Systems and methods for dynamic data generation and cryptographic card authentication

The system generates dynamic virtual card numbers and security codes using cryptographic parameters to enhance transaction security and efficiency by preventing attacks and interception, addressing vulnerabilities in static virtual card numbers and insecure data transmission.

JP2025529810APending Publication Date: 2025-09-09CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
JP2025508925
Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Priority Date
2022-08-17
Filing Date
2023-08-14
Publication Date
2025-09-09

AI Technical Summary

Technical Problem

Existing virtual card numbers are static, making them vulnerable to brute force attacks and security breaches, and data transmission without encryption is susceptible to interception, leading to increased security risks and operational inefficiencies in electronic transactions.

Method used

A system and method for generating dynamic virtual card numbers and security codes using cryptographic parameters like unique identifiers, counters, and session keys, ensuring secure and limited use, and encrypting data communications to prevent unauthorized access.

Benefits of technology

Reduces security vulnerabilities by preventing brute force attacks and unauthorized data interception, enhancing transaction security and efficiency without degrading user experience.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2025529810000001_ABST
    Figure 2025529810000001_ABST
Patent Text Reader

Abstract

Systems and methods for authentication may include an authentication system. The authentication system may include a processor and a memory. The memory may include a unique identifier, a counter, a session key, and a PAN sequence number. The processor may be configured to receive an authentication request. In response to the authentication request, the processor may be configured to generate a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters including at least one selected from the group consisting of the unique identifier, the counter, the session key, and the PAN sequence number. The processor may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request.
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] CROSS-REFERENCE TO RELATED APPLICATIONS This application claims priority to U.S. Patent Application No. 17 / 890,077, filed August 17, 2022, the disclosure of which is incorporated herein by reference in its entirety.

[0002] The present disclosure relates to systems and methods for dynamic data generation and cryptographic card authentication. [Background technology]

[0003] Electronic and card-based transactions are becoming increasingly common. These transactions often involve the use of a card that can communicate with point-of-sale devices, servers, or other devices. Such communications need to be protected from interception and unauthorized access. Virtual card numbers may provide a way for users to use their accounts without disclosing their account numbers.

[0004] Currently, the virtual card numbers generated are static in nature, creating exposure to malicious actors. For example, malicious actors seeking unauthorized account access and misuse of account information can perform brute force attacks against static virtual card numbers, leading to security vulnerabilities.

[0005] Furthermore, transmission of data without encryption or other protection may be susceptible to malicious attacks, data interception, and other vulnerabilities, resulting in increased security risks and increased risk of account or card misuse. These risks may be further increased by the use of contactless cards, which communicate wirelessly with other devices.

[0006] Measures taken to address security risks may consume system resources and hinder operational efficiency. For a large number of transactions, the consumption of system resources and the hindering of transaction efficiency may increase, resulting in transactions that cannot be executed or may perform poorly.

[0007] These and other flaws exist, and therefore there is a need for secure, dynamically generated data and cryptographic card authentication. Summary of the Invention

[0008] An embodiment of the present disclosure provides an authentication system. The authentication system may include a processor and a memory. The memory may include a unique identifier, a counter, a session key, and a primary account number (PAN) sequence number. The processor may be configured to receive an authentication request. In response to the authentication request, the processor may be configured to generate a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters, including at least one selected from the group consisting of the unique identifier, the counter, the session key, and the PAN sequence number. The processor may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request.

[0009] An embodiment of the present disclosure provides an authentication method. The method may include receiving an authentication request. The method may include generating, by a processor, in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN sequence number. The method may include transmitting, by the processor, the virtual card number and the dynamic security code to complete the authentication request.

[0010] An embodiment of the present disclosure provides a computer-accessible non-transitory medium including computer-executable instructions that, when executed on a processor, perform procedures including receiving an authentication request; generating, in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN sequence number; and transmitting the virtual card number and the dynamic security code to complete the authentication request.

[0011] The various embodiments of the present disclosure, together with further objects and advantages, may best be understood by reference to the following description taken in conjunction with the accompanying drawings, in which: [Brief explanation of the drawings]

[0012] [Figure 1] 1 illustrates an authentication system according to an exemplary embodiment. [Figure 2A] FIG. 1 is a diagram of a first device according to an exemplary embodiment. [Figure 2B] FIG. 2 is a diagram of a contact pad of a first device according to an exemplary embodiment. [Figure 3] 1 illustrates an authentication method according to an exemplary embodiment. [Figure 4A] FIG. 1 illustrates a sequence diagram of a process for authentication according to an exemplary embodiment. [Figure 4B] FIG. 1 illustrates a sequence diagram of a process for authentication according to an exemplary embodiment. [Figure 4C] FIG. 1 illustrates a sequence diagram of a process for authentication according to an exemplary embodiment. [Figure 5] 1 illustrates an authentication method according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION

[0013] The following description of the embodiments provides non-limiting representative examples that refer to numerals to particularly explain the features and teachings of different aspects of the present invention. It should be recognized from the description of the embodiments that the described embodiments can be implemented separately from or in combination with other embodiments. Those skilled in the art who review the description of the embodiments should be able to learn and understand the various described aspects of the present invention. The description of the embodiments should facilitate understanding of the present invention to the extent that other implementations not specifically covered but within the knowledge of those skilled in the art who read the description of the embodiments will be understood to be consistent with applications of the present invention.

[0014] The systems and methods disclosed herein enable the provisioning and use of dynamic card verification values ​​for generated virtual card numbers. Such implementations provide controlled utilization of these parameters, which can be refreshed only upon physical possession of the card. Doing so may reduce security vulnerabilities associated with virtual card numbers. For example, they may reduce the risk of brute force attacks and fraud in card-not-present transactions, including, but not limited to, security verification transactions, authenticated access transactions, and other non-electronic commerce transactions.

[0015] Additionally, the systems and methods disclosed herein can prevent phishing attacks, prevent replay attacks, and prevent unauthorized interception of data through encrypted data communications, thereby reducing these vulnerabilities and other risks.

[0016] The disclosed systems and methods facilitate trade execution, promote trading efficiency, and make efficient use of system resources, benefits that become increasingly important as trading volumes increase.

[0017] Moreover, the systems and methods disclosed herein achieve these benefits without degrading the user experience, which makes users more likely to participate in safer transactions.

[0018] 1 illustrates an authentication system 100. System 100 may include a first device 105, a second device 110, a network 115, a server 120, and a database 125. Although FIG. 1 illustrates a single instance of the components of system 100, system 100 may include any number of components.

[0019] The system 100 may include a first device 105. The first device 105 may comprise a contactless card, a contact-based card, a network-enabled computer, or other device described herein. As referred to herein, a network-enabled computer may include a computing device or a communication device, including, but not limited to, a server, network appliance, personal computer, workstation, telephone, handheld PC, personal digital assistant, contactless card, thin client, fat client, Internet browser, kiosk, tablet, terminal, mobile device, wearable device, client device, or other device. As further described below in FIGS. 2A-2B , the first device 105 may include one or more processors 102 and a memory 104. The memory 104 may include one or more applets 106 and one or more counters 108. Each counter 108 may include a counter value. The memory 104 may include the counter value, transmission data, a unique identifier, an applet version number, a sequence number, and multiple keys.

[0020] The first device 105 may include a communication interface 107. The communication interface 107 may be capable of communicating with a physical interface or a contactless interface. For example, the communication interface 107 may be configured to communicate with a physical interface, such as by swiping through a card swipe interface or by inserting into a card chip reader on an automated teller machine (ATM) or other device configured to communicate through the physical interface. In other examples, the communication interface 107 may be configured to establish contactless communication with a card reading device via a near-field wireless communication method, such as near-field communication (NFC), Bluetooth, Wi-Fi, radio frequency identification (RFID), and other forms of contactless communication. As shown in FIG. 1 , the communication interface 107 may be configured to communicate directly with the second device 110, the server 120, and / or the database 125 via the network 115.

