System and method for encrypted context switching authentication between a website and a mobile device

The automated context switching authentication between a mobile device and merchant system, utilizing encrypted communication and NFC-enabled cards, addresses the inefficiencies of manual data entry, ensuring secure and efficient transfer of sensitive user information.

JP2025529735APending Publication Date: 2025-09-09CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025507362
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-08
Filing Date
2023-08-07
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing methods for secure transfer of sensitive user information in electronic transactions are cumbersome and prone to human error due to manual data entry, which compromises security and efficiency.

Method used

An automated process using context switching authentication between a mobile device and a merchant system, facilitated by a customized hyperlink, enables secure retrieval of user data through encrypted communication and NFC-enabled contactless cards, leveraging back-end integration with external encryption and authentication systems.

Benefits of technology

Facilitates streamlined and secure transfer of sensitive user information, reducing human error and enhancing transaction efficiency by automating the data retrieval process.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025529735000001_ABST
    Figure 2025529735000001_ABST
Patent Text Reader

Abstract

A system and method implements an automated system and process that facilitates streamlined and secure transfer of authenticated user data over a network. The process may be initiated by activating a customized hyperlink displayed in a web interface. The customized hyperlink is operatively integrated with an encryption and authentication provision system to trigger one or more data collection and / or authentication operations, enabling automated retrieval of authenticated user information in a secure manner. One aspect of security includes an authentication scheme facilitated by context switching between http / https sessions initiated in a mobile browser and one or more data collection and / or authentication functions stored on the user's mobile device. The secure data retrieval process may be further complemented by cryptographic exchange of request and / or response messages, enabled by back-end integration with the encryption and authentication provision system.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] This application claims priority to U.S. Patent Application No. 17 / 883,232, filed August 8, 2022, the disclosure of which is incorporated herein by reference in its entirety.

[0002] The present disclosure relates to systems and methods for providing authentication credentials and authenticated user information over a network, and more particularly to systems and methods for providing authentication based on encrypted context switching. [Background technology]

[0003] Streamlined, secure network transmission of authenticated user-related data from systems and applications storing sensitive data resources to systems and applications requesting the authenticated user-related data remains a significant challenge, particularly for secure and efficient electronic transactions. To provide secure access to sensitive and / or personal information, several routines have been devised to authenticate sources before retrieving and transferring the sensitive and / or personal information. However, in many cases, the verification process involving the exchange of a user's personally identifiable information (PII) and / or payment credentials (PCI) relies on the user manually entering the user's PII and PCI information into an electronic form provided by the merchant system before initiating the user-requested transaction. In such cases, the user manually enters some information, which is then verified against previously verified user information (e.g., stored by the corresponding financial institution). Because the user must gather the required data and manually enter it into an electronic form, this implementation is cumbersome and prone to human error. These and other deficiencies exist. Summary of the Invention

[0004] One aspect of the present disclosure is directed to an automated process that facilitates streamlined, secure transfer and / or retrieval of authenticated user-related information over a network. This process may be initiated via activation of a customized hyperlink displayed on a web interface (e.g., a payment checkout screen). For example, a customized hyperlink displayed on a payment checkout screen of a merchant's website may be operatively integrated with external encryption and authentication provision systems and processes on the back end to trigger one or more data collection and / or authentication operations that facilitate the authenticated retrieval of sensitive user information in a secure manner.

[0005] One aspect of the security functionality associated with the aforementioned systems and processes includes an authentication scheme facilitated through context switching between a (mobile) browser-driven HTTP and / or HTTPS session (e.g., initiated via standard web access over the Internet from a mobile device) and one or more data collection and / or authentication functions provided by one or more applications stored on the corresponding user's mobile device. Thus, the context-switching authentication scheme enables streamlined, secure retrieval of an authentication response from an authenticated user (e.g., the server and / or device that initiated the request for the user's sensitive data) before initiating the transfer of the requested (sensitive) user information to the requesting merchant system and / or server. The secure user data retrieval process can be further supplemented by encrypted exchange of request and / or response messages enabled by back-end integration of the transaction (merchant) website with external encryption and authentication-providing systems and processes.

[0006] In some embodiments, one or more applications stored on the user's mobile device may initiate the collection and authentication of requested (sensitive) user data (e.g., user PII and / or PCI data). The one or more applications (e.g., those associated with the data collection and / or authentication operations) may be launched according to one or more instructions encoded in a universal link. The universal link may be generated and sent to the mobile device in response to a request for sensitive user data originating from a remote merchant system and / or server. The user data request message may be generated by the remote merchant system upon activation of a custom link (e.g., a customized hyperlink) embedded in the merchant system's payment processing web interface (e.g., a user clicks on the custom link to complete an online transaction initiated via a mobile browser session). The request message may then be sent to an authentication server (associated with external encryption and authentication provision systems and processes) and communicated from there to the user's mobile device, for example, in the form of a universal link generated by the authentication server.

[0007] The universal link may include one or more instructions prompting one or more authentication inputs to be provided using the mobile device. The one or more authentication inputs captured on the user's mobile device are transmitted to a corresponding authentication server for validation. Once validated, the requested sensitive user data (based on authorization from the authenticated user) is communicated to the (transacting) merchant system and / or server (e.g., implemented via back-end integration of the merchant system with systems and processes that provide authentication and encryption) over an encrypted back-end communication link (e.g., implemented via back-end integration of the merchant system with systems and processes that provide authentication and encryption). The requested (authenticated) user data may then be pre-populated into an electronic transaction form provided by the merchant system as part of an online payment interface that facilitates the online payment transaction.

