Tapping of card for safely generating card data copied to clip board

By generating a virtual account number and CVV from a contactless card's encrypted data, the method securely and accurately enters payment information into forms, addressing entry errors and security risks.

JP2025146836AInactive Publication Date: 2025-10-03CAPITAL ONE SERVICES LLC
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
JP2025095830
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2019-02-01
Filing Date
2025-06-09
Publication Date
2025-10-03
Estimated Expiration
Not applicable · inactive patent

AI Technical Summary

Technical Problem

Payment card account identifiers are often long and difficult to enter correctly, leading to errors and security risks, and existing systems restrict access to contactless card data, preventing automated copying and pasting.

Method used

A contactless card generates a URL containing encrypted data, which is verified by an authentication server to produce a virtual account number, expiration date, and CVV, allowing these to be securely copied to a computing device's clipboard for automatic entry into forms.

Benefits of technology

This method enhances security by eliminating manual entry, protecting the actual account number, and ensures accurate data transfer across various operating systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025146836000001_ABST
    Figure 2025146836000001_ABST
Patent Text Reader

Abstract

To provide a system, a method, a product and a computer readable medium for tapping a non-contact card for safely generating card data.SOLUTION: In a system 100, a mobile device allows a web browser to output a form including a payment field, receives URL including encrypted data generated by a non-contact card on the basis of a secret key stored in a memory of the non-contact card from a communication interface of the non-contact card, an account application transmits the encrypted data to an authentication server, the server decrypts the encrypted data on the basis of the secret key in the authentication server, the mobile device receives a virtual account number, an expiration date and a card verification value (CVV) from a virtual account number server, and OS pastes the virtual account number to the payment field of the form of the web browser, and outputs notification including the expiration date associated with the virtual account number and the CVV.SELECTED DRAWING: Figure 1B
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] TECHNICAL FIELD Embodiments herein relate generally to computing platforms, and more specifically to tapping a card to a computing device to securely generate card data that can be copied to the computing device's clipboard.

[0002] Related Applications This application claims priority to U.S. Patent Application No. 16 / 265,937, entitled "Tapping a Card to Securely Generate Card Data to Copy to Clipboard," filed February 1, 2019, the contents of which are incorporated herein by reference in their entirety. [Background technology]

[0003] Payment card account identifiers are often long numbers and / or strings of characters. This makes it difficult for users to manually enter account identifiers correctly. In fact, users often make mistakes and enter incorrect account identifiers into computing interfaces (e.g., payment interfaces). Furthermore, processes have been developed that allow cameras to capture and identify account identifiers entered into devices, creating security risks for account identifiers. Furthermore, certain operating systems restrict the ability to access identifiers stored on contactless cards. This blocks traditional attempts to programmatically copy and / or paste account identifiers. Summary of the Invention

[0004] Embodiments disclosed herein provide systems, methods, articles of manufacture, and computer-readable media for tapping a contactless card to securely generate card data to copy to a clipboard. According to one example, a web browser executing on a processor circuit may output a form including payment fields. A uniform resource locator (URL) may be received from a communication interface of the contactless card, the URL including encrypted data generated by the contactless card based at least in part on the contactless card's private key stored in the contactless card's memory. An application executing on the processor circuit may transmit the encrypted data to an authentication server, and the authentication server verifies the encrypted data by decrypting the encrypted data based at least in part on the contactless card's private key stored in the authentication server's memory. The application may receive a virtual account number from a virtual account number server based on verification of the encrypted data by the authentication server. The application may receive an expiration date associated with the virtual account number and a card verification value (CVV) associated with the virtual account number. The application may copy the virtual account number to a clipboard of an operating system (OS) running on the processor circuit. The OS may paste the virtual account number from the clipboard into a payment field in a web browser form. The OS may output a notification with the expiration date and CVV associated with the virtual account number. [Brief explanation of the drawings]

[0005] [Figure 1A] 1 illustrates an embodiment of a system for tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 1B] 1 illustrates an embodiment of a system for tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 1C]1 illustrates an embodiment of a system for tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 2A] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 2B] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 2C] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 2D] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 3A] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 3B] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 3C] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 3D] 13 illustrates an embodiment of tapping a contactless card to securely generate card data to copy to a clipboard. [Figure 4] 1 illustrates a first logic flow embodiment. [Figure 5] 10 illustrates a second logic flow embodiment. [Figure 6] 10 illustrates a third logic flow embodiment. [Figure 7] 1 illustrates an embodiment of a computing architecture. DETAILED DESCRIPTION OF THE INVENTION

[0006] Embodiments disclosed herein provide secure techniques for using a contactless card to generate card data (e.g., account number, expiration date, customer billing address, shipping address, and / or card verification value (CVV)) that can be copied to a computing device's clipboard. Generally, a contactless card may come within communication range of a computing device, for example, via a tap gesture. In doing so, the contactless card generates a uniform resource locator (URL), which is sent to the computing device. The URL may include data used by an authentication server as part of the verification process. For example, the URL may include encrypted data that is decrypted by the server as part of the verification process. As another example, the URL may include a unique identifier associated with the contactless card that is used by the authentication server as part of the verification process. Once verified, the authentication server may instruct a virtual account number server to generate card data for the account associated with the contactless card. The card data may include a virtual account number, expiration date, and CVV. The generated card data may then be sent to the computing device. In some embodiments, account owner information (e.g., name, billing address, and / or shopping address, etc.) may also be sent to the computing device. The computing device may copy at least one element (e.g., virtual account number, expiration date, and / or CVV) of the card data and / or account holder information (e.g., name, billing address, and / or shopping address) to a clipboard. Once copied to the clipboard, the data may be copied to a corresponding field of a form in a web browser and / or other application. Additionally, a notification may be output that includes the generated one or more elements of the card data and / or account holder information. The notification may cause other elements of the data to be copied to the clipboard and pasted into payment fields of the form.

[0007] Advantageously, the embodiments disclosed herein improve the security of all devices and associated data. For example, some operating systems may restrict access to data stored on contactless cards and / or certain types of data stored on contactless cards. Therefore, conventional techniques for copying and / or auto-entering card data do not function properly. However, advantageously, the embodiments disclosed herein allow card data to be securely generated, transmitted, copied, and / or auto-entered on any type of operating system. Furthermore, conventional approaches require users to manually enter card data into forms. However, doing so may allow other users or devices to capture the card data as the user enters it into the form. Eliminating the need for users to manually enter card data into forms enhances the security of the card data. Furthermore, server-performed validation provides an additional safeguard to ensure that the correct card data is entered into the form. Furthermore, because conventional solutions require the contactless card's actual account number to be entered into the form, generating a virtual card number and entering it into the form protects the security of the contactless card's actual account number.

[0008] With general reference to the notation and nomenclature used herein, one or more portions of the detailed descriptions which follow may be presented in terms of program procedures executed on a computer or network of computers. These procedural descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art. A procedure is herein, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. These operations are operations requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be noted, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.

[0009] Further, these operations are often referred to in terms, such as adding or comparing, which are commonly associated with mental operations performed by a human operator. However, no such capability of a human operator is necessary, or desirable in most cases, for any of the operations described herein forming part of one or more embodiments. Rather, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by a computer program stored therein and written in accordance with the teachings herein, and / or include apparatuses or digital computers specially constructed for the required purposes. Various embodiments also relate to apparatuses or systems for performing these operations. These apparatuses may be specially constructed for the required purposes. The required structure for these various machines will be apparent from the description given.

[0010] Reference is now made to the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding thereof. It will be apparent, however, that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate description. The intention is to cover all modifications, equivalents, and alternatives within the scope of the claims.

