System and method for accessing the web using contactless cards
The use of a contactless card for secure authentication via NFC communication addresses the inefficiencies and security vulnerabilities of conventional methods, offering a faster and more secure way to access web applications by dynamically guiding user devices through encrypted authentication credentials.
Patent Information
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Filing Date
- 2024-03-14
- Publication Date
- 2026-04-10
AI Technical Summary
Conventional methods for verifying user identity in web applications are time-consuming and insecure, as they rely on one-time passwords that can be intercepted or stolen, leading to frustration and potential fraud.
A system and method using a contactless card to dynamically guide a user device to a URL, enabling secure authentication through NFC communication, where the contactless card shares authentication credentials with the user device, which are then verified by a server before granting access to the desired web application.
This approach provides faster and more secure access to web applications by reducing human error and minimizing the risk of credential theft, enhancing user experience and security.
Smart Images

Figure 2026511067000001_ABST
Abstract
Description
Technical Field
[0001] This application claims the priority of U.S. Patent Application No. 18 / 124516, filed on March 21, 2023, the disclosure of which is incorporated herein by reference in its entirety.
[0002] The present invention generally relates to accessing web applications with contactless cards.
Background Art
[0003] Mobile or web applications are often used to verify the identity of mobile users. For example, a user may want to purchase from a website. To verify the user's identity, the website sends the user a Uniform Resource Locator (URL) link. The user clicks on the link and is directed to another website or mobile application where the user is asked to enter a one-time password. This two-factor authentication adds an additional layer of security and helps prevent fraudsters from using the user's stolen information to purchase products.
[0004] However, this conventional method is time-consuming. The input in the second authentication method takes time and can frustrate the user. Also, this method may not be secure. An unauthorized party can intercept the one-time password over the network or simply steal the user's number. A faster and more secure method is needed to access web applications.
[0005] These and other deficiencies exist. Therefore, there is a need to provide a system and method that overcome these deficiencies and provide secure authentication.
Summary of the Invention
[0006] Embodiments of this disclosure provide a system for the dynamic guidance of a user device to a URL, the system comprising a user device, a card, and a server. The server further comprises memory and a processor. The processor opens a communication field between the user device and the card and sends a request from the card to the user device, which guides the user device to the server, the request further comprising a personal identification code associated with the owner of the user device and a Uniform Resource Locator (URL) associated with a given website. The processor guides the user device to the server. The processor then receives an authentication request from the server and sends authentication credentials to the server. The processor verifies the authentication credentials and guides the user device to the website associated with the URL.
[0007] Embodiments of the present disclosure provide a method for the dynamic guidance of a user device to a URL, the method comprising opening a communication field between the user device and a card by a processor, and sending a request from the card to the user device to guide the user device to a server, the request further comprising a personal identification code associated with the owner of the user device and a uniform resource locator (URL) associated with a given website, the method comprising guiding the user device to the server by the processor, receiving an authentication request from the server, sending authentication credentials to the server, verifying the authentication credentials by the processor, and guiding the user device to the website associated with the URL by the processor.
[0008] Embodiments of the present disclosure provide a computer-readable non-temporary medium containing instructions executable by a computer, which, when executed by a processor, includes the steps of: opening a communication field between a user device and a card; sending a request from the card to the user device, which directs the user device to a server, the request further including a personal identification code associated with the owner of the user device and a uniform resource locator (URL) associated with a given website; and the processor performing a procedure which includes the steps of directing the user device to the server, receiving an authentication request from the server, sending authentication credentials to the server, verifying the authentication credentials by the processor, and directing the user device to the website associated with the URL by the processor. [Brief explanation of the drawing]
[0009] To facilitate a full understanding of the present invention, the accompanying drawings are provided for reference. The drawings are not intended to be construed as limiting the present invention, but are intended solely to illustrate various aspects and embodiments of the present invention.
[0010] [Figure 1] Figure 1 is a block diagram showing a system according to an exemplary embodiment. [Figure 2] Figure 2 shows a contactless card according to an exemplary embodiment. [Figure 3] Figure 3 shows a contact pad of a contactless card according to an exemplary embodiment. [Figure 4] Figure 4 is a method flowchart illustrating an encryption method according to an exemplary embodiment. [Figure 5] Figure 5 shows a near-field communication (NFC) field according to an exemplary embodiment. [Figure 6] Figure 6 is a flowchart showing the process according to an exemplary embodiment. [Figure 7] Figure 7 is a flowchart showing the process according to an exemplary embodiment. [Figure 8]Figure 8 is a flowchart showing the process according to an exemplary embodiment. [Modes for carrying out the invention]
[0011] Exemplary embodiments of the present invention are described below to illustrate various features of the invention. The embodiments described herein are not intended to limit the scope of the invention, but are intended to provide examples of the components, uses, and operations of the invention.
[0012] Furthermore, the described features, advantages, and characteristics of the exemplary embodiments may be combined in any suitable manner. Those skilled in the art will see that an embodiment may be carried out without one or more of the specific features or advantages of the embodiment. In other examples, certain embodiments may recognize additional features and advantages that may not be present in all embodiments. Those skilled in the art will understand that the features, advantages, and characteristics of the described embodiments can be combined interchangeably with those of other embodiments.
[0013] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or part of an instruction containing one or more executable instructions for performing a particular logical function. In some alternative implementations, the functions shown within a block may be executed in a different order than shown in the diagram. For example, two consecutively shown blocks may actually be executed substantially simultaneously, and blocks may be executed in reverse order depending on the related functions. It should also be noted that each block in the block diagram and / or flowchart, and combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based system that performs a particular function or operation, or a combination of dedicated hardware and computer instructions.
[0014] Exemplary embodiments of this disclosure include systems and methods for using a contactless card to access a web application. Generally, the system includes a contactless card, a user device such as a smartphone, and a server. The contactless card may be pre-configured with URL requests (or other link requests) and personal ID data. The user may tap the contactless card on the user device. In response, the user device reads the information and directs the user device to the web application. Before granting access, the web application requires the user to verify itself. To perform verification, the user device opens a communication field such as an NFC field. The contactless card enters the NFC field and shares authentication credentials. These credentials may, but are not limited to, a digital signature or a diversified key exchange. After receiving the authentication credentials, the server verifies the credentials and allows the user to access the web application.
[0015] The exemplary embodiment offers many improvements over conventional systems and methods. For example, the exemplary embodiment provides a faster way for users to access a website or application. Rather than using a search engine or manually entering a URL to find a desired web application, users can simply tap a contactless card on their device, saving time and improving the user experience.
