System and method for context switching authentication in short-range wireless communication

The proposed system uses BLE and NFC to streamline online access authentication by enabling a first device to authenticate web access requests from a second device through context switching, addressing the inefficiencies and security concerns of existing methods.

JP2025516198APending Publication Date: 2025-05-27CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024563378
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-04-27
Filing Date
2023-04-26
Publication Date
2025-05-27

AI Technical Summary

Technical Problem

Existing systems for online access authentication are cumbersome and prone to human error, requiring additional user inputs and relying on third-party data providers for device verification.

Method used

A method and system for context switching authentication using Bluetooth Low Energy (BLE) links and Near Field Communication (NFC) to authenticate connections between devices, allowing a first device to authenticate a web access request initiated from a second device by generating and transmitting authentication tokens.

Benefits of technology

This solution provides a secure and streamlined authentication process that reduces user input requirements and eliminates the need for third-party data providers, enhancing the security and efficiency of online access authentication.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025516198000001_ABST
    Figure 2025516198000001_ABST
Patent Text Reader

Abstract

Systems and methods are provided for implementing strong user authentication in public networks. One operational aspect of the disclosed systems and methods includes integration of browser functionality that communicates with processes and hardware elements on a device initiating a network connection to implement a context switching authentication scheme. The disclosed systems and processes further include implementing two-factor strong authentication based on a single authentication input from a user involving an NFC read of a contactless card by a mobile device within Bluetooth proximity of the device initiating the network connection.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical field]

[0001] This application claims priority to U.S. Patent Application No. 17 / 731,080, filed April 27, 2022, the disclosure of which is incorporated by reference in its entirety herein.

[0002] The present disclosure relates to systems and methods for providing authentication credentials and authenticated user information over a network, and more particularly, to systems and methods for providing context switching based authentication using near field communication. [Background technology]

[0003] Authentication of the origin of access requests to systems and applications that store access-restricted resources, such as sensitive user information, is a major challenge to enable secure electronic transactions and / or user data access. Several procedures have been devised to provide reliable user authentication before granting access to sensitive and / or personal information. One such procedure corresponds to a two-factor authentication process, where a first form of authentication includes a first verification of user identification based on specific access credential information (e.g., username and password) entered by the user, and a second form of authentication is triggered after the first verification and generally consists of sending a message (e.g., a push notification or an automated phone call sent to a device registered by the user) to a pre-identified second device associated with the user and receiving a user confirmation via the pre-identified second device. Such authentication schemes typically involve a third-party data provider that pre-identifies the second device required to perform the second authentication step. Thus, existing systems and processes for implementing online access authentication are cumbersome, requiring additional user authentication inputs, and such processes are further prone to human error. These and other deficiencies exist. Summary of the Invention

[0004] An embodiment of the present disclosure is directed to a method of authenticating a connection request from a first device associated with a user using an authentication application stored on a second device associated with the same user, the second device being communicatively coupled to the first device via a short-range communication protocol such as a Bluetooth Low Energy (BLE) link. The method may include initiating an authentication application stored on the first user device in response to a transmission received over a BLE link established between the first user device and the second user device, the message including a Uniform Resource Indicator (URI) identifying the authentication application. The method may further include: generating, by the authentication application, a list of authentication schemes available on the first user device, each authentication scheme being associated with one or more authentication actions using the first user device; generating, by the authentication application, one or more authentication tokens representative of successful authentication of a user-selected authentication scheme; and authenticating a web access request initiated from a browser running on the second user device by transmitting the one or more authentication tokens over the BLE link from the first user device to the second user device.

[0005] In some embodiments, one of the authentication schemes from the list of authentication schemes available to the first user device corresponds to performing an NFC read of a contactless card by the first user device, the contactless card storing the user identification information as NFC transmittable data, and the contactless card based authentication scheme corresponds to a single user action of bringing the contactless card within NFC range of the first user device.

[0006] One aspect of the present disclosure is directed to a system for implementing context switching authentication. The system includes a computer hardware device that performs the following: launching an authentication application stored on a first user device in response to a message received over a Bluetooth Low Energy (BLE) link established between the first user device and a second user device, the message including a Uniform Resource Indicator (URI) identifying the authentication application. The computer hardware device may further perform: generating a list of authentication schemes available on the first user device, each authentication scheme being associated with one or more authentication runs performed by the first user device; generating one or more authentication tokens representing authentication success of a user-selected authentication scheme; and authenticating a web access request initiated from a browser running on the second user device by transmitting the one or more authentication tokens over the BLE link to the second user device.

[0007] According to some embodiments, a computer hardware device may be implemented to provide an authentication scheme that includes using a first user device as a reader to perform Near Field Communication (NFC) reading of a contactless card that stores user identification information as NFC transmittable data, and authenticating the origin of a web access request initiated from a browser running on a second user device by generating one or more authentication tokens.

[0008] Another aspect of the disclosure is directed to a non-transitory computer readable medium including instructions executed by a computer hardware device, the instructions, when executed, causing the computer hardware device to: launch an authentication application stored on the first user device in response to a message received over a Bluetooth link established between the first user device and the second user device, the message including a Uniform Resource Indicator (URI) identifying the authentication application; generate a list of authentication schemes available on the first user device, the list responsive to a selection input made using the first user device, each authentication scheme being associated with one or more authentication actions performed by a user using the first user device; generate one or more authentication tokens representing successful authentication of the user-selected authentication scheme; and authenticate a web access request initiated from a browser running on the second user device by transmitting the one or more authentication tokens over the Bluetooth link to the second user device.