[0008] The universal link may correspond to a Universal Resource Indicator (URI) (e.g., a hyperlink, Universal Resource Locator (URL), or other data resource indicator) and may further include configuration that identifies a target destination (e.g., a web server hosting the merchant's website from which the request came) and the particular user transaction session to which the data corresponding to the user PII and / or PCI applies. When launched according to instructions encoded in the deep link, the authentication application begins retrieving one or more authentication inputs via the mobile device to verify the request and subsequent transmission of sensitive user data to the merchant system facilitating the particular user transaction session.

[0009] Thus, a secure sensitive data retrieval process can include: providing a custom link in a website interface, the website being integrated with authentication functionality provided by an external authentication system (e.g., external to the web server initiating the transaction); generating a universal link in response to a user selection of the custom link, the universal link including a website identifier identifying the website on which the custom link is activated by the user's selection, a unique anonymous user identifier generated by the website for tracking a particular user session, and an identifier of an authentication application associated with the external authentication system and stored on a user terminal accessed from the website, the authentication application implementing a context-switching authentication scheme; transmitting the universal link to a user device, which launches an authentication application that prompts the user for one or more authentication actions and / or inputs; transmitting, by the user device, one or more authentication inputs to a corresponding authentication server for verification; and transmitting, after verification of the one or more authentication inputs, one or more requested user data to be pre-populated in the website interface.

[0010] According to some embodiments of the present disclosure, user authentication information (e.g., one or more authentication inputs associated with a context switching authentication scheme) required to authenticate a user's authentication response may be provided by a contactless card with an integrated processor and memory that stores the user's identification and / or authentication information as Near Field Communication (NFC) transmittable data (e.g., NFC Data Exchange Format (NDEF)). The user's authentication information is directly acquired by a reader on the mobile device and transmitted to an authentication server for verification. In this manner, the one or more authentication inputs may be provided by a single user action of bringing the contactless card within NFC range of the mobile device (e.g., holding the contactless card over a reader on the user's mobile device) to initiate a direct reading and subsequent verification of the user authentication information stored as NFC transmittable data on the contactless card.

[0011] In some embodiments, one or more data records corresponding to sensitive user data (e.g., user PII and / or PCI data) may be stored directly in the contactless card's internal memory as NFC-transmittable data. In response to a request for sensitive user information, the one or more data records are read from the contactless card using a user's portable device running a corresponding reading application (initiated by an authentication application) and transmitted directly to a remote merchant server for pre-population into an appropriate payment screen. In some embodiments, the requested user data read from the contactless card by a reader integrated into the user's portable device may be transmitted by the user's portable device to an authentication server for verification. Upon successful authentication, the user information (securely obtained directly from the contactless card) is transmitted to the requesting (merchant) server.

[0012] In some embodiments, network communication messages between the merchant server and the authentication server may be communicated over an encrypted communication link facilitated by back-end integration between the (remote) merchant server and encryption and authentication provision systems and processes. In some embodiments, the secure user data retrieval process may occur over a public network using public and / or private encryption processes. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 illustrates an example system implementation of authenticated data transfer using context switching authentication with cryptographic backend integration based on user-entered credentials, according to some embodiments of the present disclosure.

[0014] [Figure 2] FIG. 2 illustrates an example system implementation of authenticated data transfer using context switching authentication with crypto backend integration using NFC transfer credentials from a contactless card, according to some embodiments of the present disclosure.

[0015] [Figure 3] FIG. 3 illustrates an exemplary system implementation of authentication data transfer using a context switch between a website and an NFC-enabled contactless card according to some embodiments of the present disclosure.

[0016] [Figure 4A] FIG. 4A illustrates a contactless card according to some embodiments of the present disclosure.

[0017] [Figure 4B] FIG. 4B illustrates a contact pad of a contactless card according to some embodiments of the present disclosure.

[0018] [Figure 5]FIG. 5 illustrates an operational flowchart of an exemplary authentication process for switching context between a website and a mobile application based on user-entered authentication information, according to some embodiments of the present disclosure.

[0019] [Figure 6] FIG. 6 illustrates a timing sequence diagram for automatically filling an electronic form with authentication data sent from an NFC-enabled contactless card, according to some embodiments of the present disclosure.

[0020] [Figure 7] FIG. 7 illustrates an example block diagram of an example system according to some embodiments of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION

[0021] The various embodiments of the present disclosure, together with further objects and advantages, may best be understood by reference to the following description taken in conjunction with the accompanying drawings, in which:

[0022] The following description of the embodiments provides non-limiting representative examples that refer to numerals to particularly explain the features and teachings of different aspects of the present invention. It will be recognized from the description of the embodiments that the described embodiments can be implemented separately or in combination with other embodiments. Those skilled in the art who review the description of the embodiments will learn and understand the different described aspects of the present invention. The description of the embodiments is not specifically exhaustive, but will facilitate understanding of the present invention to the extent that other implementations within the knowledge of those skilled in the art who read the description of the embodiments will be understood to be consistent with the application of the present invention.

[0023] Some embodiments of the present disclosure configure a back-end encryption system with a context switch authentication scheme to enable direct and secure transfer and / or retrieval of sensitive data resources (e.g., user PII and / or PCI). In some embodiments, the encrypted exchange of request and response messages between a requesting merchant system and the encryption and authentication system can be accomplished via back-end integration of the merchant website with externally provided encryption and authentication systems and processes.

