Settings for applications of devices using contactless cards

The use of a contactless card to transmit an encryption key and apply configuration information to devices securely and automatically addresses the challenges of configuring new devices, enhancing security and efficiency.

JP2025519121APending Publication Date: 2025-06-24CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2024569354
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-05-23
Filing Date
2023-04-24
Publication Date
2025-06-24

AI Technical Summary

Technical Problem

Configuring new or additional devices is cumbersome, time-consuming, and error-prone, as they often lack the applications and configurations of previous devices.

Method used

A system and method that uses a contactless card to configure applications on a device by receiving an encryption key, transmitting it to a server, and applying configuration information to the device's applications based on the verified key.

Benefits of technology

Enables secure, automatic, and efficient configuration of devices by ensuring that only authorized access can initiate the configuration process, thereby enhancing security and simplifying the setup of various applications and operating systems.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025519121000001_ABST
    Figure 2025519121000001_ABST
Patent Text Reader

Abstract

A system, method, apparatus, and computer-readable medium for configuring an application on a device using a contactless card. An application executed on the device may receive a cipher from a contactless card associated with an account. The application may transmit the cipher to a server. The application may receive configuration information for a plurality of applications associated with the account based on the cipher. The application may change the respective configurations of each application on the device based on the configuration information.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the benefit of priority to U.S. Patent Application No. 17 / 664,460, filed on May 23, 2022, entitled "Application Configuration of an Apparatus Using a Contactless Card". The entire content of the above application is incorporated herein by reference in its entirety.

Background Art

[0002] Configuring new or additional devices is cumbersome, time-consuming, and error-prone. For example, a user may purchase a new device to replace another device. However, the new device does not include the applications or configurations of the other device.

Summary of the Invention

[0003] A system, method, apparatus, and computer-readable medium for configuring applications on a device using a contactless card. In one aspect, the method includes receiving, by an application executing on a device, an encryption key from a contactless card associated with an account; transmitting, by the application, the encryption key to a server; receiving, by the application, configuration information of a plurality of applications associated with the account based on the encryption key; and changing each setting of each application on the device based on the configuration information.

Brief Description of the Drawings

[0004]

Figure 1A

Figure 1B

Figure 1C

Figure 1D

Figure 2A

Figure 2B

Figure 2C

Figure 2D

Figure 3

Figure 4

Figure 5

Figure 6A

Figure 6B

Figure 7

Figure 8

[0005] To facilitate the identification of discussions regarding specific elements or acts, the most significant digit or digits of a reference number refer to the figure number in which the element first appears.

[0006] The embodiments disclosed herein provide a secure technique for automatically configuring devices such as smartphones, tablets, or other computer devices using a contactless card. Examples of configuring a device include installing an application on the device, uninstalling an application from the device, and / or setting an application on the device (e.g., changing application settings, application parameters, etc.). First, a user can register one or more applications and / or setting information of one or more applications. Doing so may include storing information about a given device and / or account in an account database. Registration may associate the application and / or setting information with the contactless card.

[0007] Thereafter, the user can tap the contactless card against any device, which may include previously registered devices, new devices, existing devices, etc. In some embodiments, tapping the card on the device may cause the card to generate an encryption key. In some embodiments, the encryption key is a parameter of a Uniform Resource Locator (URL). When the device receives the URL and / or the encryption key, the device can launch an application and send the encryption key to a server for verification. The server verifies the encryption key based at least in part on decrypting the encryption key.

[0008] In other embodiments, tapping the card on the device may cause the device to launch a web browser based on the URL. In such embodiments, the web browser can access a page associated with the URL. The server identifies the encryption key as a parameter of the URL accessed by the web browser. The server can verify the encryption key based at least in part on decrypting the encryption key.

[0009] Regardless of the application that is launched in response to tapping a card on the device, after verifying the cipher, the server can use the cipher (and / or cipher parameters) to identify relevant applications and / or application configuration information within the account database. In some embodiments, the server sends the configuration information to the device via one or more push notifications. In some embodiments, such as when the configuration information has a size exceeding a threshold, the server may send one or more tokens to the device.

[0010] Once received, the device can apply the received configuration information to each application. For example, the configuration information can include account login authentication information, server information for establishing a connection to one or more servers, user preferences, settings, and the like. In some embodiments, the configuration information may include information about one or more applications not installed on the device. In such embodiments, these applications may be downloaded and installed on the device based on receipt of the configuration information. Similarly, the configuration information may include information for disabling or uninstalling existing applications. In such embodiments, the device may disable and / or uninstall these applications based on the configuration information.

[0011] Advantageously, the embodiments disclosed herein provide a secure technique for automatically configuring a device using a contactless card. By requiring cipher verification to initiate the configuration, the security of the user's account, applications, device, and data is enhanced. Further, this ensures that the automatic configuration of the device is only executed when the user has access to a contactless card that facilitates cipher verification with the server. Additionally, by providing the disclosed automatic configuration feature, many different applications, operating systems, and / or devices can be automatically configured without the need for integration into all applications, operating systems, and / or devices.

[0012] Referring generally to the notations and nomenclature used herein, the detailed description herein may be presented from the perspective of program procedures executed on a computer or a network of computers.

[0013] A procedure is here, and generally is considered to be a self - consistent series of operations that lead to a desired result. These operations require physical manipulation of physical quantities. Although not necessarily so, usually these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is mainly for convenience in common usage that such signals are referred to as bits, values, elements, symbols, characters, terms, numbers, etc.

[0014] Furthermore, the operations performed are often referred to in terms such as addition or comparison, which are generally associated with mental operations performed by a human operator. In any of the operations described herein that form part of one or more embodiments, such capabilities of a human operator are not required and, in most cases, not desirable. Rather, the operations are machine operations. Machines useful for performing the operations of the various embodiments include digital computers or similar devices.

[0015] Some embodiments may be described using the expressions "coupled" and "connected" and their derivatives. These terms are not necessarily intended to be synonyms of each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other but still cooperate or interact with each other.

[0016] Various embodiments also relate to an apparatus or system for performing these operations. This apparatus may be specially constructed for the required purposes, or it may include a computer selectively activated or reset by a computer program stored in the computer. The procedures shown herein are not inherently related to a particular computer or other apparatus. Various machines may be used with a program written in accordance with the teachings herein, or it may prove convenient to construct a more specialized apparatus to perform the required method steps. The required structure for these various machines will be apparent from the given description.

[0017] Next, reference is made to the drawings, where like reference numerals are used throughout to refer to like elements. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding. However, the novel embodiments may be practiced without these specific details. In other instances, structures and devices are shown in block diagram form in order to facilitate the description.

[0018] In the figures and the accompanying description, designations such as “a” and “b” and “c” (and similar designators) are intended to represent variables that represent any positive integer. Thus, for example, if an implementation sets a value of a = 5, the complete set of components 123 illustrated as components 123-1 to 123-a (or 123a) can include components 123-1, 123-2, 123-3, 123-4, and 123-5.

[0019] FIG. 1A shows an exemplary computing architecture 100, also referred to as a system, that is consistent with the disclosed embodiments. The computing architecture 100 shown in FIGS. 1A through 1C has a limited number of elements in a particular topology, but it can be understood that the computing architecture 100 can include more or fewer elements in alternative topologies as desired for a given implementation.

[0020] Computing architecture 100 includes one or more computer devices 102, one or more servers 106, and one or more contactless cards 104. The contactless card 104 is representative of any type of card, such as a credit card, debit card, ATM card, gift card, payment card, smart card, etc. The contactless card 104 can include one or more communication interfaces 124 (also referred to herein as a "card reader", "wireless card reader", and / or "wireless communication interface") that communicate with the communication interface 124 of the device 102 (which is also referred to herein as a "card reader", "wireless card reader", and / or "wireless communication interface") via NFC, EMV standard, or other short - range protocols in wireless communication. Although NFC is used as an example of a communication protocol herein, the present disclosure is equally applicable to other types of wireless communication such as the EMV standard, Bluetooth, and / or Wi - Fi.

[0021] The computer device 102 represents any number and type of computer devices, such as a smartphone, tablet computer, wearable device, laptop, portable game device, virtualized computing system, merchant terminal, POS system, server, desktop computer, etc. Mobile devices can be used as an example of the computer device 102, but should not be considered as limiting the present disclosure. The server 106 represents any type of computer device, such as a server, workstation, computing cluster, cloud computing platform, virtualized computing system, etc. Although not depicted for clarity, the computer device 102, contactless card 104, and server 106 each include one or more processor circuits for executing, for example, programs, code, and / or instructions.