[0016] Furthermore, the exemplary embodiment reduces user errors and frustrations. For example, a user may struggle to find a website or web application on their device, but the exemplary embodiment avoids this frustration and wasted time for the user.
[0017] This embodiment also provides security improvements to conventional systems and methods. By implementing NFC fields to transmit authentication credentials, the system significantly reduces the opportunity for an intruder to steal the credentials. In addition, the authentication credentials can be encrypted to further enhance security.
[0018] Figure 1 is a block diagram showing a system according to an exemplary embodiment.
[0019] Figure 1 shows a system 100 according to an exemplary embodiment. System 100 may include a contactless card 110, a user device 120, a server 130, a network 140, and a database 150. Although Figure 1 shows a single example of the components of system 100, system 100 may include any number of components.
[0020] The system 100 may include one or more contactless cards 110, which will be further described below with reference to Figures 2 and 3. In some embodiments, the contactless card 110 may communicate wirelessly with the user device 120, for example, using NFC.
[0021] System 100 may include a user device 120. The user device 120 may be a network-compatible computer device. Exemplary network-compatible computer devices include, but are not limited to, servers, network devices, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, Internet browsers, mobile devices, kiosks, contactless cards, automated teller machines (ATMs), or other computer devices or communication devices. For example, the network-compatible computer device may include an iPhone (registered trademark), iPod (registered trademark), iPad (registered trademark) of Apple, or other mobile devices running Apple's iOS (registered trademark) operating system, devices running Microsoft's Windows (registered trademark) Mobile operating system, devices running Google's Android (registered trademark) operating system, and / or other smartphones, tablets, or similar wearable mobile devices.
[0022] The user device 120 may include a processor 121, a memory 122, and an application 123. The processor 121 may be a processor, a microprocessor, or other processor, and the user device 120 may include one or more of these processors. The processor 121 may include a processing circuit with additional components necessary to perform functions described herein, such as additional processors, memories, error and parity / CRC checkers, data encoders, collision avoidance algorithms, controllers, command decoders, security primitives, and anti-tampering hardware.
[0023] Processor 121 may be connected to memory 122. Memory 122 may be a read-only memory, a write-once read-multiple (WORM) memory, or a read / write memory, such as RAM, ROM, EEPROM, etc., and user device 120 may include one or more of these memories. The read-only memory may be read-only or once-programmable as programmable at the time of factory shipment. With once-programming, it can be read many times after being written once. The write-once memory may be programmed at a certain point after the memory chip has been shipped from the factory. Once programmed, the memory cannot be rewritten but can be read many times. The read / write memory may be programmed and reprogrammed many times after factory shipment. Also, it may be read many times. Memory 122 may be configured to store one or more software applications such as application 123, and other data such as the user's private data and financial account information.
[0024] Application 123 may include one or more software applications, such as a mobile application and a web browser, and may include instructions for execution on user device 120. In some examples, user device 120 may run one or more applications, such as software applications, that enable network communication with one or more components of system 100, transmit and / or receive data, and perform the functions described herein. When executed by processor 121, application 123 may provide the functions described herein to perform the steps and functions in the processing flow described below. Such processing may be performed by software, such as software modules for execution on a computer or other device. Application 123 may provide a graphical user interface (GUI) for the user to view and interact with other components and devices in system 100. The GUI may be formatted, for example, as a web page in hypertext markup language (HTML), extended markup language (XML), or in other formats suitable for display on a display device, depending on the application used by the user to interact with system 100.
[0025] The user device 120 may further include a display 124 and an input device 125. The display 124 may be any type of device for displaying visual information, such as a computer monitor, flat panel display, or mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 125 may include any device for inputting information into the user device 120, which is available to and supported by the user device 120, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or video camera. These devices may be used to input information and interact with the software and other devices described herein.
[0026] System 100 may include a server 130. Server 130 may be a network-enabled computer device. Examples of network-enabled computer devices include, but are not limited to, servers, network equipment, personal computers, workstations, telephones, handheld personal computers, personal digital assistants, thin clients, fat clients, internet browsers, mobile devices, kiosks, contactless cards, or other computer or communication devices. For example, network-enabled computer devices may include Apple's iPhone, iPod, iPad, or other mobile devices running Apple's iOS® operating system, devices running Microsoft's Windows® Mobile operating system, devices running Google's Android® operating system, and / or other smartphones, tablets, or similar wearable mobile devices.
[0027] Server 130 may include a processor 131, memory 132, and application 133. Processor 131 may be a processor, microprocessor, or other processor, and server 130 may include one or more of these processors. Processor 131 may include processing circuitry that includes additional components necessary to perform the functions described herein, such as additional processors, memory, error and parity / CRC checkers, data encoders, collision avoidance algorithms, controllers, command decoders, security primitives, and tamper-proof hardware.
[0028] The processor 131 may be connected to memory 132. Memory 132 may be read-only memory, write-once (Write Once Read Multiple) memory, or read / write memory, such as RAM, ROM, or EEPROM, and the server 130 may include one or more of these memories. Read-only memory may be programmable as read-only or one-time programmable at the time of factory shipment. One-time programming allows data to be written once and read multiple times. Write-once memory may be programmed at some point after the memory chip has left the factory. Once programmed, memory cannot be rewritten but can be read multiple times. Read / write memory may be programmed and reprogrammed multiple times after factory shipment. It can also be read multiple times. Memory 132 may be configured to store one or more software applications, such as application 133, and other data such as user private data and financial account information.
[0029] Application 133 may include one or more software applications that include instructions for execution on Server 130. In some examples, Server 130 may run one or more applications, such as software applications, that enable network communication with one or more components of System 100, send and / or receive data, and perform the functions described herein. When executed by Processor 131, Application 133 may provide the functions described herein to perform the steps and functions in the processing flow described below. For example, Application 133 may be executed to receive web form data from User Device 120 and Card 110, maintain a web session between User Device 120 and Card 110, and mask private data received from User Device 120 and Card 110. Such processing may be performed by software, such as software modules, for execution on a computer or other device. Application 133 may provide a graphical user interface (GUI) for the user to view and interact with other components and devices in System 100. The GUI can be formatted, for example, as a web page in Hypertext Markup Language (HTML) or Extended Markup Language (XML), or in other formats suitable for display on a display device, depending on the application used by the user to interact with System 100.
[0030] Server 130 may further include a display 134 and an input device 135. The display 134 may be any type of device for displaying visual information, such as a computer monitor, flat panel display, or mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device 135 may include any device available to and supported by Server 130 for inputting information into Server 130, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or video camera. These devices may be used to input information and interact with the software and other devices described herein.