[0011] FIG. 1A illustrates a schematic diagram of an exemplary system 100 consistent with disclosed embodiments. As shown, the system 100 includes one or more contactless cards 101, one or more mobile devices 110, an authentication server 120, and a virtual account number server 140. The contactless cards 101 represent any type of payment card, such as a credit card, a debit card, an ATM card, or a gift card. The contactless cards 101 may include one or more communication interfaces 150, such as a radio frequency identification (RFID) chip, configured to communicate with the mobile devices 110 via NFC, the EMV standard, or other short-range protocols for wireless communication. While NFC is used as an example communication protocol, the present disclosure is equally applicable to other types of wireless communication, such as the EMV standard, Bluetooth, and / or Wi-Fi. The mobile devices 110 represent any type of network-enabled computing device, such as a smartphone, a tablet computer, a wearable device, a laptop, a portable gaming device, or the like. Servers 120, 140 are representative of any type of computing device, such as a server, a workstation, a computing cluster, a cloud computing platform, a virtualized computing system, and the like.

[0012] As shown, memory 111 of mobile device 110 includes an instance of operating system (OS) 112. Examples of operating systems 112 include Android® OS, iOS®, Linux®, and Windows® operating systems. As shown, OS 112 includes account application 113, clipboard 114, and web browser 115. Account application 113 allows a user to perform various account-related operations, such as viewing account balances, purchasing items, and / or processing payments. In some embodiments, a user must authenticate using authentication credentials to access account application 113. For example, the authentication credentials may include a username and password, biometric credentials, etc. In some embodiments, authentication server 120 may provide the necessary authentication, as described in more detail below. Web browser 115 is an application that allows mobile device 110 to access information over network 130 (e.g., via the Internet). For example, a user may use web browser 115 to make a purchase from a merchant's website. Web browser 115 is an example of an application used to access information (e.g., to make purchases) over network 130. The use of a web browser as an example reference herein should not be considered limiting of the disclosure, as the disclosure is equally applicable to other types of applications used to access information over a network, such as applications provided by merchants that enable users to make purchases.

[0013] When using a web browser 115 (or other application), a user may encounter a form that includes one or more payment fields. Traditionally, a user must manually enter a card number, expiration date, and CVV. While some mobile operating systems allow for the automatic entry of such data into forms, other mobile operating systems have limitations in the automatic entry of such data. Advantageously, embodiments disclosed herein solve such problems by leveraging the contactless card 101 to trigger the generation of a virtual account number, expiration date, and / or CVV that can be copied to the clipboard 114 of the OS 112.

[0014] More specifically, a user may tap a contactless card 101 to a mobile device 110, thereby bringing the contactless card 101 sufficiently close to a card reader 118 of the mobile device 110 to enable NFC data transfer between the communication interface 150 of the contactless card 101 and the card reader 118 of the mobile device 110. In some embodiments, the mobile device 110 may trigger the card reader 118 via an application program interface (API) call. In one example, the mobile device 110 triggers the card reader via an API call in response to a user tapping or selecting an element of a user interface, such as a form field. Additionally and / or alternatively, the mobile device 110 may trigger the card reader 118 based on periodically polling the card reader 118. More generally, the mobile device 110 may trigger the card reader 118 to communicate using any viable method. After communication is established between the mobile device 110 and the contactless card 101, the contactless card 101 generates a message authentication code (MAC) cryptogram. In some examples, this may occur when the contactless card 101 is read by the account application 113. In particular, this may occur upon a read, such as an NFC read of a Near Field Communication Data Exchange (NDEF) tag, which may be created according to the NFC data exchange format.

[0015] More generally, applet 103 executing on a processor (not shown) of contactless card 101 generates and transmits data to mobile device 110 via communication interface 150. In some embodiments, the data generated by contactless card 101 may include a URL. This URL may be directed to authentication server 120 or another URL associated with the entity issuing contactless card 101. The URL may further be a universal link URL that opens a local resource (e.g., a page of account application 113). The URL may further include data (e.g., parameters) used by authentication server 120 to validate the data generated by contactless card 101.

[0016] For example, the applet 103 of the contactless card 101 may use an encryption algorithm to generate an encrypted payload based at least in part on the private key 104 stored in the memory 102 of the contactless card 101. In general, the applet 103 may generate the encrypted payload using any type of encryption algorithm and / or system, and the use of a particular encryption algorithm as an example herein should not be considered limiting of the disclosure. The encryption algorithm may include a cryptographic algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. In some embodiments, the applet 103 may perform encryption using key diversification techniques to generate the encrypted payload. Examples of key diversification techniques are described in U.S. Patent Application No. 16 / 205,119, filed November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety. The applet 103 of the contactless card 101 may include the cryptographic payload as a parameter of the URL.

[0017] As another example, the applet 103 for the contactless card 101 may include in the URL some other string used to identify the contactless card 101. For example, the URL may include a subset of the numbers (or letters) of the account number associated with the contactless card 101. For example, if the account number is 16 digits, the applet 103 for the contactless card 101 may include four digits of the account number as a parameter in the URL. The account number may be any type of account number, such as a primary account number (PAN), a one-time virtual account number, a token generated based on the PAN, etc.

[0018] The applet 103 may then send the generated data to the mobile device 110, which may send the received data to the authentication server 120. The authentication application 123 may then authenticate the received data. For example, if the URL includes an encrypted payload, the authentication application 123 may decrypt the encrypted payload using a copy of the private key 104 stored in the memory 122 of the server 120. The private key 104 may be identical to the private key 104 stored in the memory 102 of the contactless card 101, where each contactless card 101 is manufactured to include a unique private key 104 (and the server 120 stores a corresponding copy of each unique private key 104). Thus, the authentication application 123 may successfully decrypt the encrypted payload, thereby verifying the payload. As another example, the authentication application 123 may verify that the digits of an account number match the digits of the account number associated with the contactless card 101 stored in the account data 124, thereby verifying the account number.

[0019] Regardless of the verification technique used by the authentication application 123, once verified, the authentication application 123 may instruct a virtual account number (VAN) generator 142 in memory 141 of the virtual account number server 140 to generate a virtual account number, expiration date, and CVV for the account associated with the contactless card 101. In at least one embodiment, the virtual account number generated by the VAN generator 142 is restricted to a particular merchant or group of merchants. The virtual account number may further include other restrictions (e.g., time restrictions, location restrictions, amount restrictions, etc.). Once generated, the VAN generator 142 may provide the virtual account number, expiration date, and CVV to the mobile device 110 and / or the authentication server 120. The VAN generator 142 and / or the authentication server 120 may further provide the account holder name, billing address, and / or shipping address to the mobile device 110. However, in some embodiments, the account holder name, shipping address, and / or billing address are stored locally by the mobile device 110. The VAN generator 142 and / or the authentication server 120 may provide the data to the mobile device 110 via any suitable method, such as via push notification, text message, email, web browser 115, etc.

[0020] Upon receipt by the mobile device 110, the virtual account number, expiration date, CVV, account holder name, billing address, and / or shipping address may be copied to the clipboard 114 of the OS 112. Doing so allows the user to paste the copied data into corresponding fields in the web browser 115. For example, the user may paste the account number into the account number field of a form in the web browser 115. In some embodiments, a notification including the expiration date and CVV may be output on the mobile device 110. The notification may further include the account holder name, billing address, and / or shipping address. The notification may be output after a predefined time (e.g., 5 seconds after the virtual account number is copied to the clipboard 114). The notification allows the user to copy the account holder name, billing address, shipping address, expiration date, and / or CVV directly to the clipboard 114 and paste them into corresponding fields in the form in the web browser 115.

[0021] Generally, clipboard 114 stores data that can be copied and / or pasted within OS 112. For example, clipboard 114 may locally store data for pasting into fields on mobile device 110, and a user may input / paste the data stored on clipboard 114 using commands and / or gestures available within OS 112. For example, by copying an account number to clipboard 114, a user may paste the account number into a corresponding form field using commands and / or gestures available within OS 112. Additionally, account application 113 may output a notification specifying an expiration date and CVV while the account number is being copied to clipboard 114. In doing so, a user may manually enter the expiration date and CVV into the corresponding form fields while the notification remains displayed. In some embodiments, account application 113 and / or OS 112 may also copy the expiration date, billing address, and / or CVV to clipboard 114 and paste the expiration date, billing address, and / or CVV into the corresponding form fields.

