First factor contactless card authentication system and method

A contactless card authentication system using a cryptogram exchange protocol with a dynamic password enhances security by providing two-factor verification, addressing vulnerabilities in existing authentication systems and reducing the risk of unauthorized access.

JP7792466B2Active Publication Date: 2025-12-25CAPITAL ONE SERVICES LLC
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
JP2024103200
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-07-23
Filing Date
2024-06-26
Publication Date
2025-12-25
Estimated Expiration
2040-07-10

AI Technical Summary

Technical Problem

Existing authentication systems are vulnerable to phishing and man-in-the-middle attacks, particularly during username/password exchanges, as users often reuse passwords across multiple platforms, and cryptographic encoding does not fully protect sensitive client information.

Method used

Implement a contactless card authentication system using a cryptogram exchange protocol that includes a contactless card with an embedded integrated circuit, which generates a cryptogram comprising a username and dynamic password, enhancing security through two-factor verification.

Benefits of technology

The contactless card authentication system provides robust, passwordless access control, reducing the risk of unauthorized access by leveraging unpredictable dynamic passwords and contactless card ownership, thus strengthening client-server communication security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007792466000001
    Figure 0007792466000001
  • Figure 0007792466000002
    Figure 0007792466000002
  • Figure 0007792466000003
    Figure 0007792466000003
Patent Text Reader

Abstract

To provide a passwordless authentication system and method capable of improving security to reduce the likelihood of malicious access.SOLUTION: A method comprises registering a client's contactless card in an application service, and binding the contactless card to one or more client devices. The contactless card advantageously stores a username and a dynamic password. Access to the application service by the client may be made available using any client device, and authentication of access is executed by any client device capable of acquiring the username and dynamic password pair from a contactless card interface. Storing the username in the card without requiring user input limits access to and knowledge of login qualification information to increase the security of the application, and using the dynamic password reduces the likelihood of malicious access.SELECTED DRAWING: Figure 8
Need to check novelty before this filing date? Find Prior Art

Description

[Technical Field]

[0001] Related Applications This application claims priority to U.S. Patent Application No. 16 / 519,079, entitled "First Factor Contactless Card Authentication System and Method," filed July 23, 2019. The contents of the aforementioned application are incorporated herein by reference in their entirety. [Background technology]

[0002] Many service providers use the Internet to deliver offerings to potential or current customers, typically in the form of software applications that operate using the service provider's dedicated resources.

[0003] Many application services store sensitive client content such as account numbers, personal information, purchase history, passwords, social security numbers, etc. To restrict unauthorized access to sensitive customer content, service providers must enforce authentication controls.

[0004] Many authentication controls verify clients based on some combination of factors, including knowledge factors (something the client knows), ownership factors (something the client has), and unique factors (something the client is). Knowledge factors can include passwords, partial passwords, passphrases, or personal identification numbers (PINs), challenge-response (requiring the user to answer a question or pattern). Ownership factors can include something the client possesses (e.g., a wristband, ID card, security token, embedded device, mobile phone with a hardware token, software token, or mobile phone holding a software token). Unique factors can be related to who the user is or what the user does (e.g., a fingerprint, retinal pattern, DNA sequence, signature, face, voice, unique bioelectric signal, or other biometric identifier).

[0005] Access to service provider information and services is typically controlled through layered security protocols designed to protect sensitive or critical information using multi-factor authentication techniques. Despite such efforts, service provider systems remain vulnerable to phishing, man-in-the-middle, and other malicious attacks, particularly during username / password exchange. These are particular targets of hackers who understand users' tendency to use the same passwords across multiple platforms. Cryptographic encoding of passwords impairs, but does not eliminate, the ability of malicious actors to tamper with client accounts. Summary of the Invention

[0006] According to one aspect of the present invention, a method for authorizing access to an application by a client includes the steps of receiving a request to access an application from a first client device, identifying the client associated with the first client device, verifying authenticity of the request by forwarding notification of the request to a second client device associated with the client, and receiving a response from the second client device, the response including authentication information including a username and a dynamic password obtained by the second client device from a contactless card associated with the client. The method also includes comparing the username and dynamic password obtained by the second client device with an expected username and expected dynamic password for the client. The method also includes authenticating the request and launching the application on the first client device in response to a match between the username and the expected username and the dynamic password and the expected dynamic password. The method also includes updating and storing the dynamic password associated with the client. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the operations of the method.

[0007] According to another aspect, a system for controlling access to an application by a client includes a processor; an interface configured to receive an authentication request from a second client device associated with the client and authenticate an access request made by a first client device associated with the client to access the application, the authentication request including a cryptogram provided to the second client device by a contactless card, the cryptogram including a username and a dynamic password; a non-transitory storage medium including a client table including at least one entry for at least one client, the at least one entry including an expected username and an expected dynamic password for the client; and program code stored on the non-transitory storage medium and operable when executed by the processor. The system also includes selectively approving the authentication request in response to a first match between the username and the expected username and a second match between the dynamic password and the expected dynamic password. The system also includes updating the client's expected dynamic password in response to approving the authentication request. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the operations of the method.

