Use a payment card to unlock
Patent Information
- Application Number
- JP2024516980
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2021-09-16
- Filing Date
- 2022-09-16
- Publication Date
- 2025-09-25
AI Technical Summary
Plastic card keys with magnetic stripes or RFID tags are insecure, easily lost, inconvenient to manage, and costly for accommodations due to frequent replacement.
Utilizing a payment card with near field communication (NFC) capabilities to securely transmit and store a digital key, eliminating the need for additional plastic cards by encoding credentials and identification information wirelessly.
Enhances security, reduces loss of keys, minimizes management inconvenience, and lowers costs by using payment cards as secure digital keys for access.
Smart Images

Figure 00000000_0000_ABST
Abstract
Description
[Background technology]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to U.S. patent application Ser. No. 17 / 477,244, entitled “USE OF A PAYMENT CARD TO UNLOCK A LOCK,” filed Sep. 16, 2021, the contents of which are incorporated herein by reference in their entirety.
[0002] Hotels and other lodging facilities provide guests with keys to access rooms. The keys are typically either plastic key cards with a magnetic stripe or with a radio frequency identification (RFID) tag. In the case of plastic key cards with a magnetic stripe, hotel attendants encode information about the guest onto the magnetic stripe of the card at check-in before giving the plastic key card to the guest. For example, the guest's identifier, validity date and time, expiration date and time, and room number may be encoded onto the magnetic stripe. When a guest uses the plastic key card, they swipe the end of the plastic key card with the magnetic stripe through a magnetic card reader built into the guest room door. The magnetic card reader reads the information from the magnetic stripe, which is analyzed by the lock. If the information is the correct information to unlock the door, the door is unlocked and the guest can enter the room. If the information is not appropriate to unlock the door, access is denied and the door remains locked.
[0003] Plastic key cards with RFID chips work a little differently. At check-in, a hotel attendant encodes a guest's information onto the RFID chip of the plastic key card before handing it to the guest. When a guest wants to use the plastic key card, they hold it up to an RFID reader built into the guest room door. The RFID reader wirelessly reads the information from the RFID chip in the plastic key card. If the information is correct to unlock the door, the door is unlocked and the guest can enter the room. If the information is not correct to unlock the door, access is denied and the door remains locked.
[0004] Such plastic key cards can be used for other purposes as well. For example, an employer may issue such a plastic key card to an employee to allow entry to the employer's premises or to a secured area. For example, a secure laboratory within a company may require key card access. Plastic key cards may be used to access other locations where a lock is deemed necessary. Such plastic key cards may also be used to lock items such as trunks, safes, etc.
[0005] There are drawbacks to using these types of plastic key cards. For example, these types of plastic key cards are not particularly secure. The information on the magnetic stripe or RFID tag is easily accessible to any party with a magnetic or RFID reader. Furthermore, such plastic key cards are easily misplaced. As a result, the plastic key card may fall into the wrong hands or the user may be unable to access locked locations or items until a new card is obtained. Furthermore, it is inconvenient for users to have to manage an additional card. Finally, for accommodation owners, purchasing plastic key cards is costly given that they are often lost or broken. Summary of the Invention
[0006] According to one aspect of the invention, the method includes receiving identification and credential information transmitted from a contactless card via a wireless communication protocol. Based on the identification and credential information, the identity of the party is verified. After verifying the identity, a payment card code is transmitted. The code serves as a digital key for unlocking the payment card.
[0007] The payment card may be a smart card or credit card equipped with a wireless communication protocol. The wireless communication protocol may be a Near Field Communication (NFC) protocol. The lock may be for a hotel room. The method may include storing a room number for a code on the payment card and storing an identity of a party on the payment card. The method may also include receiving the code from a computing device. The identification and credentials may be received in an encrypted package.
[0008] According to another aspect of the invention, a method includes receiving credentials and identification information for a party from a contactless card at a portable computing device via a wireless communication protocol. The credentials and identification information are transmitted to an authentication authority. Verification of the party's identity is received. Once the party's identity is verified, a code is transmitted to the payment card via the wireless communication protocol. The code serves as a digital key for unlocking.