[0021] The first device 105 may be capable of data communication with any number of components of the system 100. For example, the first device 105 may transmit data to the second device 110 and / or the server 120 over the network 115. The first device 105 may transmit data to the database 125 over the network 115. In some examples, the first device 105 may be configured to transmit data over the network 115 after inputting data into one or more communication fields of any device. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof.

[0022] System 100 may include second device 110. Second device 110 may include one or more processors 112 and memory 114. Memory 114 may be temporary and / or non-temporary memory and may include one or more applications, including, but not limited to, application 116. Second device 110 may be in data communication with any number of components of system 100. For example, second device 110 may transmit data to server 120 via network 115. Second device 110 may transmit data to database 125 via network 115. Without limitation, second device 110 may be a network-enabled computer. The second device 110 may also be a mobile device, which may include, for example, an Apple® iPhone®, iPod®, iPad®, or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0023] The second device 110 may include processing circuitry and may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as needed to perform the functions described herein. The second device 110 may further include a display and input devices. A display may be any type of device for presenting visual information, such as a computer monitor, flat-panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device available and supported by the user's device for inputting information into the user's device, such as a touchscreen, keyboard, mouse, cursor control device, touchscreen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and interact with the software and other devices described herein.

[0024] System 100 may include network 115. In some examples, network 115 may be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network, and may be configured to connect to any one of the components of system 100. For example, first device 105 may be configured to connect to server 120 via network 115. In some examples, network 115 may include one or more of an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communications service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short message service, a time division multiplexing-based system, a code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, IEEE 802.15.1, IEEE 802.11n and IEEE 802.11g, Bluetooth, NFC, RFID, Wi-Fi, etc.

[0025] Additionally, network 115 may include, but is not limited to, a telephone line, optical fiber, IEEE Ethernet 902.3, a wide area network, a wireless personal area network, a LAN, or a global network such as the Internet. Additionally, network 115 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 115 may further include one network or any number of networks of the above exemplary types, operating as an independent network or in cooperation with one another. Network 115 may utilize one or more protocols of one or more network elements communicatively coupled thereto. Network 115 may translate one or more protocols of network devices to or from other protocols. While network 115 is shown as a single network, it should be understood that, according to one or more examples, network 115 may include multiple interconnected networks, such as the Internet, a service provider network, a cable television network, an enterprise network such as a credit card association network, and a home network.

[0026] The system 100 may include one or more servers 120. In some examples, the server 120 may include one or more processors 122 coupled to a memory 124. The server 120 may be configured as a central system, server, or platform for controlling and retrieving various data at different times to perform multiple workflow operations. The server 120 may be configured to connect to the first device 105. The server 120 may be in data communication with the applets 106 and / or applications 116. For example, the server 120 may be in data communication with the applets 106 via one or more networks 115. The first device 105 may be in communication with one or more servers 120 via one or more networks 115 and may operate as a front-end to back-end pair with the server 120. The first device 105 may send one or more requests to the server 120, for example, from an applet 106 running thereon. The one or more requests may be associated with retrieving data from the server 120. The server 120 may receive one or more requests from the first device 105. Based on the one or more requests from the applet 106, the server 120 may be configured to obtain the requested data. The server 120 may be configured to transmit the received data to the applet 106, where the received data is responsive to the one or more requests.

[0027] In some examples, server 120 may be a dedicated server computer, such as a bladed server, or may be a personal computer, laptop computer, notebook computer, palmtop computer, network computer, mobile device, wearable device, or any processor-controlled device capable of supporting system 100. While Figure 1 shows a single server 120, it should be understood that in other embodiments, multiple servers or multiple computer systems may be used as needed or desired to support users, and that backup or redundant servers may also be used to prevent network downtime in the event of a particular server failure.

[0028] Server 120 may include applications that include instructions for execution thereon. For example, an application may include instructions for execution on server 120. The applications on server 120 may be capable of communicating with any component of system 100. For example, server 120 may execute one or more applications that enable network and / or data communication with, for example, one or more components of system 100, and transmit and / or receive data. Without limitation, server 120 may be a network-enabled computer. As referred to herein, a network-enabled computer may include a computing device or a communications device, including, for example, but not limited to, a server, network appliance, personal computer, workstation, telephone, handheld PC, personal digital assistant, contactless card, thin client, fat client, Internet browser, or other device. Server 120 may also be a mobile device, including, for example, an Apple® iPhone, iPod, iPad, or any other mobile device running Apple's iOS® operating system, any device running Microsoft's Windows® Mobile operating system, any device running Google's Android® operating system, and / or any other smartphone, tablet, or similar wearable mobile device.

[0029] Server 120 may include processing circuitry and may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as needed to perform the functions described herein. Server 120 may further include displays and input devices. Displays may be any type of device for presenting visual information, such as computer monitors, flat-panel displays, and mobile device screens, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. Input devices may include any device available and supported by a user's device for inputting information into the user's device, such as a touchscreen, keyboard, mouse, cursor control device, touchscreen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and interact with the software and other devices described herein.

[0030] The system 100 may include one or more databases 125. The database 125 may include a relational database, a non-relational database, or other database implementation, as well as any combination thereof, including multiple relational and non-relational databases. In some examples, the database 125 may include a desktop database, a mobile database, or an in-memory database. Furthermore, the database 125 may be hosted internally by any component of the system 100, such as the first device 105 or the server 120, or the database 125 may be hosted externally to any component of the system 100, such as the first device 105 or the server 120, by a cloud-based platform, or on any storage device in data communication with the first device 105 and the server 120. In some examples, the database 125 may be in data communication with any number of components of the system 100. For example, the server 120 may be configured to retrieve requested data from the database 125 sent by the applet 106. The server 120 may be configured to transmit received data from the database 125 over the network 115 to the applet 106, the received data being in response to one or more requests. In other examples, the applet 106 may be configured to transmit one or more requests for the requested data from the database 125 over the network 115.

[0031] In some examples, exemplary procedures according to the present disclosure described herein can be performed by a processing and / or computing arrangement (e.g., a computer hardware arrangement). Such a processing / computing arrangement can be, or include, all or part of a computer / processor, including, for example, one or more microprocessors, and capable of using instructions stored on a computer-accessible medium (e.g., RAM, ROM, hard drive, or other storage device). For example, the computer-accessible medium can be part of the memory of the first device 105, the second device 110, the server 120, and / or the database 125, or other computer hardware arrangement.

[0032] In some examples, a computer-accessible medium (e.g., a storage device such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, or a collection thereof, as described above herein) may be provided (e.g., in communication with a processing arrangement). The computer-accessible medium may include instructions executable thereon. Additionally or alternatively, a storage arrangement may be provided separate from the computer-accessible medium that may provide instructions to the processing arrangement to configure the processing arrangement to perform certain example procedures, processes, and methods, e.g., as described above herein.

[0033] The processor 102 may be configured to receive an authentication request. In some examples, the processor 102 may be configured to receive an authentication request from any device, including, but not limited to, the client device 110. In other examples, the application 116 of the client device 110 may be configured to receive an authentication request from the processor 122 of the server 120. The application 116 of the client device 110 may be configured to perform one or more reads of the first device 105, such as a card. For example, the application 116 may be configured to perform a read, such as a proximity read, of a tag on the first device 105. In some examples, the application 116 may be configured to read information including a unique identification number associated with the first device, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), or a shared secret. In some examples, the application 116 may be configured to read a cryptogram generated using one or more cryptographic algorithms. The cryptogram may be dynamically generated as described herein in response to the authentication request. In some examples, the shared secret may be a number known or derived by the server 120 and / or the client device 110 and stored on the first device 105. The shared secret may be included in cryptographic calculations (e.g., used in cryptographic operations or algorithms), but is never transmitted between any of the devices.

