Tap to copy data to clipboard via NFC
The NFC-based system securely transfers encrypted payment card data to the clipboard using key diversification, addressing the challenge of accurate data entry and enhancing security and convenience.
Patent Information
- Application Number
- JP2025179684
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2019-03-20
- Filing Date
- 2025-10-24
- Publication Date
- 2026-02-03
AI Technical Summary
Users often face difficulties in accurately entering long payment card account identifiers due to their complex nature, leading to errors and inefficiencies in manual input processes, and existing systems lack secure methods for copying this data to a clipboard.
A system utilizing NFC communication between a contactless card and a mobile device, employing key diversification and encryption to securely transfer encrypted account data to the clipboard, verified by a server, allowing seamless and accurate data copying without manual input.
Enhances data security and accuracy by enabling secure, automated transfer of payment card details to the clipboard, reducing errors and improving user convenience.
Smart Images

Figure 2026016581000001_ABST
Abstract
Description
[Technical Field]
[0001] TECHNICAL FIELD Embodiments herein relate generally to mobile computing platforms, and more particularly to tapping to copy data to a clipboard via near field communication (NFC).
[0002] Related Applications This application claims priority to U.S. Patent Application No. 16 / 359,966, entitled "Tap to Copy Data to Clipboard via NFC," filed March 20, 2019, the contents of which are incorporated herein by reference in their entirety. [Background technology]
[0003] Payment card account identifiers are often long strings of numbers or characters. This makes it difficult for users to manually enter the account identifier correctly. In fact, users often make mistakes and enter incorrect account numbers into computing interfaces (e.g., payment interfaces). Furthermore, processes have been developed that allow cameras to capture the account identifier even when a user enters the correct account identifier. Summary of the Invention
[0004]
[0006] Embodiments disclosed herein provide a system, method, article of manufacture, and computer-readable medium for tapping to copy data to a clipboard via NFC. According to one example, an application may receive encrypted data from a communication interface of a contactless card associated with an account, the encrypted data being generated based on one or more encryption algorithms and a diversified key, the diversified key being stored in the contactless card's memory and being generated based on a master key and a counter value stored in the contactless card's memory. The application may then receive verification of the encrypted data from a server, the server decrypting the encrypted data based on one or more encryption algorithms and the diversified key stored in the server's memory to verify the encrypted data, the diversified key being generated based on the master key and a counter value stored in the server's memory. The application may further receive an encrypted account number associated with the account from the server. The application may decrypt the encrypted account number to generate an account number. The application may then copy the account number to a clipboard of an operating system (OS) running on a processor circuit. [Brief explanation of the drawings]
[0005] [Figure 1A] 1 illustrates an embodiment of a system for tapping to copy data to a clipboard via NFC. [Figure 1B] 1 illustrates an embodiment of a system for tapping to copy data to a clipboard via NFC. [Figure 2] 1 illustrates an embodiment of a tap to copy data to the clipboard via NFC. [Figure 3A] 1 illustrates an embodiment of a tap to copy data to the clipboard via NFC. [Figure 3B]1 illustrates an embodiment of a tap to copy data to the clipboard via NFC. [Figure 3C] 1 illustrates an embodiment of a tap to copy data to the clipboard via NFC. [Figure 4A] An example of a contactless card is shown. [Figure 4B] An example of a contactless card is shown. [Figure 5] 1 illustrates a first logic flow embodiment. [Figure 6] 10 illustrates a second logic flow embodiment. [Figure 7] 10 illustrates a third logic flow embodiment. [Figure 8] 1 illustrates an embodiment of a computing architecture. DETAILED DESCRIPTION OF THE INVENTION
[0006]
[0003] Embodiments disclosed herein provide secure techniques for copying data (e.g., account numbers) from a contactless card to a clipboard of a computing device using NFC. Generally, a device user may provide input to an application specifying that data be copied from the contactless card. The contactless card may then come into NFC communication range with the device, for example, via a tap gesture. The application may then instruct the contactless card to generate and send data to the application via NFC. The data generated by the contactless card may be encrypted using key diversification. The application may send the data received from the contactless card to a server for verification. Upon verifying the data, the server may send the account data (e.g., account number) to an application on the device, which may copy the received account data to the device's operating system clipboard. The account data may remain on the clipboard until a purchase is made or a time threshold expires, at which point the clipboard contents may be erased, overwritten, or otherwise modified. Advantageously, doing so improves the security of all devices and associated data.
[0007] With general reference to the notation and nomenclature used herein, one or more portions of the detailed descriptions which follow may be presented in terms of program procedures executed on a computer or network of computers. These procedural descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art. A procedure is herein, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. These operations are operations requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be noted, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.
[0008] Further, these operations are often referred to in terms, such as adding or comparing, which are commonly associated with mental operations performed by a human operator. However, no such capability of a human operator is necessary, or desirable in most cases, for any of the operations described herein forming part of one or more embodiments. Rather, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by a computer program stored therein and written in accordance with the teachings herein, and / or include apparatuses or digital computers specially constructed for the required purposes. Various embodiments also relate to apparatuses or systems for performing these operations. These apparatuses may be specially constructed for the required purposes. The required structure for these various machines will be apparent from the description given.
[0009] Reference is now made to the drawings, wherein like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding thereof. It will be apparent, however, that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate description. The intention is to cover all modifications, equivalents, and alternatives within the scope of the claims.
[0010] FIG. 1A illustrates a schematic diagram of an exemplary system 100 consistent with disclosed embodiments. As shown, the system 100 includes one or more contactless cards 101, one or more mobile devices 110, and a server 120. The contactless cards 101 represent any type of payment card, such as a credit card, a debit card, an ATM card, or a gift card. The contactless cards 101 may include one or more chips (not shown), such as a radio frequency identification (RFID) chip, configured to communicate with the mobile devices 110 via NFC, the EMV standard, or other short-range protocols for wireless communication, or using NFC Data Exchange Format (NDEF) tags. While NFC is used as an example communication protocol, the present disclosure is equally applicable to other types of wireless communication, such as the EMV standard, Bluetooth, and / or Wi-Fi. The mobile devices 110 represent any type of network-enabled computing device, such as a smartphone, a tablet computer, a wearable device, a laptop, a portable gaming device, or the like. Server 120 represents any type of computing device, such as a server, a workstation, a computing cluster, a cloud computing platform, a virtualized computing system, and the like.
[0011] As shown, the memory 102 of the contactless card 101 includes data 103, a counter 104, a master key 105, a diversified key 106, and a unique customer identifier 107. The data 103 generally includes any data that can be copied to a clipboard 114, such as characters, text, executable code, images, or other types of data objects. In one embodiment, the data 103 may comprise an account number, expiration date, and card verification value (CVV) associated with the contactless card 101. The account number may be any type of account number, such as a primary account number (PAN), a virtual account number, and / or a token generated based on a PAN. Other types of account numbers are contemplated, and the use of a particular type of account number as an example herein should not be considered limiting of the disclosure. Data 103 may further include name, billing address, shipping address, username and / or password, one-time use code for multi-factor authentication, personalized uniform resource locators (URLs), gift card numbers, driver's license information, passport information, loyalty program information, loyalty points, phone numbers, email addresses, contact information, access information, etc. Other types of data 103 are contemplated, and the use of any type of data 103 as an example herein should not be considered limiting of this disclosure.
