Secure authentication based on identity data stored on a contactless card.

A contactless card system with encrypted identity data and key diversification provides secure authentication, addressing vulnerabilities in conventional methods by ensuring encrypted data verification for secure operation authorization.

JP2026062746APending Publication Date: 2026-04-10CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CAPITAL ONE SERVICES LLC
Filing Date
2025-12-18
Publication Date
2026-04-10

AI Technical Summary

Technical Problem

Conventional identity verification methods, such as one-time passwords, are vulnerable to interception and require different types of additional information for various systems, making them impractical and insecure for modern computing systems.

Method used

A system utilizing a contactless card that stores identity data, such as passport and driver's license information, to generate encrypted data for authentication, which is verified by an authentication server using key diversification and encryption algorithms, ensuring secure authorization of operations.

Benefits of technology

Enhances security by requiring verification of encrypted data from a contactless card before performing operations, improving the security of devices and associated data by preventing unauthorized access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026062746000001_ABST
    Figure 2026062746000001_ABST
Patent Text Reader

Abstract

We provide systems, methods, products, and computer-readable media for secure authentication based on identity data stored on contactless cards associated with an account. [Solution] The system comprises a processor and memory for storing instructions, and an application executed on the processor receives instructions specifying the execution of an operation, receives encrypted data from a card, encrypted data based on an encryption algorithm, a customer identifier and a private key, receives instructions that the authentication server has verified the encrypted data based on the card's private key, determines the type of data required to authorize the operation, receives data from the card comprising passport data or driver's license data, and determines, based on the authentication server verifying the encrypted data and data that satisfies at least one rule, that the data satisfies the rule for authorizing the operation and authorizes the execution of the operation.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Related Applications This application claims the priority of U.S. Patent Application No. 16 / 726,385, entitled "Secure Authentication Based on Identity Data Stored in a Contactless Card", filed on December 24, 2019. The entire content of the aforementioned application is incorporated herein by reference in its entirety.

[0002] Embodiments herein generally relate to computing platforms, and more specifically, to using contactless cards that store identity data for secure authentication.

Background Art

[0003] Identity verification is an important task for modern computing systems. In conventional approaches, a user may need to provide additional information such as a one-time password (OTP) when accessing a computing system or performing an electronic transaction. However, these solutions may have security vulnerabilities. For example, an OTP can be intercepted and used to gain unauthorized access. Additionally, different systems may require different types of additional information for identity verification, and conventional solutions are not practical for many users.

Summary of the Invention

[0004] Embodiments disclosed herein provide systems, methods, articles, and computer-readable media for secure authentication based on identity data stored on a contactless card. In one example, an application may receive instructions specifying that it perform an operation associated with an account. The application may receive encrypted data, encrypted data based on an encryption algorithm, a customer identifier, and a private key for the contactless card from a contactless card associated with the account. The application may receive instructions from an authentication server specifying that the authentication server has verified the encrypted data based on the private key for the contactless card. The application may determine the type of authentication data required to authorize the operation. Based on the determined type of authentication data, the application may receive a first data element from the contactless card, the first data element comprising passport data or driver's license data. The application may determine that the first data element satisfies at least one rule for authorizing the operation. Based on the received instructions specifying that the authentication server has verified the encrypted data and the determination that the first data element satisfies at least one rule for authorizing the operation, the application may authorize the execution of the operation. [Brief explanation of the drawing]

[0005] [Figure 1A] This document illustrates an embodiment of a system for secure authentication based on identity data stored on a contactless card. [Figure 1B] This document illustrates an embodiment of a system for secure authentication based on identity data stored on a contactless card. [Figure 2A] This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 2B] This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 2C]This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 3A] This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 3B] This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 3C] This embodiment demonstrates how a contactless card can be tapped to a computing device to provide secure authentication based on identity data stored on the contactless card. [Figure 4A] An example of a contactless card is shown. [Figure 4B] An example of a contactless card is shown. [Figure 5] This shows an embodiment of the first logical flow. [Figure 6] This shows a second embodiment of the logic flow. [Figure 7] This shows an embodiment of the third logical flow. [Figure 8] This shows an embodiment of a computing system. [Modes for carrying out the invention]

[0006] Embodiments disclosed herein provide a technology for secure authentication using identity data stored on a contactless card. Generally, a contactless card may store several different types of information about a user, such as driver's license information, passport information, social security number, and / or other personal history information. The user may then attempt to perform operations such as making a purchase, transferring funds through an application running on a mobile device, or requesting a credit increase through an application. The application may determine the type of authentication data required to authorize the requested operation. For example, a rule may specify that authentication based on passport data stored on a contactless card is required to transfer funds through the application. Thus, the application may determine that passport data is the type of authentication data.

[0007] Next, the user may tap the contactless card on their mobile device to initiate a secure authentication process. Tapping the contactless card may generate encrypted data which may then be sent to the application. The encrypted data may be generated based on an encryption algorithm, a customer identifier, and the encryption key of the contactless card. The application may then send the encrypted data to an authentication server for authentication. The server may then authenticate the encrypted data by decrypting it using a local copy of the encryption key of the contactless card and generating a customer identifier. The server may then send instructions to the application to authenticate the encrypted data.

[0008] Next, the application may process passport data. In some embodiments, passport data is transmitted to the application by a contactless card using an encrypted customer identifier. In other embodiments, passport data is transmitted to a mobile device by the contactless card following another tap on the contactless card. To process passport data, the application may perform any number of operations. For example, passport data stored on a contactless card may include a passport image depicting the user. In such an example, the application may instruct the user to capture an image of their face using a mobile device. Once captured, the application may compare the images to determine the similarity between them. If the similarity exceeds a similarity threshold level specified by a rule, the application may authenticate the user and / or verify the user's identity. The application may then authorize the execution of an operation based on the received instructions specifying that the authentication server has verified the encrypted data and that the image similarity exceeds the similarity threshold level. For example, a user may be permitted to access the application's interface to transfer funds from one account to another.

[0009] Advantageously, the embodiments disclosed herein improve the security of all devices and associated data. For example, security of applications and / or data is improved by requiring verification of encrypted data generated by a contactless card to access the application and / or data. Another example is the improvement of security of operations and associated assets by requiring verification of encrypted data before performing the operation (e.g., purchase, credit extension, etc.).

[0010] Referring generally to the notation and nomenclature used herein, one or more parts of the following detailed descriptions may be presented relating to program procedures performed on a computer or a network of computers. The descriptions and representations of these procedures are intended to convey to those skilled in the art in the most effective way to the substance of their work. Procedures, as described herein, are generally considered to be a set of self-consistent operations that lead to a desired result. These operations are operations that require the physical manipulation of physical quantities. Usually, but not always, these quantities take the form of electrical, magnetic, or optical signals that can be stored, transferred, combined, compared, and otherwise manipulated. For reasons of common use, it may be convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.