[0022] FIG. 1B illustrates an embodiment in which applet 103 of contactless card 101 generates an encrypted payload for verification by authentication application 123. As mentioned, when a user may encounter a payment form in web browser 115, in response, OS 112 and / or account application 113 may output a notification instructing the user to tap contactless card 101 to mobile device 110. In some embodiments, the user may select a form field related to the payment (e.g., an account number field, an expiration date field, and / or a CVV field), which brings focus to the form field. In such an embodiment, OS 112 and / or account application 113 may output a notification to tap contactless card 101 to mobile device 110 upon determining that a payment field has gained focus. As another example, OS 112 and / or account application 113 may determine that a form includes one or more payment fields. For example, in some embodiments, account application 113 and / or OS 112 read metadata of the form fields to determine the type of information. For example, the form field metadata may specify that the form field is associated with an account number field, an expiration date field, a CVV field, a shipping address field, and / or a billing address field. In some embodiments, information such as the 16-digit card number, the CVV, and the customer name may be available offline, while other information such as the address and the generated virtual number may not be available offline and require a network connection. In response, the account application 113 and / or the OS 112 may output a notification to tap the contactless card 101 to the mobile device 110.Thus, the account application 113 and / or the OS 112 may output a notification to tap the contactless card 101 to the mobile device 110 based on automatically determining that the form includes one or more payment fields and / or based on determining that a payment field has moved focus.

[0023] Upon tapping, applet 103 of contactless card 101 may generate encrypted data 105 based on private key 104. In one embodiment, when contactless card 101 is tapped to mobile device 110, contactless card 101 generates and transmits encrypted data 105 to mobile device 110. In other embodiments, when contactless card 101 is tapped to mobile device 110, account application 113 may instruct contactless card 101 to generate and transmit encrypted data 105 to mobile device 110. In some embodiments, encrypted data 105 may be a string of characters, such as "A1B2C3Z." Applet 103 may further determine URL 106. URL 106 may be directed to authentication server 120. In some embodiments, applet 103 dynamically generates URL 106. In other embodiments, applet 103 dynamically selects URL 106, which is one of multiple URLs 106 stored in memory 102. In some embodiments, URL 106 is a universal link that opens one or more pages of account application 113. Applet 103 may include the generated encrypted data 105 as a parameter of URL 106, thereby generating URL 108 that includes the encrypted data. For example, URL 106 may be "http: / / www.example.com / ". Thus, URL 108 that includes the encrypted data may be "http: / / www.example.com / ?A1B2C3Z".

[0024] In some embodiments, applet 103 may encode encrypted data 105 according to a URL-compatible encoding format before including it as a parameter of URL 106. For example, encrypted data 105 may be a string of binary data (e.g., 0s and 1s), which may not be URL-compatible. Therefore, applet 103 may encode encrypted data 105 into the American Standard Code for Information Interchange (ASCII) base64 encoding format. In doing so, it represents the binary encrypted data 105 in ASCII string format by converting it to a base-64 representation (e.g., "ABC123Z" in the previous example).

[0025] The contactless card 101 may then send the URL 108 containing the encrypted data to the mobile device 110. The account application 113 may then open to a corresponding page, where the account application 113 extracts the encrypted data 105 from the URL 108 containing the encrypted data. In some embodiments, if the user is not logged in to the account application 113, the account application 113 opens a login page where the user provides credentials to log in to the account before extracting the encrypted data 105. The account application 113 may then send the encrypted data 105 to the authentication server 120 over the network 130. In one embodiment, the account application 113 sends the encrypted data to the URL 106 generated by the contactless card 101. In other embodiments, the URL 108 containing the encrypted data causes the web browser 115 to open a new tab and follow the URL 108 containing the encrypted data, as described in more detail below. In such an embodiment, the URL 108 containing the encrypted data leads to the authentication application 123, which can extract the encrypted data 105 from the URL 108 containing the encrypted data.

[0026] Once received, the authentication application 123 may then attempt to decrypt the encrypted data 105 using the private key 104 associated with the contactless card 101. As noted, in some embodiments, the encrypted data 105 is encoded by the applet 103. In such embodiments, the authentication application 123 may decrypt the encrypted data 105 before the decryption is attempted. If the authentication application 123 is unable to decrypt the encrypted data to produce the expected result (e.g., a customer identifier for an account associated with the contactless card 101, etc.), the authentication application does not verify the encrypted data 105 and does not instruct the VAN generator 142 to generate a virtual account number. If the authentication application 123 is able to decrypt the encrypted data to produce the expected result (e.g., a customer identifier for an account associated with the contactless card 101, etc.), the authentication application verifies the encrypted data 105 and instructs the VAN generator 142 to generate a virtual account number, an expiration date, and a CVV value. As shown, the VAN generator 142 generates a virtual number 125 comprising a virtual account number, an expiration date, and a CVV value.

[0027] The virtual number 125 may then be transmitted over the network to the mobile device 110. Upon receipt, the account application 113 provides one or more elements of the virtual number 125 to the clipboard 114 of the OS 112. For example, the account application 113 may extract the virtual account number from the virtual number 125 and provide the extracted virtual account number to the clipboard 114, thereby copying the virtual account number to the clipboard 114. Doing so may allow the user to return to the web browser 115 and paste the virtual account number from the clipboard into the account number field of a form in the web browser 115.

[0028] 1C illustrates an embodiment in which applet 103 of contactless card 101 generates an identifier for verification by authentication application 123. As mentioned, when a user may encounter a payment form in web browser 115, in response, OS 112 and / or account application 113 may output a notification instructing the user to tap contactless card 101 to mobile device 110. In some embodiments, the user may select a form field related to the payment (e.g., an account number field, an expiration date field, and / or a CVV field), which brings focus to the form field. In such an embodiment, OS 112 and / or account application 113 may output a notification to tap contactless card 101 to mobile device 110 when it determines that the payment field has moved focus.

[0029] In response to the tap, the contactless card applet 103 determines an identifier to include as a parameter in the URL 106. In one embodiment, the applet 103 selects a predetermined number of characters of the account identifier 107 associated with the contactless card 101. For example, the applet 103 may select the last four digits of the account ID 107 and add the selected digits to the URL 106, thereby generating a URL 109 that includes the account ID. As mentioned, the URL 106 may be a universal link that opens one or more predefined pages of the account application 113.

[0030] Contactless card 101 may then send URL 109 containing the account ID to mobile device 110. Account application 113 may then open to a corresponding page, where account application 113 extracts the account ID 107 digits from URL 109 containing the account ID. In some embodiments, if the user is not logged in to account application 113, account application 113 opens a login page where the user provides credentials to log in to the account before extracting encrypted data 105. Account application 113 may then send the account ID 107 digits to authentication server 120 over network 130. Authentication application 123 may then verify account ID 107. For example, authentication application 123 may determine whether the account ID 107 digits match the corresponding digits of the account identifier of the account associated with contactless card 101 in account data 124. In such an embodiment, the account application 113 may provide data (e.g., an account token, a username associated with the account currently logged in to the account application 113, etc.) that allows the authentication application 123 to verify that the account ID 107 is associated with an account in the account data 124.

[0031] If the authentication application 123 verifies the account ID 107, the authentication application 123 instructs the VAN generator 142 to generate a virtual account number. Otherwise, a virtual account number is not generated in response to tapping the contactless card 101. In one embodiment, if the authentication application 123 can verify the account, the authentication application 123 may cause the account application 113 to log in to the corresponding account without requiring user input.

