Secure authentication based on passport data stored on contactless cards
A contactless card system with encrypted passport data and server verification addresses vulnerabilities in traditional identity verification, enhancing security and integrity through key diversification and attribute-based decryption.
Patent Information
- Application Number
- JP2022537705
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2020-11-23
- Publication Date
- 2025-09-08
- Estimated Expiration
- 2040-11-23
AI Technical Summary
Traditional identity verification methods, such as one-time passcodes, are vulnerable to interception and require different authentication types across systems, making them impractical and insecure for modern computing systems.
A system utilizing a contactless card to store encrypted passport data, which generates encrypted customer and passport data for authentication, verified by a server using key diversification and decryption based on passport attributes, ensuring secure access to operations.
Enhances security by requiring verification of encrypted data, improving the integrity of devices and operations, and ensuring secure access to applications and data.
Smart Images

Figure 0007735274000001 
Figure 0007735274000002 
Figure 0007735274000003
Abstract
Description
[Technical Field]
[0001] Related Applications This application claims priority to U.S. Patent Application No. 16 / 725,547, entitled "Secure Authentication Based on Passport Data Stored on a Contactless Card," filed December 23, 2019, the contents of which are incorporated herein by reference in their entirety.
[0002] TECHNICAL FIELD Embodiments herein relate generally to computing platforms, and more particularly to using contactless cards that store passport data for secure authentication. [Background technology]
[0003] Identity verification is a critical task for modern computing systems. Traditional approaches may require users to provide additional information, such as a one-time passcode (OTP), when accessing a computing system or performing an electronic transaction. However, these solutions may have security vulnerabilities. For example, the OTP may be intercepted and used to gain unauthorized access. Furthermore, different systems may require different types of additional information for identity verification, making traditional solutions impractical for many users. Summary of the Invention
[0004]
[0003] Embodiments disclosed herein provide systems, methods, articles of manufacture, and computer-readable media for secure authentication based on identity data stored on a contactless card. In one example, an application may receive instructions specifying execution of an operation associated with an account. The application may receive encrypted data from a contactless card associated with the account, the encrypted data based on an encryption algorithm, a customer identifier, and a private key for the contactless card. The application may receive instructions from an authentication server indicating that the authentication server has verified the encrypted data based on the private key for the contactless card. The application may receive encrypted passport data from the contactless card, the encrypted passport data for a passport associated with the account. The application may determine attributes of the passport based at least in part on image data or text input. The application may decrypt the encrypted passport data based on the attributes of the passport. The application may initiate execution of the operation based on the received instructions specifying that the authentication server has verified the encrypted data and the decryption of the encrypted passport data. [Brief explanation of the drawings]
[0005] [Figure 1A] 1 illustrates an embodiment of a system for secure authentication based on passport data stored on a contactless card. [Figure 1B] 1 illustrates an embodiment of a system for secure authentication based on passport data stored on a contactless card. [Figure 2A] 1 illustrates an embodiment of a system for secure authentication based on passport data stored on a contactless card. [Figure 2B] 1 illustrates an embodiment of a system for secure authentication based on passport data stored on a contactless card. [Figure 3A] 1 illustrates an embodiment in which a contactless card is tapped against a computing device to provide secure authentication based on passport data stored on the contactless card. [Figure 3B] 1 illustrates an embodiment in which a contactless card is tapped against a computing device to provide secure authentication based on passport data stored on the contactless card. [Figure 4A] An example of a contactless card is shown. [Figure 4B] An example of a contactless card is shown. [Figure 5] 1 illustrates a first logic flow embodiment. [Figure 6] 10 illustrates a second logic flow embodiment. [Figure 7] 10 illustrates a third logic flow embodiment. [Figure 8] 1 illustrates an embodiment of a computing system. DETAILED DESCRIPTION OF THE INVENTION
[0006] Embodiments disclosed herein provide techniques for secure authentication using passport data stored on a contactless card. Generally, a contactless card may store multiple different types of information for a user, such as payment information, passport information, and / or any other biographical information. The user may then attempt to perform an operation, such as making a purchase, transferring funds via an application running on a mobile device, or requesting a credit increase via an application. The application may determine the type of authentication data required to approve the requested operation. For example, a rule may specify that transferring funds via an application requires authentication based on passport data stored on the contactless card. Thus, the application may determine the passport data as the type of authentication data.
[0007] The user may then tap the contactless card to the mobile device to initiate the secure authentication process. Upon tapping the contactless card, encrypted data may be generated and sent to the application. The encrypted data may be generated based on an encryption algorithm, a customer identifier, and the contactless card's encryption key. The application may then send the encrypted data to an authentication server for authentication. The server may then decrypt the encrypted data using a local copy of the contactless card's encryption key and generate a customer identifier to authenticate the encrypted data. The server may then send an instruction to authenticate the encrypted data to the application.
[0008] The application may then attempt to decrypt the passport data. In some embodiments, the passport data is transmitted to the application by the contactless card using the encrypted customer identifier. In other embodiments, the passport data is transmitted separately by the contactless card to the mobile device following another tap of the contactless card. To decrypt the passport data, the application may receive one or more attributes of the passport. For example, an image depicting one or more pages of the passport may be captured, and attributes may be extracted from the captured image. As another example, a user may provide the attributes as input. The application may then authorize the performance of an operation based on the received instruction specifying that the authentication server has verified the decryption of the encrypted data and passport data. For example, a user may be authorized to access an interface of the application to transfer funds from one account to another.
[0009] Advantageously, the embodiments disclosed herein improve the security of all devices and associated data. For example, by requiring verification of encrypted data generated by a contactless card to access applications and / or data, the security of the applications and / or data is improved. As another example, by requiring verification of encrypted passport data before performing an operation (e.g., making a purchase, extending credit, etc.), the security of such operation and associated assets is improved.
[0010] With general reference to the notation and nomenclature used herein, one or more portions of the detailed descriptions which follow may be presented in terms of program procedures executed on a computer or network of computers. These procedural descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art. A procedure is herein, and generally, conceived to be a self-consistent sequence of operations leading to a desired result. These operations are operations requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be noted, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.
[0011] Further, these operations are often referred to in terms, such as adding or comparing, that are commonly associated with mental operations performed by a human operator. However, no such capability of a human operator is necessary, or desirable in most cases, for any of the operations described herein that form part of one or more embodiments. Rather, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers selectively activated or configured by a computer program stored therein and written in accordance with the teachings herein, and / or include specially constructed apparatus or digital computers for the required purposes. Various embodiments also relate to apparatus or systems for performing these operations. These apparatus may be specially constructed for the required purposes. The required structure for these various machines will be apparent from the description given.
[0012] Reference is now made to the drawings. Like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding thereof. However, it may be apparent that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate description thereof. The intention is to cover all modifications, equivalents, and alternatives within the scope of the claims.
