Tap the card to securely generate card data to copy to the clipboard.

A contactless card system generates encrypted data for verification, allowing secure and automated entry of virtual account details into payment forms, addressing entry errors and security risks.

JP2026123257APending Publication Date: 2026-07-29CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
CAPITAL ONE SERVICES LLC
Filing Date
2026-05-07
Publication Date
2026-07-29

AI Technical Summary

Technical Problem

Users face difficulties in accurately entering long account identifiers for payment cards, and existing systems restrict programmatically copying such data, leading to security risks and inefficiencies.

Method used

A system that uses a contactless card to generate encrypted data, which is verified by an authentication server, allowing generation of a virtual account number, expiration date, and CVV, which can be copied to the clipboard for secure and automated entry into payment forms.

Benefits of technology

Enhances security and efficiency by enabling secure, automated entry of card data without manual input, protecting the actual account number and overcoming operating system restrictions on data access.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 2026123257000001_ABST
    Figure 2026123257000001_ABST
Patent Text Reader

Abstract

The present invention provides a device, method, and non-temporary computer-readable storage medium for tapping a contactless card to securely generate card data to be copied to a clipboard. [Solution] The URL of the form containing the payment field contains encrypted data generated based on the private key of the contactless card. The mobile device sends the encrypted data to the authentication server, the authentication server decrypts the encrypted data based on the private key, the mobile device receives a virtual account number from the virtual account number server, receives the expiration date and card verification value (CVV), and copies the virtual account number to the operating system (OS) clipboard. The OS pastes the virtual account number from the clipboard into the payment field of the form in the web browser and outputs a notification containing the expiration date and CVV associated with the virtual account number.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this specification generally relate to computing platforms, and more specifically, to tapping a card on a computing device to securely generate card data that can be copied to the clipboard of the computing device.

[0002] Related Applications This application claims priority to U.S. Patent Application No. 16 / 265,937, entitled "Tapping of a Card to Securely Generate Card Data for Copying to a Clipboard," filed on February 1, 2019. The content of the foregoing application is hereby incorporated by reference in its entirety.

Background Art

[0003] Account identifiers for payment cards are often long numbers and / or strings. Therefore, it is difficult for users to manually enter the account identifier correctly. In fact, users often make mistakes and enter incorrect account identifiers into a computing interface (e.g., a payment interface). Furthermore, a security risk has arisen for account identifiers because a process has been developed to allow a camera to capture and identify the account identifier entered into a device. Additionally, certain operating systems restrict the ability to access identifiers stored on contactless cards. This blocks conventional attempts to programmatically copy and / or paste account identifiers.

Summary of the Invention

[0004] Embodiments disclosed herein provide a system, method, article, and computer-readable medium for tapping a contactless card to securely generate card data to be copied to a clipboard. For example, a web browser running on a processor circuit may output a form comprising payment fields. A uniform resource locator (URL) may be received from the contactless card's communication interface, and the URL may comprise encrypted data generated by the contactless card based at least partially on the contactless card's private key stored in the contactless card's memory. An application running on the processor circuit may send the encrypted data to an authentication server, which verifies the encrypted data by decrypting it based at least partially on the contactless card's private key stored in the authentication server's memory. Based on the authentication server's verification of the encrypted data, the application may receive a virtual account number from a virtual account number server. The application may receive an expiration date associated with the virtual account number and a card verification value (CVV) associated with the virtual account number. The application may copy the virtual account number to the clipboard of an operating system (OS) running on the processor circuit. The OS may paste the virtual account number from the clipboard into the payment field of a web browser form. The OS may output a notification with the expiration date and CVV associated with the virtual account number. [Brief explanation of the drawing]

[0005] [Figure 1A] This document illustrates an embodiment of a system for tapping a contactless card to securely generate card data to be copied to the clipboard. [Figure 1B] This document illustrates an embodiment of a system for tapping a contactless card to securely generate card data to be copied to the clipboard. [Figure 1C]This document illustrates an embodiment of a system for tapping a contactless card to securely generate card data to be copied to the clipboard. [Figure 2A] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 2B] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 2C] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 2D] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 3A] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 3B] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 3C] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 3D] This example demonstrates an embodiment in which a contactless card is tapped to securely generate card data to be copied to the clipboard. [Figure 4] This shows an embodiment of the first logic flow. [Figure 5] This shows a second embodiment of the logic flow. [Figure 6] This shows an embodiment of the third logical flow. [Figure 7] This shows an embodiment of the computing architecture. [Modes for carrying out the invention]

[0006] Embodiments disclosed herein provide a secure technique for generating card data (e.g., account number, expiration date, customer billing address, shipping address, and / or card verification value (CVV)) that can be copied to the clipboard of a computing device using a contactless card. Generally, a contactless card can enter the communication range of a computing device, for example, via a tap gesture. In doing so, the contactless card generates a Uniform Resource Locator (URL), which is transmitted to the computing device. The URL may contain data used by an authentication server as part of the verification process. For example, the URL may contain encrypted data that is decrypted by the server as part of the verification process. As another example, the URL may contain a unique identifier associated with the contactless card that is used by the authentication server as part of the verification process. Once verified, the authentication server may instruct a virtual account number server to generate card data for the account associated with the contactless card. The card data may include a virtual account number, expiration date, and CVV. The generated card data can then be transmitted to the computing device. In some embodiments, account owner information (e.g., name, billing address, and / or shopping address) can also be transmitted to the computing device. A computing device may copy at least one element of card data and / or account owner information (e.g., name, billing address, and / or shopping address), such as a virtual account number, expiration date, and / or CVV, to the clipboard. Once copied to the clipboard, the data may be copied to the corresponding fields in forms in a web browser and / or other applications. Furthermore, it may output a notification containing one or more elements of the generated card data and / or account owner information. The notification may allow the user to copy other elements of the data to the clipboard and paste them into the payment fields of the form.

[0007] As an advantage, the embodiments disclosed herein improve the security of all devices and associated data. For example, some operating systems may restrict access to data stored on contactless cards, and / or certain types of data stored on contactless cards. Therefore, conventional techniques for copying and / or automatically entering card data do not work correctly. However, advantageously, the embodiments disclosed herein enable card data to be securely generated, transmitted, copied, and / or automatically entered on any type of operating system. Furthermore, conventional approaches require users to manually enter card data into forms. However, doing so could allow other users or devices to capture card data while the user is entering it into the form. The security of card data is enhanced because users are no longer required to manually enter card data into forms. In addition, verification performed by the server provides an additional safeguard to ensure that the correct card data is entered into the form. Furthermore, since conventional solutions require users to enter the actual account number of the contactless card into the form, generating a virtual card number and entering it into the form protects the security of the actual account number of the contactless card.

[0008] Referring generally to the notation and nomenclature used herein, one or more parts of the following detailed descriptions may be presented relating to program procedures performed on a computer or a network of computers. The descriptions and representations of these procedures are intended to convey to those skilled in the art in the most effective way to the substance of their work. Procedures are generally considered to be a set of self-consistent operations leading to a desired result. These operations are those that require the physical manipulation of physical quantities. Usually, but not always, these quantities take the form of electrical, magnetic, or optical signals that can be stored, transferred, combined, compared, and otherwise manipulated. For reasons of common use, it may be convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.

[0009] Furthermore, these operations are often referred to in terms such as addition or comparison, and these are generally associated with intelligent calculations performed by human operators. However, in any of the calculations described herein that form part of one or more embodiments, such ability of a human operator is not required, or in most cases, undesirable. Rather, these calculations are machine calculations. Useful machines for performing the calculations of various embodiments include digital computers selectively activated or configured by computer programs stored therein, written in accordance with the teachings herein, and / or devices or digital computers specifically constructed for the required purpose. Various embodiments also relate to devices or systems for performing these calculations. These devices may be specifically constructed for the required purpose. The structures required for these various machines will become apparent from the given description.