[0012] As shown, memory 111 of mobile device 110 includes an instance of operating system (OS) 112. Examples of operating systems 112 include Android® OS, iOS®, Linux®, and Windows® operating systems. As shown, OS 112 includes an account application 113, a clipboard 114, and one or more other applications 115. Account application 113 allows a user to perform various account-related operations, such as viewing account balances and processing payments, as described in more detail below. Initially, a user must authenticate using authentication credentials to access the account application. For example, the authentication credentials may include a username and password, biometric credentials, etc. Clipboard 114 stores data that can be copied and / or pasted within OS 112. For example, as discussed in more detail below, an account number (e.g., part of data 103) for an account associated with contactless card 101 may be programmatically copied to clipboard 114 in a secure manner using commands and / or gestures available within OS 112. The account number may then be pasted from clipboard 114 to account application 113, other applications 115, and / or other components of OS 112 using commands and / or gestures available within OS 112. In at least one embodiment, clipboard 114 includes a single data field for all elements of data 103. In other embodiments, clipboard 114 includes multiple data fields, with at least one field for each element of data 103 (e.g., a field for account number, a field for expiration date, a field for CVV number, a field for first name, and a field for last name, etc.).
[0013] As shown, server 120 includes a data store of account data 124 and memory 122. Account data 124 includes account-related data for multiple users and / or accounts. Account data 124 may include at least master keys 105, counters 104, customer IDs 107, associated contactless cards 101, and biographical information for each account. Memory 122 includes management application 123 and instances of one or more account data 103, counters 104, master keys 105, and diversified keys 106 from account data 124.
[0014] Generally, the system 100 is configured to implement key diversification to protect data. The server 120 (or other computing device) and the contactless card 101 may be provisioned with the same master key 105 (also referred to as a master symmetric key). More specifically, each contactless card 101 is programmed with a separate master key 105 that has a corresponding pair within the server 120. For example, when the contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of the contactless card 101. Similarly, the unique master key 105 may be stored in the customer record associated with the contactless card 101 within the account data 124 of the server 120 (or in another secure location). The master key may be kept secret from all parties other than the contactless card 101 and the server 120, thereby enhancing the security of the system 100. Other examples of key diversification techniques are described in U.S. Patent Application No. 16 / 205,119, filed November 29, 2018. The aforementioned patent applications are incorporated herein by reference in their entirety.
[0015] The master key 105 may be used in combination with a counter 104 to enhance security using key diversification. The counter 104 comprises a value that is synchronized between the contactless card 101 and the server 120. The counter value 104 may comprise a number that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or the contactless card 101 and the mobile device 110). To enable NFC data transfer between the contactless card 101 and the mobile device 110, the account application 113 may communicate with the contactless card 101 when the contactless card 101 is sufficiently close to a card reader 118 of the mobile device 110. The card reader 118 may be configured to read from and / or communicate with the contactless card 101 (e.g., via NFC, Bluetooth, RFID, etc.). Accordingly, an exemplary card reader 118 includes an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.
[0016] For example, a user may tap the contactless card 101 to the mobile device 110, thereby bringing the contactless card 101 close enough to the card reader 118 of the mobile device 110 to enable NFC data transfer between the contactless card 101 and the card reader 118 of the mobile device 110. After communication is established between the client device 110 and the contactless card 101, the contactless card 101 generates a message authentication code (MAC) cryptogram. In some examples, this may occur when the contactless card 101 is read by the account application 113. In particular, this may occur upon a read, such as an NFC read of a Near Field Exchange (NDEF) tag, which may be created according to the NFC data exchange format. For example, the account application 113 and / or a reader, such as the card reader 118, may send a message, such as an applet selection message, using the applet ID of the NDEF generation applet. Once the selection is confirmed, a sequence of a select file message followed by a read file message may be sent. For example, the sequence may include "select feature file," "read feature file," and "select NDEF file." At this point, a counter value 104 maintained by the contactless card 101 may be updated or incremented, followed by "read NDEF file." At this point, a message may be generated, which may include a header and a shared secret. A session key may then be generated. A MAC ciphertext may be created from the message, which may include the header and the shared secret. The MAC ciphertext may then be concatenated with one or more blocks of random data, and the MAC ciphertext and random number (RND) may be encrypted with the session key. The ciphertext and header may then be concatenated, encoded as ASCII hexadecimal, and returned in an NDEF message format (in response to the "read NDEF file" message). In some examples, the MAC ciphertext may be sent as an NDEF tag, and in other examples, the MAC ciphertext may be included with a uniform resource indicator (e.g., as a formatted string).Contactless card 101 may then transmit the MAC cryptogram to mobile device 110, which may then forward the MAC cryptogram to server 120 for verification, as described below. However, in some embodiments, mobile device 110 may verify the MAC cryptogram.
[0017] More generally, when preparing to send data (e.g., to the server 120 and / or the mobile device 110), the contactless card 101 may increment the counter value 104. The contactless card 101 may then provide the master key 105 and the counter value 104 as inputs to an encryption algorithm, which generates the diversified key 106 as output. The encryption algorithm may include an encryption algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc. Non-limiting examples of encryption algorithms may include a symmetric encryption algorithm such as 3DES or AES128, a symmetric HMAC algorithm such as HMAC-SHA-256, or a symmetric CMAC algorithm such as AES-CMAC. The contactless card 101 may then encrypt data (e.g., a customer identifier 107 and any other data) using the diversified key 106. Contactless card 101 may then transmit the encrypted data to account application 113 on mobile device 110 (e.g., via an NFC connection, a Bluetooth connection, etc.). Account application 113 on mobile device 110 may then transmit the encrypted data to server 120 over network 130. In at least one embodiment, contactless card 101 transmits counter value 104 along with the encrypted data. In such an embodiment, contactless card 101 may transmit encrypted counter value 104 or unencrypted counter value 104.
[0018] Upon receiving the data, the management application 123 of the server 120 may perform the same symmetric encryption using the counter value 104 as input to the encryption and the master key 105 as the key for the encryption. As mentioned, the counter value 104 may be specified in the data received from the mobile device 110 or a counter value 104 maintained by the server 120 to implement key diversification for the contactless card 101. The output of the encryption may be the same diversified key value 106 created by the contactless card 101. The management application 123 may then use the diversified key 106 to decrypt the encrypted data received over the network 130, thereby revealing the data (e.g., at least the customer identifier 107) transmitted by the contactless card 101. In doing so, the management application 123 can verify the data transmitted by the contactless card 101 via the mobile device 110, for example, by comparing the decrypted customer ID 107 with the customer ID in the account data 124 for the account.
[0019] While the counter 104 is used as an example, other data can be used to protect communications between the contactless card 101, the mobile device 110, and / or the server 120. For example, the counter 104 can be replaced with a random nonce generated each time a new diversified key 106 is needed, the full value of the counter value transmitted from the contactless card 101 and the server 120, a portion of the counter value transmitted from the contactless card 101 and the server 120, a counter maintained independently by but not transmitted between the contactless card 101 and the server 120, a one-time passcode exchanged between the contactless card 101 and the server 120, and a hash of encrypted data. In some examples, one or more portions of the diversified key 106 can be used by parties to create multiple diversified keys 106.
[0020] As shown, server 120 may include one or more hardware security modules (HSMs) 125. For example, one or more HSMs 125 may be configured to perform one or more cryptographic operations as disclosed herein. In some examples, one or more HSMs 125 may be configured as special-purpose security devices configured to perform one or more cryptographic operations. HSMs 125 may be configured such that keys are never exposed outside of HSMs 125 but are instead maintained within HSMs 125. For example, one or more HSMs 125 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 125 may be included within server 120 or in data communication with server 120.