[0009] In some embodiments, the authentication scheme used to generate the one or more authentication tokens corresponds to successful verification of one or more user identities obtained by a first user device performing an NFC read of a contactless card, the contactless card storing the user identities as NFC transmittable data. [Brief description of the drawings]

[0010] [Figure 1] FIG. 1 illustrates an example system implementation of context switching authentication using Bluetooth processes according to some embodiments of the present disclosure. [Diagram 2] FIG. 2 illustrates an example system for implementing context switching authentication to provide strong two-factor authentication based on the actions of a single user, according to some embodiments of the present disclosure. [Figure 3A]FIG. 3A illustrates a contactless card according to some embodiments of the present disclosure. [Figure 3B] FIG. 3B illustrates a contact pad of a contactless card according to some embodiments of the present disclosure. [Figure 4] FIG. 4 is a flow diagram of an automatic context switching authentication process according to some embodiments of the disclosure. [Diagram 5] FIG. 5 is a flow diagram of an automatic context switching authentication process that implements two-factor authentication with a single authentication execution from a user according to some embodiments of the present disclosure. [Figure 6] FIG. 6 is a block diagram illustrating an example system according to some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE PREFERRED EMBODIMENTS

[0011] The various embodiments of the present disclosure, together with further objects and advantages, will be best understood by reference to the following description taken in conjunction with the accompanying drawings, in which:

[0012] The following description of the embodiments provides a non-limiting representative example that refers to numbers to specifically describe the features and teachings of different aspects of the present invention. It should be recognized from the description of the embodiments that the described embodiments can be implemented separately or in combination with other embodiments. Those skilled in the art who review the description of the embodiments will be able to learn and understand the different described aspects of the present invention. The description of the embodiments will facilitate the understanding of the present invention to the extent that other embodiments that are not specifically covered but are within the knowledge of those skilled in the art who read the description of the embodiments will be understood to be consistent with the application of the present invention.

[0013] One aspect of the present disclosure is directed to a system and method for an improved implementation of access authentication that may be applied to grant access to sensitive resources and / or information over a public network such as the Internet. The proposed scheme involves a novel integration of browser functionality that allows access to and utilization of websites to hardware and software functions associated with a connected computing device (e.g., a smartphone and / or tablet with a web browsing application) into a process that allows a connected computing device that does not have authentication capabilities to establish authenticated access to restricted online resources.

[0014] In this manner, some embodiments of the present disclosure allow for user and / or access authentication functionality configured on one device to be seamlessly applied to authenticate connections initiated by other devices that may not have the aforementioned authentication configuration / functionality. Thus, according to some embodiments, authentication functionality configured on a particular device (e.g., smartphone, tablet) may be dynamically applied to authenticate connections initiated by other separate devices (e.g., personal computers, laptops, tablets, smartphones, etc.). In embodiments, authentication information between two user devices may be communicated over a short-range communication link, such as a Bluetooth Low Energy (BLE) link.

[0015] For the purposes of this disclosure, the term "website" is used interchangeably to refer to a web server that hosts a website.

[0016] Another aspect of the present disclosure is directed to a system and method for implementing a strong two-factor authentication process while requiring a single authentication input from a user. The strong two-factor authentication process corresponds to the verification of user authentication information stored on a contactless card and read via NFC by a reader integrated and / or installed on a user mobile device. The contactless card used in the authentication process comprises an integrated processor and a memory that stores the user identification information as NFC Data Exchange Format (NDEF) data. In this strong two-factor authentication implementation, the first factor authentication is implicitly verified upon successful pairing and interaction (of the access-requesting user device) with another nearby user device (e.g., the user mobile device), which is also configured as an NFC reader for the contactless card. Verification of the information obtained via NFC reading of the contactless card by the (nearby user device) user mobile device constitutes explicit verification of the second form of authentication. Furthermore, the only external authentication execution (e.g., provided to the user) required to facilitate the above-mentioned strong two-factor authentication scheme is bringing the contactless card within NFC range of the mobile device reader.

[0017] In some embodiments, where a username and / or password may be used as the first form of authentication, the described systems and methods may provide three form factor strong authentication based on verification of the proximity of two different user associated devices (e.g., a first user device within Bluetooth range of a second (access requesting) user device and a contactless card within NFC range of the first user device), where two authentication inputs are required from the user, corresponding to entering username and / or password credentials via a mobile device and tapping a contactless card on the user's mobile device.

[0018] One aspect of the present disclosure includes a dynamically triggered process that is initiated upon detecting that a website code received by a connected user device (e.g., a website loaded by a browser on the connected user device) includes one or more instructions to initiate a Bluetooth process at a source device (e.g., the connected user device) to establish a Bluetooth Low Energy (BLE) connection with one or more other users that are within Bluetooth pairing range of the connected user device. Upon detection of such website code, an authentication application stored on a first user device located within Bluetooth pairing range of the connecting user device may be automatically initiated according to one or more instructions transmitted over the BLE connection.

[0019] The authentication application launched on the first user device then facilitates the generation and provision of the necessary authentication information in response to an authentication request from the website to verify that the entity requesting access to the restricted-access electronic resource and / or website is in possession of or in close proximity to both the first user device (e.g., an authentication-capable user mobile device) and a second user device (e.g., a connected user device) associated with the entity requesting access, such that the entity can be authenticated as the user it claims to be and provided the requested access.

[0020] One aspect of the present disclosure is directed to a proposed system and method that uses an authentication scheme involving a contactless card that stores NFC-transmittable user authentication information (e.g., readable by a mobile device equipped with a reader component running a corresponding application) in combination with browser functionality that utilizes the connecting device's Bluetooth processes to enable a contactless card authentication process to authenticate a connection initiated by the connecting device.

[0021] According to some embodiments, a user may dynamically receive one or more notifications regarding the first user device and / or the second user device, prompting the user to use the first user device to authenticate a web connection initiated from the second user device. In other embodiments, the first user device may directly transmit authentication information to a destination website that requests authentication in order to authenticate a connection initiated from the second user device.

[0022] Some embodiments of the present disclosure are directed to providing two-factor authentication strength based on verifying that an entity requesting access to a user's sensitive information is in possession of two devices, namely, a first user device (e.g., a smartphone, a tablet with an NFC reader) and an NFC-tagged contactless card, while only requiring a single authentication action and / or input from the user (e.g., tapping an NFC-enabled contactless card to a reader of the first user device that is actively paired with a (second) connected device). As mentioned above, the proposed context-switching authentication scheme can be enabled, for example, via any proximity-based electronic pairing protocol that can be established between two user devices.

[0023] One aspect of the present disclosure relates to a method for implementing context switching authentication, the method including launching a specific authentication application stored on the first user device in response to a message received over a Bluetooth link established between the first user device and the second user device. The message may include a URI identifying the specific authentication application stored on the first user device. When launched, the authentication application may provide a list of authentication schemes available on the first user device, each authentication scheme being associated with one or more authentication runs performed by a user using the first user device. Upon successful completion of the authentication process (based on the user's selection of an authentication scheme), the authentication application may generate one or more authentication tokens indicating successful authentication results for the user-selected authentication scheme. The authentication tokens are transmitted from the first user device to the second user device over the Bluetooth link and, when transmitted to a corresponding web server, authenticate web access requests initiated from a browser running on the second user device.