[0031] System 100 may include one or more networks 140. In some examples, network 140 may be one or more wireless networks, wired networks, or any combination of wireless and wired networks, and may be configured to connect user devices 120, servers 130, databases 150, and cards 110. For example, network 140 may include one or more of the following: fiber optic networks, passive optical networks, cable networks, Internet networks, satellite networks, wireless local area networks (LANs), global systems for mobile communications, personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplexing-based systems, code division multiplexing-based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n, 802.11g, Bluetooth®, NFC, radio frequency identification (RFID), Wi-Fi, etc.
[0032] In addition, network 140 may include, but is not limited to, telephone lines, optical fibers, IEEE Ethernet 902.3, wide area networks, wireless personal area networks, LANs, or global networks such as the Internet. Furthermore, network 140 may support Internet networks, wireless communication networks, cellular networks, or any combination thereof. Network 140 may further include any number of the exemplary types of networks described above, either as a single network, a standalone network, or working together. Network 140 may utilize one or more protocols of one or more communicatively connected network elements. Network 140 may translate protocols of one or more network devices to or from other protocols. Although network 140 is shown as a single network, it should be understood from one or more examples that network 140 may include multiple internally connected networks, such as the Internet, service provider networks, cable television networks, corporate networks such as credit card agency networks, and home networks. Network 140 may further include, or be configured to include, one or more front channels that are publicly accessible and whose communications may be observable, and one or more secure back channels that are not publicly accessible and whose communications are not observable.
[0033] System 100 may include a database 150. Database 150 may be one or more databases configured to store data including, but not limited to, user private data, user financial accounts, user identity, user transactions, and authenticated and unauthenticated documents. Database 150 may include relational databases, non-relational databases, or other database implementations, and any combination thereof, including multiple relational and non-relational databases. In some examples, database 150 may include a desktop database, a mobile database, or an in-memory database. Furthermore, database 150 may be hosted internally by server 130, or it may be hosted externally by server 130, for example, by a server, by a cloud-based platform, or by a storage device that communicates data with server 130.
[0034] In some examples, the exemplary procedures relating to the present disclosure described herein may be performed by an processing unit and / or computing device (e.g., computer hardware device). Such a processing unit and / or computing device may be, or include, all or part of a computer / processor, which includes, for example, one or more microprocessors and can use instructions stored in a non-temporary computer-accessible medium (e.g., RAM, ROM, hard drive, or other storage device). For example, the computer-accessible medium may be a contactless card 110, a user device 120, a server 130, a network 140, and part of the memory of a database 150 or other computer hardware device.
[0035] In some examples, computer-accessible media (for example, storage devices such as hard disks, floppy disks, memory sticks, CD-ROMs, RAM, ROMs, or combinations thereof, as described herein) may be provided (for example, in communication with a processing unit). Computer-accessible media may contain instructions that can be executed thereon. In addition or alternatively, storage devices may be provided separately from computer-accessible media and may be instructed to configure a processing unit to perform certain exemplary procedures, processes, and methods, for example, as described herein above.
[0036] Figure 2 is a diagram of a card according to an exemplary embodiment.
[0037] Figure 2 shows a contactless card 200 according to an example embodiment. The contactless card 200 may include a payment card such as a credit card, debit card, or gift card issued by a service provider 205, as indicated on the front or back of the card 200. In some examples, the payment card may include a dual-interface contactless payment card. In some examples, the contactless card 200 may include, but is not limited to, an identification card, membership card, loyalty card, transit card, and access card, and is not related to a payment card.
[0038] The contactless card 200 may include a substrate 210 which may include a single layer or one or more layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 200 may have physical properties conforming to the ID-1 format of ISO / IEC 7810, while in other cases, the contactless card may conform to ISO / IEC 14443. However, the contactless card 200 relating to this disclosure may have different properties, and it should be understood that this disclosure does not require the use of contactless cards as payment cards.
[0039] The contactless card 200 may also include identification information 215 displayed on the front and / or back of the card, and a contact pad 220. The contact pad 220 may be configured to establish communication with another communication device, such as a user device, smartphone, laptop, desktop, or tablet computer. The contactless card 200 may also include processing circuits, an antenna, and other components not shown in Figures 2 and 3. These components may be located behind the contact pad 220 or elsewhere on the substrate 210. The contactless card 200 may also include a magnetic stripe or magnetic tape, which may be located on the back of the card (not shown in Figure 2).
[0040] Figure 3 shows the contact pad 305 of the contactless card 200 according to an example embodiment.
[0041] As shown in Figure 3, the contact pad 305 may include a processing circuit 310 for storing and processing information, which includes a microprocessor 320 and memory 325. It is understood that the processing circuit 310 may include additional components necessary to perform the functions described herein, such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware.
[0042] Memory 325 may be read-only memory, write-once (Write Once Read Multiple) memory, or read / write memory, such as RAM, ROM, or EEPROM, and the contactless card 200 may include one or more of these memories. Read-only memory may be programmed as read-only or one-time programmable at the time of factory shipment. One-time programming allows it to be written to once and read multiple times. Write-once memory may be programmed at some point after the memory chip has left the factory. Once programmed, memory cannot be rewritten but can be read multiple times. Read / write memory may be programmed and reprogrammed multiple times after factory shipment. It can also be read multiple times.
[0043] Memory 325 may be configured to store one or more applets 330, one or more counters 335, and customer identifiers 340. One or more applets 330 may include one or more software applications configured to run on one or more contactless cards, such as Java Card applets, and to perform the functions described herein. However, it is understood that applet 330 is not limited to Java Card applets, but may instead be any software application that can run on contactless cards or other devices with limited memory. One or more counters 335 may include numeric counters sufficient to store integers. Customer identifiers 340 may include a unique alphanumeric identifier assigned to a user of a contactless card 200, the identifier may distinguish a user of a contactless card from a user of another contactless card. In some examples, customer identifiers 340 may identify both the customer and the account assigned to the customer, and further may identify the contactless card associated with the customer's account.
[0044] The processor and memory elements of the exemplary embodiments described above are described with reference to the contact pads, but the disclosure is not limited thereto. It is understood that these elements may be implemented outside of the pads 305, or entirely apart from the pads 305, or as additional elements in addition to the elements of the processor 320 and memory 325 located within the contact pads 305.
[0045] In some examples, the contactless card 200 may include one or more antennas 315. The one or more antennas 315 may be located within the contactless card 200 and around the processing circuit 310 of the contact pads 305. For example, the one or more antennas 315 may be integrated with the processing circuit 310, or the one or more antennas 315 may be used with an external booster coil. In another example, the one or more antennas 315 may be located outside the contact pads 305 and the processing circuit 310.