[0021] As described above, data such as data 103 from contactless card 101 and / or server 120 may be securely copied to clipboard 114. In some embodiments, one or more data elements of data 103 are received directly from contactless card 101 and copied to the clipboard. For example, the account number, expiration date, and CVV of contactless card 101 may be received from data 103 in one or more data packages from contactless card 101. In some embodiments, contactless card 101 may encrypt requested elements of data 103 and, in response to receiving an indication of successful authentication of the encrypted data generated by contactless card 101 (e.g., by server 120), transmit a data package comprising encrypted data 103 that may be parsed by account application 113 and copied to clipboard 114. In other embodiments, server 120 may authenticate the encrypted data generated by contactless card 101 and transmit data 103 stored on server 120 in one or more data packages to account application 113, which may copy the data 103 received from server 120 to clipboard 114. In embodiments in which data 103 is transmitted to mobile device 110 in a single package (e.g., from card 101 and / or server 120), the single data package may include delimiters and / or metadata that enable account application 113 to parse and extract each element of data 103 (e.g., account number, expiration date, CVV, billing address, and / or shipping address).
[0022] For example, a user of the account application 113 may specify that data be copied to the clipboard 114. In response, the account application 113 may instruct the user to tap the contactless card 101 to the mobile device 110. By doing so, the account application 113 generates and sends an instruction to the contactless card 101 to generate encrypted data 108. In response, the contactless card 101 increments the counter value 104 and provides the master key 105 and the counter value 104 as inputs to an encryption algorithm, which generates the diversified key 106 as output. The contactless card 101 can then encrypt the customer identifier 107 using the diversified key 106 to generate the encrypted data 108. As mentioned, in some embodiments, the contactless card 101 may further encrypt the data 103 and include the encrypted data 103 as part of the encrypted data 108. Contactless card 101 may then transmit encrypted data 108 to account application 113 on mobile device 110 (e.g., via an NFC connection, a Bluetooth connection, etc.). Account application 113 on mobile device 110 may then transmit encrypted data 108 to server 120 over network 130. In at least one embodiment, contactless card 101 transmits counter value 104 along with encrypted data 108.
[0023] Upon receiving the encrypted data 108, the management application 123 of the server 120 may verify the encrypted data 108 using key diversification. As described above, the management application 123 of the server 120 may perform the same symmetric encryption using the counter value 104 as input to the encryption and the master key 105 as the key for the encryption to generate the diversified key 106. The management application 123 may then use the diversified key 106 to decrypt the encrypted data 108 received over the network 130, thereby revealing the data (e.g., at least the customer identifier 107) transmitted by the contactless card 101. In doing so, the management application 123 may verify the data transmitted by the contactless card 101 via the mobile device 110, for example, by comparing the decrypted customer ID 107 with the customer ID in the account data 124 for the account, where a match of the customer ID value verifies the encrypted data received from the contactless card 101.
[0024] If the management application 123 successfully verifies the encrypted data 108, the management application 123 may send a verification instruction to the account application 113. As noted, in some embodiments, the encrypted data 108 generated by the contactless card 101 may include the data 103. Thus, in response to receiving the verification instruction from the management application 123, the account application 113 decrypts and parses the encrypted data 108 received from the contactless card 101 and copies the decrypted data 103 to the clipboard 114. As noted, in some embodiments, the management application 123 may further transmit the requested data 103 from the server 120 to the account application 113. In such embodiments, the account application 113 may copy the data 103 received from the server 120 to the clipboard 114.
[0025] In at least one embodiment, a time threshold may be applied to a request to copy data to the clipboard 114. In such an embodiment, the account application 113 may notify the server 120 that a request to copy data to the clipboard 114 has been initiated. The server 120 may then start a timer. If the timer value exceeds the time threshold, the server 120 may refrain from verifying the encrypted data 108, refrain from sending an instruction to verify the encrypted data 108, and / or refrain from transmitting the data 103 from the server 120 to the account application 113. For example, if the server 120 receives the encrypted data 108 from the contactless card 101 via the mobile device 110 15 seconds after starting the timer and the time threshold is 30 seconds, the server 120 may verify the encrypted data 108 and transmit the data 103 from the server 120 to the mobile device 110. However, if the server 120 receives encrypted data 108 from the contactless card 101 via the mobile device 110 45 seconds after starting the timer, the server 120 may refrain from verifying the encrypted data 108 and send a failure status to the account application 113, which may refrain from copying the data to the clipboard 114.
[0026] 1B illustrates the results of the verification process performed by the management application 123. As shown, after verifying the encrypted data 108, the management application 123 of the server 120 transmits the data 103 from the server 120 to the mobile device 110. In at least one embodiment, the management application 123 encrypts the data 103 before transmitting it to the account application 113. As noted, the data 103 may include the account number, CVV, expiration date, and / or billing address of the contactless card 101. Further, as noted, the account number may comprise a single-use virtual account number. The account application 113 may then receive the data 103 and, if the data 103 is encrypted, decrypt the received data 103. The account application 113 may then programmatically write the data 103 to the clipboard 114 without requiring user input and without exposing the data 103. For example, the OS 112 may provide an application programming interface (API) for copying data to the clipboard 114. Thus, account application 113 may call an API that includes data 103 to be copied to clipboard 114. The result of the API call may copy the provided data 103 to clipboard 114. As another example, account application 113 may use one or more code statements supported by OS 112 to copy data 103 directly to the clipboard. Once copied to clipboard 114, a user may easily paste data 103 from clipboard 114 to other targets within OS 112 using commands and / or gestures available within OS 112.
[0027] In some embodiments, data 103 copies all relevant information (e.g., account number, expiration date, CVV, billing address, and / or shipping address) needed to make a purchase using an account associated with contactless card 101 to clipboard 114. However, in other embodiments, individual elements of data 103 may be incrementally copied to clipboard 114 using one or more taps of contactless card 101 and mobile device 110. For example, a first tap of the contactless card 101 and mobile device 110 may copy the account number of the data 103 to the clipboard 114, while a second tap of the contactless card 101 and mobile device 110 may copy the expiration date to the clipboard 114, a third tap of the contactless card 101 and mobile device 110 may copy the CVV to the clipboard 114, a fourth tap of the contactless card 101 may copy the shipping address to the clipboard 114, and a fifth tap of the contactless card 101 may copy the billing address to the clipboard 114. In one embodiment, a separate package of encrypted data 108 is generated by the contactless card 101 in response to each tap, and the server 120 verifies each package of encrypted data 108 before copying the corresponding data 103 to the clipboard 114. In some embodiments, a single package of encrypted data 108 is generated in response to the initial tap, and server 120 verifies the single package of encrypted data 108. In some such embodiments, account application 113 may receive data 103 from server 120 in a single package with delimiters and / or metadata identifying each data element (e.g., account number, expiration date, date, CVV, billing address, and / or shipping address) in data 103. Account application 113 may parse the data elements using the delimiters and / or metadata to extract each element of data from the single package of data 103 received from the server.The account application 113 may then copy the parsed data to the clipboard in response to each tap of the contactless card 101 and the mobile device 110. In some such embodiments, the account application 113 may parse the data 103 based on the current fields displayed on the device 110. For example, if the account number field is currently selected and / or displayed on the device 110, the account application 113 may parse the account number from the data 103 and copy the account number to the clipboard 114.