[0024] Information exchanged between the first and second user devices over the Bluetooth interoperability link may be encrypted and may include one or more users' personally identifiable information (PII) and / or payment credential information (PCI).

[0025] According to some embodiments, the one or more authentication executions performed using the first user device may include entering one or more user login credentials into the first user device and / or entering a temporary one-time password transmitted as text and / or voice into the first user device to verify the user's identity.

[0026] The URI encoded in the message received by the first user device via the Bluetooth link may include a HyperText Transfer Protocol (HTTP) deep link to redirect the user to an information page if the authentication application is not installed on the first user device. In some embodiments, the URI may be coded to redirect the user to an application store to download the authentication application if the authentication application is not installed on the first user device. In some embodiments, the URI may include a universal link using a custom format with one or more identifiers that specify a target application to launch on the first user device. In some embodiments, the URI may include a Uniform Resource Locator (URL).

[0027] According to some embodiments, one or more authentication tokens generated by an authentication application running on a first user device are sent to an authentication request web server via a backend application programming interface (API) integration with the authentication request web server to authenticate a web access request initiated by a browser running on a second user device.

[0028] One aspect of the present disclosure may relate to a system for implementing context switching authentication. The system may include a computer hardware device that implements an authentication process according to the embodiments described above. Another aspect of the present disclosure may relate to a non-transitory computer readable medium that includes instructions for execution by the computer hardware device, which upon execution of the instructions may cause the computer hardware device to perform procedures according to one or more of the embodiments described above.

[0029] 1 illustrates an example system 100 that implements context switching authentication utilizing a first user device (e.g., user mobile device 110) to authenticate a sensitive data access request (129) initiated by a second user device (120) across a standard network connection (128) to a network device that hosts sensitive data (e.g., a web server 150 storing secure data 153). The request for sensitive data (129) may be initiated by the second user device (e.g., for purposes of this disclosure, the user computing device 120 is also referred to as the access requester or connecting user device) and transmitted across the network connection 128 to a destination web server (e.g., web server 150).

[0030] With reference to the exemplary embodiment 100 shown in FIG. 1 , the BLE link (134) between the first and second user devices may be invoked by a request for authentication data (130) sent by a destination web server (e.g., web server 150) to the access-requesting user device (120) in an attempt to authenticate a request for access (129) to sensitive and / or secure data 153 stored therein.

[0031] In addition to the first and second user devices, the exemplary system 100 may further include an application server (e.g., application server 140) communicatively coupled to the user mobile device 110 and responsive to one or more communications from one or more applications (e.g., application 113) stored on the user mobile device 110. The application server (140) may also be connected to a database (e.g., database 144) that may be used to store one or more user personally identifiable information (PII) and / or payment credential information (PCI). Although FIG. 1 illustrates an example of one component, the system 100 may include any number of components.

[0032] Returning to FIG. 1, a first user device (e.g., user mobile device 110) can receive one or more messages 125 over a BLE link (134) for a second user device (e.g., user computing device 120) located within Bluetooth pairing proximity of the first user device (110).

[0033] The one or more messages (125) may include a request for authentication data (130) received from the web server (150) and / or one or more electronic notifications and / or messages of specific authentication data required by the (destination) web server (150) before the (access request) second user device (120) is granted access to the requested sensitive data (e.g., secure data 153) via the network connection (128). The message (125) may further include an authentication response, i.e., one or more authentication tokens (126), generated by an authentication application (114) running on the first user device (110) and / or a corresponding application (143) running on the application server (140). In some embodiments, the generation of the authentication tokens (126) may be performed in part by an application (from the application suite 143) running on the application server (140) and in part by the authentication application (114) running on the first user device (110).

[0034] A request for authentication data (130), interchangeably referred to for purposes of this disclosure as an authentication request (130), may be generated at the (destination) web server (150) in response to the sensitive data access request (129) and transmitted to the access requesting device (e.g., user computing device 120) via a network connection (128). Upon receipt by the access requesting device (120), the authentication request (130) may be wirelessly transmitted from the access requesting device (120) via a dynamically activated BLE link (134) to the first user device (110) for authentication processing. Upon completion of the authentication process, one or more authentication tokens (126) may be generated (indicating successful authentication) and transmitted to the access requesting user device (120) via the BLE link. The authentication tokens (126) may then be included in an authentication response (131) and communicated to the appropriate web server (e.g., web server 150) via, for example, a network connection (128) established via network (127).

[0035] As mentioned above, according to some embodiments of the present disclosure, the authentication process may be facilitated by an authentication application (114) stored on the user mobile device. The authentication application (114) may have one or more application components stored on the first user device and / or one or more components stored on a corresponding application server (140). In some embodiments, a user authentication process responsive to one or more authentication requests received by the user mobile device (110) over a Bluetooth Low Energy (BLE) link (e.g., BLE link 134) may be facilitated by the authentication application (114) performing one or more client-side operations and further communicating over the network 127 with one or more of the applications 143 of the application server (140) to initiate one or more server-side operations related to the user authentication process. According to the example embodiment 100, the user authentication process may correspond to the generation of an authentication token (126) that may be directly transmitted to the second user device (120) over the BLE link (134). The authentication token 126 is then transmitted over the network connection 128 to the web server 150, enabling the access-requesting (second user) device (120) to access the secure data 153 hosted on the web server 150.

[0036] In some embodiments, the authentication token 126 may be transmitted from the user mobile device (110) via the BLE link 134 to the access requesting device (e.g., user computing device 120) and from there to the web server 150 via a network connection (128) established via the network 127. The authentication token may also be transmitted directly by the (first) user mobile device (110) and / or the application server (120) to an appropriate web server (e.g., web server 150), e.g., via the network 127. The web server (150) may store information regarding different authentication signatures from one or more verified sources, e.g., to facilitate verification and validation of the authentication token 126 included in the authentication response (131).

