Non-contact card personal identification system
The integration of PIN verification with a contactless card authentication process using a dynamic key and encrypted data transmission effectively counters credit card cloning by ensuring both knowledge and possession are verified, enhancing transaction security.
Patent Information
- Application Number
- JP2022538157
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2020-11-23
- Publication Date
- 2025-07-11
- Estimated Expiration
- 2040-11-23
AI Technical Summary
Credit card cloning, or 'skimming', poses a significant threat to transaction security, particularly with EMV cards, as PIN eavesdropping and man-in-the-middle attacks can compromise chip and PIN authentication systems.
A multi-factor authentication system combining PIN verification with a contactless card authentication process, using a dynamic key based on a counter value to encrypt data, ensuring that the PIN is not transmitted in an identifiable form, and requiring both knowledge of the PIN and possession of the contactless card for authorization.
This system significantly reduces the likelihood of card cloning by ensuring that the PIN is not transmitted in a recognizable form, thus enhancing transaction security and preventing unauthorized access.
Smart Images

Figure 0007706455000001 
Figure 0007706455000002 
Figure 0007706455000003
Abstract
Description
Technical Field
[0001] This application claims priority to U.S. Patent Application No. 16 / 725,133, filed on December 23, 2019, entitled "Contactless Card Personal Identification System". The entire content of the above application is incorporated herein by reference.
Background Art
[0002] Credit card cloning, or "skimming", is a technique in which malicious actors copy credit card information from a credit card associated with an account onto a counterfeit card. Cloning is typically done by passing the credit card through a skimmer to extract ("skim") the credit card information from the magnetic stripe of the card and storing that information on the counterfeit card. The counterfeit card can be used to make charges against the account.
[0003] EMV (derived from Europay, Mastercard, Visa) defines the standards for using smart payment cards, as well as the terminals and automated teller machines that accept them.
[0004] An EMV card is a smart card (i.e., a chip card or an IC (integrated circuit) card) that includes an integrated circuit configured to store card information in addition to magnetic stripe information (for backward compatibility). EMV cards include both cards that are physically inserted (or "dipped") into a reader and contactless cards that can be read over a short distance using near-field communication (NFC) technology.
[0005] Some EMV cards use chip and PIN (Personal Identification Number) technology to overcome problems related to cloning. For example, to authorize a transaction, the user may enter a Personal Identification Number (PIN) at a transaction terminal following a card swipe. The PIN obtained from the card and stored by the transaction terminal is compared with the PIN input, and the transaction is approved only if the two match. Such a solution can reduce fraud, but remains vulnerable to PIN eavesdropping caused by skimming, man-in-the-middle, or other types of attacks.
SUMMARY OF THE INVENTION
[0006] According to one aspect of the present invention, a multi-factor authentication system, apparatus, and method combine a Personal Identification Number (PIN) verification procedure with a contactless card authentication process to reduce the potential for losses due to card cloning.
[0007] According to one aspect, a method for two-factor authentication for a request for access to an account associated with a client includes receiving an input PIN from a user interface, inserting a contactless card storing the PIN associated with the client, transmitting the input PIN to the contactless card, receiving a ciphertext from the contactless card when the input PIN matches the stored PIN, transmitting the ciphertext to an authentication device, and permitting the request when the ciphertext is authenticated by the authentication device. The ciphertext is formed using a dynamic key of the contactless card, the dynamic key is formed using a counter value held by the contactless card, and the ciphertext includes data of the contactless card encrypted using the dynamic key.
[0008] According to another aspect, a method for two-factor authentication for a request to access an account associated with a client includes receiving an input PIN from a user interface. The method further includes inserting a contactless card storing a PIN associated with the client. The method further includes receiving a ciphertext from the contactless card, the ciphertext being formed using a dynamic key of the contactless card, the dynamic key being formed using a counter held by the contactless card, the ciphertext including data of the contactless card including the PIN and being encrypted using the dynamic key. The method further includes transmitting the input PIN and the ciphertext to an authentication device. The method further includes permitting the request when the input PIN and the ciphertext are authenticated by the authentication device.
[0009] According to a further aspect, a device includes a contactless card interface configured to communicate with a contactless card associated with a client, a user interface, a processor, and a non-volatile memory having stored program code for authenticating a request by the client. The program code, when executed by the processor, is operable to transmit an input PIN received by the user interface to the contactless card and, when the input PIN matches the stored PIN, to receive a ciphertext from the contactless card. The ciphertext is formed using a dynamic key of the contactless card, the dynamic key being formed using a counter value held by the contactless card, and the ciphertext includes data of the contactless card encrypted using the dynamic key. The program code may further be operable to transmit the ciphertext to an authentication device and permit the request when the ciphertext is authenticated by the authentication device. BRIEF DESCRIPTION OF THE DRAWINGS
[0010]
Figure 1A
Figure 1B
Figure 2A
Figure 2B
Figure 3A
Figure 3B
Figure 4A
Figure 4B
Figure 5A
Figure 5B
Figure 6
Figure 7
Figure 8
Figure 9
Figure 10
Embodiments for Carrying Out the Invention
[0011] The security of data and the integrity of transactions are of utmost importance to businesses and consumers. As electronic transactions make up an increasingly large portion of commercial activities and malicious actors become increasingly aggressive in attempting to breach transaction security, this need continues to grow.
[0012] Embodiments of the present disclosure provide a system, method, and apparatus for multi-factor authentication of transactions received at a client device using a personal identification number (PIN) in combination with a contactless card.
[0013] The contactless card may include a substrate that includes memory storing one or more applets, a counter value, and one or more keys. In some embodiments, as described herein, the memory may further store a PIN that controls the use of the contactless card. In one embodiment, the counter value may be used to generate a unique cryptographic code that can be used for authentication of contactless card transactions. The cryptographic code may be used in conjunction with the PIN to provide two-factor authentication for contactless card transactions.
[0014] The cryptographic code may be formed as described in U.S. Patent Application Serial Number 16 / 205,119, filed November 29, 2018, by Osborn et al. and incorporated herein by reference, entitled "Systems and Methods for Cryptographic Authentication of Contactless Cards" (hereinafter referred to as the "'119 application"). In some embodiments, the cryptographic code may be formed from a shared secret, a plurality of keys, and a cryptographic hash of the counter value.
