Unlocking the intelligent card
The system securely unlocks contactless cards using encryption and authentication, addressing vulnerabilities and enhancing user control over transaction usage, thereby reducing fraud and improving convenience.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- CAPITAL ONE SERVICES LLC
- Filing Date
- 2026-01-29
- Publication Date
- 2026-05-26
AI Technical Summary
Existing payment card lock mechanisms do not provide secure and convenient methods for unlocking contactless cards, leaving them vulnerable to fraudulent use when lost or stolen, and do not adapt to user preferences or location-based usage.
A system comprising a contactless card and a mobile device with a processor, memory, and communication interface, using encryption and authentication to securely unlock the card based on user preferences and location, ensuring authorized transactions.
Enhances security by preventing unauthorized use of lost or stolen contactless cards and allows controlled, user-preferred transactions, reducing fraud and inconvenience.
Smart Images

Figure 2026086504000001_ABST
Abstract
Description
Technical Field
[0001] This application claims priority to U.S. Non-Provisional Application No. 16 / 863,179, filed Apr. 30, 2020, entitled “Intelligent Card Unlock”. The entire content of the aforementioned application is hereby incorporated by reference.
[0002] Examples herein generally relate to computing platforms, and more specifically to intelligently unlocking the lock of a payment card, including contactless cards used in transactions.
Background Art
[0003] The payment card lock function can currently lock the payment card so that the user cannot use it when the user does not own the card, that is, when the card is lost, stolen, or forgotten. By locking the card, it can be prevented from being used in any transaction. With the card lock function, the user can confirm whether the card was simply forgotten rather than stolen without having to perform all the actions required when reporting the loss or theft of the card. The act of reporting the loss or theft of a card can include suspension of the account associated with the card, sending a new physical card via a postal service, and other inconveniences. The payment card lock function was developed to save the actions required for such card replacement and reduce inconvenience.
[0004] It would be beneficial and advantageous for fraud prevention and user security if the payment card could be locked at all times and easily unlocked upon the user's request or when it is determined that the user is in a convenient time zone or a location where the user is likely to be located.
Summary of the Invention
[0005] Examples disclosed herein provide systems, methods, articles, and computer-readable media that enable the unlocking of contactless cards used in card presentation transactions. According to one embodiment, the apparatus may include a display device, a processor circuit, a transceiver, a card reader circuit, and memory. The processor circuit may be operable to display a graphical user interface on the display device. The transceiver may be connected to the processor circuit and may be operable to communicate with an external device. The card reader circuit may be connected to the processor circuit and may be operable to transmit and receive signals within a signal field. Memory may be connected to the processor circuit and may be operable to store an unlock-lock application. The unlock-lock application, when executed by the processor circuit, may have instructions to cause the processor circuit to receive encrypted data from a contactless card via the card reader circuit. The contactless card may be locked to prevent its use in card presentation transactions, and the encrypted data is generated based on an encryption algorithm and a diversified key. The unlock-lock application executed by the processor circuit may transfer the encrypted data to an authentication server for authentication and unlocking of the contactless card. The user may receive an instruction indicating that the contactless card has been unlocked and is now available for use in card presentation transactions. The instruction indicating unlocking indicates that the contactless card has been authenticated. The user's preference for using the contactless card in payment card transactions at the time of unlocking may be identified, and a representation of the identified user preference for the contactless card may be presented on the graphical user interface displayed on the display device.
[0006] Another example discloses a system comprising a contactless card and a mobile device. The contactless card may include a processor, memory, and a communication interface capable of operating to support at least one of the following communication protocols: Near Field Communication, Bluetooth®, or Wi-Fi®. The mobile device may include a mobile device processor, mobile device memory, a transceiver, a display device, and a card reader circuit. The card reader circuit may be capable of operating to communicate with the contactless card via the communication interface, and the mobile device memory may store programming code, including an instance of an unlock-lock application. The contactless card processor may generate encrypted data using a cryptographic algorithm and a diversified key, and may be capable of transmitting a signal via the communication interface containing the encrypted data that can be used to authenticate the contactless card. The programming code, when executed by the mobile device processor, causes the mobile device processor to perform functions including the ability to receive a signal from the card reader circuit containing the encrypted data transmitted from the contactless card. The encrypted data may be transmitted via the transceiver for authentication and unlocking of the contactless card. The mobile device processor may receive an unlock instruction indicating that the contactless card has been unlocked. When unlocked for use in card presentation transactions, user preferences that allow limited use of the contactless card may be identified. When unlocked, a representation of the identified user preference for the contactless card may be displayed in a graphical user interface on a display device.
[0007] An example of a non-temporary computer-readable storage medium is provided. The non-temporary computer-readable storage medium may be embodied by having computer-readable program code. The computer-readable program code is executable by a processor circuit, which can receive encrypted data from the communication interface of a contactless card via a card reader circuit. The contactless card may be locked to prevent use in card presentation transactions, and the encrypted data is generated based on an encryption algorithm and a diversified key. The encrypted data may be transferred to an authentication server to enable the unlocking of the contactless card. An unlock instruction may be received indicating that the contactless card has been unlocked for use in card presentation transactions. The unlock instruction is proof of the encrypted data. Authorized contactless card usage restrictions relating to the contactless card's ability to complete payment card transactions may be specified. An indication of the unlocked status for use and an indication of authorized contactless card usage restrictions may be presented on a graphical user interface presented on a display device. [Brief explanation of the drawing]
[0008] [Figure 1A] Figures 1A and 1B show an example of a system for locking and unlocking cards used in transactions. [Figure 1B] Figures 1A and 1B show an example of a system for locking and unlocking cards used in transactions.
[0009] [Figure 2A] Figures 2A and 2B show examples of locking and unlocking cards used for transactions. [Figure 2B] Figures 2A and 2B show examples of locking and unlocking cards used for transactions.
[0010] [Figure 3A] Figures 3A and 3C show examples of locking and unlocking cards used in transactions. [Figure 3B]Figures 3A and 3C show examples of locking and unlocking cards used in transactions. [Figure 3C] Figures 3A and 3C show examples of locking and unlocking cards used in transactions.
[0011] [Figure 4A] Figures 4A and 4B show examples of contactless cards suitable for use in the examples shown in Figures 1 to 2B. [Figure 4B] Figures 4A and 4B show examples of contactless cards suitable for use in the examples shown in Figures 1 to 2B.
[0012] [Figure 5] Figure 5 shows an example of a mobile device suitable for implementing the examples in Figures 1 to 4.
[0013] [Figure 6] Figure 6 shows an example of a computing architecture suitable for implementing the examples in Figures 1 to 5. [Modes for carrying out the invention]
[0014] One example disclosed herein provides secure technology for locking and unlocking payment cards for use in card presentation transactions. Generally, payment cards are unlockable and operable to complete card presentation transactions with merchants. If a card is lost, even if the card can be locked, there is still an opportunity for the lost card to be used for fraudulent purposes, provided the user is unaware that the card has been lost. The aforementioned example provides an easy-to-use and implement solution that, to its advantage, reduces the possibility of credit fraud.
[0015] In the example above, an unauthenticated contactless card is locked so that it cannot be used in card presentation transactions, while authentication of a contactless card indicates that the contactless card is valid (for example, assigned to an authenticated and authorized user and payment account) and unlocks it so that it can be used in card presentation transactions.
[0016] For general reference to the nomenclature used herein, one or more parts of the detailed description that follows may be provided in terms of program procedures executed on a computer or a network of computers. These descriptions and expressions of procedures are intended to be used by those skilled in the art to most effectively convey the gist of their work to those skilled in the art. A procedure is considered here, and also generally, to be a self-consistent sequence of operations that produce a desired result. These operations require the physical manipulation of physical quantities. These quantities, though not always, take the form of electrical, magnetic, or optical signals that can be stored, transferred, connected, compared, and otherwise manipulated. It is sometimes convenient, primarily for general reasons of use, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these terms and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.
[0017] Furthermore, these operations are often referred to in terms such as addition, or comparison, etc. that are commonly associated with mental operations performed by a human operator. However, in any of the operations described herein that form part of one or more examples, an ability such as that of a human operator is not required and, in many cases, not desirable. Rather, these operations are machine operations. Useful machines for performing the operations of the various examples include digital computers selectively activated or configured by computer programs stored internally written according to the teachings herein, and / or include devices specially constructed for the required purpose or for a digital computer. The various examples also relate to devices or systems for performing these operations. These devices may be specially constructed for the required purpose. The required structure of these various machines will become apparent from the disclosure.
[0018] Referring to the drawings, like reference numerals are used throughout to refer to like elements. In the following description, numerous specific details are set forth for purposes of explanation to provide a thorough understanding. However, it will be apparent that the new examples can be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form in order to facilitate the description. It is intended to cover all modifications, equivalents, and alternatives falling within the scope of the claims.
[0019] FIG. 1A shows a schematic diagram of an example of a system 100 that conforms to an example of the disclosure.
[0020] In the example shown in Figure 1A, the mobile device 110 may include a processor circuit 147, a communication interface 146, a touchscreen display 149, and memory 141. Memory 141 may be capable of storing an account authentication application 143, an unlock-lock application 144, and other applications 145 such as a messaging application, a banking application, a location data application, or a telephone application. Each of the applications 143 to 145 may include computer-readable programming code executable by the processor or processor circuit. The account authentication application 143 may provide functions and features in response to requests from the unlock-lock application 144. Examples of functions and features provided in response to requests are illustrated with reference to Figures 2A and 2B.