[0009] The portable computing device may be a smartphone, a tablet computing device, a smart watch, or a wearable device. The wireless communication protocol may be a Near Field Communication (NFC) protocol. The key may be for a hotel room. The identification information and credentials may be received in an encrypted package. The sending and receiving confirmation may occur over a network connection. The network connection may be either a wireless network connection, a cellular network connection, or a wired network connection.
[0010] According to a further inventive aspect, the smart card includes a memory that stores identification information about a user, a key code for unlocking with the smart card, and computer program instructions for unlocking with the key code and for performing a wireless payment. The smart card also includes a processor that executes the computer program instructions for unlocking and for performing a wireless payment stored in the memory. The smart card further includes hardware that enables the smart card to communicate wirelessly.
[0011] The hardware may be capable of Near Field Communication (NFC) wireless communication. The lock may be a door lock. The lock may be a hotel room lock. The memory may further store computer program instructions for downloading a key code from the device. The device may be a smartphone. [Brief description of the drawings]
[0012] [Figure 1] FIG. 1 illustrates an example environment for an example embodiment. [Diagram 2] FIG. 2 shows a flow chart of exemplary steps that may be performed to transmit a digital key to a payment card. [Diagram 3] FIG. 3 shows a flow chart of exemplary steps that may be performed in such an exemplary embodiment. [Figure 4] FIG. 4 illustrates an exemplary computing environment that may be suitable for exemplary embodiments. [Diagram 5] FIG. 5 illustrates the activity of the various components in carrying out such an interaction. [Figure 6A] FIG. 6A illustrates the front face of an exemplary contactless card suitable for exemplary embodiments. [Figure 6B] FIG. 6B shows the components of the contactless card of FIG. 6A. [Figure 7]FIG. 7 shows a components diagram illustrating the interaction between a contactless card and a computing device. [Figure 8A] FIG. 8A shows a block diagram illustrating how cryptographic hash functions are used in an exemplary embodiment. [Figure 8B] FIG. 8B shows a diagram of possible types of inputs that may be hashed in an exemplary embodiment. [Figure 9] FIG. 9 shows a block diagram illustrating encryption of a secure package according to an example embodiment. [Figure 10] FIG. 10 shows a flowchart of exemplary steps that may be performed in authenticating a customer's identity in an exemplary embodiment. [Figure 11] FIG. 11 illustrates certain items that are stored as part of the authentication service in an exemplary embodiment. [Figure 12] FIG. 12 shows a flow chart of the steps performed to authenticate an initiating party in an exemplary embodiment. [Figure 13] FIG. 13 illustrates a block diagram of a payment card suitable for exemplary embodiments. [Figure 14] FIG. 14 shows a flowchart of exemplary steps that may be performed to make a payment using a payment card in an exemplary embodiment. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS
[0013] Exemplary embodiments can provide a user's payment card with a key to unlock access to a location or item. Examples of payment cards include, but are not limited to, credit cards, debit cards, smart cards, employee identification cards with payment capabilities, and the like. A secure token that acts as a digital key can be uploaded to the user's payment card. For example, if the key is for a room at a lodging facility, the guest can log into a website or access the lodging facility's application and provide personal and payment information to check in. In some cases, the guest can access a self-service terminal that encodes the payment card with a secure token that acts as a digital key. In other examples, the user can leverage the capabilities of a mobile computing device, such as a smartphone, tablet, smartwatch, or wearable device, to download a secure token using an application or website and transmit the secure token to the payment card. The payment card can then be placed near a wireless reader of the lock. The wireless reader retrieves the secure token and extracts its contents. If the contents are correct to unlock, the lock is unlocked. Otherwise, the lock remains locked.
[0014] A suitable wireless communication protocol for use in the exemplary embodiment is the Near Field Communication (NFC) protocol or other wireless communication protocol. Thus, the mobile computing device or terminal and the payment card may be NFC-enabled. If a self-service terminal is used, the terminal can transmit the secure token to the payment card via NFC. Similarly, the mobile computing device can transmit the secure token to the payment card via NFC. The payment card can similarly transmit the secure token to the lock's wireless reader via NFC.