[0015] According to one aspect, the cipher may be used together with a PIN to provide multi-factor authentication for contactless card transactions. The multi-factor authentication may include verifying the user's knowledge of the card's PIN before or as part of authenticating a transaction that uses the cipher. In some embodiments, the cipher may be formed using the PIN. In some embodiments, the cipher may include the encoded PIN. In either case, since the PIN is not transmitted in an identifiable form, the security of the transaction is maintained, and thus the likelihood of theft is reduced. Such a measure of using the PIN together with the cipher for two-factor authentication has a protection function against cloning of contactless cards by unauthorized third parties.
[0016] In some embodiments, the PIN verification may be performed by the card as a prerequisite for cipher generation. In other embodiments, the PIN verification may be performed by the transaction device or the backend authentication server as part of the cipher authentication. Each of these methods will be described in more detail below.
[0017] Of course, in various systems including clients, client devices, and authentication servers of various embodiments, the functions of PIN storage, encryption, and authentication may be performed by various components. In some embodiments, a copy of the PIN may be held in the memory of the contactless card. In such embodiments, the copy of the PIN may be used to verify the user of the contactless card as part of the cipher authentication process. In some embodiments, the PIN may be used to generate a digital signature or a cipher. In some embodiments, the cipher authentication may be performed by the transaction device, the authentication server, or some combination thereof.
[0018] Thus, the system provides two-factor authentication that establishes both knowledge (i.e., the PIN number) and possession (i.e., the contactless card and the dynamic key), and can reduce the ability of malicious actors to successfully clone the contactless card.
[0019] Next, these and other features of the present invention will be described with reference to the drawings. Here, like reference numerals are used throughout to refer to like elements. Referring generally to the notations and nomenclature used herein, the following detailed description may be presented from the perspective of program processes executed on a computer or a network of computers. The description and representation of these processes are used by those skilled in the art to most effectively convey the substance of their work.
[0020] A process is here, and generally is considered to be a sequence of self-consistent operations that bring about a desired result. These operations require physical manipulation of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of performing operations such as storing, transmitting, combining, comparing, and others. It can be seen that mainly for reasons of common usage, it is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, and the like. However, it should be noted that all of these terms and similar terms should be associated with appropriate physical quantities and are merely convenient labels applied to those quantities.
[0021] Furthermore, the operations performed are often referred to in terms such as addition or comparison, which are generally associated with mental operations performed by a human operator. In almost any of the operations described herein that form part of one or more embodiments, in most cases, such an ability of a human operator is not necessary or desirable. Rather, this operation is a machine operation. Useful machines for performing the operations of the various embodiments include general-purpose digital computers or similar devices.
[0022] Various embodiments also relate to an apparatus or system for performing these operations. The apparatus may be specially configured for the required purpose, or may include a general-purpose computer selectively activated or reconfigured by a computer program stored in a computer. The processes shown herein are not inherently related to a particular computer or other apparatus. Various general-purpose machines may be used with programs written in accordance with the teachings herein, or it may prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for these various machines will become apparent from the given description.
[0023] Reference is now made to the drawings. Throughout, like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding. It will be evident, however, that new embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form in order to facilitate the description. The intention is to cover all modifications, equivalents, and alternatives falling within the scope of the claimed subject matter.
[0024] FIG. 1A shows a data transmission system according to an exemplary embodiment. As further discussed below, system 100 may include a contactless card 105, a client device 110, a network 115, and a server 120. Although FIG. 1A shows a single example of components, system 100 may include any number of components.
[0025] System 100 may include one or more contactless cards 105. In one embodiment, contactless card 105 includes a credit card-sized card that includes an embedded integrated circuit, a storage device, and an interface that enables the card to communicate with a transmitting device using a near field communication (NFC) protocol. Contactless cards that may be used herein include, for example, the contactless cards described in the '119 application.
[0026] System 100 may include a client device 110. The client device 110 may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, a computer device such as a server, network equipment, a personal computer, a workstation, a telephone, a handheld PC, a personal digital assistant, a thin client, a fat client, an Internet browser, or other devices, or a communication device. The client device 110 may also be a mobile device. For example, the mobile device may include an Apple (registered trademark) iPhone (registered trademark), iPod (registered trademark), iPad (registered trademark), or any other mobile device running the Apple (registered trademark) iOS operating system, any device running the Microsoft Windows (registered trademark) mobile operating system, any device running Google's Android (registered trademark) operating system, and / or other smartphones, tablets, or similar wearable mobile devices.
[0027] The client device 110 may include a processor and a memory, and the processing circuitry may include additional components such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and anti-tampering hardware necessary to perform the functions described herein. The client device 110 may further include a display and an input device. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including a liquid crystal display, light emitting diode display, plasma panel, and cathode ray tube display. The input device may include any device for inputting information into the user device that can be utilized and supported by the user device, such as a touch screen, keyboard, mouse, cursor control device, touch screen, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and interact with the software and other devices described herein.
[0028] In some examples, the client device 110 of the system 100 may execute one or more applications, such as a software application that enables network communication with one or more components of the system 100 to transmit and / or receive data, for example.
[0029] The client device 110 may communicate with one or more servers 120 via one or more networks 115, and may operate as a respective front-end and back-end pair together with the server 120. The client device 110 may, for example, send one or more requests to the server 120 from a mobile device application executed on the client device 110. The one or more requests may be related to obtaining data from the server 120. The server 120 may receive one or more requests from the client device 110. Based on the one or more requests from the client device 110, the server 120 may be configured to obtain the requested data from one or more databases (not shown). Based on the receipt of the requested data from the one or more databases, the server 120 may be configured to send the received data in response to the one or more requests to the client device 110.