[0024] The process according to the above-described embodiment may be dynamically triggered upon activation of a custom (checkout) link (e.g., an active button or icon) presented on a transaction (merchant) server's web interface (e.g., a checkout screen). This custom link is associated with back-end integration with the transaction merchant's website and an external encryption system with context-switching authentication capabilities that is initiated upon activation of the custom link. The external encryption system with context-switching authentication capabilities may refer to a system and / or process that is implemented externally to the transaction merchant system but provides functionality accessible by the transaction merchant system via back-end integration with a service provider system. Therefore, for purposes of this disclosure, the encryption and authentication providing system may be referred to interchangeably as an "external encryption and authentication system" and / or an "external authentication system."

[0025] As described, the aforementioned functionality (corresponding to the encrypted and authenticated transfer and / or retrieval of a user's sensitive data) can be accessed, for example, upon activation of a custom checkout link presented on a payment checkout screen of a merchant's website. In some embodiments, in addition to activating the custom link, a user can be required to enter initial identifying information, such as an email address, to generate a request for the secure data transfer process. The initial user identifying information is transmitted to an authentication server (integration with a backend) along with a request for the user's sensitive information (e.g., the user's PII and PCI). The initial user identifying information can be used by the receiving (authentication) server as a search index to identify and collect relevant and / or requested user information. In some embodiments, the receiving (authentication) server can use the initial user identifying information to, for example, determine a device identifier associated with the user's mobile device, along with one or more application identifiers corresponding to one or more data collection and / or authentication applications stored on the user's mobile device.

[0026] The set of identifiers associated with the user's mobile device and corresponding mobile applications can be incorporated into a universal resource indicator (URI), such as a universal link, universal resource locator (URL), or other indicator, generated by a URI generation process running on a receiving (authentication) server, for example. According to some embodiments, the URI generation process may be performed on the authentication server. According to some embodiments, the URI generation process may be performed on a remotely located URI generation server communicatively coupled to the authentication server. The URI generation process can integrate one or more mobile application identifiers corresponding to one or more data collection applications and / or authentication applications stored on the user's mobile device into the generated universal link.

[0027] FIG. 1 illustrates an exemplary encryption and authentication provision system (100) (interchangeably referred to as the “authentication system” (100) for purposes of this disclosure) that implements authorized transfer of sensitive user data that is verified based on one or more user authentication inputs provided to authorize the transfer. Referring to FIG. 1 , acquisition of one or more user authentication inputs (102) may be enabled by a context switch between a mobile browser session (103) initiated from a user's mobile device (101) and an authentication application (104) stored on the user's mobile device (101). The one or more user authentication inputs are then transmitted by the user's mobile device (101) to an authentication server (110) for validation. Upon validation of the one or more authentication inputs provided in association with a data transfer authorization response, the requested user's sensitive information is transmitted to a remote destination server (e.g., the merchant server 120) via an encrypted back-end communication channel (130) (e.g., implemented via a back-end integration of the authentication and encryption provisioning system and process (100) with the merchant server (120)).

[0028] The authentication server (110) may include one or more server-side applications (113) corresponding to, for example, a data collection application (114) and / or an authentication application (115). The authentication server is communicatively coupled to a device (e.g., a mobile device 101) and can respond to one or more communications from one or more (client-side) applications (e.g., authentication application 104) stored on the user's mobile device (101). The authentication server (110) may also be communicatively coupled to multiple remote merchant systems via back-end integration between the aforementioned remote merchant systems and the authentication system (100). As described above, the authentication process may be based on context switching between a browser session (103) initiated by a web browser running on the user's mobile device 101 and authentication functionality provided by the external authentication system 100. The authentication server (110) may also be connected to a database (e.g., database 140) used to store one or more user personally identifiable information (PII) and / or payment credential information (PCI) for multiple users. Although FIG. 1 shows an example of a single configuration, system 100 may include any number of configurations.

[0029] Returning to FIG. 1 , the context switch authentication process may be initiated by sending a universal link (117) to the user's mobile device (101). The universal link (118) may be generated by the authentication server (110) in response to a data request message (116) received from a remote merchant server (120). The data request message (116) may correspond to a request for sensitive user data (1) triggered by a user's selection of a custom link (121) on a web interface (122) of the transaction merchant server (120). The requested sensitive user data may correspond, for example, to one or more user data records necessary to process a payment transaction on the merchant website's web interface. In addition to the request for sensitive user data (1), the data request message (116) may further include a merchant website identifier (2), an anonymous unique user session identifier (3) (for identifying a particular user transaction session on the merchant website), and initial user identification information (4) (e.g., an email address provided by the user on the web interface 122 of the merchant server 120). The data request (116) is transmitted to the authentication server (110) over a back-end encrypted communication link (130). In response, the authentication server (110) initiates a context switching (authentication) scheme to match the data request for sensitive user information with an approval response from an authenticated user (e.g., based on verification of one or more user authentication inputs 102) before authorizing transmission of the requested sensitive user data to the remote merchant server.