[0037] The user mobile device (110) may send one or more user-related data messages to the application server (140). The user-related data may correspond to one or more user identification information stored, in part or in whole, on the user mobile device (110) and / or the application server (140). The user-related data may also correspond to one or more real-time captured user inputs provided in response to one or more actionable notifications received by the user mobile device (110).

[0038] The user mobile device 110 may be a network-enabled computing device. Exemplary network-enabled computing devices include, but are not limited to, a server, a network facility, a personal computer, a workstation, a telephone, a handheld personal computer, a personal digital assistant, a thin client, a fat client, an Internet browser, a mobile device, a kiosk, a contactless card, or other computing or communication device. For example, a network-enabled computing device may include an Apple® iPhone®, an iPod®, an iPad®, or other mobile device running Apple's iOS® operating system, a device running Microsoft®'s Windows® mobile operating system, a device running Google®'s Android® operating system, and / or other smartphones, tablets, or similar wearable mobile devices.

[0039] A first user device (e.g., user mobile device 110) may include a processor (111), memory (112), and one or more applications (113). The processor 111 may be a processor, microprocessor, or other processor, and the first user device 110 may include one or more of these processors. The processor 111 may include processing circuitry that may include additional components including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware necessary to perform the functions described herein.

[0040] The processor 111 may be coupled to a memory 112. The memory (112) may be a read-only memory, a write-once read-multiple memory, or a read / write memory, e.g., RAM, ROM, and EEPROM, and the user mobile device 110 may include one or more of these memories. The read-only memory may be factory programmable as read-only or may be one-time programmable. One-time programmable means that it is written once and can be read many times. The write-once read-multiple memory can be programmed at a time after the memory chip leaves the factory. Once programmed, the memory cannot be rewritten, but can be read many times. The read / write memory can be programmed and reprogrammed many times after the factory, and can be read many times. The memory 112 may store one or more software applications (113), and the memory 112 may also store user-related information, such as the user's private and / or financial account information.

[0041] The one or more software applications 113 may be one or more mobile applications, a web browser with one or more browser extensions, one or more electronic data collection and authentication applications, and / or one or more banking applications with, for example, integrated authentication functionality. The application 113 may further include instructions to execute on the first user device (e.g., user mobile device 110). In some examples, the first user device 110 may execute one or more applications, such as software applications that enable network communication with one or more components of the system 100, transmit and / or receive data, and perform functions described herein. Upon execution by the processor 111, one or more applications from the application 113 may provide the functionality described herein, and in particular, execute and perform steps and functions within the process flows described herein. For example, the authentication application 114 may perform one or more client-side operations in performing one or more user authentication processes in response to one or more authentication requests received at the second user device (120) via the BLE link (134). Execution of the authentication process and subsequent generation of the authentication token 126 may be performed in part or in whole by the authentication application 114 and / or a corresponding server-side application 143 stored on the application server (140). The authentication token 126, indicating a successful authentication result, may then be transmitted by the first user device (110) to the user computing device (120) via the same BLE link (134) over which the one or more messages (125) containing the authentication request (130) were received by the first user device (110). The authentication token 126 is then transmitted by the second user device (120) to the web server 150 via the network connection 128, as indicated by data transfer (131).Upon verifying the authentication token (126), the web server (140) can validate the sensitive data access request (129) and grant the access-requesting (second) user device (120) access to the secure data (153), as illustrated by the data transfer path (132) shown with respect to the exemplary embodiment 100 of FIG. 1.

[0042] Such processes may be implemented in software, such as software modules, for execution by a computer or other machine. One or more applications may further provide a graphical user interface (GUI) through which a user can view and interact with other components and devices within system 100. The GUI may be formatted, for example, as a HyperText Markup Language (HTML), Extensible Markup Language (XML) web page, or in any other suitable format for presentation on a display device depending on the application being used by a user to interact with system 100.

[0043] The first user device (e.g., user mobile device 110) may further include input / output (I / O) devices 115. The I / O devices may include any type of device for presenting visual information, such as a display or computer monitor, flat panel display, and mobile device screen, including liquid crystal display, light emitting diode display, plasma panel, and cathode ray tube display. The I / O devices 115 may also include any device for inputting information available and supported by the user device (110), such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder, or camcorder. The I / O devices 115 may also include a reading device (116) that allows for automatic acquisition / reading of data, for example, using a near field communication (NFC) protocol. The I / O devices (115) may be used to input and / or read information and interact with the software and other devices described herein.

[0044] The application server 140 may be a network-enabled computing device. Exemplary network-enabled computing devices may include, but are not limited to, servers, network appliances, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, Internet browsers, mobile devices, kiosks, contactless cards, or other computing and / or communications devices. For example, network-enabled computing devices may include Apple's iPhone, iPod, iPad, or other mobile devices running Apple's iOS operating system, devices running Microsoft's Windows mobile operating system, devices running Google's Android operating system, and / or other smartphones, tablets, or similar wearable mobile devices.

[0045] The application server 140 may include a processor (141), memory (142), and one or more applications (143). The processor 141 may be a processor, microprocessor, or other processor, and the application server 140 may include one or more of these processors. The processor (141) may include processing circuitry that may include additional components, including additional processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, necessary to perform the functions described herein.

[0046] The processor 141 may be coupled to a memory 142. The memory 142 may be a read-only memory, a write-once read-multiple memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the application server (140) may include one or more of these memories. The read-only memory may be factory programmable as read-only or may be one-time programmable. One-time programmable means that it is written once and can be read many times. The write-once read-multiple memory may be programmed at a time after the memory chip leaves the factory. Once programmed, the memory cannot be rewritten, but can be read many times. The read / write memory may be programmed and reprogrammed many times after the factory. It may also be read many times. The memory 142 may store one or more software applications, such as an application suite 143. The application server 140 may store data corresponding to the PII and PCI of one or more users.