[0034] In response to an authentication request, the processor 102 may be configured to generate a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters, including at least one selected from the group consisting of a unique identifier, a counter, a session key, and a primary account number (PAN) sequence number. In some examples, the initial value of the virtual card number is 0 (zero). Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0035] The processor 102 may be configured to transmit data responsive to a read, such as an initial read, after entering one or more communication fields of any device, including, but not limited to, the second device 110. For example, the processor 102 may be configured to transmit a cipher after initially entering a first communication field of the second device 110. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The cipher may be received upon request via a Near Field Communication Data Exchange Format (NDEF) read. The processor 102 may be configured to transmit the cipher. In some examples, the processor 102 may be configured to encrypt the first cipher before transmission. For example, the processor 102 may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. A message authentication code (MAC) may be generated using the first session key. The MAC may be encrypted with the second session key before being transmitted for decryption and verification. The processor 122 of the server 120 may be configured to generate a unique derived key using the unique identifier and the master key. The processor of the server 120 may be configured to generate a session key from the unique derived key and a counter. The processor 122 of the server 120 may be configured to decrypt the encrypted MAC from the cipher. The processor 122 of the server 120 may be configured to verify the MAC using the session key.

[0036] The processor 102 may be configured to transmit the cryptogram via the communication interface 107. For example, the processor 102 may be configured to transmit the cryptogram to one or more applications, such as the application 116. In some examples, the processor 102 may be configured to transmit the cryptogram to the application 116 that includes instructions for execution on the second device 110. The processor 102 may be configured to update a counter value after transmitting the cryptogram.

[0037] In some examples, processor 122 of server 120 may be configured to have processor 102 receive the encryption sent by processor 112. Application 116 of client device 110 may be configured to have processor 102 send the encryption to processor 122 of server 120. Processor 122 of server 120 may be configured to decrypt the encryption.

[0038] The processor 102 may be further configured to restrict the virtual card number to limited use. It will be appreciated that in other examples, the processor 122 of the server 120 may be configured to perform any number of operations performed by the processor 102 of the first device 105. For example, the processor 102 may be configured to limit the virtual card to one use or any number of uses not exceeding a threshold number. Additionally, the processor may be configured to restrict the virtual card number to limited use for or excluding types of transactions, specific merchants, categories of merchants, and / or transactions at or near specific locations. Without limitation, the processor may be configured to determine restrictions based on an evaluation of transaction history information, transaction frequency in a given time period, transaction locations, transaction amounts, login information, session information, merchant information, and / or user account information.

[0039] In some examples, the processor 102 may be configured to select one or more digits of a cipher via one or more cipher algorithms to generate the virtual card number. For example, the processor 102 may be configured to select the first digit of the cipher. In another example, the processor 102 may be configured to select the last digit of the cipher. In another example, the processor 102 may be configured to select any number and / or any sequence of numbers between the first and last digits of the cipher. In another example, the processor 102 may be configured to select any combination of digits of the cipher.

[0040] In some examples, processor 122 of server 120 may be configured to select one or more digits of a cryptogram to generate the virtual card number. In some examples, a sequence of numbers may be selected. Processor 122 may be configured to generate the virtual card number after successfully verifying the cryptogram and / or customer data (e.g., customer identifier, transaction data). Processor 122 may be configured to transmit the virtual card number to first device 105.

[0041] In another example, processor 102 of first device 105 may be configured to select one or more number sequences between the first and last digits of the cryptogram. In such an example, processor 122 of server 120 may be configured to maintain a bitmap to define the sequence order used during generation and verification of dynamic virtual card numbers. The bitmap may be maintained at the virtual card number system level or at the record level.

[0042] In some examples, the processor 102 may be further configured to restrict the virtual card number to a time window. For example, the processor 102 may be configured to limit use of the virtual card number to a range of a time window that includes a first value and a second value. In some examples, the processor 102 may be configured to restrict use of the dynamic security code to a time window. Further, the processor 102 may be configured to invalidate the dynamic security code if it is not used within the time window. Without limitation, the range of the time window may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0043] Thus, when a user is prompted to enter a virtual card number and dynamic security code, such as, but not limited to, via an application 116 on the second device 110 to provide information to a website to process a transaction, the processor 102 on the first device 105 may enter a communication field on the device to transmit this information along with a cryptogram to the device. Thus, the application 116 on the second device 110 may be configured to transmit a cryptogram including a counter to the processor 122 on the server 120. The processor 122 on the server 120 may be configured to allow the dynamic security code and virtual card number for a specified time window until the counter is adjusted. Thus, with this implementation, virtual card number usage can be restricted, requiring the physical card itself and the dynamic security code.

[0044] Additionally, the processor 102 may be further configured to synchronize the counter with the server during the time window. For example, the processor 102 may be configured to adjust the counter. In some examples, the processor 102 may be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In some examples, the processor 102 may be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The increment and / or decrement may be determined by the processor 102 according to a sequence. For example, the processor 102 may be configured to increment the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. For example, the processor 102 may be configured to decrement the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. It will be further understood that the sequence may be selected by the processor to avoid increasing the processing load on the first device 105. In this manner, one or more cryptographic algorithms may be configured to create a sufficiently high entropy number for the dynamic security code, which may reduce the possibility of brute force attacks. Thus, the processor 122 of the server 120 may be configured to record adjustments to the card's counter, such as increments or decrements, and associate them with the dynamic security code and virtual card number, and to avoid desynchronization with the first device 105. Without input by the processor 102 of the first device 105 into the communication field of the second device 110, such as the aforementioned tap, swipe, or wave, the dynamic security code and virtual card number generated by the card cannot be transmitted, thus resulting in a failed authentication request.

[0045] Dynamic generation of the security code is only possible after successful cryptographic verification, for example by processor 120 of server 120. Furthermore, integration with application 116 of second device 110 may also be required prior to generation of the security code.

[0046] The processor 102 may be further configured to encrypt the virtual card number and dynamic security code using a session key, such as a session key generated as described herein. After successful verification of the cryptography and / or customer data, the mobile application 116 may be configured to display the virtual card number and dynamic security code. Successful verification may be required before the virtual card number and dynamic security code are displayed and / or used. Display and / or use of the virtual card number and dynamic security code may be restricted to authorized applications and devices, such as the application 116 and the server 120. Decryption of the virtual card number and dynamic security code may be controlled by a hardware security module and / or a managed and integrated application programming interface of the second device 110 and the server 120.

[0047] The processor 102 may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. For example, the processor 102 may be configured to transmit the virtual card number and the dynamic security code in response to scanning a Quick Response (QR) code. In some examples, the processor 102 may be configured to transmit the virtual card number and the dynamic security code via a notification. The notification may include, but is not limited to, at least one selected from the group of a pop-up notification, a short message service, and a QR code. The notification may be displayed by the application 116 of the second device 110.

[0048] In some examples, the processor 102 may be further configured to encrypt the counter with the virtual card number and dynamic security code before transmission. The processor 102 may be configured to perform the encryption using a session key, such as a session key generated as described herein. Display and / or use of the virtual card number and dynamic security code may be permitted only after successful verification of the cryptography and / or customer data and may be restricted to authorized applications and devices, such as the application 116 and the server 120. Decryption of the virtual card number and dynamic security code may be controlled by hardware security modules and / or managed and integrated application programming interfaces of the second device 110 and the server 120.

[0049] 2A and 2B show one or more first devices 200. The first devices 200 may refer to the same or similar components of the first device 105, as described above with respect to FIG. 1. Although FIGS. 2A and 2B show a single example of components of the first device 200, any number of components may be utilized.

[0050] The first device 200 may be configured to communicate with one or more components of the system 100. The first device 200 may include a contact-based or contactless card, which may include a payment card such as a credit card, debit card, or gift card issued by a service provider 205 displayed on the front or back of the contactless card 200. In some examples, the contactless card 200 is unrelated to payment cards and may include, but is not limited to, identification cards, membership cards, access point cards, and transportation cards. The contactless card 200 may include a substrate 210, which may include a single layer or one or more laminates of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, contactless card 200 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard, while in others, contactless cards may conform to the ISO / IEC 14443 standard. However, it should be understood that contactless card 200 according to the present disclosure may have different characteristics, and the present disclosure does not require that the contactless card be implemented as a payment card.