[0030] The system 100 may include one or more networks 115. In some examples, the network 115 may be one or more of a wireless network, a wired network, or any combination of a wireless network and a wired network, and may be configured to connect the client device 110 to the server 120. For example, the network 115 may include one or more of an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (LAN), a global system for mobile communications, a personal communication service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short messaging service, a time division multiplexing based system, a code division multiple access based system, D-AMPS, Wi-Fi (registered trademark), fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth (registered trademark), NFC, radio frequency identification (RFID), Wi-Fi (registered trademark), etc.
[0031] Furthermore, network 115 may include, but is not limited to, a telephone line, fiber optic, IEEE Ethernet 902.3, wide area network, wireless personal area network, LAN, or a global network such as the Internet. Further, network 115 may support an Internet network, a wireless communication network, a cellular network, etc., or any combination thereof. Network 115 may operate as a stand-alone network or may further include one network or any number of the exemplary types of networks described above that cooperate with each other. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may translate to or from other protocols to one or more protocols of network devices. Although network 115 is depicted as a single network, according to one or more examples, network 115 may include, for example, multiple interconnected networks such as the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, and a home network.
[0032] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to memory. Server 120 may be configured as a central system, server, or platform for controlling and invoking various data at various times to execute multiple workflow operations. Server 120 may be configured to connect to one or more databases. Server 120 may be connected to at least one client device 110. In some embodiments, server 120 may be an authentication server configured to perform cryptographic authentication as disclosed herein.
[0033] Figure 1B is a timing diagram showing an exemplary sequence for authenticating a contactless card transaction according to one or more embodiments of the present disclosure. In particular, Figure 1B describes an exemplary process for exchanging authentication data including an encryption key between the contactless card 105 and the client device 110. The system 100 may include the contactless card 105 and the client device 110 that may include the application 122 and the processor 124. Figure 1B may refer to the same components as shown in Figure 1A.
[0034] In step 102, the application 122 communicates with the contactless card 105 (e.g., after being carried near the contactless card 105). The communication between the application 122 and the contactless card 105 may include the contactless card 105 getting close enough to a card reader (not shown) of the client device 110 to enable NFC data transmission between the application 122 and the contactless card 105.
[0035] In step 104, after communication is established between the client device 110 and the contactless card 105, the contactless card 105 generates a message authentication code (MAC) encryption key. In some examples, this may be done when the contactless card 105 is read by the application 122. In particular, this may be done during a read, such as an NFC read, of a Near Field Data Exchange (NDEF) tag that may be generated according to the NFC data exchange format. For example, a reader such as the application 122 may send a message such as an applet selection message having an applet ID of an NDEF generation applet. When the selection is confirmed, a read file message may be sent following a sequence of selection file messages. For example, the sequence may include "select function file", "load function file", and "select NDEF file". At this point, the counter value held by the contactless card 105 may be updated or incremented, and then "load NDEF file" may be sent. At this point, a message including a header and a shared secret may be generated.
[0036] Thereafter, a session key may be generated. In one embodiment, the transformation key may be generated by combining a master symmetric key and a dynamic counter value maintained by the contactless card using a cryptographic hash. Examples of cryptographic hash algorithms that may be used include symmetric encryption algorithms, HMAC algorithms, and CMAC algorithms. Non-limiting examples of symmetric algorithms that may be used to encrypt a username and / or password include symmetric encryption algorithms such as 3DES (Triple Data Encryption Algorithm) or AES (Advanced Encryption Standard) 128, symmetric hash-based message authentication (HMAC) algorithms such as HMAC-SHA-256, and symmetric cipher-based message authentication code (CMAC) algorithms such as AES-CMAC. It is understood that many forms of encryption are known to those skilled in the art, and the present disclosure is not limited to the forms specifically identified herein.
[0037] A MAC cipher may be generated from a message, which may include a header and a shared secret. In some embodiments, shared information including, but not limited to, the shared secret and / or PIN may then be concatenated with one or more blocks of random data and encoded using an encryption algorithm and a transformation key to generate a MAC cipher. Thereafter, the MAC cipher and the header may be concatenated, encoded as hexadecimal of ASCII, and returned in an NDEF message format (in response to the "Read NDEF file" message).
[0038] In some examples, the MAC cipher may be transmitted as an NDEF tag, and in other examples, the MAC cipher may be included with a uniform resource identifier (e.g., as a formatted string).
[0039] In some examples, the application 122 may be configured to send a request to the contactless card 105, and the request may include an instruction to generate a MAC cipher.
[0040] In step 106, the contactless card 105 transmits the MAC cipher to the application 122. In some examples, the transmission of the MAC cipher is performed by NFC, but the present disclosure is not limited thereto. In other examples, this communication may be performed by Bluetooth®, Wi-Fi®, or other means of wireless data communication.
[0041] In step 108, the application 122 transmits the MAC cipher to the processor 124.
[0042] In step 112, the processor 124 verifies the MAC cipher according to the instructions from the application 122. For example, the MAC cipher may be verified by an authentication server such as the server 120 in FIG. 1A. The authentication server may store a copy of the client device's counter, shared secret, and key for each client device 110. In some embodiments, as will be described in more detail below, the authentication server may store the PIN associated with the client device. The authentication server may update the counter for each contactless card transaction according to the protocol established between the client device 110 and the authentication server so as to maintain the synchronized state of the counter. The authentication server may construct the expected MAC cipher using a copy of the counter, key, shared secret, and / or PIN.
[0043] In some examples, the MAC cipher may function as a digital signature for verification purposes. Other digital signature algorithms such as public key asymmetric algorithms, for example, digital signature algorithms, RSA algorithms, or zero-knowledge protocols may be used to perform this verification.
[0044] The authentication server may compare the MAC cipher received from the contactless card with a predicted MAC cipher generated by the authentication server. Such measures improve the security of transactions in various ways. First, the dynamic nature of the cipher constructed using a variable counter value that is periodically updated according to the protocol established between the client and the server reduces the ability of malicious third parties to reuse the authentication information. Second, the use of an encryption algorithm further prevents the discovery of confidential information by eavesdropping. Third, by incorporating PIN code verification along with cipher authentication, a knowledge modifier for two-factor authentication is added.
[0045] Figures 2A and 2B show the respective systems and processes of one embodiment of a two-factor authentication system configured to support an authentication method that uses a PIN, along with and / or as part of, a cipher.