[0022] As shown, the memory 108 of the contactless card 104 includes an applet 110, counters 116, one or more master keys 114, one or more diversification keys 120, a unique ID 112, a primary account number (PAN) sequence number 144, and one or more unique derived keys (UDKs) 118. The unique ID 112 may be any identifier that uniquely identifies the contactless card 104 as compared to other contactless cards 104. The PAN sequence 144 may include a counter value stored by the contactless card 104. The applet 110 is executable code that performs some or all of the operations described herein. The counter 116 is a value that is synchronized between the contactless card 104 and the server 106. The counter 116 may include a numerical value that changes each time data is exchanged between the contactless card 104 and the server 106 (and / or between the contactless card 104 and the computer device 102). The counter 116, the master key 114, the diversification key 120, the UDK 118, the PAN sequence 144, and / or the unique ID 112 are used to provide security in the system 100 as described in further detail below.

[0023] As shown, the memory 132 of the device 102 includes an instance of an operating system 134. Examples of operating systems include the Android® OS, iOS®, macOS®, Linux®, and Windows® operating systems. As shown, the operating system 134 includes an account application 136 and one or more other applications 146. The account application 136 enables a user to perform various operations such as configuring the device 102 based on the configuration information 148 stored by the server 106. In some embodiments, the account application 136 can further perform other account-related operations such as activating a payment card, viewing account balances, purchasing items, processing payments, and the like. In some embodiments, a user can authenticate using authentication credentials to access specific features of the account application 136. For example, the authentication credentials can include a username (or login) and password, biometric information (fingerprint, face ID, etc.). The other applications 146 are representative of any type of application such as a web browser, an email client, a messaging client, a social media application, and the like.

[0024] As shown, the memory 126 of the server 106 includes an authentication application 138 and an account database 128. The account database 128 generally includes information related to account holders (e.g., one or more users), one or more accounts of the account holders, and one or more contactless cards 104 of the accounts. For example, as shown, the account database 128 can include configuration information 148 for a plurality of accounts. The configuration information 148 can include any data that configures the computer device 102, the operating system 134, the account application 136, other applications 146, and / or any of their components. For example, the configuration information 148 can include information for connecting to one or more servers (e.g., Internet Protocol (IP) address, port, etc.), account information (e.g., login / password), the contents of the received tray (e.g., messages, emails, etc.), preferences, variable values, and / or settings. The configuration information 148 can further include executable files, scripts, etc. that install and / or configure one or more portions of the configuration information 148 on a predetermined computer device 102. Since the configuration information 148 can be used to change any attributes and / or functions of the computer device 102 and / or any of its software components, embodiments are not limited in this context.

[0025] As described above, the setting information 148 can be used to automatically configure the computer device 102. In other words, the setting information 148 can represent a "backup" of at least a portion of a given device and / or account (including any applications, operating systems, and / or parameters), and any device can be restored to a state similar to the backup. For example, when a user purchases a new smartphone, the setting information 148 from the previous smartphone can be used to automatically configure the new smartphone. For example, the setting information 148 can be used to install applications on the new smartphone (e.g., applications that were not included with the smartphone at the time of purchase but were installed on the previous smartphone and registered as part of the setting information 148), delete applications that were not installed on the previous smartphone from the new smartphone (delete restricted applications based on the setting information 148), apply settings and / or parameters from the old smartphone to the new smartphone, and so on.

[0026] In various embodiments, a user can first register the configuration information 148 with the server 106. For example, the user can access the functionality of the account application 136, access a web page, or access any other resource to register the configuration information 148 for any device and / or account. The configuration information 148 may be unique to all devices associated with the account and / or a subset of the devices associated with the account. Additionally and / or alternatively, the configuration information 148 may be unique to all applications associated with the account and / or a subset of the applications associated with the account. In some embodiments, the account application 136 may collect information describing the computer device 102, such as installed applications, configuration files, etc., which may be stored as the configuration information 148. In other embodiments, the user may provide an input specifying different applications, configurations, functions, etc. of a given device. In some embodiments, the configuration information 148 includes the package name of each application being registered, metadata describing the operating system 134 being registered (e.g., device identifier, device version, preferences, settings, etc.), metadata describing each application being registered, preferences, login information, application ID, or other attributes of the device, application, operating system 134, and / or their components. Further, the configuration information 148 can be associated with an account in the account database 128, whereby the server 106 can further associate the configuration information 148 with one or more contactless cards 104 associated with the account.

[0027] For example, a user can register a social media application and an email client with server 106. Accordingly, the configuration information 148 for the user includes the package names of the social media application and the email client, the connection information for the media application and the email client to connect to each server, the user's identity in the social media application and the email application, the email inbox (or folder) of the email client, the social media profile in the social media application, the social media messages in the social media application, the versions of the social media application and the email client, display settings (e.g., enabling dark mode in any application), enabling push notifications in any application, access permissions for each application within the operating system 134, etc. The embodiments are not limited to this context. Accordingly, the display of such information may be stored as the configuration information 148 of the account.

[0028] Thereafter, the user can desire to configure the computer device 102 using the configuration information 148. For example, the computer device 102 may be a new smartphone, and the user may desire to configure the social media application and the email client (e.g., restoring all emails of the email client, loading the social media profile / settings of the social media application, etc.). In some embodiments, since these applications may not be installed on the new smartphone, the configuration information 148 can be further used to download the social media application and / or the email client for installation on the computer device 102. To initiate the configuration of the device based on the configuration information 148, the user may tap the contactless card 104 on the computer device 102.

[0029] In the embodiment depicted in FIG. 1A, the user can tap the contactless card 104 on the computer device 102 (or place the contactless card 104 within the communication range of the communication interface 124 of the device 102). Thereafter, the applet 110 may generate an encryption key 122. The encryption key 122 may be generated based on any suitable encryption technique. In some embodiments, the encryption key 122 may be based on the unique ID 112 of the contactless card 104. In some embodiments, the applet 110 may include the encryption key 122 and unencrypted identifiers (e.g., counter 116, PAN sequence 144, unique ID 112, and / or other unique identifiers) as part of a data package that includes the encryption key 122. In at least one embodiment, the data package is an NDEF file.

[0030] As described above, the computing architecture 100 performs key diversification to protect data, which may be referred to herein as a key diversification technique. Generally, the server 106 (or other computer device) and the contactless card 104 may be provided with the same master key 114 (also referred to as a master symmetric key). More specifically, each contactless card 104 is programmed with a separate master key 114 that has a pair corresponding to the hardware security module (HSM) 130 of the server 106. For example, when the contactless card 104 is manufactured, a unique master key 114 may be programmed into the memory 108 of the contactless card 104. Similarly, the unique master key 114 may be stored in a record 142 within the HSM 130.

[0031] Further, when a predetermined card 104 is manufactured, the UDK 118 may be diversified from the master key 114 via an HSM function that takes as input a diversifying coefficient and a reference to the master key 114 index within the HSM 130 (e.g., an index to record 142). In some embodiments, the diversifying factor may be the unique ID 112 of the contactless card 104 and / or the PAN sequence 144. The UDK 118 may be stored in the contactless card 104 and the record 142 of the HSM 130. The master key 114 and the UDK 118 can be kept secret from all parties other than the contactless card 104 and the server 106, thereby enhancing the security of the system 100. Although depicted as being stored in the record 142, in some embodiments, the counter 116 and / or the PAN sequence 144 are not stored in the HSM 130. For example, the unique ID 112, the counter 116, and the PAN sequence 144 may be stored in the account database 128.

[0032] In some embodiments, to generate the cipher 122, the applet 110 provides the UDK 118, the unique ID 112, and the diversifying coefficient as input to the cryptographic algorithm, thereby generating the diversified key 120. In some embodiments, the diversifying factor is the counter 116. In other embodiments, the PAN sequence 144 is the diversifying factor. The diversified key 120 can then be used to encrypt some data such as the diversifying factor (e.g., the counter 116 and / or the PAN sequence 144) or other confidential data. The applet 110 and the server 106 may encrypt the same type of data to facilitate the decryption and / or verification process of the cipher.