[0011] Furthermore, these operations are often referred to in terms such as addition and comparison, and these are generally associated with intelligent calculations performed by human operators. However, in any of the calculations described herein that form part of one or more embodiments, such ability of a human operator is neither necessary nor, in most cases, desirable. Rather, these calculations are machine calculations. Useful machines for performing the calculations of the various embodiments include digital computers selectively invoked or configured by computer programs stored therein, written in accordance with the teachings herein, and / or devices or digital computers specifically constructed for the required purpose. The various embodiments also relate to devices or systems for performing these operations. These devices may be specifically constructed for the required purpose. The structures required for these various machines will become apparent from the given description.

[0012] Herein, we refer to the drawings. Similar reference numbers are used throughout to refer to similar elements. In the following description, many specific details are given for illustrative purposes and to fully understand them. However, it may be apparent that novel embodiments can be carried out without these specific details. In other examples, well-known structures and devices are shown in block diagram form to facilitate their description. The intent is to cover all modifications, equivalents, and alternatives within the scope of the claims.

[0013] Figure 1A shows a schematic diagram of an exemplary system 100 consistent with the disclosed embodiment. As shown, system 100 includes one or more contactless cards 101, one or more mobile computing devices 110, and an authentication server 120. The contactless card 101 represents any type of payment card, such as a credit card, debit card, ATM card, or gift card. The contactless card 101 may have one or more communication interfaces 133, such as a radio frequency identification (RFID) chip, configured to communicate with the computing device 110 via NFC, EMV standards, or other short-range protocols in wireless communication. While NFC is used as an example of a communication protocol, this disclosure is equally applicable to other types of wireless communication, such as EMV standards, Bluetooth®, and / or Wi-Fi. The mobile device 110 represents any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop, or portable gaming device. The authentication server 120 represents any type of computing device, such as a server, workstation, computing cluster, cloud computing platform, or virtualization computing system.

[0014] As shown, the memory 102 of the contactless card includes an applet 103, a counter 104, a master key 105, a diversified key 106, a unique customer identifier (ID) 107, passport data 108, driver's license data 109, and other user data 131. The applet 103 is executable code configured to perform the operations described herein. The counter 104, master key 105, diversified key 106, and customer ID 107 are used to provide security to the system 100, as will be described in more detail below. The passport data 108 represents the electronic passport of the user associated with the contactless card 101. The passport data 108 may include any number and type of data. For example, the passport data 108 may include text data describing different attributes of the passport and / or the user (e.g., name, date of birth, passport number, passport issue date, passport expiration date, issuing country, etc.) as well as image data (e.g., one or more images of the passport itself, images of the user included in the passport, etc.). Customer ID 107, passport data 108, driver's license data 109, and other user data 131 may collectively be referred to as “identity data” in this specification.

[0015] The driver's license data 109 represents one or more driver's licenses held by a user associated with a contactless card. Similar to the passport data 108, the driver's license data 109 may include any number and type of data. For example, the driver's license data 109 may include barcodes (or other computer-readable markers) encoding different attributes of the driver's license and / or the user (e.g., name, date of birth, license number, license issuance date, expiration date, issuing state, etc.), text data representing the attributes (and / or barcodes), and / or image data (e.g., one or more images of the driver's license, images of the user included in the driver's license, etc.). The other user data 131 represents other data describing the user. For example, the other user data 131 may include a social security number, images, data representing the user's biometric identifier, other identification cards, loyalty program information, etc. In some embodiments, the passport data 108, the driver's license data 109, and the other user data 131 are encrypted.

[0016] As shown, the memory 111 of the mobile device 110 contains an instance of an operating system (OS) 112. Examples of operating systems 112 include Android® OS, iOS®, macOS®, Linux®, and Windows® operating systems. As shown, the OS 112 contains an account application 113. The account application 113 allows the user to perform various account-related operations, such as viewing account balances, purchasing items, and processing payments. The account application 113 may have further control over access permissions to different functions provided by the account application 113 and / or other applications 114. Generally, the user may access certain functions of the account application 113 by authenticating using authentication credentials. For example, authentication credentials may include a username (or login) and password, or biometric credentials (e.g., fingerprint, Face ID, etc.).

[0017] According to various embodiments, a user may attempt to request and / or perform an operation. The operation may include any type of operation, such as purchasing using the contactless card 101, accessing a specific function of the account application 113, performing various account-related operations using the account application 113, and / or accessing another application 114 (or any of its functions). The other application 114 may represent any type of computing application, such as a web browser, a messaging application, a word processing application, a social media application, etc. For example, a user may desire to transfer funds from their account to another account using the account application 113. The use of specific operations as reference examples herein is not limiting as the disclosure is equally applicable to any other type of operation.

[0018] To authorize a requested operation (for example, before transferring funds), system 100 must authenticate and / or verify the user's identity. To authenticate the user's identity, embodiments disclosed herein may utilize a contactless card 101. More specifically, when a user requests to perform an operation (or access to a restricted resource), the account application 113 may output a notification instructing the user to tap the contactless card 101 on the device 110. Generally, when the contactless card 101 comes within range of the communication interface 118 of the device 110, the applet 103 of the contactless card 101 may generate encrypted data, such as an encrypted customer ID 132, as part of the authentication process necessary to authorize the requested operation. To enable NFC data transfer between the contactless card 101 and the mobile device 110, the account application 113 may communicate with the contactless card 101 when it is close enough to the communication interface 118 of the mobile device 110. The communication interface 118 may be configured to read from and / or communicate with the communication interface 133 of the contactless card 101 (e.g., via NFC, Bluetooth®, RFID, etc.). Thus, the exemplary communication interface 118 includes an NFC communication module, a Bluetooth® communication module, and / or an RFID communication module.

[0019] As described above, system 100 is configured to perform key diversification to protect data, which may be referred to herein as key diversification technology. Generally, server 120 (or other computing device) and contactless card 101 may be provisioned with the same master key 105 (also referred to as a master symmetric key). More specifically, each contactless card 101 is programmed with a distinct master key 105 that has a corresponding pair within server 120. For example, when contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of contactless card 101. Similarly, the unique master key 105 may be stored in the customer's record associated with contactless card 101 within the account data 124 of server 120 (and / or stored in a different secure location such as a hardware security module (HSM) 125). The master key may be kept secret from all parties other than contactless card 101 and server 120, thereby enhancing the security of system 100. In some embodiments, the applet 103 of contactless card 101 may use an encryption algorithm with the master key 105 and data as inputs to encrypt and / or decrypt data (e.g., customer ID 107, passport data 108, driver's license data 109, and / or other user data 131). For example, encrypting customer ID 107 with master key 105 may generate an encrypted customer ID 132. Similarly, authentication server 120 may encrypt and / or decrypt data associated with contactless card 101 using the corresponding master key 105.