[0021] The touch screen display 149 is, for example, connected to the processor circuit 147 and can be operable to present a graphical user interface (shown in other examples) in response to a signal from the processor circuit 147. The communication interface 146 can be operable to communicate with an external device such as the server 120 via a plurality of transceivers (not shown in this example). For example, it can be a mobile device 110 such as a smartphone equipped with a cellular transceiver and a Wi-Fi transceiver (e.g., the 802.11 group of transceivers) (shown in other examples). The card reader 148 can include a near-field communication (NFC) circuit operable to transmit and receive signals within the signal field of the mobile device 110 (e.g., in a short-distance region of about 2 - 10 cm). As shown, the memory 141 of the mobile device 110 includes an instance of an operating system (OS) 142. An example of the operating system 142 includes Android (registered trademark) OS, iOS (registered trademark), Linux (registered trademark), and Windows (registered trademark) operating systems. As shown, the OS 142 includes an account authentication application 143, an unlock-lock application 144, and one or more other applications 145. With the account authentication application 143, the user can perform various account-related operations such as viewing account balances, purchasing items, and payment processing. First, the user needs to authenticate using authentication information to access the account authentication application 143. For example, the authentication information can include a username and password, biometric authentication information, etc.
[0022] The executed account authentication application causes the processor circuit 147 to perform functions related to the authentication of a contactless card such as 101. For example, when a locked contactless card 101 is placed in the signal field of the card reader 148 of the mobile device 110, the contactless card 101 establishes a communication path with the mobile device 110 and provides encrypted data 190 to the account authentication application 143 of the mobile device 110. The account authentication application 143 may cause the encrypted data 190 to be transferred to the server 120 via the network 130, which authenticates and unlocks the contactless card 101 for use in card presentation transactions. The server 120 may provide the account authentication application 143 with instructions via a message on the network 130 indicating the success of the authentication and unlocking of the contactless card 101. The account authentication application 143 may provide instructions to the unlock-lock application 144, which, when executed, causes the processor circuit 147 to perform functions related to restricting the operation of the unlocked contactless card, or notify it in other ways. When the account authentication application 143 is executed, the processor circuit 147 is instructed to perform a function. When the account authentication application 143 and the unlock-lock application 144 are running, the content of the graphical user interface may be generated or provided by the account authentication application 143 and the unlock-lock application 144 executed by the processor circuit 147.
[0023] The aforementioned operational examples provide context for the functionality of each disclosed example, and it may be beneficial to describe the components of system 100 in more detail by referring to the functions performed by each component.
[0024] As illustrated, system 100 includes one or more contactless cards 101, one or more mobile devices 110, and a server 120. The contactless card 101 is typically any type of payment card, such as a credit card, debit card, ATM card, or gift card. The contactless card 101 may include one or more chips (not shown), such as a radio-frequency identification (RFID) chip, capable of communicating with the mobile device 110 via NFC, EMV® standards, or other short-range protocols via wireless communication. While NFC is used as an example of a communication protocol, this disclosure is equally applicable to other types of wireless communication, such as EMV standards, Bluetooth®, and / or Wi-Fi. The mobile device 110 is typically any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop, or portable game device. The server 120, comprising one or more processors 121, may be any type of computing device, such as a server, workstation, computer cluster, cloud computing platform, or virtualization computing system.
[0025] The contactless card 101 may include a processor 115 and a communication interface 116. As illustrated with reference to the examples in Figures 4A and 4B, the processor 115 may be a circuit capable of performing logical functions, and the communication interface 116 may be a circuit capable of exchanging signals with other devices such as a mobile device 110.
[0026] As illustrated, the contactless card memory 102 includes a data store for card data 103, a counter 104, a master key 105, a diversified key 106, a unique customer identifier 107, and an account number 108. The card data 103 generally includes account-related information, such as information used to process payments using the contactless card 101. For example, the card data 103 may include an account number, expiration date, billing address, or security code (CVV). The account number may be any type of account number, such as a primary account number (PAN), a virtual account number, and / or a token generated based on a PAN. Other types of account numbers are conceivable, and the use of account numbers or other types of card data 103 should not be considered as limiting this disclosure. The card data 103 may further include a name, billing address, delivery address, and other account-related information. The account number 108 stores a one-time use virtual account number with associated expiration and CVV values. For example, account number 108 may contain multiple one-time use virtual account numbers, expiration dates, and CVV values.
[0027] As shown in the figure, the server 120 includes a data store for account data 124 and memory 122. The account data 124 includes account-related data for a number of users and / or accounts. The account data 124 may include at least a master key 105, a counter 104, a customer identifier 107, an associated contactless card 101, the account holder's name, the account's billing address, one or more delivery addresses, one or more virtual card numbers, and history information for each account. The memory 122 may include a management application 123 and may include one or more instances of the account's card data 103 from the account data 124, an instance of the counter 104, an instance of the master key 105, and an instance of the diversified key 106.
[0028] System 100 is capable of implementing key diversification to protect data, which may be referred to here as the key diversification technique. Generally, the server 120 (or other computing device) and the contactless card 101 may be provisioned to use the same master key 105 (also called a master symmetric key). More specifically, each contactless card 101 is programmed with a separate master key 105 that has a corresponding pair with the server 120. For example, when a contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of the contactless card 101. Similarly, a unique master key 105 may be stored (and / or stored in another secure location) in the customer records associated with the contactless card 101 in the account data 124 of the server 120. The master key can be kept secret from anyone other than the contactless card 101 and the server 120, thereby improving the security of System 100.
[0029] The master key 105 can be used in conjunction with the counter 104, enhancing security through key diversification. The counter 104 contains a value synchronized between the contactless card 101 and the server 120. The value of the counter 104 may include a numerical value that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or between the contactless card 101 and the mobile device 110). To enable NFC data transfer between the contactless card 101 and the mobile device 110, the account authentication application 143 may communicate with the contactless card 101 when it is sufficiently close to the card reader 148 of the mobile device 110. The card reader 148 may be capable of reading from and / or communicating with the contactless card 101 (e.g., via NFC, Bluetooth, RFID, Wi-Fi, etc.). Thus, the exemplary card reader 148 includes an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.
[0030] After the account authentication application 143 and / or the unlock-lock application 144 are launched or loaded (opened), the loaded applications may prompt the user to tap the contactless card 101 on the mobile device 110. For example, the user may tap the contactless card 101 on the mobile device 110, thereby bringing the contactless card 101 close enough to the card reader 148 of the mobile device 110 to enable NFC data transfer between the contactless card 101 and the card reader 148 of the mobile device 110. In some examples, the mobile device 110 may trigger the card reader 148 via an API call or the like. In addition and / or alternatively, the mobile device 110 may trigger the card reader 148 by periodically polling it. More generally, the mobile device 110 may trigger the card reader 148 to engage in communication using any viable method. When the contactless card 101 is tapped on the mobile device 110 (for example, brought within the NFC communication range of the card reader 148), the account authentication application 143 may, on its own initiative or in response to a signal from the unlock-lock application 144, generate encrypted data 190 as depicted in Figure 1A and send instructions to the contactless card 101.
[0031] In response, the contactless card 101 increments the value of counter 104, provides the master key 105 and the value of counter 104 as input to a cryptographic algorithm, and generates a diversified key 106 as output. The contactless card 101 may then encrypt the customer identifier 107 using the diversified key 106 and generate encrypted data 190. The contactless card 101 may then transmit the encrypted data 190 to the account authentication application 143 of the mobile device 110 (e.g., via NFC connection, Bluetooth connection, etc.). The account authentication application 143 of the mobile device 110 may then transmit the encrypted data 190 to the server 120 via the network 130. In at least one example, the contactless card 101 transmits the value of counter 104 along with the encrypted data 190.
[0032] After communication is established between the mobile device 110 and the contactless card 101, the contactless card 101 may generate a message authentication code (MAC) cipher. In particular, this may occur when reading a Near Field Radio Data Exchange (NDEF) tag, which may be generated according to the NFC Data Exchange format, such as through NFC reading. For example, an account authentication application 143 and / or a reader such as a card reader 148 may send a message such as an applet selection message having the applet ID of an NDEF generation applet. At this time, the value of the counter 104 held by the contactless card 101 may be updated or incremented. At this point, a message containing a header and a shared secret may be generated. Subsequently, a session key may be generated. The MAC cipher may be generated from the message which may contain a header and a shared secret. Subsequently, the MAC cipher may be formed by concatenating one or more blocks of random data, and the MAC cipher and random number (RND) may be encrypted with the session key. Subsequently, the cipher and header may be concatenated, encoded as an ASCII hexadecimal number, and returned in NDEF message format (for example, showing the answer to another message). In some examples, the MAC encryption may be transmitted as an NDEF tag, and in other examples, the MAC encryption may be included with the URI (uniform resource indicator) (for example, as a formatted string). The contactless card 101 may transmit the MAC encryption to the mobile device 110, which may forward the MAC encryption to the server 120 for verification, as described later. However, in some examples, the mobile device 110 may verify the MAC encryption.
[0033] More generally, when preparing to transmit data (for example, to a server 120 and / or a mobile device 110), the contactless card 101 may increment the value of counter 104. The contactless card 101 may then provide the master key 105 and the value of counter 104 as inputs to a cryptographic algorithm that generates a diversified key 106 as an output. The cryptographic algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cryptographic message authentication code (CMAC) algorithms, etc. Non-limiting examples of cryptographic algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, symmetric CMAC algorithms such as AES-CMAC, etc. The contactless card 101 may then encrypt the data (for example, customer identifier 107 and other data) using the diversified key 106. The contactless card 101 may then transmit encrypted data (e.g., encrypted data 190) to the account authentication application 143 on the mobile device 110 (e.g., via NFC connection, Bluetooth connection, etc.). For example, the contactless card 101 may be operable to transmit encrypted data via tap 174 and receive signals when the contactless card is in the signal field of the card reader 148. Similarly, the card reader 148 may also be operable to transmit and receive signals. More specifically, the card reader 148 may receive encrypted data 190 via tap 174 while the contactless card 101 is locked. The account authentication application 143 on the mobile device 110 may then transmit the encrypted data to the server 120 via the network 130. In at least one example, the contactless card 101 transmits the value of counter 104 along with the encrypted data. In such an example, the contactless card 101 may transmit either the encrypted value of the counter 104 or the unencrypted value of the counter 104.
