Card Issuance Using Limited Virtual Numbers
The system addresses the inflexibility of existing virtual credit card systems by generating virtual card numbers with personalized restrictions via contactless card authentication, enhancing security and flexibility in managing virtual card transactions.
Patent Information
- Application Number
- JP2022538808
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2020-11-23
- Publication Date
- 2025-05-26
- Estimated Expiration
- 2040-11-23
AI Technical Summary
Existing virtual credit card systems lack the ability to set personalized restrictions for recipients, such as merchant, amount, time, and location restrictions, which are inflexible and not tailored to the specific needs of the recipient.
The system generates virtual card numbers with personalized restrictions applied via contactless card authentication, allowing users to set specific restrictions such as merchant, amount, time, and location, and can write these numbers to a blank card or transfer them directly to a recipient's device.
This approach enables secure and personalized management of virtual card numbers, allowing users to tailor restrictions to specific recipients and ensuring secure authentication through one-tap contactless card authentication.
Smart Images

Figure 0007682896000001 
Figure 0007682896000002 
Figure 0007682896000003
Abstract
Description
Technical Field
[0001] Related Applications This application claims the benefit of U.S. Patent Application No. 16 / 726,210, titled "Card Issuance Using Restricted Virtual Numbers," filed on December 23, 2019. The entire content of the foregoing application is hereby incorporated by reference in its entirety.
Background Art
[0002] A virtual credit card is a virtual credit card number commonly used for online purchases and disposable transactions. The virtual card number can be a randomly generated number associated with an actual credit card. Some card-issuing companies may set an upper limit for the virtual number and, in some cases, an expiration date within one year from the creation of the virtual number. To online merchants, the virtual card number may appear no different from other credit cards.
[0003] Basic restrictions associated with the virtual card number, such as the maximum claim amount and expiration date, can be set by the issuer, but there is a need for specially personalized restrictions tailored to the recipient so that the issuing user can set them safely.
Summary of the Invention
[0004] Various embodiments are directed to applying one or more restrictions to a virtual card number via contactless card authentication and generating a card number for use by a recipient. The one or more restrictions can be specifically personalized for the recipient and can include, for example, merchant restrictions, amount restrictions, time restrictions, or location restrictions. The generated virtual card number, along with the one or more applied restrictions, can be consumed in various ways, such as writing the number to a blank card via near-field communication or directly transmitting the number to the recipient's computing device.
Brief Description of the Drawings
[0005]
Figure 1A
Figure 1B
Figure 2
Figure 3A
Figure 3B
Figure 4
Figure 5
Figure 6
Figure 7
Figure 8
Figure 9
[0006] Various embodiments generally aim to generate virtual card numbers and apply one or more restrictions to the card numbers in a personalized and secure manner. In an example, an issuing user may set personalized restrictions tailored to the recipient of the virtual card number, such as merchant restrictions, amount restrictions, time period restrictions, location restrictions, etc. For example, a user (parent) may want to leave a babysitter $30 for dinner, but the $30 must be used at a specific pizza restaurant. In another example, a user (e.g., a business owner) may want to provide an employee with $5,000 for purchasing consumables, but the expenditure is limited to 2 hours and must be spent with a specific supplier.
[0007] To create a virtual card number with one or more restrictions, a user may open a software application (e.g., a banking app) and select an icon to generate the virtual card number. According to an embodiment, the user may select one or more restrictions to apply to the card number using the software application. Next, the user may perform one - tap authentication (which may also be referred to herein as "one - tap contactless card authentication") via a contactless card belonging to the user to finalize and apply the selected restrictions and generate the virtual card number.
[0008] In an example, when a virtual card number is generated, the number (with the selected one or more restrictions applied) may be written to a blank and unlocked card via the software application and activated so that it can be used in any point - of - sale information management system. According to a further embodiment, the virtual card number may be transmitted from a first computing device to a second computing device, for example, from a user computing device to a recipient computing device. The first and second computing devices may be near - field communication (NFC) - enabled devices, and the virtual card number may be transmitted via NFC.
[0009] As will be further explained below, one - tap contactless card authentication can be a very secure way to verify a user's identity, for example, to confirm that the restrictions are actually set by the user rather than a fraudster. Further, since contactless cards are often used as a means of payment for "loading" virtual card numbers or raising funds, one - tap authentication guarantees that the user is the person who actually approves the creation and funding of the virtual card number.
[0010] According to an embodiment, one - tap contactless card authentication may include the user placing, tapping, or bringing a contactless card into a designated area of a user computing device (e.g., a smartphone). The user computing device may detect the contactless card via near - field communication (NFC) and receive one or more ciphertexts from the contactless card. Information included in the ciphertext that can identify the true owner of the contactless card may be compared or matched with authentication information related to the user signed in to the banking app. If they match, it can be confirmed that the verification of the user's identity has been successful.
[0011] As described above, in previous solutions, the restrictions imposed on virtual card numbers were inflexible and impersonal. The embodiments and examples described herein overcome previous solutions and are advantageous in that the user can easily and conveniently personalize and adjust one or more restrictions on a virtual card number based on the recipient of the number. Further, the user can write the virtual card number to a blank and unlocked card via the user's computing device and activate the card so that the recipient can use it in various point - of - sale information management systems. Further, the user can advantageously transfer the virtual card number from the user's computing device to the recipient's computing device via near - field communication. Overall, the application of one or more restrictions and the generation of virtual card numbers can be performed in a very secure and safe way via one - tap contactless card authentication.
[0012] Reference is now made to the drawings, where like reference numerals are used throughout to refer to like elements. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding. It will be evident, however, that the novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form in order to facilitate the description. The intention is to cover all modifications, equivalents, and alternatives falling within the scope of the claims.
[0013] FIG. 1A shows an exemplary data transmission system according to one or more embodiments. As will be discussed further below, system 100 may include a contactless card 105, a client device 110, a network 115, and a server 120. Although FIG. 1A shows a single instance of the components, system 100 may include any number of components.
[0014] System 100 may include one or more contactless cards 105, which are further described below with reference to FIGS. 3A and 3B. In some embodiments, contactless card 105 may wirelessly communicate with client device 110, for example, using NFC.