[0033] As described above, the UDK 118 of the contactless card 104 and the server 106 can be used in combination with the counter 116 to enhance security using key diversification. As described above, the counter 116 includes a value that is synchronized between the contactless card 104 and the server 106. The counter 116 may include a numerical value that changes each time data is exchanged between the contactless card 104 and the server 106 (and / or the contactless card 104 and the device 102). When preparing to send data (e.g., to the server 106 and / or the device 102), the applet 110 of the contactless card 104 may increment the counter 116. Thereafter, the applet 110 of the contactless card 104 provides the UDK 118, the unique ID 112, and the counter 116 as inputs to an encryption algorithm, which generates a diversified key 120 as an output. Encryption algorithms include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cipher-based message authentication code (CMAC) algorithms, etc. Non-limiting examples of encryption algorithms include symmetric encryption algorithms such as 3DES and AES107, symmetric HMAC algorithms such as HMAC-SHA-256, symmetric CMAC algorithms such as AES-CMAC, etc. An example of key diversification technology is described in detail in U.S. Patent Application 16 / 205,119, filed on November 29, 2018. The aforementioned patent application is hereby incorporated by reference in its entirety. In some embodiments, the PAN sequence 144 is used as an input to the encryption algorithm instead of the counter 116, for example, by encrypting the UDK 118, the unique ID 112, and the PAN sequence 144 to generate the diversified key 120.

[0034] Applet 110 can then encrypt some data (e.g., unique ID 112, counter 116, PAN sequence 144, command, and / or any other data) using the diversification key 120 and the data as input to the encryption algorithm. For example, encrypting the unique ID 112 with the diversification key 120 can result in an encrypted unique ID 112 (e.g., ciphertext 122). As described above, the applet 110 and the server 106 may encrypt the same data.

[0035] In some embodiments, two diversification keys 120 may be generated based on, for example, one or more portions of the input to the encryption function. In some embodiments, the two diversification keys 120 are generated based on two different master keys 114, two different UDKs 118, the unique ID 112, and the counter 116 (or PAN sequence 144). In such embodiments, one of the diversification keys 120 may be used to generate a message authentication code (MAC), and the other of the diversification keys 120 may be used to encrypt the MAC. The MAC may be generated based on any suitable data input to the MAC algorithm, such as sensitive data, the unique ID 112, the counter 116, and / or the PAN sequence 144. More generally, the applet 110 and the server 106 may generate the MAC based on the same data. In some embodiments, the ciphertext 122 is included in a data package such as an NDEF file. Then, the account application 136 can read the data package containing the ciphertext 122 via the communication interface 124 of the computer device 102.

[0036] In some embodiments, the applet includes the cipher 122 as a URL parameter. For example, the URL is "http: / / www.example.com / appconfig?param=ABC123&custID=123". In such an example, the cipher 122 may correspond to the parameter "ABC123", and the unique ID 112 may correspond to the parameter "custID". When received by the operating system 134, the operating system 134 can open an application for processing the URL. In some embodiments, the URL may be registered with the account application 136, whereby the operating system 134 launches the account application 136 and provides the URL 120 as input to the account application 136. However, in other examples, the operating system 134 may launch a web browser and provide the URL as input to the web browser. In other embodiments, the cipher 122 is not a URL parameter but is sent with the URL in a data package such as an NDEF file. In such embodiments, the operating system 134 can read the data package including the URL and the cipher 122 via the communication interface 124 of the computer device 102.

[0037] In the example shown in FIG. 1A, the operating system 134 can launch the account application 136 based on reading the cipher 122. As described above, the cipher 122 may be a URL parameter. In such an example, the URL may be associated with the account application 136. Thereby, the operating system 134 launches the account application 136. Next, the account application 136 can extract the cipher 122 and send the cipher 122 to the server 106 for verification.

[0038] In embodiments where the cipher 122 is not a parameter of the URL, the operating system 134 can launch the account application 136 based on reading the cipher 122 and / or the NDEF file containing the cipher 122. The operating system 134 may provide the cipher 122 to the account application 136. Next, the account application 136 can extract the cipher 122 and send the cipher 122 to the server 106 for verification.

[0039] In some embodiments, the account application 136 (or other applications used to configure the computer device 102 based on the configuration information 148) may not be installed on the device. In some such embodiments, the operating system 134 may cause the account application 136 to be downloaded and installed on the computer device 102 based on the URL and / or the cipher 122. In other such embodiments, an application clip (e.g., Apple® App Clip), an instant application (e.g., Android™ instant application), or a progressive web application (e.g., Android progressive web application) that includes the disclosed functionality of the account application 136 may be downloaded and installed on the computer device 102 to configure the computer device 102 based on the configuration information 148. In such embodiments, the app clip, instant application, and / or progressive web application may be automatically deleted from the computer device 102 after the configuration information 148 has been used to configure the computer device 102.

[0040] Figure 1B shows an embodiment in which the account application 136 transmits the ciphertext 122 to the server 106. The server 106 can provide the ciphertext 122 to the authentication application 138 and / or the HSM 130 for verification based at least in part on an instance of the master key 114 and / or the UDK 118 stored by the server 106. In some embodiments, the authentication application 138 and / or the HSM 130 may identify the UDK 118 (or the master key 114) and the counter 116 using the unencrypted unique ID 112 provided to the server 106. In an example where the PAN sequence 144 is used in the generation of the ciphertext 122, the server 106 may identify the PAN sequence 144 in the account database 128 and / or the HSM 130 using the unencrypted unique ID 112. In some examples, the authentication application 138 can provide the UDK 118, the unique ID 112, and the counter 116 as inputs to the encryption function of the HSM 130, and the HSM 130 generates one or more diversified keys 120 as outputs. In other embodiments, the server encrypts the UDK 118, the unique ID 112, and the PAN sequence 144 to generate the diversified key 120. The resulting diversified key 120 corresponds to the diversified key 120 of the contactless card 104 and can be used for decrypting the ciphertext 122 and / or verifying the MAC after it has been decrypted once. For example, the server 106 may generate a MAC based on the same data as the applet 110, such as confidential data, the unique ID 112, the counter 116, and / or the PAN sequence 144. If the MAC generated by the server 106 matches the decrypted MAC of the ciphertext 122, the server 106 can verify or authenticate the ciphertext 122.

[0041] Regardless of the decryption technique used, the authentication application 138 and / or the HSM 130 can verify and / or authenticate the ciphertext 122 by successfully decrypting the ciphertext 122 and verifying the MAC. If the decryption and / or MAC verification is successful, the authentication application 138 can identify the account setting information 148 by referring to the account database 128. In some embodiments, the authentication application 138 can access the setting information 148 based on the unencrypted unique ID 112 provided to the server 106. Since any suitable identifier can be used to access the account setting information 148, the embodiments are not limited in this context. The server 106 may further send a response to the computer device 102 (e.g., to the account application 136 and / or the operating system 134) indicating that the server 106 can verify the ciphertext 122 and use the setting information 148 to configure the computer device 102.

[0042] Next, the authentication application 138 can analyze the setting information 148 to identify each application, operating system, and / or setting registered therein. Continuing with the previous example, the setting information 148 can include instructions for a social media application and an email client. As will be described in more detail below, the server 106 can then send the setting information 148 (and / or a portion thereof) to the computer device 102.

[0043] Returning to decryption, if the authentication application 138 cannot decrypt the ciphertext 122 (and / or cannot verify the MAC), the authentication application 138 does not verify the ciphertext 122. In such an example, the authentication application 138 determines to refrain from accessing the setting information 148 to automatically configure the computer device 102. The authentication application 138 can send a response to the computer device 102 that includes a display of the failed decryption and / or verification and a display that the setting information 148 cannot be used to configure the computer device 102.

[0044] FIG. 1C shows an embodiment in which the authentication application 138 sends a push notification 150 including the configuration information 148 to the account application 136 for each identified application or other software component in the configuration information 148 within the account database 128. In some embodiments, the push notification 150 may include an indication that the server 106 has verified the cipher 122 and that the computer device 102 may be configured using the configuration information 148. Although depicted as being sent in a single push notification, in some embodiments, the server 106 may send multiple push notifications to the computer device 102, each push notification including at least a portion of the configuration information 148. In some embodiments, a given push notification may be received in the background of the operating system 134 (e.g., a background push notification that is sent directly to the corresponding application and / or operating system 134 rather than being output for display on the computer device 102). In some embodiments, the push notification is a foreground push notification (e.g., a notification displayed on the device 102). In some embodiments, the configuration information 148 includes one or more configuration files.