[0030] As previously described, the context switching (authentication) scheme may be initiated by transmitting a universal link (117) to the user's portable device (101). The universal link may include an application identifier identifying a target application (e.g., authentication application 104) stored on the user's portable device (102) and coded instructions to launch the target (authentication) application. When launched according to one or more instructions coded in the universal link, the authentication application (104) may begin retrieving one or more authentication inputs (102) via the user's portable device (101). The one or more authentication inputs (102) captured by the user's portable device (101) may then be sent back to a corresponding authentication application and / or process (115) for validation. Once validated, an authentication signal (118) may trigger a data collection application and / or process (114) to retrieve the requested sensitive user data and transmit it via a response message (119) to a remote merchant server (120). The response message may be sent to the merchant system / server via an encrypted back-end communication link (130) implemented via a back-end integration of the merchant server (120) with the authentication system 100. The particular user's transaction session is then identified (e.g., based on the anonymous unique user session identifier (3) included in the response message 119), and the requested user data (e.g., user PII and / or PCI) is pre-populated into an electronic transaction form provided by the merchant server as part of an online payment interface enabled via the back-end integration with the authentication system 100. The user PCI data may correspond to a primary account number (PAN) and / or credit / debit card data. In some embodiments, a merchant-specific virtual credit card number (VCN) may be generated in response to the data request message (116) and subsequently provided as the user PCI data in the response message (119).

[0031] Encrypted network communications exchanged between the remote merchant server (120) and the authentication server (110) may occur over an encrypted back-end communications link (130). The encrypted network communications correspond to a data request message (116) from the remote merchant server (120) followed by a response message (119) sent by the authentication server (110). In some embodiments, such communications may occur over a public network using public / private encryption routines. In one embodiment, communications between the merchant server and the authentication server are performed using shared secret cryptography.

[0032] In some embodiments, the target application associated with the application identifier encoded in the universal link may correspond to a data collection application integrated with authentication functionality provided by an external authentication system. In some embodiments, the data collection application may be operatively coupled to a separate authentication application stored separately on the user device (101). The data collection application collects the user's PII and PCI information (stored partially or entirely on one or more of the user's mobile device (101), a corresponding authentication server (110), and / or one or more external / internal data repositories (e.g., database 140)) and, upon validating the request for sensitive user information (via an authentication confirmation signal (118) from the authentication application), transmits the sensitive user information to the merchant's website for pre-population into a payment checkout screen. The authentication confirmation signal (118) may correspond to an approval response from the authenticated user.

[0033] In some embodiments, the authentication scheme used to authenticate a user authorization response to transfer sensitive user data to a remote entity may amount to verifying that the user authorizing the transfer of sensitive user information is in possession of or proximity to a verifiable device associated with the user performing the transaction (e.g., a user initiating a transaction by clicking a custom checkout link provided on a payment screen on a merchant website). The verifiable user device may be provided in the form of a contactless card with an integrated processor and memory that stores the user's identification / authentication information as near field communication (NFC)-transmittable data.

[0034] Thus, one aspect of the proposed system and method is directed to an authentication scheme that includes a uniquely configured contactless card with an embedded NFC tag that stores NFC-transmittable user authentication data (e.g., readable by a portable device equipped with a reader and running a corresponding application). The specific structure, configuration, and operation of the contactless card (including an integrated processor, memory, NFC functionality, and a secure method of storing sensitive information as NFC-transmittable data) are described with reference to Figures 4A and 4B. An exemplary system implementation (200) of context switching authentication using the aforementioned contactless card is shown in Figure 2.

[0035] 2 illustrates an exemplary system (200) implementing the automatic transfer of encrypted user data supplemented by an authentication scheme implemented by context switching between a web session (103) and a contactless card (201). The described context switching authentication scheme allows for a single authentication operation involving the contactless card (201) providing a valid authentication confirmation signal (118) that authorizes the transfer of sensitive user information (e.g., via a response message 119) to a (requesting) remote web server (120). FIG. 2 may reference components and operations that are the same or similar to those described above with respect to FIG. 1.

[0036] The exemplary context switching authentication implementation (200) shown in Figure 2 utilizes a contactless card (201) having a symmetrically encrypted NFC channel (203) to a user's portable device (110) for encrypted transmission of user authentication data (202) (stored on the contactless card (201) as NDEF data). User authentication data (202) obtained from the contactless card (201) via the encrypted NFC transmission (202) can be provided to an authentication application (104) running on the user's portable device (110). The encrypted NFC channel (203) can be activated, for example, when a reader (124) of the user's portable device (110) is brought into NFC proximity of the contactless card (201) and / or vice versa. The encrypted authentication data (202) received by the authentication application (104) can be decrypted using a symmetric key shared between the contactless card (201) and a corresponding reading application (e.g., authentication application 104) running on the user portable device (101). The authentication data is sent to a corresponding authentication application / process (115) running on the authentication server (110) for verification. Upon authentication (represented by an authentication signal (118) from the authentication application (115) to a data collection process 114 running on the authentication server 110), sensitive user information can be provided to a (requesting) remote merchant server (120) (e.g., via a response message 119 sent over an encrypted backend communication channel 130) to, for example, facilitate the user's payment transaction.

[0037] One aspect of the present disclosure is directed to the automated transfer of sensitive user data directly from a contactless card, as shown in the exemplary embodiment (300) of Figure 3. The automated data transfer process, which corresponds to the secure transfer of user information directly from a contactless card (301) to a remote merchant server (120), can be facilitated by context switching between the user's web session (103) and NFC reading functionality provided by, for example, an application / process (105) running on a mobile device.