[0015] System 100 may include a client device 110, which may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, a computer device, or a communication device such as, for example, a server, a network appliance, a personal computer, a workstation, a telephone, a smartphone, a handheld PC, a personal digital assistant, a thin client, a fat client, an Internet browser, or other devices. The client device 110 may be a mobile computing device, such as, for example, an Apple® iPhone®, iPod®, iPad®, or other suitable device running Apple's iOS® operating system, a device running Microsoft's Windows® Mobile operating system, a device running Google's Android® operating system, and / or other suitable mobile computing devices such as smartphones, tablets, or similar wearable mobile devices.
[0016] The client device 110 may include a processor and memory. The processing circuitry may include additional components such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and anti-tampering hardware as needed to perform the functions described herein. The client device 110 may further include a display and an input device. The display may be any type of device for presenting visual information such as a computer monitor, flat panel display, and mobile device screen including liquid crystal displays, light emitting diode displays, plasma panels, and cathode ray tube displays. The input device may include any device for inputting information available and supported on the user's device into the user's device, such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder or camcorder. These devices may be used to input information and interact with the software and other devices described herein.
[0017] In some examples, the client device 110 of the system 100 may execute one or more applications, such as software applications, that enable network communication with one or more components of the system 100 and transmit and / or receive data.
[0018] Client device 110 can communicate with one or more servers 120 via one or more networks 115 and can operate as a pair from the front end to the back end with each of the servers 120. The client device 110 can send one or more requests to the server 120, for example, from a mobile device application executed on the client device 110. The one or more requests can be associated with the acquisition of data from the server 120. The server 120 can receive one or more requests from the client device 110. Based on the one or more requests from the client device 110, the server 120 can be configured to obtain the requested data from one or more databases (not shown). Based on the reception of the requested data from the one or more databases, the server 120 can be configured to send the received data to the client device 110, and the received data can respond to the one or more requests.
[0019] System 100 can include one or more networks 115. In some examples, the network 115 can be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network, and can be configured to connect the client device 110 to the server 120. For example, the network 115 can include one or more of an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communication service, a personal area network, a wireless application protocol, a multimedia messaging service, an extended messaging service, a short message service, a time division multiplexing-based system, a code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth (registered trademark), NFC, radio frequency identification (RFID), Wi-Fi, etc.
[0020] Furthermore, network 115 may include, but is not limited to, a telephone line, fiber optic, IEEE Ethernet 802.3, wide area network, wireless personal area network, LAN, or a global network such as the Internet. Further, network 115 may support an Internet network, a wireless communication network, a cellular network, etc., or any combination thereof. Network 115 may further include one network, or any number of the exemplary types of networks described above, operating as a stand-alone network or cooperating with each other. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may convert from other protocols to one or more protocols of network devices, or from other protocols. Although network 115 is shown as a single network, according to one or more examples, network 115 may include, for example, multiple interconnected networks such as the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, and a home network.
[0021] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to a memory. Server 120 may be configured as a central system, server, or platform for controlling and invoking various data at different times to execute multiple workflow actions. Server 120 may be configured to connect to one or more databases. Server 120 may be connected to at least one client device 110.
[0022] Figure 1B shows an exemplary sequence diagram for providing authenticated access according to one or more embodiments. This figure may include a contactless card 105 and a client device 110, which may include an application 122 and a processor 124. Figure 1B may refer to components similar to those shown in Figure 1A.
[0023] In step 102, the application 122 communicates with the contactless card 105 (e.g., after being brought close to the contactless card 105). The communication between the application 122 and the contactless card 105 may include a contactless card 105 that is close enough to a card reader (not shown) of the client device 110 to enable NFC data transfer between the application 122 and the contactless card 105.
[0024] In step 104, after communication is established between the client device 110 and the contactless card 105, the contactless card 105 generates a message authentication code (MAC) ciphertext. In some examples, this may occur when the contactless card 105 is read by the application 122. In particular, this may occur upon reading, such as NFC reading, of a Near Field Data Exchange (NDEF) tag that may be created according to the NFC data exchange format.
[0025] For example, a reader such as application 122 may send a message such as an applet selection message using the applet ID of the NDEF generation applet. When the selection is confirmed, a series of selection file messages followed by read file messages may be sent. For example, the sequence may include "selection of function file", "reading of function file", and "selection of NDEF file". At this point, the counter value maintained by the contactless card 105 may be updated or incremented, and then "reading of NDEF file" may follow. At this point, a message that may include a header and a shared secret may be generated. Thereafter, a session key may be generated. A MAC ciphertext may be created from the message, which may include a header and a shared secret. Next, the MAC ciphertext may be concatenated with one or more blocks of random data, and the MAC ciphertext and random number (RND) may be encrypted with the session key. Thereafter, the ciphertext and the header may be concatenated and encoded as ASCII hexadecimal and returned in the NDEF message format (in response to the "reading of NDEF file" message).
[0026] In some examples, the MAC ciphertext may be sent as an NDEF tag, and in other examples, the MAC ciphertext may be included together with a uniform resource indicator (e.g., a formatted string).
[0027] In some examples, application 122 may be configured to send a request to contactless card 105, and the request comprises an instruction for generating a MAC ciphertext.
[0028] In step 106, contactless card 105 sends the MAC ciphertext to application 122. In some examples, the transmission of the MAC ciphertext is performed via NFC, but the present disclosure is not limited thereto. In other examples, this communication may be performed via Bluetooth®, Wi-Fi, or other wireless data communication means.
[0029] In step 108, application 122 communicates the MAC ciphertext to processor 124. In step 112, processor 124 verifies the MAC ciphertext according to the instructions from application 122. For example, as described below, the MAC ciphertext can be verified.
[0030] In some examples, the verification of the MAC ciphertext can be performed by a device other than client device 110, such as server 120 that is in data communication with client device 110 (as shown in FIG. 1A). For example, processor 124 can output the MAC ciphertext for transmission to server 120, which can verify the MAC ciphertext.
[0031] In some examples, the MAC ciphertext can function as a digital signature for verification purposes. To perform this verification, a public key asymmetric algorithm, such as a digital signature algorithm and an RSA algorithm, or other digital signature algorithms such as a zero-knowledge protocol, can be used.
[0032] In some examples, it can be understood that the contactless card 105 can start communication after the contactless card is brought close to the client device 110. As an example, the contactless card 105 can send a message to the client device 110 indicating, for example, that the contactless card has established communication. Thereafter, the application 122 of the client device 110 can proceed with communication with the contactless card in step 102 as described above.