[0045] Furthermore, in some embodiments, the size of the configuration information 148 (and / or a portion thereof) may exceed a size threshold (e.g., 1 megabyte, 10 megabytes, etc.). In such embodiments, the server 106 may generate one or more tokens, associate each token with one or more portions of the configuration information 148, and send the one or more tokens to the computer device 102. The computer device 102 may then send the token to the server 106 to retrieve the associated configuration information 148 (and / or a portion thereof) from the server 106. For example, by associating the token with the configuration information 148, the server 106 can provide the associated configuration information 148 based on receipt of the token from the account application 136, the operating system 134, and / or other applications 146.

[0046] In some embodiments, the device 102 may transmit the configuration information 148 and / or the token to the contactless card 104. The contactless card 104 may then store the configuration information 148 and / or the token in the memory 108. The computer device 102 may then receive the configuration information 148 from the contactless card 104 (e.g., via NFC in response to a tap of the contactless card 104 on the computer device 102) to configure the computer device 102 and any of its components as described herein.

[0047] Further, as shown, FIG. 1C shows an embodiment in which the computer device 102 includes, in addition to the account application 136, three different applications, e.g., other application 146-1, other application 146-2, and other application 146-N. Advantageously, the account application 136 can use the configuration information 148 to configure these applications on the computer device 102.

[0048] FIG. 1D shows an embodiment in which the account application 136 uses one or more portions of the configuration information 148 received from the server 106 to configure the computer device 102. As described above, the account application 136 may condition the use of the configuration information 148 based on a response from the server 106 indicating that the server 106 has verified the cipher 122 and may use the configuration information 148 to configure the computer device 102. As shown, the account application 136 uses the configuration information 148-1 to configure another application 146-1 and uses the configuration information 148-N to configure another application 146-N. In some embodiments, the account application 136 may analyze the configuration information 148 to generate the configuration information 148-1 to 148-N. In other embodiments, the server 106 generates the configuration information 148 to include multiple files, each file for each application or other entity configured on the computer device 102. Thus, in such embodiments, the configuration information 148-1 to 148-N is generated by the server 106. In some embodiments, at least a portion of the configuration information 148 is associated with the account application 136 and is thus used to configure the account application 136 (e.g., load user profiles, settings, etc.).

[0049] In some embodiments, the account application 136 stores (or writes) the configuration information 148 as each configuration file at a location associated with each application and / or the operating system 134. For example, the account application 136 may store the configuration information 148-1 as a configuration file for use with a file name and / or file location associated with a file storing the configuration information of another application 146-1 (e.g., the application 146-1). As another example, the account application 136 may use a portion of the configuration information 148 to store and / or modify one or more files, registry settings, or other parameters of the operating system 134. In some such examples, the account application 136 may provide the configuration information 148 to the operating system 134, and the operating system 134 may use the configuration information 148 to modify the operating system 134. In some embodiments, using the configuration information 148 may result in writing new configuration information to the computer device 102, modifying some of the existing configuration information of the computer device 102 (e.g., by changing values, settings, etc.), and / or leaving other existing configuration information of the computer device 102 unchanged.

[0050] Furthermore, the account application 136 uses the configuration information 148-3 to determine that the application 146-3 is not installed on the computer device 102. In such an embodiment, the account application 136 uses the configuration information 148-3 (e.g., the package name of the application 146-3) to download the application 146-3 from the Internet. Thereafter, the account application 136 can configure the application 146-3 as described herein using the configuration information 148-3.

[0051] Similarly, the account application 136 determines, using the configuration information 148, that other applications 146-2 are not registered in the configuration information 148. In some embodiments, the account application 136 determines, based on the configuration information 148, that other applications 146-2 are restricted applications. For example, a company can restrict the use of social media applications on a device. Thus, based on the configuration information 148, the account application 136 causes the computer device 102 to uninstall other applications 146-2 or otherwise disable them. In some embodiments, the account application 136 may permanently restrict the user from reinstalling or otherwise enabling other applications 146-2 (e.g., by configuring the operating system 134 to restrict the installation and / or enabling of other applications 146-2 on the computer device 102).

[0052] In some embodiments, the account application 136 may require additional permissions to configure the computer device 102. For example, the account application 136 may need access to a storage medium (e.g., non-volatile memory and / or volatile memory, not shown for clarity) of the computer device 102, such as read, write, or other access to the storage device. In such embodiments, the account application 136 and / or the operating system 134 can request to permit access to storage for the account application 136, which can be permitted by the user and thus by the operating system 134.

[0053] Thus, by setting the computer device 102 using the configuration information 148, the computer device 102 can be automatically set to include all relevant applications, settings, and / or functions. For example, by setting an email client using the configuration information 148, a user can view emails, receive new emails, connect to an email server, and send new emails. Embodiments are not limited in this context. Further, before setting the computer device 102 using the configuration information 148, the user cannot view emails, receive emails, connect to an email server, or send emails using the email client (without manually configuring the email client).

[0054] FIG. 2A is a schematic diagram 200 showing an embodiment that uses a web browser 206 to perform at least a portion of the automatic configuration of the computer device 102. In the example depicted in FIG. 2A, the contactless card 104 generates a URL with an encrypted code 204 in response to tapping the contactless card 104 on the computer device 102. The URL with the encrypted code 204 can include the encrypted code generated as described above with reference to the encrypted code 122, along with other relevant information (such as an unencrypted identifier, etc.). More generally, the URL with the encrypted code 204 can be generated as described above with reference to FIGS. 1A-1D.

[0055] When read by the operating system 134 (not shown in the figure for clarity), the operating system 134 can launch a web browser 206 (e.g., one of the other applications 146) and provide the web browser 206 with the URL with the encrypted code 204. By doing so, the web browser 206 can access the URL with the encrypted code 204 (or a portion thereof). In some embodiments, the URL with the encrypted code 204 is directed to a configuration page for automatically configuring the computer device 102. Embodiments are not limited in this context.

[0056] FIG. 2B illustrates an embodiment in which web browser 206 accesses a URL with cipher 204, for example, based on a Hypertext Transfer Protocol (HTTP) request that includes the URL with cipher 204. As illustrated, authentication application 138 can receive the URL with cipher 204 based on the HTTP request. Authentication application 138 can extract the cipher from the URL with cipher 204 for verification. For example, server 106 can decrypt the cipher as described above and / or verify the MAC included therein to verify the cipher.

[0057] Based on server 106 verifying the cipher (e.g., decrypting the cipher in the URL with cipher 204 and / or verifying the MAC), server 106 can identify associated configuration information 148 by referring to account database 128. Server 106 may further send a response to computer device 102 (e.g., to web browser 206 and / or operating system 134) indicating that based on the verification, server 106 verified cipher 122 and may configure computer device 102 using configuration information 148. In some embodiments, authentication application 138 can access configuration information 148 based on unencrypted unique ID 112 provided to server 106 in the URL with cipher 204. The embodiments are not limited in this context as any suitable identifier can be used to access account configuration information 148.

[0058] On the other hand, if server 106 cannot decrypt the cipher and / or verify the MAC, server 106 does not verify the cipher. In such an example, authentication application 138 determines to refrain from accessing configuration information 148 for automatically configuring computer device 102.

[0059] FIG. 2C shows an embodiment in which server 106 verifies the encrypted portion of the URL with cipher 204. As described above, when server 106 verifies the cipher, server 106 accesses the account setting information 148 associated with the contactless card 104. Next, server 106 can identify a plurality of different applications represented in setting information 148. For each identified application, server 106 may generate each push notification that includes the associated setting information 148 and / or a portion thereof.

[0060] As shown, server 106 sends push notification 208, push notification 210, and push notification 212 to computer device 102. As shown, push notification 208 includes setting information 148-1, push notification 210 includes setting information 148-2, and push notification 212 includes setting information 148-N. In such an example, each push notification and each instance of the setting information therein may be associated with each application running on the device. In some embodiments, the push notifications may also include push notifications sent to operating system 134, which may include setting information 148 applicable to operating system 134 (e.g., enabling a blue light filter, a do not disturb function, etc.). In some embodiments, push notifications 208, 210, and / or 212 may include each indication that server 106 verified cipher 122 and that computer device 102 may be configured using setting information 148.

[0061] In some embodiments, push notifications 208, 210, and / or 212 may be received in the background of the operating system 134 (e.g., background push notifications that are sent directly to the corresponding application and / or operating system 134 rather than being output for display on the computer device 102). In some embodiments, push notifications 208, 210, and / or 212 are foreground push notifications (e.g., notifications displayed on the device 102). In some embodiments, the configuration information 148 includes one or more configuration files. Further, in some embodiments, the sizes of the configuration information 148-1 to 148-N may exceed a size threshold. In such embodiments, the server 106 can generate one or more tokens and include each token in each of the push notifications 208, 210, and 212. Once received, each application can provide the received token to the server 106 to retrieve the associated configuration information 148 (and / or a portion thereof) from the server 106.