[0020] In other embodiments, the master key 105 of the contactless card 101 and the server 120 may be used in conjunction with a counter 104 to enhance security using key diversification. The counter 104 has a value that is synchronized between the contactless card 101 and the server 120. The counter value 104 may have a number that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or between the contactless card 101 and the mobile device 110). When preparing to send data (e.g., to the server 120 and / or the mobile device 110), the contactless card 101 may increment the counter value 104. The contactless card 101 may then provide the master key 105 and the counter value 104 as input to an encryption algorithm, which generates a diversified key 106 as output. The encryption algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cryptographic-based message authentication code (CMAC) algorithms, and the like. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. Examples of key diversification techniques are described in detail in U.S. Patent Application No. 16 / 205,119, filed November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety.

[0021] Continuing with the example of key diversification, the contactless card 101 could then use a diversified key 106 and data as input to an encryption algorithm to encrypt data (e.g., customer ID 107 and / or passport data 108, driver's license data 109, and / or other arbitrary data such as other user data 131). The diversified key 106 and data are used as input to the encryption algorithm. For example, encrypting customer ID 107 using diversified key 106 may result in an encrypted customer ID 132.

[0022] Next, regardless of the encryption technology used, the contactless card 101 may transmit encrypted data (e.g., encrypted customer ID 132) to the account application 113 on the mobile device 110 (e.g., via NFC connection, Bluetooth® connection, etc.). The account application 113 on the mobile device 110 may then transmit the encrypted customer ID 132 to the server 120 via the network 130. In at least one embodiment, the contactless card 101 transmits a counter value 104 along with the encrypted data. In such an embodiment, the contactless card 101 may transmit an encrypted counter value 104 or an unencrypted counter value 104.

[0023] Upon receipt, the authentication application 123 may authenticate the encrypted customer ID 132. For example, the authentication application 123 may attempt to decrypt the encrypted customer ID 132 using a copy of the master key 105 stored in the memory 122 of the authentication server 120. In another example, the authentication application 123 may provide the master key 105 and a counter value 104 as input to an encryption algorithm, which generates a diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of a contactless card 101 that can be used to decrypt the encrypted customer ID 132.

[0024] Regardless of the decryption technique used, the authentication application 123 can successfully decrypt the encrypted customer ID 132 and thereby verify the encrypted customer ID 132 (for example, by comparing the resulting customer ID 107 with the customer ID stored in the account data 124 and / or based on the indication that decryption using keys 105 and / or 106 was successful). Although it is shown that keys 105 and 106 are stored in memory 122, keys 105 and 106 may be stored elsewhere, such as in the secure element and / or HSM 125. In such embodiments, the secure element and / or HSM 125 can use keys 105 and / or 106 and the encryption function to decrypt the encrypted customer ID 132. Similarly, the secure element and / or HSM 125 may generate a diversified key 106 based on the master key 105 and counter value 104, as described above.

[0025] However, if the authentication application 123 is unable to decrypt the encrypted customer ID 132 and obtain the expected result (for example, the customer ID 107 of the account associated with the contactless card 101), the authentication application 123 will not verify the encrypted customer ID 132. In such an example, the authentication application 123 will send a failed verification instruction to the account application 113. Thus, the account application 113 may refuse to perform the requested operation in order to maintain the security of the account.

[0026] Figure 1B shows one embodiment in which an authentication application 123 decrypts an encrypted customer ID 132 and thereby verifies (or authenticates) the encrypted data. As shown, the authentication application 123 sends verification 134 to the mobile device 110, and verification 134 indicates that the authentication application 123 has successfully decrypted the encrypted customer ID 132. In response to receiving verification 134, the account application 113 may refer to rule 115 to determine if any additional authentication steps are required. Rule 115 may generally specify multiple different authentication rules and / or thresholds for different requested operations. The rules may be based on the type of requested operation. For example, for a fund transfer, rule 115 may require additional authentication based on additional data elements such as passport data 108 and / or driver's license data 109.

[0027] In an example where additional authentication is based on passport data 108, the account application 113 may output instructions specifying that the user tap the contactless card 101 on the mobile device 110. The account application 113 may then instruct the contactless card 101 to transmit the passport data 108. Accordingly, the contactless card 101 may transmit the passport data 108 to the account application 113. In some embodiments, the passport data 108 may be encrypted. In such embodiments, the account application 113 may send the encrypted passport data 108 to the server 120 for decryption (e.g., based on keys 105 and / or 106), and then transmit the decrypted passport data 108 to the account application 113. In other embodiments, the user may provide input to the account application 113 used to decrypt the encrypted passport data 108.

[0028] Furthermore, the account application 113 may instruct the user to capture an image of themselves using the camera 119. The account application 113 may then compare the captured images with the passport images in the passport data 108 to determine the similarity of the people depicted in each image. If the account application 113 determines that the similarity of the people depicted in the images exceeds the threshold similarity specified in rule 115, the account application 113 may approve the requested operation. The user may then proceed to complete the fund transfer using the account application 113.

[0029] As stated, in other examples, Rule 115 may require authentication based on driver's license data 109. The account application 113 may then output instructions specifying that the user tap a contactless card 101 on a mobile device 110. The account application 113 may then instruct the contactless card 101 to transmit the driver's license data 109. Accordingly, the contactless card 101 may transmit the driver's license data 109 to the account application 113. In some embodiments, the driver's license data 109 may be encrypted. Otherwise, the account application 113 may restrict the execution of the operation (for example, by restricting access to the graphical user interface (GUI) of the account application 113 used to transfer funds). In such embodiments, the account application 113 may send the encrypted driver's license data 109 to a server 120 for decryption, which may then send the decrypted driver's license data 109 to the account application 113.

[0030] Similar to passport-based authentication, the account application 113 may then instruct the user to capture an image of themselves using the camera 119. The account application 113 may then compare the captured images with the driver's license image in the driver's license data 109 to determine the similarity of the person depicted in each image. If the account application 113 determines that the similarity of the person depicted in the images exceeds the threshold similarity specified in Rule 115, the account application 113 may approve the requested operation. Otherwise, the account application 113 may restrict the execution of the operation (for example, by restricting access to the GUI of the account application 113 used to transfer funds). The user may then proceed to complete the fund transfer using the account application 113.

[0031] Image-based authentication is used as an example, but other data elements may be used to authorize the requested operation. For example, account application 113 may determine whether the name on the passport and / or driver's license matches the name of the account associated with the contactless card 101. As another example, account application 113 may determine whether the data encoded in the driver's license data 109 is readable. As yet another example, account application 113 may determine whether the date of birth on the passport and / or driver's license matches a known date of birth, for example, the date of birth specified in the account data 124 of the account associated with the contactless card 101. As yet another example, a social security number stored in other user data 131 may be compared to a known social security number of the user associated with the account. If a matching name and / or social security number is found, account application 113 may authorize the attempted operation. Otherwise, account application 113 may reject the attempted operation.