[0008] According to a further aspect, a method for authorizing access to an application by a client includes receiving a request to access the application from a first device associated with the client, identifying the client associated with the first device, and verifying authenticity of the request by forwarding notification of the request to a second device associated with the client, the request including generating a prompt for display on the second device requesting authentication input from the client. The method also includes comparing the authentication input with an expected authentication input for the client. The method also includes enabling access to the application by the first device in response to a match between the authentication input and the expected authentication input. Other embodiments of this aspect include corresponding computer systems, apparatuses, and computer programs recorded on one or more computer storage devices, each configured to perform the operations of the method.

[0009] According to another aspect, a method for launching an application hosted by a service provider includes registering a client with the application and binding a contactless card to the client. In one embodiment, binding the contactless card to the client may include obtaining a cryptogram comprising a username and a dynamic password from the contactless card, authenticating the username and dynamic password pair, associating the username and dynamic password pair with the client, and storing the username and dynamic password pair in memory. The method further includes updating the application interface of the client to provide a contactless card login option as part of the modified application interface.

[0010] According to a further aspect, a system for launching an application includes one or more coupled client devices, a storage device, and a client interface adapted to exchange information with a table stored on the storage device and comprising an entry for at least one client. The entry includes a card identifier and a dynamic card password for the client. The system includes an authentication unit coupled to the client interface and the table, and selectively authenticates the client in response to a comparison between the card identifier and the dynamic card password stored in the table and an authentication card identifier and authentication password obtained from the client's contactless card. The system may also include an application launch control coupled to the authentication unit and configured to selectively launch an application for the client in response to the selective authentication of the client.

[0011] According to another aspect, a method for launching an application includes displaying multiple login options to a user operating a client device, the multiple login options including a contactless card login option. The method includes, in response to selection of the contactless card login option, prompting the user to engage a contactless card with the client device to retrieve encoded ciphertext from a storage device of the contactless card, the encoded ciphertext comprising a username and a dynamic password, and forwarding the encoded ciphertext to an authorization server so that the username and dynamic password can be compared with an expected username and expected password for selective authentication. The method includes receiving an authentication result from the authorization server and selectively launching an application in response to the authentication result.

[0012] With such an arrangement, contactless card cryptographic exchange, which alone provides two-factor verification (knowledge of username, dynamic password, contactless card ownership, mobile device, etc.), may be used as the first factor authentication mechanism in a layered security protocol, thereby reducing the likelihood of sensitive client information being misused during client / server communications. [Brief explanation of the drawings]

[0013] [Figure 1] FIG. 1 is a block diagram of a data transmission system configured to pre-authenticate a customer request according to an exemplary embodiment. [Figure 2] FIG. 1 illustrates a sequence for providing authenticated access according to an exemplary embodiment. [Figure 3] 2 is an example of a contactless card for storing authentication information that can be used in the system of FIG. 1. [Figure 4] FIG. 4 is a detailed block diagram illustrating exemplary components of the contactless card of FIG. 3. [Figure 5] 2 is a diagram of exemplary fields of messages exchanged between the contactless card and the client device of FIG. 1. [Figure 6] FIG. 1B is a detailed block diagram of components of the system of FIG. 1A that may be utilized to support aspects of the present invention. [Figure 7] FIG. 1 is a data flow diagram provided to illustrate example steps that may be performed to register a client, one or more client devices, and / or a contactless card to enable contactless card first factor authentication as described herein. [Figure 8] FIG. 1 is a data flow diagram provided to explain an example embodiment of a system and method for secure passwordless login using a username / dynamic password pair provided as part of a cryptogram exchange between a contactless card and a client device. [Figure 9]1 illustrates exemplary user interface elements that may be provided on various client devices to support aspects disclosed herein. [Figure 10] 1 illustrates exemplary user interface elements that may be provided on various client devices during the passwordless login process disclosed herein. [Figure 11A] 1 illustrates exemplary user interface elements that may enable dual-factor authentication for application launch using a device. [Figure 11B] 1 illustrates exemplary user interface elements that may enable dual-factor authentication for application launch using a device. DETAILED DESCRIPTION OF THE INVENTION

[0014] Passwordless login protocols allow service providers to authenticate clients without requiring them to enter a password. For example, passwordless email- or text-based systems use an email / text address and a complex encrypted key code to verify a user's identity. Public key authentication is another method for implementing passwordless login. Passwordless login methods using public key authentication are supported by the Fast ID Online (FIDO) Alliance. FIDO defines various authentication standards, including the Universal Second Factor (U2F) protocol. The U2F protocol uses a strong second factor authentication, such as a near-field communication (NFC) tap or USB security token. During login, users are prompted to insert and touch their personal U2F device. The user's FIDO-enabled device creates a new key pair, and the public key is shared with the online service and associated with the user's account. The service can then authenticate the user by requesting that the registered device sign a challenge using the private key. Although the U2F protocol offers improved security over password-based methods, the use of static secret keys for authentication, even when encrypted, is a weakness in the overall U2F security protocol.

