Non-contact card personal identification system
The multi-factor authentication system for EMV contactless cards uses a cryptogram generated with a dynamic key to enhance security by requiring both PIN knowledge and card possession, addressing vulnerabilities in existing EMV contactless card authentication.
Patent Information
- Application Number
- JP2025111261
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2025-07-01
- Publication Date
- 2025-10-22
AI Technical Summary
Existing EMV contactless cards are vulnerable to cloning and PIN theft due to eavesdropping and man-in-the-middle attacks, as they rely solely on PIN verification for authentication.
A multi-factor authentication system combining PIN verification with a contactless card authentication process, using a cryptogram generated with a dynamic key based on a counter value maintained by the contactless card, ensuring that the PIN is never transmitted in an identifiable form.
This system significantly reduces the likelihood of card cloning by requiring both knowledge of the PIN and possession of the contactless card, enhancing transaction security and protecting against unauthorized access.
Smart Images

Figure 2025160195000001_ABST
Abstract
Description
[Technical Field]
[0001] This application claims priority to U.S. patent application Ser. No. 16 / 725,133, entitled "Contactless Card Personal Identification System," filed Dec. 23, 2019, the contents of which are incorporated herein by reference in their entirety. [Background technology]
[0002] Credit card cloning, or "skimming," is a technique in which a malicious actor copies credit card information from a credit card associated with an account onto a counterfeit card. Cloning is typically accomplished by swiping the credit card to extract ("skim") the credit card information from the card's magnetic stripe and storing that information on a counterfeit card. The counterfeit card can then be used to charge the account.
[0003] EMV (originally Europay, Mastercard, Visa) defines standards for the use of smart payment cards and the terminals and automated teller machines that accept them.
[0004] An EMV card is a smart card (i.e., a chip card or integrated circuit card) that contains an integrated circuit configured to store card information in addition to magnetic stripe information (for backward compatibility). EMV cards include both cards that are physically inserted (or "dipped") into a reader, and contactless cards that can be read over short distances using near field communication (NFC) technology.
[0005] Some EMV cards use chip and PIN (personal identification number) technology to overcome problems associated with cloning. For example, to authorize a transaction, a user may enter a personal identification number (PIN) at a transaction terminal following a card swipe. The PIN retrieved from the card and stored by the transaction terminal is compared with the PIN entry, and the transaction is approved only if the two match. While such solutions may reduce fraud, they are still vulnerable to PIN theft caused by eavesdropping, man-in-the-middle, or other types of attacks. Summary of the Invention
[0006] According to one aspect of the present invention, a multi-factor authentication system, apparatus, and method combines a personal identification number (PIN) verification procedure with a contactless card authentication process to reduce the likelihood of loss due to card cloning.
[0007] According to one aspect, a method for two-factor authentication of a request for access to an account associated with a client includes receiving an input PIN from a user interface; inserting a contactless card storing the PIN associated with the client; transmitting the input PIN to the contactless card; receiving a cryptogram from the contactless card if the input PIN and the stored PIN match; transmitting the cryptogram to an authentication device; and authorizing the request if the cryptogram is authenticated by the authentication device, wherein the cryptogram is formed using a dynamic key of the contactless card, the dynamic key being formed using a counter value maintained by the contactless card, and the cryptogram including data of the contactless card encoded using the dynamic key.
[0008] According to another aspect, a method for two-factor authentication of a request for access to an account associated with a client includes receiving an input PIN from a user interface. The method further includes inserting a contactless card that stores the PIN associated with the client. The method further includes receiving a cryptogram from the contactless card, the cryptogram formed using a dynamic key of the contactless card, the dynamic key formed using a counter maintained by the contactless card, the cryptogram including data of the contactless card including the PIN and encoded with the dynamic key. The method further includes transmitting the input PIN and cryptogram to an authentication device. The method further includes authorizing the request upon authentication of the input PIN and cryptogram by the authentication device.
[0009] According to a further aspect, the device includes a contactless card interface configured to communicate with a contactless card associated with a client, a user interface, a processor, and non-volatile memory having stored program code for authenticating a request by the client. The program code, when executed by the processor, is operable to transmit an input PIN received by the user interface to the contactless card and, upon a match between the input PIN and the stored PIN, to receive a cryptogram from the contactless card. The cryptogram is formed using a dynamic key of the contactless card, the dynamic key being formed using a counter value maintained by the contactless card, and the cryptogram includes contactless card data encoded using the dynamic key. The program code may be further operable to transmit the cryptogram to an authentication device and, upon authentication of the cryptogram by the authentication device, to authorize the request. [Brief explanation of the drawings]
[0010] [Figure 1A] FIG. 1 is a block diagram of a data transmission system configured to provide multi-factor authentication of a customer request using a personal identification number (PIN), according to an exemplary embodiment. [Figure 1B]FIG. 1 is a data flow diagram illustrating one embodiment of a sequence for providing authenticated access using data stored on a contactless card. [Figure 2A] 1 illustrates one embodiment of a system and method for two-factor PIN-based authentication disclosed herein. [Figure 2B] 1 illustrates one embodiment of a system and method for two-factor PIN-based authentication disclosed herein. [Figure 3A] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 3B] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 4A] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 4B] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 5A] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 5B] 1 illustrates an alternative embodiment of the system and method for two-factor PIN-based authentication disclosed herein. [Figure 6] 1B is an example of a contactless card for storing authentication information that can be used in the system of FIG. 1A. [Figure 7] FIG. 4 is a block diagram illustrating exemplary components that may be included in the contactless card of FIG. 3. [Figure 8] FIG. 2 illustrates exemplary areas of cryptography that may be used as part of a PIN exchange as disclosed in various embodiments herein. [Figure 9] FIG. 1B is a detailed block diagram of components of the system of FIG. 1A that may be utilized to support aspects of the present invention. [Figure 10]10 illustrates a prompt that may be provided by a user interface of a client device according to one embodiment disclosed herein. DETAILED DESCRIPTION OF THE INVENTION
[0011] Data security and transaction integrity are extremely important to businesses and consumers. This need continues to grow as electronic transactions comprise an ever-increasing proportion of commercial activity and malicious actors become increasingly aggressive in their attempts to compromise transaction security.