[0034] Upon receiving encrypted data 190 from the mobile device 110, the management application 123 of the server 120 may be able to operate to verify the encrypted data 190 using key diversification. The key diversification performed by the management application 123 of the server 120 may include performing the same symmetric encryption, using the value of counter 104 (by the contactless card processor 115) as the input to encryption and the master key 105 as the key to encryption. As described above, the value of counter 104 may be identified by the data received with the encrypted data 190 from the mobile device 110, as previously stated, or by the value of counter 104 held by the server 120 to perform key diversification on the contactless card 101. The output of the encryption may be the same as the value of the diversified key 106 generated on the contactless card 101. The management application 123 can then decrypt the encrypted data 190 received via the network 130 using the diversified key 106, and the encrypted data 190 can reveal the data transmitted by the contactless card 101 (for example, at least the customer identifier 107). In this way, the management application 123 may authenticate the data transmitted from the contactless card 101 via the mobile device 110, for example by comparing the decrypted customer identifier 107 with the customer ID in the account data 124 for the account, and if the customer ID values match, verify the encrypted data received from the contactless card 101.
[0035] While counter 104 is used as an example, other data may be used to secure communication between the contactless card 101, the mobile device 110, and / or the server 120. For example, counter 104 may be exchanged for a random nonce generated each time a new diversified key 106 is needed, the full value of the counter sent from the contactless card 101 and the server 120, a portion of the counter value sent from the contactless card 101 and the server 120, a counter maintained independently by the contactless card 101 and the server 120 but not transmitted between them, a one-time passcode exchanged between the contactless card 101 and the server 120, a cryptographic hash of the data, etc. In some examples, one or more portions of the diversified key 106 may be used by the parties to create multiple diversified keys 106.
[0036] As illustrated, the server 120 may include one or more hardware security modules (HSMs) 125. For example, one or more HSMs 125 may be operable to perform one or more cryptographic operations as disclosed herein. In some examples, one or more HSMs 125 may be configured as special-purpose security devices operable to perform one or more cryptographic operations. The HSMs 125 may be configured such that keys are never revealed outside the HSMs 125 and are instead maintained within the HSMs 125. For example, one or more HSMs 125 may be operable to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 125 may be included in the server 120 or may communicate with the server 120 for data.
[0037] After authenticating the locked contactless card 101 and then unlocking the contactless card for use in card presentation transactions, the components of system 100 can operate according to the system example shown in Figure 1B and the accompanying discussion.
[0038] As shown in the system example in Figure 1B, in addition to the mobile device 110, network 130, and server 120 that perform the same functions, system 184 further includes an unlock server 129, a server 160 that hosts a payment account component 163, a point-of-sale device (POS device) 170 for the merchant 180, and a network 191 that connects the POS device 170 to the payment account component 163 of server 160. The unlock server 129 includes a processor and memory having programming code or instructions, and may be operable to manage the number of unlocked contactless cards belonging to other users, along with user preference settings that restrict the use of unlocked contactless cards 101', via an instance of the unlock-lock application 144''.
[0039] Returning to the example of operation, in response to sending encrypted data 190 to the server 120, the processor circuit 147, which executes the account authentication application 143, may receive an indication from the server 120 that the contactless card 101 has been unlocked based on the authentication of the encrypted data 190. Alternatively, the account authentication application 143 may output an instruction to the unlock-lock application 144 that the contactless card has been unlocked.
[0040] In another example, the unlock server 129 may be operable to receive user preference settings from the mobile device 110, which are indicated as selected for authorized uses of the contactless card in a card presentation transaction when the contactless card is unlocked. The unlock server 129 may further be operable to obtain the determined location of the mobile device 110 from the mobile device 110 via a location data application running as one of the other applications 145. The location of the mobile device 110 may be used by an instance of the unlock-lock application 144'' to generate a list of merchants that satisfy the user preference for limited card uses.
[0041] The unlock server 129 may be configured to manage user preferences for an unlock-lock application running on the mobile device processor (i.e., processor circuit 147) of the mobile device 110. In a more detailed example, the unlock server 129 may be configured to receive user preference settings from the mobile device, which are indicated as selected, authorized uses for unlocked contactless cards in card presentation transactions. The unlock server may be configured to derive a maximum transaction amount threshold from the user preference settings. For example, in the case of a transaction at a restaurant, the user preference may be set to $50. The unlock server 129 may forward the maximum transaction amount threshold derived from the user preference settings to the payment account component 163 of the server 160 via either the communication link 188 or the network 130. The communication link 188 may be a direct communication connection between the unlock server 129 and the server 160. The maximum transaction amount threshold may also be forwarded to the mobile device 110 for presentation in a graphical user interface presented on the touchscreen display 149.
[0042] As described above with respect to Figure 1A, once the management application 123 of the server 120 verifies the encrypted data 190 using key diversification, the management application 123 may send an authentication instruction to the account authentication application 143 of the mobile device 110. For example, it may establish a connection to the application programming interface (API) of the unlock-lock application 144 and provide the authentication instruction to the unlock-lock application 144. Once the unlock-lock application 144 receives an authentication instruction which it interprets as indicating that the contactless card 101' has been unlocked, the unlock-lock application 144 may send a request to the unlock server 129 regarding restrictions on the use of the unlocked contactless card 101'. Restricted uses (described in more detail with reference to other examples) may include a list of local merchants that are whitelisted for card presentation transactions using the unlocked contactless card 101'. Merchant 180 may be on the list of whitelisted merchants. An unlocked contactless card 101' functions as a contactless card 101, the only difference being that it is unlocked and, subject to the limited uses disclosed herein, is capable of participating in certain card presentation transactions. For example, an unlocked contactless card 101' may be capable of communicating with a card reader 148 via a wireless connection 175. The unlocked contactless card 101' is presented for a card presentation transaction, and transaction data 166 may be transmitted from the contactless card 101' to the merchant's POS device 170 via a wireless connection 177. The transaction data 166 may be, for example, information used to complete the transaction, such as a card number, an account number, or any other identifying information that can be used to authenticate whether the contactless card 101' is connected to an authorized payment account. Of course, if the contactless card 101' is equipped with an identification chip or magnetic strip, the information required for the transaction can be transmitted by inserting the identification chip into the POS device 170 or by swiping the magnetic strip to provide the transaction data 166.The POS device 170 of the merchant 180 may be capable of transferring transaction data 166 to the payment account component 163 via the network 191 for verification processing.
[0043] Server 160 may be configured to receive transaction data 166 and determine whether the transaction can be completed based on the verification process performed by the payment account component 163. For example, the payment account component 163 may use the transaction data 166 to process the financial aspects of the transaction, such as whether the transaction is a card presentation transaction, whether the user's payment account associated with the unlocked contactless card 101' is valid and has sufficient credit or funds, whether the contactless card 101' is unlocked for the card presentation transaction, and whether the user preference settings provided by the unlock-lock application 144 are met. Transaction response data 167 from Server 160 may be a display of the results of the verification process performed by the payment account component 163 and may be sent back to the POS device 170 via the network 191.
[0044] The payment account component 163 may include additional functionality beyond enabling the completion of card presentation transactions. The payment account component may include query logic or machine learning that can be applied to past transactions to identify patterns or trends and whitelist those transactions considered low-risk. For example, patterns or trends may reveal location patterns such as frequent visits to specific merchants, dollar thresholds that users do not frequently exceed, and / or consistently purchasing meals within one mile of the user's office or home and / or at specific times of day. These patterns and trends can be used to identify new user preferences or to modify existing user preferences. For example, in a situation where a new restaurant or coffee shop opens within a set radius, user preferences can be modified to generate a list of any lunch locations with a specific merchant category code to enable the completion of card presentation transactions. For example, user preferences can also be modified to allow purchases at restaurants costing $25 or less within one mile of the user's office.
[0045] An example in Figure 1B shows how the management application 123 of the server 120 sends card data 103 from the server 120 to the mobile device 110 after verifying the encrypted data 190 in Figure 1A. In at least one example, the management application 123 may encrypt the card data 103 before sending it to the account authentication application 143. As stated, the card data 103 may include the account number, CVV, and / or expiration date of the contactless card 101. The card data 103 may further include the account holder's last name, first name, delivery address, and billing address. In one example, the account number in the card data 103 may be a virtual card number generated after verification of the encrypted data 190 by the management application 123. In another embodiment, the account number in the card data 103 is a record from account number 108. In one example, the last name and first name are stored in the account authentication application 143 (or another element of the OS). The account authentication application 143 may provide the API of the unlock-lock application 144 with an authentication representation of the card data 103 and / or encrypted data 190. The unlock-lock application 144 may use the interpretation information provided by the account authentication application 143 to determine whether the contactless card is unlocked for a card presentation transaction, and if it is unlocked, it may perform user preferences as described with reference to this example and the examples in Figures 2A to 3C.
[0046] In one example, the card data 103 sent from the server 120 to the mobile device 110 includes all relevant information necessary to make a purchase using the account associated with the contactless card 101 (e.g., account number, expiration date, CVV, billing address, shipping address, last name, first name, etc.).
[0047] In one example, network 130 may connect to other servers in addition to server 120. For example, the mobile device processor circuit 147 may be capable of retrieving location preference settings from a number of user preference settings stored in memory 141. The mobile device processor circuit 147 may also retrieve location data from location applications and other applications 145. The location data may include location, timestamp, and speed. The retrieved location preference settings and location data may be transmitted to the unlock server 129. In response, the mobile device processor circuit 147 may receive a list of merchants that satisfy the retrieved location preference settings based on the retrieved location data. The processor circuit may present the list of merchants in a graphical user interface on a display device such as a touchscreen display 149.
[0048] The mobile device processor circuit 147 may be further operable to determine, based on location data provided by a location application, that a card unlock operation is required to fulfill an imminent card presentation transaction. The processor circuit may generate an instruction that generates a notification indicating that a card unlock operation is requested. An instruction activation signal may be output that is operable to activate an output device or a display device in accordance with the generated instruction. Examples of output devices and display devices are shown in the example in Figure 6.