[0046] In an embodiment, the coil of the contactless card 200 may operate as the secondary side of an air-core transformer. The terminal may communicate with the contactless card 200 by cutting off power or by amplitude modulation. The contactless card 200 may infer data transmitted from the terminal using the gap in the contactless card's power connection, which may be functionally maintained through one or more capacitors. The contactless card 200 may reply to the communication by switching the load with the contactless card's coil or load modulation. Load modulation may be detected by the terminal's coil via interference.
[0047] As described above, the contactless card 200 may be built on a software platform capable of running on other memory-limited devices such as smart cards or JavaCards, and one or more applications or applets may be securely executed on it. The applet may be added to the contactless card to provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a Near-Field Data Exchange request, from a reader such as a mobile NFC reader, and generate an NFC Data Exchange Format (NDEF) message containing a cryptographically secure OTP encoded as an NDEF text tag.
[0048] Figure 4 is a flowchart of a key diversification method 400 according to an exemplary embodiment.
[0049] In some examples, the sender and receiver may wish to exchange data via a sending device and a receiving device. In some examples, the sending device is a contactless card and the receiving device is a server. It is understood that one or more sending devices and one or more receiving devices may be involved, insofar as each party shares the same shared secret symmetric key. In some examples, the sending and receiving devices may be provisioned with the same master symmetric key. In other examples, the sending device may be provisioned with a diversified key generated using the master key. In some examples, the symmetric key may include a shared secret symmetric key that is kept secret from all parties other than the sending and receiving devices involved in the exchange of secure data. It is further understood that some of the data exchanged between the sending and receiving devices may include at least some of the data which may be called a counter value. The counter value may include a number which changes each time data is exchanged between the sending and receiving devices.
[0050] The transmitting and receiving devices may be configured to communicate via NFC, Bluetooth®, RFID, Wi-Fi, and / or similar technologies. The transmitting and receiving devices may also be network-enabled computer devices. In some examples, the transmitting device may include a contactless card, and the receiving device may include a server. In other examples, the receiving device may include a user device or a user device application.
[0051] Method 400 may begin with operation 405. In operation 405, the transmitting device and the receiving device may be provisioned with the same master key, such as the same master symmetric key. The transmitting device may be a user device. The receiving device may be a contactless card. The transmitting device may update a counter when it is preparing to process sensitive data in a symmetric encryption operation. In addition, the transmitting device may select an appropriate symmetric encryption algorithm, which may include at least one of the symmetric encryption algorithms, HMAC algorithms, and CMAC algorithms. In some examples, the symmetric algorithm used to process the divergence value may include any symmetric encryption algorithm used as necessary to generate a divergence symmetric key of the desired length. Examples of symmetric algorithms, though not limited to these, may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC.
[0052] In step 410, the transmitting device takes the selected encryption algorithm and processes the counter value using the master symmetric key. For example, the transmitting device may choose a symmetric encryption algorithm and use a counter that is updated with every interaction between the transmitting and receiving devices. One or more counters may include enough numeric counters to store integers. The transmitting device may increment the counter one or more times.
[0053] In step 415, the transmitting device generates two session keys: an ENC (encryption) session key and a MAC (message authentication code) session key. The transmitting device may use a master symmetric key to generate the session keys and encrypt the counter value using a selected symmetric encryption algorithm.
[0054] In step 420, the transmitting device generates a MAC based on the counter, a unique customer identifier, and a shared secret MAC session key. The customer identifier may include a unique alphanumeric identifier assigned to a contactless card user, and the identifier may distinguish a contactless card user from other contactless card users. In some examples, the customer identifier may identify both the customer and the account assigned to that customer, and may further identify the contactless card assigned to the customer's account.
[0055] In step 425, the transmitting device encrypts the MAC using the ENC session key. Once encrypted, the MAC can become ciphertext. In some examples, cryptographic operations other than encryption may be performed, and multiple cryptographic operations may be performed using a diversified symmetric key before transmitting the data to be protected.
[0056] In some examples, the MAC ciphertext may be a digital signature used to verify user information. Other digital signature algorithms, such as public-key asymmetric algorithms, e.g., digital signature algorithms and RSA algorithms, or zero-knowledge protocols, may be used to perform this verification.
[0057] In step 430, the transmitting device sends ciphertext to the receiving device. The ciphertext may include applet information, a unique customer identifier, a counter value, and an encrypted MAC.
[0058] In step 435, the receiving device verifies the ciphertext.
[0059] Figure 5 shows an example of near-field communication (NFC) according to a specific embodiment.
[0060] Generally, NFC is the transmission of data via electromagnetic waves, enabling two or more devices to communicate with each other without physical contact. NFC operates on the ISO / IEC 18000-3 wireless interface at 13.56 MHz and communicates at speeds ranging from 106 kbit / s to 424 kbit / s. When two NFC-enabled devices are placed within very close range (e.g., a few centimeters), they can perform information transactions. NFC is beneficial to consumer transactions because it enables near-instantaneous reading of information. The receiving device reads the transmitted data the moment it is sent. Therefore, human error is greatly reduced. In addition, NFC reduces the time required to read a card. Consumers can simply touch the card or user device to an NFC-enabled reader rather than swiping the card through a reader. Furthermore, NFC reduces the risk of interference from fraudulent parties. NFC devices can only communicate over very short distances, making it very difficult to intercept the information being transmitted between devices.
[0061] Some examples of NFC communication include NFC card emulation, where a smartphone operates a smart card or similar device, enabling users to perform transactions such as payments. Another example is NFC reader / writer communication, which allows a device to read information stored on an NFC tag embedded in a label or smart poster. Yet another example is NFC peer-to-peer communication, which allows two NFC-enabled devices to communicate with each other to exchange information.
[0062] The NFC standard covers communication protocols and data exchange formats and is based on existing RFID standards, including ISO / IEC 14443 and FeliCa®. The standard includes ISO / IEC 18092 and standards defined by the NFC Forum.
[0063] In Figure 5, the user device 505 and the contactless card 510 are interacting within the NFC field 515. The user device is further described with reference to Figure 1. The contactless card is further described with reference to Figures 2 and 3. Both the user device and the contactless card may be enabled with NFC technology. The user and the card can come into close contact with each other and exchange information within the communication field.
[0064] Figure 6 shows Figure 600 illustrating a sequence according to an exemplary embodiment. The sequence may include a contactless card, a user device, and a server. These elements are further described with reference to Figures 1-3 and Figure 5.