[0010] Here, we refer to the drawings. Here, similar reference numbers are used throughout to refer to similar elements. In the following description, many specific details are given for illustrative purposes to fully understand them. However, it will be apparent that novel embodiments can be implemented without these specific details. In other examples, well-known structures and devices are shown in block diagram form to facilitate their description. The intent is to cover all modifications, equivalents, and alternatives within the claims.

[0011] Figure 1A shows a schematic diagram of an exemplary system 100 corresponding to the disclosed embodiment. As shown, system 100 includes one or more contactless cards 101, one or more mobile devices 110, an authentication server 120, and a virtual account number server 140. The contactless card 101 represents any type of payment card, such as a credit card, debit card, ATM card, or gift card. The contactless card 101 may have one or more communication interfaces 150, such as a radio frequency identification (RFID) chip, configured to communicate with the mobile device 110 via NFC, the EMV standard, or other short-range protocols in wireless communication. While NFC is used as an example of a communication protocol, this disclosure is equally applicable to other types of wireless communication, such as the EMV standard, Bluetooth®, and / or Wi-Fi. The mobile device 110 represents any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop, or portable gaming device. Servers 120 and 140 represent any type of computing device, such as servers, workstations, computing clusters, cloud computing platforms, and virtualized computing systems.

[0012] As shown, the memory 111 of the mobile device 110 contains an instance of an operating system (OS) 112. Examples of operating systems 112 include the Android® OS, iOS®, Linux®, and Windows® operating systems. As shown, the OS 112 includes an account application 113, a clipboard 114, and a web browser 115. The account application 113 allows the user to perform various account-related operations, such as viewing account balances, purchasing items, and / or processing payments. In some embodiments, the user must authenticate using authentication credentials to access the account application 113. For example, authentication credentials may include a username and password, biometric credentials, etc. In some embodiments, an authentication server 120 may provide the necessary authentication, as will be described in more detail below. The web browser 115 is an application that allows the mobile device 110 to access information over a network 130 (e.g., over the Internet). For example, a user may use the web browser 115 to make a purchase from a vendor's website. A web browser 115 is an example of an application used to access information over a network 130 (for example, to make a purchase). The use of a web browser as a reference example in this specification should not be considered limiting to the disclosure, for the disclosure is equally applicable to other types of applications used to access information over a network, such as applications provided by vendors that enable users to make purchases.

[0013] When using a web browser 115 (or other application), a user may encounter a form containing one or more payment fields. Traditionally, users have had to manually enter their card number, expiration date, and CVV. While some mobile operating systems can automatically fill in such data on forms, others have limitations in automatically filling in such data. Advantageously, embodiments disclosed herein solve such problems by leveraging a contactless card 101 to trigger the generation of a virtual account number, expiration date, and / or CVV that can be copied to the clipboard 114 of the OS 112.

[0014] More specifically, a user may tap a contactless card 101 against a mobile device 110, thereby bringing the contactless card 101 close enough to the card reader 118 of the mobile device 110 to enable NFC data transfer between the communication interface 150 of the contactless card 101 and the card reader 118 of the mobile device 110. In some embodiments, the mobile device 110 may trigger the card reader 118 via an Application Programming Interface (API) call. In one example, the mobile device 110 triggers the card reader via an API call in response to a user tapping or selecting an element of a user interface, such as a form field. Furthermore, and / or alternatively, the mobile device 110 may trigger the card reader 118 based on periodically polling it. More generally, the mobile device 110 may trigger the card reader 118 to communicate using any viable method. After communication is established between the mobile device 110 and the contactless card 101, the contactless card 101 generates a message authentication code (MAC) ciphertext. In some examples, this may occur when the contactless card 101 is read by the account application 113. In particular, this may occur during readings such as NFC reading of Near Field Radio Data Interchange (NDEF) tags, which may be created according to the NFC Data Interchange format.

[0015] More generally, an applet 103 running on the processor (not shown) of the contactless card 101 generates data via the communication interface 150 and transmits it to the mobile device 110. In some embodiments, the data generated by the contactless card 101 may include a URL. This URL may be directed to the authentication server 120 or another URL associated with the entity issuing the contactless card 101. The URL may further include a universal link URL that opens a local resource (e.g., a page in the account application 113). The URL may further include data (e.g., parameters) used by the authentication server 120 to verify the data generated by the contactless card 101.

[0016] For example, the applet 103 of the contactless card 101 may use an encryption algorithm to generate an encrypted payload based at least in part on a secret key 104 stored in the memory 102 of the contactless card 101. In general, the applet 103 may use any type of encryption algorithm and / or system to generate an encrypted payload, and the use of a particular encryption algorithm as an example herein should not be considered limiting to the disclosure. Encryption algorithms may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, crypto-based message authentication code (CMAC) algorithms, and the like. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. In some embodiments, the applet 103 may use key diversification techniques to perform encryption to generate an encrypted payload. An example of key diversification techniques is described in U.S. Patent Application No. 16 / 205,119, filed November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety. The applet 103 of the contactless card 101 may include an encrypted payload as a URL parameter.

[0017] As another example, the applet 103 of the contactless card 101 may include several other strings used to identify the contactless card 101 in the URL. For example, the URL may include a subset of the digits (or characters) of the account number associated with the contactless card 101. For example, if the account number is 16 digits long, the applet 103 of the contactless card 101 may include 4 digits of the account number as a parameter of the URL. The account number can be any type of account number, such as a primary account number (PAN), a one-time virtual account number, a token generated based on the PAN, etc.

[0018] Next, the applet 103 may send the generated data to the mobile device 110, and the mobile device 110 may send the received data to the authentication server 120. Next, the authentication application 123 may authenticate the received data. For example, if the URL includes an encrypted payload, the authentication application 123 may decrypt the encrypted payload using a copy of the secret key 104 stored in the memory 122 of the server 120. The secret key 104 may be the same as the secret key 104 stored in the memory 102 of the contactless card 101. Here, each contactless card 101 is manufactured to include a unique secret key 104 (and the server 120 stores a corresponding copy of each unique secret key 104). Therefore, the authentication application 123 may successfully decrypt the encrypted payload, thereby verifying the payload. As another example, the authentication application 123 may confirm that the digits of the account number match the digits of the account number associated with the contactless card 101 stored in the account data 124, thereby verifying the account number.

[0019] Regardless of the verification technique used by the authentication application 123, once verified, the authentication application 123 may instruct the virtual account number (VAN) generator 142 in the memory 141 of the virtual account number server 140 to generate a virtual account number, expiration date, and CVV for the account associated with the contactless card 101. In at least one embodiment, the virtual account number generated by the VAN generator 142 is restricted to a specific vendor or group of vendors. The virtual account number may further include other restrictions (e.g., time restrictions, location restrictions, amount restrictions, etc.). Once generated, the VAN generator 142 may provide the virtual account number, expiration date, and CVV to the mobile device 110 and / or the authentication server 120. The VAN generator 142 and / or the authentication server 120 may further provide the account holder name, billing address, and / or shipping address to the mobile device 110. However, in some embodiments, the account holder name, shipping address, and / or billing address are stored locally by the mobile device 110. The VAN generator 142 and / or authentication server 120 may provide data to the mobile device 110 via any appropriate method, such as push notifications, text messages, email, web browsers 115, etc.

[0020] When received by the mobile device 110, the virtual account number, expiration date, CVV, account owner name, billing address, and / or shipping address may be copied to the clipboard 114 of the OS 112. By doing so, the user may paste the copied data into the corresponding fields of the web browser 115. For example, the user may paste the account number into the account number field of a form in the web browser 115. In some embodiments, a notification including the expiration date and CVV may be output on the mobile device 110. The notification may further include the account owner name, billing address, and / or shipping address. The notification may be output after a predefined time (for example, 5 seconds after the virtual account number is copied to the clipboard 114). The notification may allow the user to directly copy the account owner name, billing address, shipping address, expiration date, and / or CVV to the clipboard 114 and paste them into the corresponding fields of a form in the web browser 115.

[0021] Generally, the clipboard 114 stores data that can be copied and / or pasted within the OS 112. For example, the clipboard 114 may locally store data for pasting into fields on the mobile device 110, and the user can input / paste the data stored in the clipboard 114 using commands and / or gestures available within the OS 112. For example, by copying an account number to the clipboard 114, the user can paste the account number into the corresponding form field using commands and / or gestures available within the OS 112. Furthermore, the account application 113 may output a notification specifying the expiration date and CVV while the account number is copied to the clipboard 114. In this way, the user can manually enter the expiration date and CVV into the corresponding form field while the notification remains displayed. In some embodiments, the account application 113 and / or the OS 112 may also copy the expiration date, billing address, and / or CVV to the clipboard 114 and paste the expiration date, billing address, and / or CVV into the corresponding form field.

[0022] Figure 1B shows an embodiment in which the applet 103 for the contactless card 101 generates an encrypted payload for verification by the authentication application 123. As stated, when a user may encounter a payment form in the web browser 115, in response, the OS 112 and / or the account application 113 may output a notification instructing the user to tap the contactless card 101 on the mobile device 110. In some embodiments, the user may select a form field related to payment (e.g., an account number field, an expiration date field, and / or a CVV field), which focuses on the form field. In such embodiments, when the OS 112 and / or the account application 113 determines that the payment field has moved focus, it may output a notification to tap the contactless card 101 on the mobile device 110. In other examples, the OS 112 and / or the account application 113 may determine that the form contains one or more payment fields. For example, in some embodiments, the account application 113 and / or the OS 112 read the metadata of the form fields to determine the type of information. For example, the metadata of a form field may specify that the form field is associated with an account number field, an expiration date field, a CVV field, a shipping address field, and / or a billing address field. In some embodiments, information such as a 16-digit card number, CVV, and customer name may be available offline, while other information such as the address and a generated virtual number may not be available offline and may require a network connection. Accordingly, the account application 113 and / or OS 112 may output a notification to tap the contactless card 101 on the mobile device 110.Therefore, the account application 113 and / or OS 112 may output a notification to tap the contactless card 101 on the mobile device 110 based on the fact that the form contains one or more payment fields and / or based on the fact that the payment field has moved focus.

[0023] When tapped, the applet 103 of the contactless card 101 may generate encrypted data 105 based on the secret key 104. In one embodiment, when the contactless card 101 is tapped to the mobile device 110, the contactless card 101 generates encrypted data 105 and sends it to the mobile device 110. In another embodiment, when the contactless card 101 is tapped to the mobile device 110, the account application 113 may instruct the contactless card 101 to generate encrypted data 105 and send it to the mobile device 110. In some embodiments, the encrypted data 105 may be a string, for example, "A1B2C3Z". The applet 103 may further determine a URL 106. The URL 106 may be directed to the authentication server 120. In some embodiments, the applet 103 dynamically generates the URL 106. In other embodiments, the applet 103 dynamically selects a URL 106 which is one of several URLs 106 stored in memory 102. In some embodiments, URL 106 is a universal link that opens one or more pages of the account application 113. The applet 103 may include the generated encrypted data 105 as a parameter of URL 106, thereby generating URL 108 containing the encrypted data. For example, URL 106 may be "http: / / www.example.com / ". Therefore, URL 108 containing the encrypted data may be "http: / / www.example.com / ?A1B2C3Z".

[0024] In some embodiments, applet 103 may encode encrypted data 105 according to a URL-compatible encoding format before including the encrypted data 105 as a parameter of URL 106. For example, encrypted data 105 may be a string of binary data (e.g., 0s and 1s) that may not be URL-compatible. Therefore, applet 103 may encode encrypted data 105 into the US Standard Code for Information Exchange (ASCII) base64 encoding format. In doing so, the binary encrypted data 105 is represented in ASCII string format by converting it to a base-64 representation (e.g., "ABC123Z" in the previous example).

[0025] Next, the contactless card 101 may send a URL 108 containing the encrypted data to the mobile device 110. Then, the account application 113 may open to a corresponding page, where the account application 113 extracts the encrypted data 105 from the URL 108 containing the encrypted data. In some embodiments, if the user is not logged into the account application 113, the account application 113 opens a login page providing the user with credentials to log into the account before extracting the encrypted data 105. Then, the account application 113 may send the encrypted data 105 to the authentication server 120 via the network 130. In one embodiment, the account application 113 sends the encrypted data to a URL 106 generated by the contactless card 101. In other embodiments, as will be described in more detail below, the URL 108 containing the encrypted data causes the web browser 115 to open a new tab and follow the URL 108 containing the encrypted data. In such an embodiment, the URL 108 containing encrypted data leads to an authentication application 123, which can extract encrypted data 105 from the URL 108 containing encrypted data.

[0026] Next, the authentication application 123 may attempt to decrypt the encrypted data 105 using the secret key 104 associated with the contactless card 101 upon receipt. As mentioned, in some embodiments, the encrypted data 105 is encoded by the applet 103. In such embodiments, the authentication application 123 may decrypt the encrypted data 105 before attempting decryption. If the authentication application 123 is unable to decrypt the encrypted data to produce the expected result (e.g., a customer identifier for an account associated with the contactless card 101), the authentication application does not validate the encrypted data 105 and does not instruct the VAN generator 142 to generate a virtual account number. If the authentication application 123 is able to decrypt the encrypted data to produce the expected result (e.g., a customer identifier for an account associated with the contactless card 101), the authentication application validates the encrypted data 105 and instructs the VAN generator 142 to generate a virtual account number, expiration date, and CVV value. As shown, the VAN generator 142 generates a virtual number 125 which has a virtual account number, an expiration date, and a CVV value.

[0027] Next, the virtual number 125 can be sent to the mobile device 110 over the network. Upon receipt, the account application 113 provides one or more elements of the virtual number 125 to the clipboard 114 of the OS 112. For example, the account application 113 may extract the virtual account number from the virtual number 125 and provide the extracted virtual account number to the clipboard 114, thereby copying the virtual account number to the clipboard 114. By doing so, the user can return to the web browser 115 and paste the virtual account number from the clipboard into the account number field of the form in the web browser 115.

[0028] Figure 1C shows an embodiment in which the applet 103 for the contactless card 101 generates an identifier for verification by the authentication application 123. As stated, when a user may encounter a payment form in the web browser 115, in response, the OS 112 and / or the account application 113 may output a notification instructing the user to tap the contactless card 101 on the mobile device 110. In some embodiments, the user may select a form field related to the payment (e.g., an account number field, an expiration date field, and / or a CVV field), which focuses on the form field. In such embodiments, when the OS 112 and / or the account application 113 determine that the payment field has moved focus, it may output a notification to tap the contactless card 101 on the mobile device 110.

[0029] In response to a tap, the contactless card applet 103 determines an identifier to include as a parameter in the URL 106. In one embodiment, the applet 103 selects a predetermined number of characters from the account identifier 107 associated with the contactless card 101. For example, the applet 103 may select the last four digits of the account ID 107 and append the selected numbers to the URL 106, thereby generating a URL 109 containing the account ID. As stated above, the URL 106 may be a universal link that opens one or more predefined pages of the account application 113.

[0030] Next, the contactless card 101 may send a URL 109 containing the account ID to the mobile device 110. Then, the account application 113 may open to a corresponding page, where the account application 113 extracts the account ID digits from the URL 109 containing the account ID. In some embodiments, if the user is not logged into the account application 113, the account application 113 opens a login page providing the user with credentials to log into the account before extracting encrypted data 105. Next, the account application 113 may send the account ID digits to the authentication server 120 via the network 130. Then, the authentication application 123 may verify the account ID 107. For example, the authentication application 123 may determine whether the account ID digits match the corresponding digits of the account identifier for the account associated with the contactless card 101 in the account data 124. In such an embodiment, the account application 113 may provide data (e.g., an account token, a username associated with the account currently logged into the account application 113, etc.) that enables the authentication application 123 to verify that the account ID 107 is associated with an account in the account data 124.

[0031] If the authentication application 123 verifies account ID 107, the authentication application 123 instructs the VAN generator 142 to generate a virtual account number. Otherwise, the virtual account number is not generated in response to the tap of the contactless card 101. In one embodiment, if the authentication application 123 can verify the account, the authentication application 123 may log the user into the account corresponding to the account application 113 without requiring user input.

[0032] As shown, after the authentication application 123 verifies the account ID 107, the VAN generator 142 generates a virtual number 126 comprising a virtual account number, an expiration date, and a CVV value. The virtual number 126 can then be sent to a mobile device 110 over the network. Upon receipt, the account application 113 provides one or more elements of the virtual number 126 to the clipboard 114 of the OS 112. For example, the account application 113 may extract the virtual account number from the virtual number 126 and provide the extracted virtual account number to the clipboard 114, thereby copying the virtual account number to the clipboard 114. By doing so, the user can return to the web browser 115 and paste the virtual account number from the clipboard into the account number field of the form in the web browser 115. The expiration date and / or CVV can similarly be extracted by the account application 113 and provided to the clipboard 114. By doing so, the expiration date and / or CVV can be pasted from the clipboard 114 into the corresponding field of the form in the web browser 115.

[0033] As stated, the VAN generator 142 and / or authentication server 120 may further provide the account owner name, billing address, and / or shipping address to the mobile device 110. However, in some embodiments, the account owner name, shipping address, and / or billing address are stored locally by the account application 113 and / or the mobile device 110. Thus, in such embodiments, the account application 113 may provide the account owner name, billing address, and / or shipping address to the clipboard 114. In doing so, the user can paste the account owner name, shipping address, and / or billing address from the clipboard into the account number field of the form in the web browser 115.

[0034] Figure 2A is a schematic diagram 200 showing an exemplary embodiment in which a contactless card 101 is tapped to generate a virtual account number and the virtual account number is copied to a clipboard 114. As shown, the web browser 115 outputs a form containing form fields 201-203 (e.g., a payment form), where field 201 corresponds to the account number field, field 202 corresponds to the expiration date field, and field 203 corresponds to the CVV field. As shown, a notification 204 is output by the OS 112 and / or the account application 113 when the account number field 201 has moved focus (e.g., is selected by the user). The notification 204 instructs the user to tap the contactless card 101 on the mobile device 110. In one embodiment, the user selects the notification 204 before tapping the contactless card 101 on the mobile device 110.

[0035] As described above, when the contactless card 101 is tapped to the mobile device 110, the account application 113 sends instructions to the contactless card 101 via the card reader 118 (e.g., via NFC, Bluetooth®, RFID, and / or EMV protocols). The instructions may specify the generation of a URL containing encrypted data. As stated, the applet 103 may use the contactless card's secret key 104 to generate a URL containing encrypted data. The applet 103 then generates a URL containing encrypted data as a parameter of the URL and may send the URL containing encrypted data to the mobile device 110. Upon receipt, the URL containing encrypted data may open a page in the account application 113.

[0036] Figure 2B is a schematic diagram 210 showing an embodiment in which the account application 113 is opened in response to receiving a URL containing encrypted data from the contactless card 101. As shown, the account application 113 requests the user to provide a fingerprint to log in to their account. In other embodiments, the user may log in to the account using FaceID, another biometric identifier, username / password, or any other type of credentials. In some embodiments, user login is not required. Once the user has logged in to the account, the account application 113 sends the encrypted data to the authentication application 123. Once verified (e.g., decrypted), the authentication application 123 causes the VAN generator 142 to generate a virtual account number, expiration date, and CVV associated with the contactless card 101. The VAN generator 142 may then send the virtual account number, expiration date, and CVV to the mobile device 110. As shown, upon receipt, the account application 113 copies the virtual account number to the OS clipboard 114. In one embodiment, the account application 113 copies the virtual account number to the clipboard 114 based on the determination that the account number field has focus. The account application 113 may then generate and output a link 205 (or other graphical object) that allows the user to return to the previous application (e.g., a web browser 115).

[0037] Figure 2C is a schematic diagram 220 showing one embodiment in which the user selects link 205 and returns to the web browser 115. As shown, notification 206 may allow the user to paste the virtual account number into form field 201 (for example, after the user long-presses form field 201). If selected, OS 112 may paste the virtual card number from clipboard 114 into form field 201. Figure 2D is a schematic diagram 230 showing an embodiment in which the virtual account number has been pasted into form field 201. As shown, OS 112 and / or account application 113 may output notification 207. Notification 207 includes the expiration date and CVV associated with the virtual account number received from VAN generator 142. As shown, notification 207 includes a link 208 that copies the expiration date to clipboard 114 if selected. Similarly, notification 207 includes a link 209 that copies the CVV to clipboard 114 if selected. Other graphic objects may be used instead of links. In some embodiments, the output of notification 207 is timed to facilitate easy copying and pasting of the expiration date and CVV. For example, account application 113 may start a timer in response to receiving the virtual account number, expiration date, and CVV from VAN generator 142. In another example, account application 113 may start a timer when the user selects link 205 and returns to web browser 115. When the timer exceeds a predefined time threshold (e.g., 5 seconds, 10 seconds, etc.), notification 207 is generated and output. This allows the user time to paste the account number into form field 201 without being distracted by notification 207, while simultaneously providing timely notification 207 to facilitate copying and / or pasting of the expiration date and / or CVV.

[0038] Figure 3A is a schematic diagram 300 showing an exemplary embodiment in which a contactless card 101 is tapped to generate a virtual account number and the virtual account number is copied to a clipboard 114. As shown, the web browser 115 loaded a website from URL 305. The website may be in the first tab of the web browser 115 and include a form (e.g., a payment form) having form fields 301-303. Field 301 corresponds to the account number field, field 302 corresponds to the expiration date field, and field 303 corresponds to the CVV field. As shown, a notification 304 is output by the OS 112 and / or the account application 113 when the account number field 301 has been moved to focus (e.g., when it is selected by the user). The notification 304 instructs the user to tap the contactless card 101 on the mobile device 110. In one embodiment, the user selects the notification 304 before tapping the contactless card 101 on the mobile device 110.

[0039] To determine that a field has moved focus, the account application 113 and / or OS 112 can parse the hypertext markup language (HTML) attributes of the account number field 301 to determine that the account number field 301 has moved focus. Furthermore, the account application 113 and / or OS 112 may parse the metadata of the account number field 301 to determine that the field 301 is associated with an account number. For example, based on the metadata, the account application 113 and / or OS 112 may determine that the account number field 301 is configured to accept 16 characters as input. As another example, the metadata may specify a name for the form field 301 that is similar to the name associated with the account number field (e.g., "accountnumber", "account_number", etc.).

[0040] As described above, when the contactless card 101 is tapped to the mobile device 110, the account application 113 sends an instruction to the contactless card 101 via the card reader 118 (e.g., via NFC, Bluetooth®, RFID, and / or EMV protocols, etc.). The instruction may specify that a URL containing encrypted data be generated. However, in some embodiments, the contactless card 101 allows the applet 103 to generate a URL containing encrypted data without requiring an instruction received from the mobile device 110. As stated, the applet 103 may use the secret key 104 of the contactless card 101 to generate a URL containing encrypted data. In the example shown in Figure 3A, the applet 103 may use the secret key 104 to generate an exemplary encrypted string "ABCD123XYZ". The applet 103 may then generate a URL to the authentication application 123, where the URL contains the encrypted data as a parameter of the URL. In the example shown in Figure 3A, the URL containing the encrypted data may be "https: / / / www.example.com / auth.html?ABCD123XYZ". Applet 103 can then send the URL containing the encrypted data to the mobile device 110.

[0041] Figure 3B is a schematic diagram 310 showing an embodiment in which a new tab in the web browser 115 opens in response to receiving a URL containing encrypted data from the contactless card 101. As shown, the URL 306 in the web browser is directed to the URL containing the encrypted data generated by the applet 103, namely, "https: / / / www.example.com / auth.html?ABCD123XYZ". The authentication application 123 may decrypt the encrypted data using the secret key 104 to verify the encrypted data. The authentication application 123 may then instruct the VAN generator 142 to generate a virtual account number, an expiration date, and a CVV. However, in some embodiments, the VAN generator 142 generates a virtual account number and selects an existing expiration date and / or CVV (e.g., from account data 124). In some such examples, the existing expiration date and / or CVV may be the expiration date and / or CVV of the contactless card 101, or another card associated with the account in account data 124.

[0042] As shown in Figure 3B, the tab in the web browser 115 contains the virtual account number, expiration date, and CVV. In one embodiment, the VAN generator 142 provides the generated data to the authentication application 123, which can then output the data to the web browser 115. Using other techniques, the web browser 115 may be redirected to the VAN generator 142, which can then output the virtual account number, expiration date, and CVV to the web browser 115. As shown, the web browser 115 includes notifying the user to close the tab in the web browser 115 once the user has copied / pasted the virtual account number, expiration date, and CVV.

[0043] Figure 3C is a schematic diagram 320 showing an embodiment in which a VAN generator 142 and / or an authentication application 123 send a push notification 307 to a mobile device containing a virtual account number, expiration date, and CVV generated by the VAN generator 142. The virtual account number, expiration date, and CVV may be generated based on any of the techniques described herein. In one embodiment, the notification 307 is generated instead of (or in addition to) outputting the virtual account number, expiration date, and CVV in the web browser 115 of Figure 3B. As shown, the notification 307 includes a link 308 that, if selected, copies the virtual account number to the clipboard 114. Similarly, the notification 307 includes a link 309 that, if selected, copies the expiration date to the clipboard 114. Similarly, the notification 307 includes a link 321 that, if selected, copies the CVV to the clipboard 114. Other graphic objects may be used instead of links. In some embodiments, the output of notification 307 is timed, for example, when the timer expires, to facilitate the easy copying / pasting of the expiration date and CVV.

[0044] Figure 3D is a schematic diagram 330 showing an embodiment in which a VAN generator 142 and / or an authentication application 123 send a text message notification 311 to a mobile device containing a virtual account number, expiration date, and CVV generated by the VAN generator 142. The virtual account number, expiration date, and CVV may be generated based on any of the techniques described herein. In one embodiment, the text message notification 311 is generated instead of (or in addition to) outputting the virtual account number, expiration date, and CVV in the web browser 115 of Figure 3B. As shown, the text message notification 311 includes the virtual account number, expiration date, and CVV. As shown, the text message notification 311 includes a link 313 that, if selected, copies the virtual account number to the clipboard 114. Similarly, the text message notification 311 includes a link 314 that, if selected, copies the expiration date to the clipboard 114. Similarly, the text message notification 311 includes a link 315 that, if selected, copies the CVV to the clipboard 114. Other graphic objects may be used instead of links. Furthermore, as shown, text message 311 includes an autofill link 312 which, when selected, autofills the virtual account number, expiration date, and CVV into form fields 301-303, respectively. In at least one embodiment, an OS autofill service (not shown) autofills the account number, expiration date, and CVV into form fields 301-303. In some embodiments, the autofill service detects the form fields (e.g., form fields 301-303), detects the content in a notification (e.g., notification 311) having a type that matches the type of the detected form fields, and provides the parsed content from the notification as autofill candidates for the keyboard. In doing so, the autofill service can automatically populate the corresponding form fields from the notification.

[0045] Although not shown in Figures 2A-2D and 3A-3D, the account holder name, billing address, and / or shipping address may be copied to the clipboard 114 and pasted into the corresponding form fields in the web browser. As mentioned, the name, billing address, and / or shipping address may be stored locally on the mobile device 110 and / or received from the VAN generator 142 and / or the authentication server 120.

[0046] Figure 4 shows an embodiment of the logical flow 400. The logical flow 400 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 400 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. Embodiments are not limited in this context.

[0047] As shown, the logical flow 400 begins in block 405, where the account application 113 and / or OS 112 determine that the payment field of the form has moved focus. The form may be in the web browser 115, the account application 113, and / or other applications. For example, a user may give focus to the payment field by tapping it on the form. Another example is that a user may select the payment field on the form using the mouse and / or keyboard. More generally, focus may be given to the payment field using any technique, including programmatically generated focus. For example, the payment field may move focus based on the HTML “focus()” method. Another example is that, for example, the payment field may automatically move focus when the form loads based on the “autofocus” HTML attribute applied to the payment field in the source code. The payment field may include one or more of the following: name field, account number field, expiration date field, shipping address field, billing address field, and / or CVV field. When a payment field gains focus, the account application 113 and / or OS 112 may output a notification instructing the user to tap the contactless card 101 on the mobile device 110. In some embodiments, the notification may be generated based on the determination that the form contains one or more payment fields, without requiring the determination that a form field has gained focus. The notification may include a GUI that provides an example of how to tap the contactless card 101 on the mobile device 110. In block 410, the user taps the contactless card 101 on the mobile device to cause the contactless card 101 to generate and transmit encrypted data as part of a URL. The account application 113 may send instructions to the contactless card 101 via the NFC card reader 118 specifying that it generate and transmit encrypted data as part of a URL.

[0048] In block 415, the contactless card applet 103 generates encrypted data using the secret key 104 and an encryption algorithm. The applet 103 may then include the encrypted data as parameters in a URL. The URL may be a universal link URL that, when followed, opens at least partially a predefined page of the account application 113. In block 420, the applet 103 may send the URL containing the encrypted data to the mobile device 110. In block 425, the account application 113 opens to the page corresponding to the universal link URL received from the contactless card 101. In some embodiments, the account application 113 may request the user to log in to their account (if they are not already logged in). In some such embodiments, the URL may be directed to an external authentication website configured to receive the credentials necessary to log the user into their account. In another example, the URL may be directed to an authentication page of the account application 113 that receives the credentials necessary to log the user into their account.

[0049] In block 430, the account application 113 extracts the encrypted data from the URL and sends the encrypted data to the authentication application 123 on the authentication server 120 for verification. If the encrypted data is encoded, the account application 113 and / or the authentication application 123 may decrypt the encrypted data. In block 435, the authentication application 123 decrypts the encrypted data using a secret key in the server 120's memory to verify the encrypted data. In block 440, the authentication application 123 sends instructions to the VAN generator 142 specifying that it generate a virtual account number, expiration date, and CVV. The authentication application 123 may further specify one or more restrictions on the virtual account number (e.g., must be used within one hour, usable only on the website of a specified vendor). In block 445, the VAN generator 142 generates the virtual account number, expiration date, and CVV. In block 450, the VAN generator 142 sends the virtual account number, expiration date, and CVV to the mobile device 110. The VAN generator 142 may further transmit the account holder name, billing address, and / or shipping address to the mobile device 110, which may be received by the VAN generator 142 from the authentication server 120. For example, the VAN generator 142 may generate a push notification, text message, or one or more data packets to be processed by the account application 113 to receive the virtual account number, expiration date, and CVV.

[0050] In block 455, the account application 113 copies the virtual account number to the OS clipboard 114. The account application 113 may also start a timer. In block 460, the user may return to the web browser 115 and paste the virtual account number stored in the clipboard 114 into the payment field of the form. In block 465, after the timer set in block 455 has elapsed (or the threshold time has been exceeded), the account application 113 outputs a notification specifying the account owner name, billing address, shipping address, expiration date, and / or CVV. This allows the user to copy the account owner name, billing address, shipping address, expiration date, and CVV and paste them into the corresponding fields of the form.

[0051] Figure 5 shows an embodiment of the logical flow 500. The logical flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 500 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. Embodiments are not limited in this context.

[0052] As shown, the logical flow 500 begins in block 505, where the account application 113 and / or OS 112 determine that the payment field of the form has moved focus. The form may be in the web browser 115, the account application 113, and / or other applications. For example, a user may give focus to the payment field by tapping the payment field of the form. Another example is that a user may select the payment field of the form using the mouse and / or keyboard. More generally, focus may be given to the payment field using any technique, including programmatically generated focus. For example, the payment field may move focus based on the HTML “focus()” method. Another example is that, for example, the payment field may automatically move focus when the form loads based on the “autofocus” HTML attribute applied to the payment field in the source code. The payment field may include one or more of the following: name field, account number field, expiration date field, shipping address field, billing address field, and / or CVV field. When the payment field gains focus, the account application 113 and / or OS 112 may output a notification instructing the user to tap the contactless card 101 on the mobile device 110. In some embodiments, the notification may be generated based on the determination that the form contains one or more payment fields. The notification may include a GUI showing an example of how to tap the contactless card 101 on the mobile device 110. In block 510, the user taps the contactless card 101 on the mobile device to cause the contactless card 101 to generate and transmit data as part of a URL. The account application 113 may send instructions to the contactless card 101 via the NFC card reader 118 specifying that it generate and transmit data as part of a URL.

[0053] In block 515, the contactless card applet 103 generates a URL that includes the account identifier (or part thereof) as a URL parameter. The URL may be a universal link URL that, when followed, opens at least partially a predefined page of the account application 113. In block 520, the applet 103 may send the URL containing the account identifier to the mobile device 110. In block 525, the account application 113 opens to the page corresponding to the universal link URL received from the contactless card 101. In some embodiments, the account application 113 may prompt the user to log in to their account (if they are not already logged in).

[0054] In block 530, the account application 113 extracts the account identifier from the URL and sends it to the authentication application 123 on the authentication server 120 for verification. In block 535, the authentication application 123 verifies the account identifier (for example, by determining whether the received account identifier matches any expected and / or known account identifier values). In block 540, the authentication application 123 sends instructions to the VAN generator 142 specifying that it generate a virtual account number, an expiration date, and a CVV. The authentication application 123 may further specify one or more restrictions on the virtual account number (for example, it must be used within one hour, or it can only be used on the website of a specified vendor). In block 545, the VAN generator 142 generates the virtual account number, an expiration date, and a CVV. In block 550, the VAN generator 142 sends the virtual account number, an expiration date, and a CVV to the mobile device 110. The VAN generator 142 may further transmit the account holder name, billing address, and / or shipping address to the mobile device 110, which may be received by the VAN generator 142 from the authentication server 120. For example, the VAN generator 142 may generate a push notification, text message, or one or more data packets to be processed by the account application 113 to receive the virtual account number, expiration date, and CVV.

[0055] In block 555, the account application 113 copies the virtual account number to the OS clipboard 114. The account application 113 may also start a timer. In block 560, the user may return to the web browser 115 and paste the virtual account number stored in the clipboard 114 into the payment field of the form. In block 565, after the timer set in block 555 has elapsed (or the threshold time has been exceeded), the account application 113 outputs a notification specifying the account owner name, billing address, shipping address, expiration date, and / or CVV. This allows the user to copy the account owner name, billing address, shipping address, expiration date, and CVV and paste them into the corresponding fields of the form.

[0056] Figure 6 shows an embodiment of the logical flow 600. The logical flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 600 may include some or all of the operations for generating a virtual account number using a contactless card and copying the virtual account number to the clipboard 114. Embodiments are not limited in this context.

[0057] As shown, the logical flow 600 begins in block 605, where the account application 113 and / or OS 112 determine that the payment field of the form has moved focus. The form may be in the first tab of the web browser 115. For example, a user may give focus to the payment field by tapping the payment field of the form. As another example, a user may select the payment field of the form using the mouse and / or keyboard. More generally, focus can be given to the payment field using any technique, including programmatically generated focus. For example, the payment field may move focus based on the HTML “focus()” method. As another example, for example, the payment field may automatically move focus when the form loads based on the “autofocus” HTML attribute applied to the payment field in the source code. The payment field may include one or more of the following: name field, account number field, expiration date field, shipping address field, billing address field, and / or CVV field. When the payment field gains focus, the account application 113 and / or OS 112 may output a notification instructing the user to tap the contactless card 101 on the mobile device 110. In some embodiments, the notification may be generated based on the determination that the form contains one or more payment fields. The notification may include a GUI showing an example of how to tap the contactless card 101 on the mobile device 110. In block 610, the user taps the contactless card 101 on the mobile device to cause the contactless card 101 to generate and transmit encrypted data as part of a URL. The account application 113 may send instructions to the contactless card 101 via the NFC card reader 118 specifying that it generate and transmit encrypted data as part of a URL.

[0058] In block 615, the contactless card applet 103 generates encrypted data using the secret key 104 and an encryption algorithm. The applet 103 may then include the encrypted data as a parameter in a URL. The URL may be a URL to the authentication application 123 and / or authentication server 120, which opens a second tab in the web browser 115. In block 620, the applet 103 may send the URL containing the encrypted data to the mobile device 110. In block 625, the web browser 115 opens a second tab and loads the URL containing the encrypted data.

[0059] In block 630, the authentication application 123 extracts the encrypted data from the URL, decrypts the encrypted data using the secret key in the server 120's memory, and verifies the encrypted data. In block 635, the authentication application 123 sends instructions to the VAN generator 142 specifying that it generate a virtual account number, an expiration date, and a CVV. The authentication application 123 may further specify one or more restrictions on the virtual account number (e.g., it must be used within one hour, it can only be used on the website of a specified vendor, etc.). In block 640, the VAN generator 142 generates the virtual account number, an expiration date, and a CVV.

[0060] In block 645, the VAN generator 142 sends a push notification to the mobile device 110 containing the virtual account number, expiration date, and CVV. The VAN generator 142 may further send the account owner name, billing address, and / or shipping address as part of the push notification. The mobile device 110 may then output the received push notification. In addition and / or instead, in block 650, the VAN generator 142 sends a text message to the mobile device 110 containing the virtual account number, expiration date, and CVV. The mobile device 110 may then output a notification corresponding to the text message, the notification displaying the virtual account number, expiration date, and CVV. In addition and / or instead, in block 655, the virtual account number, expiration date, CVV, account owner name, billing address, and / or shipping address are optionally output for display in a second tab of the web browser 115. In block 660, one or more of the following may be copied from a push notification, text message notification, and / or a second browser tab and pasted into a form in the first browser tab: virtual account number, expiration date, CVV, account owner name, billing address, and / or shipping address. Alternatively, the virtual account number, expiration date, CVV, account owner name, billing address, and / or shipping address may be automatically populated into the form.

[0061] Figure 7 shows an exemplary embodiment of the computing architecture 700, comprising a computing system 702 suitable for implementing the various embodiments described above. In various embodiments, the computing architecture 700 may be implemented with or as part of an electronic device. In some embodiments, the computing architecture 700 may represent, for example, a system that implements one or more components of system 100. In some embodiments, the computing system 702 may represent, for example, the mobile device 110, the authentication server 120, and / or the virtual account number server 140 of system 100. Embodiments are not limited to this context. More generally, the computing architecture 700 is configured to implement all the logic, applications, systems, methods, devices, and functions described herein with reference to Figures 1 to 6.

[0062] The terms “system,” “component,” and “module” used in this application are intended to refer to any computer-related entity, whether hardware, a combination of hardware and software, software, or running software, examples of which are provided by the exemplary computing architecture 700. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, an execution thread, a program, and / or a computer. For example, both an application running on a server and the server itself may be components. One or more components may reside within a process and / or an execution thread, and components may be localized to one computer and / or distributed across two or more computers. Furthermore, components may be coupled together in a communicative manner by various types of communication media and their operation may be coordinated. Coordination may include the one-way or two-way exchange of information. For example, components may communicate information in the form of signals communicated over a communication medium. Information may be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, further embodiments may use data messages as an alternative. Such data messages can be transmitted over various connections. Examples of connections include parallel interfaces, serial interfaces, and bus interfaces.

[0063] The computing system 702 includes various common computing elements such as one or more processors, multicore processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, and power supplies. However, the embodiments are not limited to those implemented by the computing system 702.

[0064] As shown in Figure 7, the computing system 702 includes a processor 704, system memory 706, and a system bus 708. The processor 704 may be any of a variety of commercially available computer processors, including but not limited to AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multiprocessor architectures may also be used as the processor 704.

[0065] The system bus 708 provides an interface to system components, including but not limited to the system memory 706 and the processor 704. The system bus 708 can be one of several types of bus structures that can further interconnect to the memory bus (with or without a memory controller), peripheral buses, and local buses using any of various commercially available bus architectures. Interface adapters can connect to the system bus 708 via slot architectures. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, Industry Standard Architecture ((E)ISA), Microchannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extensible) (PCI(X)), PCI Express, and Personal Computer Memory Card International Association (PCMCIA).

[0066] The system memory 706 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon oxide nitride (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drives (SSDs)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in Figure 7, the system memory 706 may include non-volatile memory 710 and / or volatile memory 712. The non-volatile memory 710 may store the Basic Input / Output System (BIOS).

[0067] The computing system 702 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 714, a magnetic floppy disk drive (FDD) 716 for reading from or writing to a removable magnetic disk 718, and an optical disk drive 720 for reading from or writing to a removable optical disk 722 (e.g., a CD-ROM or DVD). The HDD 714, FDD 716, and optical disk drive 720 may be connected to the system bus 708 by an HDD interface 724, an FDD interface 726, and an optical drive interface 728, respectively. The HDD interface 724 for external drive implementation may include at least one or both of the Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 702 is generally configured to implement all the logic, systems, methods, apparatus, and functions described herein with reference to Figures 1 to 6.

[0068] The drives and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-executable instructions, etc. For example, a number of program modules may be stored in the drives and memory units 710, 712, including an operating system 730, one or more application programs 732, other program modules 734, and program data 736. In one embodiment, the one or more application programs 732, other program modules 734, and program data 736 may include, for example, various applications and / or components of system 100, such as an operating system 112, an account application 113, a clipboard 114, a web browser 115, an authentication application 123, and a VAN generator 142.

[0069] The user may input commands and information to the computing system 702 via one or more wired / wireless input devices, such as a keyboard 738 and a pointing device such as a mouse 740. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, gamepad, stylus pen, card reader, dongle, fingerprint reader, grab, graphics tablet, joystick, keyboard, retina reader, touchscreen (e.g., capacitive, resistive, etc.), trackball, trackpad, sensor, stylus, etc. These and other input devices are often connected to the processor 704 via an input device interface 742 coupled to the system bus 708, but may also be connected via other interfaces such as a parallel port, IEEE 1394 serial port, game port, USB port, or IR interface.

[0070] Monitor 744 or other types of display devices are also connected to the system bus 708 via interfaces such as the video adapter 746. Monitor 744 can be located inside or outside the computing system 702. In addition to Monitor 744, the computer typically includes other peripheral output devices such as speakers and printers.

[0071] The computing system 702 may operate in a network environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computers 748. The remote computers 748 could be workstations, server computers, routers, personal computers, portable computers, microprocessor-based entertainment devices, peer devices, or other common network nodes, typically including many or all of the elements described in relation to the computing system 702, but for brevity, only the memory / storage device 750 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 752 and / or a larger network, such as a wide area network (WAN) 754. Such LAN and WAN network environments are common in offices and businesses and facilitate enterprise-scale computer networks such as intranets. All of these may connect to global communication networks, such as the Internet. In embodiments, the network 130 in Figure 1 is one or more of the LAN 752 and WAN 754.

[0072] When used in a LAN networking environment, the computing system 702 is connected to the LAN 752 via a wired and / or wireless network interface or adapter 756. The adapter 756 may facilitate wired and / or wireless communication to the LAN 752, which may include a wireless access point placed on it to communicate with the wireless capabilities of the adapter 756.

[0073] When used in a WAN networking environment, the computing system 702 may include a modem 758, or be connected to a communication server on the WAN 754, or have other means of establishing communication on the WAN 754, such as via the Internet. The modem 758 may be internal or external, wired and / or wireless, and connect to the system bus 708 via an input device interface 742. In a network environment, the program modules, or parts thereof, shown with respect to the computing system 702 may be stored in a remote memory / storage device 750. The shown network connections are illustrative, and it will be understood that other means of establishing communication links between computers may be used.

[0074] Computing system 702 is capable of communicating with wired and wireless devices or entities using the IEEE 802 standard family, such as wireless devices configured to operate wirelessly (e.g., IEEE 802.16 wireless modulation technology). This includes at least Wi-Fi (or Wireless Fidelity), WiMAX, and Bluetooth® wireless technologies. Thus, communication can be a predefined structure, similar to conventional networks, or simply ad-hoc communication between at least two devices. Wi-Fi networks provide secure, reliable, and high-speed wireless connectivity using wireless technologies known as IEEE 802.11x (a, b, g, n, etc.). Wi-Fi networks can be used to connect computers to each other, to connect to the Internet, or to wired networks (using IEEE 802.3 related media and functions).

[0075] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computed code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. The determination of whether an embodiment is implemented using hardware and / or software elements may vary depending on any number of factors, such as required computing speed, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus rate, and other design or performance constraints.

[0076] One or more aspects of at least one embodiment can be implemented by representative instructions stored in a machine-readable medium representing various logics within a processor, which, when read by a machine, produce logic that performs the techniques described herein. Such representations, known as "IP cores," are stored in tangible machine-readable medium and provided to various customers or manufacturing facilities for loading into manufacturing machines that create logic or processors. Some embodiments can be implemented using, for example, a machine-readable medium or article that can store instructions or a set of instructions that, when executed by a machine, can cause a machine to perform methods and / or operations according to the embodiment. Such machines can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disks, floppy disks, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewritable (CD-RW), optical disks, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tapes, cassettes, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, cryptographic code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.

[0077] The foregoing description of exemplary embodiments is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit this disclosure to the exact form disclosed. Many modifications and changes are possible in light of this disclosure. The scope of this disclosure is intended to be limited by the appended claims rather than by this detailed description. Future applications claiming priority to this application may assert the disclosed subject matter in different ways and may generally include any set of one or more limitations, as variously disclosed or demonstrated herein.

Claims

1. Processor circuit and A device comprising a memory for storing instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The web browser executed by the aforementioned processor circuit outputs a form that includes a payment field, Receiving a uniform resource locator (URL) from the communication interface of the contactless card, which contains encrypted data generated by the contactless card based at least partially on the secret key of the contactless card stored in the memory of the contactless card, The application executed on the processor circuit transmits the encrypted data to an authentication server, the authentication server verifies the encrypted data by decrypting it at least partially based on the secret key of the contactless card stored in the authentication server's memory. Based on the verification of the encrypted data by the authentication server, the application receives a virtual account number from the virtual account number server. The application receives the expiration date associated with the virtual account number and the card verification value (CVV) associated with the virtual account number. The application copies the virtual account number to the clipboard of the operating system (OS) running on the processor circuit, The OS pastes the virtual account number from the clipboard into the payment field of the form in the web browser, The OS outputs a notification comprising the expiration date and the CVV associated with the virtual account number, To execute Device.

2. The aforementioned memory stores instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The OS opens an application in response to the reception of the URL, and the URL includes a universal link URL. Receiving the virtual account number, the expiration date, the CVV, and the account billing address from the virtual account number server, wherein the expiration date and the CVV comprise one or more of (i) the expiration date and CVV generated by the virtual account number server, and (ii) the expiration date and CVV of the contactless card received from the account database. The application receives an input specifying that it should return to the web browser, and based on the received input, outputs the web browser to the device's display. Based on the received input, the web browser is output to the display of the device, To execute The apparatus according to claim 1.