[0032] In at least one embodiment, an applet 103 of a contactless card 101 may use keys 105 and / or 106 to generate digital signatures (not shown) of passport data 108 and / or driver's license data 109. Each digital signature may sign the passport data 108 and / or driver's license data 109. The contactless card 101 then sends the digital signature containing the passport data 108 and / or driver's license data 109 to an account application 113, which may send the digital signature to an authentication server 120. The authentication application 123 may also verify the digital signature by decrypting it using a public key associated with the contactless card 101 and stored by the server 120. If the digital signature is verified, the authentication application 123 may send an instruction to the account application 113 that the verification was successful, thereby allowing it to perform an operation based on the verification of the digital signature. If the digital signature is not verified, the account application 113 may restrict the execution of an operation.

[0033] Although shown in Figures 1A and 1B as occurring in separate tap operations, in some embodiments, passport data 108 and / or driver's license data 109 may be transmitted along with an encrypted customer ID 132 in response to a single tap of the contactless card 101 on the mobile device 110.

[0034] Furthermore, in some embodiments, the user may obtain new and / or updated identification information, such as a passport or driver's license. In such embodiments, the account application 113 may receive new and / or updated versions of passport data 108, driver's license data 109, and / or other user data 131 from, for example, the authentication server 120. In such embodiments, the account application 113 may transmit the data received from the server 120 to the contactless card 101, and the applet 103 may store the received data in memory 102.

[0035] Figure 2A is a schematic diagram 200 showing an exemplary embodiment in which a contactless card 101 is tapped to provide secure authentication based on identity data stored on the contactless card 101. As shown, the account application 113 may receive a request to perform an operation. Continuing from the previous example, the request may be to transfer funds from one account to another. Accordingly, the account application 113 may output instructions to tap the contactless card 101 to the device 110. When the user taps the contactless card 101 to the mobile device 110, the applet 103 of the contactless card 101 generates an encrypted customer ID 132. The applet 103 may then transmit the encrypted customer ID 132 to the mobile device 110, for example, via NFC. Upon receipt, the account application 113 may transmit the encrypted customer ID 132 to the authentication application 123.

[0036] Next, the authentication application 123 may attempt to decrypt the encrypted customer ID 132 using the master key 105 and / or diversified key 106 associated with the contactless card 101. If the authentication application 123 is unable to decrypt the encrypted customer ID 132 and produce the expected result (e.g., customer ID 107 for the account), the authentication application 123 will not verify the encrypted customer ID 132 and will notify the account application 113 of the verification failure. The account application 113 may then reject the request to initiate a transfer of funds. If the authentication application 123 successfully decrypts the encrypted customer ID 132 and produces the expected result (e.g., customer ID 107 for the account), the authentication application 123 will verify the encrypted customer ID 132 and send instructions to the account application 113 to verify the encrypted customer ID 132.

[0037] In response to receiving verification from the authentication application 123, the account application 113 may refer to Rule 115 to determine the type of data required to authorize the requested fund transfer. For example, Rule 115 may specify that the fund transfer requires verification of an encrypted customer ID 132 and verification based on passport data 108. In at least one embodiment, the type of data specified by Rule 115 is based on the type of operation requested (e.g., fund transfer). Generally, Rule 115 may specify different levels of security for different types of transactions (e.g., requiring verification of passport data 108 for high-risk operations and not requiring verification of passport data 108 for low-risk operations).

[0038] The account application 113 may output other instructions for tapping the contactless card 101 on the device 110. The account application 113 may instruct the contactless card 101 to transmit passport data 108. The applet 103 may then transmit the passport data 108 to the mobile device 110, for example, via NFC.

[0039] Next, as shown in schematic diagram 210 of Figure 2B, the account application 113 may output instructions to the user to capture an image of their face. The user may then use the camera 119 to capture an image of their face. The account application 113 may then compare the captured images with the passport images in the passport data 108 to determine the similarity of the people depicted in each image. If the account application 113 determines that the similarity of the people depicted in the images exceeds the threshold similarity specified in rule 115, the account application 113 may approve the requested fund transfer operation. Otherwise, the account application 113 may reject the requested fund transfer operation and restrict access to the account application 113's GUI for performing the fund transfer. In the example shown in Figure 2B, the similarity exceeds the threshold, and the account application 113 allows the requested transfer to be performed. The user may then proceed to complete the fund transfer using the corresponding GUI of the account application 113.

[0040] Figure 3A is a schematic diagram 300 showing an exemplary embodiment in which a contactless card 101 is tapped to provide secure authentication based on identity data stored on the contactless card 101. As previously stated, the contactless card 101 may be used as a payment method for purchases, and the system 100 may use the identity data stored on the contactless card to provide secure authentication when processing the payment. While face-to-face transactions are shown as examples, the disclosure is equally applicable to online transactions.

[0041] As shown, the vendor device 301 display 302 outputs a display indicating that an age-restricted item is identified as part of the requested purchase and that the customer must provide their age to complete the requested purchase. The vendor device 301 represents any type of device capable of processing payments, such as a card reader device, smartphone, tablet computer, desktop computer, point-of-sale (POS) terminal, server, workstation, or laptop computer. The vendor device 301 includes a communication interface 303 configured to communicate via one or more of NFC, Bluetooth®, RFID, and / or Wi-Fi. Thus, the vendor device 301 can communicate with a contactless card 101 and / or a mobile device 110. In some embodiments, the communication interface 118 of the mobile device 110 operates in NFC card emulation mode to emulate the contactless card 101 and make payments for transactions via the vendor device 301.

[0042] Therefore, the account application 113 may receive instructions from the vendor device 301 indicating that customer age verification is required. The account application 113 may then output instructions specifying that the contactless card 101 be tapped to the device 110. When the customer taps the contactless card 101 to the mobile device 110, the applet 103 of the contactless card 101 generates an encrypted customer ID 132. The applet 103 may then transmit the encrypted customer ID 132 to the mobile device 110, for example, via NFC. In the embodiments shown in Figures 3A to 3C, the contactless card 101 also encrypts the driver's license data 109 and transmits it to the mobile device 110 along with the encrypted customer ID 132. Upon receipt, the account application 113 may transmit the encrypted customer ID 132 and the driver's license data to the authentication application 123. The authentication application 123 may then decrypt the encrypted customer ID 132 and thereby verify the encrypted customer ID 132. The authentication application 123 can further decrypt the driver's license data 109.

[0043] Figure 3B shows an embodiment in which the account application 113 receives a notification from the authentication application 123 that the encrypted customer ID 132 has been verified. The account application 113 may further receive decrypted driver's license data 109 from the authentication application 123. The account application 113 (and / or the authentication application 123) may read the driver's license data 109 to determine the customer's age (e.g., based on the difference between the current date and the date of birth specified in the driver's license data 109). If the determined age exceeds the minimum age for purchasing age-restricted items, the account application 113 sends a verification 310 instruction to the vendor device 301. In some embodiments, the account application 113 sends the relevant driver's license data 109 (e.g., date of birth) to the vendor device 301. By doing so, the vendor device 301 can independently verify that the customer is of the required age to purchase age-restricted items.