[0028] Additionally, in some embodiments, clipboard 114 may be Hypertext Markup Language (HTML) based. In such embodiments, data 103 may be wrapped with HTML. For example, an account number may be wrapped with HTML to indicate the presence of an account number. The expiration date, CVV, and address may likewise be wrapped with HTML. Thus, when pasting from clipboard 114, the HTML and data 103 are pasted into a target (e.g., a form in OS 112, account application 113, and / or other application 115). In at least one embodiment, clipboard 114 and / or OS 112 may parse the form in light of the data 103 and / or the generated HTML and associate the data 103 and / or the generated HTML with fields in the form. For example, this may allow the account number, expiration date, CVV, billing address, and shipping address to be pasted into the correct fields in a form even if the form uses different HTML tags for the fields.
[0029] Additionally, account application 113 and / or OS 112 may manage data 103 copied to clipboard 114. For example, data 103 may be deleted from clipboard 114 after the data 103 has been stored on clipboard 114 for a predetermined amount of time. As another example, data 103 may be deleted from clipboard 114 after the data 103 has been used to make a purchase, e.g., after a threshold amount of time has elapsed since the data 103 was used to make a purchase. Additionally and / or alternatively, clipboard 114 may be modified to remove data 103, e.g., by copying random data to clipboard 114.
[0030] 2 is a schematic diagram 200 illustrating an example embodiment of tapping to copy data to a clipboard via NFC. In general, schematic 200 illustrates an embodiment in which account application 113 reads data 103 directly from contactless card 101 (e.g., via card reader 118). As shown, account application 113 on mobile device 110 may specify that contactless card 101 be tapped to mobile device 110 in response to receiving user input specifying, for example, copying data from contactless card 101 to clipboard 114. When contactless card 101 is tapped to mobile device 110, account application 113 sends instructions to contactless card 101 via NFC card reader 118 to transmit data 103. Contactless card 101 may then transmit data 103 to account application 113 via NFC. Account application 113 may then copy the received data 103 to clipboard 114. As noted, data 103 may include one or more of an account number, an expiration date, and a CVV. Data 103 may then be pasted from clipboard 114 to any number and type of targets within OS 112.
[0031] 3A is a schematic diagram 300 illustrating an example embodiment of tapping to copy data to a clipboard via NFC. Generally, FIG. 3A reflects an embodiment in which a single tap is used to copy an account number of data 103. As shown, account application 113 on mobile device 110 may specify that contactless card 101 be tapped to mobile device 110 in response to receiving user input specifying, for example, copying data 103 to clipboard 114. When contactless card 101 is tapped to mobile device 110, account application 113 sends instructions to contactless card 101 to transmit data via NFC card reader 118. In one embodiment, contactless card 101 transmits the account number directly to mobile device 110 via NFC, and card reader 118 provides the received data to account application 113, which copies the account number to clipboard 114. In such an embodiment, an applet (e.g., applet 440 of FIG. 4B) on contactless card 101 may determine to transmit an account number and maintain counter values for incrementing the counter value in response to each tap. In such an embodiment, at least one counter value is associated with transmitting the account number, at least one other counter value is associated with transmitting the expiration date, and at least one other counter value is associated with transmitting the CVV.
[0032] In other embodiments, contactless card 101 may perform encryption using key diversification as described above to generate encrypted data (e.g., encrypted data 108) and send the encrypted data to account application 113. Account application 113 may then send the encrypted data to server 120, where management application 123 verifies the encrypted data using key diversification as described above. Management application 123 may then send the account number to account application 113, which copies the account number to clipboard 114.
[0033] Regardless of the technique used to copy the contactless card's 101 account number to the clipboard 114, the user may then paste the account number as desired. Additionally, if desired, the user may further tap the contactless card 101 to the mobile device 110 to copy the contactless card's 101 expiration date to the clipboard 114.
[0034] 3B is a schematic diagram 310 illustrating an exemplary embodiment in which a user taps contactless card 101 against mobile device 110 to copy the expiration date of contactless card 101 to clipboard 114. When contactless card 101 is tapped against mobile device 110, account application 113 sends instructions to contactless card 101 to transmit data via NFC card reader 118. In one embodiment, contactless card 101 transmits the expiration date directly to mobile device 110 via NFC, and account application 113 copies the expiration date to clipboard 114. In such an embodiment, an applet on contactless card 101 may increment a counter value in response to the tap and may refer to the counter value to determine whether to transmit the expiration date.
[0035] In other embodiments, contactless card 101 may perform encryption using key diversification as described above to generate encrypted data (e.g., encrypted data 108) and send the encrypted data to account application 113. Account application 113 may then send the encrypted data to server 120, and management application 123 may verify the encrypted data using key diversification as described above. Management application 123 may then send the expiration date to account application 113, which may copy the expiration date to clipboard 114 so that the user can paste the expiration date as needed. Additionally, if desired, the user may further tap contactless card 101 against mobile device 110 to copy the CVV of contactless card 101 to clipboard 114.
[0036] 3C is a schematic diagram 320 illustrating an exemplary embodiment in which a user taps contactless card 101 against mobile device 110 to copy the CVV of contactless card 101 to clipboard 114. When contactless card 101 is tapped against mobile device 110, account application 113 sends instructions to contactless card 101 to transmit data via NFC card reader 118. In one embodiment, contactless card 101 transmits the CVV directly to mobile device 110 via NFC. Card reader 118 may then provide the CVV to account application 113, which may copy the CVV to clipboard 114. In such an embodiment, the applet on contactless card 101 may increment a counter value in response to the tap and may reference the counter value to determine to transmit the CVV.
[0037] In other embodiments, contactless card 101 may perform encryption using key diversification as described above to generate encrypted data (e.g., encrypted data 108) and send the encrypted data to account application 113. Account application 113 may then send the encrypted data to server 120, where management application 123 verifies the encrypted data using key diversification as described above. Management application 123 may then send the CVV to account application 113, which copies the CVV to clipboard 114. The user may then paste the CVV as desired.
[0038] In some embodiments, a first tap of contactless card 101 on mobile device 110 (e.g., the tap shown in FIG. 3A ) causes contactless card 101 and / or server 120 to transfer the account number, expiration date, and CVV to account application 113 (e.g., in an NDEF file). In such embodiments, in response to the first tap, account application 113 copies the account number from the NDEF file to clipboard 114. In response to the second tap, account application 113 copies the expiration date from the NDEF file to clipboard 114 without having to receive additional data from contactless card 101 and / or server 120. In response to the third tap, account application 113 copies the CVV from the NDEF file to clipboard 114 without having to receive additional data from contactless card 101 and / or server 120.
[0039] FIG. 4A illustrates a contactless card 101, which may comprise a payment card such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 405, with the card's name displayed on the front or back of the card. In some examples, the contactless card 101 may comprise, but is not limited to, an identification card unrelated to a payment card. In some examples, the payment card may comprise a dual-interface contactless payment card. The contactless card 101 may comprise a substrate 410, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard; otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, it should be understood that contactless cards 101 according to the present disclosure may have different characteristics and the present disclosure does not require that contactless cards be implemented as payment cards.
[0040] The contactless card 101 may also include identification information 415 displayed on the front and / or back of the card, and a contact pad 420. The contact pad 420 may be configured to establish contact with a user device or other communication device, such as a smartphone, laptop, desktop, or tablet computer. The contactless card 101 may also include processing circuitry, an antenna, and other components not shown in FIG. 4A . These components may be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 may also include a magnetic strip or tape (not shown in FIG. 4A ) that may be located on the back of the card.