[0015] The exemplary embodiment has the advantage that no additional plastic card is required to access a locked location or item. This saves the user from having to manage additional plastic cards. Similarly, since many users choose to encode the key on their payment cards, the issuer of the plastic card key does not have to purchase as many plastic card keys, which reduces costs. The digital key on the payment card used in the exemplary embodiment is less likely to be lost by the user, since users tend to pay attention to their payment cards, whereas users pay less attention to traditional plastic card keys, since new plastic card keys are easily available. The key used in the exemplary embodiment is secure in that each secure token that serves as a digital key is encrypted and cannot be accessed without the decryption key required to decrypt the secure package.
[0016] FIG. 1 illustrates an example of an exemplary environment 100 for an exemplary embodiment. The exemplary environment 100 includes a contactless card 102. The contactless card 102 supports the NFC protocol and can communicate with other devices via the NFC protocol. For example, the contactless card 102 can wirelessly communicate with a mobile computing device or terminal 104 when the contactless card 102 is close enough (e.g., within 1.5 inches) to the mobile computing device or terminal 104. Details of the exemplary contactless card 102 are provided below. The mobile computing device 104 can be, for example, a smartphone, a tablet computing device, a smart watch, a wearable computing device, or any other computing device that is mobile and has the necessary functionality described herein. The terminal 104 can be an NFC-enabled terminal or computer system interfaced with a server 106. The mobile computing device / terminal 104 can communicate with the server 106 via a wireless, wired, or combination thereof network connection. The server 106 may be a web server, may be located on the cloud, or may be accessible via a local area network (LAN), a wide area network (WAN) such as the Internet, or a combination thereof.
[0017] The mobile computing device / terminal 104 can communicate with a user's payment card 108. For example, as described above, the mobile computing device / terminal 104 can provide the payment card 108 with a secure package that acts as a digital key. The payment card 108 can interact with a lock 110 to unlock a door, as described below.
[0018] One use of a digital key on a payment card is to unlock a door at a lodging establishment, such as a motel, hotel, inn, rental property, etc. When a user uses the digital key on a payment card to unlock a lodging room or rental property, there are at least two approaches that can be used in the exemplary embodiment to obtain the digital key on the payment card 108. In the first approach, the mobile computing device 104 transmits the digital key to the payment card 108. FIG. 2 shows a flow chart of exemplary steps that may be performed to transmit the digital key to the payment card 108. First, a user uses the mobile computing device 104 to access a lodging establishment application (such as a hotel chain or rental agency application) or access a lodging establishment website to check in (202). The website may run on or the application may be in communication with the server 106. To check in, the user may be required to provide identifying information, such as name, address, phone number, etc., and payment information, such as a credit card number, debit card number, etc. In some cases, as described below, the user may be required to tap the contactless card 102 to the mobile computing device 104 to authenticate identity. Once the guest has successfully checked in, the user may be asked the option to generate a digital key for storage on the payment card 108 (see 204). If the user selects the option to generate a digital key for storage on the payment card 108, the mobile computing device 104 sends a secure token to the payment card 108 that functions as the digital key (see 206). As described below, the secure token may be downloaded from the server 106 to the mobile computing device 108 and then sent to the payment card 108.
[0019] Another method for use at the lodging facility is to download the key from a self-service terminal at the lodging facility's front desk or kiosk. FIG. 3 shows a flow chart 300 of exemplary steps that may be performed in such an exemplary embodiment. First, the user checks in (see 302) using a website or application or by providing the necessary personal and payment information to an employee or kiosk, as described above. As part of the check-in, the user may be asked to identify themselves (see 304). This may include presenting appropriate identification, providing personal information via a kiosk, or verifying identity using a contactless card 102. Once the user's identity has been verified, the secure token, which functions as a digital key, is uploaded (see 306) to the payment card 108 via the terminal 104. The terminal 104 may be located, for example, at the reception desk of the lodging facility. In some exemplary embodiments, the terminal 104 is NFC-enabled and uses NFC to transmit the secure token to the user's payment card 108, which is also NFC-enabled.
[0020] FIG. 4 illustrates an exemplary computing environment 400 in greater detail than FIG. 1 that may be suitable for exemplary embodiments. A customer 418 may access a mobile computing device / terminal 402. The mobile computing device / terminal 402 includes a processor 408, such as a central processing unit (CPU), a graphics processing unit (GPU), an application specific integrated circuit (ASIC), a field programmable gate array (FPGA), or other processing device. The processor 408 may execute instructions, such as in a computer program, such as an application 414, to perform the functions described herein. The mobile computing device / terminal 402 may include storage 410, including random access memory (RAM), read only memory (ROM), solid state memory, optical disk storage, magnetic disk storage, or other various memories or storage for storing data and instructions. The storage 410 may include a non-transitory computer readable storage medium that holds processor executable instructions. The storage 410 may store an application 414. The application 414 may provide functionality for checking in and transmitting a secure token to a payment card 108, as described herein. The application 414 may also enable authentication of the identity of the user 418 using the contactless card 102. The application 414 may be a web browser in some exemplary embodiments.
[0021] The mobile computing device / terminal 402 may include an integrated circuit (IC) for providing NFC functionality 416. The NFC IC 416 may include an NFC transceiver and a loop antenna for participating in NFC communications. A contactless card 420 can communicate with the mobile computing device / terminal 402 via NFC, such as when the contactless card is tapped to the mobile computing device / terminal 402. The contactless card 420 may include a counter 415 used for secure communications. A payment card 403 can wirelessly communicate with the mobile computing device / terminal via NFC or another wireless protocol.
[0022] The mobile computing device / terminal 402 may communicate with server 404 and / or server 430. In some exemplary embodiments, the mobile computing device / terminal 403 communicates directly only with server 430. These servers 404 and 430 may be connected to the mobile computing device / terminal 402 through a network 406. The network 406 may include wide networks, such as the Internet and / or cellular networks, as well as local area networks or intranets, such as corporate networks, Ethernet networks, WiFi networks, etc. The server 404 may include one or more processors 422. The processor 422 may take a variety of forms similar to those described for the processor 408. The server 404 may include storage 424, including the forms of storage or memory described above for the storage 410 of the mobile computing device / terminal 402. The storage 424 may store computer programming instructions 440. In some exemplary embodiments, these computer programming instructions 440 are for a website that the user 418 can access to check into the accommodation and obtain a digital key as described above. The computer programming instructions may also be server code that interacts with application 414 to facilitate check-in and digital key acquisition. Server 430 is used when authentication of a user's identity is required and may be called by server 404 to provide identity authentication. The server may include a processor 433 that executes an authentication service 432 to authenticate the user's identity. Servers 404 and 430 may have access to data 434, such as a database.
[0023] As mentioned above, one option for using a payment card as a digital key for a lodging room is for a user to identify themselves using a contactless card and transmit the digital key to the payment card via a mobile computing device. FIG. 5 illustrates the activity of various components in carrying out such an interaction. FIG. 5 is described with reference to the depictions of components in FIG. 4. First, a user 418 opens an application 414 on a mobile computing device 402 (see 502). The application may be an application for the lodging facility or may be a web browser that allows access to the lodging facility's website. Using the application 414, the user 418 communicates with a program including computer program instructions 440 on a server 440 and requests check-in (see 503). As part of the check-in process, the application 414 instructs the user 418 to tap a contactless card 420 against the mobile computing device 402 (see 504). The contactless card 420 is tapped and transmits identifying information to the mobile computing device 402 via NFC in a secure package (see 506). The composition and contents of the secure package from the contactless card 420 are described in more detail below. The mobile computing device 402 sends a secure package including the identification information to the server 404 (see 508). The server 430 can forward the secure package to an authentication service 432 on the server 430. The authentication service 432 on the server 430 then authenticates the user's identity (see 510). Once the user is authenticated, the user may be checked in, such as by the server 404. In an exemplary embodiment, the server 404 can request the server 430 to perform authentication of the user's identity and notify the server 404 of the result. If the authentication is not successful, a rejection may be sent to the server 404 and forwarded to the application 414 on the mobile computing device 402. If the authentication is successful, the user is checked in, and the server 404 reports the successful check-in to the application 414 on the mobile computing device 402 (see 512).
[0024] Next, the application 414 on the mobile computing device 402 may instruct the user to use the payment card as a key (see 514). The user may respond affirmatively that they would like to use the payment card as a key (see 516). If the user does not select this option, the process stops. Otherwise, the application 414 may request the key from the server 404 (see 518). Computer program instructions 440 on the server generate a secure package that is a digital key. The key code and other information of the secure package may then be sent from the server 404 to the application 414 on the mobile computing device 402 (see 520). The application 414 instructs the user 418 to tap the payment card to the mobile computing device 402. The payment card is tapped to the mobile computing device 403 (see 524). The secure package, which holds the digital key code, may be sent to the payment card via NFC by the application 414 on the mobile computing device as a result of the tap. Specifically, the mobile computing device 402 transmits a key code (see 526), which is stored on the payment card (see 528).
[0025] The following description focuses on the details of the use of contactless cards. FIG. 6A shows an example of a surface of a contactless card 600 that may be issued by a service provider 606, such as a merchant, financial institution, etc. In some exemplary embodiments, the contactless card 600 may include an identification card. In some cases, the card 600 may include a dual interface contactless payment card. The contactless card 600 may include a substrate 608, which may include a single layer or laminate composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 600 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, or the contactless card 600 may conform to the ISO / IEC 14443 standard. However, it is understood that the contactless card 600 according to the present disclosure may have different characteristics.
[0026] The contactless card 600 may also include identification information 604 displayed on the front and / or back of the card, and a contact pad 602. The contact pad 602 may be configured to establish a connection with another communication device, such as a user device, a smartphone, a laptop, desktop, or tablet computer. The contactless card 600 may also include processing circuitry, an antenna, and other components not shown in FIG. 6A. These components may be located behind the contact pad 602 or elsewhere on the substrate 608. The contactless card 600 may also include a magnetic stripe or tape, which may be located on the back of the card (not shown in FIG. 6A).
[0027] As shown in Figure 6B, the contact pad 602 of Figure 5A may include processing circuitry 610 for storing and processing information, including a microprocessor 614 and memory 616. It will be understood that the processing circuitry 610 may include additional components such as processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware necessary to perform the functions described herein.
[0028] The memory 616 may be a read-only memory, a write-once read multiple memory, or a read / write type memory, such as RAM, ROM, EEPROM, etc., and the contactless card 600 may include one or more of these memories. Read-only memory is factory programmable as read-only or one-time programmable. One-time programmable provides the opportunity to write once and read many times. Write-once / read multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory cannot be rewritten, but it can be read many times. Read / write memory can be programmed and reprogrammed many times after leaving the factory, and it can be read many times.
[0029] The memory 616 may be configured to store one or more applets 618, one or more counters 620, and a unique customer identifier 622. The one or more applets 618 may include one or more software applications configured to run on one or more contactless cards, such as a JavaCard applet. However, it is understood that the applet 618 is not limited to a JavaCard applet and may be any software application capable of operating on a contactless card or other memory-limited device. The one or more counters 620 may include a numeric counter sufficient to store an integer number. The customer identifier 622 may include a unique alphanumeric identifier assigned to a user of the contactless card 600, which may distinguish a user of the contactless card from other users of contactless cards. In some examples, the customer identifier 622 may identify both a customer and an account assigned to the customer, and may further identify a contactless card associated with the customer's account.
[0030] In some examples, the contactless card 600 may include one or more antennas 612. The one or more antennas 612 may be disposed within the contactless card 600 and around the processing circuit 610 of the contact pad 602. For example, the one or more antennas 612 may be integrated with the processing circuit 610, or the one or more antennas 612 may be used with an external booster coil. As another example, the one or more antennas 612 may be external to the contact pad 602 and the processing circuit 610.
[0031] In one embodiment, the coil of the contactless card 600 can act as the secondary of an air-core transformer. The terminal can communicate with the contactless card 600 by interrupting or amplitude modulating the power. The contactless card 600 can infer data sent from the terminal using gaps in the power connection of the contactless card, which may be kept functional through one or more capacitors. The contactless card 600 can return communication by switching the load on the coil of the contactless card, or by load modulation. Load modulation can be detected at the terminal coil due to interference.
[0032] As mentioned above, the contactless card 600 may be built on a software platform capable of running on a smart card or other memory-limited device such as a JavaCard and may securely execute one or more applications or applets. An applet may be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a near-field data exchange request, from a reader such as a mobile NFC reader and generate an NDEF message that includes an encrypted, secure OTP encoded as an NDEF text tag.
[0033] 7 shows a components diagram illustrating the interaction between a contactless card 702 and a computing device 706. The contactless card may be equipped with NFC capabilities. When the contactless card is brought into proximity with an NFC reader 708 on a mobile computing device 706, the identifying information in the secure package 704 is transmitted to the computing device.