[0049] Figure 2A is a flowchart illustrating an example of processing using the system example in Figure 1. Process 200 may be executed by the mobile device 110 in Figure 1A or Figure 1B. By executing an unlock-lock application and an authentication application, the processor circuit 147 of the mobile device 110 may be operable in 210 to receive encrypted data from a contactless card via a card reader circuit. For example, the contactless card may be locked to prevent its use in card presentation transactions, and the encrypted data is generated based on an encryption algorithm and a diversified key generated by the contactless card. In 220, the encrypted data is transferred to an authentication server, which can authenticate and unlock the contactless card. For example, the authentication server may be operable to decrypt the encrypted data, verify the decrypted data, and authenticate the contactless card. If verification is successful and authentication is obtained, the contactless card may be unlocked for card presentation transactions. Based on the verification of the decrypted data, the authentication server may be operable to generate an unlock instruction indicating that the contactless card has been unlocked and to transfer the unlock instruction to the mobile device. The mobile device's processor may receive an unlock instruction indicating that the contactless card has been unlocked and is ready for use in a card presentation transaction (230). The unlock instruction may also indicate that the contactless card has been authenticated and unlocked. The processor may further be configured (240) to identify user preferences regarding the use of the contactless card once it has been unlocked for use in a payment card transaction.User preferences may include, for example, keeping the card unlocked for a set number of card presentation transactions (e.g., the next 10 or 20 transactions), allowing manual re-locking via phone or location (area from commute to office, specific business district, shopping mall, travel destination, etc.), spending amount (e.g., total of $100 for all transactions, limit of $50 for individual transactions, etc.), time increments (e.g., next 6 hours, 1 hour, 45 minutes, commute or trip time), or re-lock settings to re-lock the card (or transitioning to a default state (e.g., fully or partially locking a transaction) after the unlock duration, such as after the aforementioned user preference time settings, after default time settings, after a number of transactions or other settings, etc.). Alternatively, a server such as 120 or 129 in Figure 1 may automatically re-lock the card, for example, according to default settings or user preferences, so that card presentation transactions are no longer possible without further unlocking. In 250, the processor may present a representation of the identified user preferences of the contactless card in a graphical user interface presented on a display device, which may be a touchscreen display.
[0050] Figure 2B shows another example of a process that may be implemented when an unlock-lock application 144 is executed, enabling the unlocking of a contactless card. Process 201 may be implemented as a mobile computing application that can provide authorized use of the unlocked contactless card. Mobile computing applications such as the unlock-lock application 143 in Figure 1 may be stored in memory as a non-temporary computer-readable medium, or they may be implemented by a processor or processing circuit. In exemplary process 201, the processor may receive encrypted data from the communication interface of the contactless card via a card reading circuit (211). For example, the contactless card may be locked so as not to be used in card presentation transactions, and the encrypted data is generated based on an encryption algorithm and diversified key implemented and stored on the contactless card. The processor can have the encrypted data transferred to an authentication server to enable the unlocking of the contactless card (221). In 231, the processor running the unlock-lock application on the mobile device may receive an unlock instruction that the contactless card has been unlocked for use in card presentation transactions. Furthermore, this instruction may be used as a server-side confirmation that the encrypted data was provided by an authorized user of the card. The unlock-lock application executed by the processor may identify permitted contactless card usage restrictions regarding the contactless card's functionality for completing payment card transactions (241). For example, a merchant whitelist may be stored in a database maintained by the server, such as the unlock-lock application data 126 in Figure 1A. In response to confirming that the encrypted data was provided by an authorized user of the card, the server may distribute part or all of the merchant whitelist to the unlock-lock application on the mobile device. The unlocked contactless card may only be usable (i.e., permitted for use) for card presentation transactions at merchants included in the merchant whitelist.For example, a server may receive user preference settings from the mobile device's unlock-lock application. User preference settings may include user-preferred time and area settings, such as allowing card presentation transactions at 9 a.m. within 5 square blocks or half a mile of the user's location, such as the user's office or home location, area settings, and merchant code settings (e.g., only coffee shops, restaurants, and drugstores). Other settings may be based on geographical location, geofenced area, merchant name, price threshold, time threshold, day of the week, time range within a day, zip code, area code, merchant category, product category, etc. The time threshold may be a default timer, such as 30 minutes from the time the contactless card is unlocked. As an example, geofencing is a feature of computer programs that allows developers or administrators to define geographical boundaries using mobile device location data services such as the Global Positioning System (GPS) or Radio Frequency Identification (RFID) tags (if permitted by the mobile device user), or Wi-Fi® or cellular data available when determining location. A geofenced area may be, for example, an area enclosed by a radius, an area defined by a postal code, or a government boundary such as a city or county designation. For example, a merchant whitelist may be based on users selecting merchant codes to restrict the use of unlocked contactless cards at merchants to which those merchant codes have been assigned.
[0051] In paragraph 251, the mobile device may present a graphical user interface on the display device that indicates the unlock status for use (e.g., an unlocked, open lock icon) and a representation of identified permitted contactless card usage restrictions. For example, the representation may be part of a distribution of merchant whitelists or a map of identified area settings. In one example, the processor may present multiple contactless card restriction uses to the user preference selection for setting contactless card restriction uses via the graphical user interface. Restriction uses may include one or more of the following: geographical location, geofenced area, merchant name, price threshold, time threshold, day of the week, time range within a day, zip code, area code, merchant category, product category, etc.
[0052] The processor circuit may further operate to receive user preference selections via a graphical user interface that set restrictions on the use of contactless cards. Location information may not be available until the user opens an application, and for example, when the user requests to unlock the card (as in example 211 in Figure 2B), an unlock-lock application may be launched that may obtain permission to access or obtain location information from a location application or service such as GPS or Wi-Fi location service. For example, a location data application may be operable to determine the location of the device. In one example, memory may be operable to store a number of user preference settings for the unlock-lock application and further instructions when executed by the processor circuit. The processor circuit may be operable to determine, based on the location provided by the location data application, that a card unlock operation is required to fulfill an imminent card presentation transaction. The processor circuit may be operable to generate instructions to generate a notification indicating that a card unlock operation is required and to output a notification activation signal that can be operated to activate an output device or display device in accordance with the generated instructions. For example, the processor circuit may present a prompt in the graphical user interface indicating the locked state of the contactless card.
[0053] In the example operation, in response to the authentication prompt, the unlock-lock application 144 may generate a list of card usage restrictions in the graphical user interface based on the user preferences maintained by the unlock-lock application 144, and present the generated list of card usage restrictions (as shown in another example).
[0054] The processor circuit may be capable of operating to present a menu of user preference settings on a graphical user interface, which can be selected by the user. These user preference settings can allow the use of an unlocked contactless card in card presentation transactions, and by selecting this, the user can customize the use of the contactless card when it is unlocked. For example, as shown in Figure 3A, the menu of the graphical user interface 313 may include several user preferences 301-305. The user can select one or more of the presented user preferences 301-305. As shown in Figure 3A, user preference #1 301 and user preference #3 303 are shown in bold to indicate that these user preferences have been selected by the user.
[0055] The processor circuit may be operable to receive instructions for selecting one or more user preference settings presented in a menu. Figure 3B shows an example of a graphical user interface that shows the selection of user preference settings. For example, a mobile device 310 may present a graphical user interface 314 on a display device 320. If the display device is a touchscreen, the unlock-lock application may present touch-based selections to the graphical user interface 314. Examples of user preference settings to select may include a location selection such as location #1 317, a time range selection such as time range #3 311, an area selection such as radius #6, and a merchant category code selection such as MCC#X 315. In one example, a time range selection may specify a time range during which the contactless card remains unlocked. An area selection may specify an area that may be used for card presentation transactions when the contactless card is unlocked. For example, an area may be defined by a radius from the user's location, an area within a square block or square mile or foot, or by other means indicating an area such as a zip code or other postal code. For example, the radius selection can specify the distance from the user's location to which contactless payment is permitted for card presentation transactions. The merchant category code selection specifies the category of goods or services offered by each merchant, to which a merchant category code is assigned.
[0056] The processor circuit may retrieve location preference settings from multiple user preference settings stored in memory (see, for example, location #1 setting 317 in Figure 3B). The unlock-lock application executed by the processor circuit may be operable to retrieve location data from a location data application also executed on the processor circuit. The unlock-lock application may be operable to send the retrieved location preference settings and location data to the unlock server. The unlock server may be able to identify the number of merchants that satisfy the retrieved location preference settings. For example, the unlock server may be operable to access not only information about merchants that satisfy each location preference setting, but also other user preference settings. Based on the retrieved location data, the unlock-lock application may receive a list of merchants that satisfy the retrieved location preference settings or other settings.
[0057] Returning to the example in Figure 2A, the processor circuit may be configured to communicate with a server, such as 120 in Figure 1, which is configured to manage the user preferences of the unlock-lock application via the unlock-lock application. In one example, the processor circuit may be configured to provide user preference settings that are selected to allow the use of an unlocked contactless card in a card presentation transaction.
[0058] For example, the merchant name or merchant category code (e.g., grocery store, specialty services, etc. (Merchant Category Code (MCC) according to IRS Revised Procedure 2004-43)) is a classification code that payment card authorities assign to merchants / payees. Payment card authorities assign specific codes to merchants based on the merchant's primary business activities. Merchant category codes enable users to make card-based purchases even in new areas. For example, a restaurant so new that a user has never made a card-based purchase there before, or a restaurant not yet established in the map applications used for location data services.
[0059] Figure 3A shows an example of a graphical user interface (GUI) for an unlock-lock application 144 on a mobile device 110. For example, the processor may be able to operate a display device, such as the touchscreen display of the mobile device, to present a graphical user interface with a number of user preferences for setting restrictions on the use of contactless cards. Each user preference 301-305 may include settings based on geographical location, geofenced area, merchant name, price threshold, time threshold, day of the week, time range within a day, zip code, area code, merchant category, product category, etc.