[0047] The application suite 143 may include one or more software applications that include instructions to execute on the application server (140). In some examples, the application server 140 may execute one or more applications, such as software applications that enable network communication with one or more components of the system 100, transmit and / or receive data, and perform functions described herein. When executed by the processor (141), one or more applications from the application suite 143 may provide the functionality described herein. For example, one or more applications from the application suite (143) may execute one or more server-side operations to implement a user authentication process in response to one or more authentication requests received by the user mobile device (110) for the (second) access-requesting user device (120) over a Bluetooth Low Energy (BLE) link (e.g., BLE link 134). The one or more authentication requests may then be communicated to the application server (140) over the network (127). For example, one or more applications from the application suite 143 stored on the application server (140) can provide one or more server-side functions to generate an authentication token (126) that can be sent back to a corresponding application (e.g., authentication application 114) on the user mobile device (110) and from there to the requesting device (120) via the BLE link (134). The authentication token 126 can then be included in an authentication response (131) and sent over the network connection 128 to the web server 150 to facilitate authentication of the sensitive data access request 129 and provide the requesting device (120) with access to the secure data (153), as represented by the data access path (132) in the exemplary system implementation (100).

[0048] Such processes may be implemented in software, such as software modules, for execution by a computer or other machine. Applications 113 and / or 143 may provide a GUI through which a user can view and interact with other components and devices in system 100. The GUI may be formatted, for example, as a HyperText Markup Language (HTML), Extensible Markup Language (XML) web page, or in any other suitable format for presentation on a display device, depending on the application being used by a user to interact with system 100.

[0049] The database 144 may include one or more databases that store data including, but not limited to, one or more user identities and / or financial account information. The database 144 may include a relational database, a non-relational database, or other database implementation, and any combination thereof, including multiple relational and non-relational databases. In some examples, the database 144 may include a desktop database, a mobile database, or an in-memory database. Furthermore, the database 144 may be hosted internally by the application server (140) or implemented externally on a separate storage device or database, or any storage device in data communication with the application server (140). The database 144 may be supported by one or more local servers or associated with a cloud-based platform.

[0050] The system 100 may also include one or more networks 127. In some examples, the network 127 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks and may connect the user mobile devices (110), the user computing devices (120), the application server (140), and the web server (150). A database 144 may be connected to the application server 140 via the network 127 and / or a direct connection (145). The network 127 may include fiber optic networks, passive optical networks, cable networks, Internet networks, satellite networks, wireless local area networks (LANs), global systems for mobile communications, personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplexing based systems, code division multiple access based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, Radio Frequency Identification (RFID), Wi-Fi, etc.

[0051] Further, network 127 may include, but is not limited to, a telephone line, fiber optics, IEEE Ethernet 902.3, a wide area network, a wireless personal area network, a LAN, or a global network such as the Internet. Additionally, network 127 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 127 may further include one network, or any number of the exemplary types of networks described above, operating as independent networks or in cooperation with one another. Network 127 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 127 may translate from other protocols to one or more protocols of a network device, or from other protocols to one or more protocols of a network device. Although network 127 is depicted as a single network, it will be understood that according to one or more embodiments, network 127 may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, an enterprise network such as a credit card association network, and a home network. Network 127 may further include or be configured to generate one or more front channels that are publicly accessible and through which communications may be observable, and one or more secure back channels that are not publicly accessible and through which communications may not be observable.

[0052] In some examples, communication between the user mobile device (110) and the application server (140) may occur using one or more front channels and one or more secure back channels. A front channel may be a communication protocol employing a publicly accessible and / or insecure communication channel. Exemplary front channels may include, but are not limited to, the Internet, open networks, and other publicly accessible communication networks. In some examples, front channel communications may include HyperText Transfer Protocol (HTTP) Secure Sockets Layer (SSL) communications, HTTP Secure (HTTPS) communications, and browser-based communications with servers or other devices.

[0053] A secure backchannel may be a communication protocol that employs a secure and / or non-publicly accessible communication channel. In some embodiments, the communication link between the user mobile device (110) and the application server (140) may correspond to a secure backchannel communication. In some examples, the select number of devices may consist of known, trusted, or otherwise previously authorized devices. Exemplary secure backchannels include, but are not limited to, closed networks, private networks, virtual private networks, offline private networks, and other private communication networks.

[0054] Returning to FIG. 1 , the request for authentication data (130) sent back to the second (access-requesting) user device (120) may include one or more instructions to obtain the required user authentication data from other sources in the paired vicinity of the access-requesting user device (120). Thus, a BLE link 134 may be established in response thereto to facilitate exchange of authentication request and / or response messages (125) between the second (connection-requesting) user device and the first (authentication-providing) user device. In an embodiment, the one or more instructions sent back with the request for authentication data (130) from the web server (150) may include a uniform resource indicator (URI) identifying an authentication mode and / or an authentication application (e.g., authentication application 114) that may be stored on the user mobile device (110) and used to facilitate the authentication process.

[0055] According to some embodiments, invocation of one or more applications (e.g., authentication application 114) stored on the user mobile device (110) may require user authentication and may be allowed to proceed only upon detection of specific user input provided in response to an authentication request (130) included in a message (125) and received by the user mobile device (110) to the (second) user computing device (120) via a BLE link (134). According to some embodiments, the user authentication related input (e.g., captured through one or more of the I / O devices 115 installed on the user mobile device 110) may be transmitted to the application server (140) for execution.

[0056] As mentioned above, one aspect of the proposed system and method is directed to an authentication scheme that includes a uniquely configured contactless card with an embedded NFC tag that stores NFC-transmittable user authentication information (e.g., readable by a mobile device equipped with a reader component and running a corresponding application). The specific structure, configuration, and operation of the contactless card (including an integrated processor, memory, NFC functionality, and a secure method of storing sensitive information as NFC-transmittable data) are described with reference to Figures 3A and 3B. An exemplary system implementation (200) of context switching authentication using the contactless card described above is shown in Figure 2.

[0057] FIG. 2 illustrates an exemplary system and method for implementing context switching authentication, for example, utilizing a contactless card (202) readable by a first user device (e.g., user mobile device 110). The contactless card (202) may include an integrated processor (203) and memory (204). The card-integrated memory (204) may store a number of items consisting of one or more applets (205) that may be communicatively coupled to one or more applications executing on the user mobile device 110 and / or one or more applications stored on a corresponding application server. The card-integrated memory (204) may also store an application transaction counter (206) that tracks a series of transactions involving the contactless card (202). The contactless card (202) may further include a near field communication (NFC) interface (207) to facilitate NFC communication with, for example, the user mobile device (110).

[0058] According to some embodiments, the contactless card (202) and user mobile device (110) can be used in combination with browser functionality to access a Bluetooth process of an access-requesting user device (e.g., second user device 120) to enable a single authentication execution involving the contactless card (202) and first user device (110) to provide strong two-step authentication for connection requests initiated by the (access-requesting) second user device (120) located within Bluetooth pairing distance of the first user device (110).