[0065] In operation 605, the user device opens a communication field. This operation may be performed by the processor associated with the user device. The user device may include, but is not limited to, a smartphone, tablet, computer, or smartwatch. The communication field may be a Bluetooth®, Near Field Communication (NFC) field, an RFID-compatible field, or another communication field.
[0066] In operation 610, the user may bring a contactless card into a communication field opened by the user device. The contactless card may include, but is not limited to, a card associated with an account holder at a banking institution, or an account holder of an spending account, savings account, or growth account. Upon entering the communication field, the contactless card may transmit a predetermined set of information to the user device. The information may include a personal ID (identifier) associated with the contactless card and a URL request. The personal ID may be a unique customer identifier as further described with reference to Figure 3, or the personal ID may be other personal identification data unique to the contactless card. For example, the personal ID may be associated with an email address, telephone number, contactless card information, driver's license number, passport number, date of birth, or other personal information associated with the user or the owner of the user device or user device application. In some embodiments, the personal ID may be dynamically generated based on the user's transaction history, spending habits, or other historical or behavioral data. For example, the user may frequently make purchases on amazon.com. After a user has visited amazon.com for a certain period of time, or after a certain number of visits, the user device application or server can associate amazon.com with the personal ID. Later, if the user changes their spending habits, the user device application or server can change the destination URL to another site. The user device application can also associate the personal ID with a specific software application or web application. In other embodiments, the user can independently change the destination URL via the user device application. After the personal ID is sent to the server, a copy of the personal ID may be stored in memory or a database associated with the server. URL requests may be stored in memory associated with a contactless card. A contactless card may hold one or more URL requests. URL requests may be associated with a given website or web application.
[0067] In operation 615, the user device directs the user to a server. This operation may be performed in response to a user device receiving a personal ID and URL request from a contactless card. The server may be associated with a specific website or web application. In addition, the server may be associated with a website associated with the URL request from the contactless card.
[0068] In operation 620, the server may send an authentication request to the user device. The authentication request may be sent over the network. The authentication request may be sent by Short Message Service (SMS), Multimedia Message Service (MMS), or other suitable method.
[0069] In operation 625, the user device may open a communication field. This operation may be performed in response to receiving an authentication request from the server. The communication field may be a Bluetooth®, Near Field Communication (NFC) field, an RFID-compatible field, or another communication field.
[0070] In operation 630, when the contactless card enters the communication field, it can transmit authentication credentials to the user device. These authentication credentials may be associated with the exchange of private and public keys between the contactless card and the user device. The contactless card may possess a private key. This private key can be transmitted to the user device, which in turn transmits the private key to a server possessing a public key. This diversified key exchange may be the same process as further described with reference to Figure 4. In addition, the authentication credentials may include a digital signature from the contactless card.
[0071] In other embodiments, the authentication credentials may be in a different format. For example, the authentication credentials may be a password, a personal identification number (PIN), a fingerprint scan, a facial scan, voice recognition, or other biometric authentication.
[0072] In operation 635, the server may verify the authentication credentials transmitted by the contactless card. This operation may be performed by a processor associated with the server or by a predetermined algorithm. In operation 640, the server allows the user to access the website, web application, or mobile application associated with the URL request. This operation may be performed in response to the verification of the authentication credentials from the contactless card.
[0073] Figure 7 is a flowchart illustrating a process according to an exemplary embodiment. In some embodiments, a card may be provisioned with one or more user identification data (personal identifiers) and a URL. The URL may be read-only or read-and-write. A user can provision a URL to direct their user device to a first website, at which point the server matches the personal ID against a second URL. In directing the user to the desired second URL via the first URL, this process facilitates the user dynamically changing the second URL.
[0074] The process may begin with the processor opening a communication field in operation 705, where the user device opens a communication field. The communication field may be a Bluetooth®, NFC field, RFID-compatible field, or other communication field. The user device and associated processor are further described with reference to Figure 1.
[0075] In operation 710, the contactless card can transmit one or more user identification data or personal IDs, similar to a first URL link or information packet. The contactless card is further described with reference to Figures 2 and 3. Personal IDs may include, but are not limited to, personal information such as name, address, and telephone number; account information such as card account, security code, card verification value (CVV), payment card number (PCN), and expiration date; a unique customer identifier; or other unique user data. For example, a personal ID may be associated with an email address, telephone number, contactless card information, driver's license number, passport number, date of birth, or other personal information associated with the user or the owner of the user device or user device application. In some embodiments, personal IDs may be dynamically changed by the user. As an example, but not limited to, a user's current personal ID may ultimately direct the user device to an online shopping website or online shopping application. However, the user may change the personal ID so that the final destination is a streaming website. This change may be performed via a user device application or user profile managed by another server or processor. This change may be implemented by either changing the personal ID itself, or simply changing the URL associated with the personal ID via a website or application, or both. In some embodiments, the personal ID may be dynamically generated based on a user's transaction history, spending habits, or other historical or behavioral data. For example, a user may frequently make purchases on amazon.com. After the user has visited amazon.com for a certain period of time, or a certain number of times, the user device application or server may associate amazon.com with the personal ID. Later, if the user's spending habits change, the user device application or server may change the destination URL to another site. The user device application may also associate the personal ID with a specific software application or web application.In another embodiment, the user can independently change the destination URL via a user device application.
[0076] After the personal ID is sent to the server, a copy of the personal ID may be stored in the server's associated memory or database. URL requests may be stored in the memory associated with the contactless card. The contactless card may hold one or more URL requests. URL requests may be associated with a specific website or web application. The personal ID and URLs may be transmitted from the card to the user device via a communication field.
[0077] In operation 715, the user device guides the user to the first website. The user device may transmit a personal ID to the first website. In some embodiments, the first website may be a general-purpose or universal website designed to receive the personal ID and redirect the user device to a second website via one or more servers.
[0078] Upon receiving a personal ID and URL, in operation 720, the first website may send the personal ID to one or more servers. The first and second websites themselves may be associated with their own servers or the same servers shown in Figure 7. In operation 725, the server may match the personal ID with the second URL in the file. For example, the server may be provisioned using a list of personal IDs and associated URLs. The server can first determine whether the personal ID matches any of the personal IDs in the file. If there is a match, the server can then look for the URL associated with that personal ID (in this case, the second URL). In some embodiments, one or more URLs may be associated with each personal ID. The second URL leads to a different website than the first URL.
[0079] When the personal ID is matched with the second URL, in operation 730, the server may send an authentication request to the user device. This request may be sent, for example, over the network.
[0080] In response to receiving an authentication request, the user device may open a communication field in operation 735. The communication field may be a Bluetooth®, Near Field Communication (NFC) field, an RFID-compatible field, or another communication field. The communication field in operation 735 may be a new or, in other cases, a different communication field from those described in operation 705.
[0081] When the communication field is opened, the user device can send an authentication request in operation 740. This authentication request in operation 740 may be the same authentication request as in operation 730, or a sufficiently different authentication request that prompts for sufficient authentication credentials.
[0082] In response to an authentication request, the card may, in operation 745, transmit authentication credentials to the user device. These credentials may include, but are not limited to, a unique customer identifier, a counter value, or a digital signature including a signature from a private key provisioned to the card. The card may transmit the authentication credentials to the user device via a communication field. In other embodiments, the card may transmit the authentication credentials directly to a server via a wireless network. In some embodiments, other credentials may include, but are not limited to, a password, a personal identification number (PIN), a one-time password transmitted via short message (SMS), or biometric authentication including a fingerprint scan, facial scan, voice recognition, or handwriting sample. In some embodiments, the authentication credentials may be an encrypted message authentication code (MAC), as further described with reference to Figure 4.
[0083] In operation 750, the user device may send authentication credentials to the server. This operation may be performed by the processor associated with the user device. Upon receiving the authentication credentials, the server can verify them by comparing them with the credentials in a file. In other embodiments, the server may be provisioned with a public key to verify digital signature credentials. In other embodiments, the server may decrypt the MAC to verify the credentials. After verifying the authentication credentials, in operation 760, the user is directed to the website associated with the second URL. This operation may be performed by the processor associated with the server.
[0084] In both Figures 6 and 7, an Application Programming Interface (API) may exist to facilitate redirection of a user device to a desired URL (first or second URL). An API is a source code interface provided by a computer system or program library to assist requests for services from a software application. An API is not an explicit low-level description of how data is arranged in memory, but rather specifies a programming language that can be interpreted or compiled when the application is built. Software that provides the functionality described by an API is said to be an implementation of the API.
[0085] Figure 8 is a flowchart illustrating a process according to an exemplary embodiment. In some embodiments, the destination may be obtained from a data storage unit, a database, or other memory. By obtaining the destination URL from the data storage unit, the process can provide the URL to the user more quickly. The URL may be read-only or read-and-write.
[0086] In operation 805, the server may obtain a personal ID. The server may obtain a personal ID from a user device or from a third-party server or processor. In some embodiments, the server may obtain a personal ID directly from a contactless card.
[0087] In operation 810, the server verifies whether the user ID matches any of the personal IDs in the file. The server may be provisioned with a list of personal IDs that have been provided at a previous point in time or that are associated with accounts related to contactless cards. In some embodiments, the server may interact with several other servers to determine whether the personal ID has been provided elsewhere. In some embodiments, the personal ID may be dynamically generated based on the user's transaction history, spending habits, or other historical or behavioral data. For example, a user may frequently make purchases on amazon.com. After the user has visited amazon.com for a certain period of time or a certain number of times, the user device application or server may associate the personal ID with amazon.com. Later, if the user's spending habits change, the user device application or server may change the destination URL to another site. The user device application may also associate the personal ID with a specific software application or web application. In other embodiments, the user may independently change the destination URL via the user device application.
[0088] Once the server has confirmed the presence of the personal ID in the file, in operation 815 it can retrieve the destination URL from the data storage unit. This operation may be performed by the processor associated with the server. The destination URL is the URL that the user ultimately wants to reach. It is understood that the destination URL described in Figure 8 may be the same as the second URL described in Figure 7 or the URL described in Figure 6. The data storage unit may, in some but not limited cases, be provided with the destination URL from a previous registration process. Once the destination URL is obtained, in operation 820 the server may send an authentication request to the user device over the network.
[0089] In operation 825, the server may receive authentication credentials. In some embodiments, the server may receive authentication credentials directly from the user's contactless card. Upon receiving the authentication credentials, the server may verify them in operation 830. In some embodiments, the server may verify the authentication credentials by comparing them with credentials in a file. In other embodiments, the server may be provisioned using a public key to verify digital signature credentials. In other embodiments, the server may decrypt a MAC to verify the credentials.
[0090] In operation 835, the server can direct the browser to the destination URL. The browser may now be open on the user device. In other embodiments, the server can open the browser via the user device or through some user device application.
[0091] In some embodiments, the technology described herein relates to a system for dynamic guidance of a user device to a URL, the system comprising a card and a server, the server further comprising memory and a processor, the processor opening a communication field and receiving a request from the card via the communication field to guide a user device application to the server, the request further comprising a personal identification code associated with the owner of the user device associated with the user device application and a uniform resource locator (URL) associated with a given website, the processor guiding the user device application to the server, receiving an authentication request from the server, sending authentication credentials to the server, verifying the authentication credentials, and guiding the user device application to the website associated with the URL.
[0092] In some embodiments, the technology described herein relates to a system in which the processor, upon receiving an authentication request from a server, is further configured to open a second communication field and perform a diversified key exchange between the card and the server, the card further comprising a private key and the server further comprising a public key.
[0093] In some embodiments, the technology described herein relates to a system, wherein the user device associated with the user device application is at least one selected from the group of smartphones, tablets, or computers.
[0094] In some embodiments, the technology described herein relates to a system, where the authentication credentials are a password or a PIN number.
[0095] In some embodiments, the technology described herein relates to a system, where the authentication credentials are biometric fingerprint scanning, facial scanning, or voice recognition.
[0096] In some embodiments, the technology described herein relates to a system in which a given URL can be manually changed by the user on the user's device.
[0097] In some embodiments, the technology described herein relates to a system in which a personal identification code is associated with an email address, telephone number, or card information.
[0098] In some embodiments, the technology described herein relates to a system in which the card further comprises a private key and the server further comprises a public key.
[0099] In some embodiments, the technology described herein relates to a system in which the card is a contactless card associated with an account holder of a banking institution.
[0100] In some embodiments, the technology described herein relates to a method for directing a user device to a given URL, the method comprising the steps of: opening a communication field by a processor; sending a request through the communication field to direct a user device application to a server, the request further including a personal identification code associated with the owner of the user device associated with the user device application, and a uniform resource locator (URL) associated with a given website; directing the user device application to the server by a processor; receiving an authentication request from the server; sending authentication credentials to the server; verifying the authentication credentials by a processor; and directing the user device application to the website associated with the URL by a processor.
[0101] In some embodiments, the technology described herein relates to a method, the method further comprising the step of receiving an authentication request from a server, opening a second communication field, and performing a diversified key exchange between the card and the server, wherein the card further comprises a private key and the server further comprises a public key.
[0102] In some embodiments, the techniques described herein relate to methods, where the user device is a smartwatch.
[0103] In some embodiments, the techniques described herein relate to methods, where the personal identification code is a driver's license number, passport number, or date of birth.
[0104] In some embodiments, the techniques described herein relate to methods, where the communication field is a Bluetooth®, Near Field Communication (NFC) field, or Radio Frequency Identification (RFID) compatible field.
[0105] In some embodiments, the technology described herein relates to a method in which the card is a contactless card associated with the account holder of an spending account, savings account, or growth account.
[0106] In some embodiments, the techniques described herein relate to methods, the step further comprising sending an authentication request by short message service (SMS) or multimedia message service (MMS).
[0107] In some embodiments, the techniques described herein relate to methods, the steps further including directing a user device to a mobile application associated with a URL.
[0108] In some embodiments, the techniques described herein relate to methods in which the authentication credentials are digital signatures from a card.
[0109] In some embodiments, the technology described herein relates to a computer-readable non-temporary medium containing a computer-executable instruction, wherein, when executed by a processor, the instruction includes the steps of: opening a communication field and sending a request from the card to a user device application, which directs the user device application to a server, the request further including a personal identification code associated with the owner of the user device associated with the user device application, and a uniform resource locator (URL) associated with a given website; the processor directs the user device application to the server, receives an authentication request from the server, sends authentication credentials to the server, verifies the authentication credentials, and the processor directs the user device application to the website associated with the URL.
[0110] In some embodiments, the technology described herein relates to a computer-readable non-temporary medium, wherein copies of the personal identification code are stored in memory associated with a server.
[0111] While embodiments of the present invention are described herein in the context of specific implementations for specific purposes in specific environments, those skilled in the art will understand that the usefulness of the present invention is not limited thereto and that embodiments of the present invention can be beneficially implemented in other relevant environments for similar purposes. Accordingly, the present invention should not be limited to the embodiments, methods, and examples described above, but should be limited by all embodiments contained within the scope and spirit of the invention as described in the claims.
[0112] As used herein, user information, personal information, and confidential information may include any information relating to a user, including personal and non-personal information. Personal information may include any confidential data, such as financial data (account information, account balance, account activity, etc.), personal / personally identifiable information (social security number, home or work address, date of birth, telephone number, email address, passport number, driver's license number, etc.), access information (password, security code, authentication code, biometric data, etc.), and other information that the user wishes to keep confidential from unauthorized persons. Non-personal information may include any data that is publicly known or not intended to be kept confidential.
[0113] In this invention, various embodiments have been described with reference to the accompanying drawings. However, it is clear that various modifications and changes are possible without departing from the broader scope of the invention as described in the claims, and that additional embodiments may be implemented. Therefore, the invention and the drawings should be interpreted as illustrative rather than restrictive.
[0114] The present invention is not limited to the specific embodiments described herein, but is intended to be illustrative of various aspects. Many modifications and changes are possible without departing from the spirit and scope of the invention. In addition to those enumerated herein, functionally equivalent systems, processes, and apparatus within the scope of the invention will be apparent from the representative descriptions herein. Such modifications and changes are intended to be included in the appended claims. The present invention is limited only by the conditions of the appended claims and the entire scope of equivalents to which such representative claims are granted.
[0115] As used herein, the terms “card” and “contactless card” are not limited to any particular type of card. Rather, it is understood that the term “card” can refer to a contact-based card, a contactless card, or any other card unless otherwise indicated. It is further understood that this disclosure is not limited to cards for a specific purpose (such as payment cards, gift cards, identification cards, or membership cards), cards associated with a specific type of account (such as credit accounts, debit accounts, or membership accounts), or cards issued by a specific organization (such as a financial institution, a government agency, or a social club). Instead, it is understood that this disclosure includes cards for any purpose, associated account, or issuing organization.
[0116] The aforementioned specification refers to uniform resource locator (URL) links. However, this disclosure may include, but is not limited to, other types of links, including, but is not limited to, uniform resource identifier (URI) hyperlinks and other data references.
[0117] Furthermore, the systems and methods described herein may be visibly embodied in one or more physical media, such as compact discs (CDs), digital multipurpose discs (DVDs), floppy disks, hard drives, read-only memory (ROMs), random access memory (RAMs), and other physical media capable of storing data. For example, data storage may include random access memory (RAMs) and read-only memory (ROMs) that can be configured to access and store data and information and computer program instructions. Data storage may also include storage media or other suitable types of memory (e.g., RAMs, ROMs, programmable read-only memory (PROMs), erasable programmable ROMs (EPROMs), electrically erasable programmable ROMs (EEPROMs), magnetic disks, optical disks, floppy disks, hard disks, removable cartridges, flash drives, and any type of tangible and non-temporary storage medium), and may store application programs such as operating systems, web browser applications, email applications, and / or other applications, and files that constitute data files. The data storage of a network-enabled computer system may include electronic information, files, and documents stored in various ways, including flat files, index files, hierarchical databases, relational databases (such as databases created and maintained using software from Oracle® Corporation), Microsoft® Excel files, Microsoft® Access files, solid-state storage devices (which may include flash arrays, hybrid arrays, or server-side products), enterprise storage (which may include online storage or cloud storage), or other storage mechanisms. Furthermore, the diagram shows various components (e.g., servers, computers, processors, etc.) separately.Functions described as being performed by various components may also be performed by other components, and these components may be combined or separated. Other variations may also be made.
[0118] The computer-readable program instructions described herein may be downloaded from a computer-readable storage medium to each computing and / or processing device, or to an external computer or external storage device via a network such as the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmissions, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface in each computing / processing device receives computer-readable program instructions from the network and transfers the computer-readable program instructions to be stored in the computer-readable storage medium within each computing / processing device.
[0119] The computer-readable program instructions for performing the operation of the present invention may be assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state setting data, or source code or object code written in any combination of one or more programming languages, including object-oriented programming languages such as Java, Smalltalk, and C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed on the user's entire computer, on a portion of the user's computer, as a standalone software package on a portion of the user's computer, and on a portion of a remote computer or on the entire remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or it may be connected to an external computer (for example, via the Internet using an Internet service provider). In some embodiments, an electronic circuit including a programmable logic circuit, a field-programmable gate array (FPGA), or a programmable logic array (PLA) may execute computer-readable program instructions by utilizing state information of computer-readable program instructions for personalizing the electronic circuit in order to perform an aspect of the present invention.
[0120] These computer-readable program instructions may be provided to a general-purpose computer, a dedicated computer, or a processor of another programmable data processing device to generate a machine that creates means for performing functions / operations specified in blocks of a flowchart and / or block diagram, through instructions executed via the processor of the computer or other programmable data processing device. These computer-readable program instructions may be stored on a computer-readable storage medium on which the instructions are stored, which can be instructed to operate a computer, a programmable data processing device, and / or other device, such that the storage medium contains instructions that perform the modes of functions / operations specified in blocks of a flowchart and / or block diagram.
[0121] Computer-readable program instructions may be loaded onto a computer, another programmable device, or another device to perform a series of operational steps on the computer, another programmable device, or another device in order for a computer execution process to generate instructions that execute on the computer, another programmable device, or another device to perform the functions / operations specified in the blocks of a flowchart and / or block diagram.
[0122] The detailed description of the exemplary embodiments described above provides non-limiting representative examples, with reference to reference numbers, to illustrate the features and teachings of various aspects of the present invention. It should be recognized that the described embodiments can be implemented independently of the description of embodiments or in combination with other embodiments. A person skilled in the art who has read the description of embodiments should be able to learn and understand the various aspects of the present invention. The description of embodiments is not specifically exhaustive, but should facilitate the understanding of the present invention to the extent that other embodiments within the knowledge of a person skilled in the art who has read the description of embodiments will be understood to be consistent with the application of the present invention.
[0123] The various technologies described herein may be implemented in digital electronic circuits, or in computer hardware, firmware, software, or combinations thereof. The implementation may also be implemented as a computer program product, i.e., a computer program tangibly embodied in an information carrier, such as a machine-readable memory device or a propagating signal, for execution by or control of a data processing device, such as a programmable processor, computer, or multiple computers. Computer programs, such as those described above, can be written in any form of programming language, including compiled and interpreted languages, and can be deployed in any form, as a standalone program or as modules, components, subroutines, or other units suitable for use in a computing environment. Computer programs can be deployed to run on one computer or on multiple computers at one site, or distributed across multiple sites and interconnected by a communication network.
[0124] The steps of the method may be performed by one or more programmable processors that execute computer programs to perform functions by operating on input data and generate outputs. The steps of the method may also be performed by a dedicated logic circuit, such as an FPGA (Field-Programmable Gate Array) or ASIC (Application-Specific Integrated Circuit), and the device may be implemented as a dedicated logic circuit.
[0125] The detailed description of the exemplary embodiments described above provides non-limiting representative examples, with reference to reference numbers, to illustrate the features and teachings of various aspects of the present invention. It should be recognized that the described embodiments can be implemented independently of the description of embodiments or in combination with other embodiments. A person skilled in the art who has read the description of embodiments should be able to learn and understand the various aspects of the present invention. The description of embodiments is not specifically exhaustive, but should facilitate the understanding of the present invention to the extent that other embodiments within the knowledge of a person skilled in the art who has read the description of embodiments will be understood to be consistent with the application of the present invention.
Claims
1. A system for dynamically guiding a user device to a URL, The aforementioned system, Including the card and the server, The original server further, It includes memory and a processor. The aforementioned processor, Open the communication field, The card receives a request via the communication field to direct the user device application to the server, and the request further includes a personal identification code associated with the owner of the user device associated with the user device application, and a uniform resource locator (URL) associated with a predetermined website. The user device application is directed to the server, The server receives an authentication request, The authentication credentials are sent to the aforementioned server. The aforementioned authentication credentials are verified, The user device application is configured to guide the user to the website associated with the URL. system.
2. The aforementioned processor further, Upon receiving an authentication request from the aforementioned server, the second communication field is opened, The card and the server are configured to perform diversified key exchange, The card further comprises a private key, and the server further comprises a public key. The system according to claim 1.
3. The user device associated with the user device application is at least one selected from the group of smartphones, tablets, or computers. The system according to claim 1.
4. The aforementioned authentication credentials are a password or PIN number. The system according to claim 1.
5. The aforementioned authentication credentials are biometric fingerprint scans, facial scans, or voice recognition. The system according to claim 1.
6. The aforementioned predetermined URL can be manually changed by the user on the user device. The system according to claim 1.
7. The aforementioned personal identification code is associated with an email address, telephone number, or card information. The system according to claim 1.
8. The card further comprises a private key, and the server further comprises a public key. The system according to claim 1.
9. The aforementioned card is a contactless card associated with an account holder of a banking institution. The system according to claim 1.
10. A method for guiding a user device to a predetermined URL, The aforementioned method, The processor opens the communication field, The processor transmits a request via the communication field to direct the user device application to the server, the request further including a personal identification code associated with the owner of the user device associated with the user device application, and a uniform resource locator (URL) associated with a predetermined website. The processor guides the user device application to the server, The server receives an authentication request, The authentication credentials are sent to the aforementioned server. The aforementioned processor verifies the authentication credentials, The processor guides the user device application to the website associated with the URL. Steps including method.
11. The aforementioned method further, Upon receiving an authentication request from the aforementioned server, the second communication field is opened, The card is configured to perform diversified key exchange between the card and the server. Includes steps, The card further comprises a private key, and the server further comprises a public key. The method of claim 10.
12. The user device is a smartwatch. The method of claim 10.
13. The aforementioned personal identification code is a driver's license number, passport number, or date of birth. The method of claim 10.
14. The aforementioned communication field is a Bluetooth®, Near Field Communication (NFC) field, or Radio Frequency Identification (RFID) compatible field. The method of claim 10.
15. The aforementioned card is a contactless card associated with the account holder of an expenditure account, savings account, or growth account. The method according to claim 11.
16. The above step further, This includes sending the authentication request via Short Message Service (SMS) or Multimedia Message Service (MMS). The method of claim 10.
17. The above step further, This includes guiding the user device to the mobile application associated with the URL, The method of claim 10.
18. The aforementioned authentication credentials are a digital signature from the card. The method according to claim 11.
19. A computer-readable non-temporary medium containing computer-executable instructions, When the aforementioned instruction is executed by the processor, The processor opens the communication field, The card sends a request to the user device application, which directs the user device application to a server, and the request further includes a personal identification code associated with the owner of the user device associated with the user device application, and a uniform resource locator (URL) associated with a predetermined website. The processor guides the user device application to the server, The server receives an authentication request, The authentication credentials are sent to the aforementioned server. The aforementioned processor verifies the authentication credentials, The processor guides the user device application to the website associated with the URL. Perform the steps that include the following steps. Computer-readable non-temporary medium.
20. A copy of the aforementioned personal identification code is stored in the memory associated with the server. A computer-readable non-temporary medium according to claim 19.