[0060] When the contactless card 101 is tapped on the mobile device 110, the account authentication application 143 sends instructions to the contactless card 101 via the card reader 148 (e.g., via NFC, Bluetooth, RFID, and / or the EMV protocol). In one example, the instructions may specify that encryption be performed using key diversification, as shown in Figure 1A, in which case the account authentication application 143 receives card data 103 from the server 120. In another example, the instructions may specify that the card data 103 be sent to the account authentication application 143 in an NDEF file (e.g., via NFC, Bluetooth, RFID, etc.), in which case the account authentication application 143 receives the card data 103 in the NDEF file directly from the contactless card 101 via the card reader 148. In another example, the instructions may specify that card data 103 be sent to the account authentication application 143 via the EMV protocol, in which case the account authentication application 143 receives card data 103 directly from the contactless card 101 via the EMV protocol. However, in the example where the EMV protocol is used as described, the CVV value is received from the contactless card 101 in the NDEF file and / or from the management application 123. In yet another example, the instructions may specify that the account number 108 be sent to the account authentication application 143 after encryption using key diversification as depicted in Figure 1A, in which case the account authentication application 143 receives a record of account number 108 from the contactless card 101 (which is used after verification of encrypted data 190 by the server 120).
[0061] Figure 3B shows a mobile device 310 presenting a graphical user interface 314 including the selection of user preference settings 311-317. The mobile device may be operable to send the selected user preference settings 311-317 to a server. For example, the server may receive user preference settings from the unlock-lock application of the mobile device. User preference settings 311-317 may include, for example, time settings, user-preferred time and area settings such as allowing card presentation transactions at 9 a.m. within 5 square blocks or half a square mile of the user's location, the user's office or home, area settings, merchant code settings (e.g., coffee shops, restaurants and drugstores only).
[0062] As shown in Figure 3C, the unlock-lock application may be capable of displaying a list of merchants 321-327 on a graphical user interface 314 on the display device 320 (e.g., a touchscreen display) of the mobile device 310. For example, as described above, the mobile device 110 may provide the location of the mobile device to the unlock server 129. More specifically, the unlock server 129 may obtain a location setting from a user preference setting provided via the graphical user interface 313 in Figure 3A. In one example, the location setting may be a radius from a given location (e.g., radius #6 in the graphical user interface 314 in Figure 3B). The given location may be, for example, the location of the mobile device, the user's office, home, a friend's house, a favorite restaurant, a gym, etc. Based on the user preference setting, the unlock server 129 may access a merchant location service such as 149. From the merchant location service 149, an instance of the unlock-lock application 144'' can obtain a list of merchants such as merchant #1-#X based on the obtained location setting and the determined location. An instance of the unlock-lock application 144'' may be operable to generate a list of merchants based on the acquired location settings and the determined location of the mobile device. The generated list of merchants may be transferred to the mobile device 110, for example, via the network 130. In the example of Figure 3C, the mobile device 310 may be operable to present the list of merchants 321-327 in the graphical user interface 324 on the display device 320 of the mobile device 310.
[0063] Figure 4A shows a contactless card 101 / 101' which may include payment cards such as credit cards, debit cards, and / or gift cards. As shown, the contactless card 101 / 101' may be issued by a service provider 405, which is displayed on the front or back of the card 101 / 101'. In some examples, the contactless card 101 / 101' may include an identification card, which is unrelated to and not limited to a payment card. In some examples, the payment card may include a dual-interface contactless card. The contactless card 101 / 101' may include a substrate 410 which may include a single layer or one or more layers made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 / 101' may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, and the contactless card may otherwise conform to the ISO / IEC 14443 standard. However, the contactless card 101 / 101' according to this disclosure may have different characteristics, and it should be understood that this disclosure does not require the contactless card to be implemented as a payment card.
[0064] The contactless card 101 / 101' may also include identification information 415 displayed on the front and / or back of the card, as well as a contact pad 420. The contact pad 420 may be operable to establish contact with another communication device, such as a mobile device 110, a user device, a smartphone, a laptop, a desktop, or a tablet computer. The contactless card 101 may also include a processor circuit, an antenna, and other components not shown in the example in Figure 4A. These components may be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 / 101' may also include a magnetic strip or tape, which may be located on the back of the card (not shown in Figure 4A).
[0065] As shown in Figure 4B, the contact pads 420 of the contactless card 101 / 101' may include a processor circuit 425 for storing and processing information, including a microprocessor 430, a communication interface 431, and memory 420. It will be understood that the processor circuit 425 may include additional components necessary to perform the functions described herein, such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitives, and tamper-proof hardware.
[0066] Memory 420 may be read-only memory, one-write, multiple-read memory, or read / write memory, such as RAM, ROM, or EEPROM, and contactless card 101 / 101' may include one or more of these memories. Read-only memory may be factory-programmable as read-only, or it may be one-time programmable. One-time programmable provides multiple opportunities to read after it has been written once. One-write, multiple-read memory can be programmed after the memory chip has left the factory. Once programmed, memory cannot be rewritten, but it can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can also be read multiple times after leaving the factory.
[0067] Memory 420 may be operable to store one or more applets 440, one or more counters 404, a customer identifier 407, and a virtual account number 408. One or more applets 440 may include one or more software applications operable to run on one or more contactless cards, such as a Java® Card applet. However, it will be understood that applet 440 is not limited to a JavaCard applet, but may instead be any software application operable to run on a contactless card or other device with limited memory. One or more counters 404 may include numeric counters sufficient to store integers. The customer identifier 407 may include a unique alphanumeric identifier assigned to a user of a contactless card 101 / 101', and the customer identifier 407 may distinguish a user of a contactless card 101 / 101' from a user of another contactless card. In some examples, the customer identifier 407 may identify both the customer and the account assigned to that customer, and may further identify the contactless card associated with the customer's account. As mentioned above, account number 408 may include thousands of one-time use virtual account numbers associated with contactless card 101 / 101'.
[0068] The processor and memory elements in the exemplary embodiments described above are described with reference to the contact pad 420, but the disclosure is not limited thereto. It is understood that these elements may be implemented as additional elements in addition to the microprocessor 430 and memory 402 elements located outside the contact pad 420, completely separate from it, or within the contact pad 420.
[0069] In some examples, the contactless card 101 / 101' may include one or more antennas 455. The one or more antennas 455 may be located inside the contactless card 101 / 101' and around the processor circuit 425 of the contact pads 420. For example, the one or more antennas 455 may be integrated with the processor circuit 425, and the one or more antennas 455 may be used with an external booster coil to provide a communication interface 431. In another example, the one or more antennas 455 may be outside the contact pads 420 and the processor circuit 425.
[0070] For example, the coil of the contactless card 101 / 101' may function as the secondary side of an air-core transformer. A terminal such as the card reader 148 of the mobile device 110 in Figure 1 may communicate with the contactless card 101 / 101' by cutting power or by amplitude modulation. The contactless card 101 / 101' may collect data transmitted from a POS terminal (not shown in this example) or card reader 148 using a gap in the contactless card's power connection, which may be functionally maintained through one or more capacitors. The contactless card 101 / 101' may return communication by switching the load on the contactless card's coil via detectable load modulation. The load modulation may be detected by the terminal's coil. More generally, using information stored in the antenna 455, processor circuit 425, and / or memory 420, the contactless card 101 / 101' provides a communication interface 431 that communicates via NFC, Bluetooth, and / or Wi-Fi communication protocols, respectively. If the contactless card 101 / 101' is equipped to provide Bluetooth and Wi-Fi communication, Bluetooth and Wi-Fi communication may be provided via the transceiver 435.
[0071] As described above, the contactless card 101 / 101' may be built on a software platform capable of running on a smart card with limited memory, such as a JavaCard, or on other devices, and one or more applications or applets may be securely executed on it. The applet 440 may be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet 440 may be capable of responding to one or more requests, such as a Near Field Data Exchange request from a reader (e.g., a mobile NFC reader on a mobile device 110), and generating an NDEF message containing a cryptographically secure OTP encoded as an NDEF text tag.
[0072] An example of an NDEF OTP is the NDEF short-record layout (SR=1). In such an example, one or more applet 440 may be able to operate to encode the OTP as a well-known type of text tag of NDEF type 4. In some examples, an NDEF message may contain one or more records. Applet 440 may be able to operate to add one or more static tag records in addition to the OTP record.
[0073] In some examples, one or more applet 440 may be capable of operating to emulate a Radio Automatic Identification (RFID) tag. The RFID tag may include one or more polymorphic tags. In some examples, each time the tag is read, different encrypted data is presented that can indicate the authenticity of the contactless card. Based on one or more applications, the NFC reading of the RFID tag may be processed, the data may be sent to a server such as server 120, and the data may be verified by the server.
[0074] In some examples, the contactless cards 101 / 101' and the server 120 may contain specific data so that the cards can be properly identified. The contactless cards 101 / 101' may contain one or more unique identifiers (not shown). Each time a read operation is performed, the counter 404 may be operable to increment. In some examples, each time data from the contactless cards 101 / 101' is read (for example, by a mobile device 110), the counter 404 is sent to the server for verification, and (as part of the verification) it is determined whether the counter value 404 is equal or not.
[0075] One or more counters 404 may be capable of preventing replay attacks. For example, if a ciphertext is retrieved and replayed, the ciphertext is immediately rejected if counter 404 has been read, used, or passed over. If counter 404 has not been used, it may be replayed. In some examples, a counter incremented on the card is different from a counter incremented for a transaction. Contactless cards 101 / 101' cannot determine the application transaction counter 404 because there is no communication between applets 440 on contactless cards 101 / 101'. In some examples, contactless cards 101 / 101' may include a first applet and a second applet, which may be transaction applets. Each of the first and second applets may include its own counter 404.
[0076] In some examples, counter 404 may be asynchronous with the server, as shown in Figure 1, 120. In some examples, counter 404 may increment to account for accidental reads, such as tilt readings, when initiating a transaction, but the application does not process counter 404. In some examples, when the mobile device 110 is woken up, the card reader 148 (acting as an NFC device in this example) may be enabled, and the mobile device 110 may be able to operate to read available tags, but no action is taken in response to the read.