[0013] FIG. 1A illustrates a schematic diagram of an exemplary system 100 consistent with disclosed embodiments. As shown, the system 100 includes one or more contactless cards 101, one or more mobile computing devices 110, and an authentication server 120. The contactless cards 101 represent any type of payment card, such as a credit card, a debit card, an ATM card, or a gift card. The contactless cards 101 may include one or more communication interfaces 133, such as a radio frequency identification (RFID) chip, configured to communicate with the computing devices 110 via NFC, EMV standards, or other short-range protocols for wireless communication. While NFC is used as an example communication protocol, the present disclosure is equally applicable to other types of wireless communication, such as EMV standards, Bluetooth, and / or Wi-Fi. The mobile devices 110 represent any type of network-enabled computing device, such as a smartphone, a tablet computer, a wearable device, a laptop, a portable gaming device, or the like. The authentication server 120 represents any type of computing device, such as a server, a workstation, a computing cluster, a cloud computing platform, a virtualized computing system, or the like.
[0014] As shown, contactless card memory 102 includes applet 103, counter 104, master key 105, diversified key 106, unique customer identifier (ID) 107, and passport data 108. Applet 103 is executable code configured to perform the operations described herein. Counter 104, master key 105, diversified key 106, and customer ID 107 are used to provide security for system 100, as described in more detail below. Passport data 108 is representative of a user's electronic passport associated with contactless card 101. Passport data 108 may include any number and type of data. For example, passport data 108 may include text data describing different attributes of the passport and / or the user (e.g., name, date of birth, passport number, passport issue date, passport expiration date, issuing country, etc.), as well as image data (e.g., one or more images of the passport itself, an image of the user contained in the passport, etc.). In some embodiments, passport data 108 is encrypted. For example, the passport data 108 may be encrypted based on one or more attributes of the passport, which may include the passport number, the passport issue date, and / or the passport expiration date.
[0015] As shown, memory 111 of mobile device 110 includes an instance of operating system (OS) 112. Examples of operating systems 112 include Android® OS, iOS®, macOS®, Linux®, and Windows® operating systems. As shown, OS 112 includes account application 113. Account application 113 allows a user to perform various account-related operations such as viewing account balances, purchasing items, processing payments, etc. The account application 113 may further control access permissions to different features provided by the account application 113 and / or other applications 114. Generally, a user may authenticate using authentication credentials to access certain features of the account application 113. For example, authentication credentials may include a username (or login) and password, biometric credentials (e.g., fingerprint, Face ID, etc.), etc.
[0016] According to various embodiments, a user may request and / or attempt to perform an operation. The operation may include any type of operation, such as making a purchase using the contactless card 101, accessing a particular feature of the account application 113, using the account application 113 to perform various account-related operations, and / or accessing other applications 114 (or any features thereof). The other applications 114 are representative of any type of computing application, such as a web browser, a messaging application, a word processing application, a social media application, etc. For example, a user may wish to transfer funds from their account to another account using the account application 113. The use of particular operations as reference examples herein does not limit the disclosure, as the disclosure is equally applicable to any other type of operation.
[0017] To approve a requested operation (e.g., prior to transferring funds), the system 100 must authenticate and / or verify the user's identity. To authenticate the user's identity, embodiments disclosed herein may utilize the contactless card 101. More specifically, when the user requests to perform an operation (or access a restricted resource), the account application 113 may output a notification instructing the user to tap the contactless card 101 against the device 110. Generally, when the contactless card 101 comes within communication range of the communication interface 118 of the device 110, the applet 103 of the contactless card 101 may generate encrypted data, such as an encrypted customer ID 132, as part of the authentication process required to approve the requested operation. To enable NFC data transfer between the contactless card 101 and the mobile device 110, the account application 113 may communicate with the contactless card 101 when the contactless card 101 is sufficiently close to the communication interface 118 of the mobile device 110. The communication interface 118 may be configured to read from and / or communicate with the communication interface 133 of the contactless card 101 (e.g., via NFC, Bluetooth, RFID, etc.). Thus, exemplary communication interfaces 118 include an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.
[0018] As mentioned, the system 100 is configured to implement key diversification to protect data, which may be referred to herein as key diversification technology. Generally, the server 120 (or other computing device) and the contactless card 101 may be provisioned with the same master key 105 (also referred to as a master symmetric key). More specifically, each contactless card 101 is programmed with a separate master key 105 that has a corresponding pair within the server 120. For example, when the contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of the contactless card 101. Similarly, the unique master key 105 may be stored in the customer record associated with the contactless card 101 within the account data 124 of the server 120 (and / or may be stored in a different secure location, such as a hardware security module (HSM) 125). The master key may be kept secret from all parties other than the contactless card 101 and the server 120, thereby enhancing the security of the system 100. In some embodiments, applet 103 of contactless card 101 may encrypt and / or decrypt data (e.g., customer ID 107, and / or passport data 108) using an encryption algorithm with master key 105 and the data as input. For example, encrypting customer ID 107 with master key 105 may generate encrypted customer ID 132. Similarly, authentication server 120 may encrypt and / or decrypt data associated with contactless card 101 using the corresponding master key 105.
[0019] In other embodiments, the master key 105 of the contactless card 101 and the server 120 may be used in combination with the counter 104 to enhance security using key diversification. The counter 104 comprises a value that is synchronized between the contactless card 101 and the server 120. The counter value 104 may comprise a number that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or the contactless card 101 and the mobile device 110). When preparing to send data (e.g., to the server 120 and / or the mobile device 110), the contactless card 101 may increment the counter value 104. The contactless card 101 may then provide the master key 105 and the counter value 104 as inputs to an encryption algorithm, which generates the diversified key 106 as an output. The encryption algorithm may include an encryption algorithm, a hash-based message authentication code (HMAC) algorithm, a cipher-based message authentication code (CMAC) algorithm, etc. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. Examples of key diversification techniques are described in detail in U.S. Patent Application No. 16 / 205,119, filed November 29, 2018. The aforementioned patent application is incorporated herein by reference in its entirety.
[0020] Continuing with the key diversification example, the contactless card 101 may then encrypt data (e.g., customer ID 107 and / or any other data, such as passport data 108) using the diversified key 106 and the data as inputs to an encryption algorithm. For example, encrypting customer ID 107 with diversified key 106 may result in encrypted customer ID 132.
[0021] Regardless of the encryption technique used, contactless card 101 may then transmit the encrypted data (e.g., encrypted customer ID 132) to account application 113 of mobile device 110 (e.g., via an NFC connection, a Bluetooth connection, etc.). Account application 113 of mobile device 110 may then transmit the encrypted customer ID 132 to server 120 over network 130. In at least one embodiment, contactless card 101 transmits counter value 104 along with the encrypted data. In such an embodiment, contactless card 101 may transmit encrypted counter value 104 or unencrypted counter value 104.