[0015] According to one aspect, an improved passwordless authentication protocol actually applies a contactless card cryptogram exchange protocol as a first factor authentication mechanism to facilitate application service access without sacrificing the security of the application service.

[0016] In one embodiment, the contactless card comprises a credit card-sized card including an embedded integrated circuit, a storage device, and an interface that enables the card to communicate with a transmitting device using a near field communication (NFC) protocol. Exemplary contactless cards that may be used herein include those described in U.S. Patent Application No. 16 / 205,119, entitled "System and Method for Cryptographic Authentication of Contactless Cards," filed November 29, 2018 by Osborn et al. (hereinafter the '119 application), which is incorporated herein by reference. The contactless card may be configured to exchange cryptograms as part of an NFC exchange.

[0017] The improved passwordless protocol includes registering a client's contactless card with an application service, binding the contactless card to the client, and performing first factor, second factor, and / or other authentication of the client access request by the application service using the cryptographic exchange protocol described in the '119 application. In one embodiment, the contactless card may include one or more applets, a counter value, a plurality of keys, and a memory including one or more processors configured to increment the counter value for each cryptogram exchanged with the service provider. The contactless card may be configured to create a cryptogram using the plurality of keys and the counter value and transmit the cryptogram to a receiving device via a communication interface, such as a near-field communication (NFC) interface. According to one aspect, the cryptogram may comprise a username or other identifier of the client. In various embodiments, the username may be automatically generated for the client or defined by the client. In various embodiments, the username may be embedded in the contactless card before delivery to the client, or may be loaded or embedded in the contactless card as part of a registration process by the service provider. In some embodiments, the username may be hashed or encrypted using one or more hash functions, symmetric encryption algorithms, and / or keys provided by the contactless card.

[0018] According to another aspect, the cryptogram may comprise a dynamic password that may be used in combination with the username to perform first factor authentication of the client when accessing the application service. In one embodiment, the dynamic password comprises a cryptogram counter, such that the dynamic password is related to the number of cryptograms exchanged between the client and the application service, i.e., the number of times the username is retrieved from the contactless card. Such a configuration enhances the security of client / server communications, as the unpredictability of the dynamic password increases confidence in the authenticity of the client.

[0019] According to one aspect, binding a contactless card to a client includes associating the card with a digital credential and / or a client device. The association of the card with the client's digital credential may occur as part of the client's initial registration with the service provider (i.e., the client's first access to an application service), or alternatively, prior to delivering the contactless card to the client. In one embodiment, at least one client device includes an interface for communicating with the contactless card. Once the contactless card is bound to a client device having a contactless card interface, a contactless card cryptogram exchange performed on a known client device may be used to authenticate client access to registered application services on any web-connected device. For example, a contactless card / mobile device cryptogram exchange may be used to authenticate a service provider access request by a client on a mobile device or other web-based device.

[0020] In one embodiment, the application service client interface may be configured to suggest or mandate the use of a cryptogram exchange authentication method for application service access. The cryptogram exchange protocol provides two-factor verification (i.e., knowledge of a username and dynamic password, and possession of a contactless card and / or client device), and because of the unpredictability of dynamic passwords, the ability to use the disclosed protocol as a first factor authentication method may satisfy clients seeking high-security, passwordless authentication.

[0021] These and other features of the present invention are described with reference to the figures, wherein like reference numerals are used to refer to like elements throughout. Referring generally to the notation and nomenclature used herein, the detailed descriptions which follow may be presented in terms of program processes executed on a computer or network of computers. These process descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art.

[0022] A process is herein and generally conceived to be a self-consistent sequence of operations leading to a desired result. These operations are those requiring physical manipulations of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.

[0023] Further, the manipulations performed are often referred to in terms, such as adding or comparing, which are commonly associated with mental operations performed by a human operator. No such capability of a human operator is necessary, or desirable in most cases, in any of the operations described herein that form part of one or more embodiments. Rather, the operations are machine operations. Useful machines for performing the operations of various embodiments include general purpose digital computers or similar devices.

[0024] Various embodiments also relate to apparatus or systems for performing these operations. This apparatus may be specially constructed for the required purposes, or it may comprise a general-purpose computer selectively activated or reconfigured by a computer program stored in the computer. The processes presented herein are not inherently related to any particular computer or other apparatus. Various general-purpose machines may be used with programs written in accordance with the teachings herein, or it may prove convenient to construct more specialized apparatus to perform the required method steps. The required structure for a variety of these machines will be apparent from the description given.

[0025] Reference is now made to the drawings. Like reference numerals are used to refer to like elements throughout. In the following description, for purposes of explanation, numerous specific details are set forth in order to provide a thorough understanding thereof. It may be apparent, however, that novel embodiments may be practiced without these specific details. In other instances, well-known structures and devices are shown in block diagram form to facilitate description. The intention is to cover all modifications, equivalents, and alternatives consistent with the claimed subject matter.