[0062] FIG. 2D shows an embodiment in which push notifications 208, 210, and 212 are received by other applications 146-1, 146-2, and 146-N, respectively. Generally, once received, the other applications 146-1, 146-2, and 146-N can use the configuration information 148-1, 148-2, and 148-N, respectively, for configuration. For example, the other application 146-1 may be configured based on the configuration information 148-1, the other application 146-2 may be configured based on the configuration information 148-2, and the other application 146-N may be configured based on the configuration information 148-N. In some embodiments, the other applications 146-1, 146-2, and 146-N, and / or the operating system 134 condition the use of the configuration information 148 based on receiving from the server 106 an indication that the server 106 has verified the cipher 122 and that the configuration information 148 is available for use in configuring the computer device 102.

[0063] In some embodiments, the configuration information 148 is stored as respective configuration files in locations associated with each application and / or the operating system 134. For example, another application 146-1 may store the configuration information 148-1 as a configuration file for the other application 146-1 (e.g., with a file name and / or file location associated with the file storing the configuration information for the application 146-1). As another example, another application 146-1 may use a portion of the configuration information 148-1 to store and / or modify one or more files, registry settings, or other parameters of the operating system 134 that configure the other application 146-1. In some such examples, another application 146-1 may provide the configuration information 148-1 to the operating system 134, and the operating system 134 may use the configuration information 148 to modify the operating system 134. Similarly, application 146-2 may store the configuration information 148-2 as a configuration file for the other application 146-2, and application 146-N may store the configuration information 148-N as a configuration file for the other application 146-N.

[0064] In some embodiments, using the configuration information 148-1 through 148-N may cause new configuration information to be written to the computer device 102, may cause some of the existing configuration information of the computer device 102 to be changed (e.g., by changing values, settings, etc.), and / or may cause some other existing configuration information of the computer device 102 to remain unchanged.

[0065] Similar to the embodiments depicted in FIGS. 1A through 1D, the configuration information 148 may be used to install and / or uninstall applications from the computer device 102. For example, the operating system 134 may receive a push notification 210 and determine that the application 146-2 is not installed on the computer device 102. In such an instance, the operating system 134 may download the application 146-2 from, for example, an application store, the Internet, etc., and install it on the computer device 102. Similarly, if the configuration information 148-N specifies that the application 146-N is not permitted to be installed on the device and / or was not registered in the configuration information 148, the configuration information 148-N may cause the application 146-N to initiate removal (and / or inactivation) of the application 146-N from the computer device 102.

[0066] Advantageously, the configuration information 148 is used to automatically configure and / or restore the computer device 102. By requiring verification of the encryption, the configuration of the computer device 102 is completed in a secure manner. More generally, a user may quickly restore a backup, configure a new device, and / or apply the configuration information 148 from one device to another.

[0067] The operations of the disclosed embodiments may be further described with reference to the following figures. Some of the figures include logical flows. Although such figures presented herein may include a specific logical flow, it should be understood that the logical flow provides only an example of how the general functions described herein may be implemented. Further, a given logical flow need not necessarily be executed in the order presented, unless otherwise indicated. Further, in some embodiments, not all of the acts illustrated in the logical flow are required. Further, a given logical flow may be implemented by hardware elements, software elements executed by a processor, or any combination thereof. Embodiments are not limited in this context.

[0068] Figure 3 shows one embodiment of a logical flow (routine) 300. The logical flow 300 may represent some or all of the operations performed by one or more of the embodiments described herein. For example, the logical flow 300 may include some or all of the operations for automatically configuring a device using configuration information and a contactless card. Embodiments are not limited in this context.

[0069] In block 302, routine 300 receives a cipher (e.g., a cipher such as cipher 122 and / or a cipher of a URL with cipher 204) from contactless card 104 associated with the account by account application 136 executed on computer device 102. In block 304, routine 300 transmits the cipher to server 106 by account application 136. In block 306, routine 300 receives, by account application 136, configuration information 148 of a plurality of applications associated with the account based on the server verifying the cipher. Server 106 can include a display specifying that the server 106 verified cipher 122 and that it may be possible to configure computer device 102 using configuration information 148, along with configuration information 148. The applications may include other applications 146, operating system 134, and / or account application 136. In block 308, routine 300 modifies the respective settings of each application on computer device 102 based on configuration information 148.

[0070] Figure 4 shows one embodiment of a logical flow (routine) 400. Logical flow 400 may represent some or all of the operations performed by one or more of the embodiments described herein. For example, logical flow 400 can include some or all of the operations of automatically configuring a device using configuration information and a contactless card. Embodiments are not limited in this context.

[0071] In block 402, routine 400 registers with server 106 a plurality of applications associated with account and / or computer device 102 and the setting information of each application. By doing so, setting information 148 can be stored in at least one entry associated with the account in account database 128. In block 404, routine 400 receives, by computer device 102, a ciphertext (e.g., ciphertext with cipher 122 and / or ciphertext of URL with cipher 204) from contactless card 104 associated with the account. In block 406, routine 400 transmits, by computer device 102, the ciphertext to server 106. In block 408, routine 400 determines, by computer device 102, based on the response received from server 106, that server 106 verifies the ciphertext and that setting information 148 can be used to configure computer device 102. In block 410, routine 400 receives, by computer device 102, setting information 148 for a plurality of applications associated with the account based on the verification of the ciphertext by server 106. The applications can include other applications 146, operating system 134, and / or account application 136.

[0072] In block 412, based on the determination that the first application is not installed on the computer device 102, the computer device 102 downloads the first application (e.g., one of the other applications 146) to the computer device. In block 414, the routine 400 installs the first application on the device by the computer device 102. In block 416, the routine 400 uninstalls the second application (e.g., another one of the other applications 146) from the computer device 102 based on the configuration information 148. For example, the configuration information 148 can specify to uninstall or disable the second application. In block 418, the routine 400 modifies the respective settings of each application by the computer device 102 based on the configuration information 148.

[0073] FIG. 5 shows an embodiment of a logical flow or routine 500. The logical flow 500 can represent some or all of the operations performed by one or more of the embodiments described herein. For example, the logical flow 500 can include some or all of the operations for automatically configuring a device using configuration information and a contactless card. Embodiments are not limited in this context.

[0074] In block 502, routine 500 registers, by the server, the setting information of each application having a plurality of applications and accounts. By doing so, the setting information 148 may be stored in an entry associated with the account in the account database 128. In block 504, routine 500 receives, by the computer device 102, a URL with an encryption 204 from the contactless card 104 associated with the account. In block 506, routine 500 launches, by the computer device 102, a web browser based on the URL with the encryption 204. In block 508, routine 500 transmits, by the web browser 206, at least the encryption to the server 106 by accessing, for example, a web page associated with the URL with the encryption 204. In block 510, routine 500 determines, by the web browser 206, based on the response received from the server, that the server has verified the encryption from the URL with the encryption 204 and that the setting information 148 can be used to configure the computer device 102.

[0075] In block 512, routine 500 receives, by computer device 102, configuration information 148 of a plurality of applications associated with an account based on verification of an encryption by a server. The applications can include other applications 146, an operating system 134, and / or an account application 136. In block 514, routine 500 downloads, by the device, a first application to computer device 102 based on a determination that the first application is not installed on computer device 102. In block 516, routine 500 installs, by computer device 102, the first application on computer device 102. In block 518, routine 500 uninstalls, by computer device 102, a second application (e.g., one of the other applications 146) from computer device 102 based on configuration information 148. For example, the configuration information 148 can specify to uninstall or disable the second application. In block 520, routine 500 changes, by computer device 102, each setting of each application based on configuration information 148.

[0076] FIG. 6A is a schematic diagram 600 showing a configuration example of the contactless card 104, which can include a payment card such as a credit card, a debit card, or a gift card issued by a service provider and displayed as service provider information 602 on the front or back of the contactless card 104. In some examples, the contactless card 104 is unrelated to a payment card and, without limitation, may include an identity certificate. In some examples, the transaction card may include a dual interface contactless payment card, a point card, and the like. The contactless card 104 may include a substrate 604, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrates include polyvinyl chloride, polyvinyl acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 104 has physical characteristics compliant with the ID-1 format of the ISO / IEC 7816 standard, and the transaction card complies with the ISO / IEC 14443 standard. However, it is understood that the contactless card 104 according to the present disclosure may have different characteristics, and the present disclosure does not require implementing a transaction card in a payment card.