[0077] To keep counter 404 synchronized, an application such as a background application may be run that can operate to synchronize with a server 120 that detects when the mobile device 110 wakes up and indicates that the read resulting from the detection will next increment counter 404. In another example, a hashed one-time password can be used to allow for a window of missynchronization. For example, within a threshold of 10, counter 404 may be able to operate to advance. However, within different thresholds, for example, within 10 or 10000, a request to perform resynchronization may be processed, which may involve one or more applications requesting the user to tap, gesture, or otherwise indicate through the user's device one or more times. If counter 404 is incrementing in the appropriate order, the user may be able to know that it is.
[0078] The key diversification technique described herein with reference to elements of Figures 1A and 1B, such as counter 104, master key 105, and diversified key 106, is one example of a key diversification technique for encrypted and / or decrypted keys. This exemplary key diversification technique should not be considered limiting to the disclosure, as the disclosure is equally applicable to other types of key diversification techniques.
[0079] During the creation process of contactless cards 101 / 101', two unique encryption keys may be assigned to each card. These encryption keys may include symmetric keys that can be used for both data encryption and decryption. The Triple DES (3DES) algorithm can be used with EMV and is implemented in hardware on contactless cards 101 / 101'. By using a key diversification process, one or more keys can be derived from a master key based on uniquely identifiable information of each entity requiring a key.
[0080] In some cases, to overcome vulnerabilities in the 3DES algorithm, session keys may be derived (e.g., a key unique to each session) but instead of using a master key, unique keys and counters derived from the card can be used as diversification data. For example, each time a contactless card 101 / 101' is used in operation, a different key may be used to generate the message authentication code (MAC) and execute the encryption. This results in triple encryption. The session key may be generated by one or more applets and by using application transaction counters 404 with one or more algorithms (as defined in EMV 4.3 Book 2 a1.3.1 Common Session Key Derivation).
[0081] Furthermore, the counter increment for each card 101 / 101' may be unique, assigned by personalization or algorithmically assigned by some identifying information. For example, a contactless card 101 / 101' ending in an odd number may be able to increment its counter by 2, while a contactless card 101 / 101' ending in an even number may increment its counter by 5. In some examples, the increment may also change by sequentially reading a single card so that the counter repeats as 1, 3, 5, 2, 2, ... A specific sequence or algorithmic sequence may be defined at issuance or at another personalization, or it may be defined from one or more processes derived from a unique identifier. Using a specific sequence or algorithmic sequence can make it difficult for a replay attacker to generalize from a small number of card instances.
[0082] The authentication message may be delivered as the content of a text NDEF record in hexadecimal ASCII format. In another example, the NDEF record may be encoded in hexadecimal format.
[0083] When a contactless card 101 is tapped towards a device running Apple's iOS operating system, such as an iPhone, iPod, or iPad, the contactless card can recognize the iOS operating system and transmit appropriate data to communicate with the device. For example, the terminating contactless card 101 / 101' can provide encrypted identification information necessary to authenticate the card using an NDEF tag, for example, via NFC. Similarly, when a contactless card tap is directed towards a mobile device 110 running the Android operating system, such as an Android smartphone or tablet, the terminating contactless card 101 / 101' can recognize the Android operating system and transmit appropriate data (such as encrypted identification information necessary for authentication by the method described herein) to communicate with the device.
[0084] Figure 5 shows an example of an exemplary computing architecture 500, including a computing system 502 that may be suitable for implementing the various embodiments described above. In various embodiments, the computing architecture 500 may include or be implemented as part of an electronic device. In some embodiments, the computing architecture 500 may be representative of a system that implements, for example, one or more components of system 100. In some embodiments, the computing system 502 may be representative of, for example, the mobile device 110 and the server 120 of system 100. Embodiments are not limited in this context. More generally, the computing architecture 500 can be operated to implement all the logic, applications, systems, methods, devices, and functionalities described herein with reference to Figures 1-6.
[0085] As used in this application, the terms “system,” “component,” and “module” are intended to refer to computer-related entities that are either hardware, a combination of hardware and software, software, or running software, examples of which are provided by the exemplary computing architecture 500. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer. As an example, both an application running on a server and the server can be components. One or more components may reside within a process and / or an execution thread, and components may be localized on one computer and / or distributed between two or more computers. Furthermore, components may be connected communicatively to one another by various types of communication media to coordinate operations. Coordination may include unidirectional or bidirectional information exchange. For example, components may communicate information in the form of signals communicated via a communication medium. Information may be implemented as signals assigned to various signal lines. In such assignments, each message is a signal. However, further embodiments may employ data messages instead. Such data messages can be transmitted across various connections. Illustrative connections include parallel interfaces, serial interfaces, and bus interfaces.
[0086] The computing system 502 includes various common computing elements such as one or more processors, multicore processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, the embodiments are not limited to implementations using the computing system 502.
[0087] As shown in Figure 5, the computing system 502 includes a processor 504, system memory 506, and a system bus 508. The processor 504 can be any of the various commercially available computer processors, such as AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors, and similar processors. Dual microprocessors, multi-core processors, and other multiprocessor architectures can also be used as the processor 504.
[0088] The system bus 508 provides an interface for connecting system components, including but not limited to system memory 506, to the processor 504. The system bus 508 may further be any of several types of bus structures that can interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of various commercially available bus architectures. Interface adapters may connect to the system bus 508 via a slot architecture. Exemplary slot architectures may include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, (Enhanced) Industry Standard Architecture ((E)ISA), Microchannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Enhanced) (PCI(X)), PCI Express, and the International Personal Computer Memory Card Association (PCMCIA).
[0089] The system memory 506 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable memory (PROM), erasable ROM (EPROM), electrically erasable and writable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon oxide-silicon nitride-silicon oxide (SONOS) memory, magnetic or optical cards, device arrays such as RAID drives, solid-state memory (e.g., USB memory, solid-state drives (SSDs)), and any other type of storage medium suitable for storing information. In the illustrated example shown in Figure 5, the system memory 506 may include non-volatile memory 510 and / or volatile memory 512. The basic input / output system (BIOS) may be stored in the non-volatile memory 510.
[0090] The computing system 502 may include one or more types of computer-readable storage media in the form of low-speed memory units, such as an internal (or external) hard disk drive (HDD) 514, a magnetic floppy disk drive (FDD) 516 that reads from or writes to a removable magnetic disk 518, and an optical disk drive 520 that reads from or writes to a removable optical disk 522 (e.g., a CD-ROM or DVD). The HDD 514, FDD 516, and optical disk drive 520 can be connected to the system bus 508 by an HDD interface 524, an FDD interface 526, and an optical drive interface 528, respectively. The HDD interface 524 for external drive implementation may include at least one or both of the Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 502 is generally operable to implement all the logic, systems, methods, devices, and functions described herein with reference to Figure 1-7.
[0091] The drive and associated computer-readable media provide volatile and / or non-volatile storage devices such as data, data structures, and computer-executable instructions. For example, the drive and memory units 510, 512 may store an operating system 530, one or more application programs 532, other program modules 534, and numerous program modules including program data 536. In one example, the one or more application programs 532, other program modules 534, and program data 536 may include, for example, various applications and / or components of system 100, such as the operating system 142, an account authentication application 143, an unlock-lock application 144, other applications 145, and an administration application 123.
[0092] The user can input commands and information to the computing system 502 via one or more wired / wireless input devices, such as a keyboard 538 and a pointing device such as a mouse 540. Other input devices may include microphones, infrared (IR) remote controls, radio frequency (RF) remote controls, gamepads, stylus pens, card readers, dongles, fingerprint readers, gloves, graphics tablets, joysticks, keyboards, retina readers, touchscreens (e.g., capacitive, resistive, etc.), trackballs, trackpads, sensors, styluses, etc. These and other input devices are often connected to the processor 504 via an input device interface 542 connected to the system bus 508, but can also be connected via other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, or an IR interface.
[0093] The monitor 544 or other type of display device is also connected to the system bus 508 via an interface such as a video adapter 546. The monitor 544 may be internal or external to the computing system 502. In addition to the monitor 544, the computer typically includes other peripheral output devices such as speakers and printers.
[0094] The computing system 502 can operate in a networked environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computers 548. The remote computers 548 may be workstations, server computers, routers, personal computers, portable computers, microprocessor-based entertainment devices, peer devices, or other common network nodes, typically including many or all of the elements described in relation to the computing system 502, although for brevity only a memory / storage device 550 is illustrated. The logical connections depicted include wired / wireless connections to a local area network (LAN) 552 and / or a larger network, such as a wide area network (WAN) 554. Such LAN and WAN networking environments are common in offices and enterprises, facilitating enterprise-scale computer networks such as intranets, all of which can connect to global communication networks such as the Internet. In this embodiment, the network 130 in Figure 1 is one or more of the LAN 552 and WAN 554.
[0095] When used in a LAN networking environment, the computing system 502 is connected to the LAN 552 via a wired and / or wireless network interface or adapter 556. The adapter 556 can facilitate wired and / or wireless communication to the LAN 552 and may also include a wireless access point placed on it for communication with the wireless capabilities of the adapter 556.
[0096] When used in a WAN networking environment, the computing system 502 may include a modem 558, or be connected to a communication server on the WAN 554, or have other means of establishing communication on the WAN 554, such as via the Internet. The modem 558, which may be internal or external and be a wired and / or wireless device, connects to the system bus 508 via an input device interface 542. In a network environment, program modules, or parts thereof, written in relation to the computing system 502 may be stored in a remote memory / storage device 550. The network connections shown are illustrative, and it will be understood that other means of establishing communication links between computers may be used.
[0097] Computing system 502 is capable of communicating with wired and wireless devices or entities using IEEE 802 family standards, such as wireless devices configured to operate wirelessly (e.g., using IEEE 802.16 wireless modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMAX, and Bluetooth® wireless technologies. Therefore, communication may have a predetermined structure, like a conventional network, or it may simply be ad-hoc communication between at least two devices. Wi-Fi networks use wireless technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and high-speed wireless connectivity. Wi-Fi networks can be used to connect computers to each other, to the Internet, and to wired networks (using IEEE 802.3 related media and features).