[0046] In the system 200 of FIG. 2A, it can be seen that a transaction device 222 (which may be a client mobile device, a merchant transaction device, or any device with NFC communication capabilities) includes a user interface 225 for receiving information such as an input PIN from a user 202. The transaction device 222 also includes an NFC interface 220 configured to support NFC communication with a contactless card 205 and a network interface 227 configured to support network communication, including but not limited to Internet Protocol (IP) communication with an authentication server 223.
[0047] According to one aspect, the contactless card 205 includes PIN verification logic 210, which may include hardware, software, or a combination thereof configured to compare the PIN stored in the memory of the contactless card with the PIN received from the transaction device 222, for example, as part of an NDEF record. The card 205 also includes cipher generation logic 211 configured to generate a cipher, for example, as disclosed in the '119 application.
[0048] The encryption logic 211 may comprise a combination of hardware and software components, which may include, but is not limited to, a storage device configured to store one or more keys and counter values for the card 205. The contactless card may further include a counter for generating a modified dynamic key for use in encoding messages from the contactless card, encryption and / or hashing hardware and software, etc. In some embodiments, the encryption logic 211 may be implemented, at least in part, as an applet stored in the memory of the contactless card 205. Although the PIN logic 210 and the encryption logic 211 are shown separately delimited, it is understood that they may be distributed in different ways in various embodiments. For example, in some embodiments, the PIN logic 210 and the encryption logic 211 may be implemented by a single applet.
[0049] It can be seen that the server 223 includes encryption verification logic 228. The encryption verification logic 228 may comprise a combination of hardware and software components, which may include, but is not limited to, a storage device for storing client keys and counter values, a counter, encryption and / or hashing hardware and software, etc. In one embodiment, the encryption verification logic 228 may be configured to generate a modified dynamic key for use in generating an expected cipher, and the verification logic may compare the expected cipher with the cipher received from the client device. Matching ciphers indicate equivalence between the counter of the client device and the authentication server. Further, matching ciphers may indicate knowledge of information such as a shared secret, PIN, etc.
[0050] Figure 2B shows a method for two-factor authentication using the system of Figure 2A. At step 251, a transaction is initiated by user 202. For example, the user may attempt to access an account, make a purchase, or perform an operation that benefits from the two-factor authentication method disclosed herein. At step 252, user 202 is prompted to enter a PIN, and upon receiving the entered PIN, the transaction device 222 may initiate a dual authentication cryptographic exchange with the contactless card 205, for example, by prompting the user to tap the card 205 on the transaction device 222 or to bring the contactless card 205 within the communication range of the transaction device 222.
[0051] When the contactless card is within the range of the transaction device, at step 253, the transaction device 222 sends the entered PIN to the contactless card 205, for example, as a PIN record, and issues a command to read the NFC tag associated with the cryptographic generation applet. At step 254, the PIN verification logic 210 may compare the entered PIN with the stored PIN 215. If it is determined to be "matched" at step 255, the cryptographic generation applet generates a cryptographic code at step 256 and is instructed to send the cryptographic code to the transaction device 222.
[0052] At step 257, if the cryptographic code is not received, for example, due to a PIN mismatch, the transaction may be cancelled at step 259. If the cryptographic code is received at step 257, at step 258, the transaction device 222 requests authentication of the transaction and sends the cryptographic code to the authentication server 223.
[0053] In step 260, when the authentication server 223 receives the ciphertext, the authentication server obtains client data including a counter, a key, a shared secret, etc. related to the contactless card 205. Using this information, in step 261, the authentication server generates an expected ciphertext, and in step 262, determines whether the generated ciphertext matches the unique digital signature provided by the received ciphertext. In step 263, the authentication server returns an approval / denial response to the transaction device 222. If the transaction device 222 determines in step 264 that the transaction is approved, the transaction may be executed in step 265. If the transaction is denied, the transaction device cancels the transaction in step 250.
[0054] The disclosed two-factor PIN-based authentication system improves transaction security by protecting the stored PIN 215 from discovery. As discussed, the stored PIN is not transmitted publicly and thus cannot be obtained by malicious monitoring during PIN exchange. If the PIN, shared secret, and / or counter value can be obtained by skimming, a cloned card without knowledge of the dynamic counter protocol implemented between the card and the authentication server will be inoperable.
[0055] Figures 3A and 3B disclose other embodiments of a two-factor PIN-based authentication system and method. Here, the PIN verification functionality may be provided by the authentication server 323 as part of the ciphertext verification logic 328. In the system 300 of Figure 3A, the card 305 stores a unique PIN 315 for the contactless card and constitutes cryptographic logic 311 that may include a ciphertext generation applet as described above. According to one embodiment, although described in more detail below, the ciphertext provided by the contactless card 305 may include the PIN 315 and / or be formed using the PIN 315.
[0056] The transaction device 322 includes a user interface 325, an NFC interface 320, and a network interface 327. Further, the transaction device may include encapsulation logic 324. In one embodiment, the encapsulation logic 324 may include code for encrypting the input PIN and / or password before transmitting the input PIN / password pair to the authentication server 323.
[0057] The authentication server 323 includes encryption verification logic 328. The encryption verification logic 328 may be operative to extract the input PIN from the encrypted input PIN / password pair. The encryption verification logic 328 may further be configured to generate an expected password using the input PIN and stored client data such as a counter and key data. The encryption verification logic 328 may then compare the expected password with the extracted password to determine a match indicating a correlation between the input PIN and the stored PIN, and the counter and key information.
[0058] FIG. 3B is a flowchart of a two-factor authentication process that may be executed by the system 300. After a transaction is initiated at step 351, the user 302 is requested to enter a PIN at step 352. At step 353, the encryption authentication process is initiated as described above. For example, the transaction device 322 may issue an NFC read operation to an NDEF tag generation applet of the card 305, particularly an NDEF tag generation applet configured to obtain the PIN 315 from the contactless card 305 for inclusion in the encryption payload. At step 356, the contactless card applet may assemble the encrypted data in the form of <user ID><counter><MAC of user ID+counter+PIN>. In some embodiments, a modified key formed using the counter may be used to encrypt <MAC of user ID+counter+PIN> using an encryption hash algorithm or the like. To perform this verification, a public key asymmetric algorithm such as a digital signature algorithm and an RSA algorithm, or a zero knowledge protocol may alternatively be used.
[0059] The contactless card 305 returns the cipher to the transaction device 322, and at step 354, the transaction device 322 combines the input PIN with the received cipher. In some embodiments, the input PIN and / or the received cipher may be encrypted to obfuscate the input PIN information, for example, using a symmetric encryption algorithm. This combination is sent to the authentication server 323.
[0060] At step 360, the authentication server 323 retrieves from storage the authentication information (including counter value, key, shared secret, etc.) regarding the contactless card. Using this information, at step 361, the authentication server may assemble a predicted cipher, for example, in the form of <MAC of user ID + stored counter + input PIN>. At step 362, the authentication server determines whether the predicted cipher matches the cipher obtained from the contactless card, and at step 363, returns the authentication status to the transaction device 322. In response to the receipt of the authentication status at step 364, the transaction is either executed at step 364 or canceled at step 359.
[0061] Thus, in the embodiments of FIGS. 3A and 3B, the cipher generated by the contactless card is formed using the PIN, but the PIN itself is not transmitted in a form that can be identified or derived on the network.
[0062] FIGS. 4A and 4B disclose other embodiments of a two-factor PIN-based authentication system and method. Here, PIN verification may be performed by the transaction device using public-key cryptography. In one embodiment, the contactless card 405 holds a private key 417. The private key 417 is known only to the contactless card 405 and may be used to decrypt communications encrypted with the public key. The contactless card may further include digital signature logic 411 configured to generate a unique digital signature, a cryptographic hash, to provide a cipher for communication to the transaction device 422.
[0063] The transaction device 422 includes a user interface 425 and an NFC interface 420. The transaction device is further shown to include a random number generator 454, an encryption logic 424, and a memory 455 that stores a public key 457 related to the contactless card. Here, the public key may be obtained by the transaction device from a trusted certification authority. The transaction device further includes a digital signature logic 456 for generating a digital signature, as described below. In some embodiments, the public key of the card 405 may be stored by the card 405 and read by the transaction device as part of the authentication process.
[0064] Figure 4B shows a method of two-factor authentication using the system 400 of Figure 4A. When it is determined in step 461 that a transaction is initiated, in step 462, the user 404 is prompted to enter an input PIN. In step 463, the transaction device obtains the public key related to the contactless card from the card itself or from a trusted certification authority. In step 465, the transaction device generates a random number, encrypts it with the public key, and transmits it to the contactless card 405. In step 466, the contactless card decrypts the random number using its private key and generates a digital signature using the combination of the random number and the stored PIN 415. The obtained digital signature is returned to the transaction device 422.
[0065] In step 467, the transaction device 422 also uses a combination of the random number and the input PIN received from the user 402 to generate a digital signature. In step 468, the digital signatures are compared to identify a match. Depending on the match status, the transaction is executed in step 470 (match) or cancelled in step 469 (mismatch).
[0066] Figures 5A and 5B disclose other embodiments of a two-factor PIN-based authentication system and method. Here, the contactless card PIN is stored in an authentication server and used in combination with a cipher to authenticate a transaction. In the system 500 of Figure 5A, the contactless card 505 includes encryption logic 511 for generating a cipher using a combination of a counter, a dynamic key, a shared secret, etc., as described above. The transaction device 522 includes a user interface 520, an NFC interface 525, and a network interface 527. Further, the transaction device may include encapsulation logic 524. The encapsulation logic 524 may include, in one embodiment, code for encrypting the input PIN and / or the cipher before sending the input PIN / cipher pair to the authentication server 523. The authentication server 523 includes a PIN table 595, PIN matching logic 594, and cipher verification logic 596.
[0067] FIG. 5B shows a method of two-factor authentication using the system 500 of FIG. 5A. Following the start of a transaction in step 551, in step 552 the user 502 is prompted to enter a PIN, and in step 553 the transaction device 522 requests a cipher from the contactless card 505. In step 555, the contactless card generates a cipher and returns it to the transaction device 5422. In step 554, the transaction device combines and encrypts the input PIN received from the user and the cipher from the contactless card and transmits it to the authentication server 523. In step 560, the authentication server obtains the PIN, counter, and key regarding the contactless card 505. In step 561, the authentication server decrypts the message from the transaction device 522, extracts the input PIN, and in step 562, compares the extracted input PIN with the expected input PIN obtained from the PIN table. In step 563, the authentication server 523 may also extract the cipher obtained from the contactless card 505. The authentication server 523 may construct an expected cipher using the stored key, counter, and shared secret information stored by the cipher verification logic. In step 564, the transaction device may compare the expected cipher with the extracted cipher to determine a match. Depending on the comparison, in step 565, the authentication server 523 returns an authentication status to the transaction device. Upon receiving the authentication status in step 566, the transaction is executed in step 568 (match) or cancelled in step 567 (mismatch).
[0068] As described above, various systems and methods for providing two-factor PIN-based authentication have been shown and described. Here, to support the methods described, exemplary components that may be included in the contactless card, transaction device, and / or authentication server, along with and / or instead of the components already described, are described with respect to FIGS. 6-10.
[0069] Figure 6 shows a contactless card 600. This may include a payment card such as a credit card, debit card, or gift card, and is issued by a service provider 605. The identity of the service provider 605 may be displayed on the front or back of the card 600. In some examples, the contactless card 600 may include, but is not limited to, an identity card and is not related to a payment card. In some examples, the payment card may include a dual interface contactless payment card. The contactless card 600 may include a substrate 610, and the substrate 610 may include a single layer made of plastic, metal, and other materials, or one or more laminations. Exemplary substrate materials include polyvinyl chloride, polyvinyl acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 600 may have physical characteristics compliant with the ID-1 format of the ISO / IEC 7810 standard; otherwise, the contactless card may comply with the ISO / IEC 14443 standard. However, it is understood that the contactless card 600 according to the present disclosure may have different characteristics, and the present disclosure does not require that the contactless card be implemented as a payment card.