[0051] Contactless card 200 may also include identification information 215 displayed on the front and / or back of the card and a contact pad 220. Contact pad 220 may be configured to establish contact with other communication devices, including, but not limited to, user devices, smartphones, laptop computers, desktop computers, or tablet computers. Contactless card 200 may also include processing circuitry, an antenna, and other components not shown in FIG. 2A . These components may be located behind contact pad 220 or elsewhere on substrate 210. Contactless card 200 may also include a magnetic strip or tape, which may be located on the back of the card (not shown in FIG. 2A ).

[0052] As shown in Figure 2B, the contact pad 220 of Figure 2A may include processing circuitry 225 for storing and processing information, including a processor 230, such as a microprocessor, and memory 235. The processing circuitry 225 may include additional components, including a processor, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, as needed to perform the functions described herein.

[0053] The memory 235 may be read-only memory, write-once, read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 200 may include one or more of these memories. Read-only memory may be programmable at the factory as read-only or one-time programmable. One-time programmability means that the memory can be written once and read many times. Write-once, read-multiple memory may be programmed at a time after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten but can be read many times. Read / write memory may be programmed and reprogrammed many times after leaving the factory and can be read many times.

[0054] The memory 235 may be configured to store one or more applets 240, one or more counters 245, and a customer identifier 250. The one or more applets 240 may include one or more software applications configured to run on one or more contactless cards, such as a Java Card applet. However, it will be understood that the applet 240 is not limited to a Java Card applet and may instead be any software application capable of running on a contactless card or other device with limited memory. The one or more counters 245 may include a numeric counter sufficient to store integers. The customer identifier 250 may include a unique alphanumeric identifier assigned to a user of the contactless card 200, which may distinguish the contactless card user from other contactless card users. In some examples, the customer identifier 250 may identify both the customer and the account assigned to the customer and may further identify the contactless card associated with the customer's account.

[0055] While the processor and memory elements of the above exemplary embodiments are described with reference to contact pads, the present disclosure is not limited thereto, and it will be understood that these elements may be implemented external to the contact pads 220, may be completely separate from the contact pads 220, or may be implemented as additional elements in addition to the processor 230 and memory 235 elements located within the contact pads 220.

[0056] In some examples, contactless card 200 may include one or more antennas 255. One or more antennas 255 may be disposed within contactless card 200 and around processing circuit 225 of contact pad 220. For example, one or more antennas 255 may be integral with processing circuit 225, or one or more antennas 255 may be used with an external booster coil. As another example, one or more antennas 255 may be external to contact pad 220 and processing circuit 225.

[0057] In one embodiment, the coil of the contactless card 200 may function as a secondary of an air-core transformer. The terminal may communicate with the contactless card 200 by cutting the power or amplitude modulation. The contactless card 200 may use gaps in the contactless card's power connection to infer data transmitted from the terminal, which may be maintained functionally via one or more capacitors. The contactless card 200 may return communication by switching the load or load modulation on the contactless card's coil. The load modulation may be detected by interference in the terminal's coil.

[0058] Figure 3 illustrates an authentication method 300. Figure 3 may reference the same or similar components of the system 100 and first device 200 of Figures 2A and 2B.

[0059] At block 310, the method may include receiving, by a processor, an authentication request. The processor may reside in a first device, including but not limited to, a card, a server, or a client device. In some examples, the processor may be configured to receive the authentication request from any device, including but not limited to, a mobile device.

[0060] At block 320, the method may include verifying and approving the authentication request by the processor, which may be performed by any of the methods described herein.

[0061] At block 330, method 300 may include generating, by the processor, in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN sequence number. In some examples, the initial value of the virtual card number is 0. Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0062] The processor may be configured to transmit data responsive to a read, such as an initial read, after inputting one or more communication fields of any device. For example, the processor may be configured to transmit a cipher after an initial input into a first communication field of the device. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The cipher may be received upon request via a Near Field Communication Data Exchange Format (NDEF) read. The processor may be configured to transmit the cipher. In some examples, the processor may be configured to encrypt the first cipher before transmission. For example, the processor may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. A MAC may be generated using the first session key. The MAC may be encrypted with the second session key before being transmitted for decryption and verification. The server may be configured to generate a unique derived key using a unique identifier and a master key. The server may be configured to generate a session key from the unique derived key and the counter. The server may be configured to decrypt the encrypted MAC from the cipher. The server may be configured to verify the MAC using the session key.

[0063] The processor may be configured to transmit the cryptogram via the communication interface. For example, the processor may be configured to transmit the cryptogram to one or more applications. In some examples, the processor may be configured to transmit the cryptogram to an application that includes instructions for execution on the second device. The processor may be configured to update a counter value after transmitting the cryptogram.

[0064] In some examples, the server may be configured to receive the encryption sent by the processor, the application on the client device may be configured to send the encryption to the server by the processor, and the server may be configured to decrypt the encryption.

[0065] At block 340, method 300 may include restricting the virtual card number to limited use. For example, the processor may be configured to limit the virtual card to one use or any number of uses not exceeding a threshold number. Further, the processor may be configured to restrict the virtual card number to limited use for or excluding types of transactions, specific merchants, categories of merchants, and / or transactions at or near specific locations. Without limitation, the processor may be configured to determine the restrictions based on an evaluation of transaction history information, transaction frequency in a given period, transaction locations, transaction amounts, login information, session information, merchant information, and / or user account information.

[0066] In some examples, the processor may be configured to select one or more digits of a cipher via one or more cipher algorithms to generate the virtual card number. For example, the processor may be configured to select the first digit of the cipher. In another example, the processor may be configured to select the last digit of the cipher. In another example, the processor may be configured to select any number and / or any sequence of numbers between the first and last digits of the cipher. In another example, the processor may be configured to select any combination of digits of the cipher.

[0067] In some examples, the processor may be further configured to restrict the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a range of a time window that includes the first value and the second value. In some examples, the processor may be configured to restrict use of the dynamic security code to a time window. Further, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the range of the time window may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0068] Thus, when a user is prompted to enter a virtual card number and dynamic security code, such as through an application on a second device to provide information to a website to process a transaction, the card may enter a communication field on the device and transmit this information along with a cryptogram to the device. Thus, the device application may be configured to transmit a cryptogram including a counter to a server. The server may be configured to allow the dynamic security code and virtual card number for a specified time window until the counter is adjusted. Thus, with this implementation, virtual card number usage can be restricted, requiring the physical card itself and the dynamic security code.

[0069] Additionally, the processor may be further configured to synchronize the counter with the server during the time window. For example, the processor may be configured to adjust the counter. In some examples, the processor may be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In some examples, the processor may be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The increment and / or decrement may be determined by the processor according to a sequence. For example, the processor may be configured to increment the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. For example, the processor may be configured to decrement the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. It will be further understood that the sequence may be selected by the processor to avoid increasing the processing load on the card. In this manner, one or more cryptographic algorithms may be configured to create a sufficiently high entropy number for the dynamic security code, which may reduce the possibility of brute force attacks. Thus, the server may be configured to record adjustments to the card's counter, such as increments or decrements, and associate them with the dynamic security code and virtual card number, and to avoid desynchronization with the card, whereby the absence of input into the card's communication fields, such as the aforementioned tap, swipe, or wave, would prevent the dynamic security code and virtual card number generated by the card from being transmitted, thus resulting in a failed authentication request.