[0077] The contactless card 104 can also include identification information 606 displayed on the front and / or back of the card and contact pads 608. The contact pads 608 can include one or more pads and can establish contact with another client device such as an ATM, device, smartphone, laptop, desktop, or tablet computer via the transaction card. The contact pads are designed according to one or more standards such as the ISO / IEC 7816 standard and can enable communication according to the EMV protocol. The contactless card 104 can also include a processing circuit, an antenna, and other components as further described in FIG. 6B. These components may be arranged behind the contact pads 608 or at other locations on the substrate 604, such as within different layers of the substrate 604, and may be electrically and physically coupled to the contact pads 608. The contactless card 104 may also include a magnetic strip or tape, which may be arranged on the back of the card (not shown in FIG. 6A). The contactless card 104 can also include a near field communication (NFC) device coupled to an antenna capable of communicating via the NFC protocol. Embodiments are not so limited.

[0078] As shown in FIG. 6B, the contact pads 608 of the contactless card 104 can include a processing circuit 610 for storing, processing, and communicating information, including a processor 612, a memory 108, and one or more communication interfaces 124. It is understood that the processing circuit 610 may include additional components as necessary to perform the functions described herein, including a processor, a memory, an error and parity / CRC checker, a data encoder, a collision avoidance algorithm, a controller, a command decoder, a security primitive, and anti-counterfeiting hardware.

[0079] Memory 108 may be a read-only memory, a write-once / read-multiple memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 104 may include one or more of these memories. The read-only memory may be programmable as read-only at factory shipment or may be one-time programmable. The one-time programmable provides an opportunity to read as many times as written once. The write-once / read-multiple memory can be programmed after the memory chip is shipped from the factory. The programmed memory cannot be rewritten but can be read as many times as possible. The read / write memory can be programmed and reprogrammed many times after factory shipment. The read / write memory may also be read many times after factory shipment. In one embodiment, the memory 108 may be an encrypted memory that utilizes an encryption algorithm executed by the processor 612 to encrypt data.

[0080] The memory 108 may store one or more applets 110, one or more counters 116, a unique ID 112, a master key 114, a UDK 118, a diversification key 120, a PAN sequence 144, and setting information 148. The setting information 148 may include one or more tokens generated by the server 106. The one or more applets 110 may include one or more software applications that execute on one or more contactless cards 104, such as Java (registered trademark) card applets. However, it is understood that the applet 110 is not limited to Java card applets and may be any software application operable on a contactless card or other device having limited memory. The one or more counters 116 may include numerical counters sufficient to store integers. The unique ID 112 may include a unique alphanumeric identifier assigned to the contactless card 104, and the identifier may distinguish the contactless card 104 from other contactless cards 104. In some examples, the unique ID 112 can identify both the customer and the account assigned to that customer.

[0081] The processor 612 and memory elements of the foregoing exemplary embodiments have been described with reference to the contact pads 608, but the present disclosure is not limited thereto. These elements may be implemented outside the contact pads 608, may be completely separated from the contact pads 608, or may be implemented as additional elements in addition to the processor 612 and memory 108 elements disposed within the contact pads 608.

[0082] In some examples, the contactless card 104 may include one or more antennas 614. The one or more antennas 614 may be disposed within the contactless card 104 around the processing circuit 610 of the contact pads 608. For example, the one or more antennas 614 may be integral with the processing circuit 610, and the one or more antennas 614 may be used with an external booster coil. As another example, the one or more antennas 614 may be external to the contact pads 608 and the processing circuit 610.

[0083] In one embodiment, the coil of the contactless card 104 may function as the secondary side of an air-core transformer. The terminal can communicate with the contactless card 104 by cutting off the power or amplitude modulation. The contactless card 104 may infer data transmitted from the terminal using the gap in the power connection of the contactless card 104, and this data may be functionally maintained via one or more capacitors. The contactless card 104 may send back communication by switching the load on the coil of the contactless card 104 or by load modulation. Load modulation may be detected by the coil of the terminal due to interference. More generally, using the antenna 614, the processor 612, and / or the memory 108, the contactless card 104 provides a communication interface for communicating via NFC, Bluetooth, and / or Wi-Fi communication.

[0084] As described above, the contactless card 104 may be built on a software platform operable on a smart card having limited memory such as a Java card or other device, and one or more applications or applets may be securely executed. The applet 110 may be added to the contactless card to provide one-time passwords (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet 110 may respond to one or more requests such as a short-range data exchange request from a reader such as a mobile NFC reader (e.g., the mobile computer device 102 or a POS terminal), and generate an NDEF message consisting of an encrypted and secure OTP encoded as an NDEF text tag. The NDEF message may include an encryption such as an encrypted URL with encryption 122 or encryption 204, and other data.

[0085] An example of an NDEF OTP is an NDEF short record layout (SR = 1). In such an example, one or more applets 110 may encode the OTP as a well-known type of text tag of NDEF type 4. In some examples, the NDEF message may include one or more records.

[0086] In some examples, one or more applets 110 may emulate an RFID tag. The RFID tag may include one or more polymorphic tags. In some examples, each time the tag is read, different encrypted data that may indicate the authenticity of the contactless card is presented. Based on one or more applets 110, the NFC reading of the tag is processed, and the data is sent to a server such as a server of a banking system, and the data may be verified at the server.

[0087] In some examples, the contactless card 104 and the server can include specific data so that the card is properly identified. The contactless card 104 can include one or more unique identifiers (not shown). Each time a read operation is performed, the counter 116 may be incremented. In some examples, each time data from the contactless card 104 is read (e.g., by a device), the counter 116 is sent to the server for verification, and it is determined whether the counter 116 is equal to the server's counter (as part of the verification).

[0088] One or more counters 116 may prevent replay attacks. For example, if a cipher is obtained and replayed, if the counter 116 is read, used, or otherwise delivered, the cipher is immediately rejected. If the counter 116 has not been used, it may be replayed. In some examples, the counter incremented on the contactless card 104 is different from the counter incremented for a transaction. Since there is no communication between applets 110 on the contactless card 104, the contactless card 104 cannot determine the application transaction counter 116. In some examples, the contactless card 104 may include a first applet 440-1 and a second applet 440-2 that may be transaction applets. Each applet 440-1, 440-2 may include its own counter 116.

[0089] In some examples, the counters 116 may not be synchronized. In some examples, the counter 116 may be incremented to account for accidental reads that initiate a transaction, such as a skewed read, but the application may not process the counter 116.

[0090] To keep counter 116 in a synchronized state, an application such as a background application may be executed that detects when computer device 102 is started and synchronizes with a server of a banking system where the read generated by the detection indicates advancement of counter 116. In other examples, hashed one-time passwords may be utilized such that a window of mis-synchronization is acceptable. For example, if within a threshold of 10, counter 116 may be advanced. However, within a different threshold, for example within 10 or 1000, a request to perform re-synchronization may be processed that requests, via one or more applications, that the user indicate one or more times via tapping, gestures, or other means through the user's device, and the user may be made aware if counter 116 is incremented in the appropriate order.

[0091] The key diversification techniques described herein with reference to counter 116, master key 114, UDK 118, and diversification key 120 are an example of encryption and / or decryption by key diversification techniques.

[0092] In the process of creating contactless card 104, two cryptographic keys may be uniquely assigned per card. The cryptographic keys may include symmetric keys used for both encryption and decryption of data. The Triple DES (3DES) algorithm may be used in EMV and is implemented in the hardware of contactless card 104. By using a key diversification process, one or more keys can be derived from a master key based on uniquely identifiable information for each entity that requires a key.

[0093] In some examples, to overcome the deficiencies of the 3DES algorithm that is vulnerable to attacks, a session key may be derived (such as a key unique for each session), but instead of using the master key, a unique card-derived key (e.g., UDK118) and a counter may be used as diversifying data. For example, each time the contactless card 104 is in operation, different keys may be used for creating a message authentication code (MAC) and performing encryption. As a result, triple encryption of the cipher is realized. The session key may be generated by one or more applets and derived by using an application transaction counter with one or more algorithms (defined in EMV 4.3 Book 2 A1.3.1 Common Session Key Derivation).