[0070] The contactless card 600 may include identification information 615 displayed on the front and / or back of the card, and contact pads 620. The contact pads 620 may be configured to establish contact with other communication devices such as user devices, smartphones, laptops, desktops, or tablet computers. The contactless card 600 may also include a processing circuit, an antenna, and other components not shown in Figure 6. These components may be arranged behind the contact pads 620 or in other locations on the substrate 610. Further, the contactless card 600 may include a magnetic stripe or tape, which may be arranged on the back of the card (not shown in Figure 6).
[0071] As shown in FIG. 7, the contact pad 720 may include a processing circuit for storing and processing information, and the processing circuit includes a microprocessor 730 and a memory 735. The processing circuit may include additional components including a processor, a memory, an error and parity / CRC checker, a data encoder, a collision prevention algorithm, a controller, a command decoder, a security primitive, and anti-tampering hardware necessary to execute the functions described herein.
[0072] The memory 735 may be a read-only memory, a write-once / read-multiple memory, or a read / write memory, such as RAM, ROM, and EEPROM, and the non-contact card 700 may include one or more of these memories. The read-only memory may be programmable at the factory as read-only or may be programmable only once. The once-only programmability provides the opportunity to read multiple times after writing once. The write-once / read-multiple memory may be programmed after the memory chip is shipped from the factory. Once the memory is programmed, it cannot be rewritten but may be read multiple times.
[0073] The memory 735 may be configured to store one or more applets 740, one or more counters 745, and customer information 750. According to one aspect, the memory 735 may store a PIN 777.
[0074] One or more applets 740 may include one or more software applications associated with the applications of respective one or more service providers, such as Java (registered trademark) card applets, and configured to execute on one or more non-contact cards. For example, the applet may include logic configured to generate a MAC cipher as described above. The MAC cipher includes, in some embodiments, a MAC cipher formed using at least in part PIN information.
[0075] The counter 745 of 1 or more may include a numeric counter sufficient to store an integer. The customer information 750 may include a unique alphanumeric identifier assigned to the user of the contactless card 700 and / or one or more keys that can be used together to distinguish the user of the contactless card from the users of other contactless cards. In some examples, the customer information 750 may include information identifying both the customer and the account assigned to that customer, and may further identify the contactless card associated with the customer's account.
[0076] Although the processor and memory elements of the foregoing exemplary embodiments have been described with reference to the contact pads, the present disclosure is not limited thereto. It is understood that these elements may be implemented external to the pads 720, or may be implemented completely separately therefrom, or may be implemented as additional elements in addition to the microprocessor 730 and memory 735 elements disposed within the contact pads 720.
[0077] In some examples, the contactless card 700 may include one or more antennas 725 disposed within the contactless card 700 and around the processing circuit 755 of the contact pads 720. For example, the one or more antennas may be integral with the processing circuit, and the one or more antennas may be used with an external booster coil. As another example, the one or more antennas may be external to the contact pads 720 and the processing circuit.
[0078] As described above, the contactless card 700 may be constructed on a software platform operable on a smart card or other device that includes program code such as Java (registered trademark) card, processing capabilities, and memory. The applet may be configured to respond to one or more requests, such as a Near Field Data Exchange (NDEF) request from a reader such as a mobile Near Field Communication (NFC) reader, and generate an NDEF message containing an encrypted and secure OTP encoded as an NDEF text tag.
[0079] FIG. 8 shows an exemplary NDEF short record layout (SR = 1) 800 according to an exemplary embodiment. The NDEF message provides a standardized way for a transaction device to communicate with a contactless card. In some examples, the NDEF message may include one or more records. The NDEF record 800 includes a header 802, which defines how to interpret the rest of the record, including a message start (MB) flag 803a, a message end (ME) flag 803b, a chunk flag (CF) 803c, a short record (SR) flag 803d, an ID length (IL) flag 803e, and a type name format (TNF) field 803f. The MB 803a and ME flags 803b may be set to indicate the first and last records of the message, respectively. The CF 803c and IL flags 803e provide information about the record, including whether the data can be "chunked" (data that spans multiple records within the message) or whether the ID type length field 808 can be relevant. The SR flag 803d may be set if the message contains only one record.
[0080] The TNF field 803f identifies the type of content included in the field, as defined by the NFC protocol. These types include empty, well-known (data defined by the NFC Forum's record type definition (RTD)), multipurpose internet mail extensions (MIME) [defined by RFC2046], uniform resource identifiers (URI) [defined by RFC3986], external (user-defined), unknown, unchanged [for chunks], and reserved.
[0081] The other fields of the NFC record include type length 804, payload length 806, ID length 808, type 810, ID 812, and payload 814. The type length field 804 specifies the exact kind of data found within the payload. The payload length 806 includes the length of the payload in bytes. The record may contain up to 4,294,967,295 bytes (or 2^32 - 1 bytes) of data. The ID length 808 includes the length of the ID field in bytes. The type 810 identifies the type of data the payload contains. For example, for authentication purposes, Type 810 may indicate that the payload 814 is an encrypted code formed at least in part using a personal identification number (PIN) retrieved from the memory of a contactless card. The ID field 812 provides a means for an external application to identify the entire payload carried within the NDEF record. The payload 814 contains the message.
[0082] In some examples, data may first be stored in the contactless card by performing STORE DATA (E2) under a secure channel protocol. This data may include not only the personal user ID (pUID) and PIN unique to the card, but also cryptographic processing data including an initial key, a session key, a data encryption key, a random number, and one or more of the other values described in more detail below. In other embodiments, the pUID and PIN may be pre-loaded into the contactless card before the contactless card is delivered to the client. In some embodiments, the PIN may be selected by the client regarding the contactless card and written back to the contactless card after verification of the client using various strict authentication methods.