[0032] As shown, after verification of account ID 107 by authentication application 123, VAN generator 142 generates virtual number 126 comprising a virtual account number, an expiration date, and a CVV value. Virtual number 126 may then be transmitted over the network to mobile device 110. Upon receipt, account application 113 provides one or more elements of virtual number 126 to clipboard 114 of OS 112. For example, account application 113 may extract the virtual account number from virtual number 126 and provide the extracted virtual account number to clipboard 114, thereby copying the virtual account number to clipboard 114. Doing so allows the user to return to web browser 115 and paste the virtual account number from the clipboard into an account number field of a form in web browser 115. The expiration date and / or CVV may similarly be extracted by account application 113 and provided to clipboard 114. Doing so allows the user to paste the expiration date and / or CVV from clipboard 114 into corresponding fields of a form in web browser 115.

[0033] As mentioned, VAN generator 142 and / or authentication server 120 may further provide the account holder name, billing address, and / or shipping address to mobile device 110. However, in some embodiments, the account holder name, shipping address, and / or billing address are stored locally by account application 113 and / or mobile device 110. Accordingly, in such embodiments, account application 113 may provide the account holder name, billing address, and / or shipping address to clipboard 114. In doing so, the user may paste the account holder name, shipping address, and / or billing address from the clipboard into the account number field of a form in web browser 115.

[0034] FIG. 2A is a schematic diagram 200 illustrating an exemplary embodiment of tapping contactless card 101 to generate a virtual account number and copying the virtual account number to clipboard 114. As shown, web browser 115 outputs a form including form fields 201-203 (e.g., a payment form), where field 201 corresponds to an account number field, field 202 corresponds to an expiration date field, and field 203 corresponds to a CVV field. As shown, notification 204 is output by OS 112 and / or account application 113 when account number field 201 gains focus (e.g., is selected by the user). Notification 204 instructs the user to tap contactless card 101 to mobile device 110. In one embodiment, the user selects notification 204 before tapping contactless card 101 to mobile device 110.

[0035] As described above, when the contactless card 101 is tapped to the mobile device 110, the account application 113 sends instructions to the contactless card 101 via the card reader 118 (e.g., via NFC, Bluetooth, RFID, and / or EMV protocols, etc.). The instructions may specify generating a URL containing encrypted data. As noted, the applet 103 may use the contactless card's private key 104 to generate the URL containing the encrypted data. The applet 103 may then generate a URL containing the encrypted data as a parameter of the URL and send the URL containing the encrypted data to the mobile device 110. Once received, the URL containing the encrypted data may open a page of the account application 113.

[0036] FIG. 2B is a schematic diagram 210 illustrating an embodiment in which account application 113 is opened in response to receiving a URL containing encrypted data from contactless card 101. As shown, account application 113 requires the user to provide a fingerprint to log in to their account. In other embodiments, the user may log in to their account using FaceID, other biometric identifiers, a username / password, or any other type of credentials. In some embodiments, user login is not required. When the user logs in to their account, account application 113 sends the encrypted data to authentication application 123. Once verified (e.g., decrypted), authentication application 123 causes VAN generator 142 to generate a virtual account number, expiration date, and CVV associated with contactless card 101. VAN generator 142 may then send the virtual account number, expiration date, and CVV to mobile device 110. As shown, once received, account application 113 copies the virtual account number to OS clipboard 114. In one embodiment, based on determining that the account number field has focus, the account application 113 copies the virtual account number to the clipboard 114. The account application 113 may then generate and output a link 205 (or other graphical object) that allows the user to return to the previous application (e.g., web browser 115).

[0037] FIG. 2C is a schematic diagram 220 illustrating an embodiment in which a user selects link 205 and returns to web browser 115. As shown, notification 206 may enable a user to paste a virtual account number into form field 201 (e.g., after a user long-presses form field 201). When selected, OS 112 may paste the virtual card number from clipboard 114 into form field 201. FIG. 2D is a schematic diagram 230 illustrating an embodiment in which a virtual account number has been pasted into form field 201. As shown, OS 112 and / or account application 113 may output notification 207. Notification 207 includes the expiration date and CVV associated with the virtual account number received from VAN generator 142. As shown, notification 207 includes link 208 that, when selected, copies the expiration date to clipboard 114. Similarly, notification 207 includes link 209 that, when selected, copies the CVV to clipboard 114. Other graphic objects may be used in place of links. In some embodiments, the output of notification 207 is timed to facilitate easy copying / pasting of the expiration date and CVV. For example, account application 113 may start a timer in response to receiving the virtual account number, expiration date, and CVV from VAN generator 142. As another example, account application 113 may start a timer when the user selects link 205 to return to web browser 115. When the timer exceeds a predefined time threshold (e.g., 5 seconds, 10 seconds, etc.), notification 207 is generated and output. This allows the user time to paste the account number into form field 201 without being distracted by notification 207, while simultaneously providing timely notification 207 to facilitate copying and / or pasting of the expiration date and / or CVV.

[0038] FIG. 3A is a schematic diagram 300 illustrating an exemplary embodiment of tapping contactless card 101 to generate a virtual account number and copying the virtual account number to clipboard 114. As shown, web browser 115 has loaded a website from URL 305. The website may be in a first tab of web browser 115 and may include a form (e.g., a payment form) having form fields 301-303. Field 301 corresponds to an account number field, field 302 corresponds to an expiration date field, and field 303 corresponds to a CVV field. As shown, notification 304 is output by OS 112 and / or account application 113 when account number field 301 gains focus (e.g., is selected by the user). Notification 304 instructs the user to tap contactless card 101 to mobile device 110. In one embodiment, the user selects notification 304 before tapping contactless card 101 to mobile device 110.

[0039] To determine which field has moved focus, account application 113 and / or OS 112 may parse HyperText Markup Language (HTML) attributes of account number field 301 to determine that account number field 301 has moved focus. Additionally, account application 113 and / or OS 112 may parse metadata of account number field 301 to determine that field 301 is associated with an account number. For example, account application 113 and / or OS 112 may determine, based on the metadata, that account number field 301 is configured to receive 16 characters as input. As another example, the metadata may specify a name for form field 301 similar to a name associated with the account number field (e.g., “accountnumber,” “account_number,” etc.).

[0040] As mentioned above, when contactless card 101 is tapped to mobile device 110, account application 113 sends instructions to contactless card 101 via card reader 118 (e.g., via NFC, Bluetooth, RFID, and / or EMV protocols, etc.). The instructions may specify generating a URL including encrypted data. However, in some embodiments, contactless card 101 causes applet 103 to generate a URL including encrypted data without the need for instructions received from mobile device 110. As mentioned, applet 103 may generate a URL including encrypted data using contactless card 101's private key 104. In the example shown in FIG. 3A , applet 103 may use private key 104 to generate an exemplary encrypted string of “ABCD123XYZ.” Applet 103 may then generate a URL to authentication application 123, where the URL includes the encrypted data as a parameter of the URL. 3A, the URL containing the encrypted data may be "https: / / / www.example.com / auth.html?ABCD123XYZ." Applet 103 may then send the URL containing the encrypted data to mobile device 110.

[0041] FIG. 3B is a schematic diagram 310 illustrating an embodiment in which a new tab in web browser 115 is opened in response to receiving a URL containing encrypted data from contactless card 101. As shown, web browser URL 306 is directed to the URL containing the encrypted data generated by applet 103, i.e., “https: / / / www.example.com / auth.html?ABCD123XYZ.” Authentication application 123 may decrypt the encrypted data using private key 104 to verify the encrypted data. Authentication application 123 may then instruct VAN generator 142 to generate a virtual account number, expiration date, and CVV. However, in some embodiments, VAN generator 142 generates a virtual account number and selects an existing expiration date and / or CVV (e.g., from account data 124). In some such examples, the existing expiration date and / or CVV may be the expiration date and / or CVV of contactless card 101 or another card associated with an account in account data 124.

[0042] 3B, the tab of web browser 115 includes a virtual account number, expiration date, and CVV. In one embodiment, VAN generator 142 provides the generated data to authentication application 123. In doing so, authentication application 123 may output the data to web browser 115. Other techniques may be used to redirect web browser 115 to VAN generator 142, which may output the virtual account number, expiration date, and CVV to web browser 115. As shown, web browser 115 includes a notification to the user to close the tab of web browser 115 once the user has copied / pasted the virtual account number, expiration date, and CVV.

[0043] FIG. 3C is a schematic diagram 320 illustrating an embodiment in which VAN generator 142 and / or authentication application 123 send a push notification 307 to a mobile device that includes a virtual account number, expiration date, and CVV generated by VAN generator 142. The virtual account number, expiration date, and CVV may be generated based on any of the techniques described herein. In one embodiment, notification 307 is generated instead of (or in addition to) outputting the virtual account number, expiration date, and CVV in web browser 115 of FIG. 3B. As shown, notification 307 includes a virtual account number, expiration date, and CVV. As shown, notification 307 includes a link 308 that, when selected, copies the virtual account number to clipboard 114. Similarly, notification 307 includes a link 309 that, when selected, copies the expiration date to clipboard 114. Similarly, notification 307 includes a link 321 that, when selected, copies the CVV to clipboard 114. Other graphic objects may be used in place of links. In some embodiments, the output of notification 307 is timed to facilitate easy copy / paste of the expiration date and CVV, for example, upon expiration of a timer as described above.

[0044] FIG. 3D is a schematic diagram 330 illustrating an embodiment in which VAN generator 142 and / or authentication application 123 send a text message notification 311 to a mobile device that includes a virtual account number, expiration date, and CVV generated by VAN generator 142. The virtual account number, expiration date, and CVV may be generated based on any of the techniques described herein. In one embodiment, text message notification 311 is generated instead of (or in addition to) outputting the virtual account number, expiration date, and CVV in web browser 115 of FIG. 3B. As shown, text message notification 311 includes the virtual account number, expiration date, and CVV. As shown, text message notification 311 includes link 313 that, when selected, copies the virtual account number to clipboard 114. Similarly, text message notification 311 includes link 314 that, when selected, copies the expiration date to clipboard 114. Similarly, text message notification 311 includes link 315 that, when selected, copies the CVV to clipboard 114. Other graphic objects may be used in place of links. Additionally, as shown, text message 311 includes autofill link 312, which, when selected, autofills the virtual account number, expiration date, and CVV into form fields 301-303, respectively. In at least one embodiment, an OS autofill service (not shown) autofills the account number, expiration date, and CVV into form fields 301-303. In some embodiments, the autofill service detects form fields (e.g., form fields 301-303), detects content in a notification (e.g., notification 311) that has a type that matches the type of the detected form field, and provides the parsed content from the notification as keyboard autofill suggestions. In doing so, the autofill service may automatically populate the corresponding form fields from the notification.

[0045] 2A-2D and 3A-3D, the account holder name, billing address, and / or shipping address may be copied to clipboard 114 and pasted into corresponding form fields in the web browser. As mentioned, the name, billing address, and / or shipping address may be stored locally on mobile device 110 and / or received from VAN generator 142 and / or authentication server 120.

[0046] 4 illustrates an embodiment of a logic flow 400. The logic flow 400 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 400 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. In this context, the embodiments are not limited.

[0047] As shown, logic flow 400 begins at block 405, where the account application 113 and / or OS 112 determines that a payment field on a form has shifted focus. The form may be in a web browser 115, account application 113, or other application. For example, a user may tap on a payment field on the form to give focus to the payment field. As another example, a user may select the payment field on the form using a mouse and / or keyboard. More generally, any technique may be used to give focus to the payment field, including programmatically generated focus. For example, the payment field may shift focus based on the HTML “focus()” method. As another example, the payment field may automatically shift focus when the form loads, for example, based on the “autofocus” HTML attribute applied to the payment field in source code. The payment fields may include one or more of a name field, an account number field, an expiration date field, a shipping address field, a billing address field, and / or a CVV field. When the payment field moves focus, account application 113 and / or OS 112 may output a notification specifying the user to tap contactless card 101 to mobile device 110. In some embodiments, the notification may be generated based on a determination that the form includes one or more payment fields, without requiring a determination that a form field has moved focus. The notification may include a GUI that provides an example of how to tap contactless card 101 to mobile device 110. At block 410, the user taps contactless card 101 to the mobile device, causing contactless card 101 to generate and transmit encrypted data as part of a URL. Account application 113 may send instructions to contactless card 101 via NFC card reader 118 specifying the generation and transmission of encrypted data as part of a URL.

[0048] At block 415, the contactless card applet 103 generates encrypted data using the private key 104 and an encryption algorithm. The applet 103 may then include the encrypted data as a parameter in a URL. The URL may be a universal link URL that, when followed, causes a predefined page of the account application 113 to be at least partially opened. At block 420, the applet 103 may send the URL including the encrypted data to the mobile device 110. At block 425, the account application 113 is opened to a page corresponding to the universal link URL received from the contactless card 101. In some embodiments, the account application 113 may request that the user log in to their account (if they are not already logged in). In some such embodiments, the URL may be directed to an external authentication website configured to receive the credentials necessary to log the user into their account. As another example, the URL may be directed to an authentication page of the account application 113 that receives the credentials necessary to log the user into their account.

[0049] At block 430, the account application 113 extracts the encrypted data from the URL and sends it to the authentication application 123 of the authentication server 120 for verification. If the encrypted data is encoded, the account application 113 and / or the authentication application 123 may decrypt the encrypted data. At block 435, the authentication application 123 decrypts the encrypted data using a private key in the server 120's memory to verify the encrypted data. At block 440, the authentication application 123 sends instructions to the VAN generator 142 specifying that a virtual account number, expiration date, and CVV be generated. The authentication application 123 may further specify one or more restrictions on the virtual account number (e.g., must be used within one hour, be usable only at a specified merchant's website, etc.). At block 445, the VAN generator 142 generates the virtual account number, expiration date, and CVV. At block 450, the VAN generator 142 sends the virtual account number, expiration date, and CVV to the mobile device 110. VAN generator 142 may further send the account holder name, billing address, and / or shipping address to mobile device 110, which may be received by VAN generator 142 from authentication server 120. For example, VAN generator 142 may generate a push notification, a text message, or one or more data packets that are processed by account application 113 to receive the virtual account number, expiration date, and CVV.

[0050] In block 455, the account application 113 copies the virtual account number to the OS clipboard 114. The account application 113 may also start a timer. In block 460, the user may return to the web browser 115 and paste the virtual account number stored in the clipboard 114 into a payment field on the form. In block 465, the account application 113 outputs a notification specifying the account holder name, billing address, shipping address, expiration date, and / or CVV after the timer set in block 455 has elapsed (or after a threshold time has been exceeded). This allows the user to copy and paste the account holder name, billing address, shipping address, expiration date, and CVV into the corresponding fields on the form.

[0051] 5 illustrates an embodiment of a logic flow 500. The logic flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 500 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. In this context, the embodiments are not limited.

[0052] As shown, the logic flow 500 begins at block 505, where the account application 113 and / or OS 112 determines that a payment field on a form has shifted focus. The form may be in a web browser 115, an account application 113, or another application. For example, a user may tap on a payment field on the form to give focus to the payment field. As another example, a user may select the payment field on the form using a mouse and / or keyboard. More generally, any technique may be used to give focus to the payment field, including programmatically generated focus. For example, the payment field may shift focus based on the HTML “focus()” method. As another example, the payment field may automatically shift focus when the form loads, for example, based on the “autofocus” HTML attribute applied to the payment field in source code. The payment fields may include one or more of a name field, an account number field, an expiration date field, a shipping address field, a billing address field, and / or a CVV field. When the payment field moves focus, account application 113 and / or OS 112 may output a notification specifying the user to tap contactless card 101 to mobile device 110. In some embodiments, the notification may be generated based on a determination that the form includes one or more payment fields. The notification may include a GUI showing an example of how to tap contactless card 101 to mobile device 110. At block 510, the user taps contactless card 101 to the mobile device, causing contactless card 101 to generate and transmit data as part of a URL. Account application 113 may send instructions to contactless card 101 via NFC card reader 118 specifying to generate and transmit data as part of a URL.