[0059] 2 utilizes a contactless card (202) having a symmetrically encrypted NFC channel (208) to a first user device (110) to encrypt and transmit user authentication data 210 (stored as NDEF data on the contactless card (202)) to, for example, an authentication application (114) running on the first user device (110). The NFC channel (208) can be activated, for example, when a reader (116) of the user mobile device (110) is brought into NFC proximity of the contactless card (202) and / or vice versa.

[0060] In the exemplary embodiment (200), an arrangement including a contactless card (202) and a user mobile device (110) is utilized in combination with a dynamically established Bluetooth communication link (e.g., BLE link 134) between a (second) access requesting device (e.g., user computing device 120) and the first user device (110) to implement two-factor authentication strength. The two-factor authentication strength can correspond, for example, to verifying that an entity or source requesting access to sensitive user information (e.g., secure data 153) from the second user device (120) is in possession of two other distinct devices, namely, the first user device (e.g., user mobile device 110) and the contactless card (202). The above-described context switching authentication scheme provides two-factor authentication strength while only requiring a single authentication action / input from the user (e.g., tapping an NFC-enabled contactless card (202) to a reader (116) of a first user device (110) that is paired in proximity with the second user device (120) (access request). The proposed context switching authentication method may be enabled, for example, via any proximity-based electronic pairing protocol that may be established between the first user device (110) and the second user device (120).

[0061] Figures 3A-3B show an exemplary contactless card 300. Although Figures 3A-3B illustrate a single component example of card 300, any number of components may be utilized.

[0062] The card 300 may be in communication with one or more components of the system 100. The card 300 may be a contact card (e.g., a card that is read by swiping a magnetic stripe or by insertion into a chip reader) or a contactless card, and the card 300 may be a payment card, such as a credit card, a debit card, or a gift card. As shown in FIG. 3A, the card 300 may be issued with a service provider name 305 displayed on the front of the card 300 (and / or on the back of the card 300). In some examples, the payment card may be a dual interface contactless payment card. In some implementations, the card 300 is unrelated to a payment card and may be, but is not limited to, an identification card, a membership card, and a transportation card.

[0063] The card 300 may include a substrate 310, which may include a single layer or one or more laminates of plastic, metal, and other materials. Exemplary substrates may be polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, biodegradable materials, and the like. In some examples, the card 300 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, and the card 300 may otherwise conform to the ISO / IEC 14443 standard. However, it will be understood that the card 300 according to the present disclosure may have different characteristics, and the present disclosure does not require implementation into a payment card.

[0064] Card 300 may also include identification information 315 displayed on the front and / or back of the card, and card 300 may include a contact pad 320. Contact pad 320 may be configured to establish contact with a user device, other communication device, including, but not limited to, a smart phone, laptop, desktop, or tablet computer. Card 300 may also include processing circuitry, an antenna, and other components not shown in FIG. 3A. These components may be located behind contact pad 320 or elsewhere on substrate 310.

[0065] The service provider name 305 may include the name and logo of the service provider, and may also include information about the service provider, including, but not limited to, a phone number, an address, instructions for handling the card 300 if lost or damaged, and other information. The service provider name 305 may also include an image or graphical design.

[0066] The identification information 315 may include, but is not limited to, an account number, a name, an expiration date, a phone number, a nickname, and other information. In some examples, the identification information 315 may further include an image or graphic design. For example, the identification information 315 may include an image, photo, drawing, or logo of the user.

[0067] As shown in Figure 3B, the contact pad 320 of Figure 3A can include processing circuitry 325 for storing and processing information, including a processor 330, such as a microprocessor, and memory 335. It is understood that the processing circuitry 325 may include additional components including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware necessary to perform the functions described herein.

[0068] The memory 335 may be a read-only memory, a write-once read-multiple memory, or a read / write memory, e.g., RAM, ROM, and EEPROM, and the card 300 may include one or more of these memories. A read-only memory may be factory programmable as read-only or one-time programmable. One-time programmable offers the opportunity to write once and read many times. A write-once read-multiple memory can be programmed at some point after the memory chip leaves the factory. Once programmed, the memory cannot be rewritten, but can be read many times. A read / write memory may be programmed and reprogrammed many times after leaving the factory, and can be read many times.

[0069] The memory 335 may store one or more applets 340, one or more counters 345, and a customer identifier 350. The one or more applets 340 may include one or more software applications that run on one or more contact or contactless cards, such as a Java Card applet. However, it is understood that the applet 340 is not limited to a Java Card applet, but may instead be any software application operable on a contact or contactless card, or other device with limited memory. The one or more counters 345 may include a numeric counter sufficient to store an integer number. The customer identifier 350 may include a unique alphanumeric identifier assigned to a user of the card 300, which may distinguish a user of a contactless card from users of other contactless cards. In some examples, the customer identifier 350 may identify both the customer and an account assigned to the customer, and may further identify the contactless card associated with the customer's account.

[0070] Although the processor and memory elements of the foregoing exemplary embodiments are described with reference to contact pads, the disclosure is not limited thereto, and it will be understood that these elements may be implemented external to the contact pads 320, may be completely separate from the contact pads 320, or may be implemented as additional elements in addition to the processor 330 and memory 335 elements disposed within the contact pads 320.

[0071] In some examples, the card 300 may include one or more antennas 355. The one or more antennas 355 may be disposed within the card 300 around the processing circuit 325 of the contact pads 320. For example, the one or more antennas 355 may be integral with the processing circuit 325, or the one or more antennas 355 may be used in conjunction with an external booster coil. As another example, the one or more antennas 355 may be external to the contact pads 320 and the processing circuit 325.

[0072] In one embodiment, the coil of the card 300 may act as the secondary of an air-core transformer. The terminal may communicate with the card 300 by disconnecting the power or amplitude modulation. The card 300 may infer data transmitted from the terminal using gaps in the card's power connection, which may be kept functional through one or more capacitors. The card 300 may return communication by switching the load or performing load modulation on the card's coil. Load modulation may be detected by the terminal's coil through interference.