[0044] Figure 3C shows an embodiment in which an account application 113 instructs a user to tap a contactless card 101 on a mobile device 110 to complete payment for a purchase, based on verification of an encrypted customer ID 132 and the customer's age by an authentication application 123. The communication interface 118 of the mobile device 110, operating in NFC card emulation mode, can cause the applet 103 of the contactless card 101 to send payment information (e.g., card number, expiration date, and / or card verification value (CVV)) to the account application 113. In some embodiments, the payment information includes an encrypted customer ID 132, which is sent by the account application 113 to a server 120 for verification. Once verified, the account application 113 sends the received payment information as payment data 311 to a vendor device 301. The vendor device 301 can then use the received payment data 311 to process the transaction.

[0045] Figure 4A shows a contactless card 101 that may include a payment card such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 405, which is displayed on the front or back of the card 101. In some examples, the contactless card 101 may include an identification card that is not related to a payment card, but is not limited to this. In some examples, the payment card may be a dual-interface contactless payment card. The contactless card 101 may include a substrate 410 which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 may have physical properties that conform to the ID-1 format of the ISO / IEC 7810 standard, or otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, please understand that the contactless card 101 relating to this disclosure may have different characteristics, and this disclosure does not require that payment cards be contactless.

[0046] The contactless card 101 may also include identification information 415 displayed on the front and / or back of the card, and a contact pad 420. The contact pad 420 may be configured to establish contact with other communication devices such as a mobile device 40, a user device, a smartphone, a laptop, a desktop, or a tablet computer. The contactless card 101 may also include processing circuits, an antenna, and other components not shown in Figure 4A. These components may be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 may also include a magnetic strip or tape that may be located on the back of the card (not shown in Figure 4A).

[0047] As shown in Figure 4B, the contact pads 420 of the contactless card 101 may include a processing circuit 425 for storing and processing information, which includes a microprocessor 430 and memory 102. It is understood that the processing circuit 425 may include additional components, as necessary to perform the functions described herein, including a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware.

[0048] Memory 102 may be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and contactless card 101 may include one or more of these memories. Read-only memory may be read-only or programmable once at the factory. One-time programming allows it to be written once and read multiple times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritable but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can be read multiple times after leaving the factory.

[0049] Memory 102 may be configured to store one or more applets 103, a counter 104, a master key 105, a diversified key 106, one or more customer (or user) IDs 107, passport data 108, driver's license data 109, and other user data 131. One or more applets 103 may comprise one or more software applications configured to run on one or more contactless cards, such as a Java® card applet. However, it is understood that applet 103 is not limited to a Java card applet, but could instead be any software application capable of running on a contactless card or other device with limited memory. Customer ID 107 may comprise a unique alphanumeric identifier assigned to a user of a contactless card 101, the identifier being able to distinguish a user of a contactless card from a user of another contactless card. In some examples, customer ID 107 may identify both the customer and the account assigned to that customer, and further identify the contactless card associated with the customer's account. In some embodiments, applet 103 may generate an encrypted customer ID 132 by using customer ID 107 as input to an encryption algorithm using keys 105 and / or 106.

[0050] While the processor and memory elements of the exemplary embodiments described above have been described with reference to the contact pads, this disclosure is not limited thereto. It is understood that these elements may be implemented as additional elements in addition to the processor 430 and memory 102 elements located outside or completely separated from the pads 420, or within the contact pads 420.

[0051] In some examples, the contactless card 101 may have one or more antennas 455. One or more antennas 455 may be located inside the contactless card 101 and around the processing circuit 425 of the contact pads 420. For example, one or more antennas 455 may be integrated with the processing circuit 425, or one or more antennas 455 may be used with an external booster coil. In other examples, one or more antennas 455 may be located outside the contact pads 420 and the processing circuit 425.

[0052] In one embodiment, the coil of the contactless card 101 may function as the secondary side of an air-core transformer. A terminal may communicate with the contactless card 101 by disconnecting power or amplitude modulation. The contactless card 101 may infer data transmitted from the terminal by using a gap in the contactless card's power connection, which can be functionally maintained through one or more capacitors. The contactless card 101 may return communication by switching the load of the contactless card's coil or load modulation. Load modulation may be detected in the terminal's coil by interference. More generally, using an antenna 455, processing circuitry 425, and / or memory 102, the contactless card 101 provides a communication interface for communication via NFC, Bluetooth®, and / or Wi-Fi communication.

[0053] As described above, the contactless card 101 may be built on a software platform capable of running on other devices with limited memory, such as smart cards or Java cards, and one or more applications or applets may be securely executed. The applet may be added to the contactless card and provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a near-field data exchange request from a reader (e.g., the communication interface 118 of device 110), and generate an NDEF message with a cryptographically secure OTP encoded as an NDEF text tag.

[0054] The operation of the disclosed embodiments can be further described with reference to the following figures. Some figures may include logical flows. While such figures presented herein may include specific logical flows, it should be understood that logical flows merely provide examples of how general functions as described herein can be implemented. Furthermore, a given logical flow does not necessarily have to be executed in the order presented unless otherwise specified. Moreover, a given logical flow may be implemented by hardware elements, software elements executed by a processor, or any combination thereof. Embodiments are not limited in this context.

[0055] Figure 5 shows an embodiment of the logical flow 500. The logical flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 500 may include some or all of the operations for providing secure authentication using the contactless card 101 based on identity data stored on the contactless card 101. Embodiments are not limited in this context.

[0056] As shown, the logical flow 500 begins in block 505, where the account application 113 receives a request to perform an operation. As stated, the requested operation may be received based on user input from the account application 113, an external source (e.g., a vendor device 301), one of the other applications 114, or any other source. The request may relate to, for example, the use of the account application 113, the use of the other applications 114, an operation related to an account associated with the contactless card 101, and / or a transaction. More generally, the request may be received after the user has provided the authentication credentials necessary to access the account in the account application 113. In block 510, the user taps the contactless card 101 to the mobile device 110, causing the applet 103 on the contactless card 101 to generate an encrypted customer ID 132 and send it to the mobile device 110.

[0057] In block 515, the account application 113 may receive the encrypted customer ID 132 from the contactless card 101. The account application 113 may then send the encrypted customer ID 132 received from the contactless card 101 to the authentication server 120. The server 120 may attempt to decrypt the encrypted customer ID 132 as described herein. In block 520, the account application 113 receives an instruction from the server 120 that the encrypted customer ID 132 has been verified by decrypting it.

[0058] In block 525, the account application 113 determines the type of request. In block 530, the account application 113 determines the type of verification data specified in rule 115 that is required to authorize the type of operation. For example, passport data 108 may be specified as the verification data required by rule 115. In block 535, the user taps the contactless card 101 to the mobile device 110. By doing so, the applet 103 on the contactless card 101 is instructed to send the passport data 108 to the mobile device 110. In block 535, the account application 113 may receive additional data (e.g., passport data 108) from the contactless card 101.