[0026] 1 illustrates a system 100 including one or more client devices 110 coupled to a service provider 120 via a network 115. According to one aspect, the client devices 110 comprise network-enabled computers and communicate with the service provider 120 via networks 115 and 125 to access the service provider's content and services.

[0027] As referred to herein, a network-enabled computer may include, for example, but is not limited to, a computing device or communications device including, for example, a server, a network appliance, a personal computer (PC), a workstation, a mobile device, a telephone, a handheld PC, a personal digital assistant (PDA), a thin client device, a fat client device, an internet browser, or other device.

[0028] Accordingly, client device 110 may include a processor and memory, and it is understood that processing circuitry may include additional components, including processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and tamper-proof hardware, to perform the functions described herein. Client device 110 may further include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, a flat-panel display, and a mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input devices may include any device for inputting information into a user's device that is available and supported by the user's device, such as a touchscreen, a keyboard, a mouse, a cursor control device, a microphone, a digital camera, a video recorder, or a camcorder. These devices may be used to input information and interact with the software and other devices described herein.

[0029] The one or more client devices 110 may be mobile devices such as, for example, an Apple® iPhone®, iPod®, iPad®, or other mobile devices running Apple's iOS® operating system, devices running Microsoft's Windows® mobile operating system, and / or other smartphones or similar wearable mobile devices.

[0030] 1 include a mobile phone 142, a laptop 144, a tablet 148, and a terminal 146. The client device 110 may include a thin client application specifically adapted for communication with the service provider 120. The thin client application may be stored in the client device's memory, be operative when executed by the client device, control the interface between the client device and the service provider application, and enable a user of the client device to access the service provider's content and services.

[0031] In some examples, network 115 may be one or more of a wireless network, a wired network, or any combination of wireless and wired networks, and may be configured to connect client device 110 to service provider 120. For example, network 115 may include one or more of an optical fiber network, a passive optical network, a cable network, an Internet network, a satellite network, a wireless local area network (WLAN), a global system for mobile communications, a personal communications service, a personal area network, a wireless application protocol, a multimedia messaging service, an enhanced messaging service, a short message service, a time division multiplex-based system, a code division multiple access-based system, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, radio frequency identification (RFID), Wi-Fi, etc.

[0032] Additionally, network 115 may include, but is not limited to, telephone lines, optical fiber, IEEE Ethernet 902.3, a wide area network ("WAN"), a wireless personal area network ("WPAN"), a local area network ("LAN"), or a global network such as the Internet. Furthermore, network 115 may support an Internet network, a wireless communication network, a cellular network, or the like, or any combination thereof. Network 115 may further include one or any number of the exemplary types of networks listed above, operating as a standalone network or in cooperation with one another. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may translate to or from other protocols to one or more protocols of network devices.

[0033] According to one or more examples, it should be appreciated that network 115 may be part of multiple interconnected networks, such as, for example, the Internet, a service provider's private network 125, a cable television network, an enterprise network such as a credit card association network or a home network, etc. Additionally, private network 125 may be implemented as a virtual private network layered on network 115.

[0034] Service provider 120, in one embodiment, is a business that provides computer-based services to clients over network 115. The combination of software and hardware that provides the service provider's particular service to clients is referred to herein as a "server." The server may communicate over the service provider's private network 125, which is often referred to as a corporate or enterprise network. Private network 125 may comprise a wireless network, a wired network, or any combination of wireless and wired networks, as described above with respect to network 115.

[0035] The software service may be embodied in an application that runs on an electronic device, such as a desktop application that runs on an operating system of a computing device, a mobile application that runs on a mobile operating system of a mobile device, or a web application that runs on a browser component of either a mobile operating system or a desktop operating system. Those skilled in the art will understand how to design, build, and deploy software applications on any type of electronic device. In some embodiments, the application may be a browser application running on the device's operating system.

[0036] In the system of FIG. 1 , service provider 120 is shown to include application server 150 and authentication server 160. While each server is shown as a separate device, it is understood that applications and servers may be distributed throughout an enterprise or, in the case of distributed resources such as “cloud” resources, throughout network 115. Application server 150 may support one or more application services, such as account management services, offered by service provider 120. According to one aspect, authentication server 160 may be configured to provide one or both of first and second factor authentication using contactless cards, as disclosed in more detail below.

[0037] Database 130 comprises data storage resources that may be used to store customer account, credential, and other authentication information, including dynamic password data, for use by application server 150 and authentication server 160, for example. Database 130 may be comprised of combined data resources comprising any combination of local storage, distributed data center storage, or cloud-based storage, where the data resources comprise non-transitory, tangible storage media that do not involve carrier waves or propagated data signals.

[0038] According to one aspect, contactless card 105 may communicate wirelessly, e.g., via near field communication (NFC), with one or more client devices 110. For example, contactless card 105 may include one or more chips, such as a radio frequency identification chip, configured to communicate via NFC or other short-range protocols. In other embodiments, contactless card 105 may communicate with client device 110 via other means, including, but not limited to, Bluetooth, satellite, and / or WIFI. As described in the '119 application, contactless card 105 may be configured to communicate with one of card reader terminal 146, mobile phone 142, laptop 144, and / or tablet 148 via NFC when contactless card 105 is within range of the respective client device. As described in more detail below, contactless card 105 may contain username, key, and counter information that may be converted using an encryption algorithm to generate ciphertext including a dynamic password that may be used by a service provider to authenticate the client device.