[0073] FIG. 4 provides an operational overview of a context switching authentication process according to some embodiments of the present disclosure. With reference to FIG. 4, at (402), a first user device (e.g., user mobile device 110) receives a URI included in a message over a Bluetooth link established with a second user device (e.g., user computing device 120) that is within suitable range of the first user device. Upon receiving the message over the BLE link with the second user device, an authentication interface application identified by the URI is launched on the first user device (step 404). The authentication interface application may provide a list of authentication modes and programs available on the first user device (step 406). Once an authentication mode is selected and appropriate authentication input commensurate with the selected authentication mode is entered, for example using the first user device, the authentication information is verified. At step 408, one or more authentication tokens are generated, representing successful authentication of the user. The authentication process, and subsequent generation of the authentication tokens, may match the user's authentication input against previously verified and securely stored information of the user. This process may be performed by an authentication application on the user mobile device (110) and / or a corresponding server-side application on the application server (140). In some embodiments, the authentication operations may be performed in part by an authentication application on the first user device (110) and in part by the corresponding application server (140).

[0074] At step 410, an authentication token is transmitted from the first user device (110) to the second user device (120) via the Bluetooth link. In some embodiments, the authentication token may be generated and transmitted by the application server (120) directly to the device requesting access (e.g., the second user device 120) via a public network connection (e.g., network 127). At step 412, the authentication token is communicated to a web server hosting the sensitive data content (e.g., secure data 153), thereby authenticating the web access request initiated from the second user device (120). It should be noted that the web access request may be initiated by a user or automatically (e.g., by a website or application on the second user device).

[0075] FIG. 5 illustrates an example flow chart (500) corresponding to an operational overview of a context switching authentication process according to some embodiments of the present disclosure. Referring to the example flow chart (500), in step 502, a first user device (e.g., user mobile device 110) receives a URI message via a Bluetooth link established with a second user device (e.g., user computing device 1120) located within a suitable range of the first user device. Upon receipt of the message via the BLE link with the second user device, a notification is generated (e.g., user mobile device 110) that a user authenticates with a contactless card (e.g., contactless card 202) using the first user device (e.g., user mobile device 110) as a reader. In step 506, the information read from the contactless card via NFC transmission is verified. Upon verifying the information, one or more authentication tokens are generated to indicate successful verification of the NFC data transferred from the contactless card (202). The authentication tokens are generated by one or more applications stored on the user mobile device 110 and / or the application server 140. In step 510, the authentication token is transmitted from the first user device to the second user device over the active BLE link. In step 512, the authentication token is communicated to a web server requesting authentication to authenticate a secure network connection request initiated from the second user device. The secure network connection request may be user initiated or may be automatically initiated (e.g., initiated by a website or application on the second user device).

[0076] 6 shows a block diagram of an exemplary embodiment of a system according to the present disclosure. For example, the exemplary procedures according to the present disclosure described herein may be executed by a processing device and / or computing device (e.g., computer hardware device) 605. Such a processing device / computing device 605 may, for example, be in whole or in part a computer / processor 610, which may, for example, include, but is not limited to, one or more microprocessors, and may use instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard drive, other storage device).

[0077] 6, for example, a computer-accessible medium 615 (e.g., a storage device such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, or a collection thereof, as described hereinabove) may be provided (e.g., in communication with the processing unit 605). The computer-accessible medium 615 may include executable instructions 620. Additionally or alternatively, a storage device 625 may be provided separate from the computer-accessible medium 615, which may provide instructions to the processing unit 605, for example, to configure the processing unit to perform certain example procedures, processes, and methods, as described hereinabove.

[0078] Additionally, the exemplary processing device (605) may comprise or include input / output ports (635) that may include, for example, wired networks, wireless networks, the Internet, an intranet, data collection probes, sensors, etc. As shown in FIG. 6, the exemplary processing device (605) may be in communication with an exemplary display device (630), which may be, for example, a touch screen configured for input of information into the processing device in addition to output of information from the processing device, according to certain exemplary embodiments of the present disclosure. Additionally, the exemplary display device (630) and / or storage device (625) may be used to display and / or store data in a user-accessible and / or user-readable format.

[0079] As used herein, the term "card" is not limited to a particular type of card. Rather, it is understood that the term "card" can refer to a contact card, a contactless card, or other card, unless otherwise indicated. Furthermore, it is understood that the present disclosure is not limited to cards having a particular purpose (e.g., payment cards, gift cards, identification cards, membership cards, transportation cards, access cards), cards associated with a particular type of account (e.g., credit accounts, debit accounts, membership accounts), or cards issued by a particular entity (e.g., commercial organizations, financial institutions, government agencies, social clubs, etc.). Instead, it is understood that the present disclosure includes cards having any purpose, account association, or issuing entity.

[0080] The systems and methods described herein can provide secure, authenticated access to restricted electronic resources and / or websites. Once authenticated access is established, the resources and / or websites can allow, without limitation, financial transactions (e.g., credit card and debit card transactions), account management transactions (e.g., card renewal, card replacement, add new card transactions), membership transactions (e.g., immigration transactions), access point transactions (e.g., building access, secure warehouse access transactions), transportation transactions (e.g., ticketing and boarding), and other transactions.

[0081] As used herein, personally identifiable information (PII) may include any sensitive data, including financial data (e.g., account information, account balances, account activity), personal and / or personally identifiable information (e.g., social security numbers, home or work addresses, dates of birth, telephone numbers, email addresses, passport numbers, driver's license numbers), access information (e.g., passwords, security codes, authentication codes, biometric data), and other information that a user wishes to avoid exposing to unauthorized persons.

[0082] The present disclosure is not limited in terms of the specific embodiments described in this application, which are intended as examples of various aspects. Clearly, many modifications and variations can be made without departing from the spirit and scope thereof. In addition to those recited herein, functionally equivalent methods and apparatuses within the scope of the present disclosure will be apparent from the above exemplary description. Such modifications and variations are intended to be included within the scope of the appended exemplary claims. The present disclosure is limited only by the terms of the appended exemplary claims, along with the full scope of equivalents to which such exemplary claims are entitled. It should also be understood that the terms used herein are for the purpose of describing specific embodiments only, and are not intended to be limiting.

