first signal, de-energizing the plurality of receiving coils, energizing the selected first receiving coil, and establishing communication with the first device using the selected first receiving coil.
[0006] In some implementations, the present subject may include one or more of the following optional features. The first device may be a contactless card. The second device may include a processor and multiple receiving coils. Establishing communication may include establishing a near-field communication (NFC) exchange between the second device and the contactless card. Based on the establishment of the NFC exchange, the contactless card may be configured to transmit contactless card data to the second device. The contactless card data may include at least one of the following: an account number associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, and any combination thereof.
[0007] In some implementations, the contactless card may include at least one of the following: credit card, debit card, electronic gift card, prepaid credit card, prepaid debit card, and any combination thereof.
[0008] In some implementations, multiple receiving coils can be energized simultaneously, and after being energized, each of the multiple receiving coils can be configured to generate a corresponding transmission and send it to the first device.
[0009] In some implementations, multiple receiving coils may be energized in a predetermined order, and after being energized, each of the multiple receiving coils may be configured to generate a corresponding transmission based on the predetermined order and send it to a first device.
[0010] In some implementations, the selected first receiving coil can be configured to receive the highest current used to excite the first receiving coil.
[0011] In some implementations, the excitation may include energizing a selected first receiving coil and de-energizing the remaining receiving coils among a plurality of receiving coils.
[0012] In some embodiments, the method may further include determining one or more locations of the first device relative to a plurality of receiving coils based on the determined signal strength. The method may also include selecting a first location of the first device from the one or more locations of the first device according to a selected first receiving coil. The first location may correspond to the first device being close to the selected first receiving coil and potentially far from the remaining receiving coils among the plurality of receiving coils. The method may include generating an indication for repositioning the first device based on the selected first location and displaying the generated indication on a graphical user interface communicatively coupled to a processor.
[0013] In some embodiments, the present subject matter relates to a system for improving the sensitivity and / or readability of contactless cards. The system may include at least one processor communicatively coupled to a plurality of receive coils and at least one non-transitory storage medium storing instructions, which, when executed by the processor, may cause the processor to perform operations including determining one or more locations of a first device relative to the plurality of receive coils. This determination may include receiving one or more signals from the first device, each of the one or more signals being responsive to one or more transmissions generated and transmitted to the first device when a corresponding receive coil of the plurality of receive coils is energized. The operation may also include determining the signal strength of each of the one or more signals received from the first device and determining one or more locations of the first device based on the determined signal strengths. The operation may further include identifying a first signal with the highest signal strength among the one or more signals based on the determined signal strengths, selecting a first receive coil corresponding to the first signal, determining a first location among one or more locations that may be close to the first receive coil, and generating an indication for repositioning the first device to the first location.
[0014] In some implementations, the current subject may include one or more of the following optional features. The operation may also include deactivating a plurality of receiving coils and activating a selected first receiving coil, and establishing communication with a first device using the selected first receiving coil. The operation may also include displaying the generated indication on a graphical user interface communicatively coupled to at least one processor. The first device may be a contactless card, wherein establishing communication may include establishing a near-field communication (NFC) exchange with the contactless card. Based on the establishment of the NFC exchange, the contactless card may be configured to transmit contactless card data. The contactless card data may include at least one of the following: an account number associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, and any combination thereof.
[0015] In some implementations, the selected first receiving coil can be configured to receive the highest current used to excite the first receiving coil.
[0016] In some implementations, the excitation may include energizing a selected first receiving coil and de-energizing the remaining receiving coils among a plurality of receiving coils.
[0017] In some embodiments, the present subject matter may relate to a computer program product comprising a non-transitory machine-readable medium storing instructions which, when executed by at least one programmable processor, can cause the programmable processor to perform operations including: determining the signal strength of each of one or more signals received from a first device, wherein each of the one or more signals can be in response to one or more transmissions generated and transmitted to the first device by one or more receiving coils of a plurality of receiving coils when energized; identifying a first signal with the highest signal strength among the one or more signals based on the determined signal strength of the one or more signals; selecting a first receiving coil corresponding to the first signal; de-energizing the plurality of receiving coils; and energizing the selected first receiving coil and establishing communication with the first device using the selected first receiving coil.
[0018] Non-transitory computer program products (i.e., physically implemented computer program products) are also described, storing instructions that, when executed by one or more data processors of one or more computing systems, cause at least one data processor to perform the operations described herein. Similarly, computer systems are also described, which may include one or more data processors and memory coupled to the one or more data processors. The memory may temporarily or permanently store instructions that cause at least one processor to perform one or more operations described herein. Furthermore, the methods may be implemented by one or more data processors within a single computing system or distributed among two or more computing systems. Such computing systems may be interconnected and may exchange data and / or commands or other instructions via one or more connections, including but not limited to connections via networks (e.g., the Internet, wireless wide area networks, local area networks, wide area networks, or wired networks), direct connections between one or more computing systems, etc.
[0019] Details of one or more variations of the subject matter described herein are set forth in the accompanying drawings and the description below. Other features and advantages of the subject matter described herein will be apparent from the description and drawings, as well as from the claims. Attached Figure Description
[0020] The accompanying drawings, which are incorporated in and constitute a part of this specification, illustrate certain aspects of the subject matter disclosed herein and, together with the specification, help to explain some principles associated with the disclosed embodiments. In the drawings:
[0021] Figure 1A An exemplary system for determining the readability of a contactless card in various computing environments is shown, according to some implementations of the present topic;
[0022] Figure 1BAnother exemplary system for determining the readability of contactless cards in various computing environments is shown, according to some implementations of the present topic;
[0023] Figure 1C An example of a virtual grid for contactless cards is shown, according to some implementations of the current topic;
[0024] Figure 2 Exemplary processes for improving the readability of contactless cards and / or any other mobile devices, according to some embodiments of the present subject, are shown;
[0025] Figure 3 Another exemplary process for improving the readability of contactless cards and / or any other mobile devices is shown, according to some implementations of the present topic;
[0026] Figure 4 An exemplary process for determining the position of a contactless card, according to some embodiments of the present topic, is shown;
[0027] Figure 5 This illustrates yet another exemplary process for improving the readability of contactless cards and / or any other mobile devices, according to some implementations of the present subject matter;
[0028] Figure 6 One aspect of the subject matter according to some embodiments is shown;
[0029] Figure 7 One aspect of the subject matter according to some embodiments is shown;
[0030] Figure 8 The following are examples of contactless cards according to some embodiments of the present topic;
[0031] Figure 9 The transaction card component is shown according to some embodiments of the present topic;
[0032] Figure 10 The sequence stream is shown according to some implementations of the current topic;
[0033] Figure 11 The data structures shown are based on some implementations of the current topic;
[0034] Figure 12 This is a schematic diagram of a key system based on some implementations of the current topic;
[0035] Figure 13 This is a flowchart of a method for generating passwords based on some implementations of the current topic;
[0036] Figure 14One aspect of the subject matter according to some embodiments is shown; and
[0037] Figure 15 One aspect of the subject matter is shown according to some implementation methods. Detailed Implementation
[0038] To address these and other potential shortcomings of currently available solutions, one or more embodiments of the present subject matter relate to methods, systems, articles, etc., which (among other possible advantages) provide improved sensitivity and / or readability of contactless cards in a variety of computing environments, such as mobile and / or non-mobile devices that allow transactions to be performed using taps.
[0039] In some implementations, the present subject matter relates to providing improved sensitivity / readability in interfaces (such as, for example, near-field communication switching interfaces) between contactless cards and / or mobile devices and another mobile and / or non-mobile device. In exemplary, non-limiting implementations, contactless cards (such as, for example, hereinafter combined with...) Figures 6-15 The card shown and described may be configured to communicate with computing devices (e.g., mobile phones, point-of-sale terminals, and / or any other type of computing device).
[0040] The computing device can be configured to include multiple receiving coils that can be energized to generate signals and / or transmit signals to a contactless card. Energization of the receiving coils can be achieved, for example, by supplying current to the coils from the power supply of the computing device via one or more circuits also incorporated into the computing device. Each of the receiving coils can be configured as a transceiver and can transmit and / or receive signals from the contactless card. The receiving coils can be configured to transmit signals using different and / or the same frequencies. The transmission of signals can be achieved via Near Field Communication (NFC) exchange and / or an interface. It is understood that any other means of providing communication between the contactless card and the computing device are possible.
[0041] When transmitting one or more signals to a contactless card via one or more receiving coils, a computing device can be configured to determine the signal strength of the signals that have been transmitted to and / or received from the contactless card. The signal strength can be used to further determine the location of the contactless card relative to each receiving coil that may have transmitted signals to the contactless card and / or which receiving coil may have generated / transmitted and / or received the strongest signal. One or more processors of the computing device can be configured to obtain signal strength measurements from one or more sensors, which can be incorporated into the computing device and / or the receiving coils. The sensors can be current sensors, which can indicate the current being supplied to the receiving coils and / or the current generated by the receiving coils when one or more signals are received from the contactless card. Alternatively or additionally, in some example embodiments, the subject matter can be configured to use a radio frequency (RF) detector with the receiving coils for signal strength measurement purposes, which can be implemented in circuits such as diodes, capacitors, voltage dividers, etc. Furthermore, the current subject can also be configured to use data integrity interrogation techniques, which may rely on and / or use at least a portion of the signal bandwidth to detect and / or determine the presence of any missing information (e.g., missing bits) in the signal, such as by using a modified Manchester encoder and / or any other similar device. It is understood that any other type of sensor can be used to determine signal strength.
[0042] When analyzing signal strength, a computing device can be configured to identify the signal that may have the highest signal strength compared to other signals. Signal strength can be the strength of a signal that may have been generated / transmitted to and / or received from a contactless card. One or more processors of the computing device can be configured to perform comparisons of signal strength data that they may receive from receiving coils and / or any other sensors to sort the signal strengths from highest to lowest. Once sorted, the processors can determine which receiving coil corresponds to the highest signal strength and / or highest current being received by that coil. This can be achieved using one or more identifiers and / or any other data that may be included in the signals processed by one or more processors of the computing device for signal strength analysis.
[0043] When the signal with the highest strength and its corresponding receiving coil are identified, that receiving coil can be selected as the receiving coil for further communication with the contactless card. Other receiving coils can be deactivated (e.g., the processor can shut off the current supply from the computing device's power supply to them). The selected receiving coil can also be temporarily deactivated.
[0044] To establish communication with the contactless card, the selected receiving coil can be energized again (e.g., supplied with current). The computing device can then use the energized selected receiving coil to establish a communication link with the contactless card (e.g., via NFC) to activate the contactless card's chip, perform further data exchange, etc.
[0045] In some implementations, once communication is established between the computing device and the contactless card, the contactless card can be configured to transmit various data / information to the computing device via an NFC interface / switch. For example, the data / information may include at least one of the following: an account associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, any combination thereof, and / or any other data / information. Furthermore, the contactless card can be a credit card, debit card, electronic gift card, prepaid credit card, prepaid debit card, any combination thereof, and / or any other type of contactless card.
[0046] In some implementations, the computing device may be configured to simultaneously energize all of its receiving coils (e.g., supply current). Alternatively or additionally, the coils may be energized in a predetermined order (e.g., sequentially, etc.). Once energized, the coils may be configured to transmit and / or receive signals from the contactless card according to an energizing schedule (e.g., simultaneously, in a predetermined order, etc.).
[0047] In some implementations, the computing device can be configured to determine the location (e.g., proximity) of the contactless card relative to each receiving coil from which signals have been transmitted and / or received. For example, the proximity of the contactless card relative to each particular receiving coil can be determined based on the strength of the signal that may have been received from the contactless card; that is, the stronger the received signal received by a particular coil, the closer the contactless card is to that coil.
[0048] Using proximity data, a computing device can be configured to generate instructions (e.g., to a user communicating with the computing device using a contactless card) to reposition the contactless card closer to or closer to a specific receiving coil. This ensures that communication established between the computing device and the contactless card is not affected by weak signals and / or interrupted by weak signals.