[0070] At block 350, method 300 may include transmitting, by the processor, the virtual card number and the dynamic security code to complete the authentication request. For example, the processor may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. For example, the processor may be configured to transmit the virtual card number and the dynamic security code in response to scanning a QR code. In some examples, the processor may be configured to transmit the virtual card number and the dynamic security code via a notification. Without limitation, the notification may include at least one selected from the group of a pop-up notification, a short message service, and a QR code. The notification may be displayed by the device.

[0071] 4A shows a sequence diagram 400 of a process for authentication according to an example embodiment. FIG. 4A may reference the same or similar components of system 100, first device 200 of FIGS. 2A and 2B, and method 300 of FIG. 3.

[0072] In step 401, a processor may be configured to receive one or more requests. The processor may reside in a first device, including but not limited to a card (or first device), a server, or a client device, or a combination thereof. In some examples, the processor may be configured to receive an authentication request from any device, including but not limited to a client device. The request may be sent from a processor in a server to a processor or application in an intermediary device, such as a client device, and the intermediary device may in turn be configured to send the authentication request to a processor in a card.

[0073] In step 402, a processor or application on the client device may be configured to perform one or more reads. For example, the processor or application may be configured to perform a read, such as a proximity read of a tag on the card. Other information that may be read includes a unique identification number associated with the card, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), a shared secret, and a cryptogram. In some examples, the cryptogram may be generated by the card containing the read data, or the cryptogram may be generated using the read data and / or one or more cryptographic algorithms. In some examples, the shared secret may include a number known or derived by the application and / or server and stored on the card. The shared secret may be used to generate the cryptogram and / or perform a cryptographic operation using one or more cryptographic algorithms. In some examples, the processor or application on the client device may be configured to display a notification or otherwise prompt the user to perform the read.

[0074] In step 403, the processor may be configured to generate a virtual card number and a dynamic security code based on a mapping of the read data with multiple parameters, including, for example, a unique identifier, a counter, a session key, and a cryptogram including at least one selected from the group consisting of a PAN sequence number. In some examples, the initial value of the virtual card number is 0. Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0075] In other examples, the processor may receive a virtual card number generated by another device, such as a card, a server, or a client device. The virtual card number may be generated based on information received from the card (e.g., a unique identifier, a counter, a shared secret) upon successful authentication of the received information. In some examples, the shared secret may be a number known or derived by the server and / or client device and stored on the first device. The shared secret may be included in cryptographic calculations (e.g., used in cryptographic operations or algorithms) but is never transmitted between any of the devices.

[0076] The virtual card number may be generated with an initial or default security code value, such as a security code of 0. The virtual card number may be maintained in a database of virtual card numbers and transmitted to a processor. The virtual card number may be encrypted, for example, with a session key, before transmission. Upon receiving the virtual card number, the processor may decrypt the virtual card number and generate a dynamic security code.

[0077] The processor may be configured to transmit data responsive to a read, such as an initial read, after inputting one or more communication fields of any device. For example, the processor may be configured to transmit a cipher after an initial input into a first communication field of the device. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The cipher may be received upon request via a Near Field Communication Data Exchange Format (NDEF) read. The processor may be configured to transmit the cipher. In some examples, the processor may be configured to encrypt the first cipher before transmission. For example, the processor may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. A MAC may be generated using the first session key. The MAC may be encrypted with the second session key before being transmitted for decryption and verification. The server may be configured to generate a unique derived key using a unique identifier and a master key. The server may be configured to generate a session key from the unique derived key and the counter. The server may be configured to decrypt the encrypted MAC from the cipher. The server may be configured to verify the MAC using the session key.

[0078] The processor may be configured to transmit the cryptogram via the communication interface. For example, the processor may be configured to transmit the cryptogram to one or more applications. In some examples, the processor may be configured to transmit the cryptogram to an application that includes instructions for execution on the second device. The processor may be configured to update a counter value after transmitting the cryptogram.

[0079] In some examples, the server may be configured to receive the encryption sent by the processor, the application on the client device may be configured to send the encryption to the server by the processor, and the server may be configured to decrypt the encryption.

[0080] In step 404, the processor may be configured to restrict the virtual card number to limited use. For example, the processor may be configured to limit the virtual card to one use or any number of uses not exceeding a threshold number. Additionally, the processor may be configured to restrict the virtual card number to limited use for or excluding types of transactions, specific merchants, categories of merchants, and / or transactions at or near specific locations. Without limitation, the processor may be configured to determine restrictions based on an evaluation of transaction history information, transaction frequency in a given period, transaction locations, transaction amounts, login information, session information, merchant information, and / or user account information.

[0081] In step 405, the processor may be configured to select one or more digits of the cipher via one or more cipher algorithms to generate the virtual card number. For example, the processor may be configured to select the first digit of the cipher. In another example, the processor may be configured to select the last digit of the cipher. In another example, the processor may be configured to select any number and / or any sequence of numbers between the first and last digits of the cipher. In another example, the processor may be configured to select any combination of digits of the cipher.

[0082] In some examples, the processor may be further configured to restrict the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a range of a time window that includes the first value and the second value. In some examples, the processor may be configured to restrict use of the dynamic security code to a time window. Further, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the range of the time window may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0083] Thus, when a user is prompted to enter a virtual card number and dynamic security code, such as, but not limited to, through a second device application to provide information to a website to process a transaction, the card may complete a communication field on the device and transmit this information to the device along with a cryptogram. In this manner, the device application may be configured to transmit the cryptogram, including the counter, to a server. The server may be configured to allow the dynamic security code and virtual card number for a specified time window until the counter is adjusted. Thus, in this implementation, virtual card number use can be restricted, requiring the physical card itself and the dynamic security code. Furthermore, the processor may be configured to restrict the virtual card number to limited use for or excluding types of transactions, specific merchants, categories of merchants, and / or transactions at or near specific locations. Without limitation, the processor may be configured to determine restrictions based on an evaluation of transaction history information, transaction frequency over a given time period, transaction locations, transaction amounts, login information, session information, merchant information, and / or user account information.

[0084] Additionally, the processor may be further configured to synchronize the counter with the server during the time window. For example, the processor may be configured to adjust the counter. In some examples, the processor may be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In some examples, the processor may be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The increment and / or decrement may be determined by the processor according to a sequence. For example, the processor may be configured to increment the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. For example, the processor may be configured to decrement the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. It will be further understood that the sequence may be selected by the processor to avoid increasing the processing load on the card. In this manner, one or more cryptographic algorithms may be configured to create a sufficiently high entropy number for the dynamic security code, which may reduce the possibility of brute force attacks. Thus, the server may be configured to record adjustments to the card's counter, such as increments or decrements, and associate them with the dynamic security code and virtual card number, and to avoid desynchronization with the card, whereby the absence of input into the card's communication fields, such as the aforementioned tap, swipe, or wave, would prevent the dynamic security code and virtual card number generated by the card from being transmitted, thus resulting in a failed authentication request.

[0085] In step 406, the processor may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. For example, the processor may be configured to transmit the virtual card number and the dynamic security code in response to scanning a QR code. In some examples, the processor may be configured to transmit the virtual card number and the dynamic security code via a notification. Without limitation, the notification may include at least one selected from the group of a pop-up notification, a short message service, and a QR code.

[0086] In step 407, a notification may be displayed by the device's processor after receiving the virtual card number and dynamic security code from the card's processor. In some examples, the notification may only be displayed for a certain period of time and / or may be displayed based on whether the user has logged into the account for a certain period of time and / or whether the user has engaged in an active session after logging into the account. The virtual card number and dynamic security code may be stored in the device's memory.

[0087] 4B illustrates a sequence diagram 410 of a process for authentication according to an example embodiment. FIG. 4B may reference the same or similar components of system 100, first device 200 of FIGS. 2A and 2B, method 300 of FIG. 3, and sequence diagram 400 of FIG. 4A.