[0012] Embodiments of the present disclosure provide systems, methods, and apparatus for multi-factor authentication of transactions received at a client device using a personal identification number (PIN) in combination with a contactless card.
[0013] The contactless card may include a substrate containing memory that stores one or more applets, a counter value, and one or more keys. In some embodiments, the memory may further store a PIN that controls use of the contactless card, as described herein. In one embodiment, the counter value may be used to generate a unique cryptogram that can be used to authenticate a contactless card transaction. The cryptogram may be used in conjunction with the PIN to provide two-factor authentication of a contactless card transaction.
[0014] The cipher may be formed as described in U.S. Patent Application Serial No. 16 / 205,119, entitled "Systems and Methods for Cryptographic Authentication of Contactless Cards," filed November 29, 2018 by Osborn et al. (hereinafter the "'119 Application"), which is incorporated herein by reference. In some embodiments, the cipher may be formed from a cryptographic hash of a shared secret, multiple keys, and a counter value.
[0015] According to one aspect, a cryptogram may be used in conjunction with a PIN to provide multi-factor authentication of contactless card transactions. Multi-factor authentication may include verifying a user's knowledge of the card's PIN prior to, or as part of, authenticating the transaction using the cryptogram. In some embodiments, the cryptogram may be formed using the PIN. In some embodiments, the cryptogram may include an encoded PIN. In either case, the PIN is never transmitted in an identifiable form, thereby maintaining the security of the transaction and thus reducing the likelihood of theft. This use of a PIN in conjunction with a cryptogram for two-factor authentication protects against cloning of contactless cards by unauthorized third parties.
[0016] In some embodiments, PIN verification may be performed by the card as a prerequisite for cryptographic generation. In other embodiments, PIN verification may be performed by the transaction device or backend authentication server as part of cryptographic authentication. Each of these methods is described in more detail below.
[0017] Of course, in various systems, including the client, client device, and authentication server of various embodiments, the functions of PIN storage, encryption, and authentication may be performed by various components. In some embodiments, a copy of the PIN may be kept in the memory of the contactless card. In such embodiments, the copy of the PIN may be used to verify the user of the contactless card as part of a cryptographic authentication process. In some embodiments, the PIN may be used to generate a digital signature or cryptogram. In some embodiments, the cryptographic authentication may be performed by the transaction device, the authentication server, or some combination thereof.
[0018] In this way, the system provides two-factor authentication that establishes both knowledge (i.e., PIN number) and possession (i.e., contactless card and dynamic key), reducing the ability of malicious actors to successfully clone contactless cards.
[0019] These and other features of the present invention are now described with reference to the drawings, wherein like reference numerals are used to refer to like elements throughout. Referring generally to the notation and nomenclature used herein, the detailed descriptions which follow may be presented in terms of program processes running on a computer or network of computers. These process descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art.
[0020] A process is here, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. These operations require physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It proves convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.
[0021] Further, the manipulations performed are often referred to in terms, such as adding or comparing, that are commonly associated with mental operations performed by a human operator. No such capability of a human operator is necessary, or desirable, in most cases, in any of the operations described herein that form part of one or more embodiments. Rather, the operations are machine operations. Useful machines for performing the operations of the various embodiments include general purpose digital computers or similar devices.
[0022] Various embodiments also relate to apparatus or systems for performing these operations. This apparatus may be specially constructed for the required purposes, or it may comprise a general-purpose computer that is selectively activated or reconfigured by a computer program stored in the computer. The processes presented herein are not inherently related to any particular computer or other apparatus. Various general-purpose machines may be used with programs written in accordance with the teachings herein, or it may prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for a variety of these machines will be apparent from the description given.
[0023] Reference is now made to the drawings. Like reference numerals are used throughout to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding thereof. However, it may be apparent that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate description. The intention is to cover all modifications, equivalents, and alternatives consistent with the claimed subject matter.
[0024] 1A illustrates a data transmission system according to an exemplary embodiment. As discussed further below, system 100 may include contactless card 105, client device 110, network 115, and server 120. Although FIG. 1A illustrates a single example of a component, system 100 may include any number of components.
[0025] System 100 may include one or more contactless cards 105. In one embodiment, contactless card 105 comprises a credit card-sized card that includes an embedded integrated circuit, a storage device, and an interface that allows the card to communicate with a transmitting device using a Near Field Communication (NFC) protocol. Contactless cards that may be used herein include, for example, the contactless cards described in the '119 application.
[0026] System 100 may include client device 110. Client device 110 may be a network-enabled computer. As referred to herein, a network-enabled computer may include, for example, but is not limited to, a computing or communications device, including a server, network appliance, personal computer, workstation, telephone, handheld PC, personal digital assistant, thin client, fat client, Internet browser, or other device. Client device 110 may also be a mobile device. For example, the mobile device may include an Apple® iPhone®, iPod®, iPad®, or any other mobile device running Apple®'s iOS operating system, any device running Microsoft's Windows® mobile operating system, any device running Google's Android® operating system, and / or other smartphones, tablets, or similar wearable mobile devices.
[0027] Client device 110 may include a processor and memory, and it is understood that processing circuitry may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, necessary to perform the functions described herein. Client device 110 may also include a display and input devices. A display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device for inputting information into a user device that may be available and supported by the user device, such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and interact with the software and other devices described herein.
[0028] In some examples, client device 110 of system 100 may execute one or more applications, such as, for example, software applications that enable network communication with one or more components of system 100 to send and / or receive data.
[0029] Client device 110 may communicate with one or more servers 120 via one or more networks 115 and may operate with server 120 as a respective front-end and back-end pair. Client device 110 may send one or more requests to server 120, for example, from a mobile device application executing on client device 110. The one or more requests may relate to retrieving data from server 120. Server 120 may receive one or more requests from client device 110. Based on the one or more requests from client device 110, server 120 may be configured to retrieve the requested data from one or more databases (not shown). Based on receiving the requested data from the one or more databases, server 120 may be configured to transmit received data responsive to the one or more requests to client device 110.