[0083] FIG. 9 shows a communication system 900 in which either the contactless card 910 and / or the authentication server 950 can store information that can be used during the authentication of the first element. As described with respect to FIG. 3, each contactless card may include a microprocessor 912 and a memory 916 for customer information 919 including one or more unique identification attributes such as identifiers, keys, random numbers, etc. In one aspect, the memory further includes an applet 917 operable when executed by the microprocessor 912 to control the authentication process described herein. As previously described, the PIN 918 may be stored within the memory 916 of the card 910 and accessed by the applet and / or as part of the customer information 919. Further, each card 910 may include one or more counters 914 and an interface 915. In one embodiment, the interface operates NFC or other communication protocols.
[0084] The client device 920 includes a contactless card interface 925 for communicating with a contactless card, and one or more other network interfaces (not shown) that enable the device 920 to communicate with a service provider using various communication protocols as described above. The client device may further include a user interface 929 that enables communication between the application of the service provider and the user of the client device 920. The user interface 929 may include one or more of a keyboard or a touch screen display. The client device 920 further includes a processor 924 and a memory 922. The memory 922 stores information and program code that controls the operation of the client device 920 when executed by the processor, and includes, for example, a client-side application 923 that can be provided to the client by the service provider to facilitate access to the application of the service provider and the use of the application of the service provider. In one embodiment, the client-side application 923 includes program code configured to transmit authentication information including a PIN code from the contactless card 910 to one or more services provided by the service provider as described above. The client-side app 923 may be controlled via an application interface displayed on the user interface 926. For example, the user may select an icon, link, or other mechanism provided as part of the application interface to launch the client-side application to access the application service. Here, part of the launch includes verifying the client using an encryption exchange.
[0085] In an exemplary embodiment, the cryptographic exchange includes a transmitting device having a processor and a memory, where the memory of the transmitting device includes a master key, transmission data, and a counter value. The transmitting device communicates with a receiving device having a processor and a memory, where the memory of the receiving device includes a master key. The transmitting device generates a transformed key using the master key and one or more cryptographic algorithms, stores the transformed key in the memory of the transmitting device, encrypts the counter value using the one or more cryptographic algorithms and the transformed key to generate an encrypted counter value, encrypts the transmission data using the one or more cryptographic algorithms and the transformed key to generate encrypted transmission data, and is configured to transmit the encrypted counter value and the encrypted transmission data as a cipher to the receiving device. The receiving device is configured to generate a transformed key based on the stored master key and the stored counter value, store the transformed key in the memory of the receiving device, and decrypt the encrypted cipher (including the encrypted counter and the encrypted transmission data) using the one or more decryption algorithms and the transformed key. The receiving device may authenticate the transmitting device when the decrypted counter matches the stored counter. The counter is incremented at each of the transmitting device and the receiving device for subsequent authentication, thereby providing a dynamic authentication mechanism based on the cipher for the transmitting device / receiving device transaction.
[0086] As described in connection with FIG. 1A, client device 920 may be connected to various services of service provider 905 and managed by application server 906. In the illustrated embodiment, authentication server 950 and application server 906 are shown as separate components, but it should be understood that the application server may include all of the functionality described as being included in the authentication server.
[0087] It can be seen that the authentication server 950 includes a network interface 953 for communicating with members of the network via the network 930 and a central processing unit (CPU) 959. In some embodiments, the authentication server may include a non-transitory storage medium for storing a PIN table 952 containing PIN information regarding clients of the service provider. Such information may include, but is not limited to, the client's username, the client's identifier, and the client's key and counter. In one embodiment, the authentication server further includes an authentication unit 954 for controlling decryption of the cipher and extraction of the counter, and a client counter value table 956 that can be used as described below to perform authentication in cooperation with the contactless card 910. In various embodiments, the authentication server may further include a PIN table 952 configured to have an entry for each client / contactless card pair.
[0088] FIG. 10 shows an example of a client device 1000 including a display 1010 including a prompt window 1020 and an input unit 1030. The prompt portion may display various prompts for guiding the client through the authentication process, for example, including the prompt "Please hold the card in front of the device" to prompt the movement of the card 805 towards the device 1000. As shown in FIG. 10, the prompt includes instructions such as "Please enter the PIN", and a keyboard or other input mechanism may be provided to enable the user to enter the PIN. In some embodiments, following a successful card tap and PIN entry, the user may complete a transaction. For example, completing a charge, accessing confidential data, accessing a particular person, etc.
[0089] As described above, a two-factor PIN-based authentication system and method using cipher and PIN exchange for multi-factor authentication have been shown and described to reduce and / or eliminate the possibility of card cloning.
[0090] As used herein, the terms "system," "component," and "unit" are intended to refer to a computer-related entity, either hardware, a combination of hardware and software, software, or software in execution, examples of which are described herein. For example, a component may be a process running on a processor, a processor, a hard disk drive, a plurality of storage drives, a non-transitory computer-readable medium (of optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer, among others. By way of illustration, both an application running on a server and the server can be components. One or more components may be present within a process and / or thread of execution, and a component may be localized on one computer and / or distributed between two or more computers.
[0091] Furthermore, components may be communicatively coupled to each other by various types of communication media for purposes of coordinating operations. This coordination may include the exchange of information in a unidirectional or bidirectional manner. For example, components may communicate information in the form of signals communicated through a communication medium. The information may be implemented as a signal assigned to various signal lines. In such an assignment, each message may be a signal. However, further embodiments may alternatively employ data messages. Such data messages may be transmitted across various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.
[0092] Some embodiments may be described using the expressions "an embodiment" or "some embodiments" along with their derivatives. These terms mean that the particular features, structures, or characteristics described in relation to the embodiments are included in at least one embodiment. Although the expression "in one embodiment" appears in various places in this specification, it does not necessarily refer to the same embodiment every time. Furthermore, unless otherwise noted, it is recognized that the foregoing features can be used in any combination with each other. Accordingly, features discussed separately can be employed in combination with each other unless it is noted that those features are not interchangeable with each other.
[0093] Generally referring to the notations and nomenclatures used in this specification, the detailed description of this specification may be presented from the perspective of functional blocks or units that can be implemented as program procedures executed on a computer or a computer network. The description and representation of these procedures are used by those skilled in the art to most effectively convey the content of the work.
[0094] A procedure is here and generally considered to be a sequence of self - consistent operations that produce a desired result. These operations require physical manipulation of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of performing operations such as storing, transmitting, combining, comparing, and others. It can be seen that mainly for reasons of common usage, it is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all of these terms and similar terms should be associated with appropriate physical quantities and are nothing more than convenient labels applied to those quantities.
[0095] Furthermore, the operations performed are often referred to in terms such as addition or comparison, which are generally associated with mental operations performed by a human operator. In almost any of the operations described herein that form part of one or more embodiments, in most cases, such capabilities of a human operator are not necessary or desirable. Rather, this operation is a mechanical operation. Useful machines for performing the operations of the various embodiments include general-purpose digital computers or similar devices.
[0096] Some embodiments may be described using the expressions "coupled" and "connected", along with their derivatives. These terms are not necessarily intended to be synonyms of each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements cooperate or interact with each other, even though they are not in direct contact with each other.
[0097] It should be emphasized that the gist of the present disclosure is provided so that the reader can quickly grasp the nature of the technical disclosure. It is submitted with the understanding that it is not used to interpret or limit the scope or meaning of the claims. Further, in the foregoing detailed description, various features are grouped together in a single embodiment for the purpose of streamlining the disclosure. This method of disclosure should not be construed as reflecting an intention to claim more features than are expressly recited in each claim for the claimed embodiment. Rather, as reflected in the following claims, the subject matter of the invention lies in less than all of the features of a single disclosed embodiment. Accordingly, the following claims are incorporated into the detailed description in a state where each claim stands on its own as an independent embodiment. In the appended claims, the terms "including" and "in which" are used as the plain English equivalents of the terms "comprising" and "wherein", respectively. Further, the terms "first", "second", "third", etc. are used merely as labels and are not intended to impose numerical requirements on their objects.
[0098] What has been described above includes examples of the disclosed configurations. Of course, it is not possible to describe all possible combinations of components and / or methodologies, but those skilled in the art will recognize that many further combinations and substitutions are possible. Accordingly, the novel configurations are intended to embrace all such changes, modifications, and variations that fall within the spirit and scope of the appended claims.
Claims
1. An input device, A non-contact interface, A processor, A memory coupled to the non-contact interface and the input device, A computing device comprising: The memory is configured to store instructions, When the instructions are executed by the processor, Receive, via the non-contact interface, an encryption key for executing a transaction from a non-contact card, Receive a personally identifiable number (PIN) entered via the input device, Be operable to: The encryption key is formed using a dynamic key of the non-contact card, The dynamic key is formed using a counter value held by the non-contact card, The encryption key includes the counter value and non-contact card data encrypted using the dynamic key, When the instructions are executed by the processor, further, Encrypt the encryption key and the PIN by the processor, Execute an authentication operation including authenticating the counter value, the non-contact card data, and the PIN using at least the encryption key, and generate an authentication response including an indication as to whether the transaction is authenticated or not, and transmit the encrypted encryption key and the PIN to a server configured to: Receive the authentication response from the server, Enable the transaction if the indication indicates that the transaction is authenticated, Block the transaction if the indication indicates that the transaction is not authenticated Be operable to: A computing device.
2. The computing device according to claim 1, wherein the instructions are further configured to cause the processor to initiate a near field communication (NFC) exchange with the non-contact card to request the encryption key.
3. The computing device according to claim 1, wherein the encryption key includes identification information for identifying a user associated with the non-contact card.
4. The computing device according to claim 1, wherein the instructions are further configured to cause the processor to encrypt the PIN, the encryption key, or both and transmit them to the server.
5. The computing device according to claim 4, wherein a symmetric encryption algorithm is used to encrypt the PIN, the encryption key, or both.
6. The computing device according to claim 1, wherein the non-contact interface includes a near field communication (NFC) interface. **Claim 7** The computing device according to claim 1, wherein the instruction is further configured to output a prompt for prompting the user to provide the PIN via the input device. **Claim 8** The computing device according to claim 1, wherein the computing device is a mobile device or a merchant transaction device. **Claim 9** A method implemented by a computer, comprising: receiving, via a non-contact interface, an encryption key for executing a transaction from a non-contact card; receiving, via an input device, a personal identification number (PIN) entered; wherein the encryption key is formed using a dynamic key of the non-contact card; wherein the dynamic key is formed using a counter value held by the non-contact card; wherein the encryption key includes the counter value and non-contact card data encrypted using the dynamic key; the method further comprising: encrypting, by a processor, the encryption key and the PIN; performing an authentication operation including authenticating the counter value, the non-contact card data, and the PIN using at least the encryption key, and generating an authentication response including an indication as to whether the transaction is authenticated or not, and transmitting, via a network interface, the encrypted encryption key and the PIN to a server configured to generate the authentication response; receiving, by the network interface, the authentication response from the server; enabling the transaction if the indication indicates that the transaction is authenticated; blocking the transaction if the indication indicates that the transaction is not authenticated; A method including the above steps. **Claim 10** The method according to claim 9, wherein a near field communication (NFC) exchange with the non-contact card is initiated to request the encryption key. **Claim 11** The method according to claim 9, wherein the encryption key includes identification information for identifying a user associated with the non-contact card. **Claim 12** The method according to claim 9, including encrypting the PIN, the encryption key, or both and transmitting them to the server. **Claim 13** The method according to claim 12, wherein a symmetric encryption algorithm is used to encrypt the PIN, the cipher, or both.
14. The method according to claim 9, wherein the non-contact interface includes a Near Field Communication (NFC) interface.
15. The method according to claim 9, further comprising the step of prompting the user to provide the PIN via the input device.
Citation Information
Patent Citations
Authentication system, authentication server, and wireless tag
JP2007249654A
Establishing secure sessions between card readers and mobile devices
JP2017524312A
Ticket issuing machine
JP2018147146A
Payment method by the linkage between payment terminal and multi-PIN pad device and the system
KR1020160019653A
Stand-alone secure pin entry device for enabling EMV card transactions with separate card reader
US20130144792A1