[0038] 3 may refer to the same or similar components as described above with respect to FIGS. 1 and 2. In an exemplary embodiment (300), an arrangement including a contactless card (301) and a user portable device (101) may be utilized to effect a direct transfer of a user's PII and / or PCI data from the contactless card to a remote merchant server (120). Referring to the exemplary system implementation (300), the URI transmission 117 (e.g., in the exemplary embodiment (300), the target application (105) may correspond to an NFC reader application that activates the reader functionality of the portable device (101) (e.g., causes the device to simply function as a reader) to enable collection (e.g., NFC tapping of the contactless card against the user's portable device) of sensitive user information 302 (e.g., user PII and / or PCI data) stored directly on the contactless card (301). In this manner, input into a payment checkout screen or account registration screen is possible. The required user PII and / or PCI can be obtained via an NFC tap directly from a contactless card (301) that stores the NFC-transmittable user PII and / or PCI information (302). The user information received by the mobile application (105) via an NFC transmission from the contactless card (301) can then be transmitted to an authentication process / application (115) on the authentication server (110) for verification (e.g., verifying that the user data obtained from the card (301) matches the initial user identification data (4) embedded in the data request message (116)).

[0039] According to some embodiments, transmission of user data (302) from a contactless card (301) to a receiving app / process (105) on a mobile device (101) may be facilitated over a symmetrically encrypted NFC link (203). The symmetric encryption may be associated with a common secret encryption key shared between the contactless card (301), the target application (105), and the authentication application (115) on the authentication server (110). User data (302) obtained by the mobile (target) application (105) via a direct NFC read of the card (301) by a reader (124) on the mobile device (101) is decrypted using the shared secret key and verified by the authentication application (115) based on a correct match with the initial user identification data (4) in the data request message (116). Upon successful authentication, an authentication confirmation signal (118) is sent to the mobile application (105), and a response message (119) containing the requested user data is sent over an encrypted network connection to a remote web server (120), for example, to facilitate an online payment transaction. In some embodiments, the response message (119) may be generated directly by the mobile application in response to the confirmation authentication signal (118) from the authentication server (110). The response message (119) may be sent by the mobile application (105) to the remote merchant server (120) over an encrypted communication channel (130) associated with back-end integration between the merchant server / system (120) and the system implementation (300). According to some embodiments, the response message (119) may be encrypted with the public key of the destination merchant system (120) and sent over the web session (103) to the remote merchant server (120). This corresponds to the data transfer (123) being facilitated over the web session 103 over a public network 127, as shown in FIG. 3 . The user data is then automatically entered into the web interface (122) of the merchant's website / web server (120).In some embodiments, a VCN generation process (303), running on, for example, the authentication server (110), may be invoked in response to a data request message (116) from the remote merchant system (120), resulting in a merchant-specific VCN being generated and sent along with an authentication confirmation signal (118) to the mobile application (105) and provided to the remote merchant system (120) along with the user PII data.

[0040] Figures 4A and 4B illustrate an exemplary contactless card 400. Although Figures 4A and 4B illustrate a single instance of the components of card 400, any number of components may be utilized.

[0041] Card 400 may communicate with one or more components of system 100. Card 400 may be a contact card (e.g., a card that is read by swiping a magnetic stripe or inserting into a chip reader) or a contactless card, and card 400 may be a payment card such as a credit card, debit card, or gift card. As shown in FIG. 4A , card 400 may be issued with a service provider designation 405 displayed on the front of card 400 (on the back of card 400). In some examples, the payment card may be a dual-interface contactless payment card. In some embodiments, card 400 is unrelated to a payment card and may be, but is not limited to, an ID card, a membership card, and a transportation card.

[0042] Card 400 can include a substrate 410, which can include a single layer or one or more laminated layers of plastic, metal, and other materials. Exemplary substrates include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium dioxide, palladium, gold, carbon, paper, biodegradable materials, and the like. In some examples, card 400 has physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, and card 400 can conform to the ISO / IEC 14443 standard. However, it is understood that card 400 according to the present disclosure may have different characteristics, and the present disclosure does not require implementation into a payment card.

[0043] Card 400 may also include identification information 415 displayed on the front and / or back of the card, and card 400 may include contact pad 420. Contact pad 420 may establish contact with other communication devices, including, but not limited to, user devices, smartphones, laptops, desktops, or tablet computers. Card 400 may also include processing circuitry, an antenna, and other components not shown in FIG. 4A. These components may be located behind contact pad 420 or elsewhere on substrate 410.

[0044] The service provider designation 405 may include the name and logo of the service provider, and may also include information about the service provider, including, but not limited to, a phone number, an address, instructions for handling the card 400 if lost or damaged, and other information. The service provider name 405 may also include an image or graphic design.

[0045] The identification information 415 may include, but is not limited to, an account number, a name, an expiration date, a phone number, a nickname, and other information. In some examples, the identification information 415 may further include an image or graphic design. For example, the identification information 415 may include an image, photograph, drawing, or logo of the user.

[0046] As shown in Figure 4B, the contact pad 420 of Figure 4A may include processing circuitry 425 for storing and processing information, including a processor 430, such as a microprocessor, and memory 435. It is understood that the processing circuitry 425 may include additional components including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware necessary to perform the functions described herein.