[0033] FIG. 2 shows an exemplary system 200 that uses a contactless card. System 200 can include a contactless card 205, one or more client devices 210, a network 215, servers 220, 225, one or more hardware security modules 230, and a database 235. Although FIG. 2 shows a single instance of a component, system 200 can include any number of components.
[0034] System 200 may include one or more contactless cards 205, which are further described below with respect to FIGS. 3A and 3B. In some examples, contactless card 205 may communicate wirelessly with client device 210, such as via NFC communication. For example, contactless card 205 may include one or more chips, such as a radio frequency identification chip, configured to communicate via NFC or other short-range protocol. In other embodiments, contactless card 205 may communicate with client device 210 via other means including, but not limited to, Bluetooth®, satellite, Wi-Fi, wired communication, and / or any combination of wireless and wired connections. According to some embodiments, contactless card 205 may be configured to communicate via NFC with a card reader 213 of client device 210 (which may be referred to herein as an NFC reader, NFC card reader, or reader) when contactless card 205 is within the range of card reader 213. In other examples, communication with contactless card 205 may be achieved via a physical interface, such as a universal serial bus interface or a card swipe interface.
[0035] System 200 may include a client device 210 that can be a network-enabled computer. As referred to herein, a network-enabled computer can include, for example, a computer device, or a communication device including, for example, a server, a network appliance, a personal computer, a workstation, a mobile device, a telephone, a handheld PC, a personal digital assistant, a thin client, a fat client, an Internet browser, or other devices, but is not limited thereto. One or more client devices 210 can also be mobile devices. For example, mobile devices can include Apple's iPhone (registered trademark), iPod (registered trademark), iPad (registered trademark), or other mobile devices running Apple's iOS (registered trademark) operating system, devices running Microsoft's Windows (registered trademark) mobile operating system, devices running Google's Android (registered trademark) operating system, and / or other smartphones or similar wearable mobile devices. In some examples, client device 210 can be the same as or similar to client device 110 as described with reference to FIGS. 1A or 1B.
[0036] Client device 210 can communicate with one or more servers 220 and 225 via one or more networks 215. Client device 210 can send one or more requests to one or more servers 220 and 225, for example, from an application 211 running on client device 210. The one or more requests can be associated with obtaining data from one or more servers 220 and 225. Servers 220 and 225 can receive one or more requests from client device 210. Based on the one or more requests from client device 210, one or more servers 220 and 225 can be configured to obtain the requested data from one or more databases 235. Based on receiving the requested data from one or more databases 235, one or more servers 220 and 225 can be configured to send the received data to client device 210, and the received data responds to the one or more requests.
[0037] System 200 can include one or more hardware security modules (HSMs) 230. For example, the one or more HSMs 230 can be configured to perform one or more encryption operations as disclosed herein. In some examples, the one or more HSMs 230 can be configured as special-purpose security devices configured to perform one or more encryption operations. HSM 230 can be configured such that the key is never disclosed outside of HSM 230 and is instead maintained within HSM 230. For example, the one or more HSMs 230 can be configured to perform at least one of key derivation, decryption, and MAC operations. The one or more HSMs 230 can be included within servers 220 and 225 or can communicate with them.
[0038] System 200 may include one or more networks 215. In some examples, network 215 may be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network, and may be configured to connect client device 210 to server 220 and / or 225. For example, network 215 may be an optical fiber network, a passive optical network, a cable network, a cellular network, an Internet network, a satellite network, a wireless LAN, a global system for mobile communications, a personal communication service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short message service, a time division multiplexing based system, a code division multiple access based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth®, NFC, RFID, Wi-Fi, and / or one or more of any combination of those networks. As a non-limiting example, communication from contactless card 205 and client device 210 may include NFC communication, a cellular network between client device 210 and a carrier, and the Internet between the carrier and the backend.
[0039] Furthermore, network 215 can include, but is not limited to, a telephone line, an optical fiber, IEEE Ethernet 802.3, a wide area network, a wireless personal area network, a local area network, or a global network such as the Internet. Further, network 215 can support an Internet network, a wireless communication network, a cellular network, etc., or any combination thereof. Network 215 can further include one network, or any number of the exemplary types of networks described above, operating as a stand-alone network or cooperating with each other. Network 215 can utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 215 can translate from one or more protocols of network devices to other protocols, or from other protocols. Although network 215 is shown as a single network, according to one or more examples, network 215 can include, for example, the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, and multiple interconnected networks such as a home network.
[0040] In various examples according to the present disclosure, the client device 210 of the system 200 may execute one or more applications 211 and include one or more processors 212 and one or more card readers 213. For example, one or more applications 211, such as software applications, may be configured to enable network communication with one or more components of the system 200 and to send and / or receive data. Although FIG. 2 shows only a single instance of the components of the client device 210, it is understood that any number of devices 210 may be used. The card reader 213 may be configured to read from and / or communicate with the contactless card 205. In conjunction with one or more applications 211, the card reader 213 may communicate with the contactless card 205. In an example, the card reader 213 may include a circuit or circuit component, such as an NFC reader coil, that generates a magnetic field that enables communication between the client device 210 and the contactless card 205.
[0041] Any application 211 of the client device 210 may communicate with the contactless card 205 using short-range wireless communication (e.g., NFC). The application 211 may be configured to interface with a card reader 213 of the client device 210 that is configured to communicate with the contactless card 205. It should be noted that those skilled in the art will understand that a distance of less than 20 centimeters corresponds to the NFC range.
[0042] In some embodiments, the application 211 communicates with the contactless card 205 via an associated reader (e.g., card reader 213).
[0043] In some embodiments, card activation may occur without user authentication. For example, the contactless card 205 may communicate with the application 211 via the card reader 213 of the client device 210 via NFC. The communication (e.g., tapping of the card in proximity to the card reader 213 of the client device 210) enables the application 211 to read the data associated with the card and perform activation. In some cases, the tap may activate or launch the application 211 and then initiate communication with one or more action or account servers 225 to activate the card for subsequent use. In some cases, if the application 211 is not installed on the client device 210, tapping the card on the card reader 213 may initiate the download of the application 211 (e.g., navigation to an application download page). Following the installation, tapping the card may activate or launch the application 211 and then initiate the activation of the card (e.g., via the application or other backend communication). After activation, the card may be used in various transactions including commercial transactions.