[0039] As noted above, according to one embodiment, first factor authentication may be performed by exchanging a username and a dynamic password as part of a cryptogram exchange such as that described in the '119 application. A description of an exemplary cryptogram exchange system and method will now be described with reference to Figures 2-5.

[0040] 2 is a data flow diagram illustrating an example workflow for authenticating client access to a service provider application in accordance with various aspects disclosed herein. In FIG. 2, client device 110 is shown including application 122 and processor 124. In one embodiment, the application may comprise, for example, a client-side applet comprising program code operable when executed by processor 124 to control an interface between client device 110 and a service provider application hosted by a server of a service provider network.

[0041] In step 102, application 122 communicates with contactless card 105 (e.g., after being brought into proximity with contactless card 105). Communication between application 122 and contactless card 105 may involve contactless card 105 being sufficiently close to a card reader (not shown) of client device 110 to enable NFC data transfer between application 122 and contactless card 105.

[0042] In step 104, after communication between the client device 110 and the contactless card 105 is established, the contactless card 105 generates a message authentication code (MAC) cryptogram according to an NFC data exchange format. In some examples, this may occur when the contactless card 105 is read by the application 122, for example, in response to the application 122 issuing a read of a Near Field Radio Data Exchange (NDEF) tag stored on the contactless card. At this point, a counter value maintained by the contactless card 105 may be updated or incremented, and the contactless card may generate a message including a header, a payload, and a shared secret. According to one aspect, the payload may include the client's username, and the shared secret may include a dynamic password used to authenticate the client. A MAC cryptogram may be created from the message, which may include the header, the payload, and the shared secret. The MAC cryptogram may then be concatenated with one or more blocks of random data, and the MAC cryptogram and the random number (RND) may be encrypted with a session key. The ciphertext and header may then be concatenated, encoded as ASCII hex, and returned in NDEF message format (in response to a "read NDEF file" message).

[0043] In some examples, the MAC cryptogram may be transmitted as an NDEF tag, and in other examples, the MAC cryptogram may be included with the uniform resource indicator (eg, as a formatted string).

[0044] In some examples, the application 122 may be configured to send a request to the contactless card 105, the request comprising instructions to generate a MAC cryptogram.

[0045] In step 106, contactless card 105 transmits the MAC cryptogram to application 122. In some examples, transmission of the MAC cryptogram occurs via NFC; however, this disclosure is not limited thereto. In other examples, this communication may occur via Bluetooth, Wi-Fi, or other wireless data communication means.

[0046] In step 108, the application 122 communicates the MAC ciphertext to the processor 124.

[0047] In step 112, processor 124 verifies the MAC ciphertext according to instructions from application 122. For example, the MAC ciphertext may be verified as described below.

[0048] In some examples, verification of the MAC ciphertext may be performed by a device other than client device 110, such as service provider 120 in data communication with client device 110 (as shown in FIG. 1). For example, processor 124 may output the MAC ciphertext for transmission to authentication server 160 of service provider 120, which may verify the MAC ciphertext.

[0049] According to one aspect, first factor security authentication may prompt a user to perform one or more actions associated with one or more contactless cards. In effect, the security factor authentication prompts the user to engage in one or more types of actions, including, but not limited to, one or more tap gestures associated with the contactless cards. In some examples, the one or more tap gestures may comprise a user tapping the contactless card against the device. The one or more tap gestures may be used to exchange cryptograms comprising a username and a dynamic password for purposes of authenticating a client access request with a service provider.

[0050] In one embodiment, as described in more detail below, the contactless card includes cryptographic processing functionality that can be used to generate a cryptogram that includes a username, a key, a counter, and a dynamic password that can be used to validate the user of the client device along with the username. In one embodiment, the dynamic password is associated with the counter. Thus, in such an embodiment, the dynamic password advantageously reflects the card owner's previous behavior. For example, a counter-based dynamic password may reflect the number of times a user has previously accessed a particular service of a service provider, a knowledge factor that is virtually impossible for a malicious third party to grasp.

[0051] FIG. 3 illustrates one or more contactless cards 300, which may comprise a payment card, such as a credit card, debit card, or gift card, issued by a service provider 305 with identifying information displayed on the front or back of the card 300. In some examples, the contactless card 300 may be unrelated to a payment card and may comprise, but is not limited to, an identification card or passport. In some examples, the payment card may comprise a dual-interface contactless payment card. The contactless card 300 may comprise a substrate 310, which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 300 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard; otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, it should be understood that contactless cards 300 according to the present disclosure may have different characteristics and the present disclosure does not require contactless cards to be implemented as payment cards.