[0083] Further, it should be noted that the systems and methods described herein may be embodied in one or more physical media, such as, but not limited to, a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a hard drive, a read-only memory (ROM), a random access memory (RAM), and other physical media capable of storing data. For example, data storage devices include random access memory (RAM) and read-only memory (ROM), which may access and store data and information as well as computer program instructions. For example, a data storage device may be a storage medium or other suitable type of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disk, optical disk, floppy disk, hard disk, removable cartridge, flash drive, any type of tangible and non-transitory storage medium, etc.), in which an operating system, application programs, including, for example, a web browser application, an email application, and / or other applications, and files constituting data files are stored. The data storage of a network-enabled computer system may include electronic information, files, and documents stored in a variety of ways, including flat files, indexed files, hierarchical databases, relational databases, such as databases created and maintained with software from Oracle® Corporation, Microsoft® Excel files, Microsoft® Access files, solid-state storage devices which may include flash arrays, hybrid arrays, or server-side products, enterprise storage which may include online or cloud storage, or any other storage mechanism. Additionally, the diagram shows the various components (e.g., servers, computers, processors, etc.) individually.The functions described as being performed by various components may be performed by other components, the various components may be combined or separated, and other variations are possible.

[0084] In the preceding specification, various embodiments have been described with reference to the accompanying drawings. It will be apparent, however, that various modifications and changes may be made thereto, and additional embodiments may be implemented, without departing from the broader scope of the invention as defined in the claims which follow. The specification and drawings are therefore to be regarded in an illustrative rather than a restrictive sense.

Claims

1. 1. A method for performing context switching authentication, comprising: receiving a transmission over a Bluetooth link established between a first user device and a second user device by an authentication application stored on the first user device, the message including a Uniform Resource Indicator (URI) identifying the authentication application; generating, by the authentication application, a list of authentication schemes available to the first user device, each authentication scheme being associated with one or more authentication actions using the second user device; generating, by said authentication application, one or more authentication tokens representing successful authentication of a user-selected authentication scheme; authenticating a web access request initiated from a browser running on the second user device by transmitting one or more authentication tokens from the first user device to the second user device via the Bluetooth link; A method comprising:

2. 2. The method of claim 1, wherein the one or more authentications performed include one or more of: entering login credentials using the first user device; entering a temporary one-time password transmitted as text and / or voice into the first user device to verify identity.

3. The method of claim 1 , wherein the URI includes a HyperText Transfer Protocol (HTTP) deep link that redirects the first user device to an information page if the authentication application is not installed on the first user device.

4. 2. The method of claim 1, wherein the URI is coded to redirect the first user device to an application store to download the authentication application if the authentication application is not installed on the first user device.

5. The method of claim 1 , wherein the URI comprises a universal link using a custom format having one or more identifiers that specify a target application to be launched on the first user device.

6. 2. The method of claim 1, wherein a website loaded by the browser of the second user device includes instructions to initiate a Bluetooth process on the second user device to establish a connection with the first user device that is within pairing distance of the second user device.

7. The method of claim 1 , wherein information exchanged between the first user device and the second user device over the Bluetooth link is encrypted.

8. The method of claim 1 , wherein information exchanged between the first user device and the second user device over the Bluetooth link includes one or more user personally identifiable information (PII).

9. The method of claim 1 , wherein information exchanged between the first user device and the second user device over the Bluetooth link includes payment related information.

10. an authentication scheme from a list of authentication schemes available to the first user device corresponds to verification of one or more pieces of information obtained by performing an NFC read of a contactless card by the first user device; The method of claim 1 , wherein the contactless card stores one or more user identification information as NFC transmittable data.

11. The method of claim 1 , wherein the one or more authentication actions correspond to a single user action of placing a contactless card within NFC range of the first user device.

12. The method of claim 1 , wherein the one or more authentication tokens are sent from the first user device to an authentication request web server via a back-end Application Programming Interface (API) integration with the authentication request web server.

13. 1. A system for implementing context switching authentication, comprising: The system includes a computer hardware device. The computer hardware device includes: receiving a message over a Bluetooth link established between a first user device and a second user device, the message including a Uniform Resource Indicator (URI) identifying an authentication application stored on the first user device; generating a list of authentication schemes available to the first user device, each authentication scheme being associated with one or more authentication attempts performed by a user using the second user device; generating one or more authentication tokens representing successful authentication of a user-selected authentication scheme; authenticating a web access request initiated from a browser running on the second user device by transmitting one or more authentication tokens to the second user device via the Bluetooth link; Run the system.

14. 14. The system of claim 13, wherein the computer hardware device further provides an authentication scheme including using the first user device as a reader to perform Near Field Communication (NFC) reading of a contactless card that stores user identification information as NFC transmittable data, and generating the one or more authentication tokens.

15. 15. The system of claim 14, wherein the computer hardware device transmits the one or more authentication tokens generated by the authentication scheme to an authentication request web server via a back-end application programming interface (API) integration with the authentication request web server.

16. 14. The system of claim 13, wherein the computer hardware device further encrypts information exchanged between the second user device and the first user device over the Bluetooth link.

17. 14. The system of claim 13, wherein the computer hardware device transmits personally identifiable information (PII) of one or more users as part of information exchanged over the Bluetooth link.

18. A non-transitory computer readable medium containing instructions that, when executed, cause the computer hardware device to: receiving a message over a Bluetooth link established between a first user device and a second user device, the message including a Uniform Resource Indicator (URI) identifying an authentication application stored on the first user device; generating a list of authentication schemes available on the first user device, the list of authentication schemes being responsive to a selection input made using the first user device, each authentication scheme being associated with one or more authentication attempts performed by a user using the first user device; generating one or more authentication tokens representing successful authentication of a user-selected authentication scheme; authenticating a web access request initiated from a browser running on the second user device by transmitting one or more authentication tokens to the second user device via the Bluetooth link; A non-transitory computer-readable medium for executing the method of the present invention.

19. 20. The non-transitory computer-readable medium of claim 18, wherein the authentication scheme used to generate the one or more authentication tokens corresponds to performing an NFC read of a contactless card by the first user device, the contactless card storing a user's identification information as NFC transmittable data.

20. 20. The non-transitory computer-readable medium of claim 18, further comprising instructions to cause the computer hardware device to transmit one or more authentication tokens generated by a selected authentication scheme to an authentication request web server via a back-end application programming interface (API) integration with the authentication request web server.