[0044] According to some embodiments, the contactless card 205 may include a virtual payment card. In those embodiments, the application 211 may obtain the information associated with the contactless card 205 by accessing a digital wallet implemented on the client device 210, and the digital wallet includes the virtual payment card. In some examples, the virtual payment card data may include one or more statically or dynamically generated virtual card numbers.
[0045] Server 220 may include a web server that communicates with database 235. Server 225 may include an account server. In some examples, server 220 may be configured to verify one or more qualification information from contactless card 205 and / or client device 210 by comparing with one or more qualification information in database 235. Server 225 may be configured to approve one or more requests such as payments and transactions from contactless card 205 and / or client device 210.
[0046] FIG. 3A shows one or more contactless cards 300, which may include payment cards such as credit cards, debit cards, or gift cards issued by service provider 305 displayed on the front or back of card 300. In some examples, contactless card 300 may not be related to a payment card and may include, but is not limited to, an identification card. In some examples, the payment card may include a dual interface contactless payment card. Contactless card 300 may include a substrate 310 that may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, contactless card 300 may have physical characteristics that conform to the ID-1 format of the ISO / IEC 7810 standard; otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, it is understood that contactless card 300 according to the present disclosure may have different characteristics, and the present disclosure does not require that the contactless card be implemented as a payment card.
[0047] The contactless card 300 may also include identification information 315 displayed on the front and / or back of the card, and contact pads 320. The contact pads 320 may be configured to establish contact with other communication devices such as user devices, smartphones, laptops, desktops, or tablet computers. The contactless card 300 may also include a processing circuit, an antenna, and other components not shown in FIG. 3A. These components may be located behind the contact pads 320 or at other locations on the substrate 310. The contactless card 300 may also include a magnetic strip or tape that may be disposed on the back of the card (not shown in FIG. 3A).
[0048] As shown in FIG. 3B, the contact pads 320 of FIG. 3A may include a processing circuit 325 for storing and processing information, including a microprocessor 330 and a memory 335. The processing circuit 325 may include additional components as necessary to perform the functions described herein, including a processor, a memory, an error and parity / CRC checker, a data encoder, a collision avoidance algorithm, a controller, a command decoder, a security primitive, and anti-tampering hardware.
[0049] The memory 335 may be a read-only memory, a write-once / read-multiple memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 300 may include one or more of these memories. The read-only memory may be factory-read-only or programmable as a one-time programmable. With a one-time program, it can be written once and read many times. The write-once / read-multiple memory may be programmed at some point after the memory chip is shipped from the factory. The memory may not be rewritable once programmed, but can be read many times. The read / write memory may be programmed and reprogrammed many times after factory shipment. Also, it can be read many times.
[0050] Memory 335 may be configured to store one or more applets 340, one or more counters 345, one or more diversified keys 347, and a customer identifier 350. The one or more applets 340 may include one or more software applications configured to execute on one or more contactless cards, such as Java card applets. However, it is understood that the applets 340 are not limited to Java card applets and may instead be any software application operable on a contactless card or other device having limited memory. The one or more counters 345 may include numeric counters sufficient to store integers. As further described below, the one or more diversified keys 347 may be used to encrypt various information, such as information about a user or customer (e.g., customer identifier 450), to generate a ciphertext that can be transmitted, for example, to a mobile device for at least authentication purposes. The customer identifier 350 may include a unique alphanumeric identifier assigned to a user of the contactless card 300, and the identifier may distinguish the user of the contactless card from users of other contactless cards. In some examples, the customer identifier 350 may identify both the customer and the account assigned to that customer and may further identify the contactless card associated with the customer's account.
[0051] The processor and memory elements of the foregoing exemplary embodiments have been described with reference to the contact pads, but the present disclosure is not limited thereto. These elements may be implemented outside of the pads 320, or may be completely separated therefrom, or may be implemented as additional elements in addition to the processor 330 and memory 335 elements disposed within the contact pads 320.
[0052] In some examples, the contactless card 300 may include one or more antennas 355. The one or more antennas 355 may be disposed within the contactless card 300 around the processing circuit 325 of the contact pad 320. For example, the one or more antennas 355 may be integral with the processing circuit 325, and the one or more antennas 355 may be used with an external booster coil. As another example, the one or more antennas 355 may be external to the contact pad 320 and the processing circuit 325.
[0053] In one embodiment, the coil of the contactless card 300 may function as the secondary side of an air-core transformer. The terminal may communicate with the contactless card 300 by interrupting power or amplitude modulation. The contactless card 300 may infer data transmitted from the terminal using the gap of the power connection of the contactless card, which may be functionally maintained via one or more capacitors. The contactless card 300 may return communication by switching or load-modulating the load of the coil of the contactless card. The load modulation may be detected by the coil of the terminal due to interference.
[0054] As described above, the contactless card 300 may be built on a software platform operable on other devices with limited memory, such as smart cards or JavaCards, and one or more applications or applets may be securely executed. Applets may be added to the contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a short-range wireless data exchange request from a reader such as a mobile NFC reader, and generate an NDEF message containing an encrypted and secure OTP encoded as an NDEF text tag.
[0055] In an example, when preparing to send data (e.g., a mobile device, a server, etc.), the contactless card 300 may increment the counter value of one or more counters 345. Next, the contactless card 300 may provide, as inputs to an encryption algorithm that generates a diversified key as an output that may be a master key, which may be a distinct key stored in the card 300, and one of the diversified keys 347, the counter value. The master key and the counter value are also stored in the memory of a device or component that receives data from the contactless card 300, and it is understood that the data is decrypted using the diversified key that the card used to encrypt the transmitted data. The encryption algorithm may include an encryption algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc. Non-limiting examples of the encryption algorithm may include a symmetric encryption algorithm such as 3DES or AES128, a symmetric HMAC algorithm such as HMAC-SHA-256, a symmetric CMAC algorithm such as AES-CMAC. Next, the contactless card 300 may encrypt data (e.g., a customer identifier 350 and other data) using, for example, the diversified key in the form of one or more ciphertexts that may be transmitted to the mobile device as an NFC Data Exchange Format (NDEF) message. Next, the contactless card 300 may transmit the encrypted data (e.g., the ciphertext) to the mobile device, which may then decrypt the ciphertext using the diversified key (e.g., the diversified key generated by the mobile device using the counter value and the master key stored in its memory).