[0098] Figure 6 shows an example of a mobile device that can be used to implement the techniques and processes described with reference to the examples in Figures 1-5.
[0099] The mobile device 611 may be a smartphone that includes a display device such as a touchscreen display 620. The touchscreen display 620 may be connected to a processor 612 and be operable to present screen content and receive input via a touch sensor 622. Examples of touchscreen mobile devices such as the mobile device 611 may include (but are not limited to) smartphones, personal digital assistants (PDAs), tablet computers, smartwatches, or other portable devices. However, the structure and operation of the mobile device 611 utilizing a touchscreen are provided as examples, and the subject art described herein is not intended to be limited thereto. For the purposes of this discussion, Figure 6 shows an example of a mobile device 611 having a touchscreen display for displaying content and receiving user input as (or as part of) a user interface.
[0100] There are various ways in which the mobile device 611 may operate to obtain information about the device's current location. In our example, the mobile device 611 includes a Global Positioning System (GPS) receiver 632 and an associated antenna 634. GPS is a space-based satellite navigation system that provides location and time information at virtually any location on Earth. The rechargeable battery 629 can supply enough power to power the various components of the mobile device 611.
[0101] Mobile devices supporting the sales notification applications and technologies described herein may include a variety of different types of user interface elements. For the purposes of discussion, in the example of a smartphone mobile device shown in Figure 6, the user interface elements of the mobile device 611 include a touchscreen display 620 (hereinafter also referred to here as “touchscreen 620” or “display 620”). For output purposes, the touchscreen 620 includes a display screen such as a liquid crystal display (LCD). For input purposes, the touchscreen display 620 includes a plurality of touch sensors 622. Other interface elements may include a keypad containing one or more keys 630. For example, the keypad may be implemented in hardware as a T9 or QWERTY keyboard of the mobile device 611, and the keys 630 may correspond to the physical keys of such a keyboard. Alternatively, the keys 630 (and keyboard) of the mobile device 611 may be implemented as “soft keys” of a virtual keyboard graphically represented in an appropriate arrangement via the touchscreen display 620. Soft keys presented on the touchscreen display 620 may allow the user of the mobile device 611 to invoke the same user interface functions as physical hardware keys. In some implementations, the microphone 602 and speaker 604 may also be used as additional user interface elements for voice input and output, as well as for some functions relating to processing related to interaction with the sales notification application 647, as described herein. In a further example, the sales notification application 647 may, in response to accessing contacts stored in the mobile device memory 614, present a prompt to a user interface such as 425 in Figure 4B to send a request to one or more of the contacts to join an affinity reward group.
[0102] For output, the touchscreen display 620 is a display device used to present information (e.g., text, video, graphics, or other visible content) to the user of the mobile device 611. The processor 612 controls the visible display output on the LCD or other display element of the touchscreen display 620 via the display driver 624 to present various visible outputs to the device user. Furthermore, output devices may include, for example, a speaker 604, a vibration mechanism 631, and the touchscreen display 620.
[0103] Generally, the touchscreen display 620 and touch sensors 622 (and, if included, one or more keys 630) are used to provide a text and graphical user interface to the mobile device 611. In one example, the touchscreen display 620 provides content that can be displayed to the user on the mobile device 611. The touchscreen display 620 also allows the user to directly interact with the content that can be displayed in the content display area by touching the clean surface, typically a finger or an instrument such as a stylus.
[0104] As shown in Figure 6, the mobile device 611 also includes a touch detection circuit 628 connected to a touch sensor 622 to detect the occurrence and relative position / location of each touch on the content display area of the touchscreen display 620. In this example, the touch detection circuit 628 can be operated to provide touch position information to the processor 612 based on user input received via the touch sensor 622. In some implementations, the processor 612 can be operated to associate the touch position information with specific content displayed within the content display area of the touchscreen display 620. The touch position information captured by the touch detection circuit 628 and provided to the processor 612 may include, but is not limited to, coordinates that identify the position of each detected touch on the display area of the touchscreen display 620 and a timestamp corresponding to each detected touch position.
[0105] In the example shown in Figure 6, the mobile device 611 includes a microphone 602 for voice signal input and a speaker 604 for voice signal output. The microphone 602 and speaker 604 are commutatically connected to a voice or voice encoder / decoder (vocoder) 606. In the case of a voice phone, for example, the vocoder 606 provides bidirectional conversion between an analog voice signal representing voice or other sound and a digital sample at a compressed bitrate that conforms to the digital protocol of radiotelephone network communication or voice over packet (e.g., Internet Protocol) communication. The vocoder, speaker, and microphone may also be used as elements of a user interface during other operations of the device, including certain types of transactional communication.
[0106] Furthermore, as shown in Figure 6, the mobile device 611 includes at least one transceiver (XCVR) 608, which may be a digital transceiver for digital wireless communication over a wide-area radio mobile communication network, although the mobile device 611 may include additional digital or analog transceivers (not shown). The transceiver 608 conforms to one or more of the various digital wireless communication standards used by modern mobile networks. Examples of such transceivers include, but are not limited to, transceivers capable of operating according to Code Division Multiple Access (CDMA) and 3GPP® (Third Generation Partnership Project) network technologies, including 3GPP® Type 2 (or 3GPP® 2) and 3GPP® Long-Term Evolution (LTE), sometimes referred to as "4G". For example, the transceiver 608 provides two-way wireless communication of information, including digitized voice signals, still images and / or video signals, web page information and web-related inputs for display, and various types of mobile message communication between the mobile device 611 and the transceiver 608. The transceiver 608 is connected to the antenna 609 via a radio frequency (RF) transmit / receive amplifier (not shown). The transceiver 608 can also support various types of mobile messaging services, such as Short Message Service (SMS), Extended Message Service (EMS), and / or Multimedia Messaging Service (MMS).
[0107] In one example, the transceiver 608 may be connected to the processor 612 and be capable of operating to exchange communications. The processor 612 of the mobile device 611 may further operate to perform additional functions, including the ability to use the transceiver to establish a connection with a server, such as the affinity exchange server 45 in Figure 1, and exchange communications. Through the connection with the server, the mobile device 611 may be able to obtain various information, such as affinity reward exchange rates, neutral affinity reward values, and affinity aggregate account-related information. The processor in the execution of the sales notification application 647 may implement the embodiments described above with reference to Figure 1-5.
[0108] The mobile device 611 may also include a Wi-Fi transceiver 610 and an associated antenna 633. Although Wi-Fi is used as an example here, the transceiver 610 may take the form of any available bidirectional wireless local area network receiver of a type compatible with one or more standard protocols for communication implemented in a wireless local area network, such as one of the Wi-Fi standards under IEEE 802.11 and / or WiMAX.
[0109] The mobile device 611 further includes a processor 612 and functions as a programmable controller of the mobile device 611 by configuring the mobile device 611 to perform various operations, for example, according to instructions or programming that can be executed by the processor 612. For example, such operations may include various general operations of the mobile device 611 and operations related to adjusting screen brightness, as described herein. Flash memory 614 may be used to store programming or instructions to be executed by the processor 612, for example. Depending on the type of device, the mobile device 611 stores and runs an operating system on which a particular application can be run. Examples of operating systems include Android, Apple iOS, Microsoft Windows OS, Bada, Tizen, Symbian OS, Blackberry OS, etc. Flash memory 614 may also be used to store mobile configuration settings for different mobile applications or services that can be run on the mobile device 611 (using the processor 612). The mobile device 611 may also include non-volatile random access memory (RAM) 616 for working data processing memory. The RAM memory 616 or storage device 637 may be connected to the processor 612 and be operable to store programming code that can be executed by the processor 612.
[0110] Alternatively, or additionally, the application may be stored in a storage device 637, which may be solid memory storage or other memory device suitable for storing the application. In one example, the storage device 637 may be a separate chip that includes tamper-proof storage and execution memory and is capable of operating to communicate with an operating system. The storage device 637 may store, for example, instances of the sales notification application 647 for processing receipt data, communicating with one or more services or servers, and processing as described with reference to the example in Figure 1-3. Other applications such as 642 and 644 may also be stored in the storage device 637.
[0111] The logic implemented by the processor 612 of the mobile device 611 constitutes the processor 612 to control the various functions implemented by the mobile device 611. While the processor logic can be implemented in various ways, in the presented example, the processor logic is implemented by programming for execution by the processor 612.
[0112] Various examples may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software elements, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computed code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. Whether or not an embodiment is implemented using hardware and / or software elements may vary depending on any number of factors such as desired computing speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.
[0113] One or more aspects of at least one embodiment may be implemented by representative instructions stored in a machine-readable medium representing various logics within a processor, which, when read by a machine, can cause the machine to produce logic for performing the techniques described herein. Such representations, known as "IP cores," may be stored in a tangible machine-readable medium and supplied to various customers or manufacturing facilities so that they can be loaded into manufacturing machines that produce logic or processors. Some examples may be implemented using a machine-readable medium or article which may store instructions or sets of instructions that, when executed by a machine, can cause a machine to perform a method and / or operation according to one example. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage medium and / or storage device, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disks, floppy disks, compact disc read-only memory (CD-ROM), compact disc recordable (CD-R), compact disc rewritable (CD-RW), optical discs, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital versatile discs (DVDs), tapes, cassettes, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, cryptographic code, etc., implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.
[0114] The description of the embodiments set forth herein is presented for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit the disclosure to the exact form disclosed herein. Many modifications and variations are possible in light of the disclosure. The scope of the disclosure is intended to be limited not by this detailed description, but rather by the claims attached herein. Future applications claiming priority to this application may claim the disclosed subject matter in different ways and may generally include any set of one or more limitations disclosed herein in various ways or otherwise indicated herein.