[0059] In block 540, the account application 113 may receive additional data from the contactless card 101. In block 545, the account application 113 may process the data received in block 540. For example, the account application 113 may perform any age verification, account verification, and / or identity verification specified by Rule 115. As another example, the account application 113 and / or the authentication server 120 may verify the digital signature of the received data. In block 550, the account application 113 determines that the processed data satisfies Rule 115. In block 555, the account application 113 authorizes the execution of the requested operation based on the server 120's verification of the encrypted customer ID 132 and the determination in block 535 that the processed data received satisfies Rule 115. In block 560, the requested operation may be performed, for example, by the user and / or by the account application 113.

[0060] Figure 6 shows an embodiment of the logical flow 600. The logical flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 600 may include some or all of the operations for providing authentication based on passport data 108 stored on the contactless card 101. Embodiments are not limited in this context.

[0061] As shown, the logical flow 600 begins in block 610, where the account application 113 determines that Rule 115 requires passport-based verification based on the type of operation requested. In block 620, the account application 113 outputs an instruction to the user to capture an image depicting at least the user's face. In block 630, the account application 113 receives the image captured by the camera 119 of the mobile device 110. In block 640, the account application 113 compares the captured image received in block 630 with one or more images associated with the passport in the passport data 108 and determines that the similarity of the person depicted in each image exceeds the similarity threshold level specified by Rule 115. In block 650, based on the decision in block 640, the account application 113 determines that the user depicted in the captured image matches the person depicted in the passport image in the passport data 108. In block 660, the account application 113 permits the execution of the requested operation based at least in part on the determination that the user depicted in the captured image matches the person depicted in the passport image of the passport data 108, and / or the determination that the determined similarity exceeds the threshold specified by rule 115.

[0062] While logical flow 600 relates to an image in passport data 108, logical flow 600 is equally applicable to image-based verification using a user's image in driver's license data 109. Thus, account application 113 can determine whether the user in the captured image matches the user depicted in driver's license data 109. Embodiments are not limited to these contexts.

[0063] Figure 7 shows an embodiment of the logical flow 700. The logical flow 700 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 700 may include some or all of the operations for providing authentication based on driver's license data 109 stored on the contactless card 101. Embodiments are not limited in this context.

[0064] As shown, the logical flow 700 begins in block 710, where the account application 113 receives instructions from the vendor device 310 indicating that age verification is required to purchase age-restricted items. In block 720, the account application 113 receives driver's license data 109 from the contactless card 101 based on the card 101 being tapped onto the mobile device 110. In block 730, the account application 113 processes the driver's license data 109 to determine the age of the person in question, for example, based on the date of birth contained in the driver's license data.

[0065] In block 740, the account application 113 determines that the person's age, as determined in block 730, exceeds the minimum age threshold. In block 750, the account application 113 sends an instruction that the person's age exceeds the threshold. Additionally and / or alternatively, the account application 113 may send age and / or driver's license data 109 to the vendor device 301 for processing and verification. In block 760, the account application 113 receives payment data from the contactless card 101 in response to a tap of the contactless card 101 on the mobile device 110. In block 770, the account application 113 sends the payment data to the vendor device 301. In block 780, the vendor device 301 may process the transaction using the received payment data. In some embodiments, the vendor device 301 sends a payment confirmation to the account application 113.

[0066] Figure 8 shows an exemplary embodiment of computing architecture 800 comprising a computing system 802 suitable for implementing the various embodiments described above. In various embodiments, computing architecture 800 may be implemented with or as part of an electronic device. In some embodiments, computing architecture 800 may represent a system that implements, for example, one or more components of system 100. In some embodiments, computing system 802 may represent, for example, a contactless card 101, a mobile device 110, and an authentication server 120 of system 100. Embodiments are not limited in this context. More generally, computing architecture 800 is configured to implement all logic, applications, systems, methods, apparatus, and functions described herein with reference to Figures 1 to 7.

[0067] The terms “system,” “component,” and “module” as used in this application are intended to refer to any computer-related entity, whether hardware, a combination of hardware and software, software, or running software, examples of which are provided by the exemplary computing architecture 800. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, an execution thread, a program, and / or a computer. For example, both an application running on a server and the server itself may be components. One or more components may reside within a process and / or an execution thread, and components may be localized to one computer and / or distributed across two or more computers. Furthermore, components may be coupled together in a communicative manner by various types of communication media and their operation may be coordinated. Coordination may include the one-way or two-way exchange of information. For example, components may communicate information in the form of signals communicated over a communication medium. Information may be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, further embodiments may use data messages as an alternative. Such data messages can be transmitted over various connections. Examples of connections include parallel interfaces, serial interfaces, and bus interfaces.

[0068] The computing system 802 includes various common computing elements such as one or more processors, multicore processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, and power supplies. However, the embodiments are not limited to those implemented by the computing system 802.

[0069] As shown in Figure 8, the computing system 802 comprises a processor 804, system memory 806, and a system bus 808. The processor 804 may be any of a variety of commercially available computer processors, including but not limited to AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multiprocessor architectures may also be used as the processor 804.

[0070] The system bus 808 provides an interface to system components, including but not limited to system memory 806 and processor 804. The system bus 808 can be one of several types of bus structures that can further interconnect to the memory bus (with or without a memory controller), peripheral buses, and local buses using any of various commercially available bus architectures. Interface adapters can connect to the system bus 808 via slot architectures. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, Industry Standard Architecture ((E)ISA), Microchannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extensible) (PCI(X)), PCI Express, and Personal Computer Memory Card International Association (PCMCIA).

[0071] System memory 806 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon oxide nitride (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drives (SSDs)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in Figure 8, system memory 806 may include non-volatile memory 810 and / or volatile memory 812. The non-volatile memory 810 may store the basic input / output system (BIOS).

[0072] The computing system 802 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 814, a magnetic floppy disk drive (FDD) 816 for reading from or writing to a removable magnetic disk 818, and an optical disk drive 820 for reading from or writing to a removable optical disk 822 (e.g., a CD-ROM or DVD). The HDD 814, FDD 816, and optical disk drive 820 may be connected to the system bus 808 by an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. The HDD interface 824 for external drive implementation may include at least one or both of the Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 802 is generally configured to implement all the logic, systems, methods, apparatus, and functions described herein with reference to Figures 1 to 7.

[0073] The drives and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-readable instructions, computer-executable instructions, etc. For example, a number of program modules may be stored in drives and memory units 810, 812, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836. In one embodiment, one or more application programs 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as an applet 103, a counter 104, a master key 105, a diversified key 106, a customer ID 107, passport data 108, driver's license data 109, other user data 131, an encrypted customer ID 132, an operating system 112, an account application 113, other applications 114, an authentication application 123, and / or account data 124.