[0022] Upon receipt, the authentication application 123 may authenticate the encrypted customer ID 132. For example, the authentication application 123 may attempt to decrypt the encrypted customer ID 132 using a copy of the master key 105 stored in the memory 122 of the authentication server 120. In another example, the authentication application 123 may provide the master key 105 and the counter value 104 as inputs to an encryption algorithm, which produces the diversified key 106 as output. The resulting diversified key 106 may correspond to the diversified key 106 of the contactless card 101, which can be used to decrypt the encrypted customer ID 132.
[0023] Regardless of the decryption technique used, the authentication application 123 may successfully decrypt the encrypted customer ID 132, thereby verifying the encrypted customer ID 132 (e.g., by comparing the resulting customer ID 107 to the customer ID stored in the account data 124 and / or based on an indication that decryption using the keys 105 and / or 106 was successful). While the keys 105, 106 are shown as stored in the memory 122, the keys 105, 106 may be stored elsewhere, such as in the secure element and / or HSM 125. In such an embodiment, the secure element and / or HSM 125 may use the keys 105 and / or 106 and the encryption function to decrypt the encrypted customer ID 132. Similarly, the secure element and / or HSM 125 may generate the diversified key 106 based on the master key 105 and the counter value 104, as described above.
[0024] However, if the authentication application 123 is unable to decrypt the encrypted customer ID 132 with the expected result (e.g., the customer ID 107 of the account associated with the contactless card 101), the authentication application 123 does not verify the encrypted customer ID 132. In such an instance, the authentication application 123 sends an indication of the failed verification to the account application 113. Thus, the account application 113 may refuse to perform the requested operation in order to maintain account security.
[0025] 1B illustrates one embodiment in which authentication application 123 decrypts encrypted customer ID 132, thereby verifying (or authenticating) the encrypted data. As shown, authentication application 123 sends verification 134 to mobile device 110, which indicates that authentication application 123 successfully decrypted encrypted customer ID 132. In response to receiving verification 134, account application 113 may refer to rules 115 to determine what, if any, additional authentication steps are required. Rules 115 may generally specify multiple different authentication rules and / or thresholds for different requested operations. Rules may be based on the type of operation requested. For example, for a funds transfer, rules 115 may require additional authentication based on additional data elements, such as passport data 108.
[0026] In such an example, the account application 113 may output an indication specifying that the user tap the contactless card 101 to the mobile device 110. The account application 113 may then instruct the contactless card 101 to transmit the passport data 108. In response, the contactless card 101 may transmit the passport data 108 to the account application 113. As mentioned, in some embodiments, the passport data 108 may be encrypted. The passport data 108 may be encrypted using one or more attributes of the user's passport, such as the passport number of the user's passport, the issuance date of the user's passport, and / or the expiration date of the user's passport. Although shown as being received with separate taps of the contactless card 101, in some embodiments, the passport data 108 is transmitted along with the encrypted user ID 132 with a single tap of the contactless card 101 to the mobile device 110, such as the tap shown in FIG. 1A.
[0027] The account application 113 may then receive the passport attributes for decrypting the encrypted passport data 108. For example, a user may provide the passport number, expiration date, and / or issue date via a graphical user interface (GUI) of the account application 113. In other embodiments, the camera 119 of the mobile device 110 may be used to capture one or more images of one or more pages of a physical version of the passport. The one or more pages may depict the attributes necessary to decrypt the encrypted passport data 108. Thus, the account application 113 may extract the passport number, expiration date, and / or issue date from the captured image by, for example, using computer vision, optical character recognition (OCR), etc.
[0028] 1B , the account application 113 uses the received passport attributes to decrypt the encrypted passport data 108. If the decryption is successful, the account application 113 may allow the requested operation to be performed. For example, upon decrypting the passport data 108, the account application 113 may display a GUI that allows the user to initiate the desired funds transfer. Otherwise, the account application 113 may restrict the execution of the requested operation by, for example, blocking access to the GUI for the funds transfer, outputting a notification that the requested operation cannot be performed based on the failed decryption, etc.
[0029] In some embodiments, the authentication server 120 decrypts the encrypted passport data 108. For example, FIG. 2A is a schematic diagram 200 illustrating an embodiment in which the authentication server 120 is used to decrypt the passport data 108. As shown, the user taps the contactless card 101 to the mobile device 110 to proceed with the requested operation. As previously described, the user may provide authentication credentials to access an account associated with the contactless card 101 before tapping the contactless card 101 to the device 110. For example, the requested operation may be to update account information in the account application 113 after providing authentication credentials to access the account details. In response to the tap, the applet 103 generates an encrypted customer ID 201, which is sent to the account application 113 along with the encrypted passport data 108. Generally, the encrypted customer ID 201 is generated by the applet 103 as described above with respect to generating the encrypted customer ID 132 (e.g., by encrypting the customer ID 107 with the master key 105 and / or the diversified key 106).
[0030] In response to receiving the encrypted customer ID 201 and the encrypted passport data 108, the account application 113 may receive the passport attributes (e.g., passport number, expiration date, and / or issue date) necessary to decrypt the encrypted passport data 108. For example, a user may provide the passport attributes as input to a GUI of the account application 113. As another example, an image of a physical passport may be captured, and the account application 113 may extract the passport attributes from the captured image, for example, by identifying relevant fields and values in the image. Once received, the account application 113 may send the received passport attributes to the authentication server 120 as passport attributes 202 with the encrypted customer ID 201 and passport data 108.
[0031] Once received, the authentication application 123 may attempt to decrypt the encrypted customer ID 201 using the master key 105 and / or the diversified key 106, as described above. If the attempted decryption results in a customer ID 107 associated with the account, the authentication application 123 may attempt to decrypt the passport data 108 using the passport attributes 202. As reflected in FIG. 2B , if the decryption of the encrypted customer ID 201 and passport data 108 is successful, the authentication application 123 may send a verification 204 to the account application 113. The account application 113 may then authorize the requested operation based on receiving the verification 204 specifying that the encrypted customer ID 201 and encrypted passport data 108 have been verified (or authenticated) by the authentication server 120. For example, the account application 113 may expose and / or enable a GUI that allows a user to change their account details. If either decryption attempt (of the encrypted customer ID 201 and encrypted passport data 108) is unsuccessful, the authentication application 123 may send a failed decryption indication to the account application 113, which may refuse to perform the requested operation. For example, the account application 113 may limit access to (and / or disable elements of) the GUI that allows a user to change their account details.