3. The aforementioned memory stores instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The OS receives input of a notification specifying that the expiration date should be copied to the clipboard, The OS, in response to the input received in the notification, copies the expiration date to the clipboard. The OS pastes the expiration date into the expiration date field of the form in the web browser, To execute The apparatus according to claim 1.

4. The aforementioned memory stores instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The OS receives input of a notification specifying that the CVV should be copied to the clipboard, The OS, in response to an input specifying that the CVV should be copied to the clipboard, copies the CVV to the clipboard. The OS pastes the CVV into the CVV field of the form in the web browser, The OS receives input of a notification specifying that the billing address should be copied to the clipboard, The OS, in response to an input specifying that the billing address should be copied to the clipboard, copies the billing address to the clipboard. The OS pastes the billing address into the billing address field of the form in the web browser, To execute The apparatus according to claim 3.

5. The aforementioned memory stores instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The application starts a timer in response to receiving the virtual account number, the expiration date, the CVV, and the billing address, When the timer determines that the threshold has been exceeded, the OS is instructed to generate and output the notification. To execute The apparatus according to claim 4.

6. The aforementioned memory stores instructions, When the aforementioned instruction is executed by the processor circuit, the processor circuit will: The application extracts the encrypted data from the URL, and the applet executed in the memory of the contactless card generates the URL and the encrypted data. To execute The apparatus according to claim 1.

7. The apparatus according to claim 1, wherein the application authenticates access to an account associated with the contactless card based on one or more of (i) a received username and password, (ii) a received biometric authentication credentials, and (iii) instructions for verifying the encrypted data received from the authentication server, and the communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth®, and Wi-Fi.

8. A web browser running on the processor circuit of a computing device outputs a first browser tab containing a form with payment fields, The process involves receiving a uniform resource locator (URL) of an authentication server from the communication interface of a contactless card, wherein the URL comprises encrypted data generated by the contactless card, at least in part, based on the secret key of the contactless card stored in the memory of the contactless card. The second browser tab of the web browser accesses the URL of the authentication server, and the authentication server verifies the encrypted data of the URL by decrypting the encrypted data based at least partially on the secret key of the contactless card stored in the authentication server's memory. Based on the verification of the encrypted data by the authentication server, the virtual account number generated by the virtual account number server is received. To receive the expiration date associated with the virtual account number and the card verification value (CVV) associated with the virtual account number, The virtual account number is copied to the clipboard of the operating system (OS) running on the processor circuit, The OS pastes the virtual account number from the clipboard into the payment field of the form in the first browser tab of the web browser, A method that includes this.

9. The method according to claim 8, wherein the virtual account number, the expiration date, the CVV, and the billing address are received from the virtual account number server via (i) the second browser tab, (ii) a push notification received by an application running on the processor circuit, and (iii) a text message.

10. The aforementioned method, The OS receives input specifying that the expiration date should be copied to the clipboard, The OS, in response to the received input, copies the expiration date to the clipboard. The OS pastes the expiration date into the expiration date field of the form in the first browser tab of the web browser. The method according to claim 9, further comprising:

11. The aforementioned method, The OS receives input specifying that the CVV should be copied to the clipboard, The OS copies the CVV to the clipboard in response to the received input, The OS pastes the CVV into the CVV field of the form in the first browser tab of the web browser, The OS receives input of a notification specifying that the billing address should be copied to the clipboard, The OS, in response to an input specifying that the billing address should be copied to the clipboard, copies the billing address to the clipboard. The OS pastes the billing address into the billing address field of the form in the web browser, The method according to claim 9, further comprising:

12. The aforementioned method, The OS outputs a notice containing the expiration date, the CVV, and the billing address associated with the virtual account number. The method according to claim 8, further comprising:

13. The method according to claim 8, wherein the authentication server provides the virtual account number server with instructions to verify the encrypted data, and the expiration date and CVV comprise one or more of (i) an expiration date and CVV generated by the virtual account number server, and (ii) an expiration date and CVV of the contactless card received from the account database, and the virtual account number server provides the virtual account number, the expiration date, and the CVV to one or more of the computing device and the authentication server.

14. The communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth®, and Wi-Fi, and the method is The OS outputs a notification instructing the user to close the second browser tab. The method according to claim 8, further comprising:

15. A non-temporary computer-readable storage medium in which computer-readable program code is materialized, wherein the computer-readable program code, which is executable by a processor circuit, is provided to the processor circuit. The web browser executed by the aforementioned processor circuit outputs a form that includes a payment field, The application executed on the processor circuit receives a uniform resource locator (URL) containing the identifier of the contactless card from the communication interface of the contactless card, The application authenticates the account associated with the contactless card, The application transmits the identifier of the account to the authentication server, and the authentication server verifies the identifier of the contactless card authenticated by the application and the account. The application receives a virtual account number from the virtual account number server based on the authentication server's verification of the encrypted data, The application receives the expiration date associated with the virtual account number and the card verification value (CVV) associated with the virtual account number. The application copies the virtual account number to the clipboard of the operating system (OS) running on the processor circuit, The OS pastes the virtual account number from the clipboard into the payment field of the form in the web browser, The OS outputs a notification comprising the expiration date and the CVV associated with the virtual account number, A non-temporary computer-readable storage medium that enables execution of [a certain action].

16. The non-temporary computer-readable storage medium contains computer-readable program code executable by the processor circuit, and the processor circuit contains: The OS opens an application that responds to the reception of the URL, wherein the URL includes a universal link URL. Receiving the virtual account number, the expiration date, the CVV, and the account billing address from the virtual account number server, wherein the expiration date and the CVV comprise one or more of (i) the expiration date and CVV generated by the virtual account number server, and (ii) the expiration date and CVV of the contactless card received from the account database. The application receives an input specifying that it should return to the web browser, and based on the received input, outputs the web browser to the display of the device. Based on the received input, the web browser is displayed on the computing device's display, A non-temporary computer-readable storage medium according to claim 15, further comprising computer-readable program code that causes the execution of the program.

17. The non-temporary computer-readable storage medium contains computer-readable program code executable by the processor circuit, and the processor circuit contains: The application starts a timer in response to the receipt of the virtual account number, the expiration date, and the CVV, When the timer determines that the threshold has been exceeded, the OS is instructed to generate and output the notification. A non-temporary computer-readable storage medium according to claim 15, further comprising computer-readable program code that causes the execution of the program.

18. The non-temporary computer-readable storage medium contains computer-readable program code executable by the processor circuit, and the processor circuit contains: The application extracts the identifier of the contactless card from the URL, and an applet running in the memory of the contactless card provides the application with the URL and the identifier of the contactless card, wherein the identifier of the contactless card comprises a portion of the account number associated with the account. A non-temporary computer-readable storage medium according to claim 15, further comprising computer-readable program code that causes the execution of the program.

19. The non-temporary computer-readable storage medium contains computer-readable program code executable by the processor circuit, and the processor circuit contains: The OS receives input of the notification specifying that the expiration date should be copied to the clipboard, The OS, in response to the input received in the notification, copies the expiration date to the clipboard. The OS pastes the expiration date into the expiration date field of the form in the web browser, A non-temporary computer-readable storage medium according to claim 15, further comprising computer-readable program code that causes the execution of the program.

20. The non-temporary computer-readable storage medium contains computer-readable program code executable by the processor circuit, and the processor circuit contains: The OS receives the input of the notification specifying that the CVV should be copied to the clipboard, The OS, in response to an input specifying that the CVV should be copied to the clipboard, copies the CVV to the clipboard. The OS pastes the CVV into the CVV field of the form in the web browser, Here, the communication interface of the contactless card is configured to support at least one of Near Field Communication (NFC), Bluetooth®, and Wi-Fi. A non-temporary computer-readable storage medium according to claim 15, further comprising computer-readable program code that causes the execution of the program.