[0094] Furthermore, the increment for each card may be unique and may be assigned by personalization or algorithmically assigned by some identification information. For example, odd-numbered cards may be incremented by 2 each time, and even-numbered cards may be incremented by 5 each time. In some examples, the increment may also change in sequential reads such that one card increments in order by repeating 1, 3, 5, 2, 2,.... A specific sequence or algorithm sequence may be defined at the time of personalization or may be defined from one or more processes derived from a unique identifier. This can make it difficult for a replay attacker to generalize from a small number of card examples.

[0095] The authentication message may be delivered as the content of a text NDEF record in hexadecimal ASCII format.

[0096] FIG. 7 shows an NDEF Short Record Layout (SR = 1) data structure 700 according to an exemplary embodiment. One or more applets 110 may encode the OTP as a well-known type of text tag of NDEF type 4. In some examples, the NDEF message includes one or more records. The applet may add one or more static tag records in addition to the OTP record. Exemplary tags include, but are not limited to, tag type: well-known type, text, English encoding (en); applet ID: D2760000850101; performance: read-only access; encoding: the authentication message may be encoded as ASCII hexadecimal. The type length value (TLV) data, which may be provided as a personalization parameter used in the generation of the NDEF message. In one embodiment, the authentication template may include a first record having a well-known index for providing actual dynamic authentication data. The data structure 700 may include an encryption such as an encrypted URL with encryption 122 or encryption 204, and any other data provided by the applet 110.

[0097] FIG. 8 shows an embodiment of an exemplary computer architecture 800 suitable for implementing various embodiments as described above. In one embodiment, the computer architecture 800 may include or be implemented as part of the computing architecture 100 and / or 200. In some embodiments, the computing system 800 may represent, for example, a contactless card 104, a computer device 102, and / or a server 106. The embodiments are not limited in this context. More generally, the computing architecture 800 implements all of the logic, applications, systems, methods, devices, and functions described herein with reference to FIGS. 1A through 7.

[0098] As used in this application, the terms "system" and "component" are intended to refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution, examples of which are provided by the exemplary computing computer architecture 800. For example, a component can be a process running on a processor, a processor, a hard disk drive, a plurality of storage drives (of optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer, but is not limited thereto. By way of illustration, both an application running on a server and the server can be components. One or more components can exist within a process and / or execution thread, a component can be localized on one computer, and / or can be distributed between two or more computers. Further, components can be communicatively coupled to each other by various types of communication media and can be coordinated in their operations. This coordination involves information exchange, which can be unidirectional or bidirectional. For example, a component can communicate information in the form of signals communicated through a communication medium. The information can be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, in further embodiments, alternatively, data messages can be employed. Such data messages can be transmitted through various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0099] The computer architecture 800 includes various common computing elements such as one or more processors, multi-core processors, coprocessors, memory units, chip sets, controllers, peripheral devices, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to implementation by the computing computer architecture 800.

[0100] As shown in FIG. 8, computer architecture 800 includes a computer 812 consisting of a processor 802, a system memory 804, and a system bus 806. The processor 802 may be any of a variety of commercially available processors. The computer 812 can represent the computer device 102 and / or the server 106.

[0101] The system bus 806 provides an interface to the processor 802 for system components including, but not limited to, the system memory 804. The system bus 806 can be any of several types of bus structures and can further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures. An interface adapter can be connected to the system bus 806 via a slot architecture. Exemplary slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, (Extended) Industry Standard Architecture ((E)ISA), Micro Channel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extended) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), and the like.

[0102] Computer architecture 800 can include or implement various manufactured products. The manufactured product can include a computer-readable storage medium that stores logic. Examples of computer-readable storage media can include any tangible medium capable of storing electronic data, such as volatile or non-volatile memory, removable or non-removable memory, erasable or non-erasable memory, writable or rewritable memory, etc. Examples of logic can include executable computer program instructions implemented using any suitable type of code, such as source code, compiled code, interpreter code, executable code, static code, dynamic code, object-oriented code, visual code, etc. Embodiments can also be at least partially included in a non-transitory computer-readable medium or implemented as instructions included in a non-transitory computer-readable medium, the instructions being readable and executable by one or more processors to enable performance of the operations described herein.

[0103] The system memory 804 can include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory, polymer memory such as ferroelectric polymer memory, ovonic memory, phase change memory or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, an array of devices such as a RAID (Redundant Array of Independent Disks) drive, solid state memory devices (e.g., USB memory, solid state drive (SSD)), and any other type of storage medium suitable for storing information. In the illustrated embodiment shown in FIG. 8, the system memory 804 can include non-volatile 808 and / or volatile 810. The basic input / output system (BIOS) can be stored in the non-volatile 808.

[0104] Computer 812 can include various types of computer-readable storage media in the form of one or more low-speed memory units, including a built-in (or external) hard disk drive 814, a magnetic disk drive 816 for reading from or writing to a removable magnetic disk 818, and an optical disk drive 820 for reading from or writing to a removable optical disk 822 (e.g., CD-ROM or DVD). The hard disk drive 814, the magnetic disk drive 816, and the optical disk drive 820 can each be connected to the system bus 806 by an HDD interface 824, and an FDD interface 826, and an optical disk drive interface 828, respectively. The HDD interface 824 for external drive implementation can include at least one or both of universal serial bus (USB) and IEEE 1394 interface technologies.

[0105] The drives and associated computer-readable media provide volatile and / or non-volatile storage such as data, data structures, computer-executable instructions, etc. For example, a number of program modules, including an operating system 830, one or more applications 832, other program modules 834, and program data 836, can be stored on the drive and non-volatile 808, and volatile 810. In one embodiment, the one or more applications 832, other program modules 834, and program data 836 can include, for example, various applications and / or components of system 100.

[0106] The user can input commands and information into the computer 812 via one or more wired / wireless input devices such as a pointing device like a keyboard 838 or a mouse 840. Other input devices can include a microphone, an infrared (IR) remote control, a radio frequency (RF) remote control, a game pad, a stylus pen, a card reader, a dongle, a fingerprint reader, a glove, a graphics tablet, a joystick, a keyboard, a retina reader, a touch screen (e.g., capacitive, resistive, etc.), a trackball, a track pad, a sensor, a stylus, and the like. These and other input devices are often connected to the processor 802 via an input device interface 842 coupled to the system bus 806, but can also be connected by other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, and the like.

[0107] A monitor 844 or other type of display device is also connected to the system bus 806 via an interface such as a video adapter 846. The monitor 844 can be internal or external to the computer 812. In addition to the monitor 844, the computer typically includes other peripheral output devices such as speakers, printers, and the like.

[0108] Computer 812 can operate in a network environment using logical connections via wired and / or wireless communication to one or more remote computers such as remote computer 848. Remote computer 848 can be a workstation, server computer, router, personal computer, portable computer, microprocessor-based consumer electronics, peer device, or other common network node, and typically includes many or all of the elements described in relation to computer 812, but only memory and / or storage device 850 is illustrated for brevity. The logical connections depicted include wired / wireless connections to local area network 852 and / or a larger network, such as wide area network 854. Such LAN and WAN networking environments are common in offices and companies, facilitate enterprise-wide computer networks such as intranets, and all of them can be connected to a global communication network such as the Internet.

[0109] When used in the local area network 852 networking environment, computer 812 is connected to local area network 852 via a wired and / or wireless communication network interface or network adapter 856. Network adapter 856 can facilitate wired and / or wireless communication to local area network 852 and can also include a wireless access point disposed thereon for communicating with the wireless function of network adapter 856.

[0110] When used in the networking environment of the wide area network 854, the computer 812 can include a modem 858, or be connected to a communication server on the wide area network 854, or have other means for establishing communication via the wide area network 854, such as via the Internet. The modem 858 can be an internal or external, and wired and / or wireless device, and is connected to the system bus 806 via the input device interface 842. In a network environment, program modules depicted in relation to the computer 812, or a portion thereof, can be stored in a remote memory and / or storage device 850. The illustrated network connections are exemplary, and it will be understood that other means for establishing communication links between computers can be used.

[0111] The computer 812 is operable to communicate with wired and wireless devices or entities using standards of the IEEE 802 family, such as wireless devices operably arranged to operate in wireless communication (e.g., IEEE 802.11 wireless modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, and Bluetooth (R) wireless technologies. A Wi-Fi network uses wireless technologies called IEEE 802.11 (a, b, g, n, ac, ax, etc.) to provide a secure, reliable, and high-speed wireless connection. Wi-Fi networks can be used for connections between computers, to the Internet, and to wired networks (using media and functions related to IEEE 802.3).