[0032] In some embodiments, passport data 108 encrypted using passport attributes may be further encrypted by applet 103 based on master key 104 and / or diversified key 106. Thus, in such embodiments, authentication application 123 may first decrypt passport data 108 using keys 105 and / or 106 as described above. If the initial decryption is successful, authentication application 123 may attempt to decrypt passport data 108 using passport attributes 202. If the decryption of passport data 108 using passport attributes 202 is successful, authentication application 123 may send verification 204 to account application 113, which may approve the requested operation.
[0033] Regardless of the entity that decrypts the passport data 108, in at least one embodiment, the applet 103 of the contactless card 101 may generate a digital signature (not shown) of the passport data 108 using keys 105 and / or 106. The digital signature may sign the passport data 108. The contactless card 101 may then send the digital signature with the passport data 108 to the account application 113, which transmits the digital signature to the authentication server 120. The authentication application 123 may also verify the digital signature by decrypting it using a public key associated with the contactless card 101 and stored by the server 120. If the digital signature is verified, the authentication application 123 may send an indication of successful digital signature verification to the account application 113, which may allow the execution of an operation based on the verification of the digital signature. If the digital signature is not verified, the account application 113 may restrict the execution of the operation.
[0034] Regardless of the entity that decrypts passport data 108, in some embodiments, account application 113 may determine the level of access permissions specified by rules 115 required to perform the operation. For example, rules 115 may require a user to have a “high” security level to perform a requested operation (e.g., transferring funds). However, the user's account data 124 (which may be stored locally on account application 113 and / or received from server 120) may specify that the user has a “medium” level of security. In such embodiments, account application 113 may send a request for an updated permission level to server 120. In response, authentication application 123 may determine to update the user's permission level to “high” based on the decryption of encrypted customer ID 201 and passport data 108. In such embodiments, authentication application 123 may send the updated permission level to account application 113, which authorizes the requested operation based on the updated permission level that meets the permission level required by rules 115.
[0035] Additionally, in some embodiments, the user may obtain a new and / or updated passport. In such embodiments, the account application 113 may receive new and / or updated versions of the passport data 108, for example, from the authentication server 120. In such embodiments, the account application 113 may transmit the updated passport data received from the server 120 to the contactless card 101, and the applet 103 may store the received data in the memory 102.
[0036] FIG. 3A is a schematic diagram 300 illustrating an example embodiment of tapping a contactless card 101 to provide secure authentication based on passport data 108 stored on the contactless card 101. As shown, an account application 113 may receive a request to perform an operation. For example, the request may be to transfer funds from one account to another. The account application 113 may refer to rules 115 to determine what type of data is required to approve the requested transfer of funds. For example, rules 115 may specify that the transfer of funds requires verification of an encrypted customer ID and verification based on passport data 108. In at least one embodiment, the type of data specified by rules 115 is based on the type of operation requested (e.g., transfer of funds). In general, rules 115 may specify different levels of security for different types of transactions (e.g., requiring verification of passport data 108 for high-risk operations and not requiring verification of passport data 108 for low-risk operations).
[0037] In response, account application 113 may output instructions for tapping contactless card 101 to device 110. When the user taps contactless card 101 to mobile device 110, applet 103 on contactless card 101 encrypts customer ID 107 (e.g., to generate encrypted customer ID 132 and / or 201). Applet 103 may then transmit encrypted customer ID 107 and encrypted passport data 108 to mobile device 110, for example, via NFC.
[0038] 3B, account application 113 may output instructions specifying that the user take a photograph of one or more pages of a physical passport using camera 119. The user may then capture an image of the passport. Account application 113 may then process the captured image to extract one or more attributes of the passport, such as the passport number, issue date, and expiration date.
[0039] As noted, in some embodiments, account application 113 may use the attributes extracted from the image to decrypt encrypted passport data 108. In other embodiments, such as the embodiment of Figures 3A-3B, authentication application 123 may use the attributes extracted by account application 113 to decrypt encrypted passport data 108. Thus, account application 113 may send encrypted customer ID 107, encrypted passport data 108, and the extracted attributes of the passport to authentication application 123.
[0040] The authentication application 123 may then attempt to decrypt the encrypted customer ID 107 (and / or the encrypted passport data 108) using the master key 105 and / or the diversified key 106 associated with the contactless card 101. If the authentication application 123 is unable to decrypt the encrypted customer ID 107 to produce the expected result (e.g., the customer ID 107 for the account), the authentication application 123 does not verify the encrypted customer ID 107. If the authentication application 123 successfully decrypts the encrypted customer ID 107 to produce the expected result (e.g., the customer ID 107 for the account), the authentication application 123 verifies the encrypted customer ID 107 and attempts to decrypt the passport data 108 using the attributes received from the account application 113. If the authentication application 123 successfully decrypts the passport data 108, the account application 123 sends instructions to the account application 113 to verify the encrypted customer ID 107 and the encrypted passport data 108. The account application 113 may then, in response to receiving the verification, authorize the performance of the requested operation.
[0041] However, if the authentication application 123 is unable to decrypt the encrypted customer ID 107 and / or the encrypted passport data 108, the authentication application 123 sends a failed decryption indication to the account application 113. The account application 113 may then restrict the performance of the requested operation, for example, by disabling the "Next" button shown in FIG. 3B.
[0042] As noted, in some embodiments, rules 115 specify the permission level required to perform the associated operation. For example, to update account details, rules 115 may require a permission level of 2.0 or greater on a scale of 0.0 to 10.0. Accordingly, in such embodiments, account application 113 may send the user's current permission level to authentication application 123. The current permission level may be stored locally by account application 113 (e.g., in an instance of account data 124 stored in memory 111 of mobile device 110) and / or received from authentication application 123 (e.g., when the user logs in to account application 113 using authentication credentials).
[0043] In such an example, the user's current permission level may be 1.5. Accordingly, the account application 113 may send an indication to the authentication application 123 specifying that the user's current permission level does not meet the required permission level. The authentication application 123 may then determine whether to increase the user's permission level. For example, based on the authentication application 123 successfully decrypting the encrypted customer ID 107 and the encrypted passport data 108, the authentication application 123 may increase the user's permission level to 3.0. The authentication application 123 may send an indication of the new permission level to the account application 113, along with the verification. The account application 113 may then, in response to receiving the verification from the authentication server 123, authorize the performance of the requested operation based on the updated permission level, which exceeds the permission level specified in the rules 115.
[0044] FIG. 4A illustrates a contactless card 101, which may comprise a payment card such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 405, which displays the card's name on the front or back. In some examples, the contactless card 101 may comprise, but is not limited to, an identification card unrelated to a payment card. In some examples, the payment card may comprise a dual-interface contactless payment card. The contactless card 101 may comprise a substrate 410, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 101 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard; otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, it should be understood that contactless cards 101 according to the present disclosure may have different characteristics and the present disclosure does not require contactless cards to be implemented as payment cards.