[0030] System 100 may include one or more networks 115. In some examples, network 115 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks and may be configured to connect client device 110 to server 120. For example, network 115 may include one or more of an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communication service, a personal area network, a wireless application protocol, a multimedia message service, an enhanced message service, a short message service, a time division multiplexing based system, a code division multiple access based system, D-AMPS, Wi-Fi®, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth®, NFC, radio frequency identification (RFID), Wi-Fi®, etc.
[0031] Additionally, network 115 may include a global network such as, but not limited to, telephone lines, optical fiber, IEEE Ethernet 902.3, a wide area network, a wireless personal area network, a LAN, or the Internet. Furthermore, network 115 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 115 may further include one network or any number of the aforementioned exemplary types of networks, operating as a standalone network or operating in cooperation with one another. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may translate to or from other protocols into one or more protocols of network devices. While network 115 is depicted as a single network, according to one or more examples, it should be understood that network 115 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, an enterprise network such as a credit card association network, and a home network.
[0032] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to a memory. Server 120 may be configured as a central system, server, or platform for controlling and invoking various data at various times to perform multiple workflow operations. Server 120 may be configured to connect to one or more databases. Server 120 may be connected to at least one client device 110. In some embodiments, server 120 may be an authentication server configured to perform cryptographic authentication as disclosed herein.
[0033] FIG. 1B is a timing diagram illustrating an exemplary sequence for authenticating a contactless card transaction in accordance with one or more embodiments of the present disclosure. In particular, FIG. 1B describes an exemplary process for exchanging authentication data, including cryptography, between a contactless card 105 and a client device 110. System 100 may include contactless card 105 and client device 110, which may include an application 122 and a processor 124. FIG. 1B may reference similar components as shown in FIG. 1A.
[0034] In step 102, application 122 communicates with contactless card 105 (e.g., after being held near contactless card 105). Communication between application 122 and contactless card 105 may include contactless card 105 being close enough to a card reader (not shown) of client device 110 to enable NFC data transmission between application 122 and contactless card 105.
[0035] In step 104, after communication is established between client device 110 and contactless card 105, contactless card 105 generates a message authentication code (MAC) cryptogram. In some examples, this may occur when contactless card 105 is read by application 122. In particular, this may occur upon reading, such as an NFC read, of a Near Field Data Exchange (NDEF) tag, which may be generated according to the NFC data exchange format. For example, a reader, such as application 122, may send a message, such as an applet selection message, with the applet ID of an NDEF generation applet. Once the selection is confirmed, a sequence of select file messages may be sent followed by a read file message. For example, the sequence may include "select function file," "load function file," and "select NDEF file." At this point, a counter value maintained by contactless card 105 may be updated or incremented, followed by sending "load NDEF file." At this point, a message may be generated that includes a header and a shared secret.
[0036] A session key may then be generated. In one embodiment, a variant key may be generated by combining the master symmetric key with a dynamic counter value maintained by the contactless card using a cryptographic hash. Examples of cryptographic hash algorithms that may be used include symmetric encryption algorithms, HMAC algorithms, and CMAC algorithms. Non-limiting examples of symmetric algorithms that may be used to encrypt the username and / or cipher may include symmetric encryption algorithms such as 3DES (Triple Data Encryption Algorithm) or AES (Advanced Encryption Standard) 128, symmetric hash-based message authentication (HMAC) algorithms such as HMAC-SHA-256, and symmetric cipher-based message authentication code (CMAC) algorithms such as AES-CMAC. It is understood that many forms of encryption are known to those skilled in the art, and the present disclosure is not limited to the forms specifically identified herein.
[0037] A MAC cipher may be generated from a message, which may include a header and a shared secret. In some embodiments, the shared information, including but not limited to the shared secret and / or PIN, may then be concatenated with one or more blocks of random data and encoded using a cryptographic algorithm and a variant key to generate the MAC cipher. The MAC cipher and header may then be concatenated, encoded as ASCII hexadecimal numbers, and returned in an NDEF message format (responding to a "Read NDEF file" message).
[0038] In some examples, the MAC code may be transmitted as an NDEF tag, and in other examples, the MAC code may be included with the uniform resource indicator (eg, as a formatted string).
[0039] In some examples, the application 122 may be configured to send a request to the contactless card 105, the request including instructions to generate a MAC cryptogram.
[0040] In step 106, contactless card 105 transmits the MAC code to application 122. In some examples, the transmission of the MAC code occurs via NFC, although the disclosure is not limited thereto. In other examples, this communication may occur via Bluetooth, Wi-Fi, or other means of wireless data communication.
[0041] In step 108, the application 122 communicates the MAC cipher to the processor 124.
[0042] In step 112, processor 124 verifies the MAC cryptogram according to instructions from application 122. For example, the MAC cryptogram may be verified by an authentication server, such as server 120 of FIG. 1A. The authentication server may store a copy of the client device's counter, shared secret, and key for each client device 110. In some embodiments, as described in more detail below, the authentication server may also store a PIN associated with the client device. The authentication server may update the counter for each contactless card transaction according to a protocol established between client device 110 and the authentication server so that the counters remain synchronized. The authentication server may construct an expected MAC cryptogram using its copy of the counter, key, shared secret, and / or PIN.
[0043] In some examples, the MAC cipher may function as a digital signature for purposes of verification. Other digital signature algorithms, such as public key asymmetric algorithms, e.g., the Digital Signature Algorithm, the RSA algorithm, or zero-knowledge protocols, may also be used to perform this verification.
[0044] The authentication server may compare the MAC cryptogram received from the contactless card with an expected MAC cryptogram generated by the authentication server. Such measures improve the security of the transaction in several ways. First, the dynamic nature of the cryptogram, constructed using a variable counter value that is periodically updated according to an established protocol between the client and server, reduces a malicious third party's ability to reuse authentication information. Second, the use of an encryption algorithm further prevents the discovery of sensitive information through eavesdropping. Third, incorporating PIN code verification along with cryptographic authentication adds a knowledge modifier for two-factor authentication.
[0045] 2A and 2B illustrate the systems and processes, respectively, of one embodiment of a two-factor authentication system configured to support an authentication method that uses a PIN in conjunction with and / or as part of a cryptography.
[0046] 2A, the transaction device 222 (which may be a client mobile device, a merchant transaction device, or any device with NFC communication capabilities) is seen to include a user interface 225 for receiving information, such as an input PIN, from the user 202. The transaction device 222 is also seen to include an NFC interface 220 configured to support NFC communication with the contactless card 205, and a network interface 227 configured to support network communication, including but not limited to Internet Protocol (IP) communication with the authentication server 223.
[0047] According to one embodiment, contactless card 205 includes PIN verification logic 210, which may include hardware, software, or a combination thereof, configured to compare a PIN stored in the contactless card's memory with a PIN received from transaction device 222, for example, as part of an NDEF record. Card 205 also includes cryptography generation logic 211 configured to generate a cryptography, for example, as disclosed in the '119 application.
[0048] The crypto logic 211 may comprise a combination of hardware and software components, including, but not limited to, a storage device configured to store one or more keys and counter values for the card 205. The contactless card may further include counters, encryption and / or hashing hardware and software for use in generating variant dynamic keys for use in encoding messages from the contactless card, etc. In some embodiments, the crypto logic 211 may be implemented, at least in part, as an applet stored in memory of the contactless card 205. While the PIN logic 210 and the crypto logic 211 are shown as separate entities, it will be understood that the functionality may be distributed differently in various embodiments. For example, in some embodiments, the PIN logic 210 and the crypto logic 211 may be implemented by a single applet.
[0049] Server 223 is seen to include cryptographic verification logic 228. The cryptographic verification logic 228 may comprise a combination of hardware and software components, including, but not limited to, a storage device for storing the client key and counter value, a counter, encryption and / or hashing hardware and software, etc. In one embodiment, cryptographic verification logic 228 may be configured to generate a variant dynamic key for use in generating an expected cryptogram, and the verification logic may compare the expected cryptogram with a cryptogram received from the client device. A cryptographic match indicates equivalence between the client device's counter and the authentication server. Furthermore, a matching cryptogram may indicate knowledge of information such as a shared secret, a PIN, etc.
[0050] 2B illustrates a method for two-factor authentication using the system of FIG. 2A. In step 251, a transaction is initiated by user 202. For example, the user may access an account, make a purchase, or otherwise attempt to perform an action that would benefit from the two-factor authentication methods disclosed herein. In step 252, user 202 is prompted to enter a PIN, and upon receiving the entered PIN, transaction device 222 may initiate a dual authentication cryptographic exchange with contactless card 205, for example, by tapping card 205 on transaction device 222 or by prompting the user to bring contactless card 205 within communication range of transaction device 222.
[0051] When the contactless card is within range of the transaction device, in step 253 the transaction device 222 transmits the entered PIN to the contactless card 205, e.g., as a PIN record, and initiates a read of the NFC tag associated with the cryptography generation applet. In step 254, the PIN verification logic 210 may compare the entered PIN with the stored PIN 215. If a "match" is determined in step 255, the cryptography generation applet is instructed to generate a cryptography and transmit the cryptography to the transaction device 222 in step 256.
[0052] If the cryptogram is not received in step 257, for example due to a PIN mismatch, the transaction may be cancelled in step 259. If the cryptogram is received in step 257, then in step 258 the transaction device 222 requests authorization of the transaction and sends the cryptogram to the authentication server 223.
[0053] In step 260, once the authentication server 223 receives the cryptogram, it obtains client data including counters, keys, shared secrets, etc. associated with the contactless card 205. Using this information, in step 261, the authentication server generates an expected cryptogram and, in step 262, determines whether the generated cryptogram matches the unique digital signature provided by the received cryptogram. In step 263, the authentication server returns an allow / deny response to the transaction device 222. If the transaction device 222 determines that the transaction is allowed in step 264, the transaction may be executed in step 265. If the transaction is denied, the transaction device cancels the transaction in step 250.
[0054] The disclosed two-factor PIN-based authentication system improves transaction security by protecting the stored PIN 215 from discovery. As discussed, the stored PIN is not publicly transmitted and therefore cannot be obtained by malicious monitoring during the PIN exchange. If the PIN, shared secret, and / or counter value can be obtained by skimming, a cloned card without knowledge of the dynamic counter protocol implemented between the card and the authentication server will be rendered inoperable.
[0055] 3A and 3B disclose another embodiment of a two-factor PIN-based authentication system and method, where PIN verification functionality may be provided by an authentication server 323 as part of cryptographic verification logic 328. In the system 300 of FIG. 3A, card 305 stores a unique PIN 315 for the contactless card and configures cryptographic logic 311, which may include a cryptographic generation applet as described above. According to one embodiment, described in more detail below, the cryptographic code provided by contactless card 305 may include and / or be formed using PIN 315.
[0056] The transaction device 322 includes a user interface 325, an NFC interface 320, and a network interface 327. Additionally, the transaction device may include encapsulation logic 324. The encapsulation logic 324, in one embodiment, may include code for encrypting the input PIN and / or cipher before transmitting the input PIN / cipher pair to the authentication server 323.
[0057] The authentication server 323 includes cryptographic verification logic 328. The cryptographic verification logic 328 may operate to extract the input PIN from the encrypted input PIN / cryptographic pair. The cryptographic verification logic 328 may further be configured to generate an expected cryptographic using the input PIN and stored client data, such as counter and key data. The cryptographic verification logic 328 may then compare the expected cryptographic with the extracted cryptographic to determine a match correlating the input PIN and the stored PIN, as well as the counter and key information.