[0052] Contactless card 300 may also include identification information 315 displayed on the front and / or back of the card, and contact pad 320. Contact pad 320 may be configured to establish contact with a user device or other communication device, such as a smartphone, laptop, desktop, or tablet computer. Contactless card 300 may also include processing circuitry, an antenna, and other components not shown in FIG. 3 . These components may be located behind contact pad 320 or elsewhere on substrate 310. Contactless card 300 may also include a magnetic strip or tape (not shown in FIG. 3 ) that may be located on the back of the card.

[0053] 4, contact pad 420 may include processing circuitry for storing and processing information, including a microprocessor 430 and memory 435. It is understood that the processing circuitry may include additional components such as processors, memory, error and parity / CRC checkers, data encoders, anti-collision algorithms, controllers, command decoders, security primitives, and anti-tamper hardware necessary to perform the functions described herein.

[0054] The memory 435 may be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 400 may include one or more of these memories. Read-only memory may be programmable at the factory as read-only or one-time programmable. A one-time program allows it to be written once and read many times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritten, but it may be read many times. Read / write memory may be programmed and reprogrammed many times after leaving the factory, and it may also be read many times.

[0055] The memory 435 may be configured to store one or more applets 440, one or more counters 445, and customer information 450. The one or more applets 440 may be associated with a respective one or more service provider applications and comprise one or more software applications configured to run on one or more contactless cards, such as a Java Card applet. According to one aspect, each applet may store a username 402 for a client to access the service provider application associated with the applet.

[0056] The one or more counters 445 may comprise a numeric counter sufficient to store an integer number. The customer information 450 may comprise a unique alphanumeric identifier assigned to the user of the contactless card 400 and / or one or more keys that may be used together to distinguish the user of the contactless card from other users of contactless cards. In some examples, the customer information 450 may include information that identifies both the customer and the account assigned to the customer, and may further identify the contactless card associated with the customer's account. According to some embodiments, the username 442 may be derived from a combination of the one or more customer information 450 and / or one or more keys.

[0057] Although the processor and memory elements of the foregoing exemplary embodiments are described with reference to contact pads, the present disclosure is not limited thereto, and it will be understood that these elements may be implemented outside of the pads 420, completely separate from the pads 420, or as additional elements in addition to the microprocessor 430 and memory 335 elements located within the contact pads 420.

[0058] In some examples, the contactless card 400 may include one or more antennas 425 disposed within the contactless card 400 around the processing circuit 455 of the contact pad 420. For example, the one or more antennas may be integral with the processing circuit, or the one or more antennas may be used with an external booster coil. As another example, the one or more antennas may be external to the contact pad 420 and the processing circuit.

[0059] As described above, the contactless card 400 may be built on a software platform operable on a smart card or other device comprising program code, processing power, and memory, such as a Java Card. An applet may be added to the contactless card to generate one-time passwords (OTPs) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a Near Field Communication (NDEF) request, from a reader, such as a mobile Near Field Communication (NFC) reader, and generate an NDEF message comprising a cryptographically secure OTP encoded as an NDEF text tag. Thus, the contactless card's functionality is adapted to provide a unique one-time password as part of the near field wireless data exchange communication, as described below.

[0060] FIG. 5 illustrates an exemplary NDEF short record layout (SR=1) 500 according to an exemplary embodiment. NDEF messages provide a standardized method for client device 110 to communicate with contactless card 105. In some examples, an NDEF message may comprise one or more records. NDEF record 500 includes a header 502 containing several flags that define how to interpret the rest of the record, including a start-of-message (MB) flag 503a, an end-of-message (ME) flag 503b, a chunk flag (CF) 503c, a short record (SR) flag 503d, an ID length (IL) flag 503e, and a type name format (TNF) field 503f. MB 503a and ME flag 503b may be set to indicate the first and last records, respectively, of the message. CF 503c and IL flag 503e provide information about the record, including whether the data is "chunked" (data spread across multiple records within a message) or whether an ID type length field 508 is relevant, respectively. If there is only one record in the message, the SR flag 503d may be set.

[0061] The TNF field 503f identifies the type of content the field contains, as defined by the NFC protocol. These types include empty, well-known (data defined in the NFC Forum's Record Type Definition (RTD)), Multipurpose Internet Mail Extensions (MIME) [defined in RFC2046], absolute Uniform Resource Identifier [defined in RFC3986], foreign (user-defined), unknown, unchanged [for chunks], and reserved.

[0062] Other fields in an NFC record include type length 504, payload length 506, ID length 508, type 510, ID 512, and payload 514. Type length field 504 specifies the exact type of data found in the payload. Payload length 506 contains the length of the payload in bytes. A record can contain up to 4,294,967,295 bytes (or 2^32-1 bytes) of data. ID length 508 contains the length of the ID field in bytes. Type 510 identifies the type of data contained in the payload. For example, for authentication purposes, type 510 may indicate that the payload contains a username / password pair. ID field 512 provides a means for external applications to identify the entire payload carried within the NDEF record. Payload 514 comprises the message.