[0045] The contactless card 101 may also include identification information 415 displayed on the front and / or back of the card, and a contact pad 420. The contact pad 420 may be configured to establish contact with other communication devices, such as the mobile device 40, a user device, a smartphone, a laptop, a desktop, or a tablet computer. The contactless card 101 may also include processing circuitry, an antenna, and other components not shown in FIG. 4A . These components may be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 may also include a magnetic strip or tape (not shown in FIG. 4A ) that may be located on the back of the card.
[0046] 4B, contact pad 420 of contactless card 101 may include processing circuitry 425 for storing and processing information, including microprocessor 430 and memory 102. It will be understood that processing circuitry 425 may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, as needed to perform the functions described herein.
[0047] The memory 102 may be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 101 may include one or more of these memories. Read-only memory may be read-only or one-time programmable at the factory. One-time programming allows it to be written once and read many times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritten, but it may be read many times. Read / write memory may be programmed and reprogrammed many times after leaving the factory. Read / write memory may be read many times after leaving the factory.
[0048] Memory 102 may be configured to store one or more applets 103, counter 104, master key 105, diversified key 106, one or more customer (or user) IDs 107, and passport data 108. One or more applets 103 may comprise one or more software applications configured to run on one or more contactless cards, such as a Java Card applet. However, it is understood that applet 103 is not limited to a Java Card applet and may instead be any software application capable of operating on a contactless card or other device with limited memory. Customer ID 107 may comprise a unique alphanumeric identifier assigned to a user of contactless card 101, which may distinguish a contactless card user from other contactless card users. In some examples, customer ID 107 may identify both the customer and the account assigned to that customer, and further identify the contactless card associated with the customer's account. In some embodiments, applet 103 may encrypt customer ID 107 using customer ID 107 as input to an encryption algorithm with keys 105 and / or 106. Similarly, applet 103 may use passport data 108 (which may be unencrypted and / or encrypted based on one or more attributes of passport 108) as input to an encryption algorithm with keys 105 and / or 106 to encrypt passport data 108.
[0049] Although the processor and memory elements of the foregoing exemplary embodiments are described with reference to contact pads, the present disclosure is not limited thereto, and it will be understood that these elements may be implemented external to, or completely separate from, the pads 420, or as additional elements in addition to the processor 430 and memory 102 elements located within the contact pads 420.
[0050] In some examples, the contactless card 101 may include one or more antennas 455. The one or more antennas 455 may be disposed within the contactless card 101 and around the processing circuit 425 of the contact pad 420. For example, the one or more antennas 455 may be integrated with the processing circuit 425, or the one or more antennas 455 may be used with an external booster coil. As another example, the one or more antennas 455 may be external to the contact pad 420 and the processing circuit 425.
[0051] In one embodiment, the coil of the contactless card 101 may function as the secondary of an air-core transformer. The terminal may communicate with the contactless card 101 by disconnecting power or amplitude modulation. The contactless card 101 may infer data transmitted from the terminal using gaps in the contactless card's power connection, which may be maintained functionally through one or more capacitors. The contactless card 101 may return communication by switching the load on the contactless card's coil or load modulation. Load modulation may be detected in the terminal's coil through interference. More generally, using the antenna 455, processing circuitry 425, and / or memory 102, the contactless card 101 provides a communication interface for communicating via NFC, Bluetooth, and / or Wi-Fi communications.
[0052] As described above, contactless card 101 may be built on a software platform capable of running on a smart card or other device with limited memory, such as a Java card, and one or more applications or applets may be securely executed. The applet may be added to the contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a near-field data exchange request, from a reader, such as a mobile NFC reader (e.g., communication interface 118 of device 110), and generate an NDEF message comprising the cryptographically secure OTP encoded as an NDEF text tag.
[0053] The operation of the disclosed embodiments may be further explained with reference to the following figures. Some figures may include logic flows. While such figures presented herein may include specific logic flows, it may be understood that the logic flows merely provide examples of how the general functions as described herein may be implemented. Furthermore, a given logic flow does not necessarily have to be executed in the order presented, unless otherwise specified. Furthermore, a given logic flow may be implemented by a hardware element, a software element executed by a processor, or any combination thereof. In this context, the embodiments are not limited.
[0054] 5 illustrates an embodiment of a logic flow 500. The logic flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 500 may include some or all of the operations for using the contactless card 101 to provide secure authentication based on passport data stored on the contactless card 101. In this context, the embodiments are not limited.
[0055] As shown, the logic flow 500 begins at block 505, where the account application 113 receives a request to perform an operation. As mentioned, the requested operation may be received based on input from a user of the account application 113, an external source (e.g., one of the other applications 114), or any other source. The request may relate to, for example, but not limited to, use of the account application 113, use of the other applications 114, an operation related to an account associated with the contactless card 101, and / or a transaction. More generally, the request may be received after a user provides authentication credentials necessary to access an account with the account application 113. At block 510, the user taps the contactless card 101 against the mobile device 110, causing the applet 103 of the contactless card 101 to encrypt the customer ID 107 and transmit the encrypted customer ID to the mobile device 110.
[0056] At block 515, account application 113 may receive the encrypted customer ID from contactless card 101. Account application 113 may then send the encrypted customer ID received from contactless card 101 to authentication server 120. Server 120 may attempt to decrypt the encrypted customer ID as described herein. At block 520, account application 113 receives an indication from server 120 that the encrypted customer ID has been verified by decrypting encrypted customer ID 132.
[0057] At block 525, the account application 113 determines the type of request, which may be used to determine the type of verification data specified in the rules 115 that is required to authorize the type of operation. For example, passport data 108 may be specified as the verification data required by the rules 115. At block 530, the user taps the contactless card 101 against the mobile device 110. Doing so instructs the applet 103 of the contactless card 101 to transmit the passport data 108 to the mobile device 110. The account application 113 may then receive the passport data 108 from the contactless card 101. However, as mentioned, in some embodiments, the passport data 108 may be received at block 515 in response to the tap at block 510.
[0058] At block 535, the account application 113 may receive the passport attributes. For example, a user may provide the passport attributes as input to the account application 113. As another example, the account application 113 may prompt the user to capture an image of a passport page that includes the passport attributes. The account application 113 may then extract the attributes from the captured image, for example, by identifying a value associated with each passport attribute in the captured image. At block 540, the account application 113 may successfully decrypt the passport data 108 using the attributes received at block 535. However, as noted, in some embodiments, the account application 113 sends the passport data 108 and the extracted attributes to the authentication application 123 for decryption. In such embodiments, the account application 113 may send the passport data 108 and the extracted attributes along with the encrypted customer ID generated by the contactless card 101. The authentication application 123 may then attempt to decrypt the customer ID and passport data 108 and notify the account application 113 of the success or failure of the decryption attempt.
[0059] At block 545, the account application 113 authorizes performance of the requested operation based on verification of the encrypted customer ID by the server 120 and decryption of the encrypted passport data 108. At block 550, the requested operation may be performed by the user and / or by the account application 113, for example.
[0060] 6 illustrates an embodiment of a logic flow 600. The logic flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 600 may include some or all of the operations for receiving passport attributes to decrypt passport data 108 stored on the contactless card 101. In this context, the embodiments are not limited.
[0061] As shown, the logic flow 600 begins at block 610, where the account application 113 receives optional text-based input from a user specifying passport attributes. As previously described, passport attributes may include a passport number, a passport issue date, and a passport expiration date. However, other data, such as a person's name or other information, may be used to encrypt / decrypt the passport data 108. More generally, the account application 113 may recognize the required attributes and / or attribute types. At block 620, the account application 113 outputs instructions to the user to capture an image depicting a page of a physical passport corresponding to the passport data 108. At block 630, the account application 113 receives the image captured by the camera 119 of the mobile device 110.
[0062] At block 640, the account application 113 extracts attributes from the captured image. For example, the account application 113 may apply one or more image processing algorithms to extract the attributes. Generally, by being programmed to identify required passport attributes, the account application 113 may process the image to identify the required attributes and extract values associated with each attribute. For example, by recognizing text in the image, the account application 113 may identify "passport number" or variations thereof in the text of the image. The account application 113 may then extract values (e.g., numeric and / or alphanumeric values) associated with the identified phrase. For example, the account application 113 may be programmed with information describing the layout of a passport. Thus, the account application 113 may determine where in the image to extract the associated attribute names and where in the image to extract the associated values.
[0063] 7 illustrates an embodiment of a logic flow 700. The logic flow 700 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logic flow 700 may include some or all of the operations for authorizing a requested operation using passport data 108 stored on the contactless card 101. In this context, the embodiments are not limited.
[0064] As shown, logic flow 700 begins at block 705, where account application 113 receives authentication credentials associated with an account. At block 710, account application 113 determines a current permission level for the account (and / or a user associated with the account). At block 720, account application 113 determines that rules 115 specify a permission level that exceeds the user's current permission level. The permission level specified by rules 115 may be for an operation requested to be performed by the user (e.g., the operation requested at block 505 of logic flow 500).
[0065] At block 730, account application 113 sends an indication to authentication application 123 specifying that account application 113 has decrypted passport data 108 (e.g., at block 540 of logic flow 500). At block 740, authentication application 123 updates the user's permission level. Authentication application 123 may update the permission level based on the indication specifying that passport data 108 has been decrypted and determining that authentication application 123 has verified the encrypted data generated by contactless card 101. For example, authentication application 123 may set a timer in response to verifying encrypted customer ID 107 at block 520 of logic flow 500. If authentication application 123 receives the indication at block 730 before the timer exceeds a time threshold, authentication application 123 may determine to update the permission level and send the updated permission level to account application 113.
[0066] At block 750, account application 113 receives an updated permission level from server 120. At block 760, account application 113 determines that the updated permission level received at block 750 meets or exceeds the permission level specified for the operation by rule 115. In response, account application 113 may authorize performance of the operation.
[0067] FIG. 8 illustrates an embodiment of an exemplary computing architecture 800 comprising a computing system 802 that may be suitable for implementing various embodiments as described above. In various embodiments, computing architecture 800 may comprise or be implemented as part of an electronic device. In some embodiments, computing architecture 800 may represent, for example, a system implementing one or more components of system 100. In some embodiments, computing system 802 may represent, for example, contactless card 101, mobile device 110, and authentication server 120 of system 100. In this context, the embodiments are not limited. More generally, computing architecture 800 is configured to implement all logic, applications, systems, methods, apparatus, and functions described herein with reference to FIGS. 1-7.
[0068] The terms “system,” “component,” and “module,” as used in this application, are intended to refer to any computer-related entity: hardware, a combination of hardware and software, software, or software in execution, an example of which is provided by exemplary computing architecture 800. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer. By way of example, both an application running on a server and the server may be a component. One or more components may reside within a process and / or thread of execution, and components may be localized on one computer and / or distributed among two or more computers. Furthermore, components may be communicatively coupled to each other and coordinate operations by various types of communication media. Coordination may include unidirectional or bidirectional exchange of information. For example, components may communicate information in the form of signals communicated over the communication media. Information may be embodied as signals assigned to various signal lines. In such assignments, each message is a signal. However, further embodiments may alternatively use data messages. Such data messages may be transmitted over a variety of connections, examples of which include parallel interfaces, serial interfaces, and bus interfaces.
[0069] Computing system 802 includes various typical computing elements, such as one or more processors, multi-core processors, co-processors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, etc. However, embodiments are not limited to implementation by computing system 802.
[0070] 8, computing system 802 includes a processor 804, a system memory 806, and a system bus 808. Processor 804 may be any of a variety of commercially available computer processors, including, but not limited to, AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2) Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multi-processor architectures may also be used as processor 804.
[0071] The system bus 808 provides an interface from the system memory 806 to system components including, but not limited to, the processor 804. The system bus 808 may be any of several types of bus structures that may further interconnect to a memory bus (with or without a memory controller), a peripheral bus, and a local bus using any of a variety of commercially available bus architectures. Interface adapters may connect to the system bus 808 through a slot architecture. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, (Extended) Industry Standard Architecture ((E)ISA), MicroChannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Expansion) (PCI(X)), PCI Express, Personal Computer Memory Card International Association (PCMCIA), etc.
[0072] The system memory 806 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random-access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon-oxide-nitride-oxide-silicon (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drives (SSDs)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in FIG. 8, the system memory 806 may include non-volatile memory 810 and / or volatile memory 812. The non-volatile memory 810 may store a basic input / output system (BIOS).
[0073] Computing system 802 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 814, a magnetic floppy disk drive (FDD) 816 that reads from or writes to a removable magnetic disk 818, and an optical disk drive 820 that reads from or writes to a removable optical disk 822 (e.g., a CD-ROM or DVD). HDD 814, FDD 816, and optical disk drive 820 may be connected to system bus 808 by an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. HDD interface 824 for external drive implementations may include at least one or both of Universal Serial Bus (USB) and IEEE 1394 interface technologies. Computing system 802 is generally configured to implement all of the logic, systems, methods, devices, and functions described herein with reference to FIGS. 1-7.
[0074] The drives and associated computer-readable media provide volatile and / or nonvolatile storage of data, data structures, computer-readable instructions, computer-executable instructions, etc. For example, a number of program modules may be stored on the drives and memory units 810, 812, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836. In one embodiment, the one or more application programs 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as applets 103, counters 104, master keys 105, diversified keys 106, customer IDs 107, passport data 108, encrypted customer IDs 132, operating system 112, account applications 113, other applications 114, authentication applications 123, account data 124, encrypted customer IDs 201, and / or passport attributes 202.