[0058] FIG. 3B is a flow diagram of a two-factor authentication process that may be performed by system 300. After a transaction is initiated in step 351, user 302 is prompted to enter a PIN in step 352. In step 353, the cryptographic authentication process begins as described above, e.g., transaction device 322 may issue an NFC read operation to an NDEF tag generation applet in card 305, specifically an NDEF tag generation applet configured to obtain a PIN 315 from contactless card 305 for inclusion in the cryptographic payload. In step 356, the contactless card's applet may assemble cryptographic data in the format <user ID><counter><MAC of user ID+counter+PIN>. In some embodiments, a variant key formed using the counter may be used to encode <MAC of user ID+counter+PIN> using a cryptographic hash algorithm or the like. A public-key asymmetric algorithm, e.g., a digital signature algorithm and an RSA algorithm, or a zero-knowledge protocol, may alternatively be used to perform this verification.
[0059] The contactless card 305 returns the cryptogram to the transaction device 322, which combines the entered PIN with the received cryptogram in step 354. In some embodiments, the entered PIN and / or the received cryptogram may be encrypted to obfuscate the entered PIN information, for example, using a symmetric encryption algorithm. This combination is sent to the authentication server 323.
[0060] In step 360, the authentication server 323 retrieves authentication information (including counter value, key, shared secret, etc.) related to the contactless card from storage. Using this information, in step 361, the authentication server may construct an expected cryptogram, for example, in the form of <User ID MAC+stored counter+entered PIN>. In step 362, the authentication server determines whether the expected cryptogram matches the cryptogram retrieved from the contactless card, and in step 363 returns an authentication status to the transaction device 322. In response to receiving the authentication status in step 364, the transaction is either executed in step 364 or canceled in step 359.
[0061] Thus, in the embodiment of Figures 3A and 3B, the cryptogram generated by the contactless card is formed using the PIN, but the PIN itself is not transmitted over the network in an identifiable or derivable form.
[0062] 4A and 4B disclose another embodiment of a two-factor PIN-based authentication system and method, where PIN verification may be performed by the transaction device using public key cryptography. In one embodiment, the contactless card 405 holds a private key 417. The private key 417 is known only to the contactless card 405 and may be used to decrypt communications encrypted by the public key. The contactless card may further include digital signature logic 411 configured to generate a unique digital signature, a cryptographic hash, to provide encryption for communications to the transaction device 422.
[0063] The transaction device 422 includes a user interface 425 and an NFC interface 420. The transaction device is shown to further include a random number generator 454, encryption logic 424, and memory 455 that stores a public key 457 for the contactless card, where the public key may be obtained by the transaction device from a trusted certificate authority. The transaction device further includes digital signature logic 456 for generating a digital signature, as described below. In some embodiments, the public key of the card 405 may be stored by the card 405 and retrieved by the transaction device as part of the authentication process.
[0064] Figure 4B shows a method for two-factor authentication using the system 400 of Figure 4A. Once a transaction is determined to have been initiated in step 461, the user 404 is prompted to enter an input PIN in step 462. In step 463, the transaction device obtains the public key for the contactless card from the card itself or from a trusted authentication authority. In step 465, the transaction device generates a random number, encrypts it with the public key, and sends it to the contactless card 405. In step 466, the contactless card decrypts the random number using its private key and generates a digital signature using a combination of the random number and the stored PIN 415. The resulting digital signature is sent back to the transaction device 422.
[0065] In step 467, the transaction device 422 also generates a digital signature using the random number in combination with the entered PIN received from the user 402. In step 468, the digital signatures are compared to identify a match. Depending on the match, the transaction is either executed in step 470 (match) or canceled in step 469 (no match).
[0066] 5A and 5B disclose another embodiment of a two-factor PIN-based authentication system and method, in which a contactless card PIN is stored on an authentication server and used in combination with a cryptogram to authenticate a transaction. In the system 500 of FIG. 5A, a contactless card 505 includes cryptographic logic 511 for generating a cryptogram using a combination of a counter, a dynamic key, a shared secret, etc., as previously described. A transaction device 522 includes a user interface 520, an NFC interface 525, and a network interface 527. Additionally, the transaction device may include encapsulation logic 524. In one embodiment, the encapsulation logic 524 may include code for encrypting the input PIN and / or cryptogram before transmitting the input PIN / cryptogram pair to an authentication server 523. The authentication server 523 includes a PIN table 595, PIN verification logic 594, and cryptogram verification logic 596.
[0067] FIG. 5B illustrates a method for two-factor authentication using the system 500 of FIG. 5A. Following initiation of a transaction in step 551, the user 502 is prompted to enter a PIN in step 552, and the transaction device 522 requests a cryptogram from the contactless card 505 in step 553. The contactless card generates the cryptogram and returns it to the transaction device 522 in step 555. In step 554, the transaction device combines and encrypts the entered PIN received from the user and the cryptogram from the contactless card and sends it to the authentication server 523. In step 560, the authentication server obtains the PIN, counter, and key associated with the contactless card 505. In step 561, the authentication server decrypts the message from the transaction device 522, extracts the entered PIN, and in step 562, compares the extracted entered PIN with an expected entered PIN retrieved from a PIN table. In step 563, the authentication server 523 may also retrieve the cryptogram retrieved from the contactless card 505. The authentication server 523 may construct an expected cryptogram using the stored key, counter, and shared secret stored by the cryptogram verification logic. In step 564, the transaction device may compare the expected cryptogram with the extracted cryptogram to determine a match. In response to the comparison, the authentication server 523 returns an authentication status to the transaction device in step 565. Upon receiving the authentication status in step 566, the transaction is either executed in step 568 (match) or canceled in step 567 (no match).
[0068] Having thus shown and described various systems and methods for providing two-factor PIN-based authentication, exemplary components that may be included in a contactless card, transaction device, and / or authentication server, along with and / or in place of the components already described, to support the described methods will now be described with reference to Figures 6-10.
[0069] FIG. 6 illustrates a contactless card 600, which may include a payment card such as a credit card, debit card, or gift card, issued by a service provider 605. The identity of the service provider 605 may be displayed on the front or back of the card 600. In some examples, the contactless card 600 may be unrelated to a payment card and may include, but is not limited to, an identification card. In some examples, the payment card may include a dual-interface contactless payment card. The contactless card 600 may include a substrate 610, which may include a single layer or one or more laminates of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, contactless card 600 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, while in other cases, the contactless card may conform to the ISO / IEC 14443 standard. However, it is understood that contactless card 600 according to the present disclosure may have different characteristics, and the present disclosure does not require that the contactless card be implemented as a payment card.