[0063] In some examples, data may be initially stored on the contactless card by implementing STORE DATA (E2) under a secure channel protocol. This data may include a personal user ID (pUID) or other username unique to the card, and cryptographic processing data including one or more initial keys, session keys, data encryption keys, random numbers, and other values ​​described in more detail below. In other embodiments, the pUID or other username may be pre-loaded onto the contactless card before delivering the contactless card to the client. In some embodiments, the username may be automatically generated by the service provider.

[0064] In some embodiments, a unique username may be provided for each service provider applet / service. In some embodiments, the username may be automatically generated by the service provider and unknown to the client. In other embodiments, the username may be selected by the client as part of a registration process with the service provider application and downloaded to the contactless card as part of the registration process. Thus, the username may comprise any combination of automatically generated or predefined data stored in the applet or other part of the contactless card's memory, include a pUID, be a distinct value, and / or be encrypted or encoded using a hash value or key on the contactless card.

[0065] For example, each of the client and authentication server may use one or more hash algorithms, including but not limited to the SHA-2 algorithm, to encode the username. Alternatively, the encryption algorithm that may be used to encrypt / decrypt the username and / or ciphertext payload may be selected from a group including at least one of a symmetric encryption algorithm, an HMAC algorithm, and a CMAC algorithm. Non-limiting examples of symmetric algorithms that may be used to encrypt the username and / or ciphertext may include a symmetric encryption algorithm such as 3DES (Triple Data Encryption Algorithm) or Advanced Encryption Standard (AES) 128, a symmetric hash-based message authentication (HMAC) algorithm such as HMAC-SHA-256, or a symmetric cipher-based message authentication code (CMAC) algorithm such as AES-CMAC. Many forms of encryption are known to those skilled in the art, and it is understood that the present disclosure is not limited to those specifically identified herein.

[0066] Following initialization, both the contactless card, the client device applet, and / or the authentication server store information to uniquely identify the cardholder via the username / dynamic password authentication process described herein.

[0067] FIG. 6 illustrates a communication system 600 in which a contactless card 610 may store information that can be used during first factor authentication. As described with respect to FIG. 4, each contactless card may include a microprocessor 612 and memory 616 for customer information 618, including one or more uniquely identifying attributes such as an identifier, a key, a random number, etc. In one aspect, the memory further includes an authentication applet 617 that is operable when executed by the microprocessor 612 to control the authentication process described herein. As noted above, a username 618 may be stored as part of the applet and / or as part of the customer information 618. Additionally, each card 610 may include one or more counters 614 and an interface 615. In one embodiment, the interface operates NFC or other communication protocols.

[0068] The client device 620 includes a contactless card interface 625 for communicating with a contactless card and one or more other network interfaces (not shown) that enable the device 620 to communicate with a service provider using various communication protocols, as described above. The client device may further include a user interface 626, which may include one or more of a keyboard or a touchscreen display, that enables communication between a service provider application and a user of the client device 620. The client device 620 further includes a processor 624 and a memory 622 that stores information and program code that, when executed by the processor, controls the operation of the client device 620, including a client-side application 623 that may be provided to a client by a service provider to facilitate access to and use of the service provider application. In one embodiment, the client-side application 623 includes program code configured to communicate authentication information, including a username and dynamic password, from the contactless card 610 to one or more services offered by the service provider. The client-side application 623 may be controlled via input received at a service provider (SP) application interface 627, which is displayed on the user interface 626. For example, a user may select an icon, link, or other mechanism provided as part of the SP application interface 627 to launch a client-side application and access the SP application services, part of the launch including verifying the client using a cryptographic exchange.

[0069] In an exemplary embodiment, the ciphertext exchange includes a transmitting device having a processor and memory, the transmitting device's memory including a master key, transmitted data, and a counter value. The transmitting device is in communication with a receiving device having a processor and memory, the receiving device's memory including the master key. The transmitting device may be configured to generate a diversified key using the master key and one or more encryption algorithms, store the diversified key in the transmitting device's memory, encrypt a counter value using the one or more encryption algorithms and the diversified key to generate an encrypted counter value, encrypt transmitted data using the one or more encryption algorithms and the diversified key to generate encrypted transmitted data, and transmit the encrypted counter value and the encrypted transmitted data as ciphertext to the receiving device. The receiving device may be configured to generate the diversified key based on the stored master key and the stored counter value, store the diversified key in the receiving device's memory, and decrypt the encrypted ciphertext (comprising the encrypted counter and the encrypted transmitted data) using one or more decryption algorithms and the diversified key. The receiving device may authenticate the transmitting device in response to a match between the decrypted counter and the stored counter. A counter may then be incremented at each of the sending and receiving devices for subsequent authentication, thereby providing a cryptogram-based dynamic authentication mechanism for sending device / receiving device transactions.

[0070] 1, client device 620 may be connected to various services of service provider 605 and managed by application server 606. In the illustrated embodiment, authentication server 605 and application server 606 are shown as separate components, but it should be understood that an application server may include all of the functionality described as being included in an authentication server.