[0041] As shown in Figure 4B, the contact pad 420 of Figure 4A may include processing circuitry 425 for storing and processing information, including a microprocessor 430 and memory 102. It is understood that the processing circuitry 425 may include additional components including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-resistant hardware necessary to perform the functions described herein.
[0042] The memory 102 may be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 101 may include one or more of these memories. Read-only memory may be read-only or one-time programmable at the factory. One-time programming allows it to be written once and read many times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritten, but it may be read many times. Read / write memory may be programmed and reprogrammed many times after leaving the factory. Read / write memory may also be read many times after leaving the factory.
[0043] The memory 102 may be configured to store one or more applets 440, one or more elements of data 103, one or more counters 104, a master key 105, a diversified key 106, and a customer identifier 107. The one or more applets 440 may comprise one or more software applications configured to run on one or more contactless cards, such as a Java Card applet. However, it is understood that the applet 440 is not limited to a Java Card applet and may instead be any software application capable of operating on a contactless card or other device with limited memory. The one or more counters 104 may comprise a numeric counter sufficient to store an integer. The customer identifier 107 may comprise a unique alphanumeric identifier assigned to a user of the contactless card 101, which identifier may distinguish the contactless card user from other contactless card users. In some examples, the customer identifier 107 may identify both the customer and the account assigned to the customer, and further identify the contactless card associated with the customer's account.
[0044] Although the processor and memory elements of the foregoing exemplary embodiments are described with reference to contact pads, the present disclosure is not limited thereto, and it will be understood that these elements may be implemented external to, or completely separate from, the pads 420, or as additional elements in addition to the processor 430 and memory 102 elements located within the contact pads 420.
[0045] In some examples, the contactless card 101 may include one or more antennas 455. The one or more antennas 455 may be disposed within the contactless card 101 and around the processing circuit 425 of the contact pad 420. For example, the one or more antennas 455 may be integrated with the processing circuit 425, or the one or more antennas 455 may be used with an external booster coil. As another example, the one or more antennas 455 may be external to the contact pad 420 and the processing circuit 425.
[0046] In one embodiment, the coil of the contactless card 101 may function as the secondary of an air-core transformer. The terminal may communicate with the contactless card 101 by disconnecting power or amplitude modulation. The contactless card 101 may infer data transmitted from the terminal using gaps in the contactless card's power connection, which may be maintained functionally through one or more capacitors. The contactless card 101 may return communication by switching the load on the contactless card's coil or load modulation. Load modulation may be detected in the terminal's coil through interference. More generally, using the antenna 455, processing circuitry 425, and / or memory 102, the contactless card 101 provides a communication interface for communicating via NFC, Bluetooth, and / or Wi-Fi communications.
[0047] As described above, contactless card 101 may be built on a software platform operable on a memory-limited smart card or other device, such as a Java Card, and one or more applications or applets may be securely executed. The applets may be added to the contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in various mobile application-based use cases. The applets may be configured to respond to one or more requests, such as a near-field data exchange request, from a reader, such as a mobile NFC reader (e.g., of mobile device 110), and generate an NDEF message comprising the cryptographically secure OTP encoded as an NDEF text tag.
[0048] 5 illustrates an embodiment of a logic flow 500. The logic flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 500 may include some or all of the operations for securely copying data associated with the contactless card 101 using key diversification. In this context, the embodiments are not limited.
[0049] As shown, logic flow 500 begins at block 505, where contactless card 101 and server 120 are provisioned with the same master key 105. At block 510, a user taps contactless card 101 to a mobile device, causing contactless card 101 to generate and transmit encrypted data (e.g., encrypted data 108). The user may tap contactless card 101 in response to providing input to account application 113 specifying copying data 103 to a clipboard. Account application 113 may send an instruction to contactless card 101 via NFC card reader 118 specifying generating and transmitting encrypted data. In response to receiving the instruction to generate the encrypted data, contactless card 101 may increment counter value 104 in memory 102. At block 515, contactless card 101 generates diversified key 106 using counter value 104 and master key 105 in memory 102 and an encryption algorithm. In block 520, the contactless card 101 encrypts data (e.g., customer identifier 107) using the diversified key 106 and the encryption algorithm to generate encrypted data (e.g., encrypted data 108).
[0050] At block 525, contactless card 101 may send the encrypted data to account application 113 of mobile device 110 using NFC. In at least one embodiment, contactless card 101 further includes an indication of counter value 104 along with the encrypted data. At block 530, account application 113 of mobile device 110 may send the data received from contactless card 101 to management application 123 of server 120. At block 535, management application 123 of server 120 may generate diversified key 106 using master key 105 and counter value 104 as inputs to an encryption algorithm. In one embodiment, management application 123 uses counter value 104 provided by contactless card 101. In other embodiments, management application 123 increments counter value 104 in memory 122 to synchronize the state of counter value 104 in memory 122 with counter value 104 in memory 102 of contactless card 101.
[0051] At block 540, the management application 123 uses the diversified key 106 and the encryption algorithm to decrypt the encrypted data received from the contactless card 101 via the mobile device 110. In doing so, at least the customer identifier 107 may be obtained. By obtaining the customer identifier 107, the management application 123 may verify the data received from the contactless card 101 at block 545. For example, the management application 123 may compare the customer identifier 107 with the customer identifier of the associated account in the account data 124 and verify the data based on a match.
[0052] At block 550, the management application 123 may send data 103 associated with the contactless card 101 to the account application 113 of the mobile device 110. For example, the management application 123 may send the account number, expiration date, and CVV. In one embodiment, the management application 123 generates a virtual account number that is sent to the account application 113 of the mobile device 110. At block 555, the account application 113 of the mobile device 110 copies the data 103 received from the server 120 to the clipboard 114 of the OS 112. At block 560, the data 103 copied to the clipboard 114 may be pasted into a form. The form may be a component of the account application 113, another application 115, and / or the OS 112.
[0053] 6 illustrates an embodiment of a logic flow 600. The logic flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 600 may include some or all of the operations for pasting data from the clipboard 114 into an application form. In this context, the embodiments are not limited.
[0054] As shown, logic flow 600 begins at block 610, where account application 113 and / or OS 112 identify a form with form fields within an application. The application may be one or more of account application 113 and / or other applications 115. For example, account application 113 and / or OS 112 may parse the source code of the form to identify the form's fields. At block 620, account application 113 and / or OS 112 may map elements of data 103 copied to clipboard 114 (e.g., account number, expiration date, and / or CVV) to corresponding form fields. For example, account application 113 and / or OS 112 may use fuzzy matching and / or rules to map the account number, expiration date, and CVV to appropriate fields of the form.
[0055] At block 630, the account application 113 and / or OS 112 may optionally generate HTML for the data 103 stored on the clipboard 114, thereby appending the HTML to the data 103 in the clipboard 114. Doing so may allow the account application 113 and / or OS 112 to insert the data 103 into a form. At block 640, the account application 113 and / or OS 112 copies the data 103 into the mapped form fields. At block 650, the account application 113 and / or OS 112 may modify and / or delete the contents of the clipboard 114 following a purchase made with the data 103 on the contactless card 101. At block 660, the account application 113 and / or OS 112 may modify and / or delete the contents of the clipboard 114 following expiration of a time limit for storing the data 103 on the clipboard 114. Doing so enhances the security of the data 103, such as account numbers, identification information, account information, etc.
[0056] 7 illustrates an embodiment of a logic flow 700. The logic flow 700 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 700 may include some or all of the operations for copying data 103 to the clipboard 114 using multiple taps of the contactless card 101 to the mobile device 110. In this context, the embodiments are not limited.
[0057] As shown, logic flow 700 begins at block 710, where the user taps contactless card 101 against mobile device 110. Doing so causes account application 113 to send instructions to contactless card 101 to generate encrypted data using key diversification. Account application 113 may further increment a tap counter in response to the tap. At block 720, contactless card 101 increments counter value 104 and generates encrypted data 108 as described above. At block 730, account application 113 receives encrypted data 108 from contactless card 101 via NFC and transmits encrypted data 108 to server 120. Server 120 may then verify encrypted data 108 using key diversification as described above. At block 740, account application 113 receives data 103 from server 120 after server 120 verifies encrypted data 108. The data 103 may include one or more of an account number, an expiration date, and a CVV associated with the contactless card 101 .
[0058] At block 750, the account application 113 may copy the data 103 to the clipboard 114. As mentioned, the account application 113 may paste one element of data based on the current value of a tap counter. For example, a counter value associated with a first tap of the contactless card 101 to the mobile device 110 may be associated with copying an account number to the clipboard 114. Similarly, a counter value associated with a second tap may be associated with copying an expiration date to the clipboard 114, while a counter value associated with a third tap may be associated with copying a CVV to the clipboard 114. At block 760, the account application 113 determines whether more data 103 remains. For example, if the tap counter indicates that the account number has been copied to the clipboard 114, the account application 113 may determine that the expiration date and / or CVV remain copied to the clipboard 114. Thus, the logic flow 700 returns to block 710. Otherwise, the logic flow 700 ends.
[0059] In some examples, the contactless card 101 may be tapped against devices, such as one or more computer kiosks or terminals, to verify identity to receive a transaction item in response to a purchase, such as coffee. Using the contactless card 101 may establish a secure method of proving identity in a loyalty program. For example, secure proof of identity or receipt of a benefit to obtain a reward, coupon, offer, or the like is established in a manner other than simply scanning a bar card. For example, an encrypted transaction may occur between the contactless card 101 and a device configured to process one or more tap gestures. As described above, one or more applications may be configured to verify the user's identity and prompt the user to take an action or response, for example, via one or more tap gestures. In some examples, data, such as bonus points, loyalty points, reward points, or healthcare information, may be written back to the contactless card.
[0060] In some examples, the contactless card 101 may be tapped to a device such as the mobile device 110. As described above, the user's identity may be verified by one or more applications that grant the user desired benefits based on the verification of the identity.
[0061] In some embodiments, the example authentication communication protocol may mimic, with some modifications, the EMV-standard offline dynamic data authentication protocol commonly performed between transaction cards and point-of-sale devices. For example, because the example authentication protocol is not used to complete a payment transaction with the card issuer / payment processor itself, some data values are unnecessary, and authentication may be performed without requiring a real-time online connection to the card issuer / payment processor. Some point-of-sale (POS) systems submit transactions to a card issuer, including a transaction value. The issuer's approval or denial of the transaction may be based on whether the card issuer recognizes the transaction value. On the other hand, in certain embodiments of the present disclosure, transactions originating from a mobile device lack a transaction value associated with the POS system. Therefore, in some embodiments, a dummy transaction value (i.e., a value recognizable to the card issuer and sufficient for activation) may be passed as part of the example authentication communication protocol. POS-based transactions may reject transactions based on the number of transaction attempts (e.g., a transaction counter). A soft rejection may occur if a number of attempts exceeds a buffer value. A soft rejection requires further validation before the transaction is accepted. In some implementations, the transaction counter buffer value may be modified to avoid rejection of legitimate transactions.
[0062] In some examples, the contactless card 101 may selectively communicate information depending on the recipient device. When tapped, the contactless card 101 may recognize the device the tap is aimed at, and based on this recognition, the contactless card may provide the appropriate data to that device. This advantageously allows the contactless card to transmit only the information necessary to complete an immediate action or transaction, such as a payment or card authentication. Limiting data transmission and avoiding the transmission of unnecessary data may improve both efficiency and data security. Information recognition and selective communication may be applied to a variety of scenarios, including card activation, balance transfers, account access attempts, commercial transactions, and staged fraud prevention.
[0063] When a tap of contactless card 101 is directed at a device running Apple's iOS® operating system, e.g., an iPhone®, iPod®, or iPad®, the contactless card may recognize the iOS® operating system and transmit appropriate data to communicate with the device. For example, contactless card 101 may provide encrypted identification information necessary to authenticate the card using, for example, an NDEF tag via NFC. Similarly, when a tap of contactless card 101 is directed at a device running the Android® operating system, e.g., an Android® smartphone or tablet, the contactless card may recognize the Android® operating system and transmit appropriate data to communicate with the device (such as encrypted identification information necessary for authentication according to the methods described herein).
[0064] As another example, a contactless card tap may be directed to a point-of-sale device, including, but not limited to, a kiosk, checkout register, payment station, or other terminal. When the tap is performed, the contactless card 101 may recognize the point-of-sale device and transmit only the information necessary for the action or transaction. For example, upon recognizing the point-of-sale device used to complete a commercial transaction, the contactless card 101 may communicate the payment information necessary to complete the transaction under the EMV standard.
[0065] In some examples, a POS device participating in a transaction may request or specify additional information provided by the contactless card, such as, for example, device-specific information, location-specific information, transaction-specific information, etc. For example, when a POS device receives a data communication from a contactless card, the POS device may request additional information necessary to recognize the contactless card and complete the action or transaction.
[0066] In some examples, the POS device may be affiliated with an authorized merchant or other entity familiar with particular contactless cards or accustomed to performing particular contactless card transactions, although it will be understood that such an affiliation is not required to practice the described methods.
[0067] In some instances, such as shopping stores, grocery stores, convenience stores, etc., the contactless card 101 may be tapped to a mobile device without opening an application to indicate a desire or intent to use one or more reward points, loyalty points, coupons, offers, etc. to cover one or more purchases, thus providing the intent behind the purchase.
[0068] In some examples, one or more applications may be configured to determine that they were launched via one or more tap gestures on the contactless card 101, such as that the launch occurred at 3:51 PM and that a transaction was processed or made at 3:56 PM, in order to verify the user's identity.
[0069] In some examples, one or more applications may be configured to control one or more actions in response to one or more tap gestures. For example, the one or more actions may comprise collecting rewards, collecting points, determining the most important purchases, determining the least expensive purchases, and / or reconfiguring to other actions in real time.
[0070] In some examples, data regarding tapping actions may be collected as biometric / gesture authentication. For example, a cryptographically secure and resistant to interception unique identifier may be transmitted to one or more backend services. The unique identifier may be configured to retrieve secondary information regarding the individual. The secondary information may comprise personally identifiable information regarding the user. In some examples, the secondary information may be stored within a contactless card.
[0071] In some examples, the device may include an application for splitting bills or checking payments among multiple individuals. For example, each individual may possess a contactless card and be a customer of the same issuing financial institution, but this is not required. Each of these individuals may receive a push notification on the device via the application to split the purchase. Rather than tapping the card only once to indicate payment, other contactless cards may be used. In some examples, individuals with different financial institutions may possess contactless cards 101 that provide information to initiate one or more payment requests from individuals tapping their cards.
[0072] In some examples, this disclosure refers to tapping a contactless card, however, it should be understood that this disclosure is not limited to tapping and includes other gestures (e.g., waving or other movements of the card).
[0073] 8 illustrates an embodiment of an exemplary computing architecture 800 comprising a computing system 802 suitable for implementing the various embodiments described above. In various embodiments, computing architecture 800 may be configured or implemented as part of an electronic device. In some embodiments, computing architecture 800 may represent, for example, a system implementing one or more components of system 100. In some embodiments, computing system 802 may represent, for example, mobile device 110 and server 120 of system 100. The embodiments are not limited in this context. More generally, computing architecture 800 is configured to implement all logic, applications, systems, methods, apparatus, and functions described herein with reference to FIGS. 1-6.
[0074] As used in this application, the terms “system,” “component,” and “module” are intended to refer to any computer-related entity: hardware, a combination of hardware and software, software, or software in execution, an example of which is provided by exemplary computing architecture 800. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a server and the server may be a component. One or more components may reside within a process and / or thread of execution, and components may be localized on one computer and / or distributed among two or more computers. Furthermore, components may be communicatively coupled to each other and coordinate operations by various types of communication media. Coordination may involve unidirectional or bidirectional exchange of information. For example, components may communicate information in the form of signals communicated over the communication media. Information may be embodied as signals assigned to various signal lines. In such assignments, each message is a signal. However, further embodiments may alternatively use data messages. Such data messages may be transmitted over a variety of connections, examples of which include parallel interfaces, serial interfaces, and bus interfaces.
[0075] Computing system 802 includes various typical computing elements, such as one or more processors, multi-core processors, co-processors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to implementation by computing system 802.
[0076] 8, computing system 802 includes a processor 804, a system memory 806, and a system bus 808. Processor 804 may be any of a variety of commercially available computer processors, including, but not limited to, AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2) Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multi-processor architectures may also be used as processor 804.
[0077] The system bus 808 provides an interface from the system memory 806 to system components including, but not limited to, the processor 804. The system bus 808 may be any of several types of bus structures that may further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures. Interface adapters may connect to the system bus 808 through a slot architecture. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, (Extended) Industry Standard Architecture ((E)ISA), MicroChannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Expansion) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), etc.
[0078] The system memory 806 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random-access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drive (SSD)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in FIG. 8, the system memory 806 may include non-volatile memory 810 and / or volatile memory 812. The non-volatile memory 810 may store a basic input / output system (BIOS).
[0079] Computing system 802 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 814, a magnetic floppy disk drive (FDD) 816 that reads from or writes to a removable magnetic disk 818, and an optical disk drive 820 that reads from or writes to a removable optical disk 822 (e.g., a CD-ROM or DVD). HDD 814, FDD 816, and optical disk drive 820 may be connected to system bus 808 by an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. HDD interface 824 for external drive implementations may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies. Computing system 802 is generally configured to implement all of the logic, systems, methods, devices, and functions described herein with reference to FIGS. 1-7.
[0080] The drives and associated computer-readable media provide volatile and / or nonvolatile storage of data, data structures, computer-executable instructions, etc. For example, a number of program modules may be stored on the drives and memory units 810, 812, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836. In one embodiment, the one or more application programs 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as operating system 112, account application 113, clipboard 114, other applications 115, and management application 123.
[0081] A user may enter commands and information into the computing system 802 through one or more wired / wireless input devices, for example, a keyboard 838 and a pointing device such as a mouse 840. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, game pad, stylus pen, card reader, dongle, fingerprint reader, glove, graphics tablet, joystick, keyboard, retina reader, touch screen (e.g., capacitive, resistive, etc.), trackball, track pad, sensor, stylus, etc. These and other input devices are often connected to the processor 804 through an input device interface 842 coupled to the system bus 808, but may be connected by other interfaces, such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, etc.
[0082] A monitor 844 or other type of display device is also connected to the system bus 808 via an interface, such as a video adapter 846. The monitor 844 may be internal or external to the computing system 802. In addition to the monitor 844, computers typically include other peripheral output devices, such as speakers, printers, etc.
[0083] The computing system 802 may operate in a networked environment using logical connections via wired and / or wireless communications to one or more remote computers, such as a remote computer 848. The remote computer 848 may be a workstation, a server computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other common network node and typically includes many or all of the elements described relative to the computing system 802, although for simplicity, only a memory / storage device 850 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 852 and / or larger networks, e.g., a wide area network (WAN) 854. Such LAN and WAN networking environments are commonplace in offices and businesses, facilitating enterprise-wide computer networks such as intranets. All of these may connect to a global communications network, e.g., the Internet. In an embodiment, the network 130 of FIG. 1 is one or more of the LAN 852 and the WAN 854.
[0084] When used in a LAN networking environment, the computing system 802 is connected to the LAN 852 through a wired and / or wireless communication network interface or adapter 856. The adapter 856 may facilitate wired and / or wireless communication to the LAN 852, which may include a wireless access point disposed thereon for communicating with the wireless functionality of the adapter 856.
[0085] When used in a WAN networking environment, the computing system 802 may include a modem 858 or have other means for establishing communications over the WAN 854, such as connected to a communications server on the WAN 854 or via the Internet. The modem 858 may be internal or external, a wired and / or wireless device, and connects to the system bus 808 via the input device interface 842. In a networked environment, program modules depicted relative to the computing system 802, or portions thereof, may be stored in the remote memory / storage device 850. It will be appreciated that the network connections shown are exemplary and other means of establishing a communications link between computers may be used.
[0086] The computing system 802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operatively arranged for wireless communication (e.g., IEEE 802.16 wireless modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, Bluetooth® wireless technologies, and the like. Thus, communication can be in a predefined structure, similar to a traditional network, or simply ad hoc communication between at least two devices. Wi-Fi networks use radio technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and high-speed wireless connectivity. Wi-Fi networks can be used to connect computers to each other, to the Internet, or to wired networks (using IEEE 802.3-related media and functions).
[0087] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include a processor, a microprocessor, a circuit, a circuit element (e.g., a transistor, a resistor, a capacitor, an inductor, etc.), an integrated circuit, an application specific integrated circuit (ASIC), a programmable logic device (PLD), a digital signal processor (DSP), a field programmable gate array (FPGA), a logic gate, a register, a semiconductor device, a chip, a microchip, a chipset, etc. Examples of software may include a software component, a program, an application, a computer program, an application program, a system program, a machine program, an operating system software, a middleware, a firmware, a software module, a routine, a subroutine, a function, a method, a procedure, a software interface, an application program interface (API), an instruction set, a computational code, a computer code, a code segment, a computer code segment, a word, a value, a symbol, or any combination thereof. The decision whether an embodiment is implemented using hardware and / or software elements may vary according to any number of factors, such as required computational speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.
[0088] One or more aspects of at least one embodiment may be implemented by representative instructions stored on a machine-readable medium that represent various logic within a processor, which, when read by a machine, causes the machine to manufacture logic that performs the techniques described herein. Such representations, known as “IP cores,” are stored on tangible machine-readable media and provided to various customers or manufacturing facilities for loading into manufacturing machines that create the logic or processors. Some embodiments may be implemented using, for example, a machine-readable medium or article that may store instructions or sets of instructions that, when executed by the machine, cause the machine to perform methods and / or operations in accordance with the embodiments. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. A machine-readable medium or article may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewriteable (CD-RW), optical disk, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tape, cassette, etc. The instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.
[0089] The foregoing description of exemplary embodiments has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the disclosure to the precise form disclosed. Many modifications and variations are possible in light of this disclosure. It is intended that the scope of the disclosure be limited not by this detailed description, but by the appended claims. Future applications claiming priority to this application may claim the disclosed subject matter differently and may generally include any set of one or more limitations as variously disclosed or demonstrated herein.
Claims
1. a processor; a memory for storing instructions, The instructions, when executed by the processor, cause the processor to: receiving encrypted data from a contactless card associated with an account, the application executing on the processor; the application receiving, from a server, verification of the encrypted data based at least in part on the server decrypting the encrypted data; the application receiving an account number, expiration date, and card verification value (CVV) associated with the contactless card; the application incrementing a tap counter; the application copying one of the account number, the expiration date, and the CVV to a clipboard of an operating system (OS) running on the processor based on the value of the tap counter; Execute Device.
2. the account number, the expiration date, and the CVV are received from either the contactless card or the server; the memory stores instructions; The instructions, when executed by the processor, cause the processor to: sending the encrypted data to the server before receiving the verification; Execute 10. The apparatus of claim 1.
3. the memory stores instructions; The instructions, when executed by the processor, cause the processor to, before copying one of the account number, the expiration date, and the CVV to the clipboard: determining that the received account number, the received expiration date, and the received CVV are encrypted; decrypting the encrypted account number, the encrypted expiration date, and the encrypted CVV; Execute 10. The apparatus of claim 1.
4. the encrypted data received from the contactless card is based on one or more encryption algorithms and diversified keys, the diversified keys being based on a master key and a counter value; 10. The apparatus of claim 1.
5. the server decrypts the encrypted data based on the diversified key instance, the diversified key instance being based on the master key instance and the counter value instance maintained by the server, and the contactless card counter value is synchronized with the counter value instance maintained by the server.
5. The apparatus of claim 4.
6. the memory stores instructions; The instructions, when executed by the processor, cause the processor to: the OS pasting one of the account number, the expiration date, and the CVV from the clipboard into a first form field of a form; Execute 10. The apparatus of claim 1.
7. the memory stores instructions; The instructions, when executed by the processor, cause the processor to: the application detecting another tap of the contactless card against the device; the application incrementing the value of the tap counter based on the additional tap; the application copying one of the expiration date and the CVV to the clipboard based on the value of the tap counter; the OS pasting one of the expiration date and the CVV from the clipboard into a second form field of the form; Execute 7. The apparatus of claim 6.
8. the memory stores instructions; The instructions, when executed by the processor, cause the processor to: modifying the clipboard based on at least one of (i) completing a purchase and (ii) expiry of a time threshold, wherein modifying the clipboard includes one or more of (i) clearing all data stored on the clipboard and (ii) copying random data to the clipboard; Execute 10. The apparatus of claim 1.
9. A computer-readable storage medium storing instructions, comprising: The instructions, when executed by a processor, cause the processor to: receiving encrypted data from a contactless card associated with an account, the application executing on the processor; the application receiving, from a server, verification of the encrypted data based at least in part on the server decrypting the encrypted data; the application receiving an account number, expiration date, and card verification value (CVV) associated with the contactless card; the application incrementing a tap counter; the application copying one of the account number, the expiration date, and the CVV to a clipboard of an operating system (OS) running on the processor based on the value of the tap counter; Execute Medium.
10. the account number, the expiration date, and the CVV are received from either the contactless card or the server; the medium storing instructions; The instructions, when executed by the processor, cause the processor to: sending the encrypted data to the server before receiving the verification; Execute The medium according to claim 9.
11. the medium storing instructions; The instructions, when executed by the processor, cause the processor to, before copying one of the account number, the expiration date, and the CVV to the clipboard: determining that the received account number, the received expiration date, and the received CVV are encrypted; decrypting the encrypted account number, the encrypted expiration date, and the encrypted CVV; Execute The medium according to claim 9.
12. the encrypted data received from the contactless card is based on one or more encryption algorithms and diversified keys, the diversified keys being based on a master key and a counter value; The medium according to claim 9.
13. the server decrypts the encrypted data based on the diversified key instance, the diversified key instance being based on the master key instance and the counter value instance maintained by the server, and the contactless card counter value is synchronized with the counter value instance maintained by the server. The medium of claim 12.
14. the medium storing instructions; The instructions, when executed by the processor, cause the processor to: the OS pasting one of the account number, the expiration date, and the CVV from the clipboard into a first form field of a form; Execute The medium according to claim 9.
15. the medium storing instructions; The instructions, when executed by the processor, cause the processor to: the application detecting another tap of the contactless card against the device; the application incrementing the value of the tap counter based on the additional tap; the application copying one of the expiration date and the CVV to the clipboard based on the value of the tap counter; the OS pasting one of the expiration date and the CVV from the clipboard into a second form field of the form; Execute The medium of claim 14.
16. the medium storing instructions; The instructions, when executed by the processor, cause the processor to: modifying the clipboard based on at least one of (i) completing a purchase and (ii) expiry of a time threshold, wherein modifying the clipboard includes one or more of (i) clearing all data stored on the clipboard and (ii) copying random data to the clipboard; Execute The medium of claim 14.
17. receiving, by an application executing on a processor of the device, encrypted data from a contactless card associated with the account; the application receiving, from a server, verification of the encrypted data based at least in part on the server decrypting the encrypted data; the application receiving an account number, expiration date, and card verification value (CVV) associated with the contactless card; the application incrementing a tap counter; the application copying one of the account number, the expiration date, and the CVV to a clipboard of an operating system (OS) running on the processor based on the value of the tap counter; A method comprising:
18. the account number, the expiration date, and the CVV are received from either the contactless card or the server; The method comprises: sending the encrypted data to the server before receiving the verification; further comprising:
18. The method of claim 17.
19. The method comprises: the application determining that the received account number, the received expiration date, and the received CVV are encrypted; the application decrypting the encrypted account number, the encrypted expiration date, and the encrypted CVV; further comprising:
18. The method of claim 17.
20. the encrypted data received from the contactless card is based on one or more encryption algorithms and diversified keys, the diversified keys being based on a master key and a counter value; 18. The method of claim 17.
21. the server decrypts the encrypted data based on the diversified key instance, the diversified key instance being based on the master key instance and the counter value instance maintained by the server, and the contactless card counter value is synchronized with the counter value instance maintained by the server.
21. The method of claim 20.
22. The method comprises: the OS pasting one of the account number, the expiration date, and the CVV from the clipboard into a first form field of a form; further comprising:
18. The method of claim 17.
23. The method comprises: the application detecting another tap of the contactless card against the device; the application incrementing the value of the tap counter based on the additional tap; the application copying one of the expiration date and the CVV to the clipboard based on the value of the tap counter; the OS pasting one of the expiration date and the CVV from the clipboard into a second form field of the form; further comprising:
23. The method of claim 22.
24. The method comprises: modifying the clipboard based on at least one of (i) the completion of a purchase, and (ii) the expiration of a time threshold; further comprising:
18. The method of claim 17.
25. Modifying the clipboard includes one or more of: (i) clearing all data stored on the clipboard; and (ii) copying random data to the clipboard.
25. The method of claim 24.