[0070] Contactless card 600 may include identification information 615 displayed on the front and / or back of the card and a contact pad 620. Contact pad 620 may be configured to establish contact with a user device or other communication device, such as a smartphone, laptop, desktop, or tablet computer. Contactless card 600 may also include processing circuitry, an antenna, and other components not shown in FIG. 6. These components may be located behind contact pad 620 or elsewhere on substrate 610. Contactless card 600 may also include a magnetic stripe or tape, which may be located on the back of the card (not shown in FIG. 6).
[0071] 7, the contact pad 720 may include processing circuitry for storing and processing information, the processing circuitry including a microprocessor 730 and memory 735. It is understood that the processing circuitry may include additional components including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware necessary to perform the functions described herein.
[0072] The memory 735 may be a read-only memory, a write-once read-multiple memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 700 may include one or more of these memories. Read-only memory may be factory programmable for read-only operation, or may be programmable only once. Programmability only once provides the opportunity to write once and read multiple times. Write-once read-multiple memory may be programmed at a time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten, but it may be read multiple times.
[0073] The memory 735 may be configured to store one or more applets 740, one or more counters 745, and customer information 750. According to one aspect, the memory 735 may store a PIN 777.
[0074] The one or more applets 740 may include one or more software applications, such as a Java Card applet, associated with a respective one or more service provider applications and configured to run on one or more contactless cards. For example, the applet may include logic configured to generate a MAC cryptogram, as described above. The MAC cryptogram, in some embodiments, includes a MAC cryptogram formed at least in part using PIN information.
[0075] The one or more counters 745 may include a numeric counter sufficient to store an integer. The customer information 750 may include a unique alphanumeric identifier assigned to the user of the contactless card 700 and / or one or more keys that may be used together to distinguish the user of the contactless card from other users of contactless cards. In some examples, the customer information 750 may include information that identifies both the customer and the account assigned to that customer, and may further identify the contactless card associated with the customer's account.
[0076] While the processor and memory elements of the foregoing exemplary embodiments have been described with reference to contact pads, the present disclosure is not limited thereto, and it will be appreciated that these elements may be implemented external to, or entirely separate from, the pads 720, or may be implemented as additional elements in addition to the microprocessor 730 and memory 735 elements located within the contact pads 720.
[0077] In some examples, the contactless card 700 may include one or more antennas 725 disposed within the contactless card 700 and around the processing circuitry 755 of the contact pads 720. For example, one or more antennas may be integral with the processing circuitry, or one or more antennas may be used in conjunction with an external booster coil. As another example, one or more antennas may be external to the contact pads 720 and processing circuitry.
[0078] As described above, contactless card 700 may be built on a software platform operable on a smart card or other device including program code, processing power, and memory, such as a Java Card. The applet may be configured to respond to one or more requests, such as a Near Field Communication (NDEF) request, from a reader, such as a mobile Near Field Communication (NFC) reader, and to generate an NDEF message including a cryptographically secure OTP encoded as an NDEF text tag.
[0079] FIG. 8 illustrates an exemplary NDEF short record layout (SR=1) 800 according to an exemplary embodiment. NDEF messages provide a standardized method for transaction devices to communicate with contactless cards. In some examples, an NDEF message may contain one or more records. NDEF record 800 includes a header 802, which contains several flags that define how to interpret the remainder of the record, including a Message Start (MB) flag 803a, a Message End (ME) flag 803b, a Chunk flag (CF) 803c, a Short Record (SR) flag 803d, an ID Length (IL) flag 803e, and a Type Name Format (TNF) field 803f. The MB 803a and ME flags 803b may be set to indicate the first and last records, respectively, of the message. The CF 803c and IL flags 803e provide information about the record, including whether the data may be "chunked" (data spread across multiple records within a message) or whether an ID Type Length field 808 is relevant, respectively. The SR flag 803d may be set if the message contains only one record.
[0080] The TNF field 803f identifies the type of content it contains, as specified by the NFC protocol. These types include empty, well-known (data defined by the NFC Forum's Record Type Definition (RTD)), Multipurpose Internet Mail Extensions (MIME) [defined by RFC2046], full Uniform Resource Identifier (URI) [defined by RFC3986], external (user-defined), unknown, unchanged [for chunks], and reserved.
[0081] Other fields in an NFC record include Type Length 804, Payload Length 806, ID Length 808, Type 810, ID 812, and Payload 814. Type Length field 804 specifies the exact type of data found in the payload. Payload Length 806 contains the length of the payload in bytes. A record may contain up to 4,294,967,295 bytes (or 2^32-1 bytes) of data. ID Length 808 contains the length of the ID field in bytes. Type 810 identifies the type of data the payload contains. For example, for authentication purposes, Type 810 may indicate that Payload 814 is a cryptogram formed at least in part using a personal identification number (PIN) retrieved from the contactless card's memory. ID field 812 provides a means for external applications to identify the entire payload carried in the NDEF record. Payload 814 contains the message.
[0082] In some examples, data may be initially stored on the contactless card by implementing STORE DATA (E2) under a secure channel protocol. This data may include a card-specific personal user ID (pUID) and PIN, as well as one or more of cryptographic data including an initial key, a session key, a data encryption key, a random number, and other values described in more detail below. In other embodiments, the pUID and PIN may be pre-loaded into the contactless card before delivery to the client. In some embodiments, the PIN may be selected by the client for the contactless card and written back to the contactless card after verification of the client using various stringent authentication methods.
[0083] FIG. 9 illustrates a communication system 900 in which one of a contactless card 910 and / or an authentication server 950 can store information that can be used during first factor authentication. As described with respect to FIG. 3, each contactless card may include a microprocessor 912 and memory 916 for customer information 919, including one or more unique identification attributes, such as an identifier, a key, a random number, etc. In one aspect, the memory further includes an applet 917 operable when executed by the microprocessor 912 to control the authentication process described herein. As previously mentioned, a PIN 918 may be stored in the memory 916 of the card 910 and accessed by the applet and / or as part of the customer information 919. Additionally, each card 910 may include one or more counters 914 and an interface 915. In one embodiment, the interface operates NFC or other communication protocols.