[0056] Figure 4 shows an example of a flow 400 that generates virtual card numbers and associated restrictions according to one or more embodiments. A user may open a banking application 402 (which may be referred to herein as the "bank app") using a mobile computing device. As shown, the bank app 402 may display at least a welcome screen and an icon 406 for signing in. The user may access the account by entering a username and password to sign in to the user's account, or by tapping the user's contactless card on the mobile computing device, or other suitable means. Tapping the user's contactless card to sign in is performed and operable in a manner similar to the one - tap authentication process described further below. It is understood that the bank app may be any software application such as a mobile - based application, a native application, a web application, or a web browser.
[0057] Once the user signs in to the user's account, the bank app 402 may display various account - related tasks such as viewing account balance, transferring funds between accounts, paying bills, generating virtual card numbers, etc., as indicated by icon 408, and make them selectable by the user. The user may select icon 408, as indicated by the highlighted box, to generate a virtual card number and one or more associated restrictions. In some examples, the user may also enter and identify the recipient of the virtual card number if the recipient may also be a bank customer. It is understood that the virtual card number may be funded, loaded, or linked to a user account associated with the user's contactless card. In an example, the user account may be a money account, a checking account, a credit card account, a debit card account, a digital wallet account, a cryptocurrency account, etc.
[0058] As further shown, the bank app 402 may display possible restriction options 410. For example, the user may select the "Time" icon to set various types of time-related restrictions on the virtual card number, such as the expiration date, the period during which the virtual card number can be used, and the specific date range when the number becomes active. The user may also select the "Merchant" icon, which can be used to set any type of merchant-related restrictions, such as restricting the use of the virtual card number to specific stores, restaurants, suppliers, etc. Further, the user may select the "Location" icon, whereby the use of the virtual card number can be restricted to a geographical location such as a specific postal code, city, town, state, etc. Further, as shown by the bottom icon, the user may select the "Amount" icon to set restrictions related to the amount, such as lowering the amount to an exact dollar and cent (or other currency) value. When the user selects any of the displayed restriction options 410, it is understood that the user may enter the restrictions manually and / or select pre-selected or pre-chosen restrictions. Advantageously, in this way, one or more restrictions that the user can set are more personalized, flexible, and unique to the recipient, thereby enabling the user to have more control over the virtual card number.
[0059] In some examples, the bank app 402 may make restriction proposals to the user based on data related to the user and, where applicable, data related to the recipient. For example, if the user has only a specific amount in the user's account that the user wants to use for funding or loading the virtual card number, an amount restriction that does not exceed the amount available in the user's account may be proposed. In other examples, if the recipient is also a customer of the bank, the financial data associated with the recipient can be analyzed to determine, for example, the types of food the recipient likes or the restaurants that the user frequently visits to propose merchant or location restrictions.
[0060] In one example of a limit, a user may generate a virtual card number for their daughter who is going out to dinner with friends at a main street restaurant. The user may set various limits for the virtual card number, such as at least a merchant limit set for the main street restaurant, a dollar limit of $40, and a time limit of 3 hours for the usage period. As shown in the dashed box, the bank app 402 may display all the selected limits and request the user to confirm that the information is correct. If changes are needed, the user may change the limits. Once the user has confirmed that the limits are correct, the user may select the icon 412 to perform a one - tap contactless card authentication and generate the virtual card number. In some examples, the one - tap authentication process may be automatically initiated when the user confirms the limits.
[0061] FIG. 5 shows an example of a flow 500 for one - tap contactless card authentication according to one or more embodiments. As described above, the exemplary one - tap authentication flow 600 may be initiated, for example, when the user selects or presses the icon 412 to generate a virtual card number with the selected limits shown in FIG. 4.
[0062] As shown, the bank app 502 (which may be similar or identical to the bank app 402) may display a one - tap introduction screen 512 and related background information to position the user for performing the one - tap authentication. For example, the background information may indicate that the user's contactless card has technology that can be used for actions requiring higher security, and may further indicate that the card can be placed flat on the screen of the computing device to proceed with the authentication process. The user may proceed by selecting or pressing the "Yes, I understand" icon.
[0063] In the example, when the user selects or presses the "Yes, I understand" icon, the banking app 502 may display a designated area enclosed by a dashed box where the user can place or tap the contactless card. It can be understood that the contactless card may be similar or identical to the above-mentioned contactless card 300. Further, as described above, it can be understood that the user's contactless card used to perform one-touch authentication may be a financial product used to "provide funds" or "load" a virtual card number.
[0064] Furthermore, it may display a one-touch authentication instruction 514, or provide an icon or link to the one-touch instruction 514. The instruction 514 may include at least step-by-step instructions for performing one-touch authentication. For example, the user may be instructed to select or press the "Please read the card" icon and then place or tap the contactless card within the dashed guide lines of the "Please place the card here" box. When the "Please read the card" icon is pressed, the banking app 502 may further provide a display indicating that the user's contactless card is ready to be scanned. In some examples, if the computing device cannot read the contactless card via NFC, the banking app 502 may instruct the user to retry card scanning. It can be understood that the contactless card can be placed anywhere on the user computing device, not only on the front of the device, but also on the back or near the NFC reader.
[0065] According to an embodiment, when the user computing device detects a contactless card via NFC, the computing device may receive one or more ciphertexts from the contactless card. It can be understood that the ciphertext may broadly refer to encrypted text, data, or information. Further, it can be understood that one or more ciphertexts may be received as an NFC Data Exchange Format (NDEF) message.
[0066] In an example, one or more received ciphertexts may include information that at least identifies a user, or other relevant information indicating that the card belongs to a particular user. For example, card user information can be any type of data or information that associates the contactless card with the user (e.g., ID number, customer number, etc.), which can be created or established in a backend system when the contactless card is created for the user and / or when the user signs up or applies for the contactless card. Subsequently, the information included in the one or more received ciphertexts can be collated or compared with the authentication information associated with the user to verify the identity of the user. The authentication information is any type of data or information that identifies the user signed into the banking app (ID number, customer number, etc.).
[0067] In one example, the banking app 502 can be configured to decrypt one or more ciphertexts received from the contactless card using at least one key (e.g., a private key, a decryption key, a key corresponding to a particular encryption-decryption scheme). The banking app 502 can securely access or receive authentication information related to the user from one or more remote computing devices such as a backend server. The authentication information can include at least an identifier or any information indicating the identity of the user logged into the banking app 502. Next, the banking app 502 can determine whether the received authentication information matches the decrypted ciphertext information received from the contactless card to verify that the contactless card actually belongs to the user and / or to verify that the user is actually claiming to be the user.