[0074] The user may input commands and information to the computing system 802 via one or more wired / wireless input devices, such as a keyboard 838 and a pointing device such as a mouse 840. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, gamepad, stylus pen, card reader, dongle, fingerprint reader, grab, graphics tablet, joystick, keyboard, retina reader, touchscreen (e.g., capacitive, resistive, etc.), trackball, trackpad, sensor, stylus, etc. These and other input devices are often connected to the processor 804 via an input device interface 842 coupled to the system bus 808, but may also be connected via other interfaces such as a parallel port, IEEE 1394 serial port, game port, USB port, IR interface, etc.

[0075] Monitor 844 or other types of display devices are also connected to the system bus 808 via interfaces such as the video adapter 846. Monitor 844 can be located inside or outside the computing system 802. In addition to Monitor 844, the computer typically includes other peripheral output devices such as speakers and printers.

[0076] Computing system 802 may operate in a network environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computer 848. Remote computer 848 could be a workstation, server computer, router, personal computer, portable computer, microprocessor-based entertainment device, peer device, or other common network node, typically containing many or all of the elements described in relation to computing system 802, but for brevity, only memory / storage device 850 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 852 and / or a larger network, such as a wide area network (WAN) 854. Such LAN and WAN network environments are common in offices and businesses and facilitate enterprise-scale computer networks such as intranets. All of these may connect to global communication networks, such as the Internet. In embodiments, network 130 in Figure 1 is one or more of LAN 852 and WAN 854.

[0077] When used in a LAN networking environment, computing system 802 is connected to LAN 852 via a wired and / or wireless network interface or adapter 856. Adapter 856 may facilitate wired and / or wireless communication to LAN 852, which may include a wireless access point placed on it to communicate with the wireless capabilities of adapter 856.

[0078] When used in a WAN networking environment, computing system 802 may include a modem 858, or be connected to a communication server on WAN 854, or have other means of establishing communication on WAN 854, such as via the Internet. The modem 858 may be internal or external, wired and / or wireless, and connect to system bus 808 via input device interface 842. In a network environment, the program modules, or parts thereof, shown with respect to computing system 802 may be stored in remote memory / storage device 850. The shown network connections are illustrative, and it will be understood that other means of establishing communication links between computers may be used.

[0079] Computing system 802 is capable of operating to communicate with wired and wireless devices or entities using the IEEE 802 standards family, such as wireless devices positioned to operate wirelessly (e.g., IEEE 802.16 wireless modulation technology). This includes at least Wi-Fi (or Wireless Fidelity), WiMAX, and Bluetooth® wireless technologies. Thus, communication can be a predefined structure, similar to conventional networks, or simply ad-hoc communication between at least two devices. Wi-Fi networks provide secure, reliable, and high-speed wireless connectivity using wireless technologies known as IEEE 802.11x (a, b, g, n, etc.). Wi-Fi networks can be used to connect computers to each other, to connect to the Internet, or to wired networks (using IEEE 802.3 related media and functions).

[0080] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. The decision of whether an embodiment is implemented using hardware and / or software elements may vary depending on any number of factors, such as desired computing speed, power level, heat resistance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.

[0081] One or more aspects of at least one embodiment can be implemented by representative instructions stored in a machine-readable medium representing various logics within a processor, which, when read by a machine, produce logic that performs the techniques described herein. Such representations, known as "IP cores," are stored in tangible machine-readable medium and provided to various customers or manufacturing facilities for loading into manufacturing machines that create logic or processors. Some embodiments can be implemented using, for example, a machine-readable medium or article that can store instructions or a set of instructions that, when executed by a machine, can cause a machine to perform methods and / or operations according to the embodiment. Such machines can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disks, floppy disks, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewritable (CD-RW), optical disks, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tapes, cassettes, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, cryptographic code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.

[0082] The foregoing description of exemplary embodiments is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit this disclosure to the exact form disclosed. Many modifications and changes are possible in light of this disclosure. The scope of this disclosure is intended to be limited by the appended claims rather than by this detailed description. Future applications claiming priority to this application may assert the disclosed subject matter in different ways and may generally include any set of one or more limitations, as variously disclosed or demonstrated herein.

Claims

1. It is a system, Processor and The system includes a memory for storing instructions, and when an instruction is executed by the processor, the processor receives the instruction. The application running on the aforementioned processor receives instructions specifying that it should perform an operation associated with the account, The application receives encrypted data from the contactless card associated with the account, wherein the encrypted data is based on an encryption algorithm, a customer identifier, and the private key of the contactless card. The application receives an instruction from the authentication server indicating that the authentication server has verified the encrypted data based on the secret key of the contactless card, The application determines the type of authentication data necessary to authorize the operation, The application receives a first data element from the contactless card based on the determined type of authentication data, wherein the first data element comprises passport data or driver's license data. The application determines that the first data element satisfies at least one rule for approving the operation, Approving the application to perform the operation based on the received instruction indicating that the authentication server has verified the encrypted data, and the determination that the first data element satisfies the at least one rule for approving the operation, A system that executes an action.

2. The memory stores instructions, and when an instruction is executed by the processor, the processor receives the instructions. Determining that the digital signature of the first data element received from the contactless card is a valid digital signature based on the public key associated with the entity providing the digital signature, Determining the type of authentication data based on the type of the operation, The system according to claim 1, which causes the execution of the following:

3. The first data element comprises a passport image, the memory stores instructions, and when an instruction is executed by the processor, the processor receives Receiving the first image depicting a person, Comparing the first image with the passport image, Based on the comparison, it is determined that the similarity between the person depicted in the passport image and the person depicted in the first image exceeds a similarity threshold, wherein the determination that the first data element satisfies at least one rule is based on the similarity between the person depicted in the passport image and the person depicted in the first image exceeding the similarity threshold, The system according to claim 2, which causes the execution of the following:

4. The memory stores instructions, and when an instruction is executed by the processor, the processor receives the instructions. The application outputs an instruction specifying that it should capture the first image in order to approve the operation, The system captures the first image using its image capture device, The system according to claim 3, which causes to perform the following:

5. The memory stores instructions, and when an instruction is executed by the processor, the processor receives the instructions. Receiving authentication credentials associated with the said account, wherein the authentication credentials include one or more of the following: login, password, or biometric authentication credentials. Determining the person depicted in the first image associated with the account based on whether the similarity between the person depicted in the passport image and the person depicted in the first image exceeds the similarity threshold, wherein the type of operation comprises one or more of the following: (i) displaying the attributes of the account, (ii) modifying the attributes of the account, (iii) accessing the application page, or (iv) processing a transaction using the contactless card. The system according to claim 4, which causes to perform the following.

6. The first data element comprises the barcode of the driver's license, the memory stores instructions, and when the instructions are executed by the processor, the processor receives The application receives instructions from a point-of-sale device specifying that the operation is to complete a transaction for an age-restricted item using the contactless card, and at least one rule includes the age required to purchase the age-restricted item. The application determines the age of the person associated with the driver's license and the contactless card based on the barcode of the driver's license, The application determines that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item, The application transmits an instruction to the point-of-sale device specifying that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item. The application receives payment data received from the contactless card, The application transmits the payment data to the point-of-sale information management device to complete the transaction. The system according to claim 3, which causes to perform the following:

7. The memory stores instructions, and when an instruction is executed by the processor, the processor receives the instructions. The application receives an updated version of the first data element, The application transmits the updated version of the first data element to be stored on the contactless card, The system according to claim 2, which causes the execution of the following:

8. A non-temporary computer-readable storage medium in which computer-readable program code is materialized, wherein the computer-readable program code, which is executable by a processor, is provided to the processor. The application running on the aforementioned processor receives instructions specifying that it should perform an operation associated with the account, The application receives encrypted data from the contactless card associated with the account, wherein the encrypted data is based on an encryption algorithm, a customer identifier, and the private key of the contactless card. The application receives an instruction from the authentication server indicating that the authentication server has verified the encrypted data based on the secret key of the contactless card, The application determines the type of authentication data necessary to authorize the operation, The application receives a first data element from the contactless card based on the determined type of authentication data, wherein the first data element comprises passport data or driver's license data. Determining that the first data element satisfies at least one rule for approving the operation, Approving the execution of the operation based on the received instruction indicating that the authentication server has verified the encrypted data, and the determination that the first data element satisfies the at least one rule for approving the operation, A non-temporary, computer-readable storage medium that enables execution of a command.

9. The non-temporary computer-readable storage medium is provided to the processor, Determining that the digital signature of the first data element received from the contactless card is a valid digital signature based on the public key associated with the entity providing the digital signature, Determining the type of authentication data based on the type of the operation, A non-temporary computer-readable storage medium according to claim 8, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

10. The first data element comprises a passport image, and the non-temporary computer-readable storage medium is provided to the processor, Receiving the first image depicting a person, Comparing the first image with the passport image, Based on the comparison, it is determined that the similarity between the person depicted in the passport image and the person depicted in the first image exceeds a similarity threshold, wherein the determination that the first data element satisfies at least one rule is based on the similarity between the person depicted in the passport image and the person depicted in the first image exceeding the similarity threshold, A non-temporary computer-readable storage medium according to claim 9, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

11. The non-temporary computer-readable storage medium is provided to the processor, The application outputs an instruction specifying that it should capture the first image in order to approve the operation, The first image is captured by an image capture device of a device equipped with the aforementioned processor, A non-temporary computer-readable storage medium according to claim 10, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

12. The non-temporary computer-readable storage medium is provided to the processor, Receiving authentication credentials associated with the said account, wherein the authentication credentials include one or more of the following: login, password, or biometric authentication credentials. Determining the person depicted in the first image associated with the account based on whether the similarity between the person depicted in the passport image and the person depicted in the first image exceeds the similarity threshold, wherein the type of operation comprises one or more of the following: (i) displaying the attributes of the account, (ii) modifying the attributes of the account, (iii) accessing the application page, or (iv) processing a transaction using the contactless card. A non-temporary computer-readable storage medium according to claim 11, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

13. The first data element comprises the barcode of the driver's license, and the non-temporary computer-readable storage medium is provided to the processor, The application receives instructions from a point-of-sale device specifying that the operation is to complete a transaction for an age-restricted item using the contactless card, and at least one rule includes the age required to purchase the age-restricted item. The application determines the age of the person associated with the driver's license and the contactless card based on the barcode of the driver's license, The application determines that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item, The application transmits an instruction to the point-of-sale device specifying that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item. The application receives payment data received from the contactless card, The application transmits the payment data to the point-of-sale information management device to complete the transaction. A non-temporary computer-readable storage medium according to claim 9, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

14. The non-temporary computer-readable storage medium is provided to the processor, The application receives an updated version of the first data element, The application transmits the updated version of the first data element to the contactless card for storage in the contactless card's memory. A non-temporary computer-readable storage medium according to claim 9, further comprising the computer-readable program code executable by the processor that causes the execution of the computer-readable program code.

15. An application running on the processor receives instructions specifying that it should perform an action associated with the account, The application receives encrypted data from the contactless card associated with the account, wherein the encrypted data is based on an encryption algorithm, a customer identifier, and the private key of the contactless card. The application transmits the encrypted data received from the contactless card to the authentication server. The application receives an instruction from the authentication server indicating that the authentication server has verified the encrypted data based on the secret key of the contactless card, The application determines the type of authentication data necessary to authorize the operation, The application receives a first data element from the contactless card based on the determined type of authentication data, wherein the first data element comprises passport data or driver's license data. The first data element is determined to satisfy at least one rule for approving the operation, Approving the execution of the operation based on the received instruction indicating that the authentication server has verified the encrypted data, and the determination that the first data element satisfies the at least one rule for approving the operation, Methods that include...

16. The aforementioned method, Determining that the digital signature of the first data element received from the contactless card is a valid digital signature based on the public key associated with the entity providing the digital signature, Determining the type of authentication data based on the type of the operation, The method according to claim 15, further comprising:

17. The first data element comprises a passport image, and the method is The application outputs an instruction specifying that an image should be captured to authorize the operation. The image capture device of the device equipped with the aforementioned processor captures a first image, The application receives the first image depicting a person, Comparing the first image with the passport image, Based on the comparison, it is determined that the similarity between the person depicted in the passport image and the person depicted in the first image exceeds a similarity threshold, and the determination that the first data element satisfies at least one rule is based on the similarity between the person depicted in the passport image and the person depicted in the first image exceeding the similarity threshold. The method according to claim 16, further comprising:

18. The aforementioned method, Receiving authentication credentials associated with the said account, wherein the authentication credentials include one or more of the following: login, password, or biometric authentication credentials. Determining the person depicted in the first image associated with the account based on whether the similarity between the person depicted in the passport image and the person depicted in the first image exceeds the similarity threshold, wherein the type of operation comprises one or more of the following: (i) displaying the attributes of the account, (ii) changing the attributes of the account, (iii) accessing the application page, or (iv) processing a transaction using the contactless card. The method according to claim 17, further comprising:

19. The first data element comprises the barcode of the driver's license, and the method is The application receives instructions from a point-of-sale device specifying that the operation is to complete a transaction for an age-restricted item using the contactless card, and at least one rule includes the age required to purchase the age-restricted item. The application determines the age of the person associated with the driver's license and the contactless card based on the barcode of the driver's license, The application determines that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item, The application transmits an instruction to the point-of-sale device specifying that the age of the person associated with the driver's license and the contactless card exceeds the age required to purchase the age-restricted item, The application receives payment data received from the contactless card, The application transmits the payment data to the point-of-sale information management device to complete the transaction. The method according to claim 16, further comprising:

20. The aforementioned method, The application receives an updated version of the first data element, The application transmits the updated version of the first data element to the contactless card. The applet executed by the processor of the contactless card stores the updated version of the first data element in the memory of the contactless card. The method according to claim 16, further comprising: