System and method for streamlining the startup of service machinery

The system uses intermediate-range communication to authenticate and authorize smart cards for automated service machines, addressing the need for contactless operation and enhancing security and convenience.

JP2026510118APending Publication Date: 2026-04-01CAPITAL ONE SERVICES LLC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Applications
Current Assignee / Owner
Filing Date
2023-10-18
Publication Date
2026-04-01

Smart Images

  • Figure 2026510118000001_ABST
    Figure 2026510118000001_ABST
Patent Text Reader

Abstract

An automated service authorization method, wherein a service facilitation system receives services from account holder user devices associated with card accounts and card account proximity cards. A service request identifies an automated service machine (ASM) and the services provided by the ASM. The service facilitation system sends a service request notification to the requested ASM. The service facilitation system receives card authentication information from the ASM, including the encrypted authentication block received by the ASM from the presented proximity card. Using the card authentication information, the service facilitation system verifies that the presented proximity card is a proximity card to the card account and determines the service authorization result for the requested service. Based on the service authorization result, the service facilitation system sends a service authorization response.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application claims the priority of U.S. Patent Application No. 17 / 977,766, filed on October 31, 2022, the disclosure of which is hereby incorporated by reference in its entirety.

[0002] This application generally relates to the use of intermediate distance field communication systems, and more particularly to systems and methods for using a proximity card to initiate the operation of an automated service machine.

Background Art

[0003] In daily life, the use of data processors to initiate machine control operations is increasing. Such actions can include starting household appliances and machines by individuals or company employees via the Internet or other networks. They can also include starting commercially operated machines that automatically provide financial and other services. As the number of network-mediated actions increases, so does the potential for improper behavior. At the same time, the desire to start machine control services without physical interaction has increased dramatically. Although the use of near-field communication (NFC) has reduced physical interaction to some extent, for many people, the required close physical interaction with NFC is too close.

Summary of the Invention

[0004] An exemplary embodiment of the present invention provides an automation method for authorizing automated services. The method includes a service facilitation data processing system receiving a service request from an account holder user device, including the identification of an automated service machine (ASM) and the services to be provided by the ASM. The account holder user device is associated with a card account and a card account proximity card. The method further includes the service facilitation data processing system sending a service request notification to the ASM, including the card account identification associated with the proximity card and the requested service information. The method further includes the service facilitation data processing system receiving card authentication information from the ASM. The card authentication information includes an encrypted authentication block received by the ASM from the presented proximity card. The service facilitation data processing system uses the card authentication information to verify that the presented proximity card is a card account proximity card and to determine the service authorization result for the requested service. The method also includes the service facilitation data processing system sending a service authorization response to the ASM, at least in part, based on the service authorization result.

[0005] Another aspect of the present invention provides a service facilitation data processing system for facilitating service transactions for a business card account in one of a plurality of automated service machines (ASMs). The system comprises a communication interface, a service request data processor, and an authentication data processor. The communication interface selectively communicates with any of the plurality of ASMs via a first network and with the account holder's user device associated with the nearby card account via a second network. The service request data processor receives a service request from the account holder's user device, which includes the identification of the requested ASM and the services to be provided by the requested ASM. The requested ASM is one of the plurality of ASMs. The service request data processor further transmits a service request notification to the requested ASM, which includes the requested service information and the card account identification associated with the card account nearby card. The authentication data processor receives card authentication information from the requested ASM, which the ASM received from the presented nearby card. The authentication data processor further verifies that the presented nearby card is the card account nearby card and determines the service authorization result for the requested service. In response to a positive service authorization decision, the authentication data processor sends an instruction to the requested ASM to initiate the requested service.

[0006] Another aspect of the present invention provides an automated method for providing automated services. This method includes ASM receiving a service request notification from a service facilitation data processing system, which includes a card account identifier associated with an account holder's device, a presented nearby card, and requested service information. This method further includes ASM establishing contactless communication with the presented nearby card and ASM receiving presented card information from the presented nearby card, which includes a presented card identifier and an encrypted authentication block. This method further includes ASM transmitting a service authorization request to the service facilitation data processing system, which includes at least a portion of the presented card information, including the encrypted authentication block. This method also includes ASM receiving an authorization response from the service facilitation data processing system and ASM initiating the requested service in response to receiving an affirmative authorization response.

[0007] The present invention can be more fully understood by reading the following detailed description together with the accompanying drawings. [Brief explanation of the drawing]

[0008] [Figure 1] Figure 1 is a schematic diagram of a service transaction processing system according to an embodiment of the present invention. [Figure 2] Figure 2 is a sequence diagram illustrating an automated service delivery scenario utilizing one or more embodiments of the present invention. [Figure 3] Figure 3 is a schematic diagram of an automated service machine and a smart transaction card that can be used with embodiments of the present invention. [Figure 4] Figure 4 is a schematic diagram of a data processing chip in a smart transaction card according to an embodiment of the present invention. [Figure 5] Figure 5 is a schematic diagram of a user data processing system that can be used with embodiments of the present invention. [Figure 6] Figure 6 is a schematic diagram of a service facilitation data processing system according to an embodiment of the present invention. [Figure 7]Figure 7 is a block diagram of an automation method that enables an automated service according to an embodiment of the present invention. [Figure 8] Figure 8 is a block diagram of an automation method that provides an automation service according to an embodiment of the present invention. [Modes for carrying out the invention]

[0009] Several embodiments of the disclosed technology will be described in more detail with reference to the accompanying drawings. However, the disclosed technology may be embodied in many different forms and should not be construed as being limited to the embodiments described herein. The components described below as constituting various elements of the disclosed technology are intended to be illustrative and not restrictive. Many suitable components that perform the same or similar functions as those described herein are intended to be included within the scope of the disclosed electronic devices and methods. Other such components not described herein may include, but are not limited to, components developed after the development of the disclosed technology.

[0010] Furthermore, it should be understood that the reference to one or more method operations does not preclude the existence of additional method operations or method operations intervening between these explicitly identified operations. Similarly, it should be understood that the reference to one or more components in an apparatus or system does not preclude the existence of additional components or components intervening between the explicitly identified components.

[0011] The present invention provides a system and method for permitting and facilitating the use of an automated service machine without requiring close interaction between the user and the machine. As used herein, the term “Automated Service Machine” or “ASM” means a network-enabled machine that can verify user authorization, communicate with one or more remote management processing systems, and provide automated services to the user. In some embodiments, for example, the method of the present invention can be used to operate an automated car wash or a key-making machine. In other embodiments, the present invention may be implemented through an automated teller machine (ATM) or a machine that accepts coins and returns banknotes. In some embodiments, the ASM may be an automated vending machine for automated products or services. The present invention can provide a user experience in which an automated service is started or completed as soon as the user approaches the ASM or ASM communication interface.

[0012] Referring to Figure 1, the method of the present invention can be implemented on or in conjunction with a service transaction processing system 100 established to incorporate and manage one or more automated service machines (ASMs) and to authenticate and process operation / service requests associated with a user or user account. The requested operation or service may be performed at least partially by a digitally controlled machine or in any form initiated by a digitally controlled machine. System 100 may include a number of network-enabled computer systems, including one or more devices 110, one or more ASMs 140, an ASM administrator 160, and a service facilitation data processing system 150, as depicted in Figure 1. Any or all of these system elements may be able to communicate with each other via a communication network 130. In some embodiments, certain components of system 100 may communicate with each other via a second network in addition to, or instead of, network 130.

[0013] As used herein, the terms “Automated Service Machine” or “ASM” mean a network-enabled machine capable of receiving operation or service requests, verifying user authorization, communicating with a central operation processing system, and performing the requested operation or service. In some embodiments, the ASM140 may be a remotely controlled machine or electrical appliance that can be activated by authorized personnel using remote code entry. In certain embodiments, the ASM140 may be a normal merchant transaction processor, and the requested operation may be the processing of an account-related transaction. In some embodiments, the ASM140 may process card-based purchases or other monetary transactions. In some embodiments, the ASM140 may be a machine that performs cash-related services, such as an automated teller machine (ATM) or a machine that accepts coins and returns banknotes. In some embodiments, the ASM may be an automated product or service vending machine that performs account-based transactions in addition to normal dispensing functions.

[0014] As will be described in more detail, the ASM140 may be equipped with a radio frequency identification (RFID) reader capable of intermediate-range communication with a compatible passive RFID transmitter. As used herein, the term “intermediate range” (or “vicinity range”) refers to passive, field-based communication limited to a distance of about 1.5 m and is used to distinguish it from near-field communication (NFC), which is typically limited to a distance of about 10 cm. Intermediate-range communication technology is sometimes used for what is often called a “vicinity card” (in contrast to the “proximity card” used for NFC). A proximity card typically uses a passive transmitter operating in accordance with IOS / IEC 15693, which specifies an operating frequency of 13.56 MHz. As will be described later, the present invention provides incorporating this functionality into a transaction card or other smart card 120. By using intermediate communication range technology, the ASM140 can receive information from card 120 at a distance that is sufficiently limited to provide security, but long enough so that close contact between the ASM140 and the card user is not required.

[0015] The ASM administrator system 160 may be, or include, a network-enabled processing system that receives operation requests and / or other operation-related information from the ASM 140 or user 110. The ASM administrator system 160 may process user or account-related operation requests and send operation-related instructions to the requesting ASM 140 or user device 110. In certain embodiments, for example, an operation request may be, or include, a request to process a purchase or other financial transaction using the user's financial account. In such embodiments, the ASM administrator system 160 may verify the account information and authorization for the requested transaction, account the transaction, and send instructions to the requesting device to complete the transaction. The ASM administrator system 160 may also receive service requests or notifications from the service facilitation system 150 and relay them to the appropriate ASM 140. The ASM administrator system 160 may also relay service verification information and / or service start instructions from the service facilitation system 150 to the ASM 140.

[0016] The service facilitation data processing system 150 may be one or more network-enabled data processors that communicate with one or more user devices 110 and one or both of the ASM 140 and the ASM administrator system 160 via the network 130, or may include them. The service facilitation system 150 may include, or be able to communicate with, a card account database 190 that contains account and account holder / user information records. The service facilitation system 150 may receive service requests from the ASM 140 user devices 110 and transmit the requests to the requested ASM 140 or ASM administrator system 160. The service facilitation system 150 may further receive positive or negative verification responses from the devices 110 and transmit an appropriate “process” or “reject” response to the verification requester.

[0017] The user processing unit 110 may be any data processing and / or communication device used by an account holder to perform operations and / or communicate with the ASM 140, an authorized operator (e.g., the ASM manager system 160), or the service facilitation system 150, including but not limited to smartphones, desktop computers, laptop computers, and tablets. As will be described in more detail below, each user device 110 may send an operation or service request to the service facilitation system 150, and receive and respond to a verification request from the service facilitation system 150. In a typical embodiment, the user processing unit 110 is a portable device having a location-based service application.

[0018] Next, with reference to Figure 2, a typical ASM service initiation scenario is described. In this scenario, a user wishing to provide services has an account associated with a trading card with nearby range communication capabilities and an account holder user device, and the account holder uses an application on the account holder user device to enter a request for a service provided by a specific ASM. The service request may include information identifying the ASM and information specifying one or a parameter of the requested service. In some embodiments, the request may specify a time interval at which the user will arrive at the ASM to receive the service. In 1100, the user device sends the service request to a service facilitation system which may be associated with the account and / or application on the user device, and the service facilitation system may verify the authorization of the user device / user making the service request. In 1200, the service facilitation system sends a service notification to the requested ASM. In some embodiments, the notification may be sent to the ASM via an ASM administrator system. The service notification may include some or all of the information contained in the service request, and may also include information related to the trading card. If the user wishes to initiate the service, the user brings the trading card and device to the ASM location. When a user comes within range of the intermediate communication, the transaction card's onboard processor is activated, and at 1300, the card sends card information to the ASM. The card information may include a card identifier and / or other information. In certain embodiments, the card information may include card processor encryption information that can be used to verify the request. In some embodiments, the ASM can use the card information to match the card with previously received service request information. In some embodiments, if no service request has been received, the ASM can send a query to the service facilitation system to determine if there are any pending service requests associated with the transaction card. In such embodiments, the service facilitation system sends the requested service information to the ASM in response.