[0084] The client device 920 includes a contactless card interface 925 for communicating with a contactless card and one or more other network interfaces (not shown) that enable the device 920 to communicate with a service provider using various communication protocols, as described above. The client device may further include a user interface 929 that enables communication between a service provider's application and a user of the client device 920. The user interface 929 may include one or more of a keyboard or a touchscreen display. The client device 920 further includes a processor 924 and a memory 922. The memory 922 stores information and program code that, when executed by the processor, controls operation of the client device 920, and includes a client-side application 923 that may be provided to the client by a service provider to facilitate, for example, access to and use of the service provider's application. In one embodiment, the client-side application 923 includes program code configured to transmit authentication information, including a PIN code, from the contactless card 910 to one or more services offered by the service provider, as described above. The client-side application 923 may be controlled via an application interface displayed on a user interface 926. For example, a user may select an icon, link, or other mechanism provided as part of the application interface to launch a client-side application to access the application service, where part of the launch includes validating the client using a cryptographic exchange.
[0085] In an exemplary embodiment, the cryptographic exchange includes a transmitting device having a processor and memory, where the transmitting device's memory contains a master key, transmitted data, and a counter value. The transmitting device is in communication with a receiving device having a processor and memory, where the receiving device's memory contains the master key. The transmitting device may be configured to generate a variegated key using the master key and one or more cryptographic algorithms, store the variegated key in the transmitting device's memory, encrypt the counter value using the one or more cryptographic algorithms and the variegated key to generate an encrypted counter value, encrypt the transmitted data using the one or more cryptographic algorithms and the variegated key to generate encrypted transmitted data, and transmit the encrypted counter value and the encrypted transmitted data as an encryption to the receiving device. The receiving device may be configured to generate a variegated key based on the stored master key and the stored counter value, store the variegated key in the receiving device's memory, and decrypt the encrypted encryption (including the encrypted counter and the encrypted transmitted data) using one or more decryption algorithms and the variegated key. The receiving device may authenticate the transmitting device when the decrypted counter matches the stored counter. The counter may be incremented in each of the sending and receiving devices for subsequent authentications, thereby providing a cryptographically based dynamic authentication mechanism for sending / receiving device transactions.
[0086] 1A, client device 920 may be connected to various services of service provider 905 and managed by application server 906. In the illustrated embodiment, authentication server 950 and application server 906 are shown as separate components, but it should be understood that the application server may include all of the functionality described as being included in the authentication server.
[0087] The authentication server 950 is seen to include a network interface 953 for communicating with members of the network via the network 930, and a central processing unit (CPU) 959. In some embodiments, the authentication server may include a non-transitory storage medium for storing a PIN table 952 containing PIN information for the service provider's clients. Such information may include, but is not limited to, the client's username, the client's personal identifier, and the client's key and counter. In one embodiment, the authentication server further includes an authentication unit 954 for controlling the decryption of the encryption and the extraction of the counter, and a client counter value table 956 that may be used, as described below, to perform authentication in conjunction with the contactless card 910. In various embodiments, the authentication server may further include the PIN table 952 configured to have an entry for each client / contactless card pair.
[0088] FIG. 10 illustrates an example of a client device 1000 with a display 1010 that includes a prompt window 1020 and an input portion 1030. The prompt portion may display various prompts to guide the client through the authentication process, including, for example, a "tap your card" prompt to encourage movement of the card 805 toward the device 1000. As shown in FIG. 10, the prompt may include instructions such as "enter your PIN" and provide a keyboard or other input mechanism to allow the user to enter the PIN. In some embodiments, following a successful card tap and PIN entry, the user may complete a transaction, such as completing a charge, accessing sensitive data, or accessing a specific person.
[0089] Thus, a system and method for two-factor PIN-based authentication using a cryptography and PIN exchange for multi-factor authentication has been shown and described to reduce and / or eliminate the possibility of card cloning.
[0090] As used herein, the terms "system," "component," and "unit" are intended to refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution, examples of which are described herein. For example, a component may be, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives, non-transitory computer-readable media (optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a server and the server may be a component. One or more components may reside within a process and / or thread of execution, and a component may be localized on one computer and / or distributed among two or more computers.
[0091] Additionally, components may be communicatively coupled to one another by various types of communication media to coordinate operations. This coordination may include unidirectional or bidirectional exchange of information. For example, components may convey information in the form of signals communicated over the communication media. The information may be implemented as signals assigned to various signal lines. In such assignments, each message may be a signal. However, further embodiments may instead employ data messages. Such data messages may be transmitted over various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.
[0092] Some embodiments may be described using the phrase "one embodiment" or "an embodiment," along with variations thereof. These terms mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. The appearances of the phrase "in one embodiment" in various places throughout this specification do not necessarily all refer to the same embodiment. Furthermore, unless otherwise noted, it is recognized that the aforementioned features can be used together in any combination. Thus, features discussed separately can be employed in combination with each other unless it is noted that the features are mutually exclusive.
[0093] Generally referring to the notation and nomenclature used herein, the detailed descriptions herein may be presented in terms of functional blocks or units that can be implemented as program procedures executed on a computer or network of computers. These procedural descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art.
[0094] A procedure is here, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. These operations require physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It proves convenient at times, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.
[0095] Further, the manipulations performed are often referred to in terms, such as adding or comparing, that are commonly associated with mental operations performed by a human operator. No such capability of a human operator is necessary, or desirable, in most cases, in any of the operations described herein that form part of one or more embodiments. Rather, the operations are machine operations. Useful machines for performing the operations of the various embodiments include general purpose digital computers or similar devices.
[0096] Some embodiments may be described using the terms "coupled" and "connected," along with derivatives thereof. These terms are not necessarily intended as synonyms for each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements cooperate or interact with each other even though they are not in direct contact with each other.
[0097] It is emphasized that the Summary of the Disclosure is provided to enable the reader to quickly grasp the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Moreover, in the foregoing Detailed Description, various features are grouped together in a single embodiment to streamline the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in fewer than all features of a single disclosed embodiment. Accordingly, the following claims are incorporated into the Detailed Description, with each claim standing on its own as an independent embodiment. In the appended claims, the terms "including" and "in which" are used as the plain-English equivalents of the terms "comprising" and "wherein," respectively. Moreover, the terms "first," "second," "third," etc. are used merely as labels and are not intended to impose numerical requirements on their objects.
[0098] What has been described above includes examples of the disclosed arrangements. Of course, it is not possible to describe every conceivable combination of components and / or methodologies, but one of ordinary skill in the art will recognize that many further combinations and permutations are possible. Accordingly, the novel arrangements are intended to embrace all such alterations, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. 1. A method for two-factor authentication for requests for access to an account associated with a client, comprising: receiving an input PIN from a user interface; inserting a contactless card storing a PIN associated with said client; transmitting the input PIN to the contactless card; receiving a cryptogram from the contactless card if the entered PIN matches a stored PIN; transmitting the encryption code to an authentication device; granting the request if the encryption is authenticated by the authentication device; Including, The encryption code is generated using a dynamic key of the contactless card, the dynamic key is formed using a counter value maintained by the contactless card; the encryption includes contactless card data encoded using the dynamic key; method.
2. The authentication device maintaining a copy of the contactless card data and a copy of the counter value; and authenticating the cryptogram by encoding a copy of the contactless card data with an expected dynamic key formed from a copy of the counter to generate an expected cryptogram, and comparing the expected cryptogram with the transmitted cryptogram. The method of claim 1.
3. The method of claim 2 , wherein the counter value and the copy of the counter value are updated according to a predetermined protocol followed by the authentication device and the contactless card, respectively.
4. The dynamic key is further formed using a master key stored on the contactless card; the authentication device stores a copy of the master key and uses the copy of the master key together with a counter to provide the predicted dynamic key; The method of claim 3.
5. The method of claim 4 , wherein the contactless card and the authentication device each use the same cryptographic hash algorithm to generate the dynamic key and the expected dynamic key.
6. The method of claim 5 , wherein the contactless card data encoded with the dynamic key includes a PIN stored on the contactless card, a shared secret, the counter value, or a combination thereof.
7. 2. The method of claim 1, wherein the method includes the step of encoding the contactless card data, the step comprising applying a cryptographic hash function to the contactless card data.
8. 8. The method of claim 7, wherein the cryptographic hash function is selected from a group of functions including 3DES (Triple Data Encryption Algorithm), Advanced Encryption Standard (AES) 128, a symmetric hash-based message authentication (HMAC) algorithm, and a symmetric cipher-based message authentication code (CMAC) algorithm such as AES-CMAC.
9. The method of claim 1 , wherein the authentication device comprises a client device, a merchant device, an authentication server, or a combination thereof.
10. 1. A method for two-factor authentication for requests for access to an account associated with a client, comprising: receiving an input PIN from a user interface; inserting a contactless card storing a PIN associated with said client; receiving a code from the contactless card; transmitting the entered PIN and the encryption to an authentication device; permitting the request if the input PIN and the password are authenticated by the authentication device; Including, The encryption code is generated using a dynamic key of the contactless card, the dynamic key is formed using a counter carried by the contactless card; the encryption includes contactless card data, including the PIN, and is encoded using the dynamic key; method.
11. The authentication device maintaining a copy of the contactless card data and a copy of the counter; and authenticating the cryptogram by encoding a copy of the contactless card data and the input PIN with an expected dynamic key formed from the copy of the counter to generate an expected cryptogram, and comparing the expected cryptogram with the transmitted cryptogram. The method of claim 10.
12. The method of claim 11 , wherein the counter value and the copy of the counter value are updated according to a predetermined protocol followed by the authentication device and the contactless card, respectively.
13. The dynamic key is further formed using a master key stored on the contactless card; the authentication device stores a copy of the master key and uses the copy of the master key together with the counter to provide the predicted dynamic key; The method of claim 12.
14. The method of claim 13 , wherein the contactless card and the authentication device each use the same cryptographic hash algorithm to generate the dynamic key and the expected dynamic key.
15. 15. The method of claim 14, wherein the contactless card data encoded with the dynamic key comprises a PIN stored on the contactless card, a shared secret, the value of the counter, or a combination thereof.
16. The method of claim 11 , wherein the method includes the step of encoding the contactless card data, the encoding comprising applying a cryptographic hash function to the contactless card data.
17. 17. The method of claim 16, wherein the cryptographic hash function is selected from a group of functions including 3DES (Triple Data Encryption Algorithm), Advanced Encryption Standard (AES) 128, a symmetric hash-based message authentication (HMAC) algorithm, and a symmetric cipher-based message authentication code (CMAC) algorithm such as AES-CMAC.
18. The method of claim 11 , wherein the authentication device comprises a client device, a merchant device, an authentication server, or a combination thereof.
19. a contactless card interface configured to communicate with a contactless card associated with the client; A user interface; a processor; a non-volatile memory having stored program code for authenticating a request by the client, the contactless card includes a stored PIN; The program code, when executed by the processor, transmitting an input PIN received by the user interface to the contactless card; If the input PIN matches the stored PIN, a code is received from the contactless card; transmitting the encryption code to an authentication device; and operable to authorize the request once the cryptogram has been authenticated by the authentication device; The encryption code is generated using a dynamic key of the contactless card, the dynamic key is formed using a counter value maintained by the contactless card; the encryption includes contactless card data encoded using the dynamic key; Device.
20. The authentication device maintaining a copy of the contactless card data and a copy of the counter value; authenticating the cryptogram by encoding a copy of the contactless card data with an expected dynamic key formed from a copy of the counter value to generate an expected cryptogram, and comparing the expected cryptogram with the transmitted cryptogram; the counter value and the copy of the counter value are updated according to a predetermined protocol followed by the authentication device and the contactless card, respectively; 20. The apparatus of claim 19.