[0068] In other examples, the banking app 502 may receive one or more ciphertexts from the contactless card, execute decryption of the ciphertexts, and send the ciphertexts to one or more remote computing devices, which may be secure backend servers, to determine whether the information contained in the one or more ciphertexts matches the authentication information related to the user. Next, the one or more remote computing devices may send an instruction or confirmation of the verification of the user's identity to the banking app 502. At least in that regard, most (if not all) of the identity verification process may be performed on one or more secure remote computing devices, which may be advantageous for certain applications or use cases.
[0069] When the verification and authentication of the user's identity are successful, the banking app 502 may display an indication indicating that the contactless card has been read and the user's identity has been successfully verified. Next, the user may select or press a "Continue" icon, whereupon the banking app 502 can generate a virtual card number with one or more of the restrictions selected above.
[0070] In some examples, the banking app 502 may request permission from the user to share user-related data with third-party services such as a third-party wallet (e.g., the recipient's third-party wallet), for example, when the virtual card number is being sent to the third-party wallet. User-related data may include the user's name, middle name, surname, billing address, email address, phone number, card number, card expiration information, etc. Further, in additional examples, the user may be prompted to agree to one or more terms and / or conditions associated with transferring the virtual card number to the third-party wallet. The user may continue by selecting or pressing an "Agree" icon as shown. Thereafter, the banking app 502 may generate a virtual card number with one or more applied restrictions and be ready for use by the recipient.
[0071] Figures 4 and 5 illustrate one - tap contactless card authentication that is performed after a user selects one or more restrictions to be applied to a virtual card number. In further embodiments, the one - tap authentication process may be performed before the user selects the restrictions. For example, a user may open a bank app and select an icon to generate a virtual card number. At this point, before selecting the restrictions and generating the virtual card number, the user may be prompted to perform one - tap authentication.
[0072] Figure 6 shows an example of a flow 600 of writing a virtual card number to a blank card via a user computing device 601 and using the card via a recipient computing device 611 according to one or more embodiments. It can be understood that the user computing device 601 and the recipient computing device 611 can be any type of NFC - enabled or NFC - compatible device. After a virtual card number with one or more restrictions is generated by the user computing device 601 according to the above - mentioned flow and / or process, the user can write the virtual card number (along with the associated restrictions) to a blank, unlocked NFC - enabled card.
[0073] As shown, a bank app 602 (which may also be similar or identical to the above - mentioned bank apps 402 and 502) may display instructions or information regarding the introduction screen and the writing process. For example, the app 602 may indicate that it is possible to write the generated virtual card number to a blank card by placing the blank card within the dashed - line guide of the next screen. It can be understood that the blank card can be a blank, unlocked NFC - enabled card that is capable of securely receiving information related to the virtual card number and associated restrictions from the user computing device 601 via near - field communication.
[0074] As further shown, the bank app 602 may display a dashed guideline so that the user can place the blank card near or on the screen (or anywhere near the NFC reader of the user computing device 601, e.g., on the back or side of the device) and press or select an icon 606 for writing the virtual card number. When the icon 606 is pressed or selected, the computing device 601 may detect the blank card via the NFC reader and associated NFC circuitry, and the virtual card number may be written to the blank card as an NFC Data Exchange Format (NDEF) tag. After writing the virtual card number to the blank card, the card may be activated for use with any point-of-sale information management system or any NFC-enabled device, the details of which are further described below, at least with respect to FIG. 8. It can be understood that the activated card may be referred to as an “active” card.
[0075] On the recipient computing device 611, the recipient may open the bank app 622 and tap the active card to receive, process, and use or consume the virtual card number as shown. For example, upon receiving the virtual card number after tapping the active card, the recipient computing device 611 may copy and paste, enter, or automatically enter the associated payment information associated with the virtual card number on any web-based application or website such as the merchant website 642. It can be understood that purchases or transactions made on the website 642 are still restricted by the limitations set by the user as described above. In other examples, the virtual card number may be added and provisioned to a third-party digital wallet. In yet other examples, the user may physically use the active card at a number of point-of-sale information management systems and NFC-enabled devices such as physical stores.
[0076] Figure 7 shows an exemplary process 700 for transferring a virtual card number according to one or more embodiments from a user computing device 702 to a recipient computing device 704. The user and recipient computing devices 702 and 704 can be NFC-enabled or NFC-compatible devices. As shown, the user device 702 can be tapped on the recipient device 704 (or vice versa) to transfer the virtual card number from the user device 702 to the recipient device 704 via near-field communication. Similar to the process of writing a virtual card number to a blank card, the virtual card number can be transferred between at least two devices via their respective banking apps.
[0077] Upon transferring the virtual card number, the recipient device 704 can consume the number in various ways. For example, as shown, the banking app 722 can process the virtual card number and be used by the recipient to copy-paste or input it into the payment field of a merchant's web-based application or website according to the restrictions set by the user. In other examples, as further shown, the recipient can use a third-party wallet app 742 to provision the virtual card number to a third-party virtual wallet.
[0078] According to an example, the virtual card number can be encrypted with a personal identification number (PIN) before sending the number to the recipient device 704. Thus, the recipient may need to input the PIN in order to use the virtual card number in the banking app 722 scenario, the third-party wallet app 742 scenario, or other scenarios.
[0079] FIG. 8 shows an example of card applets stored in the memory 802 of a contactless card according to one or more embodiments, and the communication between them. The contactless card can be the above-mentioned blank and unlocked NFC-compatible card that receives a virtual card number via an NDEF tag transmitted from a user computing device. In addition to the memory 802, the contactless card can also include one or more processors or processing circuits (not shown), similar to the contactless card 300 and its contact pads shown in FIGS. 3A and 3B.
[0080] As shown, the memory 802 of the card can include a security domain 804. Within the security domain 804, there can be at least two separate applets 810 and 812, which are different from each other and both can exist in the same security domain 804. In the example, the contactless card can receive an NDEF tag from a user computing device, and the first applet 810 can consume or process the NDEF tag. The applet 810 can extract, derive, or otherwise obtain the virtual card number and other related information, such as expiration date information, one or more restrictions set by the user, and the card verification value (CVV). Next, the applet 810 can transfer the virtual card number and related information to the applet 812 to activate the contactless card for use in a point-of-sale information management system or other NFC-compatible device. In the example, a secure communication tunnel can be formed between the two applets 810 and 812 to transfer or exchange the virtual card number, and the virtual card number, together with a new expiration date, CVV, one or more keys, etc., will then become the primary account number of the contactless card for use in purchases at the store. It can be understood that the applet 810 can be a bank applet and the applet 812 can be a payment applet.