[0112] As previously described with reference to FIGS. 1A through 12, the various elements of the apparatus can include various hardware elements, software elements, or a combination of both. Examples of hardware elements can include devices, logic devices, components, processors, microprocessors, circuits, processors, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field programmable gate arrays (FPGAs), memory units, logic gates, registers, semiconductor devices, chips, microchips, chip sets, and the like. Examples of software elements can include software components, programs, applications, computer programs, application programs, system programs, software development programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application program interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. However, determining whether an embodiment is implemented using hardware elements and / or software elements can vary according to any number of factors such as the desired computational speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints for a given implementation.

[0113] One or more aspects of at least one embodiment may be implemented by representative instructions stored on a machine-readable medium that represent various logic within a processor, which, when read by a machine, causes the machine to generate logic for performing the techniques described herein. Such representations, known as “IP cores,” may be stored on a tangible machine-readable medium and supplied to various customers or manufacturing facilities for loading onto a manufacturing machine that makes the logic or processor. Some embodiments may be implemented using, for example, a machine-readable medium or article that stores instructions or a set of instructions that, when executed by a machine, may cause the machine to perform methods and / or operations according to the embodiments. Such machines can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. The machine-readable medium or article can include, for example, digital or analog media, hard disks, floppy disks, compact disc read-only memories (CD-ROMs), recordable compact discs (CD-Rs), rewritable compact discs (CD-RWs), optical discs, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital versatile discs (DVDs), tapes, cassettes, etc., any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium, and / or storage unit. The instructions can include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.

[0114] The components and functions of the above-described apparatus can be implemented using any combination of discrete circuits, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures. Further, the features of the apparatus can be implemented using a microcontroller, a programmable logic array, and / or a microprocessor, or preferably any combination of the foregoing. Note that hardware, firmware, and / or software elements may be referred to collectively or individually herein as "logic" or "circuit."

[0115] It will be understood that the exemplary apparatus shown in the block diagrams above may represent a functionally illustrative example of many potential implementations. Accordingly, the division, omission, or inclusion of block functions depicted in the accompanying figures does not necessarily infer that the hardware components, circuits, software, and / or elements implementing these functions are divided, omitted, or included in an embodiment.

[0116] At least one computer-readable storage medium can include instructions that, when executed, cause a system to perform any of the computer-implemented methods described herein.

[0117] Some embodiments may be described using the phrase "one embodiment" or "an embodiment" along with their derivatives. These terms mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. Although the phrase "in one embodiment" may appear in various places in this specification, it is not necessarily referring to the same embodiment each time. Further, unless otherwise specified, the features described above are recognized as being usable in any combination. Thus, features described separately can be employed in combination with each other unless it is pointed out that the features are not compatible with each other.

[0118] The summary of the disclosure is provided to emphasize that it enables a reader to quickly grasp the nature of the technical disclosure. It is submitted with the understanding that the summary of the disclosure is not used to interpret or limit the scope or meaning of the claims. Further, in the foregoing detailed description, for the purpose of streamlining the disclosure, it can be seen that various features are grouped in a single embodiment. This method of disclosure should not be construed as reflecting an intention that the claimed embodiments require more features than are explicitly recited in each claim. Rather, as the following claims reflect, the inventive subject matter lies in less than all of the features of a single disclosed embodiment. Accordingly, the following claims are incorporated herein with each claim standing on its own as a separate embodiment. In the appended claims, the terms "including" and "in which" are used as the plain English equivalents of the terms "comprising" and "wherein", respectively. Further, terms such as "first", "second", "third", etc. are used merely as labels and are not intended to impose numerical requirements on their objects.

[0119] The foregoing includes examples of disclosed structures. Of course, it is not possible to describe every possible combination of components and / or methodologies, but one of ordinary skill in the art may recognize that many more combinations and permutations are possible. Accordingly, the novel architecture is intended to embrace all such alterations, modifications, and variations that fall within the spirit and scope of the appended claims.

[0120] The foregoing description of the exemplary embodiments has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the disclosure to the precise forms disclosed. Many modifications and variations are possible in light of the disclosure. The scope of the disclosure is intended to be limited not by this detailed description, but rather by the claims appended hereto. Future applications claiming the priority of this application may claim the subject matter disclosed in different aspects and generally may include any set of one or more limitations as variously disclosed herein or otherwise shown.

Claims

1. Receiving encrypted data from a contactless card associated with an account by an application executed on a device; Transmitting the encrypted data to a server by the application; Receiving, by the application, setting information of a plurality of applications associated with the account based on the encrypted data; Changing each setting of each application of the device based on the setting information; A method comprising the above.

2. Before changing each application, Determining, by the application, that a first application among the plurality of applications is not installed on the device; Downloading the first application to the device by the application; Installing the first application on the device by an operating system (OS) of the device; The method according to claim 1, further comprising the above.

3. After installing the first application on the device, Changing the settings of the first application based on the setting information of the first application The method according to claim 2, further comprising the above.

4. The method according to claim 1, wherein receiving the setting information includes receiving a plurality of setting files from the server.

5. Receiving the setting information Includes receiving each push notification from the server by each application, Each push notification includes the setting information of each application, The method according to claim 1, wherein the push notification includes a background notification.

6. Receiving the setting information Is receiving, by each application, each push notification from the server, each push notification includes each token, the push notification includes a background notification, Transmitting each token to the server by each application; Receiving, by each application, the setting information based on each token; The method according to claim 1, comprising the above.

7. The setting information includes (i) information for connecting to one or more servers, (ii) account information, (iii) messages, (iv) preferences, and (v) settings. The method according to claim 1.

8. A non-transitory computer-readable storage medium that, when executed by a processor of a device, causes the processor to receive encrypted data from a contactless card associated with an account by an application; send the encrypted data to a server by the application; receive, by the application, setting information of a plurality of applications associated with the account based on the encrypted data; change each setting of each application of the device based on the setting information; A non-transitory computer-readable storage medium including instructions for causing the above to be executed.

9. Before changing the settings of each application, the instructions cause the processor to determine, by the application, that a first application among the plurality of applications is not installed in the device; download the first application to the device by the application; install the first application in the device by an operating system (OS) of the device; The computer-readable storage medium according to claim 8, further causing the above to be executed.

10. After installing the first application in the device, the instructions cause the processor to change the settings of the first application based on the setting information of the first application The computer-readable storage medium according to claim 9, further causing the above to be executed.

11. Receiving the setting information includes receiving a plurality of setting files from the server. The computer-readable storage medium according to claim 9.

12. Receiving the setting information includes receiving each push notification from the server by each application, each push notification includes the setting information for each application, and the push notification includes a background notification. The computer-readable storage medium according to claim 8.

13. Receiving the setting information is Each application receives each push notification from the server, where each push notification includes each token, and the push notification includes a background notification, and receive; Each application sends each token to the server; Each application receives each setting information based on each token, including: The computer-readable storage medium according to claim 8.

14. The setting information includes (i) information for connecting to one or more servers, (ii) account information, (iii) messages, (iv) preferences, and (v) settings. The computer-readable storage medium according to claim 8.

15. A computer device comprising a processor and a memory, When the memory is executed by the processor, the memory causes the processor to Receive encrypted data from a contactless card associated with an account by an application; Send the encrypted data to a server by the application; Receive setting information of a plurality of applications associated with the account based on the encrypted data by the application; Change each setting of each application of the computer device based on the setting information; Store instructions for execution. Computer device.

16. Before changing the settings of each application, the instructions further cause the processor to Determine by the application that a first application among the plurality of applications is not installed on the device; Download the first application to the device by the application; Install the first application on the device by an operating system (OS) of the device. The computer device according to claim 15.

17. After installing the first application, the instructions further Cause the device to execute to change the settings of the first application based on the setting information of the first application. The computer device according to claim 16.

18. The computer device according to claim 15, wherein receiving the setting information includes receiving a plurality of setting files from the server.

19. Receiving the setting information includes, for each application, receiving each push notification from the server, each push notification including the setting information for each application, and the push notification including a background notification. The computer device according to claim 15.

20. Receiving the setting information includes, for each application, receiving each push notification from the server, each push notification including each token, the push notification including a background notification, sending each token to the server by each application, and receiving the setting information for each application based on each token by each application. The computer device according to claim 15.