[0049] In some implementations, the computing device can be configured to select an optimal location (from multiple locations) for the contactless card relative to the computing device, and the user can be prompted to position and / or reposition the contactless card to that optimal location. The selected optimal location can be determined based on the identification of the receiving coil of the computing device receiving the strongest signal and / or any other parameters. The selected location can instruct the contactless card to be close to a specific receiving coil while moving away from other receiving coils.
[0050] In some implementations, the computing device may include a graphical user interface (GUI). The selected optimal location (and / or any other location) may be displayed on the GUI. Furthermore, the GUI may display guidance instructions to the user to move the contactless card to the selected location. Once the location is reached, appropriate indications (e.g., checkmarks, etc.) may be displayed on the GUI, and / or any other alerts may be generated by the computing device.
[0051] Alternatively or additionally, mobile devices and / or any other devices (e.g., readers, etc.) configured to scan and / or read contactless cards may be configured to include a single receiving coil (e.g., a small-area coil) that can be used to scan contactless cards. The single coil can be energized to generate signals and / or send signals to the contactless card. As described above, the receiving coil can be energized by supplying current to the coil from the power supply of the computing device. The receiving coil can be used as a transceiver and can transmit to / receive from the contactless card. Near Field Communication (NFC) exchange and / or an interface may be used for signal exchange between the receiving coil and the contactless card. It is understood that any other means of providing communication between the contactless card and the computing device are possible.
[0052] In some example, non-limiting implementations, the contactless card can be configured to include and / or be subdivided into one or more "virtual" areas and / or squares, which may be arranged in a grid-like manner. This area can be used by a computing device to perform a scan of the card with a receiving coil to identify locations on the card that could lead to the strongest connection signal being established between the receiving coil and the computing device. For example, the identified locations on the card may correspond to receiving coils on the card that interact with receiving coils in the computing device when the contactless card is scanned by the computing device. The identified locations may be situated within a single area of the card and / or may span multiple areas.
[0053] Each area on a contactless card can have the same and / or different dimensions as another area on the card. The size and / or positioning of the areas on the contactless card can be predetermined using a computing device. For example, the computing device can be provided with the card dimensions, and one or more processors of the computing device can be configured to generate a virtual grid for the areas of the card. The virtual grid can then be used to guide the user to position the card's receiving coil close to the receiving coil of the computing device during card scanning.
[0054] In some implementations, the computing device can be configured to generate a virtual grid such that areas on the contactless card are uniformly distributed across the back and / or front of the card. The areas on the back of the card may and / or may not overlap with the areas on the front of the card. The computing device can generate a single grid for both sides of the card and / or separate grids for the back and front of the card. Scanning of the card can be performed using specific sides of the card and their corresponding virtual grids.
[0055] When scanning a card, the computing device can determine the card's position sensitivity for each and / or multiple areas in the grid. Position sensitivity can correspond to the signal strength between the card's receiving coil and the computing device's receiving coil, as determined based on the current response of the computing device's receiving coil. The stronger the signal, the higher the position sensitivity of a specific area on the card's grid. This may mean that the card's receiving coil is likely close to and / or located in an area with higher sensitivity. Based on this information, the computing device can instruct the user to move the card to an area with higher position sensitivity.
[0056] In some example, non-limiting implementations, the generated grid can be arranged in rows and columns. It is understood that any other arrangement of the grid is possible. For example, positional sensitivity can be determined for each column and / or each row (e.g., for the front and / or back of the card, respectively). In this case, the positional sensitivity can be determined as the corresponding average value for each column and each row. For example, assuming the card's grid has 3 rows and 5 columns, the positional sensitivity for each row can be determined as (1 / 5 + 1 / 5 + 2 / 5) / 3 = 0.2666…, and the positional sensitivity for each column can be determined as (0 + 1 / 3 + 1 / 3 + 2 / 3 + 0) / 5 = 0.2666…. It is understood that any other method of determining positional sensitivity can be used (e.g., using a weighted algorithm).
[0057] The position sensitivity value can be displayed on the graphical user interface (GUI) of the computing device, indicating to the user whether the card (and its coil and / or EMV module) is positioned close to the receiving coil of the computing device. Alternatively or additionally, the GUI of the computing device can display arrows and / or any other graphical indicators determined based on the position sensitivity value to guide the user in positioning and / or repositioning the card relative to the receiving coil of the computing device. Once the optimal position of the contactless card is achieved (e.g., which can be determined based on the highest position sensitivity value), the computing device can display appropriate indicators (e.g., checkmarks, etc.) on the GUI, generate an audible alarm, display a message, and / or provide any other indication that the optimal position of the card has been achieved.
[0058] Figure 1A An exemplary system 100 for determining the readability of a contactless card in various computing environments is illustrated according to some embodiments of this subject matter. System 100 may include computing and / or a first computing device 102 and computing and / or a second computing device 104. Computing device 102 may be a contactless card, such as, for example, in conjunction with... Figures 6-15 The contactless card shown and described. Alternatively or additionally, computing device 102 may be a mobile device (e.g., a smartphone, mobile phone, tablet, etc.). Computing device 104 may be a mobile device, point-of-sale device, fixed computing device, automatic teller machine (ATM), and / or any other type of computing device. Computing device 104 may be configured to be coupled to various other computing devices, servers, etc. Figure 1A (Not shown in the image).
[0059] In some implementations, one or more components of system 100 may include any combination of hardware and / or software. One or more components of system 100 may be located on one or more computing devices, such as servers, databases, personal computers, laptops, cellular phones, smartphones, tablets, virtual reality devices, and / or any other computing devices and / or any combination thereof. In some example implementations, one or more components of system 100 may be located on a single computing device and / or may be part of a single communications network. Alternatively, these services may be located separately from each other. A service may be a computing processor, memory, software function, routine, procedure, call, and / or any combination thereof, configured to perform specific functions associated with the current topic's lifecycle orchestration service.
[0060] In some implementations, one or more components of system 100 may include a network-enabled computer. As described herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, network equipment, personal computers, workstations, telephones, smartphones, handheld PCs, personal digital assistants, thin clients, thick clients, internet browsers, or other devices. One or more components of system 100 may also be mobile computing devices, such as iPhones, iPods, iPads from Apple, and / or devices running Apple's operating system. Any other suitable device running Microsoft's operating system. Any device running Google's mobile operating system Any device with an operating system, and / or any other suitable mobile computing device, such as a smartphone, tablet, or similar wearable mobile device.
[0061] One or more components of system 100 may include a processor and memory, and it is understood that the processing circuitry may include additional components necessary to perform the functions described herein, including a processor, memory, error checkers and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware. One or more components of system 100 may also include one or more displays and / or one or more input devices. Displays may be any type of device for presenting visual information, such as computer monitors, flat panel displays, and mobile device screens, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device available and supported by the user equipment for inputting information, such as touchscreens, keyboards, mice, cursor control devices, microphones, digital cameras, video recorders, or camcorders. These devices may be used for inputting information and interacting with the software and other devices described herein.
[0062] In some example implementations, one or more components of system 100 may execute one or more applications (such as software applications) that enable, for example, network communication with one or more components of system 100 and the transmission and / or reception of data.
[0063] One or more components of system 100 may include one or more servers and / or communicate with one or more servers via one or more networks, and may operate as a corresponding pair of front-end and back-end with one or more servers. One or more components of system 100 may, for example, transmit from a mobile device application (e.g., executing on one or more user devices, components, etc.) to one or more servers (…). Figure 1A(Not shown) One or more requests are transmitted. These requests may be associated with retrieving data from a server. The server may receive requests from components of system 100. Based on the request, the server may be configured to retrieve the requested data from one or more databases. Based on the requested data received from the databases, the server may be configured to transmit the received data to one or more components of system 100, wherein the received data may be in response to one or more requests.
[0064] System 100 may include one or more networks, such as computing devices 102 and / or 104 which may be configured to connect to. In some embodiments, the network may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect components of system 100 and / or connect components of system 100 to one or more servers. For example, a network may include one or more of the following: fiber optic network, passive optical network, cable network, Internet network, satellite network, wireless local area network (LAN), metropolitan area network (MAN), wide area network (WAN), virtual local area network (VLAN), extranet, intranet, Global System for Mobile Communications (GSMA), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiple access based system, code division multiple access based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi and / or any other type of network and / or any combination thereof.
[0065] Furthermore, the network may include, but is not limited to, telephone lines, fiber optics, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Further, the network may support Internet networks, wireless communication networks, or cellular networks, or any combination thereof. The network may further include one network or any number of the aforementioned exemplary network types, operating as independent networks or cooperating with each other. The network may utilize one or more protocols of one or more network elements to which they are communicatively coupled. The network may be able to convert between other protocols and one or more protocols of the network devices. The network may include multiple interconnected networks, such as, for example, the Internet, service provider networks, cable television networks, corporate networks (such as credit card association networks), and home networks.
[0066] System 100 may include one or more servers, which may include one or more processors coupled to memory. The servers may be configured as a central system, server, or platform to control and invoke various data at different times to perform multiple workflow actions. The servers may be configured to connect to one or more databases. The servers may be incorporated into and / or communicatively coupled to at least one component of system 100.
[0067] One or more components of system 100 may be configured to use one or more containers to execute one or more transactions. In some implementations, each transaction may be executed using its own container. A container may refer to a standard software unit that may be configured to include the code required to perform the action and all its dependencies. This allows the execution of the action to proceed quickly and reliably.
[0068] like Figure 1A As shown, computing device 104 may include an array of receiving coils 110, which may include one or more receiving coils 106 (a, b, c), a processor 108, and optional storage location 112. The coils 106 can be configured to be arranged within the array 110 in any desired manner. For example, as Figure 1A As shown, coil 106 can be arranged in a circular, random and / or any other desired manner as one or more columns, one or more rows.
[0069] Coil 106 can be coupled to one or more circuits ( Figure 1A (not shown in the image) and / or power supply ( Figure 1A(Not shown in the diagram), and / or as part of one or more circuits and / or power supplies, which may be configured to supply current to coil 106 and / or detect signals that can be received by coil 106. Coil 106 may be configured to transmit one or more signals to device 102. Furthermore, coil 106 may also be used to receive one or more signals from device 102. In some embodiments, device 104 may be configured to determine the signal strength of any signals transmitted to and / or received from device 102. For example, device 104 may be configured to measure: the current that may be supplied to each coil 106 to generate a signal for transmission to device 102, and / or the current generated by each coil 106 as a result, such as receiving one or more signals from device 102. It is understood that any other measurements and / or signal sensing may be performed for the purpose of determining signal strength. Data associated with such measurements / sensing may be provided to processor 108. Processor 108 may then determine the signal strength associated with each signal that may be transmitted / received by each coil 106. The processor 108 can then use the signal strength data to sort the signal strengths from highest to lowest (and / or vice versa). This sorting of signal strengths can be used to determine which of the coils 106 can transmit and / or receive signals at the highest strength, and thus for further communication with the device 102.
[0070] Using sorted signal strength data, processor 108 can be configured to determine that a particular coil 106 (e.g., coil 106a) can transmit and / or receive signals at the highest strength. After such determination, processor 108 can select coil 106a for further communication with device 102. For this purpose, for example, processor 108 can temporarily de-energize coil 106a (e.g., stop supplying current to it) and also de-energize other coils 106b and 106c, and then only energize coil 106a while keeping coils 106b and 106c de-energized. The energized coil 106a can then be used to establish communication with device 102.
[0071] Furthermore, device 104 can be configured to determine the proximity of device 102 to each coil 106 (e.g., how far device 102 is from each of the coils) based on the determined signal strength. This allows device 104 to make and / or refine the selection of specific coils 106 for further communication. Additionally, the position of device 102 relative to each coil 106 may help determine the motion sensitivity of device 102 with respect to each coil 106. This further enables device 102 to be positioned close to a specific coil 106 that can transmit / receive the strongest signal and / or provide more reliable communication.
[0072] In some example implementations, when processor 108 selects coil 106a for further communication with device 102, the user of device 102 may be prompted to position and / or reposition device 102 closer to coil 106a. For example, device 104 may be configured to include a graphical user interface (GUI). Figure 1A (Not shown in the image), the graphical user interface can display to the user of device 102 one or more instructions on how to position / reposition device 102 to be close to coil 106a and / or within a predetermined distance / area of coil 106a. Upon determining that device 102 is within the predetermined distance / area of coil 106a, device 104 can be configured to display appropriate indications to the user of device 102, indicating that device 102 is within that distance / area of coil 106a and is ready for communication.
[0073] Processor 108 can be configured to determine whether device 102 is located within a predetermined distance / area of coil 106a. For example, processor 108 can make this determination using data related to the signal strength transmitted / received between device 102 and coil 106a. For instance, if the measured signal strength is within a predetermined threshold, processor 108 can be configured to determine that device 102 has been located within the predetermined distance / area of coil 106a. Otherwise, processor 108 can cause the generation of one or more instructions to be displayed on a graphical user interface to alert user 102 to reposition device 102. The alert may include one or more instructions on how to reposition device 102. The instructions may be based on location information determined using signal strength data related to the transmitted / received signals between device 102 and coil 106a. For example, if device 102 is farther away from coil 106a, any signals transmitted / received between device 102 and coil 106a may be weaker than when device 102 is closer to coil 106a, and therefore processor 108 can determine that device 102 needs to be moved closer to coil 106a and generate an instruction to the user accordingly.
[0074] Once device 102 is positioned within a predetermined distance / area of the selected coil 106 (e.g., coil 106a), devices 102 and 104 can be configured to establish a communication link, such as a near field communication (NFC) exchange link, using the activated coil 106a. The other coils 106 of device 104 will remain deactivated to avoid interfering with the communication provided by the selected coil 106a.
[0075] As part of the NFC exchange link, device 104 can act as an "active" component and power device 102, which can be considered a "passive" component. Furthermore, devices 102 and / or 104 can be securely linked to accounts at financial institutions, which may contain available funds (e.g., checking accounts, savings accounts, etc.). Access to any accounts that may be associated with devices 102 and / or 104 can be protected / secured using various authentication / authorization mechanisms (e.g., username and password, user biometrics, access codes, multi-factor authentication tokens, etc.).
[0076] As part of NFC exchange, when device 102 is detected to be within a predetermined distance / area of device 104 (e.g., coil 106a), device 104 can request various identification data from device 102 and / or be automatically provided with various identification data from device 102. This identification data may include various information identifying device 102 and / or the user of device 102. It may include one or more identifiers that can be used to identify device 102. Assuming device 102 is a contactless card, device 102 may also transmit various contactless card data to device 104. Contactless card data may include, for example, but not limited to, at least one of the following: an account associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, and any combination thereof. Device 104 can then transmit the received identification data to one or more servers that can be communicatively coupled to device 104. Figure 1A (not shown in the image) to allow for any further processing.
[0077] Figure 1B-1C An alternative system 126 for determining the readability of a contactless card in various computing environments is illustrated according to some embodiments of this subject matter. System 126 may include a computing and / or first computing device 120 and a computing and / or contactless card 114. The contactless card 114 may be, as in combination with... Figure 6-15 The contactless card shown and described. Computing device 120 can be a mobile device (e.g., a smartphone, mobile phone, tablet, etc.). Computing device 120 can be a mobile device, point-of-sale device, fixed computing device, automatic teller machine (ATM), and / or any other type of computing device. Computing device 120 can be configured to be coupled to various other computing devices, servers, etc. Figure 1B-1C(Not shown in the image). One or more components of system 126 may include any combination of hardware and / or software, and / or may be located on one or more computing devices, such as servers, databases, personal computers, laptops, cellular phones, smartphones, tablets, virtual reality devices, and / or any other computing devices and / or any combination thereof. Furthermore, one or more components of system 126 may be located on a single computing device and / or may be part of a single communications network. Alternatively or additionally, these services may be located separately from each other.
[0078] System 126 can be configured to guide a user to position the contactless card 114 near the computing device 120 to achieve the strongest signal connection between the contactless card 114 and the computing device 120. As described above, this can be achieved using a grid pattern on the contactless card 114, such as... Figure 1C As shown.
[0079] like Figure 1B As shown, computing device 120 may include a receiving coil 118, a processor 122, and an optional storage location 124. The coil 118 may be coupled to one or more circuits (…). Figure 1B (not shown in the image) and / or power supply ( Figure 1B (not shown), and / or may be part of one or more circuits and / or power supplies that can provide current to coil 118 and / or detect signals that can be received by coil 118 from contactless card 114. Figure 1B As shown, computing device 120 includes a single receiving coil 118, but it will be understood that more than one coil 118 may be incorporated into device 120.
[0080] Coil 118 can transmit and / or receive one or more signals to and / or from contactless card 114. Device 120 can determine the signal strength of these signals. For example, device 120 can measure the current that can be supplied to coil 118 to generate a signal for transmission to card 114, and / or the current generated by coil 118 as a result, such as receiving one or more signals from card 114. It is understood that any other measurements and / or signal sensing can be performed to determine the signal strength. Data associated with such measurements / sensing can be provided to processor 122, which can determine the signal strength associated with each signal that can be transmitted / received by coil 118. Processor 108 can use the signal strength data to sort the signal strengths from highest to lowest (and / or vice versa) and determine the location on card 114 where the strongest signal is triggered based on this sorting. This location can be determined based on the virtual grid subdivision (back and / or front) of card 114, for example, as Figure 1C As shown.
[0081] Using the transmitted / received signals, the processor 122 of device 120 can determine the proximity of card 114 to coil 118 (e.g., how far card 114 is from coil 118) based on the determined signal strength. The position of card 114 relative to coil 118 can be used to determine the positional sensitivity of card 114 relative to coil 118, which can then guide the user to position card 114 closer to coil 118 to ensure that a higher strength signal is being transmitted / received between card 114 and device 120, thereby providing more reliable communication.
[0082] Device 120 may include a graphical user interface (GUI) Figure 1B (Not shown in the image), the graphical user interface can display one or more instructions to the user of card 114 for positioning / repositioning card 114, bringing it closer to coil 118 and / or within a predetermined distance / area of coil 118. After determining that card 114 is within the predetermined distance / area of coil 118, device 120 can be configured to display appropriate indications to the user of card 114, namely: card 114 is within that distance / area of coil 118 and is ready for communication.
[0083] Processor 122 can use the virtual grid associated with card 114 to determine whether card 114 is positioned within a predetermined distance / area of coil 118 (e.g., as shown in the image). Figure 1C (As shown). In some example, non-limiting implementations, processor 122 may generate a virtual grid with one or more virtual areas and / or squares that can be associated with contactless card 114. Processor 122 may use these areas to scan card 114 using receiver coil 118 and identify locations on card 114 that could lead to the strongest connection signal being established between card 114 and computing device 120 by receiver coil 118.
[0084] like Figure 1C As shown, the grid may include one or more regions 132 (a, b, c, d) and 134 (a, d). It is understood that there can be any number of regions. Furthermore, although regions 132 and 134 are shown as rectangles or squares, it is understood that regions 132 and 134 can have any shape and size, and the grid can have any number of regions 132 and 134. Each region 132 and 134 on card 114 may have the same and / or different dimensions than another region 132 and 134. The dimensions and / or positioning of regions 132 and 134 may be predetermined and / or determined by processor 122. For example, processor 122 may determine the dimensions, number, position, etc., of regions 132 and 134 based on the dimensions of card 114 and / or any other parameters.
[0085] In some implementations, processor 122 can generate a virtual grid such that regions 132, 134 on card 114 are evenly distributed on the back and / or front of card 114. Regions 132, 134 on the back of card 114 may and / or may not overlap with regions on the front of card 114. Processor 122 can generate a single grid for both sides of the card and / or separate grids for the back and front of the card. Card scanning can be performed using specific sides of card 114 and corresponding virtual grids.
[0086] When scanning card 114, processor 122 can determine, based on signal strength (determined based on the current value of excitation coil 118), that regions 132 (a, b, c, d) produce the weakest signal and regions 134 (a, b) produce the strongest signal. Processor 122 can then determine that, given the weaker signal strength, region 132 of card 114 may not be suitable for providing the strongest communication link between card 114 and device 120. Alternatively, region 134, and particularly, for example, region 134a, can produce the strongest signal. Therefore, processor 122 can cause device 120 to generate a graphical user interface to guide the user in positioning card 114 so that region 134a is as close as possible to coil 118. For example, region 134a may correspond to a receiving coil or EMV module on card 114. It is understood that the location on card 114 identified by processor 122 as having the strongest signal can be set within a single region of card 114 and / or can span multiple regions (e.g., regions 134a and 134b).
[0087] Using the signal strength associated with each region 132, 134, the processor 122 can determine the card's position sensitivity for each region 132, 134 and / or multiple regions in the grid. The position sensitivity can correspond to the signal strength between the card's receiving coil and the coil 118 of the device 120, which can be determined using the current response of the coil 118 of the device 120. The stronger the signal, the higher the position sensitivity of a particular region (e.g., region 134a) on the grid of the card 114. A higher position sensitivity value can indicate that the receiving coil of the card 114 is close to and / or located in a region with higher position sensitivity. Based on this information, the user can be instructed via the graphical user interface of the device 120 to move the card 114 to a region with a higher position sensitivity value (e.g., region 134a).
[0088] like Figure 1CAs shown, the grid can be arranged in rows and columns. For example, one column can have regions 134a, 134b, 132d; another column can have region 132a; and so on. Furthermore, one row can have regions 134a, 132a, 132b; another row can have regions 134b, 132c; and so on. It is understood that any other arrangement of the grid is possible. For example, position sensitivity values can be determined for each column and / or each row (e.g., for the front and / or back of the card, respectively). For example, the position sensitivity values can be determined as the corresponding average values for each column and each row. For example, assuming the card's grid has 3 rows and 5 columns, the position sensitivity for each row can be determined as (1 / 5 + 1 / 5 + 2 / 5) / 3 = 0.2666…, and the position sensitivity for each column can be determined as (0 + 1 / 3 + 1 / 3 + 2 / 3 + 0) / 5 = 0.2666…. It is understood that any other method of determining position sensitivity can be used (e.g., using a weighted algorithm).
[0089] As described above, the position sensitivity value can be displayed on the graphical user interface (GUI) of device 120 and can indicate to the user whether the user is positioning card 114 (and its coil and / or EMV module) close to coil 118 of device 120. Alternatively or additionally, the GUI of device 120 can display arrows and / or any other graphical indicators determined based on the position sensitivity value to guide the user in positioning and / or repositioning card 114 relative to coil 118 of device 120. Once the optimal position of card 114 is achieved (e.g., area 134a of card 114 is close to coil 118) (e.g., using the highest position sensitivity value), device 120 can display appropriate indicators (e.g., checkmarks, etc.) on its GUI, generate an audible alarm, display a message, and / or provide any other indication that the optimal position of the card has been achieved.
[0090] Once this optimal location of card 114 is achieved, a communication link, such as an NFC exchange link, can be established between card 114 and device 120. As part of the NFC exchange, card 114 and device 120 can exchange various identification data. Identification data may include various information identifying device 120 and / or its user, one or more identifiers that can be used to identify card 114, contactless card data 114, and / or any other data. As mentioned above, contactless card data may include, for example, but not limited to, at least one of the following: the account number associated with the card, the expiration date associated with the card, the card verification value (CVV) associated with the card, the billing address associated with the card, the user name associated with the card, and any combination thereof. Device 120 can then process the data and / or transmit it to one or more servers ( Figure 1A (not shown in the image) for further processing.
[0091] Figure 2 Exemplary process 200 for improving readability of contactless cards and / or any other mobile device, according to some embodiments of this subject matter, is illustrated. Process 200 can be provided by... Figure 1A The process 200 can be performed using system 100 and / or any other system shown. For example, process 200 can be performed using device 102 (e.g., a contactless card, another mobile device, etc.) and device 104 (e.g., a mobile device, a fixed device, an ATM, etc.).
[0092] At 202, device 104 can be configured to receive one or more signals from a first device (e.g., device 102). Each signal can be in response to one or more transmissions generated and transmitted by the first device 104 through each of a plurality of receiving coils (e.g., coils 106 (a, b, c)). The generation and / or transmission of signals through coil 106 can be performed when such coil 106 is energized. As described above, the energization of the coil can be performed by supplying current to coil 106 from a power source (e.g., a battery, AC current source, DC current source, etc.). Each receiving coil 106 can be communicatively coupled to one or more processors (e.g., such as...). Figure 1A The processor 108 shown is shown.
[0093] In some embodiments, the receiving coils of device 104 (e.g., all coils 106) can be energized simultaneously. Once energized, each receiving coil can be configured to generate a corresponding transmission and send it to device 102. In alternative embodiments, the receiving coils 106 can be energized in a predetermined order (e.g., coil 106a can be energized first, coil 106b second, coil 106c third, etc.). In this respect, each such receiving coil, once energized, can be configured to generate a corresponding transmission and send it to device 102 using this predetermined order.
[0094] In some implementations, such as Figure 1A As shown, coils 106 can be arranged in an array (e.g., array 110). Furthermore, coils can be positioned in device 104 using a predetermined pattern and / or arrangement. Device 104 can be configured to include any number of receiving coils 106.
[0095] At 204, device 104 can be configured to determine the signal strength of each signal received from the first device. The signal strength determination can be based on a measurement of the current at each receiving coil 106. The current measurement can be implemented using one or more sensors, sensor circuitry, and / or any other components of device 104. The measured current data can be provided to processor 108 to evaluate the strength of each signal received and / or transmitted by each coil 106. Processor 108 can also sort the determined signal strengths from highest to lowest, while tracking which coil 106 is associated with which signal strength.
[0096] At 206, processor 108 can be configured to identify a first signal with the highest signal strength based on the signal strength of one or more determined signals, and select at 208 a first receiving coil 106 (e.g., coil 106a) that can correspond to the first signal. The selection of a specific coil 106 can be performed for the purpose of establishing communication between device 102 and device 104 using the selected coil.
[0097] Once a specific receiving coil has been identified, at 210, all coils can be de-energized. For example, de-energizing a receiving coil might involve, for instance, blocking the supply of current from a current source to the coil. Alternatively or additionally, the selected receiving coil may remain energized, while the other coils 106 can be de-energized. However, in a further alternative embodiment, the unselected coils 106 may remain energized but not used for further signal transmission and / or reception. Furthermore, to prevent interference from the unselected receiving coils 106, one or more filters can be used to block and / or filter out signals from these unselected coils.
[0098] At 212, processor 108 can be configured to energize a selected first receiving coil (e.g., turn on a current supply from a current source). Energizing the selected coil allows the coil to transmit signals to and / or receive signals from device 102. The energized coil can be used to establish communication with device 102.
[0099] In some implementations, communication can be established via Near Field Communication (NFC) exchange and / or interface. It is understood that any other type of communication can be established between devices 102 and 104 (e.g., a contactless card and a mobile device, a mobile device and another mobile device, etc.). Once communication is established, the first device, such as device 102, such as a contactless card, can send various data, such as contactless card data, to device 104. This contactless card data may include at least one of the following: the account associated with the contactless card, the expiration date associated with the contactless card, the card verification value (CVV) associated with the contactless card, the billing address associated with the contactless card, the user name associated with the contactless card, and any combination thereof. Furthermore, in non-limiting implementations of the contactless card, such a card may be, for example, at least one of the following: a credit card, a debit card, an electronic gift card, a prepaid credit card, a prepaid debit card, and any combination thereof.
[0100] In some implementations, as described above, the signal strength determined by device 104 can be used to determine one or more locations of device 102 relative to each receiving coil 106. For example, the stronger the signal, the closer device 102 may be to a particular receiving coil 106; and conversely, the weaker the signal, the farther device 102 may be from a particular coil 106. Furthermore, a specific location of device 102 (e.g., a first location) can be selected based on the determined distance from each coil 106. The selected location can be configured to correspond to device 102 being close to the receiving coil 106 that has been selected to correspond to the highest signal strength. Additionally, this location can also correspond to device 102 being far from the remaining receiving coils 106.
[0101] Furthermore, as described above, the current topic can be configured to generate instructions (e.g., to the user of device 102) to locate and / or reposition device 102 based on a selected location. These instructions can be displayed on a graphical user interface, which can be part of device 102.
[0102] Figure 3 Another exemplary process 300 for improving the readability of contactless cards and / or any other mobile device, according to some embodiments of this subject matter, is illustrated. Similar to process 200, process 300 may also be... Figure 1A The system 100 shown and / or any other system, such as using device 102 (e.g., contactless card, another mobile device, etc.) and device 104 (e.g., mobile device, fixed device, ATM, etc.) to perform.
[0103] At 302, the processor 108 of device 104 can be configured to determine one or more positions of the first device (e.g., device 102) relative to each of the plurality of receiving coils 106 of device 104.
[0104] Figure 4 Some embodiments of this subject matter are shown for making contactless cards (e.g., such as...). Figure 1A The device 102 shown and / or such as Figure 1B An exemplary process 400 for determining the position of the contactless card 114 shown. At 402, as... Figure 1A The device 104 shown and / or such as Figure 1B The illustrated device 120 can be configured to receive one or more signals from device 102 and / or card 114, respectively. The signals can be responded to by a corresponding receiving coil 106 (e.g., Figure 1A (as shown) and / or receiving coil 118 (as shown) Figure 1B (As shown) One or more transmissions are generated and sent to device 102 and / or device 120, wherein the coil may have been energized for such generation / transmission. Alternatively or additionally, signals may be transmitted to device 102 and / or card 114 respectively.
[0105] At 404, the processor 108 of device 104 and / or the processor 122 of device 120 can be configured to determine the signal strength of the received signal. Alternatively or additionally, processors 108 and / or 122 can be configured to make such a determination based on signals transmitted to device 102 and / or card 114, respectively. The signal strength can be determined based on currents measured at one or more receiving coils 106 of device 104 and / or coil 118 of device 120, respectively. At 406, the determined signal strength can then be used to determine one or more locations of device 102 relative to device 104, and in particular, one or more locations of each coil 106, and / or alternatively, one or more locations of card 114 relative to device 120, and specifically, one or more locations of its coil 118. Figure 1B and Figure 1C As shown, the signal strength, and therefore the position sensitivity value associated with card 114, can be determined using a virtual grid with one or more regions 132, 134, such as... Figure 1C As shown.
[0106] Return to reference Figure 3 At 304, the processor 108 can be configured to identify the signal with the highest signal strength among the determined signal strengths. The determination of the highest signal strength can be based on current measurements and / or detections at each of the receiving coils 106. Higher current values can correspond to higher signal strengths.
[0107] At 306, processor 108 can be configured to select a specific receiving coil (e.g., a first coil) 106 (e.g., 106a) that corresponds to the signal with the highest signal strength. Processor 108 can then determine the location of device 102, which may correspond to the one closest to the selected receiving coil. Using this information, processor 108 can generate an instruction (e.g., to a user) to reposition device 102 to the determined location.
[0108] Figure 5 Another exemplary process 500 for improving the readability of contactless cards and / or any other mobile device, according to some embodiments of this subject matter, is shown. Similar to... Figure 2-4 The process described above, Figure 1A The system 100 and / or any other system shown can be configured to execute process 500. For example... Figure 1A As shown, process 500 may involve devices 102 (e.g., a contactless card, another mobile device, etc.) and 104 (e.g., a mobile device, a fixed device, an ATM, etc.).
[0109] At 502, device 104 may be configured to determine the signal strength of each of one or more signals received from device 102 (e.g., "first device"). Each of the signals may be in response to one or more transmissions generated by one or more receiving coils 106 and sent to device 102 when these coils are energized (e.g., supplied with current).
[0110] At point 504, device 104 can be configured to identify a first signal among the aforementioned signals that may have the highest signal strength. This determination can be based on the signal strength of each determined signal.
[0111] At 506, device 104 can be configured to select a specific receiving coil 106 (e.g., "first receiving coil") that corresponds to the identified signal, and then at 508 de-energize the plurality of receiving coils.
[0112] At 510, device 104 can be configured to energize only the selected receiving coil and establish communication with device 102 using the energized coil.
[0113] Figure 6 A data transmission system 600 according to an example embodiment is shown. As discussed further below, system 600 may include a contactless card 602, a client device 604, a network 606, and a server 608. Although Figure 6 A single instance of each component is shown, but system 600 may include any number of components.
[0114] System 600 may include one or more contactless cards 602, which are further explained below. In some embodiments, the contactless card 602 may communicate wirelessly with a client device 604 (e.g., using NFC).
[0115] System 600 may include client device 604, which may be a network-enabled computer. As mentioned herein, a network-enabled computer may include, but is not limited to, computer equipment or communication equipment, including, for example, servers, networked appliances, personal computers, workstations, telephones, handheld PCs, personal digital assistants, thin clients, thick clients, internet browsers, or other devices. Client device 604 may also be a mobile device; for example, a mobile device may include an iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.
[0116] Client device 604 may include a processor and memory, and it will be appreciated that the processing circuitry may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein. Client device 604 may also include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device available and supported by the user device for typing information into it, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or camcorder. These devices can be used to type information and interact with the software and other devices described herein.
[0117] In some examples, the client device 604 of system 600 may execute one or more applications, such as software applications, which enable, for example, network communication, transmission and / or reception of data with one or more components of system 600.
[0118] Client device 604 may communicate with one or more servers 608 via one or more networks 606 and may operate as a corresponding front-end to back-end pair with server 608. Client device 604 may, for example, transmit one or more requests to server 608 from a mobile device application running on client device 604. The one or more requests may be associated with retrieving data from server 608. Server 608 may receive one or more requests from client device 604. Based on the one or more requests from client device 604, server 608 may be configured to retrieve the requested data from one or more databases (not shown). Based on the received requested data from one or more databases, server 608 may be configured to transmit the received data to client device 604 in response to the one or more requests.
[0119] System 600 may include one or more networks 606. In some embodiments, network 606 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect client device 604 to server 608. For example, network 606 may include one or more of the following: fiber optic network, passive optical network, cable network, internetwork, satellite network, wireless local area network (LAN), Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 1302.11 networking family, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi and / or the like.
[0120] Additionally, network 606 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Furthermore, network 606 may support interconnected networks, wireless communication networks, cellular networks, or the like, or any combination thereof. Network 606 may also include a single network or any number of exemplary types of networks mentioned above, operating as independent networks or cooperatively with each other. Network 606 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 606 may translate other protocols into one or more protocols of network devices or from other protocols into one or more protocols of network devices. Although network 606 is depicted as a single network, it should be recognized that, according to one or more examples, network 606 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (e.g., a credit card association network), and a home network.
[0121] System 600 may include one or more servers 608. In some embodiments, server 608 may include one or more processors coupled to memory. Server 608 may be configured as a central system, server, or platform to control and invoke various data at different times to perform multiple workflow actions. Server 120 may be configured to connect to one or more databases. Server 608 may connect to at least one client device 604.
[0122] Figure 7 A data transmission system according to an example embodiment is illustrated. System 700 may include, for example, a transmitter or transmitting device 704, and a receiver or receiving device 708, communicating with one or more servers 702 via network 706. Devices 704, 708 may be similar to Figure 1A One or more devices 102, 104 are shown. Although Figure 7 A single instance of the components of system 700 is shown, but system 700 may include any number of the components shown.
[0123] When using symmetric cryptographic algorithms, such as encryption algorithms, hash-based message authentication codes (HMAC) algorithms, and ciphertext-based message authentication codes (CMAC) algorithms, it is important that the key remains secret between the party that initially processes the data protected using the symmetric algorithm and key and the party that receives and processes the data using the same cryptographic algorithm and the same key.
[0124] Importantly, the same key should not be used too many times. If a key is used or reused too frequently, it can become compromised. Each time a key is used, it provides an attacker with additional data samples that are processed by the cryptographic algorithm using the same key. The more data an attacker possesses that is processed using the same key, the greater the likelihood that the attacker can discover the key value. Frequently used keys can be included in a variety of different attacks.
[0125] Furthermore, each time a symmetric cryptographic algorithm is executed, it can reveal information about the key used during the symmetric cryptographic operation, such as side-channel data. Side-channel data can include minute power fluctuations that occur while the cryptographic algorithm is being executed using the key. Measurements can be made on the side-channel data sufficient to reveal enough information about the key, thus allowing an attacker to recover the key. Using the same key to exchange data will repeatedly reveal data processed by the same key.
[0126] However, by limiting the number of times a specific key will be used, the amount of side-channel data an attacker can collect is limited, thus reducing exposure and other types of attacks. As further described herein, in situations where any form of key exchange is required to maintain synchronization between parties, the parties involved in the exchange of cryptographic information (e.g., the sender and receiver) can independently generate keys from an initial shared master symmetric key combined with a counter value, thereby periodically replacing the shared symmetric key in use. By periodically changing the shared secret symmetric key used by the sender and receiver, the attacks described above become impossible.
[0127] Return to reference Figure 7 System 700 can be configured to implement key diversification. For example, the sender and receiver may expect to exchange data (e.g., raw sensitive data) via corresponding devices 704 and 708. As explained above, although a single instance of transmitting device 704 and receiving device 708 may be included, it will be appreciated that one or more transmitting devices 704 and one or more receiving devices 708 may be involved as long as each party shares the same shared secret symmetric key. In some embodiments, transmitting device 704 and receiving device 708 may be equipped with the same master symmetric key. Further, it will be appreciated that any party or device holding the same secret symmetric key can perform the function of transmitting device 704, and similarly, any party holding the same secret symmetric key can perform the function of receiving device 708. In some embodiments, the symmetric key may include a shared secret symmetric key that is kept secret from all parties except for the transmitting device 704 and receiving device 708 involved in exchanging secure data. It will also be recognized that both the transmitting device 704 and the receiving device 708 may be provided with the same master symmetric key, and it is further recognized that a portion of the data exchanged between the transmitting device 704 and the receiving device 708 includes at least a portion of data that may be referred to as a counter value. The counter value may include a number that changes each time data is exchanged between the transmitting device 704 and the receiving device 708.
[0128] System 700 may include one or more networks 706. In some embodiments, network 706 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect one or more transmitting devices 704 and one or more receiving devices 708 to server 702. For example, network 706 may include one or more of the following: fiber optic network, passive optical network, cable network, internetwork, satellite network, wireless LAN, Global System for Mobile Communications (GSMO), personal communication service, personal area network, wireless application protocol, multimedia messaging service, enhanced messaging service, short message service, time division multiplexing-based system, code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 1302.11 network family, Bluetooth, NFC, RFID, Wi-Fi and / or the like.
[0129] Furthermore, network 706 may include, but is not limited to, telephone lines, fiber optic cables, IEEE Ethernet 1402.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Additionally, network 706 may support interconnected networks, wireless communication networks, cellular networks, or the like, or any combination thereof. Network 706 may also include a single network or any number of exemplary types of networks mentioned above, operating as independent networks or cooperatively with each other. Network 706 may utilize one or more protocols of one or more network elements to which it is communicatively coupled. Network 706 may translate other protocols into one or more protocols of the network devices or from other protocols into one or more protocols of the network devices. Although network 706 is depicted as a single network, it should be recognized that, according to one or more examples, network 706 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network (such as a credit card association network), and a home network.
[0130] In some implementations, one or more transmitting devices 704 and one or more receiving devices 708 may be configured to communicate with each other and transmit and receive data without traversing the network 706. For example, communication between one or more transmitting devices 704 and one or more receiving devices 708 may occur via at least one of NFC, Bluetooth, RFID, Wi-Fi and / or the like.
[0131] At block 710, the sender may update the counter when the transmitting device 704 is preparing to process sensitive data using symmetric cryptography. Furthermore, the transmitting device 704 may select an appropriate symmetric cryptographic algorithm, which may include at least one of symmetric encryption algorithms, HMAC algorithms, and CMAC algorithms. In some embodiments, the symmetric algorithm used to process diverse values may include any symmetric cryptographic algorithm used to generate diverse symmetric keys of desired lengths as needed. Non-limiting examples of symmetric algorithms may include symmetric encryption algorithms such as 3DES or AES128; symmetric HMAC algorithms such as HMAC-SHA-256; and symmetric CMAC algorithms such as AES-CMAC. It will be appreciated that if the output of the selected symmetric algorithm does not generate a sufficiently long key, techniques such as processing the symmetric algorithm multiple times with different input data and the same master key may produce multiple outputs, which may be combined as needed to generate a sufficiently long key.
[0132] At block 712, the transmitting device 704 may employ a selected cryptographic algorithm and use a master symmetric key to process the counter value. For example, the sender may choose a symmetric encryption algorithm and use a counter that is updated with each conversation between the transmitting device 704 and the receiving device 708. The transmitting device 704 can then use the master symmetric key to encrypt the counter value using the selected symmetric encryption algorithm, thereby creating a diversified symmetric key.
[0133] In some implementations, the counter value may not be encrypted. In these examples, at block 712, the counter value may be transmitted between transmitting device 704 and receiving device 708 without encryption.
[0134] At block 714, a diversified symmetric key can be used to process sensitive data before sending the result to receiving device 708. For example, transmitting device 704 can encrypt sensitive data using a symmetric encryption algorithm (which uses a diversified symmetric key), where the output includes protected encrypted data. Transmitting device 704 can then transmit the protected encrypted data along with a counter value to receiving device 708 for processing.
[0135] At block 716, receiving device 708 may first take a counter value, and then use the counter value as input to encryption and the master symmetric key as the key for encryption to perform the same symmetric encryption. The output of the encryption may be the same diversified symmetric key value created by the sender.
[0136] At block 718, the receiving device 708 can then take the protected encrypted data and use a symmetric decryption algorithm and a variety of symmetric keys to decrypt the protected encrypted data.
[0137] At block 720, the original sensitive data can be revealed as a result of decrypting the protected encrypted data.
[0138] The next time sensitive data needs to be transmitted from the sender to the receiver via the corresponding transmitting device 704 and receiving device 708, different counter values can be selected to generate different diversified symmetric keys. By using the master symmetric key and processing the counter value with the same symmetric encryption algorithm, both the transmitting device 704 and the receiving device 708 can independently generate the same diversified symmetric key. This diversified symmetric key (instead of the master symmetric key) is used to protect the sensitive data.
[0139] As explained above, both the transmitting device 704 and the receiving device 708 initially possess a shared master symmetric key. This shared master symmetric key is not used to encrypt the original sensitive data. Because the diversification symmetric key is created independently by both the transmitting device 704 and the receiving device 708, it is never transmitted between them. Therefore, an attacker cannot intercept this diversification symmetric key, and an attacker will never see any data processed using the master symmetric key. Only counter values are processed using the master symmetric key, not sensitive data. As a result, reduced side-channel data regarding the master symmetric key is revealed. Furthermore, the operation of the transmitting device 704 and the receiving device 708 is governed by the following symmetric requirement: how often to create new diversification values and therefore new diversification symmetric keys. In one embodiment, new diversification values and therefore new diversification symmetric keys can be created for each exchange between the transmitting device 704 and the receiving device 708.
[0140] In some implementations, the key diversification value may include a counter value. Other non-limiting examples of the key diversification value include: a random nonce generated each time a new diversification key is needed; a random nonce sent from transmitting device 704 to receiving device 708; the full value of the counter value sent from transmitting device 704 and receiving device 708; a portion of the counter value sent from transmitting device 704 and receiving device 708; a counter maintained independently by transmitting device 704 and receiving device 708 but not sent between the two devices; a one-time password exchanged between transmitting device 704 and receiving device 708; and a cryptographic hash of sensitive data. In some implementations, one or more portions of the key diversification value may be used by the parties to create multiple diversification keys. For example, a counter may be used as the key diversification value. Further, combinations of one or more exemplary key diversification values described above may be used.
[0141] In another example, a portion of the counter can be used as a key diversification value. If multiple master key values are shared among the parties, multiple diversified key values can be obtained by the system and process described herein. New diversification values can be created frequently as needed, and thus new diversified symmetric keys can be created. In the most secure case, a new diversification value can be created for each exchange of sensitive data between transmitting device 704 and receiving device 708. In practice, this can create one-time-use keys, such as one-time-use session keys.
[0142] Figure 8 An example configuration of a contactless card 602 is shown, which may include a contactless card issued by a service provider, a payment card (such as a credit card, debit card, or gift card), as indicated by the service provider logo 802 displayed on the front or back of the contactless card 602. In some embodiments, the contactless card 602 is not a payment card and may include, but is not limited to, an identity card. In some embodiments, the transaction card may include a dual-interface contactless payment card, a rewards card, etc. The contactless card 602 may include a substrate 808, which may include a single layer or one or more laminates composed of plastics, metals, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some embodiments, the contactless card 602 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7816 standard, and the transaction card may otherwise conform to the ISO / IEC 14443 standard. However, it will be recognized that the contactless card 602 according to this disclosure may have different characteristics, and this disclosure does not require the transaction card to be implemented in a payment card.
[0143] The contactless card 602 may also include identification information 806 displayed on the front and / or back of the card, and a contact pad 804. The contact pad 804 may include one or more pads and is configured to establish contact with another client device (such as an ATM, user equipment, smartphone, laptop, desktop computer, or tablet computer) via the transaction card. The contact pad may be designed according to one or more standards (such as ISO / IEC 7816) and enable communication according to the EMV protocol. The contactless card 602 may also include a processing circuit system, an antenna, and other components, as will be... Figure 9 This will be discussed further. These components may be located behind the contact pad 804 or elsewhere on the substrate 808, such as within different layers of the substrate 808, and may be electronically and physically coupled to the contact pad 804. The contactless card 602 may also include a magnetic stripe or magnetic tape, which may be located on the back of the card. Figure 8(Not shown in the image). The contactless card 602 may also include an antenna-coupled near-field communication (NFC) device capable of communicating via the NFC protocol. Embodiments are not limited to this approach.
[0144] like Figure 2 As shown, the contact pad 804 of the contactless card 602 may include a processing circuitry 916 for storing, processing, and transmitting information. This processing circuitry includes a processor 902, a memory 904, and one or more interfaces 906. It will be appreciated that the processing circuitry 916 may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as required to perform the functions described herein.
[0145] Memory 904 can be a read-only memory, a write-once-read-many memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 602 may include one or more of these memories. Read-only memory can be programmed by the manufacturer to be read-only or programmable only once. One-time programmability provides the opportunity to write once and then read many times. Write-once / read-many memory can be programmed at some point after the memory chip has left the factory. Once programmed, the memory cannot be rewritten but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can also be read multiple times after leaving the factory. In some instances, memory 904 can be encrypted memory, which uses an encryption algorithm executed by processor 902 to encrypt data.
[0146] Memory 904 may be configured to store one or more applets 908, one or more counters 910, a customer identifier 914, and an account 912, which may be a virtual account. The one or more applets 908 may include one or more software applications, such as the Java Card applet, configured to execute on one or more contactless cards. However, it will be appreciated that applet 908 is not limited to the Java Card applet, but may be any software application operable on a contactless card or other device with limited memory. The one or more counters 910 may include numeric counters sufficient to store integers. The customer identifier 914 may include a unique alphanumeric identifier assigned to a user of the contactless card 602, and the identifier may distinguish the contactless card user from other contactless card users. In some embodiments, the customer identifier 914 may identify both the customer and the account assigned to that customer, and may also identify the contactless card 602 associated with the customer account. As previously described, the account 912 may include thousands of one-time-use virtual accounts associated with the contactless card 602. The applet 908 of the contactless card 602 can be configured to manage account 912 (e.g., to select account 912, mark the selected account 912 as used, and transmit account 912 to the mobile device for autofill service to autofill).
[0147] The processor 902 and memory elements of the foregoing exemplary embodiments are described with reference to contact pad 804, but this disclosure is not limited thereto. It will be appreciated that these elements may be implemented outside of or completely separated from contact pad 804, or implemented as additional elements besides the processor 902 and memory 904 elements located within contact pad 804.
[0148] In some embodiments, the contactless card 602 may include one or more antennas 918. The one or more antennas 918 may be placed within the contactless card 602 and around the processing circuitry system 916 of the contact pad 804. For example, the one or more antennas 918 may be integrated with the processing circuitry system 916, and the one or more antennas 918 may be used in conjunction with an external boost coil. As another example, the one or more antennas 918 may be externally located on the contact pad 804 and the processing circuitry system 916.
[0149] In an embodiment, the coil of the contactless card 602 can act as the secondary coil of an air-core transformer. The terminal can communicate with the contactless card 602 by cutting off power or by amplitude modulation. The contactless card 101 can infer data transmitted from the terminal using gaps in the power connection of the contactless card, which can be functionally maintained by one or more capacitors. The contactless card 602 can communicate in reverse by switching the load or load modulation on the contactless card coil. Load modulation can be detected in the terminal's coil by interference. More generally, using an antenna 918, a processor 902, and / or a memory 904, the contactless card 101 provides a communication interface for communication via NFC, Bluetooth, and / or Wi-Fi.
[0150] As explained above, the contactless card 602 can be built on a software platform operable on a smart card or other device with limited memory, such as a JavaCard, and one or more applications or applets can be securely executed. An applet 908 can be added to the contactless card to provide a one-time password (OTP) for multifactor authentication (MFA) in various mobile application-based use cases. The applet 908 can be configured to respond to one or more requests (such as near-field data exchange requests) from a reader (such as a mobile NFC reader, e.g., a mobile device or point-of-sale terminal) and generate an NDEF message that includes the password-secure OTP encoded as an NDEF text tag.
[0151] An example of NDEF OTP is the NDEF short record layout (SR=1). In such an example, one or more applets 908 can be configured to encode the OTP into a known NDEF type 4 text tag. In some implementations, an NDEF message may include one or more records. In addition to OTP records, applet 908 can be configured to add one or more static tag records.
[0152] In some implementations, one or more applets 908 may be configured to emulate an RFID tag. The RFID tag may include one or more polymorphic tags. In some implementations, different cipher data is presented each time the tag is read, and this data can indicate the reliability of the contactless card. Based on one or more applets 908, NFC readings of the tag can be processed, the data can be transmitted to a server, such as a banking system server, and the data can be verified at the server.
[0153] In some implementations, the contactless card 602 and the server may include data that allows the card to be correctly identified. The contactless card 602 may include one or more unique identifiers (not shown). A counter 910 may be configured to increment each time a read operation occurs. In some implementations, each time data is read from the contactless card 602 (e.g., by a mobile device), the counter 910 is sent to the server for verification, and it is determined whether the counter 910 is equal to (as part of the verification) the server's counter.
[0154] One or more counters 910 can be configured to prevent replay attacks. For example, if a password has been obtained and replayed, the password is immediately rejected if counter 910 has been read, used, or otherwise ignored. If counter 910 has not yet been used, it can be replayed. In some implementations, the counter incremented on the card is different from the counter incremented for a transaction. Contactless card 101 cannot determine the application transaction counter 910 because there is no communication between the applets 908 on contactless card 602.
[0155] In some implementations, counter 910 may lose synchronization. In some implementations, counter 910 may increment to handle unexpected reads that initiate a transaction, such as reads at an angle, but the application will not process counter 910. In some examples, NFC may be enabled when mobile device 110 is woken up, and mobile device 110 may be configured to read available tags, but will not take action in response to the read.
[0156] To keep counter 910 synchronized, an application, such as a background application, can be executed. This application would be configured to detect when mobile device 110 wakes up and synchronize with the bank's system server to indicate reads that have occurred due to the detection, then move counter 104 forward. In other examples, a hashed one-time password can be used to allow for out-of-sync windows. For example, if within a threshold of 10, counter 910 can be configured to move forward. However, if within a different threshold number, such as 10 or 1000, requests for resynchronization can be processed, which request the user to tap, gesture, or otherwise indicate once or multiple times via one or more applications. If counter 910 increments in the appropriate order, it becomes possible to know that the user has done so.
[0157] The key diversification technique described herein with reference to counter 910, master key, and diversification key is an example of encryption and / or decryption using key diversification techniques. This example key diversification technique should not be considered a limitation of this disclosure, as this disclosure is equally applicable to other types of key diversification techniques.
[0158] During the creation process of the contactless card 602, two cryptographic keys can be uniquely assigned to each card. These cryptographic keys may include a symmetric key, which can be used for both encryption and decryption of data. The Triple DES (3DES) algorithm can be used by EMV, and it is implemented by hardware within the contactless card 602. Through a key diversification process, one or more keys can be derived from the master key based on uniquely identifiable information for each entity requiring a key.
[0159] In some implementations, to overcome the vulnerability of the 3DES algorithm, session keys (such as a unique key for each session) can be derived instead of using the master key. The unique card-derived key and counter can be used for diversification. For example, each time the contactless card 101 is used in operation, a different key can be used to create a Message Authentication Code (MAC) and perform encryption. This results in three layers of encryption. Session keys can be generated by one or more applets and derived using an application transaction counter with one or more algorithms (as defined in EMV 4.3 Book 2 A1.3.1 Public Session Key Derivation).
[0160] Furthermore, the increment for each card can be unique and assigned algorithmically through personalized allocation or by some identifying information. For example, odd-numbered cards can increment by 2, and even-numbered cards can increment by 5. In some implementations, the increment can also vary in the order of reading, allowing a card to increment in a repeating sequence of 1, 3, 5, 2, 2, ... The specific order or algorithmic order can be defined during personalization or in one or more processes derived from the unique identifier. This makes it more difficult for a replay attacker to generalize from a small number of card instances.
[0161] The authentication message can be delivered as the content of a text NDEF record in hexadecimal ASCII format. In another example, the NDEF record can be encoded in hexadecimal format.
[0162] Figure 10 This is a timing diagram illustrating an example sequence for providing authenticated access according to one or more embodiments of the present disclosure. Sequence stream 1000 may include a contactless card 602 and a client device 604, which may include an application 1002 and a processor 1004.
[0163] At point 1008, application 1002 communicates with contactless card 602 (e.g., after being brought near contactless card 602). Communication between application 1002 and contactless card 602 may involve contactless card 602 being sufficiently close to a card reader (not shown) of client device 604 to enable NFC data transfer between application 1002 and contactless card 602.
[0164] At line 1006, after communication has been established between client device 604 and contactless card 602, contactless card 602 generates a Message Authentication Code (MAC) password. In some implementations, this may occur when contactless card 602 is read by application 1002. Specifically, this may occur during the reading of a near field data exchange (NDEF) tag (such as an NFC read), which may be created according to an NFC data exchange format. For example, a reader application (such as application 1002) may transmit a message with an app ID that generates the app via NDEF, such as an app selection message. When the selection is confirmed, a sequence of messages may be transmitted, followed by a file selection message. For example, the sequence may include "Select function file", "Read function file", and "Select NDEF file". At this time, a counter value held by contactless card 602 may be updated or incremented, which may be followed by "Read NDEF file". At this time, a message may be generated, which may include a header and a shared secret. A session key may then be generated. A MAC cipher can be created from the message, which may include a header and a shared secret. The MAC cipher can then be concatenated with one or more blocks of random data, and the MAC cipher and random number (RND) can be encrypted using a session key. After this, the cipher and header can be concatenated, encoded as ASCII hexadecimal, and returned in NDEF message format (in response to a "Read NDEF file" message).
[0165] In some implementations, the MAC cipher may be transmitted as an NDEF tag, and in other examples, the MAC cipher may be included with a Uniform Resource Indicator (e.g., as a format string). In some implementations, application 1002 may be configured to transmit a request to contactless card 602 that includes instructions for generating a MAC cipher.
[0166] At line 1010, contactless card 602 sends the MAC password to application 1002. In some embodiments, the transmission of the MAC password occurs via NFC; however, this disclosure is not limited thereto. In other examples, such communication may occur via Bluetooth, Wi-Fi, or other wireless data communication means. At line 1012, application 1002 transmits the MAC password to processor 1004.
[0167] At line 1014, processor 1004 verifies the MAC password according to instructions from application 122. For example, the MAC password can be verified as explained below. In some implementations, MAC password verification can be performed by a device other than client device 604 (such as a server of a banking system that communicates data with client device 604). For example, processor 1004 can output the MAC password for transmission to a server of the banking system, which can verify the MAC password. In some implementations, the MAC password can serve as a digital signature for verification purposes. Other digital signature algorithms, such as public-key asymmetric algorithms (e.g., digital signature algorithms and RSA algorithms) or zero-knowledge protocols, can be used to perform this verification.
[0168] Figure 11 A short record layout (SR=1) data structure 1100 for NDEF according to an example embodiment is shown. One or more applets can be configured to encode OTP into text tags of a known type 4 for NDEF. In some implementations, an NDEF message may include one or more records. The applet can be configured to add one or more static tag records in addition to the OTP record. Exemplary tags include, but are not limited to, tag type: known type, text, encoding English (en); applet ID: D2760000850101; function: read-only access; encoding: the authentication message may be encoded as ASCII hexadecimal; type-length-value (TLV) data may be provided as a personalized parameter that can be used to generate the NDEF message. In an embodiment, the authentication template may include a first record having a known index for providing actual dynamic authentication data.
[0169] Figure 12 A diagram of a system 1200 configured to implement one or more embodiments of the present disclosure is shown. As explained below, during the contactless card creation process, two cryptographic keys can be uniquely assigned to each card. The cryptographic keys may include symmetric keys that can be used for both encryption and decryption of data. The Triple DES (3DES) algorithm can be used by EMV, and it is implemented by hardware in the contactless card. By using a key diversification process, one or more keys can be derived from the master key based on uniquely identifiable information for each entity that requires a key.
[0170] Regarding master key management, the two issuer master keys 1202 and 1226 may be needed for each part of a product family that distributes one or more applets. For example, the first master key 1202 may include an issuer password generation / authentication key (Iss-Key-Auth), and the second master key 1226 may include an issuer data encryption key (Iss-Key-DEK). As further explained herein, the two issuer master keys 1202 and 1226 are diversified into card master keys 1208 and 1220, which are unique to each card. In some implementations, the Network Profile Record ID (pNPR) 522 and Derived Key Index (pDKI) 1224, which are background data, can be used to identify which issuer master keys 1202 and 1226 will be used in the cryptographic process for authentication. The system performing authentication can be configured to retrieve the values of pNPR 1222 and pDKI 1224 for contactless cards during authentication.
[0171] In some implementations, to improve the security of the solution, session keys (such as a unique key for each session) can be derived. However, instead of using a master key, it is better to use a unique card-derived key and counter as diversifying data, as explained above. For example, each time the card is used in operation, a different key can be used to create a Message Authentication Code (MAC) and perform encryption. Regarding session key generation, the key used to generate passwords and encrypt data in one or more applets may include session keys based on the card's unique key (Card-Key-Auth 1208 and Card-Key-Dek 1220). Session keys (Aut-Session-Key 1232 and DEK-Session-Key 1210) can be generated by one or more applets and derived using an Application Transaction Counter (pATC) 1204 and one or more algorithms. To fit the data into one or more algorithms, only the two lower-order bytes of the 4-byte pATC 1204 are used. In some implementations, the four-byte session key derivation method may include: F1:= PATC (lower 2 bytes) || 'F0' || '00' || PATC (4 bytes) F1:= PATC (lower 2 bytes) || '0F' || '00' || PATC (4 bytes) SK:={(ALG (MK) [F1]) || ALG (MK) [F2]}, where ALG may include 3DES ECB and MK may include the card-uniquely derived master key.
[0172] As described herein, one or more MAC session keys can be derived using the lower two bytes of the pATC 1204 counter. On each tap of the contactless card, the pATC 1204 is configured to be updated, and the card master keys Card-Key-AUTH 508 and Card-Key-DEK 1220 are further diversified into session keys Aut-Session-Key 1232 and DEK-Session-KEY 1210. The pATC 1204 can be initialized to zero during personalization or applet initialization. In some implementations, the pATC counter 1204 can be initialized during or before personalization and can be configured to increment by 1 on each NDEF read.
[0173] Furthermore, updates for each card can be unique and assigned through personalization or algorithmically via pUID or other identifying information. For example, odd-numbered cards can increment or decrement by 2, and even-numbered cards can increment or decrement by 5. In some implementations, updates can also vary in the order of reading, allowing a card to increment in a repeating sequence of 1, 3, 5, 2, 2, ... The specific order or algorithmic order can be defined during personalization or in one or more processes derived from the unique identifier. This makes it more difficult for a replay attacker to generalize from a small number of card instances.
[0174] The authentication message can be delivered as the content of a text NDEF record in hexadecimal ASCII format. In some implementations, it may consist only of authentication data, an 8-byte random number, and a MAC (Authentication Code) immediately following the authentication data. In some implementations, the random number may precede the password A and can be a block length. In other examples, there may be no restriction on the length of the random number. In further examples, the total data (i.e., the random number plus the password) may be a multiple of the block size. In these examples, an additional 8-byte block may be added to match the block generated by the MAC algorithm. For example, if the algorithm used employs a 16-byte block, an even multiple of the block size may be used, or the output may be automatically or manually padded to a multiple of the block size.
[0175] MAC can be performed using the function key (AUT-Session-Key) 1232. The data specified in the cipher can be processed using the javacard.signature method: ALG_DES_MAC8_ISO9797_1_M2_ALG3 to be associated with the EMV ARQC authentication method. The key used for this calculation may include the session key AUT-Session-Key 1232, as explained above. As explained above, the lower two bytes of the counter can be used to diversify one or more MAC session keys. As explained below, AUT-Session-Key 1232 can be used for MAC data 1206, and the resulting data or cipher A 1214 and random number RND can be encrypted using DEK-Session-Key 1210 to create cipher B or output 1218 sent in the message.
[0176] In some implementations, one or more HSM commands may be processed for decryption, such that the final 16 bytes (binary, 32-bit hexadecimal) may include the result of 3DES symmetric encryption of a random number and subsequent MAC authentication data using CBC mode and zero IV. The key used for this encryption may include a session key DEK-Session-Key 1210 derived from Card-Key-DEK 1220. In this case, the ATC value used for deriving the session key is the least significant byte of the counter pATC 1204.
[0177] The following format represents an example embodiment of the binary version. Further, in some implementations, the first byte may be set to ASCII 'A'.
[0178]
[0179]
[0180] Another exemplary format is shown below. In this example, the label can be encoded in hexadecimal format.
[0181]
[0182]
[0183] The UID field of the received message can be extracted to derive the card master key (Card-Key-Auth 1208 and Card-Key-DEK 1220) for that specific card from the master keys Iss-Key-AUTH 502 and Iss-Key-DEK 1226. Using the card master key (Card-Key-Auth 508 and Card-Key-DEK 1220), the counter (pATC) field of the received message can be used to derive the session key (Aut-Session-Key 1232 and DEK-Session-Key 1210) for that specific card. Password B 1218 can be decrypted using DEK-Session-KEY, which produces password A 1214 and RND, and the RND can be discarded. The UID field can be used to look up the shared secret of the contactless card. This secret, along with the message version, UID, and pATC fields, can be processed using a recreated Aut-Session-Key via a MAC password to create a MAC output, such as 'MAC'. If 'MAC' matches the PIN A 1214, this indicates that both message decryption and the MAC check have passed. The pATC can then be read to determine its validity.
[0184] During the authentication session, one or more passwords may be generated by one or more applications. For example, one or more passwords may be generated as a 3DES MAC using ISO9797-1 algorithm 3 with method 2 padding via one or more session keys (such as Aut-Session-Key 1232). Input data 1206 may take the form of: version (2), pUID (8), pATC (4), shared secret (4). In some implementations, the numbers in parentheses may include a length in bytes. In some implementations, the shared secret may be generated by one or more random number generators that may be configured to ensure that the random numbers are unpredictable through one or more security processes. In some implementations, the shared secret may include a random 4-byte binary number injected into the card at a personalized time known to the authentication service. During the authentication session, the shared secret may not be provided to the mobile application from one or more applets. Method 2 padding may include adding a mandatory 0x'80' byte to the end of the input data, and adding 0x'00' bytes that may be added to the end of the resulting data up to an 8-byte boundary. The resulting password may include 8 bytes in length.
[0185] In some implementations, one advantage of encrypting an unshared random number as the first block along with the MAC cipher is that it acts as an initialization vector when using the CBC (Block Chaining) mode of a symmetric encryption algorithm. This allows for block-to-block "scrambling" without the need to pre-establish fixed or dynamic IVs.
[0186] By including the Application Transaction Counter (pATC) as part of the data included in the MAC cipher, the authentication service can be configured to determine whether the value conveyed in the plaintext data has been tampered with. Furthermore, by including the version in one or more ciphers, it is difficult for an attacker to intentionally distort the application version to attempt to weaken the strength of the cipher solution. In some implementations, the pATC can start from zero and be updated to 1 each time one or more applications generate authentication data. The authentication service can be configured to track the pATC used during the authentication session. In some implementations, when the authentication data uses a pATC equal to or less than a previous value received by the authentication service, this can be interpreted as an attempt to replay an old message, and the authenticated message can be rejected. In some implementations, when the pATC is greater than a previously received value, this can be estimated to determine whether it is within an acceptable range or threshold, and if it exceeds the range or threshold or is outside of it, the verification can be considered a failure or unreliable. In MAC operation 1212, data 1206 is processed via MAC using the Aut-Session-Key 1232 to produce an encrypted MAC output (cipher A) 1214.
[0187] To provide additional protection against brute-force attacks on the exposed key, MAC cipher 1214 is expected to be encrypted. In some implementations, the data or cipher A 1214 to be included in the ciphertext may include: a random number (8) and a cipher (8). In some implementations, the number in parentheses may include a length in bytes. In some implementations, the random number may be generated by one or more random number generators configured to ensure that the random number is unpredictable through one or more security processes. The key used to encrypt the data may include a session key. For example, the session key may include DEK-Session-Key 1210. In encryption operation 1216, the data or cipher A 1214 and RND are processed using DEK-Session-Key 510 to produce encrypted data, namely cipher B 1218. The data 1214 may be encrypted using 3DES in ciphertext block chaining mode to ensure that an attacker must run any attack within all the ciphertext. As a non-limiting example, other algorithms such as Advanced Encryption Standard (AES) may be used. In some implementations, an initialization vector of 0x'00000000000000000' can be used. Any attacker attempting to brute-force the key used to encrypt this data will be unable to determine when the correct key has been used, because due to its random appearance, correctly decrypted data will be indistinguishable from incorrectly decrypted data.
[0188] In order for the authentication service to verify one or more passwords provided by one or more applets, the following data must be transmitted in plaintext from one or more applets to the mobile device during the authentication session: version number, used to determine the cipher method used and the message format used to verify the password, which allows the method to be changed in the future; pUID, used to retrieve the cipher asset and derive the card key; and pATC, used to derive the session key used for the cipher.
[0189] Figure 13 A method 1300 for generating a password is illustrated. For example, at block 1302, the Network Profile Record ID (pNPR) and Derived Key Index (pDKI) can be used to identify which issuer master keys will be used in the process of generating the password for authentication. In some implementations, the method may include performing authentication to retrieve the values of the pNPR and pDKI for the contactless card during authentication.
[0190] At block 1304, the issuer master key can be diversified by combining it with the card’s unique ID number (pUID) and the PAN serial number (PSN) of one or more applets (e.g., payment applets).
[0191] At block 1306, Card-Key-Auth and Card-Key-DEK (unique card key) can be created by diversifying the issuer's master key to generate a session key, which can be used to generate a MAC cipher.
[0192] At block 1308, the key used to generate the password and encrypt data in one or more applets may include the session key from block 1030 based on the card-unique key (Card-Key-Auth and Card-Key-DEK). In some implementations, these session keys may be generated by one or more applets and derived using pATC to produce session keys Aut-Session-Key and DEK-Session-Key.
[0193] Figure 14 An exemplary process 1400 illustrating key diversification according to one example is depicted. Initially, the sender and receiver may be equipped with two different master keys. For example, the first master key may include a data encryption master key, and the second master key may include a data integrity master key. The sender has a counter value that can be updated at block 1402, as well as other data that can be securely shared with the receiver, such as data to be protected.
[0194] At block 1404, the counter value can be encrypted by the sender using the data encryption master key to generate a data encryption-derived session key, and the counter value can also be encrypted by the sender using the data integrity master key to generate a data integrity-derived session key. In some implementations, the entire counter value or a portion of the counter value can be used between the two encryption processes.
[0195] In some implementations, the counter value may not be encrypted. In these examples, the counter value may be transmitted in plaintext between the sender and receiver, i.e., without encryption.
[0196] At block 1406, the data to be protected is processed using a cryptographic MAC operation by the sender using a data integrity session key and a cryptographic MAC algorithm. The protected data (including plaintext and shared secret) can be used to generate a MAC using one of the session keys (AUT-Session-Key).
[0197] At block 1408, the data to be protected can be encrypted by the sender using a session key derived from the data encryption in conjunction with a symmetric encryption algorithm. In some implementations, the MAC is combined with an equal amount of random data, for example, in 8-byte lengths, and then encrypted using a second session key (DEK-Session-Key).
[0198] At block 1410, the encrypted MAC, along with sufficient information identifying additional secret information (such as the shared secret, master key, etc.), is transmitted from the sender to the receiver for password verification.
[0199] At block 1412, the receiver uses the received counter value to independently derive two derived session keys from the two master keys as explained above.
[0200] At block 1414, the session key derived from the data encryption is used in conjunction with a symmetric decryption operation to decrypt the protected data. Further processing of the exchanged data then occurs. In some implementations, after the MAC is extracted, it is expected that the MAC will be regenerated and matched. For example, when verifying a password, it can be decrypted using an appropriately generated session key. The protected data can be reconstructed for verification. The MAC operation can be performed using an appropriately generated session key to determine if it matches the decrypted MAC. Since the MAC operation is an irreversible process, the only way to verify it is to attempt to recreate it from the source data.
[0201] At block 1416, the data integrity-derived session key is used in conjunction with the cipher MAC operation to verify that the protected data has not been modified.
[0202] Some examples of the methods described herein can advantageously confirm when successful authentication is determined when the following conditions are met: First, the ability to verify the MAC indicates that the derived session key is correct. A MAC can only be considered correct if decryption is successful and a correct MAC value is generated. Successful decryption indicates that a correctly derived encryption key was used to decrypt the encrypted MAC. Since the derived session key is created using a master key known only to the sender (e.g., the transmitting device) and the receiver (e.g., the receiving device), it can be trusted that the contactless card that initially created and encrypted the MAC is indeed authentic. Furthermore, the counter values used to derive the first and second session keys can be shown to be valid and can be used to perform the authentication operation.
[0203] Subsequently, the two derived session keys can be discarded, and the next iteration of the data exchange will update the counter value (returning to block 1402), and (at block 1410) a new set of session keys can be created. In some implementations, the combined random data can be discarded.
[0204] Figure 15A method 1500 for card activation according to some embodiments of the present subject is shown. For example, card activation can be performed by a system including a card, a device, and one or more servers. The contactless card, device, and one or more servers can refer to the same or similar components explained above, such as contactless card 602, client device 604, and server.
[0205] The card can be configured to dynamically generate data. In some implementations, this data may include information that can be transmitted from the card to the device, such as an account number, card identifier, card verification value, or telephone number. In some implementations, one or more portions of the data may be encrypted using the systems and methods disclosed herein.
[0206] At point 1504, one or more portions of dynamically generated data can be transmitted to the device's application via NFC or other wireless communications. For example, tapping the card near the device can allow the device's application to read one or more portions of the data associated with the contactless card. In some implementations, if the device does not include an application for assisting card activation, tapping the card can guide the device or prompt the customer to visit an app store to download the associated application to activate the card. In some implementations, the user can be prompted to gesture, place, or orient the card adequately toward the device's surface, such as placing it at an angle or flat on, near, or close to the device's surface. In response to the card's adequate gesture, placement, and / or orientation, the device can continue transmitting one or more encrypted portions of the data received from the card to one or more servers.
[0207] At point 1506, one or more portions of the data can be transmitted to one or more servers, such as a card issuer server. For example, one or more encrypted portions of the data can be transmitted from the device to the card issuer server to activate the card.
[0208] At point 1508, one or more servers may decrypt one or more encrypted portions of data via the system and methods disclosed herein. For example, one or more servers may receive encrypted data from a device and decrypt it to compare the received data with record data accessible to one or more servers. If the comparison of one or more decrypted portions of the data by one or more servers yields a successful match, the card may be activated. If the comparison of one or more decrypted portions of the data by one or more servers yields an unsuccessful match, one or more procedures may occur. For example, in response to a determination of an unsuccessful match, the user may be prompted to tap, swipe, or wave the card again. In this case, there may be a predetermined threshold including the number of attempts the user is allowed to activate the card. Alternatively, the user may receive a notification, such as a message on his or her device indicating an unsuccessful attempt at card verification, and a call, email, or text message sent to the associated service to assist in card activation; or another notification, such as a phone call on his or her device indicating an unsuccessful attempt at card verification, and a call, email, or text message sent to the associated service to assist in card activation; or another notification, such as an email indicating an unsuccessful attempt at card verification, and a call, email, or text message sent to the associated service to assist in card activation.
[0209] At point 1510, one or more servers can send a return message based on successful card activation. For example, the device can be configured to receive output from one or more servers indicating successful card activation by one or more servers. The device can be configured to display a message indicating successful card activation. Once the card has been activated, it can be configured to stop dynamically generating data to prevent fraudulent use. In this way, the card may not be activated thereafter, and one or more servers will be notified that the card has been activated.
[0210] Previous reference Figures 1A-15The various elements of the described device may include a variety of hardware elements and software elements, or combinations thereof. Examples of hardware elements may include devices, logic devices, components, processors, microprocessors, circuits, processors, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), memory cells, logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software elements may include software components, programs, applications, computer programs, application programs, system programs, software development programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computational code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. However, the determination of whether an embodiment is implemented using hardware and / or software components can vary depending on any number of factors, such as desired computing speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints as desired by a given implementation.
[0211] One or more aspects of at least one embodiment can be implemented by representative instructions stored on a machine-readable medium, which represent various logics within a processor that, when read by a machine, cause the machine to manufacture the logic to perform the techniques described herein. This representation, referred to as an "IP core," can be stored on a tangible machine-readable medium and provided to various clients or manufacturing facilities for loading into a manufacturing machine that manufactures the logic or processor. For example, some embodiments can be implemented using a machine-readable medium or article that can store an instruction or a set of instructions that, when executed by a machine, can cause the machine to perform the methods and / or operations according to the embodiments. Such a machine can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, or the like, and can be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles may include, for example, any suitable type of storage unit, storage device, storage article, storage medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, optical disc read-only memory (CD-ROM), recordable optical disc (CD-R), rewritable optical disc (CD-RW), optical disc, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital multifunction discs (DVDs), magnetic tape, cassette tape or the like. Instructions may include any suitable type of code implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code and the like.
[0212] The components and features of the device described above can be implemented using any combination of discrete circuit systems, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures. Further, where appropriate, the features of the device can be implemented using microcontrollers, programmable logic arrays, and / or microprocessors, or any combination thereof. It should be noted that hardware, firmware, and / or software elements may be collectively or individually referred to herein as “logic” or “circuit.”
[0213] It should be understood that the exemplary device shown in the above block diagrams may represent a functional description example of many potential implementations. Therefore, the division, omission, or inclusion of block functions shown in the figures does not necessarily mean that hardware components, circuits, software, and / or elements used to implement these functions will be divided, omitted, or included in the embodiments.
[0214] At least one computer-readable storage medium may include instructions that, when executed, cause a system to perform any of the computer-implemented methods described herein.
[0215] Some embodiments may be described using the expressions "one embodiment" or "an embodiment" and their derivatives. These terms mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. The phrase "in one embodiment" appearing in various places in the specification does not necessarily refer to the same embodiment. Furthermore, unless otherwise stated, the foregoing features are considered to be used in any combination. Thus, any feature discussed individually may be used in combination with each other unless it is noted that these features are incompatible with each other.
[0216] It is important to emphasize that this abstract of the disclosure is provided to allow the reader to quickly determine the nature of the technical disclosure. It is to be understood that this document should not be used to interpret or limit the scope or meaning of the claims. Furthermore, as can be seen from the above detailed description, various features are combined in a single embodiment for the purpose of simplifying the disclosure. This method of disclosure should not be construed as reflecting an intention that the claimed embodiment requires more features than expressly referenced in each claim. Rather, as reflected in the following claims, the inventive subject matter lies in the fact that a single disclosed embodiment has fewer features than all features. Therefore, the following claims are hereby incorporated into the detailed specification, wherein each claim stands independently as a separate embodiment. In the appended claims, the terms “comprising” and “wherein” are used as their plain English equivalents to the corresponding terms “including” and “wherein”, respectively. Furthermore, the terms “first,” “second,” “third,” etc., are used merely as labels and are not intended to impose numerical requirements on their objects.
[0217] The foregoing includes examples of the disclosed architecture. It is certainly impossible to describe every conceivable combination of components and / or methods, but those skilled in the art will recognize that many other combinations and permutations are possible. Therefore, the novel architecture is intended to cover all such changes, modifications, and variations falling within the spirit and scope of the appended claims.
[0218] For purposes of illustration and description, the above description of exemplary embodiments has been given. It is not intended to be exhaustive or to limit this disclosure to the precise forms disclosed. Many modifications and variations are possible based on this disclosure. The scope of this disclosure is not limited by this detailed description but by the appended claims. Future applications claiming priority to this application may claim the disclosed subject matter in different ways and may generally include one or more sets of limitations that are not disclosed herein or otherwise demonstrated.
Claims
1. A computer-implemented method, comprising: At least one processor is used to receive one or more signals from a first device, each of the one or more signals being generated and transmitted to the first device in response to one or more transmissions generated by a respective receiving coil of a plurality of receiving coils when energized, the plurality of receiving coils being communicatively coupled to the at least one processor; The at least one processor is used to determine the signal strength of each of the one or more signals received from the first device; Using the at least one processor, a first signal with the highest signal strength among the one or more signals is identified based on the determined signal strength of the one or more signals; The at least one processor is used to select a first receiving coil corresponding to the first signal; The at least one processor is used to de-excite the plurality of receiving coils; as well as The at least one processor is used to excite the selected first receiving coil and to establish communication with the first device.
2. The method according to claim 1, wherein, The first device is a contactless card.
3. The method according to claim 2, wherein, The second device includes the at least one processor and the plurality of receiving coils; Establishing the communication includes establishing a near-field communication (NFC) exchange between the second device and the contactless card.
4. The method according to claim 3, wherein, Based on the establishment of the NFC exchange, the contactless card is configured to transmit contactless card data to the second device, the contactless card data including at least one of the following: an account associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, and any combination thereof.
5. The method according to claim 2, wherein, The contactless card includes at least one of the following: credit card, debit card, electronic gift card, prepaid credit card, prepaid debit card, and any combination thereof.
6. The method according to claim 1, wherein, The plurality of receiving coils are simultaneously energized, and when energized, each of the plurality of receiving coils is configured to generate a corresponding transmission and send it to the first device.
7. The method according to claim 1, wherein, The plurality of receiving coils are energized in a predetermined order, and each of the receiving coils is configured to generate a corresponding transmission based on the predetermined order and send it to the first device when energized.
8. The method according to claim 1, wherein, The selected first receiving coil is configured to receive the highest current used to excite the first receiving coil.
9. The method according to claim 1, wherein, The excitation includes: exciting the selected first receiving coil, and de-exciting the remaining receiving coils among the plurality of receiving coils.
10. The method of claim 1, further comprising determining one or more positions of the first device relative to the plurality of receiving coils based on the determined signal strength.
11. The method of claim 10, further comprising selecting a first position of the first device in one or more locations of the first device based on the selected first receiving coil, wherein the first position corresponds to the first device being close to the selected first receiving coil and far from the remaining receiving coils among the plurality of receiving coils.
12. The method of claim 11, further comprising generating an instruction for repositioning the first device based on the selected first location.
13. The method of claim 12, further comprising displaying the generated indication on a graphical user interface communicatively coupled to the at least one processor.
14. A system comprising: At least one processor, said at least one processor being communicatively coupled to a plurality of receiving coils; as well as At least one non-transitory storage medium storing instructions that, when executed by the at least one processor, cause the at least one processor to perform the following operations: Determining one or more locations of the first device relative to the plurality of receiving coils, the determination including: One or more signals are received from the first device, each of the one or more signals being in response to one or more transmissions generated by a respective receiving coil of the plurality of receiving coils when energized and sent to the first device; Determine the signal strength of each of the one or more signals received from the first device; and The location of the first device is determined based on the determined signal strength; Based on the determined signal strength of the one or more signals, identify the first signal with the highest signal strength among the one or more signals; Select a first receiving coil corresponding to the first signal, and determine a first position among the one or more positions that is closest to the first receiving coil; and Generate an instruction to reposition the first device to the first location.
15. The system according to claim 14, wherein, The operation also includes: De-excite the plurality of receiving coils; and The selected first receiving coil is excited, and communication with the first device is established using the selected first receiving coil.
16. The system according to claim 14, wherein, The operation also includes displaying the generated instructions on a graphical user interface communicatively coupled to the at least one processor.
17. The system according to claim 14, wherein, The first device is a contactless card, wherein establishing the communication includes establishing a near field communication (NFC) exchange with the contactless card; Based on the establishment of NFC exchange, the contactless card is configured to transmit contactless card data, which includes at least one of the following: an account associated with the contactless card, an expiration date associated with the contactless card, a card verification value (CVV) associated with the contactless card, a billing address associated with the contactless card, a user name associated with the contactless card, and any combination thereof.
18. The system according to claim 14, wherein, The selected first receiving coil is configured to receive the highest current used to excite the first receiving coil.
19. The system according to claim 14, wherein, The excitation includes: exciting the selected first receiving coil and de-exciting the remaining receiving coils among the plurality of receiving coils.
20. A computer program product comprising a non-transitory machine-readable medium storing instructions that, when executed by at least one programmable processor, cause the at least one programmable processor to perform the following operations: Determine the signal strength of each of one or more signals received from a first device, wherein each of the one or more signals is in response to one or more transmissions generated by one or more of a plurality of receiving coils when energized and sent to the first device; Based on the determined signal strength of the one or more signals, identify the first signal with the highest signal strength among the one or more signals; Select the first receiving coil corresponding to the first signal; De-excite the plurality of receiving coils; and The selected first receiving coil is excited, and communication with the first device is established using the selected first receiving coil.
Citation Information
Patent Citations
Techniques to perform operations with a contactless card when in the presence of a trusted device
US20240338675A1