[0047] Memory 435 may be read-only memory, write-once-read-multiple memory, or read / write memory, e.g., RAM, ROM, and EEPROM, and card 400 may include one or more of these memories. Read-only memory may be programmable as read-only at the factory or may be one-time programmable. One-time programmable is written once and can be read any number of times. Write-once / read-multiple memory can be programmed at any time after the memory chip leaves the factory. Once programmed, memory cannot be rewritten, but can be read any number of times. Read / write memory can be programmed and reprogrammed any number of times after leaving the factory and can be read any number of times.

[0048] Memory 435 may store one or more applets 440, one or more counters 445, and a customer identifier 450. The one or more applets 440 may be one or more software applications running on one or more contact or contactless cards, such as a Java Card applet. However, it is understood that the applet 440 is not limited to a Java Card applet and may instead be any software application capable of running on a contact or contactless card or other device with limited memory. The one or more counters 445 may be a numeric counter sufficient to store an integer. The customer identifier 450 may include a unique alphanumeric identifier assigned to the user of card 400, which may distinguish a contactless card user from other contactless card users. In some examples, the customer identifier 450 may identify both the customer and the account assigned to the customer, and may further identify the contactless card associated with the customer's account.

[0049] While the processor and memory elements of the foregoing exemplary embodiments are described with reference to contact pads, the present disclosure is not limited thereto, and it is understood that these elements may be implemented external to the contact pads 420, may be completely separate from the contact pads 420, or may be implemented as additional elements in addition to the processor 430 and memory 435 elements disposed within the contact pads 420.

[0050] In some examples, the card 400 may include one or more antennas 455. The one or more antennas 455 may be disposed within the card 400 around the processing circuit 425 of the contact pads 420. For example, the one or more antennas 455 may be integral with the processing circuit 425, or the one or more antennas 455 may be used in conjunction with an external booster coil. As another example, the one or more antennas 455 may be external to the contact pads 420 and the processing circuit 425.

[0051] In one embodiment, the coil of the card 400 may function as the secondary of an air-core transformer. The terminal may communicate with the card 400 by disconnecting the power or amplitude modulation. The card 400 may infer data transmitted from the terminal using gaps in the card's power connection, which may be maintained functionally through one or more capacitors. The card 400 may return communication by switching the load on the card's coil or by load modulation.

[0052] FIG. 5 illustrates an operational overview of a context switching authentication process according to some embodiments of the present disclosure. Referring to FIG. 5, the process may begin at 502 with activation of a custom (checkout) link presented in a merchant website's online payment interface. The custom link may be associated with back-end processing options provided via an external authentication system. In response to a user selecting the custom link in the merchant website's online payment interface, process 500 proceeds to generating and sending a data request message to the external authentication system via a back-end encrypted channel for processing at 504. The data request message may include a request for the user's PII and / or PCI data, as well as configuration identifying the merchant website and the particular user transaction session associated with the selection of the custom link.

[0053] An authentication server associated with the external authentication system can receive the incoming data request message via a designated encrypted channel associated with the merchant website's back-end integration. At 506, the authentication server determines a device identifier associated with the user's mobile device based on information included in the data request message and generates a universal link that encodes the identifier to a target application stored on the user's mobile device. The universal link can include additional information, such as the information included in the data request message, and instructions for launching the target mobile application corresponding to the mobile authentication application.

[0054] At 508, the universal link is sent to the user's mobile device associated with the device identifier that may be included in the data request message. At 510, the user is prompted to enter one or more authentication inputs using the mobile device via a mobile authentication application. At 512, the one or more authentication inputs provided via the user's mobile device are validated by the authentication server, and at 514, the requested user's PII and / or PCI are transmitted to the merchant's website via a back-end encrypted channel and subsequently applied to the specific user transaction session (e.g., pre-populated into an online payment interface displaying the custom link).

[0055] 6 illustrates an exemplary sequence diagram (600) associated with an automated process for securely retrieving sensitive user information, verified based on one or more user authentication data securely stored as NFC-transmittable data on the contactless card's (601) internal memory and retrieved by the user's mobile device (602) via an encrypted NFC channel (603) established between the contactless card (601) and the user's mobile device (602). This information is transmitted to an authentication server 604 via a wireless network connection (605) for verification. Once authenticated, the sensitive user information is provided to the requesting merchant server (606) via an encrypted back-end communication channel (607) (e.g., implemented via the merchant server's (606) back-end integration with systems and processes providing authentication and encryption).

[0056] This process can be initiated in response to a data request message (608) associated with sensitive user information required to facilitate a particular user transaction. The data request message (608) is generated by the merchant server (606) in response to activation of a custom link presented in the merchant server's (606) web interface and sent to the authentication server (604). The data request message (608) can further include an anonymous unique user session identifier, a merchant website / web server identifier, and initial user identification information. In response to the data request message (608), the authentication server generates a URI (e.g., a universal link) and sends the URI (612) to the user's mobile device (602).

[0057] The URI may contain encoded instructions and identifiers to launch an authentication application stored on the user's mobile device. When launched according to the URI instructions, the mobile authentication application may prompt the user to initiate an NFC read of the contactless card (601) via a reader on the user's mobile device (602). At (615), the user authentication data stored in the NDEF on the contactless card (601) is read by the user's mobile device (602), for example, by tapping the contactless card against the reader on the user's mobile device to initiate an NFC transmission. The authentication server (604) verifies the user authentication data at (617), and the authentication server obtains the requested user secret at (618), and transmits the requested user secret at (620) to the requesting merchant server (606) via an encrypted communications link (607). However, in some embodiments, the operation (618) involving retrieving sensitive user information (e.g., collecting the user's PII data) may also include generating a merchant-specific virtual credit card number (VCN) mapped to the user's first account, which may be provided in place of the user's PAN in transmission (620). At (622), the received (sensitive) user information is pre-populated (606) into the appropriate transaction form provided by the merchant server.