[0075] A user may enter commands and information into the computing system 802 through one or more wired / wireless input devices, for example, a keyboard 838 and a pointing device such as a mouse 840. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, game pad, stylus pen, card reader, dongle, fingerprint reader, glove, graphics tablet, joystick, keyboard, retina reader, touch screen (e.g., capacitive, resistive, etc.), trackball, track pad, sensor, stylus, etc. These and other input devices are often connected to the processor 804 through an input device interface 842 coupled to the system bus 808, but may be connected by other interfaces, such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, an IR interface, etc.
[0076] A monitor 844 or other type of display device is also connected to the system bus 808 via an interface, such as a video adapter 846. The monitor 844 may be internal or external to the computing system 802. In addition to the monitor 844, computers typically include other peripheral output devices, such as speakers, printers, etc.
[0077] The computing system 802 may operate in a networked environment using logical connections via wired and / or wireless communications to one or more remote computers, such as a remote computer 848. The remote computer 848 may be a workstation, a server computer, a router, a personal computer, a portable computer, a microprocessor-based entertainment device, a peer device, or other common network node and typically includes many or all of the elements described relative to the computing system 802, although for simplicity, only a memory / storage device 850 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 852 and / or larger networks, e.g., a wide area network (WAN) 854. Such LAN and WAN networking environments are commonplace in offices and businesses, facilitating enterprise-wide computer networks such as intranets. All of these may connect to a global communications network, e.g., the Internet. In an embodiment, the network 130 of FIG. 1 is one or more of the LAN 852 and the WAN 854.
[0078] When used in a LAN networking environment, the computing system 802 is connected to the LAN 852 through a wired and / or wireless communication network interface or adapter 856. The adapter 856 may facilitate wired and / or wireless communication to the LAN 852, which may include a wireless access point disposed thereon for communicating with the wireless functionality of the adapter 856.
[0079] When used in a WAN networking environment, the computing system 802 may include a modem 858 or have other means for establishing communications over the WAN 854, such as connected to a communications server on the WAN 854 or via the Internet. The modem 858 may be internal or external, a wired and / or wireless device, and connects to the system bus 808 via the input device interface 842. In a networked environment, program modules depicted relative to the computing system 802, or portions thereof, may be stored in the remote memory / storage device 850. It will be appreciated that the network connections shown are exemplary and other means of establishing a communications link between computers may be used.
[0080] The computing system 802 is operable to communicate with wired and wireless devices or entities using the IEEE 802 family of standards, such as wireless devices operatively arranged for wireless communication (e.g., IEEE 802.16 wireless modulation techniques). This includes at least Wi-Fi (or Wireless Fidelity), WiMax, Bluetooth® wireless technologies, and the like. Thus, communication can be in a predefined structure, similar to a traditional network, or simply ad hoc communication between at least two devices. Wi-Fi networks use radio technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and high-speed wireless connectivity. Wi-Fi networks can be used to connect computers to each other, to the Internet, or to wired networks (using IEEE 802.3-related media and functions).
[0081] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include a processor, a microprocessor, a circuit, a circuit element (e.g., a transistor, a resistor, a capacitor, an inductor, etc.), an integrated circuit, an application specific integrated circuit (ASIC), a programmable logic device (PLD), a digital signal processor (DSP), a field programmable gate array (FPGA), a logic gate, a register, a semiconductor device, a chip, a microchip, a chipset, etc. Examples of software may include a software component, a program, an application, a computer program, an application program, a system program, a machine program, an operating system software, a middleware, a firmware, a software module, a routine, a subroutine, a function, a method, a procedure, a software interface, an application program interface (API), an instruction set, a computing code, a computer code, a code segment, a computer code segment, a word, a value, a symbol, or any combination thereof. The decision whether an embodiment is implemented using hardware and / or software elements may vary according to any number of factors, such as desired computational speed, power level, heat tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed and other design or performance constraints.
[0082] One or more aspects of at least one embodiment may be implemented by representative instructions stored on a machine-readable medium that represent various logic within a processor, which, when read by a machine, causes the machine to manufacture logic that performs the techniques described herein. Such representations, known as “IP cores,” are stored on tangible machine-readable media and provided to various customers or manufacturing facilities for loading into manufacturing machines that create the logic or processors. Some embodiments may be implemented using, for example, a machine-readable medium or article that may store instructions or sets of instructions that, when executed by the machine, cause the machine to perform methods and / or operations in accordance with the embodiments. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. A machine-readable medium or article may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disk, floppy disk, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewriteable (CD-RW), optical disk, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tape, cassette, etc. The instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.
[0083] The foregoing description of exemplary embodiments has been presented for purposes of illustration and description. It is not intended to be exhaustive or to limit the disclosure to the precise form disclosed. Many modifications and variations are possible in light of this disclosure. It is intended that the scope of the disclosure be limited not by this detailed description, but by the appended claims. Future applications claiming priority to this application may claim the disclosed subject matter differently and may generally include any set of one or more limitations as variously disclosed or demonstrated herein.
Claims
1. receiving, by an application executing on a processor of the device, a request to perform an operation associated with the account using a first function of the application; receiving, by the application, encrypted data from a contactless card associated with the account; receiving, by the application, an indication from an authentication server specifying a first authorization level for the account and that the authentication server has verified the encrypted data; the application determining that a first permission level of the account does not meet a required permission level to perform the operation using a first function of the application; determining that authentication using encrypted passport data is required to initiate performance of a requested operation using a first function of the application based on a first authorization level that the application does not meet and a first rule of a plurality of rules; receiving, by the application, encrypted passport data and a digital signature for the encrypted passport data from the contactless card, the encrypted passport data being for a passport associated with the account; the application decrypting the encrypted passport data; the application sending the digital signature of the encrypted passport data to the authentication server for public key based verification; based on receipt of verification of the digital signature, the application transmitting to the authentication server the first authorization level of the account or an indication specifying that the first authorization level of the account does not meet the authorization level required for the requested operation; receiving, by the application, from the authentication server, a second authorization level assigned to the account based on decryption of the encrypted passport data, the second authorization level having a greater authorization level relative to the first authorization level; the first function of the application initiates execution of the operation based on the received indication specifying that the authentication server has verified the encrypted passport data, the decryption of the encrypted passport data, the second authorization level of the account, and a determination that the digital signature is valid; A method comprising:
2. the encrypted data is based on a diversified key and a customer identifier associated with the contactless card, the diversified key is based on a counter value and a master key associated with the contactless card, and the authentication server verifies the encrypted data based on the diversified key, the counter value, and the master key. The method of claim 1.
3. Furthermore, the application receiving an updated version of the encrypted passport data; the application sending to the contactless card an updated version of the encrypted passport data for storage on the contactless card; Including, The method of claim 1.
4. Furthermore, the application extracting at least one attribute of the passport from a first image of the passport, the first image depicting at least one attribute of the passport, and the application decrypting the encrypted data based on the extracted at least one attribute. Including, The method of claim 1.
5. The operation is (i) displaying attributes of the account using a first function provided by the application; (ii) modifying an attribute of the account using a second function of the plurality of functions provided by the application; (iii) accessing a third feature of the plurality of features provided by the application; or (iv) processing a transaction using the contactless card using a fourth function of the plurality of functions provided by the application. including one or more of: The method of claim 1.
6. the required permission level is specified by a second rule of the plurality of rules; The method of claim 1.
7. verifying the digital signature includes decrypting the digital signature based on the public key; The method of claim 1.
8. A non-transitory computer-readable storage medium storing instructions for execution by a processor, When the instructions are executed by a processor, the processor: receiving, by an application executing on a processor of the device, a request to perform an operation associated with the account using a first function of the application; receiving, by the application, encrypted data from a contactless card associated with the account; receiving, by the application, an indication from an authentication server specifying a first authorization level for the account and that the authentication server has verified the encrypted data; the application determining that a first permission level of the account does not meet a required permission level to perform the operation using a first function of the application; determining that authentication using encrypted passport data is required to initiate performance of a requested operation using a first function of the application based on a first authorization level that the application does not meet and a first rule of a plurality of rules; receiving, by the application, encrypted passport data and a digital signature for the encrypted passport data from the contactless card, the encrypted passport data being for a passport associated with the account; the application decrypting the encrypted passport data; the application sending the digital signature of the encrypted passport data to the authentication server for public key based verification; based on receipt of verification of the digital signature, the application transmitting to the authentication server the first authorization level of the account or an indication specifying that the first authorization level of the account does not meet the authorization level required for the requested operation; receiving, by the application, from the authentication server, a second authorization level assigned to the account based on decryption of the encrypted passport data, the second authorization level having a greater authorization level relative to the first authorization level; the first function of the application initiates execution of the operation based on the received indication specifying that the authentication server has verified the encrypted passport data, the decryption of the encrypted passport data, the second authorization level of the account, and a determination that the digital signature is valid; The purpose is to A computer-readable storage medium.
9. the encrypted data is based on a diversified key and a customer identifier associated with the contactless card, the diversified key is based on a counter value and a master key associated with the contactless card, and the authentication server verifies the encrypted data based on the diversified key, the counter value, and the master key. The computer-readable storage medium of claim 8.
10. The instructions further include, in a processor: the application receiving an updated version of the encrypted passport data; the application sending to the contactless card an updated version of the encrypted passport data for storage on the contactless card; This allows the The computer-readable storage medium of claim 8.
11. The instructions further include, in a processor: the application extracting at least one attribute of the passport from a first image of the passport, the first image depicting at least one attribute of the passport, and the application decrypting the encrypted data based on the extracted at least one attribute. This allows the The computer-readable storage medium of claim 8.
12. The operation is (i) displaying attributes of the account using a first function provided by the application; (ii) modifying an attribute of the account using a second function of the plurality of functions provided by the application; (iii) accessing a third feature of the plurality of features provided by the application; or (iv) processing a transaction using the contactless card using a fourth function of the plurality of functions provided by the application. including one or more of: The computer-readable storage medium of claim 8.
13. the required permission level is specified by a second rule of the plurality of rules; The computer-readable storage medium of claim 8.
14. verifying the digital signature includes decrypting the digital signature based on the public key; The computer-readable storage medium of claim 8.
15. 1. A computing device including a processor and a memory for storing instructions executed by the processor, When the instructions are executed by a processor, the processor: receiving, by an application executing on a processor of the device, a request to perform an operation associated with the account using a first function of the application; receiving, by the application, encrypted data from a contactless card associated with the account; receiving, by the application, an indication from an authentication server specifying a first authorization level for the account and that the authentication server has verified the encrypted data; the application determining that a first permission level of the account does not meet a required permission level to perform the operation using a first function of the application; determining that authentication using encrypted passport data is required to initiate performance of a requested operation using a first function of the application based on a first authorization level that the application does not meet and a first rule of a plurality of rules; receiving, by the application, encrypted passport data and a digital signature for the encrypted passport data from the contactless card, the encrypted passport data being for a passport associated with the account; the application decrypting the encrypted passport data; the application sending the digital signature of the encrypted passport data to the authentication server for public key based verification; based on receipt of verification of the digital signature, the application transmitting to the authentication server the first authorization level of the account or an indication specifying that the first authorization level of the account does not meet the authorization level required for the requested operation; receiving, by the application, from the authentication server, a second authorization level assigned to the account based on decryption of the encrypted passport data, the second authorization level having a greater authorization level relative to the first authorization level; the first function of the application initiates execution of the operation based on the received indication specifying that the authentication server has verified the encrypted passport data, the decryption of the encrypted passport data, the second authorization level of the account, and a determination that the digital signature is valid; The purpose is to Computing equipment.
16. the encrypted data is based on a diversified key and a customer identifier associated with the contactless card, the diversified key is based on a counter value and a master key associated with the contactless card, and the authentication server verifies the encrypted data based on the diversified key, the counter value, and the master key.
16. The computing device of claim 15.
17. The instructions further include, in a processor: the application receiving an updated version of the encrypted passport data; the application sending to the contactless card an updated version of the encrypted passport data for storage on the contactless card; This allows the 16. The computing device of claim 15.
18. The instructions further include, in a processor: the application extracting at least one attribute of the passport from a first image of the passport, the first image depicting at least one attribute of the passport, and the application decrypting the encrypted data based on the extracted at least one attribute. This allows the 16. The computing device of claim 15.
19. The operation is (i) displaying attributes of the account using a first function provided by the application; (ii) modifying an attribute of the account using a second function of the plurality of functions provided by the application; (iii) accessing a third feature of the plurality of features provided by the application; or (iv) processing a transaction using the contactless card using a fourth function of the plurality of functions provided by the application. including one or more of:
16. The computing device of claim 15.
20. the required permission level is specified by a second rule of the plurality of rules; verifying the digital signature includes decrypting the digital signature based on the public key; 16. The computing device of claim 15.
Citation Information
Patent Citations
Adaptable security mechanisms for preventing unauthorized access to digital data
JP2003518351A
Non-contact IC card authentication system
JP2009140275A
Authentication system and program
JP2015014923A
Identity management service via virtual passport
US10298396B1
System and method for clearing point-of-sale terminal pre-authorizations
US20190188705A1