[0081] In a further example, the virtual card number can be encrypted with a PIN so that the recipient needs to enter or use the PIN to execute a transaction with the virtual card number via the contactless card.
[0082] Figure 9 shows an exemplary flowchart 900 according to one or more embodiments. Flowchart 900 is related to personalizing one or more restrictions associated with a virtual card number to a recipient and generating the virtual card number. It can be understood that the blocks of flowchart 900 and the features described therein need not be executed in a particular order. Further, it can be understood that flowchart 900 and the features described therein can be executed or supported by one or more processors.
[0083] At block 902, for example, a banking application may receive an instruction or selection from a user to generate a virtual card number. At block 904, it may be determined whether one or more restrictions are associated with the virtual card number. As described above, the one or more restrictions may include merchant restrictions, amount restrictions, time or period restrictions, and / or location restrictions, and may be selected and set by the user in a personalized manner according to the recipient. In some examples, there may be no restrictions set by the user on the virtual card number.
[0084] To generate a virtual card number with restrictions applied, one - tap contactless card authentication may be performed. Advantageously, this ensures that it is the user who actually generates the card number and applies restrictions to it. At block 906, the banking application may prompt the user to perform one - tap authentication. In an example, the authentication may be performed via the user's contactless card (which may be a payment means used for loading or funding the virtual card number), and based on the success of the authentication, the user's identity may be verified.
[0085] As described above, the NFC reader of the user computing device can detect the user's contactless card and receive one or more ciphertexts therefrom, and use this to determine whether the contactless card actually belongs to the user or is associated with the user. The ciphertext can be decrypted by the user computing device via diversified keys (diversified keys derived from at least a counter value stored in the memory and a master key) using the banking application, and can be compared with the authentication information related to the user, which can be received from one or more secure remote computing devices (e.g., server computers). In other examples, the ciphertext can be sent to one or more secure remote computing devices, and the decryption of the ciphertext and the comparison of the information contained therein with the user authentication information can be performed by the remote computing device. Based on this determination, the verification of the user's identity can be confirmed.
[0086] When the verification of the user's identity by one - tap authentication is successful, at block 908, one or more restrictions selected and set by the user (if any) can be applied to the virtual card number. Next, the banking application can generate a virtual card number, which can be consumed in different ways as described above, such as writing to a physical contactless card, sending to the recipient's computing device, etc. Also, as described above, one - tap authentication can be performed at any point in the number generation process, such as before the user selects and sets one or more restrictions.
[0087] The above - described embodiments and examples include a reader coil implemented in a mobile computing device, but it can be understood that the power to any NFC reader installed in any type of device can be dynamically adjusted to improve NFC communication. Further, the above - described NDEF messages and corresponding payloads can include message contents or data related to various use cases of contactless cards, such as activation of contactless cards, user verification, user authentication, various transactions, sales, purchases, etc.
[0088] The components and functions of the above-described device can be implemented using any combination of discrete circuits, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures. Further, the functions of the device can be implemented using a microcontroller, a programmable logic array and / or a microprocessor, or any combination of the foregoing where appropriate. It should be noted that hardware, firmware, and / or software elements may sometimes be referred to collectively or individually herein as “logic” or “circuitry.”
[0089] At least one computer-readable storage medium may include instructions that, when executed, cause a system to perform any of the computer-implemented methods described herein.
[0090] Some embodiments may be described using the expressions “one embodiment” or “an embodiment” along with their derivatives. These terms mean that a particular feature, structure, or characteristic described in connection with the embodiment is included in at least one embodiment. The appearance of the phrase “in one embodiment” in various places in this specification is not necessarily all referring to the same embodiment. Further, unless otherwise specified, it is recognized that the above features can be used together in any combination. Thus, any features discussed separately can be used in combination with each other, unless it is noted that the features are not compatible with each other.
[0091] Referring generally to the notation and nomenclature used herein, the detailed description of this specification may be presented with respect to program procedures executed on a computer or a network of computers. The descriptions and representations of these procedures are used by those skilled in the art to most effectively convey the substance of their work to those skilled in the art.
[0092] A procedure is described herein and is generally considered to be a non - self - contradictory series of operations leading to a desired result. These operations are those that require physical manipulation of physical quantities. Usually, but not always, these quantities take the form of electrical, magnetic, or optical signals that can be manipulated by storage, transfer, combination, comparison, and other means. For mainly reasons of common usage, it may be convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numerical values, etc. However, it should be noted that all of these and similar terms are merely associated with appropriate physical quantities and are nothing more than convenient labels applied to these quantities.
[0093] Furthermore, the operations performed are often referred to in terms such as addition or comparison, which are generally associated with intellectual operations performed by a human operator. In any of the operations described herein that form part of one or more embodiments, such capabilities of a human operator are not necessary or, in most cases, desirable. Rather, the operations are machine operations.
[0094] Some embodiments may be described using the expressions "coupled" and "connected" along with their derivatives. These terms are not necessarily intended to be synonyms of each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other but still cooperate or interact with each other.
[0095] Various embodiments also relate to an apparatus or system for performing these operations. This apparatus is specially constructed for the required purposes and can be selectively activated or reconfigured by a computer program stored in a computer. The procedures presented herein are not inherently related to a particular computer or other apparatus. The required structures for these various machines will become apparent from the given description.
[0096] It is emphasized that a summary of the disclosure is provided so that the reader can quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Further, in the foregoing detailed description, it can be seen that various features are grouped together in a single embodiment for the purpose of streamlining the disclosure. This method of disclosure should not be interpreted as reflecting an intention that the embodiments claimed require more features than are expressly recited in each claim. Rather, as reflected by the following claims, the subject matter of the present invention lies in less than all of the features of a single disclosed embodiment. Accordingly, the following claims are incorporated into the detailed description, with each claim standing on its own as a separate embodiment. In the appended claims, the terms "including" and "therein" are used as the plain English equivalents of the respective terms "comprising" and "wherein." Further, the terms "first," "second," "third," etc. are used merely as labels and are not intended to impose numerical requirements on their objects.