[0058] 7 shows a block diagram of an exemplary embodiment of a system according to the present disclosure. For example, exemplary procedures according to the present disclosure described herein may be performed by a processing and / or computing device (e.g., computer hardware device) 705. Such a processing and / or computing device 705 may, for example, be in whole or in part, or may include a computer / processor 710, which may include, for example, but is not limited to, one or more microprocessors, and may use instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard drive, other storage device).

[0059] 7, for example, computer-accessible medium 715 (e.g., as described above, a storage device such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, or a collection thereof) may be provided (e.g., in communication with processing unit 705). Computer-accessible medium 715 may include executable instructions 720 thereon. Additionally or alternatively, storage device 725 may be provided separate from computer-accessible medium 715, which may provide instructions to processing unit 705 to, for example, configure the processing unit to perform the example procedures, processes, and methods as described hereinabove.

[0060] Additionally, the exemplary processing device 705 can be equipped with or include input / output ports 735, which can include, for example, a wired network, a wireless network, the Internet, an intranet, data collection probes, sensors, etc. As shown in Figure 7, the exemplary processing device 705 can be in communication with an exemplary display device 730, which, according to certain exemplary embodiments of the present disclosure, can be, for example, a touchscreen for inputting information into the processing device in addition to outputting information from the processing device. Additionally, the exemplary display device 730 and / or storage device 725 can be used to display and / or store data in a user-accessible and / or user-readable format.

[0061] As used herein, the term "card" is not limited to a particular type of card. Rather, it is understood that the term "card" can refer to a contact card, a contactless card, or other card, unless otherwise indicated. Furthermore, it is understood that the present disclosure is not limited to cards having a particular purpose (e.g., payment cards, gift cards, identification cards, membership cards, transportation cards, access cards), cards associated with a particular type of account (e.g., credit account, debit account, membership account), or cards issued by a particular entity (e.g., commercial organizations, financial institutions, government agencies, social clubs, etc.). Instead, it is understood that the present disclosure includes cards having any purpose, account association, or issuing entity.

[0062] The systems and methods described herein can provide secure retrieval of sensitive user information or enable streamlined communication and processing of sensitive user information, for example, facilitating secure electronic transactions. Once a valid authorization response from an authenticated user is established, the automated data retrieval and transfer system and process can authorize financial transactions (e.g., credit card and debit card transactions), account management transactions (e.g., card renewal, card replacement, add new card transactions), membership transactions (e.g., onboarding and cancellation transactions), access point transactions (e.g., building access, secure warehouse access transactions), transportation transactions (e.g., ticketing and boarding), and other transactions.

[0063] As used herein, personally identifiable information (PII) may include any sensitive data, including financial data (e.g., account information, account balances, account activity), personal and / or personally identifiable information (e.g., Social Security number, home or work address, date of birth, telephone number, email address, passport number, driver's license number), access information (e.g., passwords, security codes, authentication codes, biometric data), and other information that a user wishes to avoid revealing to unauthorized persons.

[0064] The present disclosure is not limited in terms of the specific embodiments described herein, which are intended as illustrative of various aspects. Clearly, many modifications and variations can be made without departing from its spirit and scope. Functionally equivalent methods and apparatuses within the scope of the present disclosure, in addition to those recited herein, will be apparent from the foregoing exemplary description. Such modifications and variations are intended to be encompassed by the appended exemplary claims. The present disclosure is limited only by the terms of the appended exemplary claims, along with the full scope of equivalents to which such exemplary claims are entitled. It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only, and is not intended to be limiting.

[0065] Additionally, it should be noted that the systems and methods described herein may be embodied in one or more physical media, such as, but not limited to, a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a hard drive, a read-only memory (ROM), a random access memory (RAM), and other physical media capable of storing data. Data storage devices also include storage media or other suitable types of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard disks, removable cartridges, flash drives, any type of tangible and non-transitory storage media, etc.) on which application programs, such as operating systems, web browser applications, email applications, other applications, and files, including data files, may be stored. Data storage in a network-enabled computer system can include electronic information, files, and documents stored in a variety of ways, including, for example, flat files, indexed files, hierarchical databases, relational databases such as databases created and maintained with Oracle® Corporation software, Microsoft® Excel files, Microsoft® Access files, solid-state storage devices that may include flash arrays, hybrid arrays, or server-side products, enterprise storage devices that may include online or cloud storage, or any other storage mechanism. Furthermore, the figures illustrate various configurations (e.g., servers, computers, processors, etc.) separately. Functions described as being performed by various components may be performed by other components, and various components may be combined or separated. Other variations are also possible.

[0066] In the foregoing specification, various embodiments have been described with reference to the accompanying drawings. However, it will be apparent that various modifications and changes can be made thereto, and additional embodiments can be made, without departing from the broad scope of the invention as defined in the claims that follow. The specification and drawings are, therefore, to be regarded in an illustrative rather than a restrictive sense.

Claims

1. 1. A method for facilitating automatic transfer of authenticated user information based on context switching authentication, comprising: providing a custom link in a website interface, the website being integrated with authentication functionality provided by an external authentication system; generating a universal link in response to a user selection of the custom link, the universal link comprising: a website identifier that identifies the website on which the custom link will be activated upon selection by the user; a unique anonymous user identifier generated by the website to track a particular user session; an identifier of an authentication application associated with the external authentication system and stored on a user device accessed from the website; transmitting the universal link to the user device, the universal link launching the authentication application that prompts the user to perform an authentication action, the authentication action including bringing within near field communication (NFC) range of the user device a contactless card with an NFC tag that stores one or more user identification and payment credential information as NFC transmittable data; transmitting the one or more user identification and credential information obtained from the contactless card via NFC to be pre-populated into the interface of the website; A method comprising:

2. the universal link includes an identifier for a data collection application with a deep link to the authentication functionality provided by the external authentication system; the authentication functionality is integrated into the data collection application; The method of claim 1.

3. the authentication functionality is provided by an authentication application stored on a user device and operably coupled to the data collection application; The method of claim 2.

4. The user's identity and credential information is collected by the data collection application and transmitted to the requesting website upon verifying the user's authentication information obtained via NFC from the contactless card. The method of claim 2.

5. the website identifier and the unique anonymous user identifier information in the universal link are used to identify the particular user session associated with the authentication operation; The method of claim 1.

6. The authentication operation further includes at least one selected from the group of: entering login credentials into the authentication application; and confirming identity by entering a temporary one-time password transmitted to the user device as at least one selected from the group of text and voice. The method of claim 1.

7. the user's identification and authentication information transmitted via NFC from the contactless card to the authentication application on the user device is encrypted using symmetric encryption; The method of claim 1.

8. the one or more user identification and credential information transmitted from the user device to the website is encrypted using a public key encryption process; the user's identification and credential information is decrypted before being automatically entered into the interface of the website; The method of claim 7.

9. If the authentication application is not installed on the user device, the universal link is coded to redirect the user to an application store to download the authentication application. The method of claim 8.

10. An authentication system that performs automatic retrieval of authenticated user information based on context switching authentication, comprising: a link generation server communicatively coupled to one or more web servers via a network, the link generation computer comprising: displaying a custom link in an interface of a website associated with each of the one or more web servers, the website being integrated with authentication functionality provided by the authentication system; generating a universal link in response to a user selection of the custom link, the universal link comprising: a website identifier that identifies the website on which the custom link will be activated upon selection by the user; a unique anonymous user identifier generated by the website to track a particular user session; an identifier of an authentication application associated with the authentication system, the identifier being stored on a user device through which the authentication application accesses the website; generating a transmitting the universal link to the user device, the universal link launching the authentication application and prompting the user to perform an authentication action, the authentication action including bringing within near field communication (NFC) range of the user device a contactless card with an NFC tag that stores one or more user identification and credential information as NFC transmittable data; transmitting, via the authentication application running on the user device, one or more user identification and credential information obtained from the contactless card via NFC transmission, to be pre-populated into the interface of the website; To execute Authentication system.

11. the universal link includes an identifier for a data collection application with a deep link to the authentication functionality provided by the authentication system; the authentication functionality is integrated into the data collection application; The authentication system of claim 10.

12. the authentication functionality is provided by an authentication application stored on the user device and operably coupled to the data collection application; The authentication system of claim 11.

13. (blank)

14. The system comprises: using said data collection application to collect user identification and credential information; authenticating the transfer of the user's identity and payment credential information to the website based on verification of the user's authentication information obtained via NFC transmission from the contactless card; The authentication system of claim 11.

15. identifying the particular user session associated with the authentication operation based on the website identifier and the unique anonymous user identifier information in the universal link; The authentication system of claim 10.

16. and performing one or more authentication actions including one or more of entering login credentials into the authentication application and verifying identity by entering a temporary one-time password sent to the user device as one of a text message, a voice message, or a pop-up notification. The authentication system of claim 10.

17. and encrypting the user's identity and credential information transmitted from the contactless card via NFC using symmetric cryptography. The authentication system of claim 10.

18. and, at the user's option, encrypting the user's identification and credential information transmitted to the website on which the custom link is activated using a public key encryption scheme. The authentication system of claim 10.

19. A non-transitory computer-readable medium containing instructions for execution by a computer hardware device, comprising: Upon execution of the instructions, the computer hardware device: providing a custom link in an interface of a website, the website being integrated with authentication functionality provided by an external authentication system; generating a universal link in response to a user selection of the custom link, the universal link comprising: a website identifier that identifies the website on which the custom link will be activated upon selection by the user; a unique anonymous user identifier generated by the website for tracking a particular user session, the unique anonymous user identifier; an identifier of an authentication application associated with the external authentication system and stored on a user device accessed from the website; transmitting the universal link to the user device, the universal link launching the authentication application that prompts the user to perform an authentication action, the authentication action including bringing within near field communication (NFC) range of the user device a contactless card with an NFC tag that stores one or more user identification and credential information as NFC transmittable data; transmitting the one or more user identification and credential information obtained from the contactless card via NFC transmission to be pre-populated into the interface of the website where the custom link was activated upon user selection; Execute a process that includes Non-transitory computer-readable medium.

20. and further comprising instructions for encrypting the user's identity and payment credential information transmitted from the contactless card via NFC to the authentication application on the user device using symmetric cryptography.

20. The non-transitory computer-readable medium of claim 19.