[0019] At 1400, the ASM sends a verification request to the service facilitation system. This request may be sent directly to the service facilitation system, or, in some embodiments, via the ASM administrator system. The verification request may include some or all of the card information, and in particular, a block of card encryption information. The service facilitation system can use the card information as first evidence of authentication that the transaction card associated with the user is located at the ASM. This first authentication includes decrypting the block of card encryption information. At 1500, the service facilitation system sends a request for a second authentication element to the user device. As will be described later, this may include requesting one of several authentication elements. However, in typical embodiments and scenarios, the requested element is or includes the device's location information. At 1600, the device sends a second element response including the requested authentication element (e.g., the device's location information). The service facilitation system uses the second authentication information to ensure that the authentication / authorization criteria are met. In certain embodiments, this includes verifying that the user device is located at the same location as the ASM and the transaction card. Upon successful authentication / authorization, the service facilitation system sends an instruction to the requesting user to begin providing the requested service to the ASM.

[0020] Embodiments of the present invention will now be described in more detail. As described above, the operation or service processing system 100 may include a number of network-enabled computer systems, including one or more ASMs 140, one or more ASM administrators 160, and a service facilitation data processing system 150, all of which can communicate with one another via a communication network 130. In a typical embodiment, the system 100 may include a number of ASMs 140 under the management of one or more ASM administrators 160.

[0021] As referred to herein, a network-enabled processor, computer system, or apparatus can include any computer device, or communication device, including, but not limited to, a server, network appliance, personal computer (PC), workstation, and mobile processing devices such as smartphones, smart pads, handheld PCs, or personal digital assistants (PDAs). The mobile processing device may include a Near Field Communication (NFC) function, which can enable communication with other devices by touching or bringing them into proximity with the other devices.

[0022] A network-enabled computer system used to perform the methods intended by the present invention can, for example, run one or more software applications to receive data as input from entities accessing the network-enabled computer system, process the received data, transmit data over the network, and receive data over the network. One or more network-enabled computer systems may also include one or more software applications to send notifications to account holders or other users. In some examples, computer systems and devices can use instructions stored on computer-accessible media (e.g., storage devices such as hard disks, floppy disks, memory sticks, CD-ROMs, RAM, ROM, or a collection thereof). Computer-accessible media may contain executable instructions. Additionally or alternatively, a storage device may be provided separately from the computer-accessible media, which can provide instructions to a processing device to perform certain exemplary procedures, processes, and methods, as described herein. The depiction in Figure 3 is illustrative, and it will be understood that the functions and processes described herein can be performed by any number of network-enabled computers. It will also be understood that if the illustrated system 100 has only a single instance of certain components, multiple instances of these components may be used. System 100 may also include other devices not shown in Figure 1.

[0023] Network 130 may be any form of communication network that enables communication between trading entities of the trading monitoring system 100. For example, Network 130 may be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network. Network 130 may be an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless LAN, GSM (Global System for Mobile Communication), PCS (Personal Communication Service), a Personal Area Network (PAN), a Wireless Application Protocol (WAP), a Multimedia Messaging Service (MMS), an Enhanced Messaging Service (EMS), a Short Message Service (SMS), a Time Division Multiplexing (TDM)-based system, a Code Division Multiple Access (CDMA)-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, or one or more of other wired or wireless networks that transmit and receive data signals, or may include them. Network 130 can utilize one or more protocols of one or more network elements that are communicatively coupled. Network 130 may convert from one or more protocols of other protocols to one or more protocols of network devices, or from one or more protocols of other protocols to one or more protocols of network devices. Although Network 130 is depicted as a single network, it will be understood that it may include multiple interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network, and a home network.

[0024] Figure 4 is a schematic diagram of an exemplary ASM140. The exemplary ASM140 includes an ASM data processor 141 and a user interface 144 that receives information from and displays information to the ASM user. The user interface 144 may include any device for inputting information and instructions to the ASM, such as a touchscreen, keyboard, cursor control device, microphone, stylus, or digital camera. The user interface 144 may also include a display, which may be any type of device that presents visual information, such as a computer monitor, flat panel display, or mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays.

[0025] An exemplary ASM 140 may include either or both a cash receiving device 147 and an automated teller machine 148. The cash receiving device 147 may be any mechanism that securely receives cash from a user, determines the amount of cash received, and deposits the cash into a secure cash storage device 149. In some embodiments, the cash receiving device 147 may receive and scan checks or other documents necessary for processing ASM transactions and / or obtaining automated services. The automated teller machine 148 is any mechanism that withdraws a specified amount of cash from the cash storage device 149 and distributes it to authorized ASM users.

[0026] In some embodiments, the ASM 140 may include a service device 170 that communicates with the ASM data processor 141. The service device 170 may be any machine that provides automated services, or may include such machines. These may include, for example, conventional automatic car wash machines or coin-to-banknote exchange machines. The operation of the service device 170 may be controlled by the ASM data processor 141, and a cash receiving device 147 and an ATM 148 may be used for purchase transactions of products or services. In some embodiments, the service provided may itself be the receipt of cash to be deposited into a user's account, and may not require an additional service device 170.

[0027] The ASM 140 includes an ASM data processor 141 that communicates via a network 130 through a network communication interface 142. The ASM data processor 141 communicates with a memory 143, which stores information related to the operation of the ASM 140. This may include identification information (e.g., an ASM identifier) ​​and / or location information. The memory 143 may also have applications installed therein that have instructions for performing service vending and reporting operations. This may include, for example, applications that process machine service or product purchases and provide instructions to service equipment 170. It may also include transmitting transaction information to the ASM administrator 160.

[0028] The ASM 140 includes an ASM data processor 141 that communicates over the network 130 via a network communication interface 142. This service application may include an instruction for the ASM data processor 141 to receive a service request notification from a service facilitation system 150. This notification may be received directly from the service facilitation system 150 via the network 130, or it may be received from the service facilitation system 150 via the ASM administrator 160. The service request notification may include service request information for a service requested by a cardholder associated with a particular transaction card 120. The service request information may include an identification of the desired service and any additional information required by the ASM 140 to provide the desired service. In some embodiments, the service request information may specify a time interval at which the user will arrive at the ASM 140 to receive the service. The service request information may also include information related to the transaction card 120. In particular, this may include, or be, a card identifier or other information sufficient to distinguish the card 120 of the requesting account holder from other cards 120.

[0029] A service trading application may include instructions to establish non-networked wireless communication with a user device 110 and / or the account holder's smart trading card 120. In some embodiments, the application may achieve this by using a medium-range wireless, touchless communication device 145. In certain embodiments, the wireless communication device 145 includes a radio frequency identification receiver (or transceiver) 146 capable of operating in accordance with ISO 15693. The receiver 146 may establish wireless communication with a corresponding medium-range transmitter when the transmitter is brought within a range of about 1.5 m or less. In some embodiments, the device 145 may also include an NFC receiver or transceiver, or may include a single receiver / transceiver capable of switching frequency modes to enable communication in either NFC mode or ISO 15693 mode.

[0030] The wireless communication device 145 can establish wireless communication with the transaction card 120, in particular, for intermediate-range wireless communication. In certain embodiments, when a service transaction application establishes communication with the transaction card 120 via the wireless communication device 145, it may include a command for the ASM data processor 141 to receive transaction card information. This transaction card information may include identification information that can be compared with information previously received in a service request notification. In some embodiments, if the service application determines that the transaction card 120 communicating with (and therefore coexisting with) the ASM 140 is the card 120 associated with the service requester's account, it may begin providing the requested service.

[0031] Alternatively or additionally, transaction card information may include verification information that can only be verified by the card administrator and / or the service facilitation system 150. Such information may include, for example, an encrypted information block by the transaction card 120. In such an embodiment, the service transaction application may include instructions that the ASM data processor 141 constructs and sends to the service facilitation system 150. This request may include ASM identification information, card identification information and / or verification information. The service transaction application may receive a verification response message containing instructions to start the requested service. Upon receiving such a response message, the application may cause the ASM data processor 141 to start the service, or, if applicable, the service device 170 to start the service.

[0032] In the embodiments described above, the service request notification is received by the ASM140 before the user arrives at the ASM140's location. However, in some embodiments, if the ASM140 establishes wireless communication with the trading card 120 and determines that it has not received a service request notification associated with the trading card 120, it may send an inquiry to a service facilitation system 150 that identifies the trading card to determine whether the service can be provided without communication with the cardholder. Such service may be subject to a pending service request or may be established through simultaneous communication between the service facilitation system 150 and the trading card account holder. The service transaction application of the ASM140 may receive the service request notification in response to this inquiry. In some embodiments, a verification response may be received simultaneously.

[0033] In some embodiments, the service transaction application may be configured for further authentication of service requests. This may include configurations that receive multi-factor authentication information from the device 110 and / or directly from the user via the user interface 144. In some embodiments, authentication may include receiving an ASM transaction authentication code from the service facilitation system 150 and presenting that code to the requesting account holder using the display of the user interface 144. The code may then be transmitted by the user 110 to the service facilitation system 150 for authentication. Alternatively, the authentication instruction may include an instruction to capture a digital image of what is referred to as the authentication code and transmit what is referred to as the authentication code to the service facilitation system 150 for a second authentication.

[0034] Regardless of the specific authentication method, the service transaction application may also receive instructions from the service facilitation system 150 to perform the requested service at the time of authentication. The service transaction application may also transmit transaction completion information to the ASM administrator 160 and / or the service facilitation system 150.

[0035] It will be understood that various ASM140s may have different service capabilities and / or capacities. Even if they all have the same network and local communication capabilities, the services they provide may differ substantially. For example, some ASM140s can accept cash and coins, while others cannot. Some have limited or no user interface functionality and / or receive instructions and user information via a network connection to the account holder user device 110. Some provide mechanical services (e.g., car washing), while others provide only financial services.

[0036] In the exemplary embodiments presented herein, the account holder may be any individual or entity having a service transaction account. The account may be represented by any object, entity, or other mechanism that holds money or performs transactions in any form, including but not limited to electronic form. The account may be, for example, a card account (e.g., a prepaid card account, a stored value card account, a debit card account, a check card account, a payroll card account, a gift card account, a prepaid credit card account, or a charge card account) and have one or more transaction cards 120 associated therewith.

[0037] The trading card 120 may be any device having a processor for performing digital transactions and memory capable of permanently storing identification and encrypted information. This includes trading cards with chips ("smart" cards) and mobile and non-mobile users for computing the device. As shown in Figures 3 and 4, a typical trading card 120 usable in various embodiments of the present invention is a smart card with a microprocessor chip 121. The microprocessor chip 121 includes processing circuitry for storing and processing information, including a microprocessor 122 and memory 126. It will be understood that the processing circuitry may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware necessary to perform the functions described herein. In some embodiments, the chip 121 may include a power management system 125 which may include a power supply (e.g., a battery, capacitor, photovoltaic cell, electrodynamic or piezoelectric power scavenger, etc.) and circuitry for managing and distributing power to the components of the chip 121.

[0038] The microprocessor chip 121 may further include one or more wireless communication interfaces for short-range or intermediate-range wireless communication. In the illustrated embodiment, the chip 121 includes an NFC interface 124, which may include an NFC transmitter for establishing short-range wireless communication with a corresponding NFC receiver or transceiver. The chip 121 also includes an intermediate-range communication interface comprising an intermediate-range radio frequency transmitter operating in accordance with ISO 15693. Transaction cards equipped in this manner may be referred to herein as “neighborhood cards”. In some embodiments, the chip 121 may include a single wireless communication interface that can switch between short-range and intermediate-range (neighborhood) communication. In some embodiments, the microprocessor chip 121 may include circuitry for communication via other means such as Bluetooth, satellite, Wi-Fi, wired communication, and / or any combination of wireless and wired connections.

[0039] In certain embodiments, the memory 126 of the microprocessor chip 121 may store instructions for generating encrypted information and transmitting it to a receiving device (e.g., ASM 140) via the intermediate-range communication interface 128. Such encrypted information may be or include an encrypted verification block or signature that can be used by a service facilitation system 150 to authenticate and verify the presence of a transaction card 120 at a particular location of the ASM 140. In some embodiments, the memory 126 may store one or more card-specific keys that can be used to generate a one-time-use password or signature that can only be decrypted by a system that has access to such keys.

[0040] The NFC interface 124 and the microprocessor 122 can establish communication with a merchant transaction processing unit, in particular, to perform purchases and other transactions. The NFC interface 124 may also provide contact-based communication, in which case the interface 124 may have electrical circuits and contact pads on the surface of the card 120 to establish direct electrical communication between the microprocessor 122 and the processing circuit of the transaction terminal (e.g., ASM 140). Alternatively, and additionally, the NFC interface 124 may be for contactless communication with the transaction terminal.

[0041] The card chip memory 126 may be a read-only memory, a write-and-read multiplex memory, or a read / write memory, such as RAM, ROM, or EEPROM, and the chip 121 may include one or more of these memories. The memory 126 may store information related to the trading card account. In some embodiments, the memory 126 may permanently store a unique alphanumeric identifier associated with the account. In some embodiments, it may store the card encryption public key and / or private key.

[0042] Memory 126 may store one or more software applications for execution by the microprocessor 122. In various embodiments, memory 126 may store instructions for generating encrypted information and sending it to a receiving device (e.g., ASM 140) via the intermediate-range communication interface 128. Such encrypted information may be or include an encrypted verification block or signature that can be used to authenticate and verify the presence of the transaction card 120 during transaction processing.

[0043] In certain embodiments of the present invention, the card memory 126 may include an application that includes instructions to establish intermediate-range communication when the transaction card 120 is brought within the intermediate communication range of an intermediate-range wireless communication receiver (e.g., receiver 146 of ASM 140), and, once such communication is established, transmit transaction card information to the receiver. Such information may include, for example, an encrypted information block by the transaction card 120.

[0044] Referring to Figure 5, the account holder (or other user) processing device 110 may be any data processing and / or communication device used by the account holder to execute transactions and / or communicate with the transaction processing agency or service facilitation system 150, including but not limited to smartphones, laptops, desktop computers, and tablets. In certain embodiments, the device 110 is a mobile device having a memory module 113, a user interface 114, and an onboard data processor 111 that communicates with a network communication interface 112. The device 110 may also include an image capture device (e.g., a digital camera or scanner). The data processor 111 may include a microprocessor and associated processing circuitry and may include additional components necessary to perform the functions described herein, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware. The memory 113 can be read-only memory, write-once-read multiplex memory, or read / write memory, such as RPM, ROM, and EEPROM, and the user device 110 may include one or more of these memories.

[0045] The user interface 114 includes a user input device or mechanism, which can be any device for inputting information or instructions to the user 110, such as a touchscreen, keyboard, mouse, cursor control device, microphone, stylus, or digital camera. The user interface 114 may also include a display, which can be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays.

[0046] The network communication interface 112 establishes and supports wired or wireless data communication capabilities for connecting the device 110 to the network 130 or other communication networks. The user device 110 may also include an NFC interface 119 that can support near-field wireless communication with an NFC transmitter / receiver.

[0047] In embodiments of the present invention, the memory 113 may store therein one or more applications available to the data processor 111 for executing and / or monitoring transactions between the device 110 and the merchant device or transaction processing system via the network 130. These applications may include instructions that the data processor 111 can use to identify transaction events, store event data in the memory 113, and communicate the event data to the transaction processor.

[0048] In certain embodiments, memory 113 may store a service transaction application that requests a service from ASM 140. This application may include instructions received from the user via user interface 114 regarding a service transaction that the account holder wishes to complete using ASM 140. This information may include identifying or selecting the desired service from a list displayed to the user via user interface 114. Depending on the requested service, the application may prompt the user to provide additional parameters required by ASM 140 to initiate the service. The request information may also include identification of ASM 140 or selection of ASM 140 from a list received by user 110 from service facilitation system 150. The application may further include instructions to construct and send a service transaction request to service facilitation system 150 using the request information provided by the user. The transaction request may also include information identifying the user, account holder, account, and / or transaction card associated with the account. The service application may also receive a request response / acknowledgment from the service facilitation system 150, which may include information regarding the time and availability of the service at the selected ASM 140. In some embodiments, the response may include a proposed or alternative ASM location, which may be optionally selected by the account holder user.

[0049] The application may further instruct the data processor 111 to receive a second element verification request from the service facilitation system 150 via the network. This request is typically sent from the service facilitation system 150 after the account holder has arrived at the ASM 140 and the account holder's trading card 120 has transmitted card information to the ASM 140. The card information may be used for initial (first) authentication by the service facilitation system 150. The second authentication element verification request may include a request or instruction to the device data processor 111 to transmit at least one additional authentication element available to the service facilitation system 150 in order to verify that the second authentication criterion has been met. In some embodiments, the second authentication element may be, or include, login information and / or password information entered by the user within a predetermined time interval before or after arriving within the card communication range of the ASM140; in other embodiments, the second authentication element may be, or include, biometric characteristics of the account holder scanned or otherwise captured by the device within a predetermined time interval before or after arriving within the card communication range of the ASM140; and in certain embodiments, the second authentication element may be, or include, location information of the device 110, which can be obtained by the data processor 111 using GPS or other location information applications.

[0050] Referring to Figure 6, the service facilitation data processing system 150 is a network-enabled processing system that communicates with one or more account holder user devices 110 and multiple automated service machines 140 directly or via network 130 (or other networks) or via network 130 and ASM administrator 160. The service facilitation system 150 may include a secure communication interface 152 that communicates with network 130 and receives communications from user devices 110 and ASM 140. In some embodiments, the communication interface 152 may provide an initial security screen for verifying such communications. In some embodiments, the communication interface may communicate with the devices 110 via a first network (e.g., network 130) and with the ASM 140 via a second network.

[0051] The service facilitation system 150 further includes a service request processor 154 that receives ASM service requests from the device 110 associated with the account holder. The service request may be received as a separate, independent request (e.g., an email request) or as part of an online interactive session between the device 110 and the service facilitation system 150. In certain embodiments, the request may be sent by the device 110 using a service request application residing in the device 110.

[0052] As described above, an ASM service request may include identification information available to the request processor 154 to identify the user and / or the business card account to which user 110 is associated. The request may further include information about the service that the account holder wishes to obtain using the ASM 140. This may include information indicating the type of service and the desired parameters / characteristics of the service. In some embodiments, this may also include information relating to or identifying a particular ASM 140.

[0053] The request processor 154 may perform an initial authorization verification to ensure that the device 110 and / or the user are authorized to request and obtain the requested service. This may be based on verification of authorization information provided by the user (e.g., login information). In some embodiments, the initial verification may be established based on the user logging in via an account-related application on the user device 110.

[0054] The service request processor 154 may process a service request by retrieving ASM information from the ASM database 180 and comparing it with information provided by the user in the service request. The ASM database 180 may contain ASM data records for each ASM 140 in the ASM network. The data records may include information such as machine identifiers, the location of the ASM 140, merchant outlet-related information, access restrictions, transaction capacity or restrictions, and administrator information. In some cases, some or all of the candidates for ASM 140 may be managed by a separate third-party ASM administrator 160. In such cases, information on the ASM 140 managed in this manner is retrieved from the ASM administrator 160 by the service facilitation system 150 and stored in the ASM database 180 when the ASM 140 is added to system 100.

[0055] If a service request specifies a particular ASM140, the service request processor 154 can compare the requested service parameters with capability and status information obtained from the ASM database 180 for the requested ASM140 to determine an availability result (i.e., a determination that the ASM140 is available and capable of providing the requested service). In some embodiments, if no specific ASM140 is specified, the service request processor 154 can construct a list of candidate ASM140s in the vicinity of the user device 110 that can provide the requested service. The service request processor 154 may determine the best candidate ASM140 based on predetermined selection criteria and / or candidate availability information. Information regarding the candidate ASM140 may then be sent to the user device 110. Alternatively, the service request processor 154 may send a set of ASM candidates to the user device 110 for display to the account holder. In either case, the processor 154 may receive a response from the user device 110 that includes either acceptance of the proposed ASM140 or selection of a specific ASM140 from the candidate list.

[0056] Regardless of whether the “requested” ASM140 was determined from the initial service request or selected or approved by the user in a subsequent response, the request processor may send a service request notification to the transaction ASM140 and / or ASM administrator 160. The service request notification may include some or all of the information received in the service request. The service notification information may include an identification of the desired service and any additional information that the ASM140 may require to provide the desired service. In some embodiments, the service request information may specify a time interval in which the account holder is expected to arrive at the ASM140 to receive the service. The service request information may also include information relating to the nearby transaction card 120 or card account. In particular, this may be, or include, a card identifier or other information sufficient to distinguish the service requester’s transaction card 120 from other cards 120.

[0057] The Authentication Data Processor 158 is a network-enabled processing system that can ensure that an authorized account holder transaction card is present at the ASM location when a requested automated service transaction is being processed. The Authentication Data Processor 158 receives service verification requests from the ASM 140, either directly or via the ASM Administrator 160. The service verification request includes card authentication information, which includes either or both a card identifier and verification information, typically in the form of a card encrypted authentication block. The Authentication Data Processor 158 may use the card authentication information as the first authentication for the requested service. This involves retrieving and comparing the card and account information of the requested account holder's account from the card account database 190. The Authentication Data Processor may compare the received card identifier with the identifier of the card 120 associated with the account. In embodiments where the verification request includes an encrypted authentication block, the retrieved card account information may include one or more encryption keys available to the Authentication Data Processor 158 to decrypt the encrypted authentication block. In certain embodiments, the retrieved card information may also include counters that can be used to determine a one-use session key to decrypt the authentication block. This counter is decremented upon use and restored to the card account database. It will be understood that the successful decryption of the encrypted authentication block itself is sufficient to initially verify that the card presented by ASM140 is a card account-nearby card associated with the requester's account. Further verification can be achieved by comparing the decrypted content with information from the card account database 190.

[0058] In some embodiments, the authentication data processor 158 may obtain second authentication information to further authenticate the service transaction request. In some such embodiments, the authentication data processor 158 may verify that the account holder is logged in using an account-related application on the user device 110, or has logged in recently (i.e., within a predetermined time). In other embodiments, the authentication data processor 158 may send a request for one or more second authentication credentials to the account holder user device. This may include, for example, login information or biometric characteristics determined by the device 110, either simultaneously with the request or within a predetermined time interval prior to the request. Upon receiving the second authentication credentials from the account holder user device 110, the authentication data processor 158 can use them to establish a second authentication result for the service request (for example, by comparison with information retrieved from the account database 190).

[0059] In some embodiments, the authentication data processor 158 may receive a request for geolocation information from the account holder's user device 110. Upon receiving this information from the account holder's user device, the authentication data processor can use the geolocation information to determine the location of the account holder's user device and compare it to the location of the requested ASM 140. In some embodiments, the authentication data processor 158 may determine the distance between the account holder's user device 120 and the requested ASM 140 and compare it to a predetermined proximity criterion to determine whether the user device 120 is close enough to the ASM 140 to allow the requested service.

[0060] The authentication data processor 158 may determine an overall service authorization result for the requested service based on a combination of one or more of the above determinations (i.e., a first authentication result based on verification of the existence of the transaction card 120 associated with the requester's account, a second authentication result based on user-provided authentication information, and, where appropriate, an availability result for the requested ASM 140). If all applicable determination results are positive, the authentication data processor 158 establishes a positive service authorization result and sends an instruction to the requested ASM 140 to start the requested service. If any of the determination results are negative, the authentication data processor 158 may establish a negative service authorization result. In some embodiments, the authentication data processor 158 may send a denial of service message to the ASM 140 and / or user 110, which may include reasons for denying authorization of the requested service.

[0061] The service facilitation processing system of the present invention can be used to perform various service request authentication methods. Figure 7 shows the operation in exemplary method M100 for authenticating an automated service according to an embodiment of the present invention. In S110 of method M100, a service facilitation data processing system (e.g., data processing system 150 of system 100) receives a service request from an account holder user device (e.g., device 110 of user system 100) associated with a trading card account and a card account proximity card (e.g., card 120 of system 100). The service request may be received as a separate, independent request (e.g., an email request) or as part of an online interaction session between the account holder user device and the service facilitation system. The service request may include identification of any or all of the user device, the trading card account, the account holder associated with the trading card account, and some of the card account proximity cards. The request may also include identification of an ASM (e.g., ASM 140 of system 100) and the service provided by the ASM. The latter includes information indicating the type of service and the desired parameters / characteristics of the service.

[0062] In S120, the Service Facilitation Data Processing Unit sends a service request notification to the requested ASM. The service request notification may include some or all of the service request information. Typically, this includes an identification of the requested service and any additional information requested by the ASM to provide the service. In some embodiments, the service request information may specify a time interval at which the user will arrive at the ASM to receive the service. The service request information may include information related to the card account proximity card. In particular, this may be, or include, a card identifier or other information sufficient to distinguish the card account proximity card from other transaction cards.

[0063] In S130, the Service Facilitation Data Processor receives card authentication information from the requested ASM, received from the nearby card presented to the ASM. This includes card identifier information and / or an encrypted authentication block received by the ASM from the presented nearby card. In S140, the Service Facilitation Data Processor uses the card identifier information to verify that the presented nearby card is a nearby card of a card account. In some embodiments, this includes retrieving card and account information for the requesting account holder's account from the card account database and comparing the received card identifier with the identifier of the nearby card of the card account. In embodiments where the verification request includes an encrypted authentication block, the operation in S140 may include decrypting the encrypted authentication block. It will be understood that successful decryption of the encrypted authentication block itself may be sufficient to first verify that the card presented to the ASM is a nearby card of a card account. Further verification may be obtained by comparing the decrypted content with information from the card account database.

[0064] In S150, the service facilitation data processor determines a service authorization result for the requested service. In some embodiments, this may be based at least in part on the result of the card verification operation in S140. In some embodiments, the determination in S150 may be based at least in part on a positive result of a second authentication operation. This involves obtaining second authentication information from the user associated with the account. This can be achieved by sending a request for at least one second authentication credential to the account holder's user device and receiving the requested credentials from the E device. The requested credentials may be the user's biometric characteristics or login credentials received by the user device from the user.

[0065] In some embodiments, the operation in S150 may include verifying that the account holder user device is within or has been within an acceptable distance of the requested ASM. This verification may include sending a request for geolocation information to the account holder user device and receiving the requested geolocation information from the account holder user device. The service facilitation data processing device may then use the geolocation information to determine the location of the account holder user device and the separation distance between the account holder user device and the ASM. This separation distance can be compared to a predetermined proximity criterion to determine whether it is an acceptable separation distance for granting the requested service.

[0066] In some embodiments, the operation determining the service authorization result in S150 may include determining a service risk coefficient that indicates the relative degree of risk associated with the authorization of the requested service. The relative degree of risk may be based on determining the time interval since the most recent login to the account application associated with the card account, determining the time interval since the most recent transaction involving the card account, and / or determining the location of the most recent transaction involving the card account. Once the service risk factors are determined, they can be compared to predetermined risk factor criteria. The service facilitation data processor can determine a positive result for service authorization only if the service risk factors meet the predetermined risk factor criteria.

[0067] In some embodiments, the determination of the authorization result in S150 may include one or more actions that verify authorization for a user, user device, or card account to obtain the requested service in the requested ASM. This includes using information from the card account database to check whether the status of the card account's account parameters meets certain requirements for the requested service, whether the card account itself is authorized for the requested service, and / or whether the account holder's user device is associated with an authorized user requesting the requested service.

[0068] In some embodiments, the determination of the authorization result in S150 may include one or more actions that verify that the requested ASM is available and capable of providing the requested service. This may include comparing the requested service parameters with capability and status information obtained from the ASM database or the ASM administrator.

[0069] In S160, the Service Facilitation Data Processor may send a service authorization response to the requested ASM. If the service authorization result is positive, the service authorization response includes instructing the ASM to initiate the requested service. If the service authorization result is negative, the response instructs the ASM to deny the requested service.

[0070] Figure 8 shows the operation in an exemplary method M200 in which an automated service is provided by an ASM (e.g., ASM140 in system 100). In S210 of method M200, the ASM receives a service request notification from a service facilitation data processing system. The service request notification may include card account identification related to an account, account holder device, and nearby card. The service request notification may also include requested service information that can identify the requested service and one or more service characteristics or parameters. In some embodiments, the ASM may determine that it is not currently able to provide the requested service. In such embodiments, the ASM may send a response to the service facilitation data processing device indicating this.

[0071] In S220, the ASM establishes contactless communication with the nearby card presented at the ASM's location. In certain embodiments, this communication is established by using a communication device capable of intermediate-range wireless communication in accordance with ISO 15693. In certain embodiments, intermediate-range communication is established when the ISO 15693-compliant nearby card is placed within the intermediate communication range of the ASM. The maximum value of such communication range is 1.0 to 1.5 m. In S230, the ASM receives presented card information from the presented nearby card via intermediate-range communication. This includes the presented card identifier or card account identifier and an encrypted authentication block. The encrypted authentication block may be or include a one-time password encrypted by a microprocessor on the presented business card. In S240, the ASM sends a service authorization request to the service facilitation data processing system via the network. The service authorization request includes card authentication information that the service facilitation data processing system can use to verify that the presented nearby card is a nearby card associated with an account. The card authentication information may be at least a part of the presented card information, including the encrypted authentication block. In S250, the ASM receives an authorization response from the service facilitation data processing system, and in S260, the ASM determines whether the response is positive or negative. If the response is a positive authorization response, the ASM initiates the requested service in S270. If the response is a negative authorization response, the ASM rejects the service request in S280. As part of the denial of service operation, the ASM may display a message to the cardholder indicating that the service is being denied. In some embodiments, the negative response may include the reason why the service is being denied. In such embodiments, the ASM may also display this information.

[0072] It will be understood that the nature of the services requested, provided, or facilitated in the methods described above is limited only by the capabilities of the requested ASM. The present invention can be used to provide or facilitate any service that can be initiated and controlled by a network-enabled data processing system. The methods and systems of the present invention provide a significant improvement over current interactions with automated service machines. The present invention allows users to obtain services from such machines without contact or very close (e.g., NFC range) interaction. The present invention also enhances security by providing authentication of service requests based not only on information from a smart proximity card, but also on information from relevant devices that may be required to be in the same location as the card and the ASM.

[0073] While specific embodiments of this disclosure have been described in relation to what are considered to be the most practical and diverse embodiments currently available, it should be understood that this disclosure is not intended to be limited to the disclosed embodiments, but rather to cover a variety of modifications and equivalent arrangements that fall within the scope of the appended claims. Certain terms are used herein, but these are used in a general and descriptive sense only and are not intended to be limiting.

[0074] This specification discloses specific embodiments of the Art and illustrates them with examples to enable those skilled in the art to practice these specific embodiments, including the manufacture and use of any device or system, and the execution of any incorporated methods. The patentable scope of the specific embodiments of the Art is defined in the claims and may include other examples that those skilled in the art can conceive of. Such other examples are intended to be included in the claims if they have structural elements that are not different from the language of the claims, or if they include equivalent structural elements that are substantially not different from the language of the claims. Those skilled in the art will readily understand that the invention has broad utility and applicability. Many embodiments and adaptations of the invention other than those described herein, as well as many variations, modifications and equivalent arrangements, will become apparent from the invention and the preceding description or will be reasonably suggested, without departing from the essence or scope of the invention.

Claims

1. An automation method that allows automated services, The service facilitation data processing system receives service requests from account holder user devices, including the identification of an automated service machine (ASM) and the services provided by the ASM, wherein the account holder user device is associated with card accounts and cards near card accounts, and receives... The service facilitation data processing system transmits a service request notification to the ASM, which includes the card account identification associated with the nearby card and the requested service information. The service facilitation data processing system receives card authentication information, including the encrypted authentication block received by the ASM from the presented nearby card, from the ASM. The service facilitation data processing system uses the card authentication information to verify that the presented nearby card is a nearby card for the card account. The service facilitation data processing system determines the service permission result for the requested service, The service facilitation data processing system transmits a service authorization response to the ASM based at least partially on the service authorization result. Automation methods, including those mentioned above.

2. The operation of sending the aforementioned service request notification is performed after the operation of receiving card authentication information. The automation method according to claim 1.

3. The operation that determines the service authorization result is: Verification that the account parameter status of the card account meets the specified requirements for the requested service, Verify that the aforementioned card account is authorized to provide the requested service, Verify that the account holder user device is associated with a user authorized to request the requested service, The automation method according to claim 1, comprising at least one of a set including the following.

4. The operation that determines the service authorization result is: Sending a request for at least one second authentication credential to the account holder user device, The account holder user device receives at least one second authentication credential, The service authorization result is determined by using at least one of the second authentication credentials, at least partially. The automation method according to claim 1, including the method described in claim 1.

5. The at least one second authentication credential includes the user biometric characteristics of the account holder user device, The operation that determines the service authorization result is: Searching for the account holder biometric characteristics of the account holder associated with the aforementioned card account, The user biometric characteristics are compared with the account holder biometric characteristics, The automation method according to claim 4, including the method described in claim 4.

6. The automation method according to claim 4, wherein the at least one second authentication credential includes login credentials provided through the account application of the account holder user device.

7. The operation that determines the service authorization result is: Sending a request for geolocation information to the account holder user device, The requested geolocation information is received from the account holder user device, Using the geolocation information, the location of the account holder user device is determined, Determining the separation distance between the account holder user device and the ASM, To determine whether the aforementioned separation distance meets a predetermined proximity standard for the requested service. The automation method according to claim 1, including the method described in claim 1.

8. The operation that determines the service authorization result is: To determine a service risk factor that indicates the degree of relative risk associated with granting the aforementioned requested service, The service risk factors are compared with predetermined risk factor criteria, A positive service approval result is established only when the aforementioned service risk factors meet the predetermined risk factor criteria. The automation method according to claim 1, including the method described in claim 1.

9. The process for determining the aforementioned service risk factors is: Determine the time interval since the most recent login to the account application associated with the aforementioned card account, Determining the time interval from the most recent transaction associated with the aforementioned card account, To determine the location of the most recent transaction associated with the aforementioned card account, The automation method according to claim 8, comprising at least one of a set including the following.

10. The operation to verify that the presented nearby card is a nearby card for the card account is as follows: Determining the card-specific encryption key of the aforementioned nearby card, Using the aforementioned card-specific encryption key, a transaction-specific session key is constructed, Decrypting the aforementioned encrypted authentication block, The automation method according to claim 1, including the method described in claim 1.

11. A service facilitation data processing system for facilitating service transactions of nearby card accounts in any of several automated service machines (ASMs), A communication interface that selectively communicates with any of the plurality of ASMs via a first network and selectively communicates with account holder user devices associated with the nearby card account via a second network, The account holder user device receives a service request that includes the identification of the requested ASM and the services provided by the requested ASM, which is one of several ASMs. To send a service request notification to the requested ASM, including the requested service information and the nearby card account and the card account identification associated with the nearby card account, A service request data processor that executes, The ASM to receive the card authentication information it has received from the presented nearby card, The present nearby card is to be verified to be a nearby card for the card account, To determine the result of the service authorization for the requested service, In response to a decision of a positive service approval result, send a command to the requested ASM to initiate the requested service, An authentication data processor that performs the following: A service-facilitating data processing system equipped with the following features.

12. The authentication data processor further, as part of the operation that determines the service authorization, Sending a request for geolocation information to the account holder user device, Receiving the requested geolocation information from the account holder user device, Using the geolocation information, determine the location of the account holder user device. Determining the separation distance between the account holder user device and the requested ASM, To determine whether the separation distance satisfies the predetermined proximity criteria for the requested service, The service facilitation processing system according to claim 11, comprising:

13. The authentication data processor, as part of the operation to determine the service authorization, Sending a request for at least one second authentication credential to the account holder user device, Receiving the at least one second authentication credential from the account holder user device, The result of the service authorization is determined using at least one of the second authentication credentials. Further execution The service facilitation data processing system according to claim 11.

14. The aforementioned card authentication information includes an encrypted authentication block, The authentication data processor, as part of the operation that determines the service authorization, Obtain encryption key information for cards near the aforementioned card account from the card account information database, Using the aforementioned encryption key information, the encrypted authentication block is decrypted to obtain the card authentication information. In order to confirm that the presented nearby card is a nearby card for the card account, the card authentication information is used, Further execution The service facilitation data processing system according to claim 11.

15. An automation method that provides an automation service, The automated service machine (ASM) receives service request notifications from the service facilitation data processing system, including card account identification and requested service information associated with the account holder device and nearby card, The aforementioned ASM establishes contactless communication with the presented nearby card, The ASM receives presented card information, including the presented card identifier and the encrypted authentication block, from the presented nearby card. The ASM transmits a service authorization request to the service facilitation data processing system, which includes at least a portion of the presented card information, including the encrypted authentication block. The ASM receives permission responses from the service facilitation data processing system, In response to receiving permission, the ASM initiates the requested service, Automation methods including

16. The ASM is capable of intermediate-range wireless communication in accordance with ISO 15693, The operation to establish the contactless communication includes occurring immediately when the presented nearby card is brought within the maximum communication range of the ASM. The automation method according to claim 15.

17. The maximum communication range is 1.0 to 1.5 m. The automation method according to claim 16.

18. The requested service is a cash transaction service. The automation method according to claim 15.

19. Receiving a positive authorization response indicates that the account holder user device is within a predetermined distance from the ASM. The automation method according to claim 15.

20. The encryption authentication block is characterized by including the encryption one-time password or one-time password, as determined by the microprocessor of the nearby card. The automation method according to claim 15.