[0088] In step 411, a processor may be configured to receive an authentication request. The processor may reside in a first device, including but not limited to a card (or first device), a server, or a client device, or a combination thereof. In some examples, the processor may be configured to send the authentication request to any device, including but not limited to an application on the client device. In some examples, the request may be sent from a processor on a server to a processor or application on an intermediary device, such as a client device, which in turn may be configured to send the authentication request to a processor on the card and / or perform a card read.

[0089] In step 412, a processor or application on the client device may be configured to perform one or more reads. For example, the processor or application on the client device may be configured to perform a read, such as a proximity read of a tag on the card, to obtain read data. Other information that may be read and included in the read data may include a unique identification number associated with the card, a counter (e.g., a counter associated with the number of reads of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter), a PAN sequence number, a shared secret, and a cipher. In some examples, the cipher may be generated by the card containing the read data, and the cipher may be generated using the read data and / or one or more cryptographic algorithms. In some examples, the shared secret may include a number known or derived by the application and / or server and stored on the card. The shared secret may be used to generate the cipher and / or perform a cryptographic operation using one or more cryptographic algorithms. In some examples, the processor or application on the client device may be configured to display a notification or otherwise prompt the user to perform the read.

[0090] For example, a processor or application on the client device may be configured to transmit data responsive to a read, such as an initial read, after inputting one or more communication fields on any device. For example, the processor may be configured to transmit a cipher after first inputting a first communication field on the device. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The cipher may be received via a Near Field Communication Data Exchange Format (NDEF) read upon request. The processor or application may be configured to transmit the cipher. In some examples, the processor may be configured to encrypt the first cipher before transmission. For example, the processor or application may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. A MAC may be generated using the first session key. The MAC may be encrypted with the second session key before being transmitted for decryption and verification.

[0091] In step 413, the processor or application of the client device can be configured to send the request for the read data and the virtual card number to the processor of the server. The processor of the server can be configured to receive the request for the read data and the virtual card number and decrypt the request for the read data and the virtual card number, if necessary, by any method described herein. For example, the server can be configured to generate a unique derived key using the unique identifier and the master key. The server can be configured to generate a session key from the unique derived key and a counter. The server can be configured to decrypt the encrypted MAC from the cipher.

[0092] The processor of the server may be configured to authenticate the read data in step 414. For example, the server may be configured to verify the MAC using a session key.

[0093] In step 415, the server's processor may be configured to generate a virtual card number and a dynamic security code based on a mapping of the read data with multiple parameters, including, for example, a unique identifier, a counter, a session key, and a cryptogram including at least one selected from the group consisting of a PAN sequence number. In some examples, the initial value of the virtual card number is 0. Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0094] In step 416, the processor of the server may be configured to register the virtual card number with one or more payment authentication systems to enable use of the virtual number. In some examples, the processor may be further configured to restrict the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a range of a time window that includes a first value and a second value. In some examples, the processor may be configured to restrict use of the dynamic security code to a time window. Furthermore, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc. Furthermore, the processor may be configured to restrict use of the virtual card number to or excluding a type of transaction, a particular merchant, a category of merchants, and / or transactions at or near a particular location. Without limitation, the processor may be configured to determine the restriction based on an evaluation of transaction history information, transaction frequency in a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0095] In step 417, the processor of the server may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. In some examples, the processor may be configured to transmit the virtual card number and the dynamic security code via a notification. Without limitation, the notification may include at least one selected from the group of a pop-up notification, a short message service, and a QR code.

[0096] The notification may be displayed by a processor or application on the client device after receiving the virtual card number and dynamic security code from the processor on the server. In some examples, the notification may be displayed for only a certain period of time and / or based on whether the user has been logged into the account for a certain period of time and / or whether the user has engaged in an active session after logging into the account. The virtual card number and dynamic security code may be stored in a memory on the client device.

[0097]

[0033] Figure 4C illustrates a sequence diagram 420 of a process for authentication according to an example embodiment. Figure 4C may reference the same or similar components of system 100, first device 200 of Figures 2A and 2B, method 300 of Figure 3, sequence diagram 400 of Figure 4A, and sequence diagram 410 of Figure 4B.

[0098] In step 421, a processor may be configured to request an authentication request and a virtual card number. The processor may reside in a first device, including but not limited to a card (or first device), a server, or a client device, or a combination thereof. In some examples, the processor may be configured to send the authentication request and the request for the virtual card number to any device, including but not limited to an application on the client device and a processor on the card. In some examples, the request may be sent from a processor on the server to a processor or application on an intermediary device, such as the client device, which may in turn be configured to send the authentication request to the processor on the card and / or perform the card read.

[0099] In step 422, the card processor may be configured to generate a virtual card number and a dynamic security code based on a mapping of the read data with multiple parameters, including, for example, a unique identifier, a counter, a session key, and a cryptogram including at least one selected from the group consisting of a PAN sequence number. In some examples, the initial value of the virtual card number is 0. Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0100] In some examples, the processor may be further configured to restrict the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a time window range that includes the first value and the second value. In some examples, the processor may be configured to restrict use of the dynamic security code to a time window. Furthermore, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc. Furthermore, the processor may be configured to restrict use of the virtual card number to or excluding a type of transaction, a particular merchant, a category of merchants, and / or transactions at or near a particular location. Without limitation, the processor may be configured to determine the restriction based on an evaluation of transaction history information, transaction frequency in a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0101] The card's processor may be configured to transmit the virtual card number and dynamic security code to the server in step 423. In some examples, the virtual card number and dynamic security code may be transmitted from the card's processor to a processor or application on an intermediary device, such as a client device, which in turn may be configured to transmit the virtual card number and dynamic security code to a processor on the server.

[0102] In some examples, prior to transmission, the card may generate a cryptogram using the included data and / or one or more cryptographic algorithms, including the virtual card number, dynamic security, and other data associated with the card, such as a unique identification number, a counter (e.g., a counter associated with the number of swipe attempts of the first device, a counter associated with the number of transactions involving the first device, an application transaction counter, a PAN sequence number), a shared secret, and a cryptogram. In some examples, the shared secret may include a number known or derived by the application and / or server and stored on the card. The shared secret may be used to generate the cryptogram and / or to perform cryptographic operations using one or more cryptographic algorithms.

[0103] In some examples, the processor of the card may be configured to encrypt the first cipher before transmission. For example, the processor may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. A MAC may be generated using the first session key. The MAC may be encrypted with the second session key before being transmitted for decryption and verification.

[0104] The server's processor can be configured to receive the request for the read data and the virtual card number by any method described herein and decrypt the request for the read data and the virtual card number, if necessary. For example, the server can be configured to generate a unique derived key using the unique identifier and the master key. The server can be configured to generate a session key from the unique derived key and a counter. The server can be configured to decrypt the encrypted MAC from the cipher.

[0105] The processor of the server may be configured to authenticate the read data in step 424. For example, the server may be configured to verify the MAC using a session key.

[0106] In step 425, the processor of the server may be configured to register the virtual card number with one or more payment authentication systems to enable use of the virtual number. In some examples, the processor may be further configured to restrict the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a range of a time window that includes a first value and a second value. In some examples, the processor may be configured to restrict use of the dynamic security code to a time window. Furthermore, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the time window range may include any number of seconds, minutes, hours, days, weeks, months, years, etc. Furthermore, the processor may be configured to restrict use of the virtual card number to or exclude a type of transaction, a particular merchant, a category of merchants, and / or transactions at or near a particular location. Without limitation, the processor may be configured to determine the restriction based on an evaluation of transaction history information, transaction frequency in a given time period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0107] In step 426, the processor of the server may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. In some examples, the processor may be configured to transmit the virtual card number and the dynamic security code via a notification. Without limitation, the notification may include at least one selected from the group of a pop-up notification, a short message service, and a QR code.

[0108] The notification may be displayed by a processor or application on the client device after receiving the virtual card number and dynamic security code from the processor on the server. In some examples, the notification may be displayed for only a certain period of time and / or based on whether the user has been logged into the account for a certain period of time and / or whether the user has engaged in an active session after logging into the account. The virtual card number and dynamic security code may be stored in a memory on the client device.