Claims
1. Display devices and, A processor circuit capable of displaying a graphical user interface on the aforementioned display device, A transceiver connected to the aforementioned processor circuit and capable of communicating with an external device, A card reading circuit connected to the aforementioned processor circuit and capable of transmitting and receiving signals within a signal field, A memory connected to the aforementioned processor circuit and capable of storing an unlock-lock application, A device equipped with, When the unlock-lock application is executed by the processor circuit, the processor circuit will: The card reading circuit receives encrypted data generated based on an encryption algorithm and diversified keys from a contactless card that is locked to prevent the use of the presented transaction. Transfer of the encrypted data to the authentication server for authentication and unlocking of the contactless card, The contactless card has been unlocked for use in the current transaction, and the receipt of an unlock instruction, including that the contactless card has been authenticated. When unlocked, the user's preferences regarding the use of the contactless card in payment card transactions are identified, and The graphical user interface displayed on the display device presents an expression of the preferences of the identified user of the contactless card. A device that includes instructions to execute a command.
2. When the aforementioned instruction is executed by the processor circuit, the memory capable of storing the aforementioned instruction is used to send the processor circuit to the processor circuit. Operate a display device to present a graphical user interface that includes the preferences of multiple users for setting restrictions on the use of the contactless card. The apparatus according to claim 1, which includes an instruction to perform an action.
3. When the memory is executed by the processor circuit, the processor circuit will Through the graphical user interface, the user's preference for setting restrictions on the use of the contactless card is presented with a list of multiple restrictions on the use of the contactless card. The apparatus according to claim 1, which is capable of storing an instruction to execute.
4. The aforementioned usage restrictions are: Includes one or more of the following: geographical location, geofenced area, merchant name, price threshold, time threshold, day of the week, time range within a day, postal code, area code, merchant category, or product category. The apparatus according to claim 3.
5. When the memory is executed by the processor circuit, the processor circuit will Receiving the user's preference selection for setting restrictions on the use of the contactless card via the graphical user interface, The apparatus according to claim 3, which is capable of storing an instruction to execute.
6. The application further includes a position application capable of determining the position of the device, The aforementioned memory is Multiple user preference settings for the unlock-lock application, When executed by the aforementioned processor circuit, the processor circuit, From the plurality of user preference settings stored in the memory, the location preference setting is obtained. From the position application executed by the processor circuit, acquire position data. The acquired location preference settings and acquired location data are transmitted to the unlock server. Based on the acquired location data, a list of affiliated stores that meet the acquired location preference settings is received, and Presentation of the list of affiliated stores on the graphical user interface on the display device, The apparatus according to claim 1, which is capable of storing additional instructions for executing the
7. An output device connected to the aforementioned processor circuit and capable of generating sound or vibration, The position of the device can be determined and the position application can be performed by the processor circuit, further including The memory is capable of storing multiple user preference settings for the unlock-lock application, and when executed by the processor circuit, the processor circuit, Based on the location provided by the aforementioned location application, when a card presentation transaction is imminent, a decision is made requesting a card unlock action, and via the output device or the display device, generation of a notification indicating a request for the card unlock operation, It can store additional instructions to execute. The apparatus according to claim 1.
8. The aforementioned memory is Multiple user preference settings for the unlock-lock application, When executed by the aforementioned processor circuit, the processor circuit, The graphical user interface presents a user preference settings menu for the user to select whether to allow the use of the contactless card in card presentation transactions when unlocked. Receiving instructions to select one or more of the user preference settings presented in the menu, and Instructions for user preference settings are provided to a server capable of managing the user preferences of the unlock-lock application as a selection for authorizing the unlocked contactless card in a card presentation transaction. Additional instructions to execute, It can store The apparatus according to claim 1.
9. The instruction to select one or more of the aforementioned user preference settings is: A time range selection that identifies the time range in which the contactless card is unlocked, In card presentation transactions, the selection of a radius to determine the distance from the user's location where contactless use is permitted, or Merchant code selection identifies the category of goods or services offered by the merchant to which the selected merchant code is assigned, The apparatus according to claim 8, including the following:
10. A contactless card including a processor, memory, and a communication interface capable of operating to support at least one of the following communication protocols: Near Field Communication, Bluetooth, or Wi-Fi. A mobile device including a mobile device processor, mobile device memory, transceiver, display device, and card reader circuitry, A system equipped with, The aforementioned processor, Using cryptographic algorithms and diversified keys, encrypted data is generated. The communication interface is operable to transmit a signal containing encrypted data that can be used to authenticate the contactless card, The card reader circuit is operable to communicate with the contactless card via the communication interface, The mobile device memory stores programming code including an instance of the unlock-lock application, and the programming code, when executed by the mobile device processor, The card reader circuit receives a signal containing encrypted data emitted from the contactless card. The encrypted data is transmitted via the transceiver for authentication and unlocking of the contactless card. Upon receiving an unlock instruction indicating that the contactless card has been unlocked, When unlocked for use in card presentation transactions, the system identifies the user's preference for limited use of the contactless card, The preferences of the identified user of the unlocked contactless card are displayed on a graphical user interface shown on the display device. The function is to be executed by the mobile device processor. system.
11. The processor of the contactless card further, It is capable of generating diversified keys using a master key and a counter value stored in the memory of a contactless card. The counter value is a count of either the number of times the contactless card was used for a card presentation transaction or the number of times the contactless card was authenticated. The system according to claim 10.
12. It further includes an authentication server connected to a memory that stores cryptographic algorithms and diversified keys, and capable of operating to execute programming code, When executing the aforementioned programming code, The mobile device authorized to communicate with the authentication server receives encrypted data. The encrypted data is decrypted, The decrypted data is verified, and the contactless card is authenticated. Based on the verification of the decrypted data, an unlock instruction indicating the unlocking of the contactless card is generated. The aforementioned unlock instruction is output to the mobile device. It is possible to operate in this manner. The system according to claim 10.
13. The system further includes an unlock-lock server that hosts an instance of the unlock application capable of managing user settings for the unlock application, The user preference settings are provided by the mobile device processor executing the instance of the unlock application stored in the mobile device's memory. A location application capable of determining the location of the mobile device is stored in the mobile device's memory. The aforementioned mobile device processor is Determine the location of the aforementioned mobile device, The determined location of the mobile device is operable to provide the unlock-lock server, The aforementioned unlock-lock server When the contactless card is unlocked, the user preference setting is received from the mobile device as an option indicating that the use of the contactless card is permitted in the card presentation transaction. The determined location of the mobile device is obtained from the mobile device. From the aforementioned user preference settings, obtain the position setting, which is the radius from a predetermined position. Based on the aforementioned user preference settings, access the merchant location service, Based on the acquired location setting and the determined location, the merchant list is obtained from the merchant location service. Based on the acquired location settings and the determined location of the mobile device, a list of affiliated stores is generated. It is possible to transfer the generated list of affiliated stores to the mobile device. The system according to claim 10.
14. A payment account component that is operable to authorize purchases involving contactless cards and is operable to maintain a maximum transaction amount threshold used to authorize or reject such purchases involving contactless cards, An unlock-lock server capable of managing user preferences for an unlock-lock application running on the mobile device processor, Furthermore, The aforementioned unlock-lock server The mobile device receives a user preference setting indicating that permission to use the unlocked contactless card is selected in the card presentation transaction. From the user preference settings mentioned above, the maximum transaction amount threshold is derived. The maximum transaction amount threshold obtained from the user preference settings is transferred to the payment account component. The maximum transaction amount threshold is transferred to the mobile device and displayed on the graphical user interface. It is possible to operate in this manner. The system according to claim 10.
15. When unauthenticated, the contactless card is locked and cannot be used for card presentation transactions. The authenticated contactless card is valid and unlocked so that it can be used in card presentation transactions. The system according to claim 10.
16. A non-temporary computer-readable storage medium that embodies computer-readable program code within it, The computer-readable program code is executable by a processor circuit, and the processor circuit, The card reader circuit receives encrypted data generated based on an encryption algorithm and diversified keys from the communication interface of a contactless card, which is locked to prevent its use in card presentation transactions. The encrypted data is transferred to the authentication server, enabling the unlocking of the contactless card. The contactless card has been unlocked for use in card presentation transactions, and has received an unlock instruction which is a confirmation of encrypted data. Identify the permitted restrictions on the use of the contactless card for completing payment card transactions. The graphical user interface displayed on the display device should be configured to show the unlock status for use and the usage restrictions of identified authorized contactless cards. Non-temporary computer-readable storage medium.
17. The processor circuit further includes computer-readable program code that can be executed by the processor circuit, The aforementioned processor circuit, The display device is driven to perform actions that present a graphical user interface with multiple user preferences for setting restrictions on the use of the contactless card. The non-temporary computer-readable storage medium according to claim 16.
18. The processor circuit further includes computer-readable program code that can be executed by the processor circuit, The aforementioned processor circuit, Through a graphical user interface, when unlocked, the system presents multiple usage restrictions for the contactless card, allowing the user to select their preferences for the contactless card. The graphical user interface receives a selection of at least one of the plurality of usage restrictions, When unlocked, the system is configured to save the selection as the user preference for the contactless card. The aforementioned usage restrictions include one or more of the following: geographical location, geofenced area, merchant name, price threshold, time threshold, day of the week, time range within a day, postal code, area code, merchant category, or product category. The non-temporary computer-readable storage medium according to claim 16.
19. The processor circuit further includes computer-readable program code that can be executed by the processor circuit, The aforementioned processor circuit, Obtain location preference settings from multiple user preference settings, From a location application, obtain location data including location, timestamp, and speed. The acquired location preference settings and the acquired location data are transmitted to the unlock-lock server. Based on the acquired location data, receive a list of affiliated stores that satisfy the acquired location preference settings. The graphical user interface of the aforementioned display device is configured to display a list of affiliated stores. The non-temporary computer-readable storage medium according to claim 16.
20. The processor circuit further includes computer-readable program code that can be executed by the processor circuit, The aforementioned processor circuit, Based on location data provided by the location application, if a card presentation transaction is imminent, it is determined that a card unlock action has been requested. Generate an instruction to generate a notification indicating a request for a card unlock operation, The system is configured to output an alert signal that can be operated to activate an output device or a display device, in accordance with the generated command. The non-temporary computer-readable storage medium according to claim 19.