[0097] What has been described above includes examples of the disclosed architecture. Of course, it is not possible to describe all possible combinations of components and / or methodologies, but one of ordinary skill in the art can recognize that many more combinations and permutations are possible. Accordingly, the novel architecture is intended to embrace all such changes, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. An apparatus, the apparatus comprising: a near-field communication circuit for receiving and transmitting data via a near-field communication (NFC) circuit; a memory for storing instructions; one or more processors coupled to the memory, the one or more processors being operable to execute the instructions, which when executed cause the one or more processors to: receive login information from a user to access a software application and permit the user to access the software application based on the login information; receive an instruction or selection from the user via the software application and generate a virtual card number from the user account; determine whether one or more restrictions are associated with the generation of the virtual card number, the one or more restrictions being input, set, or specified by the user; receive one or more ciphertexts from a first contactless card belonging to the user via the NFC circuit and authenticate the user by decrypting the one or more ciphertexts using a diversified key, the diversified key being generated based on a master key and a counter value stored in the memory; apply the one or more restrictions to the virtual card number and generate the virtual card number based on the successful authentication of the user's identity; and the one or more processors further cause: detect a second contactless card via the NFC circuit; write the virtual card number to the second contactless card as an NFC data exchange format (NDEF) tag between the apparatus and the second contactless card; Apparatus.
2. The apparatus according to claim 1, wherein the one or more restrictions include merchant restrictions, amount restrictions, time restrictions, and / or location restrictions.
3. The apparatus according to claim 1, wherein the second contactless card includes at least a first applet and a second applet different from the first applet, and the first and second applets exist in the same secure domain.
4. The first applet consumes or processes the NDEF tag and transfers the virtual card number to the second applet, enabling the second contactless card to be activated for use in a point-of-sale information management system. Since the virtual card number is encrypted with a personal identification number (PIN), the PIN is required to use the virtual card number. The apparatus according to claim 3.
5. The one or more processors detect an NFC-compatible device via the NFC circuit, and transmit the virtual card number to the NFC-compatible device, and further cause Since the virtual card number is encrypted with a personal identification number (PIN), the PIN is required to use the virtual card number. The apparatus according to claim 1.
6. The second contactless card is tapped on an NFC-compatible device, and the NFC-compatible device reads at least the virtual card number, allowing the virtual card number to be copied and pasted or entered into one or more fields of a website or web-based application according to one or more restrictions set by the user. The apparatus according to claim 4.
7. The one or more processors further perform transmitting and provisioning the virtual card number to a third-party digital wallet. The apparatus according to claim 5.
8. The one or more processors further cause the expiration date and card verification value (CVV) information to be securely transmitted to the second contactless card via the NFC circuit. The apparatus according to claim 1.
9. The one or more processors prompt the user to confirm or change one or more restrictions input, set, or specified by the user before the authentication, and receive a selection of compliance or change, and enable the user to change the one or more restrictions based on the selection of change. and further cause. The apparatus according to claim 1.
10. The apparatus according to claim 1, wherein the first non-contact card comprises a memory and a processing circuit for executing instructions stored in the memory to transmit the one or more ciphertexts as one or more NFC Data Exchange Format (NDEF) messages to the apparatus for performing the authentication of the identity of the user.
11. The apparatus according to claim 3, wherein the second non-contact card comprises a memory and a processing circuit for executing instructions stored in the memory to process and execute the first and second applets existing in the same secure domain.
12. The apparatus according to claim 1, wherein the second non-contact card is a blank and unlocked card and belongs to the recipient of the generated virtual card number.
13. A method for generating a virtual card number, the method comprising: receiving login information from a user via a computing device to access a software application; receiving, via the software application, an instruction or selection from the user for generating the virtual card number from a user account; authenticating the user by receiving one or more ciphertexts from a first non-contact card belonging to the user via near field communication (NFC) via the computing device and decrypting the one or more ciphertexts using diversified keys, wherein the diversified keys are generated based on a master key and a counter value stored in a memory; determining, via the computing device, whether one or more restrictions are associated with the generation of the virtual card number, wherein the one or more restrictions are input, set, or specified by the user; applying the one or more restrictions to the virtual card number based on the determination and generating the virtual card number via the computing device; (i) detecting a second non-contact card via NFC and writing the virtual card number to the second non-contact card and / or (ii) transmitting the virtual card number to an NFC-compatible device different from the computing device; A method including the above steps.
14. Executing the authentication includes Detecting the contactless card via NFC and receiving the one or more ciphertexts from the contactless card, wherein the one or more ciphertexts include at least card user information; Determining whether the card user information from the received one or more ciphertexts matches or corresponds to the user, and confirming the authentication of the user's identity based on the determination that the card user information matches or corresponds to the user; The method according to claim 13, comprising the above.
15. The method according to claim 13, wherein the one or more restrictions include merchant restrictions, amount restrictions, time restrictions, and / or location restrictions.
16. The method according to claim 13, wherein the second contactless card is a blank and unlocked card belonging to the recipient of the generated virtual card number.
17. A non-transitory computer-readable storage medium storing computer-readable program code executable by a processor to perform the following predetermined operations: Receiving an instruction or selection from a user to generate a virtual card number from a user account; Receiving one or more restrictions associated with the generation of the virtual card number; Receiving one or more ciphertexts from a first contactless card belonging to the user via Near Field Communication (NFC) and authenticating the user by decrypting the one or more ciphertexts using diversified keys, wherein the diversified keys are generated based on a master key and a counter value stored in a memory; Verifying the identity of the user based on the authentication and applying the one or more restrictions to the virtual card number; Generating the virtual card number; Detecting a second contactless card via the NFC circuit; Writing the virtual card number to the second contactless card as an NFC Data Exchange Format (NDEF) tag between the processor and the second contactless card; Causing the above to be executed; A non-transitory computer-readable storage medium.
18. The non-transitory computer-readable storage medium according to claim 17, wherein the one or more restrictions include merchant restrictions, amount restrictions, time restrictions, and / or location restrictions.
19. The non-transitory computer-readable storage medium according to claim 17, wherein the user account is a money account, a checking account, a credit card account, a debit card account, a digital wallet account, or a cryptocurrency account.
Citation Information
Patent Citations
Systems and methods for cryptographic authentication of contactless cards
US10489781B1
One-tap payment using a contactless card
US10510074B1
Payment Processing Platform
US20090281945A1