[0109] Figure 5 illustrates an authentication method 500 according to an example embodiment. Figure 5 may reference the same or similar components of system 100, first device 200 of Figures 2A and 2B, method 300 of Figure 3, sequence diagram 400 of Figure 4A, sequence diagram 410 of Figure 4B, and sequence diagram 420 of Figure 4C.

[0110] At block 510, the method may include generating a cryptogram in response to an authentication request. For example, the processor may be configured to generate the cryptogram in response to an authentication request from an intermediary device or any other device. The processor may belong to a first device, including, but not limited to, a card. In some examples, the processor may be configured to receive an authentication request from any device, including, but not limited to, a mobile device. The processor may be configured to transmit data responsive to a read, such as an initial read, after inputting one or more communication fields of the device. For example, the processor may be configured to transmit the cryptogram after an initial input into a first communication field of the device. Without limitation, each input may be associated with a tap, a swipe, a wave, and / or any combination thereof. The cryptogram may be received via a Near Field Communication Data Exchange Format (NDEF) read upon request. The processor may be configured to transmit the cryptogram. In some examples, the processor may be configured to encrypt the first cryptogram before transmission. For example, the processor may be configured to generate multiple session keys, such as a first session key and a second session key, using a secret key combined with a counter. The MAC may be generated using a first session key. The MAC may be encrypted with a second session key before being sent for decryption and verification. The server may be configured to generate a unique derived key using the unique identifier and the master key. The server may be configured to generate a session key from the unique derived key and a counter. The server may be configured to decrypt the encrypted MAC from the cipher. The server may be configured to verify the MAC using the session key.

[0111] The processor may be configured to transmit the cryptogram via the communication interface. For example, the processor may be configured to transmit the cryptogram to one or more applications. In some examples, the processor may be configured to transmit the cryptogram to an application that includes instructions for execution on the second device. The processor may be configured to update a counter value after transmitting the cryptogram.

[0112] In some examples, the server may be configured to receive the encryption sent by the processor, the application on the client device may be configured to send the encryption to the server by the processor, and the server may be configured to decrypt the encryption.

[0113] At block 520, the method 300 may include generating, by the processor, a virtual card number and a dynamic security code based on a mapping with a plurality of cryptographic parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a PAN sequence number. In some examples, the initial value of the virtual card number is 0. Without limitation, the virtual card number may include up to 16 total digits. Also, without limitation, the dynamic security code may include a card verification value. For example, the card verification value may include up to 3 total digits. In some examples, the initial value of the virtual card number is not 0.

[0114] In another example, the processor may receive a virtual card number generated by another device, such as a card, a server, or a client device. The virtual card number may be generated upon successful authentication of the received information based on information received from the card (e.g., a unique identifier, a counter, and a shared secret). The virtual card number may be generated with an initial or default security code value, such as a security code of 0. The virtual card number may be maintained in a database of virtual card numbers and transmitted to the processor. The virtual card number may be encrypted, for example, with a session key, before transmission. Upon receiving the virtual card number, the processor may decrypt the virtual card number and generate a dynamic security code.

[0115] In some examples, the method may include restricting the virtual card number to limited use. For example, the processor may be configured to limit the virtual card to one use or any number of uses not exceeding a threshold number. Further, the processor may be configured to restrict the virtual card number to limited use for or excluding types of transactions, specific merchants, categories of merchants, and / or transactions at or near specific locations. Without limitation, the processor may be configured to determine the limit based on an evaluation of transaction history information, transaction frequency in a given period, transaction location, transaction amount, login information, session information, merchant information, and / or user account information.

[0116] In some examples, the processor may be configured to select one or more digits of a cipher via one or more cipher algorithms to generate the virtual card number. For example, the processor may be configured to select the first digit of the cipher. In another example, the processor may be configured to select the last digit of the cipher. In another example, the processor may be configured to select any number and / or any sequence of numbers between the first and last digits of the cipher. In another example, the processor may be configured to select any combination of digits of the cipher.

[0117] In some examples, the card, a server, or another device, such as a client device, may be configured to select one or more digits of the cryptogram to generate a virtual card number. The virtual card number may be generated after successful verification of the cryptogram and / or customer data (e.g., customer identifier, transaction data). The virtual card number may be transmitted to a processor.

[0118] At block 530, the method may include restricting, by the processor, the virtual card number to a time window. For example, the processor may be configured to limit use of the virtual card number to a range of the time window that includes the first value and the second value. In some examples, the processor may be configured to restrict use of the dynamic security code to the time window. Further, the processor may be configured to invalidate the dynamic security code if not used within the time window. Without limitation, the range of the time window may include any number of seconds, minutes, hours, days, weeks, months, years, etc.

[0119] Thus, when a user is prompted to enter a virtual card number and dynamic security code, such as through an application on a second device to provide information to a website to process a transaction, the card may enter a communication field on the device and transmit this information to the device along with a cryptogram. Thus, the application on the device may be configured to transmit a cryptogram including a counter to a server. The server may be configured to allow the dynamic security code and virtual card number for a specified time window until the counter is adjusted. Thus, with this implementation, virtual card number use can be restricted, requiring the physical card itself and the dynamic security code.

[0120] At block 540, the method may include, by the processor, synchronizing the counter with the server during the time window. For example, the processor may be configured to adjust the counter. In some examples, the processor may be configured to increment the counter with the virtual card number and the dynamic security code during the time window. In some examples, the processor may be configured to decrement the counter with the virtual card number and the dynamic security code during the time window. The increment and / or decrement may be determined by the processor according to a sequence. For example, the processor may be configured to increment the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. For example, the processor may be configured to decrement the counter by an even number, an odd number, or a formula to improve security and prevent the possibility of brute force attacks. It will be further understood that the sequence may be selected by the processor to avoid increasing the processing load on the card. In this manner, one or more cryptographic algorithms may be configured to create a sufficiently high entropy number for the dynamic security code, which may reduce the possibility of brute force attacks. Thus, the server may be configured to record adjustments to the card's counter, such as increments or decrements, and associate them with the dynamic security code and virtual card number, and to avoid desynchronization with the card, whereby the absence of input into the card's communication fields, such as the aforementioned tap, swipe, or wave, would prevent the dynamic security code and virtual card number generated by the card from being transmitted, thus resulting in a failed authentication request.

[0121] At block 550, the method may include transmitting, by the processor, the virtual card number and the dynamic security code to complete the authentication request. For example, the processor may be configured to transmit the virtual card number and the dynamic security code to complete the authentication request. For example, the processor may be configured to transmit the virtual card number and the dynamic security code in response to scanning a QR code. In some examples, the processor may be configured to transmit the virtual card number and the dynamic security code via a notification. Without limitation, the notification may include at least one selected from the group of a pop-up notification, a short message service, and a QR code. The notification may be displayed by the device.

[0122] In some aspects, the technology described herein relates to an authentication system including a processor and a memory including a unique identifier, a counter, a session key, and a sequence number, wherein the processor is configured to: receive an authentication request; receive a cryptogram including one or more parameters, the one or more parameters including at least one selected from the group of the unique identifier, the counter, the session key, and the sequence number; generate a virtual card number and a dynamic security code in response to the authentication request based on a mapping with the one or more parameters; and transmit the virtual card number and the dynamic security code to complete the authentication request.

[0123] In some aspects, the technology described herein relates to an authentication system in which the virtual card number has an initial value of 0.

[0124] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to limit the virtual card number to a single use for a type of transaction.

[0125] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to select one or more digits of the cryptogram via one or more cryptographic algorithms to generate the virtual card number.

[0126] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to restrict the virtual card number to a time window.

[0127] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to synchronize the counters during the time window.

[0128] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to increment a counter with the virtual card number and the dynamic security code during the time window.

[0129] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to decrement a counter with the virtual card number and the dynamic security code during the time window.