[0053] At block 515, the contactless card applet 103 generates a URL that includes the account identifier (or a portion thereof) as a parameter of the URL. The URL may be a universal link URL that, when followed, causes a predefined page of the account application 113 to be opened at least in part. At block 520, the applet 103 may send the URL including the account identifier to the mobile device 110. At block 525, the account application 113 is opened to a page that corresponds to the universal link URL received from the contactless card 101. In some embodiments, the account application 113 may request that the user log in to their account (if they are not already logged in).

[0054] At block 530, the account application 113 extracts the account identifier from the URL and sends the account identifier to the authentication application 123 of the authentication server 120 for validation. At block 535, the authentication application 123 validates the account identifier (e.g., by determining whether the received account identifier matches an expected and / or known account identifier value). At block 540, the authentication application 123 sends instructions to the VAN generator 142 specifying that a virtual account number, expiration date, and CVV be generated. The authentication application 123 may further specify one or more restrictions on the virtual account number (e.g., must be used within one hour, be usable only at a specified merchant's website, etc.). At block 545, the VAN generator 142 generates the virtual account number, expiration date, and CVV. At block 550, the VAN generator 142 sends the virtual account number, expiration date, and CVV to the mobile device 110. VAN generator 142 may further send the account holder name, billing address, and / or shipping address to mobile device 110, which may be received by VAN generator 142 from authentication server 120. For example, VAN generator 142 may generate a push notification, a text message, or one or more data packets that are processed by account application 113 to receive the virtual account number, expiration date, and CVV.

[0055] In block 555, the account application 113 copies the virtual account number to the OS clipboard 114. The account application 113 may also start a timer. In block 560, the user may return to the web browser 115 and paste the virtual account number stored in the clipboard 114 into a payment field on the form. In block 565, the account application 113 outputs a notification specifying the account holder name, billing address, shipping address, expiration date, and / or CVV after the timer set in block 555 has elapsed (or after a threshold time has been exceeded). This allows the user to copy and paste the account holder name, billing address, shipping address, expiration date, and CVV into the corresponding fields on the form.

[0056] 6 illustrates an embodiment of a logic flow 600. The logic flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 600 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. In this context, the embodiments are not limited.

[0057] As shown, the logic flow 600 begins at block 605, where the account application 113 and / or OS 112 determines that a payment field in a form has shifted focus. The form may be in a first tab of the web browser 115. For example, a user may tap on a payment field in the form to give focus to the payment field. As another example, a user may select the payment field in the form using a mouse and / or keyboard. More generally, any technique may be used to give focus to the payment field, including programmatically generated focus. For example, the payment field may shift focus based on the HTML “focus()” method. As another example, the payment field may automatically shift focus when the form loads, for example, based on the “autofocus” HTML attribute applied to the payment field in source code. The payment fields may include one or more of a name field, an account number field, an expiration date field, a shipping address field, a billing address field, and / or a CVV field. When the payment field moves focus, account application 113 and / or OS 112 may output a notification specifying the user to tap contactless card 101 to mobile device 110. In some embodiments, the notification may be generated based on a determination that the form includes one or more payment fields. The notification may include a GUI showing an example of how to tap contactless card 101 to mobile device 110. At block 610, the user taps contactless card 101 to the mobile device, causing contactless card 101 to generate and transmit encrypted data as part of a URL. Account application 113 may send instructions to contactless card 101 via NFC card reader 118 specifying the generation and transmission of encrypted data as part of a URL.

[0058] At block 615, the contactless card applet 103 generates encrypted data using the private key 104 and an encryption algorithm. The applet 103 may then include the encrypted data as a parameter in a URL. The URL may be to the authentication application 123 and / or authentication server 120, which causes a second tab to open in the web browser 115. At block 620, the applet 103 may send the URL containing the encrypted data to the mobile device 110. At block 625, the web browser 115 opens the second tab and loads the URL containing the encrypted data.

[0059] At block 630, authentication application 123 extracts the encrypted data from the URL and decrypts the encrypted data using the private key in server 120's memory to verify the encrypted data. At block 635, authentication application 123 sends instructions to VAN generator 142 specifying that a virtual account number, expiration date, and CVV be generated. Authentication application 123 may further specify one or more restrictions on the virtual account number (e.g., must be used within one hour, may be usable only at a specified merchant's website, etc.). At block 640, VAN generator 142 generates the virtual account number, expiration date, and CVV.

[0060] At block 645, the VAN generator 142 sends a push notification to the mobile device 110 comprising the virtual account number, expiration date, and CVV. The VAN generator 142 may further send the account holder name, billing address, and / or shipping address as part of the push notification. The mobile device 110 may then output the received push notification. Additionally and / or alternatively, at block 650, the VAN generator 142 sends a text message to the mobile device 110 comprising the virtual account number, expiration date, and CVV. The mobile device 110 may then output a notification corresponding to the text message, the notification displaying the virtual account number, expiration date, and CVV. Additionally and / or alternatively, at block 655, the virtual account number, expiration date, CVV, account holder name, billing address, and / or shipping address are optionally output for display in a second tab of the web browser 115. At block 660, one or more of the virtual account number, expiration date, CVV, account holder name, billing address, and / or shipping address may be copied from one or more of the push notification, text message notification, and second browser tab and pasted into a form in the first browser tab. Additionally and / or alternatively, the virtual account number, expiration date, CVV, account holder name, billing address, and / or shipping address may be auto-filled into the form.

[0061] 7 illustrates an embodiment of an exemplary computing architecture 700 comprising a computing system 702 that may be suitable for implementing various embodiments as described above. In various embodiments, the computing architecture 700 may comprise or be implemented as part of an electronic device. In some embodiments, the computing architecture 700 may be representative of a system implementing one or more components of the system 100, for example. In some embodiments, the computing system 702 may be representative of the mobile device 110, the authentication server 120, and / or the virtual account number server 140 of the system 100, for example. The embodiments are not limited in this context. More generally, the computing architecture 700 is configured to implement all of the logic, applications, systems, methods, apparatus, and functions described herein with reference to FIGS. 1-6.

[0062] As used in this application, the terms “system,” “component,” and “module” are intended to refer to any computer-related entity: hardware, a combination of hardware and software, software, or software in execution, an example of which is provided by exemplary computing architecture 700. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a server and the server may be a component. One or more components may reside within a process and / or thread of execution, and components may be localized on one computer and / or distributed among two or more computers. Furthermore, components may be communicatively coupled to each other and coordinate operations by various types of communication media. Coordination may include unidirectional or bidirectional exchange of information. For example, components may communicate information in the form of signals communicated over the communication media. The information may be embodied as signals assigned to various signal lines. In such assignments, each message is a signal. However, further embodiments may alternatively use data messages. Such data messages may be transmitted over a variety of connections, examples of which include parallel interfaces, serial interfaces, and bus interfaces.

[0063] Computing system 702 includes various typical computing elements, such as one or more processors, multi-core processors, co-processors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to implementation by computing system 702.

[0064] 7, computing system 702 includes a processor 704, a system memory 706, and a system bus 708. Processor 704 may be any of a variety of commercially available computer processors, including, but not limited to, AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2) Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multi-processor architectures may also be used as processor 704.

[0065] The system bus 708 provides an interface from the system memory 706 to system components including, but not limited to, the processor 704. The system bus 708 may be any of several types of bus structures that may further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures. Interface adapters may connect to the system bus 708 through a slot architecture. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, (Extended) Industry Standard Architecture ((E)ISA), MicroChannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Expansion) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), etc.

[0066] The system memory 706 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random-access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drive (SSD)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in FIG. 7, the system memory 706 may include non-volatile memory 710 and / or volatile memory 712. The non-volatile memory 710 may store a basic input / output system (BIOS).

[0067] Computing system 702 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 714, a magnetic floppy disk drive (FDD) 716 that reads from or writes to a removable magnetic disk 718, and an optical disk drive 720 that reads from or writes to a removable optical disk 722 (e.g., a CD-ROM or DVD). HDD 714, FDD 716, and optical disk drive 720 may be connected to system bus 708 by an HDD interface 724, an FDD interface 726, and an optical drive interface 728, respectively. HDD interface 724 for external drive implementations may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies. Computing system 702 is generally configured to implement all of the logic, systems, methods, devices, and functions described herein with reference to FIGS. 1-6.

[0068] The drives and associated computer-readable media provide volatile and / or nonvolatile storage of data, data structures, computer-executable instructions, etc. For example, a number of program modules may be stored on the drives and memory units 710, 712, including an operating system 730, one or more application programs 732, other program modules 734, and program data 736. In one embodiment, the one or more application programs 732, other program modules 734, and program data 736 may include, for example, various applications and / or components of system 100, such as operating system 112, account application 113, clipboard 114, web browser 115, authentication application 123, and VAN generator 142.

[0069] A user may enter commands and information into the computing system 702 through one or more wired / wireless input devices, for example, a keyboard 738 and a pointing device such as a mouse 740. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, game pad, stylus pen, card reader, dongle, fingerprint reader, grab, graphics tablet, joystick, keyboard, retina reader, touch screen (e.g., capacitive, resistive, etc.), trackball, track pad, sensor, stylus, etc. These and other input devices are often connected to the processor 704 through an input device interface 742 coupled to the system bus 708, but may be connected by other interfaces, such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, etc.

[0070] A monitor 744 or other type of display device is also connected to the system bus 708 via an interface, such as a video adapter 746. The monitor 744 may be internal or external to the computing system 702. In addition to the monitor 744, computers typically include other peripheral output devices, such as speakers, printers, etc.

[0071] The computing system 702 may operate in a networked environment using logical connections via wired and / or wireless communications to one or more remote computers, such as a remote computer 748. The remote computer 748 may be a workstation, a server computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other common network node and typically includes many or all of the elements described relative to the computing system 702, although for simplicity, only a memory / storage device 750 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 752 and / or larger networks, e.g., a wide area network (WAN) 754. Such LAN and WAN networking environments are commonplace in offices and businesses, facilitating enterprise-wide computer networks such as intranets. All of these may connect to a global communications network, e.g., the Internet. In an embodiment, the network 130 of FIG. 1 is one or more of the LAN 752 and the WAN 754.

[0072] When used in a LAN networking environment, the computing system 702 is connected to the LAN 752 through a wired and / or wireless communication network interface or adapter 756. The adapter 756 may facilitate wired and / or wireless communication to the LAN 752, which may include a wireless access point disposed thereon for communicating with the wireless functionality of the adapter 756.

[0073] When used in a WAN networking environment, the computing system 702 may include a modem 758 or have other means for establishing communications over the WAN 754, such as connected to a communications server on the WAN 754 or via the Internet. The modem 758 may be internal or external, a wired and / or wireless device, and connects to the system bus 708 via the input device interface 742. In a networked environment, program modules depicted relative to the computing system 702, or portions thereof, may be stored in the remote memory / storage device 750. It will be appreciated that the network connections shown are exemplary and other means of establishing a communications link between computers may be used.

[0074] The computing system 702 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operatively arranged for wireless communication (e.g., IEEE 802.16 wireless modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, Bluetooth® wireless technologies, and the like. Thus, communication can be in a predefined structure, similar to a traditional network, or simply ad hoc communication between at least two devices. Wi-Fi networks use radio technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and high-speed wireless connectivity. Wi-Fi networks can be used to connect computers to each other, to the Internet, or to wired networks (using IEEE 802.3-related media and functions).

[0075] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include a processor, a microprocessor, a circuit, a circuit element (e.g., a transistor, a resistor, a capacitor, an inductor, etc.), an integrated circuit, an application specific integrated circuit (ASIC), a programmable logic device (PLD), a digital signal processor (DSP), a field programmable gate array (FPGA), a logic gate, a register, a semiconductor device, a chip, a microchip, a chipset, etc. Examples of software may include a software component, a program, an application, a computer program, an application program, a system program, a machine program, an operating system software, a middleware, a firmware, a software module, a routine, a subroutine, a function, a method, a procedure, a software interface, an application program interface (API), an instruction set, a computational code, a computer code, a code segment, a computer code segment, a word, a value, a symbol, or any combination thereof. The decision whether an embodiment is implemented using hardware and / or software elements may vary according to any number of factors, such as required computational speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.

[0076] One or more aspects of at least one embodiment may be implemented by representative instructions stored on a machine-readable medium that represent various logic within a processor, which, when read by a machine, causes the machine to manufacture logic that performs the techniques described herein. Such representations, known as “IP cores,” are stored on tangible machine-readable media and provided to various customers or manufacturing facilities for loading into manufacturing machines that create the logic or processors. Some embodiments may be implemented using, for example, a machine-readable medium or article that may store instructions or sets of instructions that, when executed by the machine, cause the machine to perform methods and / or operations in accordance with the embodiments. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. A machine-readable medium or article may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewriteable (CD-RW), optical disk, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tape, cassette, etc. The instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.

[0077] The foregoing description of exemplary embodiments has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the disclosure to the precise form disclosed. Many modifications and variations are possible in light of this disclosure. It is intended that the scope of the disclosure be limited not by this detailed description, but by the appended claims. Future applications claiming priority to this application may claim the disclosed subject matter differently and may generally include any set of one or more limitations as variously disclosed or demonstrated herein.

Claims

1. a processor circuit; a memory for storing instructions, The instructions, when executed by the processor circuit, cause the processor circuit to: a web browser executed on the processor circuit outputting a form with payment fields; receiving, from a communication interface of a contactless card, a uniform resource locator (URL) comprising encrypted data generated by the contactless card based at least in part on a private key of the contactless card stored in a memory of the contactless card; an application executing on the processor circuit transmitting the encrypted data to an authentication server, the authentication server verifying the encrypted data by decrypting the encrypted data based at least in part on a private key for the contactless card stored in a memory of the authentication server; receiving, by the application, a virtual account number from a virtual account number server based on verification of the encrypted data by the authentication server; the application receiving an expiration date associated with the virtual account number and a card verification value (CVV) associated with the virtual account number; the application copying the virtual account number to a clipboard of an operating system (OS) running on the processor circuit; the OS pasting the virtual account number from the clipboard into the payment field of the form in the web browser; the OS outputting a notification comprising the expiration date and the CVV associated with the virtual account number; Execute Device.

2. the memory storing instructions; The instructions, when executed by the processor circuit, cause the processor circuit to: the OS opening an application in response to receiving the URL, the URL comprising a Universal Link URL; and receiving the virtual account number, the expiration date, the CVV, and an account billing address from the virtual account number server, wherein the expiration date and the CVV comprise one or more of: (i) an expiration date and CVV generated by the virtual account number server; and (ii) an expiration date and CVV of the contactless card received from an account database; receiving an input from the application designating a return to the web browser, and outputting the web browser on a display of the device based on the received input; outputting the web browser on a display of the device based on the received input; Execute 10. The apparatus of claim 1.

3. the memory storing instructions; The instructions, when executed by the processor circuit, cause the processor circuit to: receiving, by the OS, a notification input specifying that the expiration date be copied to the clipboard; the OS copying the expiration date to the clipboard in response to the input received in the notification; the OS pasting the expiration date into an expiration date field of the form in the web browser; Execute 10. The apparatus of claim 1.

4. the memory storing instructions; The instructions, when executed by the processor circuit, cause the processor circuit to: receiving, by the OS, a notification input specifying that the CVV be copied to the clipboard; The OS copies the CVV to the clipboard in response to an input specifying that the CVV should be copied to the clipboard; the OS pasting the CVV into a CVV field of the form in the web browser; receiving, by the OS, a notification input specifying that the billing address be copied to the clipboard; copying the billing address to the clipboard by the OS in response to an input specifying that the billing address should be copied to the clipboard; the OS pasting the billing address into a billing address field of the form in the web browser; Execute 4. The apparatus of claim 3.

5. the memory storing instructions; The instructions, when executed by the processor circuit, cause the processor circuit to: the application starting a timer responsive to receiving the virtual account number, the expiration date, the CVV, and the billing address; upon determining that the timer has exceeded a threshold, causing the OS to generate and output the notification; Execute 5. The apparatus of claim 4.

6. the memory storing instructions; The instructions, when executed by the processor circuit, cause the processor circuit to: the application extracting the encrypted data from the URL, and an applet executing in the contactless card's memory generating the URL and the encrypted data; Execute 10. The apparatus of claim 1.

7. 10. The device of claim 1, wherein the application authenticates access to an account associated with the contactless card based on one or more of: (i) a received username and password; (ii) a received biometric credential; and (iii) an indication of validation of the encrypted data received from the authentication server; and wherein the communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth, and Wi-Fi.

8. a web browser executing on a processor circuit of the computing device outputting a first browser tab with a form having payment fields; receiving, from a communication interface of a contactless card, a uniform resource locator (URL) of an authentication server, the URL comprising encrypted data generated by the contactless card based at least in part on a private key of the contactless card stored in a memory of the contactless card; a second browser tab of the web browser accessing the URL of the authentication server, wherein the authentication server verifies the encrypted data of the URL by decrypting the encrypted data based at least in part on a private key of the contactless card stored in a memory of the authentication server; receiving a virtual account number generated by a virtual account number server based on verification of the encrypted data by the authentication server; receiving an expiration date associated with the virtual account number and a card verification value (CVV) associated with the virtual account number; copying the virtual account number to a clipboard of an operating system (OS) running on the processor circuit; the OS pasting the virtual account number from the clipboard into the payment field of the form in the first browser tab of the web browser; A method comprising:

9. 10. The method of claim 8, wherein the virtual account number, the expiration date, the CVV, and the billing address are received from the virtual account number server via one or more of: (i) the second browser tab; (ii) a push notification received by an application running on the processor circuit; and (iii) a text message.

10. The method comprises: receiving, by the OS, an input specifying that the expiration date should be copied to the clipboard; the OS copying the expiration date to the clipboard in response to the received input; the OS pasting the expiration date into an expiration date field of the form in the first browser tab of the web browser; 10. The method of claim 9, further comprising:

11. The method comprises: receiving an input by the OS specifying that the CVV be copied to the clipboard; the OS copying the CVV to the clipboard in response to the received input; the OS pasting the CVV into a CVV field of the form in the first browser tab of the web browser; receiving, by the OS, a notification input specifying that the billing address be copied to the clipboard; copying the billing address to the clipboard by the OS in response to an input specifying that the billing address should be copied to the clipboard; the OS pasting the billing address into a billing address field of the form in the web browser; 10. The method of claim 9, further comprising:

12. The method comprises: the OS outputs a notification comprising the expiration date, the CVV, and a billing address associated with the virtual account number; The method of claim 8 further comprising:

13. 9. The method of claim 8, wherein the authentication server provides instructions for verifying the encrypted data to the virtual account number server, wherein the expiration date and the CVV comprise one or more of: (i) an expiration date and CVV generated by the virtual account number server; and (ii) an expiration date and CVV of the contactless card received from an account database, and wherein the virtual account number server provides the virtual account number, the expiration date, and the CVV to one or more of the computing device and the authentication server.

14. The communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth, and Wi-Fi, and the method includes: the OS outputs a notification designating that the second browser tab be closed; The method of claim 8 further comprising:

15. A non-transitory computer-readable storage medium having computer-readable program code embodied therein, the computer-readable program code being executable by a processor circuit, the computer-readable program code causing the processor circuit to: a web browser executed on the processor circuit outputting a form with payment fields; receiving, by an application executing on the processor circuit, from a communication interface of a contactless card, a uniform resource locator (URL) comprising an identifier of the contactless card; the application authenticating an account associated with the contactless card; The application transmitting the identifier of the account to an authentication server, the authentication server verifying the identifier of the contactless card and the account authenticated with the application; receiving, by the application, a virtual account number from a virtual account number server based on verification of the encrypted data by the authentication server; the application receiving an expiration date associated with the virtual account number and a card verification value (CVV) associated with the virtual account number; the application copying the virtual account number to a clipboard of an operating system (OS) running on the processor circuit; the OS pasting the virtual account number from the clipboard into the payment field of the form in the web browser; the OS outputting a notification comprising the expiration date and the CVV associated with the virtual account number; A non-transitory computer-readable storage medium that causes the

16. The non-transitory computer-readable storage medium includes computer-readable program code executable by the processor circuit, the computer-readable program code including: the OS opening an application responsive to receiving the URL, the URL comprising a Universal Link URL; and receiving the virtual account number, the expiration date, the CVV, and an account billing address from the virtual account number server, wherein the expiration date and the CVV comprise one or more of: (i) an expiration date and CVV generated by the virtual account number server; and (ii) an expiration date and CVV of the contactless card received from an account database; receiving an input from the application designating a return to the web browser, and outputting the web browser on a display of the device based on the received input; outputting the web browser on a display of a computing device based on the received input; 16. The non-transitory computer-readable storage medium of claim 15, further comprising computer-readable program code for causing the execution of:

17. The non-transitory computer-readable storage medium includes computer-readable program code executable by the processor circuit, the computer-readable program code including: the application starting a timer responsive to receiving the virtual account number, the expiration date, and the CVV; upon determining that the timer has exceeded a threshold, causing the OS to generate and output the notification; 16. The non-transitory computer-readable storage medium of claim 15, further comprising computer-readable program code for causing the execution of:

18. The non-transitory computer-readable storage medium includes computer-readable program code executable by the processor circuit, the computer-readable program code including: the application extracting the identifier of the contactless card from the URL, wherein an applet executing in the memory of the contactless card provides the URL and the identifier of the contactless card to the application, the identifier of the contactless card comprising a portion of an account number associated with the account; 16. The non-transitory computer-readable storage medium of claim 15, further comprising computer-readable program code for causing the execution of:

19. The non-transitory computer-readable storage medium includes computer-readable program code executable by the processor circuit, the computer-readable program code including: receiving, by the OS, an input of the notification specifying that the expiration date be copied to the clipboard; the OS copying the expiration date to the clipboard in response to the input received in the notification; the OS pasting the expiration date into an expiration date field of the form in the web browser; 16. The non-transitory computer-readable storage medium of claim 15, further comprising computer-readable program code for causing the execution of:

20. The non-transitory computer-readable storage medium includes computer-readable program code executable by the processor circuit, the computer-readable program code including: receiving, by the OS, input of the notification specifying that the CVV be copied to the clipboard; The OS copies the CVV to the clipboard in response to an input specifying that the CVV should be copied to the clipboard; the OS pasting the CVV into a CVV field of the form in the web browser; wherein the communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth, and Wi-Fi.

16. The non-transitory computer-readable storage medium of claim 15, further comprising computer-readable program code for causing the execution of:

Citation Information

Patent Citations

  • Computer program

    JP2008293518A

  • Securing payment transaction using circulating application transaction counter

    JP2018136984A

  • System and method for securely validating transactions

    US20110270757A1

  • Near field contactless system and method for online transactions

    US20160189140A1

  • Secure payment card, method and system

    US9600808B1