[0034] The generation of the secure package that holds the identification information 704 may be generated by a cryptographic hash function such as MD5 or SHA-1. FIG. 8A shows a block diagram 800 illustrating how a cryptographic hash function is used in an exemplary embodiment. In the example shown in FIG. 8A, three inputs 802, 804, and 806 are passed together to a hash function 808. The choice to show three inputs is for illustrative purposes and is not intended to be limiting. In some cases, other numbers of inputs may be used. The hash function 808 generates an output hash value 812. Due to the nature of the hash function 808, it is computationally difficult to derive the inputs 802, 804, and 806 from the hash value 812 without knowing the key 810 used in the hash function 808. The key 810 is kept secret. The key 810 may be dynamically generated for each session and unique to the contactless card. The hash function 808 thus provides a layer of security for the contents (e.g., inputs 802, 804, and 806) contained in the secure package.
[0035] In exemplary embodiments, inputs 802, 804, and 806 may vary depending on the information the parties wish to exchange and the protocol for authenticating the initiating party. FIG. 8B shows a diagram 830 of possible types of inputs 832 that may be hashed in exemplary embodiments. In these exemplary embodiments, a one-time password 834 generated by a contactless card may be included as an input. An account identifier 836 of the initiating party may be provided. This may be an account number or other identifier that uniquely identifies the initiating party's account. The account identifier 836 may be the initiating party's phone number. In some cases, the initiating party's phone number is not included in the hash value 812 and may be derived from the message sent from the mobile computing device. The inputs 832 may include a counter value 838 and / or the initiating party's name 840.
[0036] As an additional layer of security, the hash value 902 may be encrypted. FIG. 9 shows a block diagram 900 illustrating such encryption. The hash value 902 generated as described above is passed to an encryption engine 904 which encrypts the hash value using an encryption key 906. The resulting output is a secure package 908. The encryption engine 704 may use any of a variety of encryption algorithms such as DES, AES, RSA, DSA, etc. These may be symmetric encryption algorithms such as DES or AES, or asymmetric encryption algorithms such as RSA or DSA. The authentication service 432 is presumed to be in possession of the appropriate key to decrypt the secure package. Although not shown in FIG. 9, other content may be encrypted in combination with the hash value 902.
[0037] 10 shows a flowchart 1000 of example steps that may be performed in authenticating a user's identity. The user taps the contactless card 702 to a mobile computing device 706 equipped with an NFC reader 708 as described above (see 1002). The mobile computing device 706 sends a message including a secure package retrieved from the contactless card 702 to an authentication service 432 on the server 430 (see 1004). A one-time password (OTP) and other information in the secure package are extracted (see 1006). The authentication service 432 uses the extracted information to authenticate the user's identity (see 1008).
[0038] The authentication service, which receives the secure package originating from the contactless card, will not be described in detail here. Figure 11 shows certain items that are stored as part of the authentication service 1100. These items include a synchronization counter 1102 that may be used in the decryption / encryption operation. The authentication service 1100 includes a decryption code 1104 for performing a decryption operation on the secure package. The authentication service 1100 may store a number of decryption and encryption keys 1106.
[0039] In general, the server 430 (or other computing device) and the contactless card 420 may be provisioned with the same master key (also referred to as a master symmetric key). More specifically, each contactless card 420 may be programmed with an individual master key with a corresponding pair in the authentication service 432. For example, a unique master key may be programmed into the memory of the contactless card 420 when the contactless card 420 is manufactured. Similarly, the unique master key may be stored in the customer record associated with the contactless card 420 in account information accessible to the authentication service 432 (and / or stored in another secure location). The master key may be kept secret from all parties other than the contactless card 432 and the authentication service 432, enhancing the security of the system.
[0040] The master key may be used in combination with a counter to provide added security through key diversification. Counters 415 and 1102 contain values that are synchronized between contactless card 420 and authentication service 432. The counter value may contain a numerical value that changes each time data is exchanged between contactless card 420 and authentication service 432.
[0041] After communication is established between the mobile computing device 402 and the contactless card 420, the contactless card 420 can generate a message authentication code (MAC) cryptogram. In some examples, this can occur when the contactless card 420 is read. In particular, this can occur upon a read, such as an NFC read, of a Near Field Data Exchange (NDEF) tag that is created according to the NFC data exchange format. For example, a reader, such as an NFC reader, can send a message, such as an applet selection message, that includes an applet ID of an NDEF generating applet. Once the selection is confirmed, a sequence can be sent in which a select file message is followed by a read file message. For example, the sequence may include "Select Capabilities file", "Read Capabilities file", and "Select NDEF file". At this point, a counter value 415 maintained by the contactless card 420 can be updated or incremented, followed by "Read NDEF file". At this point, a message may be generated that includes a header and a shared secret. A session key can then be generated. A MAC cryptogram can be created from the message that includes the header and the shared secret. The MAC cryptogram may then be concatenated with one or more blocks of random data, and the MAC cryptogram and random number (RND) may be encrypted using a session key. The cryptogram and header may then be concatenated, encoded as ASCII hexadecimal, and returned in an NDEF message (in response to the "Read NDEF file" message). In some examples, the MAC cryptogram may be sent as an NDEF tag, and in other examples, the MAC cryptogram may be included with a uniform resource indicator (e.g., a formatted string). The contactless card 420 then sends the MAC cryptogram to the mobile computing device 402, which forwards the MAC cryptogram to the authentication service 432 for verification, as described below. However, in some embodiments, the mobile computing device 402 may verify the MAC cryptogram.
[0042] More generally, when preparing to send data (e.g., to server 430), contactless card 420 can increment counter 415. Contactless card 420 then provides the master key and the counter value as input to an encryption algorithm, which generates a diversified key as output. The encryption algorithm may include an encryption algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc. Non-limiting examples of encryption algorithms include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, symmetric CMAC algorithms such as AES-CMAC, etc.
[0043] The contactless card 420 can then encrypt data (e.g., a customer identifier and other data) using the diversified key. The contactless card 420 can then transmit the encrypted data to the mobile computing device 402 (e.g., via an NFC connection, a Bluetooth connection, etc.). The mobile computing device 402 can then transmit the encrypted data over the network 406 to an authentication service 432 on the server computing device 430. In at least one embodiment, the contactless card 420 transmits the counter value along with the encrypted data. In such an embodiment, the contactless card 420 can transmit the counter value encrypted or unencrypted.
[0044] Although a counter is used as an example, other data may be used to secure communications between the contactless card 420, the mobile computing device 402, and / or the authentication service 432. For example, the counter may be replaced with a random nonce that is generated each time a new diversified key is needed, the complete value of the counter value transmitted by the contactless card 420 and the authentication service 432, a portion of the counter value transmitted by the contactless card 420 and the authentication service 432, a counter maintained independently by the contactless card 420 and the authentication service 432 but not transmitted between them, a one-time passcode exchanged between the contactless card 420 and the authentication service 432, and a cryptographic hash of the data. In some examples, one or more portions of the diversified key may be used by the parties to create multiple diversified keys.
[0045] 12 shows a flow chart 1200 of steps performed to authenticate an initiating party after an authentication message containing a secure package is received by a receiving party, the authentication service 432. First, the authentication service 432 decrypts the secure package using the decryption key 1106. The decryption key 1106 is then used to decrypt the hash to extract the input hashed by the hash function 808 (see 1202). The extracted password and counter value may be compared (see 1204) to a valid password and a valid counter value. It is determined whether the passwords match and the counter values match, or whether the extracted counter value indicates that the password has not expired (see 1206). If the passwords match and the extracted password has not expired based on the extracted counter value, other extracted information may be compared (see 1208).
[0046] The other information is other authentication factors 1002, such as the phone number of the mobile computing device 402, which may be compared to the phone number of record for the user 418. The other authentication factors may include geolocation information of the user. The geolocation information may be information such as GPS information, area code, exchange prefix information, etc., that may be compared to information regarding the user's residence. The other authentication factors may also include a shared secret shared between the user and the authentication service 432.
[0047] 12, if the other information is valid (see 1210), then the user 418 is authenticated (see 1214). If not, the user 418 is not authenticated (see 1212). Similarly, if the passwords do not match or have expired as indicated by the extracted counter value, then the user is not authenticated (see 1212).
[0048] The discussion will focus on payment cards. FIG. 13 illustrates a block diagram of a payment card 1300 suitable for use in the exemplary embodiments. The payment card 1300 may be a credit card, debit card, or other type of card that can be used for payment. In some embodiments, the payment card 1300 may be a smart card, such as a multi-function card or a contact card. The payment card 1300 may include a processor 1302 for executing computer programming instructions, as described above, and NFC hardware 1314 for providing NFC functionality. The payment card 1300 may also include a memory 1304. The memory 1304 may store instructions 1306 for performing electronic payments using the payment card. The memory 1304 may store instructions 1308 for unlocking, as described above. These instructions 1306 and 1308 are executed by the processor 1302 to perform the functions of the payment card 1300 described above. The memory 1304 may hold a key code 1310 used to unlock door locks, area locks, item locks, etc. Finally, the memory may store data 1312 .
[0049] FIG. 14 illustrates a flow chart 1400 of example steps that may be performed to use a payment card 1300 to make a payment at a lodging facility, workplace, store, etc. First, a user identifies what they want to purchase (see 1402). The user then taps the payment card to a reader to make the payment (see 1404). For example, a user in a user's room can pay for items in a minibar or pay for a movie by tapping the payment card to a reader installed in the user's room. The reader may be an NFC reader that can wirelessly communicate via NFC with the payment card to effectuate the payment. As another example, an employee may have an identification card that is NFC-enabled and can be used to unlock a secured area of the workplace. The employee can pay for lunch by tapping the identification card to an NFC reader when checking out of the lunch room. The purchase is charged to a user account, such as a room account, an employee account, a bank account, etc. (see 1406).
[0050] Although this application focuses on exemplary embodiments, it should be understood that various changes in form and detail can be made without departing from the scope of the claims appended hereto.
Claims
1. receiving identification and credential information transmitted from a contactless card via a wireless communication protocol; verifying the identity of the party based on the identification information and the credentials; After verifying said identity, sending a code for the payment card; wherein the code acts as a digital key to unlock the lock. method.
2. The method of claim 1 , wherein the payment card is either a smart card or a credit card capable of using the wireless communication protocol.
3. The method of claim 1 , wherein the wireless communication protocol is Near Field Communication (NFC).
4. The method of claim 1 , wherein the lock is for a hotel room.
5. 5. The method of claim 4, further comprising storing a room number for the code and storing the identity of the party on the payment card.
6. The method of claim 1 , further comprising receiving the code from a computing device.
7. The method of claim 1 , wherein the identification information and the credentials are received in an encrypted package.
8. receiving credential and identification information for the party at the portable computing device from the contactless card via a wireless communication protocol; transmitting said credentials and said identification information to an authentication authority; receiving confirmation of the identity of said party; transmitting a code to a payment card via said wireless communication protocol after verifying said identity of said party; wherein the code acts as a digital key to unlock the lock. method.
9. The method of claim 8 , wherein the portable computing device is one of a smartphone, a tablet computing device, a smartwatch, or a wearable device.
10. The method of claim 8 , wherein the wireless communication protocol is a Near Field Communication (NFC) protocol.
11. The method of claim 8 , wherein the lock is for a hotel room.
12. The method of claim 8 , wherein the identification information and the credentials are received in an encrypted package.
13. The method of claim 8 , wherein the sending and receiving the confirmation occur over a network connection.
14. The method of claim 13 , wherein the network connection is one of a wireless network connection, a cellular network connection, or a wired network connection.
15. A smart card, A memory, Identification information about the user; a key code for unlocking the smart card; computer program instructions for unlocking the lock with the key code; computer program instructions for effecting wireless payments; a memory for storing the a processor that executes computer program instructions stored in the memory for unlocking the lock and for performing wireless payment; hardware that enables the smart card to communicate wirelessly; A smart card comprising:
16. 16. The smart card of claim 15, wherein the hardware is capable of near field communication (NFC) wireless communication.
17. 16. The smart card of claim 15, wherein the lock is a door lock.
18. 18. The smart card of claim 17, wherein the lock is a hotel room lock.
19. 16. The smart card of claim 15, wherein the memory further stores computer program instructions for downloading the key code from a device.
20. 20. The smart card of claim 19, wherein the device is a smartphone.