[0130] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to restrict the dynamic security code to usage within a time window and to invalidate the dynamic security code if not used within the time window.

[0131] In some aspects, the technology described herein relates to an authentication system, wherein the processor is further configured to transmit the virtual card number and the dynamic security code in response to scanning the QR code.

[0132] In some aspects, the technology described herein relates to a method of authentication, including receiving, by a processor, an authentication request; receiving, by the processor, a cryptogram including one or more parameters, the one or more parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a sequence number; generating, by the processor, a virtual card number and a dynamic security code in response to the authentication request based on a mapping with the one or more parameters; and transmitting, by the processor, the virtual card number and the dynamic security code to complete the authentication request.

[0133] In some aspects, the technology described herein relates to a method in which the virtual card number is initially zero.

[0134] In some aspects, the technology described herein relates to a method further including limiting, by the processor, the virtual card number to a single use for a type of transaction.

[0135] In some aspects, the technology described herein relates to a method further including selecting, by the processor, one or more digits of the cryptogram via one or more cryptographic algorithms to generate the virtual card number.

[0136] In some aspects, the technology described herein relates to a method further including restricting, by the processor, the virtual card number to a time window.

[0137] In some aspects, the techniques described herein relate to a method further including synchronizing, by the processor, a counter during the time window.

[0138] In some aspects, the techniques described herein relate to a method further including incrementing, by the processor, a counter with the virtual card number and the dynamic security code during the time window.

[0139] In some aspects, the technology described herein relates to a method further including decrementing, by the processor, a counter with the virtual card number and the dynamic security code during the time window.

[0140] In some aspects, the technology described herein relates to a method further including transmitting, by the processor, the virtual card number and the dynamic security code via a notification, wherein the notification includes at least one selected from the group of a pop-up notification, a short message service, and a QR code.

[0141] In some aspects, the techniques described herein relate to a computer-accessible non-transitory medium including computer-executable instructions that, when executed on a processor, perform procedures including receiving an authentication request; receiving a cryptogram including one or more parameters, where the one or more parameters include at least one selected from the group of a unique identifier, a counter, a session key, and a sequence number; generating a virtual card number and a dynamic security code in response to the authentication request based on a mapping with the one or more parameters; and transmitting the virtual card number and the dynamic security code to complete the authentication request.

[0142] Throughout this disclosure, reference is made to cards such as contact-based cards and contactless cards. It will be understood that this disclosure is not limited to a particular type of card; instead, this disclosure encompasses contact-based cards, contactless cards, or any other cards. It will further be understood that this disclosure is not limited to cards having a particular purpose (e.g., payment cards, gift cards, identification cards, membership cards, transportation cards, access cards), cards associated with a particular type of account (e.g., credit account, debit account, membership account), or cards issued by a particular entity (e.g., commercial entity, financial institution, government entity, social club). Instead, it will be understood that this disclosure includes cards having any purpose, account affiliation, or issuing entity.

[0143] It is further noted that the systems and methods described herein may be tangibly embodied in one or more physical media, such as, but not limited to, a compact disc (CD), a digital versatile disc (DVD), a floppy disk, a hard drive, a read-only memory (ROM), a random access memory (RAM), and other physical media capable of storing data. For example, data storage may include random access memory (RAM) and read-only memory (ROM), which may be configured to access and store data and information as well as computer program instructions. Data storage may also include storage media or other suitable types of memory (e.g., RAM, ROM, programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), magnetic disks, optical disks, floppy disks, hard disks, removable cartridges, flash drives, any type of tangible and non-transitory storage media, etc.), in which files including operating systems, application programs, including, for example, web browser applications, email applications, and / or other applications, and data files may be stored. Data storage in a network-enabled computer system may include electronic information, files, and documents stored in a variety of ways, such as, for example, flat files, indexed files, hierarchical databases, relational databases such as those created and maintained with software from Oracle® Corporation or the like, Microsoft® Excel files, Microsoft® Access files, solid-state storage which may include software flash arrays, hybrid arrays, or server-side products, enterprise storage which may include online or cloud storage, or any other storage mechanism. Additionally, the diagram depicts various components (e.g., servers, computers, processors, etc.) separately.The functions described as being performed by various components may be performed by other components, the various components may be combined or separated, and other variations may be made.

[0144] In the foregoing specification, various embodiments have been described with reference to the accompanying drawings. However, it will be apparent that various modifications and changes may be made thereto, and additional embodiments may be implemented, without departing from the broader scope of the invention as set forth in the appended claims. Accordingly, the specification and drawings should be regarded in an illustrative sense, rather than a restrictive sense.

Claims

1. 1. An authentication system comprising: a processor; a memory including a unique identifier, a counter, a session key, and a sequence number; Including, The processor: receiving an authentication request; receiving a cipher including one or more parameters, the one or more parameters including at least one selected from the group of the unique identifier, the counter, the session key, and the sequence number; generating a virtual card number and a dynamic security code based on a mapping with the one or more parameters in response to the authentication request; submitting the virtual card number and the dynamic security code to complete the authentication request; an authentication system configured to:

2. The authentication system of claim 1 , wherein the initial value of the virtual card number is 0.

3. The authentication system of claim 1 , wherein the processor is further configured to limit the virtual card number to a single use for a type of transaction.

4. The authentication system of claim 1 , wherein the processor is further configured to select one or more digits of the cryptogram via one or more cryptographic algorithms to generate the virtual card number.

5. The authentication system of claim 1 , wherein the processor is further configured to restrict the virtual card number to a time window.

6. The authentication system of claim 5 , wherein the processor is further configured to synchronize the counters during the time window.

7. The authentication system of claim 6 , wherein the processor is further configured to increment the counter with the virtual card number and the dynamic security code during the time window.

8. The authentication system of claim 6 , wherein the processor is further configured to decrement the counter with the virtual card number and the dynamic security code during the time window.

9. The processor: restricting the dynamic security code to a time window of use; invalidating the dynamic security code if not utilized within the time window; The authentication system of claim 1 further configured to:

10. The authentication system of claim 1 , wherein the processor is further configured to transmit the virtual card number and the dynamic security code in response to scanning a QR code.

11. 1. An authentication method comprising: receiving, by a processor, an authentication request; receiving, by the processor, a cipher including one or more parameters, the one or more parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a sequence number; generating, by the processor, in response to the authentication request, a virtual card number and a dynamic security code based on a mapping with the one or more parameters; transmitting, by the processor, the virtual card number and the dynamic security code to complete the authentication request; authentication methods, including

12. The method of claim 11 , wherein the initial value of the virtual card number is 0.

13. The method of claim 11 , further comprising limiting, by the processor, the virtual card number to a single use for a certain type of transaction.

14. 12. The method of claim 11, further comprising selecting, by the processor, one or more digits of the cryptogram via one or more cryptographic algorithms to generate the virtual card number.

15. The method of claim 11 , further comprising restricting, by the processor, the virtual card number to a time window.

16. The method of claim 15 further comprising synchronizing, by the processor, the counters during the time window.

17. 17. The method of claim 16, further comprising incrementing, by the processor, the counter with the virtual card number and the dynamic security code during the time window.

18. 17. The method of claim 16, further comprising decrementing, by the processor, the counter with the virtual card number and the dynamic security code during the time window.

19. 12. The method of claim 11, further comprising transmitting, by the processor, the virtual card number and the dynamic security code via a notification, the notification comprising at least one selected from the group of a pop-up notification, a short message service, and a QR code.

20. When executed on a processor, receiving an authentication request; receiving a cryptogram including one or more parameters, the one or more parameters including at least one selected from the group of a unique identifier, a counter, a session key, and a sequence number; generating a virtual card number and a dynamic security code in response to the authentication request based on a mapping with the one or more parameters; transmitting the virtual card number and the dynamic security code to complete the authentication request; A computer-accessible non-transitory medium containing computer-executable instructions for performing procedures including: