Using NFC field from phone to power card to phone bluetooth communication
The contactless card harnesses NFC field power for bidirectional communication, addressing power and security limitations, enabling secure and efficient profile updates.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2025-11-28
- Publication Date
- 2026-03-04
AI Technical Summary
Existing contactless cards often require a battery for power and are limited to one-way communication, making them vulnerable to eavesdropping and requiring cumbersome activation processes when fraud is detected.
A contactless card that harvests power from radio waves, such as an NFC field, and establishes bidirectional communication via Bluetooth or Bluetooth low energy signals, incorporating a power harvesting unit, processor, and non-volatile memory to enable secure and efficient communication with a client device.
Enables secure bidirectional communication, reduces environmental impact by eliminating the need for a battery, and allows for seamless profile updates to prevent fraud, enhancing data security and transaction integrity.
Smart Images

Figure 2026035741000001_ABST
Abstract
Description
[Technical Field]
[0001] (CROSS-REFERENCE TO RELATED APPLICATIONS) This application claims priority to U.S. Patent Application No. 17 / 007,839, filed August 31, 2020, the disclosure of which is incorporated herein by reference in its entirety.
[0002] (Technical field) The present disclosure relates to a contactless card configured to harvest power from a radio signal and establish bidirectional communication with a device. [Background technology]
[0003] Communication using contactless cards is useful in many applications. The process of establishing contactless communication using a card may require the card to contain a small battery as a power source or may be limited to one-way communication. Furthermore, some forms of wireless or contactless communication are limited to one-way communication, allowing third-party eavesdroppers to intercept the communication.
[0004] Data security and transaction integrity are extremely important to businesses and consumers. This need continues to grow as e-commerce accounts for an ever-larger proportion of commercial activity. It is increasingly important that consumers can reliably use their financial cards (e.g., credit cards and other payment cards) for commercial activities. When fraud related to a card or profile is detected, the card is typically disabled and a replacement card is delivered to the consumer. Activating the replacement financial card requires the cardholder to call a phone number or visit a website and enter or provide their card information, a time-consuming process.
[0005] Therefore, there is a need to provide users with an appropriate solution that overcomes these drawbacks to provide data security, authentication, and verification for contactless cards. Additionally, there is a need for both improved methods of card activation and improved authentication for account access. What is needed is a contactless card configured to draw power from radio waves and establish bidirectional communication with a client device. Summary of the Invention
[0006] Accordingly, it is an object of this disclosure to describe a contactless card that can harvest power from radio waves, including from a near field communication (NFC) field.
[0007] It is a further object of the present invention to establish bidirectional communication between the disclosed contactless card and a client device. In some embodiments, the bidirectional communication includes communication via Bluetooth or Bluetooth low energy signals.
[0008] It is a further object of the present invention to utilize the two-way communication capabilities of the disclosed contactless cards to enhance functionality. In one exemplary aspect, if fraud is detected on a primary profile, the contactless card may be updated to a new, alternate, or secondary profile.
[0009] An embodiment of the present disclosure relates to a contactless card comprising a processor, a non-volatile memory, a communication circuit, and a power harvesting unit, the power harvesting unit is electrically connected to the communication circuit and configured to harvest power from a wireless signal; The communication circuitry is configured to establish bidirectional communication with a client device upon receiving power from the power harvesting unit.
[0010] An embodiment of the present disclosure relates to a contactless card communication method, the method comprising the steps of providing a contactless card comprising a processor, a non-volatile memory containing one or more applets, a communication interface, and a power harvesting unit; the power harvesting unit is configured to harvest power from a near field communication (NFC) field generated by a secondary device; The communication interface is configured to transmit and receive wireless signals. The contactless card detects an NFC field generated by a secondary device, the secondary device having a wireless antenna and an NFC field generator, and the secondary device communicates with a server, and draws power from the NFC field generated by the secondary device to establish bidirectional communication between the contactless card and the secondary device.
[0011] An embodiment of the present disclosure relates to a bidirectional data transmission system including a contactless card including a processor, a non-volatile memory including one or more applets, a communication interface, and a power harvesting unit, the power harvesting unit is configured to harvest power from an NFC field generated by a mobile device; the communication interface is configured to transmit and receive radio signals, and the contactless card is configured to detect the strength of an NFC field; Upon detecting an NFC field generated by the mobile device of at least a predetermined strength, the contactless card is configured to engage in bidirectional communication with the mobile device. The mobile device comprises a processor, an antenna, and an NFC field generator, and is configured to communicate with a server and transmit information received from the server to a card. [Brief explanation of the drawings]
[0012] [Figure 1]FIG. 1 is a diagram illustrating an exemplary embodiment of a contactless card communication system. [Figure 2] FIG. 2 is a diagram illustrating an exemplary embodiment of a contactless card communication system. [Figure 3] FIG. 3 is a diagram illustrating an exemplary embodiment of a contactless card. [Figure 4A] FIG. 4A illustrates an exemplary embodiment of a contactless card with a visual display and a rechargeable battery. [Figure 4B] FIG. 4B illustrates an exemplary embodiment of a contactless card having a power harvesting unit with an NFC antenna. [Figure 5] FIG. 5 illustrates an exemplary embodiment of a contactless card with a memory containing an applet, a primary profile, and a secondary profile. [Figure 6] FIG. 6 is a flowchart of a method for utilizing a contactless card according to an exemplary embodiment. [Figure 7] FIG. 7 is a flowchart of a method for utilizing a contactless card according to an exemplary embodiment. DETAILED DESCRIPTION OF THE INVENTION
[0013] The following description of the embodiments provides non-limiting representative examples that refer to numerals to particularly explain the features and teachings of different aspects of the present invention. It should be recognized from the description of the embodiments that the described embodiments can be implemented separately or in combination with other embodiments. Those skilled in the art who review the description of the embodiments should be able to learn and understand the different described aspects of the present invention. The description of the embodiments should facilitate understanding of the invention to the extent that other implementations, while not specifically covered, will be understood to be consistent with the application of the present invention within the knowledge of those skilled in the art who read the description of the embodiments.
[0014] By employing a contactless communication interface, contactless cards are provided with a method of interaction and communication between a user's device (such as a phone) and the card itself. Exemplary embodiments utilize Bluetooth signals for communication and the NFC field as a power source.
[0015] FIG. 1 illustrates an exemplary embodiment of a data transmission system utilizing a contactless card 105. System 100 may include contactless card 105, client device 110, network 115, and server 120. While FIG. 1 illustrates one example of components, embodiments of the disclosed system 100 may include any number of components. In some examples, contactless card 105 may be in wireless communication with client device 110, such as NFC or Bluetooth communication. Exemplary embodiments of contactless cards are described with reference to FIGS. 3-5.
[0016] In some embodiments, the disclosed system may include a client device 110, which may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, a computing device, such as a server, network appliance, personal computer (PC), workstation, mobile device, telephone, handheld PC, personal digital assistant (PDA), thin client, fat client, internet browser, contactless card, or other device. The client device may be a mobile device. For example, the mobile device may include an Apple® iPhone®, iPod®, iPad®, or other mobile device running Apple's iOS® operating system, a device running Microsoft®'s Windows® Mobile operating system, a device running Google®'s Android® operating system, and / or other smartphones or similar wearable mobile devices.
[0017] In various examples according to the present disclosure, the client device executes one or more applications, such as, for example, software applications that enable the functionality described herein and network communication with one or more components of the disclosed system, to send and / or receive data.
[0018] The disclosed system may include one or more networks 115. In some examples, the network may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks and may be configured to connect client devices to a server. For example, the network may include one or more of a fiber optic network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless LAN, a Global System for Mobile Communications (GSM), a Personal Communications Service (PCS), a personal area network, a Wireless Application Protocol (WAP), a Multimedia Messaging Service (MMS), an Enhanced Messaging Service (EMS), a Short Message Service (SMS), a time division multiplexing (TDM)-based system, a code division multiple access (CDMA)-based system, a D-AMP, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n, 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, and / or the like.
[0019] Additionally, a network may include telephone lines, fiber optics, IEEE Ethernet 902.3, a wide area network (WAN), a wireless personal area network, a local area network (LAN), or a global network such as the Internet. Furthermore, a network may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. A network may further include one network or any number of the above exemplary types of networks, operating as a standalone network or in cooperation with one another. A network may utilize one or more protocols of one or more network elements to which they are communicatively coupled. A network may translate one or more protocols of network devices to and from other protocols.
[0020] The disclosed system may include one or more servers 120. In some examples, the one or more servers 120 may include one or more processors coupled to one or more memories. The one or more servers 120 may be configured as a central system, server, or platform and may control and access various data at different times to perform multiple workflow actions. The one or more servers 120 may be configured to connect to one or more databases. The one or more servers 120 may be directly or indirectly connected to at least one client device.
[0021] 2 illustrates a contactless card communication system 200. The communication system 200 may include a contactless card 205, a client device 210, a network 215, a server 220, and a database 235. The contactless card 205, the client device 210, the network 215, and the server 220 may be the same as or similar to the corresponding elements shown in FIG. 1. Although the network 215 is illustrated in FIG. 2 as a single network, according to one or more examples, the network 215 may include multiple interconnected networks, such as, for example, the Internet, a service provider network, a cable television network, an enterprise network such as a credit card association network, and a home network.
[0022] In various examples according to this disclosure, client device 210 of system 200 may execute one or more applications 211 and include one or more processors 212 and one or more card readers 213. One or more applications 211, such as software applications, may be configured to enable network communication with, for example, one or more components of system 200, to transmit and / or receive data. An application may include software designed to perform a group of coordination functions, activities, and / or tasks. An application may include, for example, one or more programs, applets, routines, and / or subroutines.
[0023] The card reader 213 may be configured to read from and / or communicate with the contactless card 205. In conjunction with one or more applications 211, the card reader 213 may communicate with the contactless card 205. A card reader may include, for example, any data input device that reads data from a card, including, but not limited to, a barcode reader, a magnetic strip reader, a contact chip reader, and / or a contactless reader such as an NFC or Bluetooth communication interface. In some embodiments, the card reader may include a memory card reader, a magnetic card reader, and / or an access card reader.
[0024] The application 211 of the client device 210 may communicate with the contactless card 205 using short-range wireless communication (e.g., NFC). The application 211 may be configured to interface with a card reader 213 of the client device 210 configured to communicate with the contactless card 205. In some embodiments, the application 211 communicates with the contactless card 205 via an associated reader (e.g., card reader 213).
[0025] 2, contactless card 205 may communicate with client device 210, which may communicate with one or more servers 220 over one or more networks 215. In some embodiments, client device 210 may operate as a respective front-end to back-end pair with server 220. Client device 210 may send one or more requests to server 220. The requests may be generated by an application 211 executed by processor 212 of client device 210.
[0026] The one or more requests may be associated with retrieving data from the server 220 and / or the database 235. The server 220 may receive one or more requests from the client device 210. Based on the one or more requests from the client device 210, the server 220 may be configured to retrieve the requested data from the one or more databases 235. Based on receiving the requested data from the one or more databases, the server 220 may be configured to transmit the received data to the client device 210, the received data being responsive to the one or more requests.
[0027] In some examples, contactless card 205 may be in wireless communication with client device 210, such as Bluetooth communication. In some alternative embodiments, contactless card 205 may communicate with client device 210 through other technologies, including, but not limited to, satellite, Wi-Fi, wired communication, and / or a combination of wireless and wired connections. According to some embodiments, contactless card 205 may be configured to communicate with card reader 213 of client device 210 via Bluetooth or NFC signals when contactless card 205 is within range of card reader 213. In other examples, communication with contactless card 205 may be achieved through a physical interface, such as a Universal Serial Bus interface or a card swipe interface.
[0028] In some examples, the disclosed contactless cards are payment cards such as credit cards, debit cards, or gift cards. Information about the issuer, cardholder, and associated vendor may be displayed on the front or back of the card. In some examples, the payment card may include a dual-interface contactless payment card. In some embodiments, the contactless card is not related to a payment card and may include, but is not limited to, an identification card, a security card, a loyalty card, a smart card, and / or an access card. The foregoing examples are non-limiting, and it is understood that the present disclosure includes contactless cards of any function or type.
[0029] Contactless cards may include a substrate that may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Examples of substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, contactless cards may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard; otherwise, contactless cards may conform to the ISO / IEC 14443 standard. However, it should be understood that contactless cards according to the present disclosure may have different characteristics, and the present disclosure does not require that contactless cards be implemented as payment cards.
[0030] FIG. 3 illustrates a contactless card 300 according to an exemplary embodiment. Contactless card 300 may be the same as or similar to contactless card 205 illustrated in FIG. 2. Contactless card 300 may communicate wirelessly with one or more client devices or one or more servers and may include a processor 310, non-volatile memory 320, communication circuitry 330, and a power harvesting unit 340. While FIG. 3 illustrates one example of these components, it will be understood that contactless card 300 may include multiple instances of each component.
[0031] 3, contactless card 300 may include processor 310. Processor 310 may include processing circuitry and additional components, such as processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware, as needed to perform the functions described herein.
[0032] The non-volatile memory 320 may be read-only memory, write-once read-multiple memory, or read / write memory, such as ROM and EEPROM, and the contactless card may include one or more of these memories, or a combination of these memories. Read-only memory may be factory-programmable as read-only or one-time programmable. One-time programmable memory can be written once and read multiple times. Write-once / read-multiple memory can be programmed after the chip leaves the factory. Write-once memory, once programmed, cannot be rewritten but can be read multiple times. Read / write memory may be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times. The memory 320 may be configured to store one or more applets, one or more counters, and a customer identifier. The one or more applets may comprise one or more software applications configured to run on one or more contactless cards, such as Java Card applets. It is understood, however, that the applet is not limited to a Java Card® applet and may be any software application capable of running on a contactless card or other device with limited memory. The one or more counters may comprise a numeric counter sufficient to store an integer. The customer identifier may comprise a unique alphanumeric identifier assigned to a contactless card user, which identifier may distinguish the contactless card user from other contactless card users. In some examples, the customer identifier may identify a customer, an account, and / or a profile assigned to the customer, and may further identify the contactless card associated with the customer, account, and / or profile.
[0033] The communications circuitry 330 may establish two-way communications with other devices, such as client devices or servers. In some examples, the communications circuitry 330 may establish two-way communications using Bluetooth signals, such as Bluetooth low energy signals. In some examples, the system may utilize the capabilities of Bluetooth low energy systems to sleep and wake in an efficient manner. In some examples, communications may be established using radio signals within the 2.400-2.4835 GHz spectrum range. In some examples, the communications circuitry 330 may use 1 or 2 MHz channels within the spectrum range. In some examples, the communications circuitry 330 may use frequency hopping to mitigate interference issues. In some examples, signals are transmitted using a power consumption of 0.01 to 0.5 watts. It is understood that the communications circuitry 330 is not limited to using Bluetooth, and may use any known frequency, method, or technology, including NFC radio frequency identification and other wireless communications methods.
[0034] The power harvesting unit 340 may be configured to harvest power from radio waves, including, for example, RFID and / or NFC field radio waves. The contactless card may also be configured to draw power from the NFC field generated by the client device; thus, some embodiments of the contactless card do not require a battery or other on-board power source. These embodiments may achieve reduced card weight, reduced material costs, reduced manufacturing costs, and reduced environmental impact.
[0035] In some embodiments, the power harvesting unit may include an induction coil or antenna. The power harvesting unit may be electrically connected to the processor, memory, and communication circuitry. In some embodiments, the contactless card may be placed within the NFC field of the client device, and the power harvesting unit may draw power from the NFC field. The power harvesting unit may then provide power to the processor and / or communication circuitry to enable communication between the contactless card and the client or secondary device. In some embodiments, two power harvesting circuits may be utilized. The first power harvesting circuit may power a capacitor designed to charge and discharge quickly. The second power harvesting circuit may power a capacitor designed to charge more slowly and capable of holding a charge for a longer period of time compared to the capacitor of the first power harvesting circuit. In some embodiments, the contactless card is preferably placed in contact with the client device to harvest power more efficiently.
[0036] In some embodiments, the power harvesting unit includes an NFC antenna. The NFC antenna can provide both the communication and / or inductance necessary for power harvesting. In some embodiments, the power harvested by the antenna of the power harvesting unit is, for example, approximately 13.56 MHz AC. In some embodiments, other frequencies, such as 125 kHz, can be used. In some embodiments, the NFC antenna can include an LC filter and / or a matching circuit. The LC filter can function as a low-pass filter that removes high-frequency components from the signal output by the IC. It should be understood that the removed high-frequency components may not be desired for the communication signal. The disclosed matching circuit can be part of an antenna that is matched to an incoming magnetic field to create inductance. Energy derived from the induced current can be passed to a power management unit and / or a processor. In some embodiments, the induced voltage is approximately 0.1 volts. In many embodiments, the harvested power is sufficient to power a Bluetooth Low Energy (LE) signal. If it is determined that the harvested power is insufficient to power the desired communication signal, in some embodiments, a transformer with additional coil turns or increased permanent magnetic field may be used to increase the voltage. In some embodiments, the NFC antenna may directly power the NFC IC chip or may be used to capture power and power a Bluetooth LE single chip device.
[0037] In some embodiments, the processor may adjust, control, and / or limit the amount of power provided to the communications circuitry. By limiting the power supplied to the communications circuitry, the processor may limit the strength of any signals transmitted by the communications circuitry and the range of such signals. Because contactless cards may be placed in close proximity to a client device, e.g., in contact with the client device, the range of signals from the communications circuitry required to establish communication with the client device is short. In some embodiments, the signal range may be limited to less than about 5 centimeters, or less than about 10 centimeters, or less than about 20 centimeters, or less than about 40 centimeters. In some embodiments, the signal range may be adjusted to at least about 5 centimeters, or at least about 10 centimeters, or at least about 20 centimeters, or at least about 40 centimeters.
[0038] In an exemplary embodiment, a contactless card may be placed in contact with a client device, such as an iPhone or an Android phone. The contactless card and power harvesting unit may be configured to harvest approximately 1 volt of power from the NFC field generated by the iPhone. In some embodiments, the contactless card and power harvesting unit may be configured to harvest between approximately 0.1 volts and approximately 2.5 volts from the NFC field. It should be understood that the power harvested by the power harvesting unit may also be converted to a desired voltage using known techniques. This power may be used to transmit and receive Bluetooth LE signals between the contactless card and the client device. Establishing bidirectional communication between the contactless card and the client device can enhance the functionality of the contactless card as described herein. It should be understood that the NFC field associated with some client devices may be stronger on the front or back of the device. For example, when using a contactless card with some models of iPhone®, it may be more efficient to charge the contactless card by contacting it with the front glass of the iPhone®. When used with some models of Android phones, contactless cards can be charged more effectively by touching them to the back of the phone. In either case, the contactless card's power harvesting unit can draw power from the NFC field without a plug or other physical connection.
[0039] Figure 4A shows a contactless card 400 having a visual display and a rechargeable battery. As shown in Figure 4A, the contactless card 400 may include a processor 410, a memory 420, a communication circuit 430, and a power harvesting unit 440, which may be the same as or similar to the corresponding components shown in Figure 3. The contactless card may also include a magnetic strip or tape (not shown in Figure 4A) that may be located on the back of the card.
[0040] As further shown in FIG. 4A , contactless card 400 may include a visual display 450, a rechargeable battery 460, and / or a contact pad 470. Visual display 450 may be any form of display that presents visual information to a user, including, but not limited to, electronic paper, electronic ink, an LCD display, an LED indicator, and / or an LED display. The visual display may be in data communication with the processor and configured to provide information to the user in many applications. In some embodiments, the visual display may be configured to notify the user when the card enters or is removed from the NFC field of the secondary device. In some embodiments, the visual display may display the card number, expiration date, username, and / or other information associated with the financial card.
[0041] Rechargeable battery 460 may be a nickel-cadmium battery, a nickel-metal hydride battery, a lithium-ion battery, a lead-acid battery, or other type of battery. The rechargeable battery may be electrically connected to power intake unit 440 and processor 410. Rechargeable battery 460 may power processor 410, memory 420, communication circuitry 430, and other components when the card is not placed within an NFC field. In some embodiments, operation of rechargeable battery 460 enables improved functionality of these components and contactless card 400, as well as the use of other components, such as other forms of memory, such as volatile memory.
[0042] 4B shows an example embodiment of a contactless card 405 having a power harvesting unit 425 with an NFC antenna 435. The power harvesting unit 425 is operably connected to a processor 415, a capacitor 445, a battery 455, and / or a communication circuit 465. In some embodiments, the power harvesting unit 425 may be operably connected to the processor 415, and the processor 415 may be operably connected to the capacitor 445, the battery 455, and / or the communication circuit 465.
[0043] In some examples, the contactless card may not include a rechargeable battery. In these examples, the contactless card has limited or no access to a significant or continuous power source when not placed within an alternating electromagnetic field, such as an NFC field. In such embodiments, non-volatile memory allows data to be stored and maintained in a consistent state while the card is not powered.
[0044] 5 shows another exemplary embodiment of a contactless card 500. As shown in FIG. 5, contactless card 500 may include a processor 510, a memory 520, a power harvesting unit 560, a capacitor 570, contact pads 580, and a communication circuit 590. Processor 510, memory 520, power harvesting unit 560, and communication circuit 590 may be the same as or similar to the corresponding components shown in FIGS. 3 and 4.
[0045] In some examples, the memory 520 may be configured to store or include one or more applets 530, a primary profile 540, a secondary profile 550, one or more counters, and a customer identifier.
[0046] The one or more applets 530 may include one or more software applications configured to run on one or more contactless cards, such as Java Card applets. However, it is understood that the applet is not limited to a Java Card applet and may be any software application capable of running on a contactless card or other device with limited memory. The one or more counters may comprise a numeric counter sufficient to store an integer. The customer identifier may comprise a unique alphanumeric identifier assigned to a contactless card user, which may distinguish the contactless card user from other contactless card users. In some examples, the customer identifier may identify a customer, an account, and / or a profile assigned to the customer, and may further identify the contactless card associated with the customer, account, and / or profile.
[0047] In some examples, a card may include information associated with both a primary profile 540 and a secondary profile 550. The primary profile associated with a user may include information such as, for example, an account number, an associated username, an expiration date, and / or a card verification value. This information may be visually displayed on the card itself, embossed on the card, displayed on a visual display, encoded on a magnetic strip, and / or stored in the card's memory. It will be understood that the primary profile information may be information typically communicated when a user redeems the card. In some examples, the secondary profile may include alternative information similar to that included in the primary profile, including, for example, an account number, a username, an expiration date, and / or a card verification value. In some examples, if it is determined that the primary profile or an account associated with the primary profile is associated with fraudulent activity, the secondary profile may be activated. If fraudulent activity associated with the primary profile is detected, the primary profile is immediately deactivated, thereby preventing additional fraudulent transactions, and the secondary profile is activated, thereby allowing the user to continue using the card with little or no interruption.
[0048] In some embodiments, a card may initially contain only a primary profile, but may provide alternate or secondary profiles by securing communication account information to the card using the communication techniques described herein. In such embodiments, a single physical card may be updated with multiple profiles over the life of the card.
[0049] 5, in some embodiments, the contactless card includes a capacitor 570 that enables short-term energy storage, thereby allowing the contactless card to remain in a powered state for short periods of time while the NFC field of the client device is turned off. During communication between the client device and the contactless card, the NFC field may switch on and off. The capacitor allows the contactless card to buffer power harvested from the NFC field and maintain operation even as the NFC field of the client device fluctuates.
[0050] In some examples, the contactless card may also include identification information displayed on the front and / or back of the card and / or on a contact pad that may be configured to establish contact with another communication device, such as a user device, smartphone, laptop, desktop, or tablet computer.
[0051] In some examples, the client device may execute one or more applications and include one or more processors and one or more card readers. The one or more applications, such as, for example, software applications, may be configured to enable network communication with, for example, one or more components of the system, to transmit and / or receive data. The card reader may be configured to read from and / or communicate with a contactless card. In some examples, the application communicates with the contactless card via an associated reader (e.g., a card reader, etc.).
[0052] An application on any client device may communicate with the contactless card using short-range wireless communications (e.g., Bluetooth, Bluetooth LE, and / or NFC). The application may be configured to interface with a card reader on the client device configured to communicate with the contactless card. Note that those skilled in the art will understand that distances of less than 20 centimeters coincide with an NFC field. Bluetooth signals may be limited to a range of approximately 20 centimeters or less by adjusting the power output associated with the communications circuitry and / or the Bluetooth transmitter.
[0053] A contactless card may be built on a software platform capable of running on a smart card or other device with limited memory, such as a JavaCard, on which one or more applications or applets may be securely executed. An applet may be added to a contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in a variety of mobile application-based use cases. The applet may be configured to respond to one or more requests from a reader, such as a mobile NFC reader, and generate an NDEF message containing a cryptographically secure OTP encoded as an NDEF text tag.
[0054] In some embodiments, key diversification may be used for authentication and data exchange. For example, the contactless card and client device (e.g., a phone or server in data communication with the contactless card through one or more intermediary devices) may be provided with the same master symmetric key, although it is understood that any party or device holding the same secret symmetric key can perform these functions. In some examples, the symmetric key may comprise a shared secret symmetric key that is kept secret from all parties other than the contactless card and client device involved in the secure data exchange. It is further understood that providing both the contactless card and the client device with the same master symmetric key comprises, and further that, that portion of the data exchanged between the contactless card and the client device comprises at least a portion of the data that may be referred to as a counter. The counter may comprise a number that changes each time data is exchanged between the contactless card and the client device.
[0055] A counter may be updated when the contactless card prepares to process sensitive data using a symmetric cryptographic operation. Additionally, the contactless card may select an appropriate symmetric cryptographic algorithm, which may include at least one of a symmetric encryption algorithm, a hash-based message authentication code (HMAC) algorithm, and a cipher-based message authentication code (CMAC) algorithm. In some examples, the symmetric algorithm used to process the diversification value may include any symmetric cryptographic algorithm used as needed to generate a diversified symmetric key of a desired length. Non-limiting examples of symmetric algorithms may include symmetric encryption algorithms such as 3DES and AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMA. It is understood that if the output of the selected symmetric algorithm does not generate a sufficiently long key, techniques such as processing multiple iterations of the symmetric algorithm using different input data and the same master key may generate multiple outputs that can be combined as needed to generate a key of sufficient length.
[0056] The contactless card uses a selected encryption algorithm and processes the counter using a master symmetric key. For example, the contactless card may select a symmetric encryption algorithm and use a counter that is updated with every conversation between the contactless card and the client device.
[0057] The contactless card may then use the master symmetric key to encrypt the counter with a selected symmetric encryption algorithm to create a diversified symmetric key. The diversified symmetric key may be used to process the sensitive data before sending the result to the client device. For example, the contactless card may encrypt the sensitive data using a symmetric encryption algorithm that uses the diversified symmetric key, with the output including the protected encrypted data. The contactless card may then send the protected encrypted data, along with the counter, to the client device for processing. In some examples, cryptographic operations other than encryption may be performed, and multiple cryptographic operations may be performed using the diversified symmetric key before sending the protected data.
[0058] In some instances, the counter may not be encrypted, and in these instances, the counter may be transmitted unencrypted between the contactless card and the client device.
[0059] In some examples, sensitive data may be protected using one or more cryptographic algorithms and diversified keys. A diversified session key, which may be created by key diversification using a counter, may be used with one or more cryptographic algorithms to protect the sensitive data. For example, data may be processed with a message authentication code (MAC) using a first diversified session key, and the resulting output may be encrypted using a second diversified session key to generate protected data.
[0060] In some examples, the client device may perform the same symmetric encryption using the counter as input to the encryption and the master symmetric key as the key for the encryption. The output of the encryption may be the same diversified symmetric key value created by the sender. For example, the client device may use the counter to independently create its own copies of first and second diversified session keys. The client device may then decrypt the protected data using the second diversified session key to reveal the output of the MAC created by the contactless card. The client device may then process the data resulting from the MAC operation using the first diversified session key.
[0061] In some examples, a client device may use various keys in one or more cryptographic algorithms to verify protected data.
[0062] In some examples, the original data may be verified: if the output of the MAC operation (via the client device using the initial diversified session key) matches the MAC output revealed by decryption, the data may be considered valid.
[0063] The next time sensitive data needs to be sent from the contactless card to the client device, a different counter may be selected to generate a different distributed symmetric key. By processing the counter using the same symmetric encryption algorithm as the master symmetric key, both the contactless card and the client device may independently generate the same distributed symmetric key. This distributed symmetric key, rather than the master symmetric key, is used to protect the sensitive data.
[0064] In some examples, both the contactless card and the client device initially possess a shared master symmetric key. The shared master symmetric key cannot be used to encrypt the original secret data. The diversified symmetric key may be created independently by both the contactless card and the client device and is therefore never transmitted between them. Therefore, an attacker cannot intercept the diversified symmetric key, and the attacker does not see the data processed with the master symmetric key. Only a small counter, not the secret data, is processed with the master symmetric key. As a result, reduced side-channel data regarding the master symmetric key is revealed. Furthermore, the sender and receiver may agree, for example, by prior agreement or other means, on how often to create a new diversification value, and therefore a new diversified symmetric key. In one embodiment, a new diversification value, and therefore a new diversified symmetric key, may be created for each exchange between the contactless card and the client device.
[0065] For example, the key diversification value may comprise a counter. Other non-limiting examples of key diversification values include: A random nonce that is generated each time a new diversified key is needed. The random nonce is sent from the contactless card to the client device. - Complete values of counters sent from contactless cards and client devices. -Part of the counter sent by the contactless card and the client device; Counters maintained separately by the contactless card and the client device that may or may not be sent between the two; One-time passcodes exchanged between the contactless card and the client device. - Cryptographic hashes of sensitive data. In some examples, one or more portions of the key diversification value may be used by a party to create multiple diversified keys. For example, a counter may be used as the key diversification value.
[0066] In another example, a portion of the counter may be used as a key diversification value. When multiple master key values are shared between parties, multiple diversified key values may be obtained by the systems and processes described herein. New diversification values, and therefore new diversified symmetric keys, may be created as often as needed. In the most secure case, new distribution values may be created each time sensitive data is exchanged between the contactless card and the client device. In effect, this may create a one-time use key, such as a single session key.
[0067] In another example, the contactless card sender and client device receiver can agree on a new diversification value, such as limiting the number of uses of the master symmetric key. Thus, new diversified symmetric keys are generated only periodically. In one example, this may be after a predetermined number of uses, such as every 10 transmissions between the contactless card and client device. In another example, this may be after a set period of time, a set period of time after transmission, or periodically (e.g., daily at a specified time, weekly on a specified day at a specified time). In another example, this may be whenever the client device signals to the contactless card that it wants to change the key on its next communication. This can be controlled by policy and may change depending on, for example, the current risk level perceived by the client device receiver.
[0068] In some embodiments, card activation may occur without user authentication. For example, a contactless card may communicate with an application via a card reader on a client device via a Bluetooth signal. The communication (e.g., a gesture of bringing the card close to the card reader on the client device) allows the application to read data associated with the card and perform the activation. In some cases, the communication may activate or launch the application and initiate one or more actions. In some cases, if the application is not installed on the client device, bringing the card close to the card reader may initiate an application download (e.g., navigate to the application download page). Following installation, a gesture of the card may activate or launch the application and initiate card activation (e.g., via the application or other back-end communication). In some embodiments, after activation, the card may be used in various transactions, including commercial transactions.
[0069] According to some embodiments, the contactless card is a virtual payment card, in which the application may obtain information associated with the contactless card by accessing a digital wallet implemented on the client device or on a server in communication with the client device, the digital wallet comprising the virtual payment card.
[0070] The server may comprise a web server in communication with the database. The server may comprise an account server. In some embodiments, the server may be configured to verify one or more credentials from the contactless card and / or client device by comparing them with one or more credentials in the database. In some embodiments, the server may be configured to approve one or more requests, such as payments and transactions, from the contactless card and / or client device.
[0071] In some embodiments, the contactless card is a payment card associated with a primary profile. In such embodiments, the contactless card may include information associated with the primary profile, including, but not limited to, an account number, a username, an expiration date, and / or a card verification value. This information may be visually displayed on the card itself, embossed on the card, displayed on a visual display, encoded on a magnetic strip, and / or stored in the card's memory.
[0072] When fraudulent activity associated with a profile is detected, the profile is typically deactivated to prevent further fraudulent activity. At that point, the user cannot use the payment card until the financial institution prepares and physically delivers a new payment card to the user. This suspends the user's activity for a period of time and may reduce the card issuer's total transaction volume while the user is unable to use the payment card.
[0073] In some examples, such as the contactless card shown in FIG. 5, the disclosed contactless card may include information associated with a secondary profile in addition to a primary profile. The secondary profile may be dormant until activated. If fraudulent activity associated with the primary profile is detected, the primary profile may be deactivated to prevent further fraudulent activity. Utilizing the two-way communication capabilities of the contactless card described herein, in some embodiments, a user can activate a secondary profile and continue using the same contactless card as a payment card without interruption. In some embodiments, the contactless card deletes information associated with the primary profile when the secondary profile is activated. The user may continue to use the contactless card as a payment card while the issuing financial institution prepares and sends a new contactless card to the user. The new contactless card may include information associated with the secondary profile physically active on the card and / or may include information associated with a dormant alternative profile stored in the replacement card's memory so that the user can activate the alternative profile if further fraudulent activity is detected at a later date.
[0074] To activate a secondary profile, a user may place a contactless card near a client device, e.g., a mobile phone, to establish two-way communication between the card and the client device. The client device may communicate with a remote server associated with a financial institution. In some embodiments, an application may request an authentication token from the contactless card via the client device. Once the authentication token is provided by the contactless card, the application may provide instructions and / or information to the contactless card to activate the secondary profile.
[0075] When a user activates a secondary profile, information associated with the secondary profile may be displayed on the visual display. In some embodiments, the visual display utilizes electronic ink or electronic paper, which requires power to change the displayed information but does not require power to continue displaying the information once it has been updated. Such embodiments may function with or without a rechargeable battery, as the visual display may be updated while the card is placed within the NFC field.
[0076] In some embodiments, the visual display of the contactless card may be used to provide an additional element of security. Various programs, accounts, and / or login credentials may be communicated with the client device via the application. The user may be prompted to establish communication between the contactless card and the client device. The application may then request an authentication token from the contactless card via the client device to verify that the user has physical possession of the contactless card and the client device associated with the user. The application may transmit information to the contactless card via the client device, causing a security code to be displayed on the visual display. The user may be required to enter the security code as an additional form of authentication before the application allows the user access to certain information or functionality.
[0077] In some embodiments, the contactless card's memory may include a single-use or limited-use card number or authentication token. In such embodiments, an application may transfer the single-use or limited-use token to the contactless card while the card is in bidirectional communication with a client device. Such limited-use tokens may be used for promotional offers, security features, and / or loyalty programs. Additionally, an application may load applets onto the contactless card while the card is in communication with a client device. In some embodiments, the contactless card may transmit information to the client device and / or an application associated with the client device, and the client device may grant privileges based on the transmitted information. Using applets, a single contactless card can be used for multiple different applications. For example, a single contactless card can be used as, but is not limited to, an identification card, security card, access card, transportation card, payment card, loyalty program card, insurance card, membership card, debit card, credit card, or any combination thereof. In some embodiments, a single contactless card can function as an access card for multiple separate access points, each requiring a separate authentication token. In some embodiments, a single contactless card can function as both a debit card and a credit card, with separate profiles associated with each account. Additionally, as a user creates new accounts, closes accounts, and / or changes accounts, the contactless card can be updated by establishing two-way communication with the client device, thereby allowing a single card to be used over time and for multiple purposes without the need to replace the physical card.
[0078] In some examples, once two-way communication is established between the contactless card and the client device, the contactless card sends information to the client device, which then auto-fills forms.
[0079] 6 is a flowchart illustrating the operation of an exemplary embodiment of a contactless card. Method 600 may reference components that are the same as or similar to those shown in FIGS. 1, 2, 3, 4A, 4B, and / or 5.
[0080] Method 600 may begin in step 605 with providing a contactless card, such as a contactless card described herein. As described, contactless card embodiments may include a processor, non-volatile memory containing one or more applets, a communication interface, and a power collection unit. The power harvesting unit is configured to harvest power from a near-field communication (NFC) field generated by a secondary device, and the communication interface is configured to transmit and receive wireless signals. Step 610 comprises gesturing the contactless card within the NFC field generated by the secondary device. The secondary device includes a wireless antenna and an NFC field generator, and the secondary device communicates with a server. In step 615, the contactless card detects the NFC field generated by the secondary device. In some embodiments, the card may indicate when it detects the NFC field using a visual display and / or an indicator light. Step 620 comprises harvesting power by the contactless card from the NFC field generated by the secondary device. The contactless card is configured to use the power harvested from the NFC field to power its processor and other components, such as communication circuitry. Step 625 comprises establishing bidirectional communication between the contactless card and the secondary device.
[0081] In some embodiments of the disclosed method, the non-volatile memory includes a primary profile and a secondary profile. Once the card establishes bidirectional communication with the secondary device, step 630 comprises the card activating the secondary profile upon receiving a signal from the secondary device. Optional step 635 comprises card deletion information associated with the primary profile. Once the secondary profile is activated, optional step 640 comprises the contactless card presenting information associated with the secondary profile on a visual display upon activating the secondary profile.
[0082] FIG. 7 is a flowchart illustrating the operation of an exemplary embodiment of a contactless card. Method 700 may reference the same or similar components as those shown in FIGS. 1, 2, 3, 4A, 4B, 5, and / or 6. In step 710, the contactless card detects an NFC field generated by a secondary device. Upon detecting the NFC field, the card may indicate the presence and / or strength of the NFC field using a visual display and / or indicator light on the card. In step 720, the contactless card harvests power from the NFC field. The harvested power may be used to charge a rechargeable battery and / or capacitor and / or to power the processor, memory, communication circuitry, and / or other components of the contactless card. In step 730, the card establishes bidirectional communication with the secondary device. In some embodiments, the bidirectional communication is achieved via a low-energy wireless signal, such as a low-energy Bluetooth signal.
[0083] Following the establishment of two-way communication, the contactless card receives an applet from the secondary device in step 740. In some embodiments, the received applet grants access to a location or other privileges. In step 750, the contactless card transmits information to the secondary device. It is understood that steps 740 and / or 750 can be performed independently and / or in any order after the contactless card has established two-way communication with the secondary device and are independent of each other.
[0084] In step 760, the secondary device auto-populates the form based on the information sent from the contactless card to the secondary device. In step 770, the secondary device grants authorization based on the information sent from the contactless card to the secondary device. It should be understood that, similar to steps 740 and 750, steps 760 and / or 770 can be performed individually and / or in any order after the contactless card sends information to the secondary device and are not dependent on one another.
[0085] In some examples, the methods, processes, and procedures described herein may be performed by a processing device and / or computing device (e.g., a computer hardware device). Such a processing / computing configuration may be, for example, all or part of a computer / processor that may include, for example, but is not limited to, one or more microprocessors and that may use instructions stored in a computer-accessible medium (e.g., RAM, ROM, hard drive, or other storage device). For example, the computer-accessible medium may be part of the memory of a contactless card, client device, and / or other computer hardware configuration described herein.
[0086] In some examples, a computer-accessible medium (e.g., a storage device such as a hard disk, floppy disk, memory stick, CD-ROM, RAM, ROM, etc., or a combination thereof, as described herein above) may be provided (e.g., in communication with a processing device). The computer-accessible medium may contain executable instructions. Additionally or alternatively, a storage device separate from the computer-accessible medium may be provided, which may provide instructions to the processing device to configure the processing device to perform particular procedures, processes, and methods, as described herein above.
[0087] The present disclosure should not be limited with respect to the specific embodiments described herein, which are intended to be illustrative of various aspects. Clearly, many modifications and variations can be made without departing from its spirit and scope. Functionally equivalent methods and apparatuses within the scope of the present disclosure, in addition to those recited herein, may be apparent from the foregoing exemplary description. Such modifications and variations are intended to fall within the scope of the appended exemplary claims. The present disclosure should be limited only by the terms of the appended exemplary claims, along with the full scope of equivalents to which such exemplary claims are entitled. It should also be understood that the terminology used herein is for the purpose of describing particular embodiments only, and is not intended to be limiting.
Claims
1. A contactless card comprising a processor, a non-volatile memory, a communication circuit, and a power harvesting unit, the power harvesting unit is electrically connected to the communication circuit and configured to harvest power from a wireless signal; the communication circuitry is configured to establish bidirectional communication with a client device upon receiving power from the power harvesting unit; Contactless card.
2. the communication circuitry is configured to generate a low energy wireless signal; 2. The contactless card according to claim 1.
3. the processor is configured to limit the amount of power provided to the communications circuitry to limit the range of a signal generated by the communications circuitry to a predetermined range.
2. The contactless card according to claim 1.
4. further comprising a visual display; 2. The contactless card according to claim 1.
5. the processor is operably connected to the visual display and configured to cause the visual display to present a notification based on the strength of the wireless signal.
5. The contactless card according to claim 4.
6. the processor is operably connected to the visual display and configured to cause the visual display to present a notification based on the strength of the wireless signal.
5. The contactless card according to claim 4.
7. a visual display, wherein the processor, upon receiving the signal, causes the visual display to display information associated with the secondary profile.
7. The contactless card according to claim 6.
8. the memory includes an authentication token, and the processor is configured to transmit the authentication token to the client device upon receiving a signal requesting the authentication token from the client device.
2. The contactless card according to claim 1.
9. further comprising a rechargeable battery electrically connected to the power intake unit; 2. The contactless card according to claim 1.
10. 10. The contactless card of claim 9, wherein the communication circuitry is powered by both the power harvesting unit and the rechargeable battery. Contactless card.
11. 10. A contactless card as claimed in claim 9, wherein the communication circuitry is powered by the rechargeable battery when the card is out of range of a radio wave.
12. 1. A contactless card communication method, the method comprising: providing a contactless card including a processor, a non-volatile memory including one or more applets, a communication interface, and a power harvesting unit; the power harvesting unit is configured to harvest power from a near field communication (NFC) field generated by a secondary device; the communication interface is configured to transmit and receive wireless signals; the contactless card detects an NFC field generated by a secondary device; the secondary device includes a wireless antenna and an NFC field generator; the secondary device is in communication with a server; harvesting power by the contactless card from an NFC field generated by the secondary device; establishing bidirectional communication between the contactless card and the secondary device; Contactless card communication method.
13. the non-volatile memory includes a primary profile and a secondary profile, and the card deletes information associated with the primary profile and activates the secondary profile upon receiving a signal from the secondary device; The method of claim 12.
14. the contactless card further includes a visual display, and upon activation of the secondary profile, the contactless card presents information associated with the secondary profile on the visual display. The method of claim 13.
15. the two-way communication is achieved via low energy wireless data transmission; The method of claim 12.
16. further comprising the contactless card receiving the one or more applets from the secondary device. The method of claim 12.
17. At least one of the one or more applets enables access to a location.
17. The method of claim 16.
18. the contactless card transmitting information to the secondary device configured to automatically fill forms. The method of claim 12.
19. and the contactless card transmitting information to the secondary device configured to grant authorization based on the transmitted information. The method of claim 12.
20. 1. A data transmission system, comprising: a contactless card including a processor, a non-volatile memory including one or more applets, a communication interface, and a power harvesting unit; the power harvesting unit is configured to harvest power from a near field communication (NFC) field generated by a mobile device; the communication interface is configured to transmit and receive wireless signals; the contactless card is configured to detect an NFC field strength; Upon detecting that the NFC field generated by the mobile device is at least a predetermined strength, the contactless card is configured for two-way communication with a mobile device; the mobile device is in communication with a server and is configured to transmit information received from the server to the contactless card; Data transmission system.