[0071] Application server 606 is shown to include an interface 607 and application program code 608. The interface may include a network interface programmed to communicate with other network members over network 630 using the network's protocols, and application program code 608 stored in non-transitory storage of application server 606 and operable when executed by a central processing unit (CPU 609) to perform the functions described herein.

[0072] Authentication server 650 is shown to include a network interface 653 for communicating with network members via network 630 and a central processing unit (CPU) 659. The authentication server may include a non-transitory storage medium for storing a client information table 652 containing information related to the service provider's clients. Such information may include, but is not limited to, the client's username, the client's personal identifier, and the client's cryptographic keys and counters. In one embodiment, the authentication server further includes a client counter value table 656 that may be used as described below to perform authentication in conjunction with contactless card 610. Authentication unit 654 includes hardware and software for performing various authentication processes described with reference to FIGS. 7 and 8 for clients using information from tables 652 and 656.

[0073] FIG. 7 illustrates various steps of a setup process 700 that may be performed to enable password-less login to an application service using cryptographic text exchange. At step 710, a client's contactless card is registered with the application service. Registration may be performed online, offline, or a combination thereof. As part of registration, the client's username may be stored in a client information database on one or both of the application server and the authentication server. In some embodiments, the client's username may be automatically generated by the service provider, unknown to the client, and loaded into both the service provider's client information table and an applet downloaded to the contactless card before or after the contactless card is delivered to the client. In alternative embodiments, the client may be informed of the username and / or self-select a username for storage on the contactless card. The self-selected username may be written to the contactless card using the NFC interface described above. Such self-selection may instead occur when registering the card with the application service or as part of the process of issuing the contactless card to the client, with a self-selected password embedded in the contactless card upon delivery to the client.

[0074] While there may be advantages to allowing the client to self-select or know a username, knowledge of the username is not a requirement of the passwordless authentication protocol described herein because username and dynamic password information is communicated electronically between the card, NFC-enabled device, and application server without client intervention. Such an arrangement mitigates the risks associated with malicious eavesdroppers in username / password authentication schemes.

[0075] At step 720, the contactless card is bound to the client. In particular, the contactless card's username, pUID, etc. are stored as part of the client's digital identity at the service provider. The digital identity may include, for example, single sign-on (SSO) information, a profile reference identifier, or other client identifier.

[0076] Once the card is registered with the client, the client and card combination may be bound to one or more client devices in step 730. For example, the digital identity may also include client device information such as a unique identifier associated with the user device (e.g., a phone number, an Internet Protocol (IP) address, a network identifier, a Mobile Equipment Identifier (MEID), an International Mobile Subscriber Identity (IMSI), a serial number, a Media Access Control (MAC) address, etc.), application information related to the application used to capture the image (e.g., an identifier for the instance of the application, an application version of the application, a session identifier, etc.), etc.

[0077] Once triangulation between the client, card, and client device is established, the contactless card may be used to support multi-factor secure passwordless login for client applications running on any client device, in step 740. More generally, a cryptogram exchange including an encrypted username and dynamic password may be used to provide multi-factor secure passwordless login for client application access.

[0078] 8 is a data flow diagram 800 provided to illustrate an exemplary embodiment of a system and method for secure passwordless login using a username / dynamic password pair provided as part of a cryptogram exchange between a contactless card and a client device. In this example, an application launch request is received from a client by selecting an access option on a website associated with an application supported by an application server, making the application accessible to the client via a web browser application.

[0079] In the embodiment of Figure 8, the client, contactless card, and client device have been pre-registered with the application using a method similar to that described with respect to Figure 7, and a user of web device 810 seeking access to the application utilizes this association by selecting a contactless card authentication option on the application login page displayed on web device 810. As a result, a contactless card authentication request is forwarded to application server 820 in step 801.

[0080] The application server may use information contained in the request to identify the client sourcing the access request based on, for example, the IP or MAC address of the web device or other device identification attributes of the application access request, including, but not limited to, cookie data stored by the browser on the web device 810 during a previous access to the application, such as when the client registered with the application.

[0081] Upon receiving the activation request, the application server 820 may obtain client device information associated with the client, including, for example, identification of one or more devices of the client (e.g., client NFC-enabled device 830) that include authentication hardware that supports contactless card cryptogram exchange (e.g., including, but not limited to, components shown within the client device 620).

[0082] In some embodiments, web device 810 and client NFC-enabled device 830 may be the same device. In other embodiments, web device 810 and client NFC-enabled device 830 may comprise different devices. For example, in one embodiment, web device 810 may comprise a laptop device and client NFC-enabled device 830 may comprise a mobile phone, both of which have been previously bound to the client. In either embodiment, NFC-enabled device 830 may work in conjunction with contactless card 840 to authenticate web-based access by web device 810.

[0083] In step 802, in response to the access request, the application server 820 establishes a communications link with the client NFC-enabled device 830 and forwards a notification to the client NFC-enabled device over the communications link. The notification may be a visual or audible indication that an access request for an application registered with the client has been received. The notification may additionally include a prompt for action by the client. The prompt may take various forms and may include one or more mechanisms that allow the client to approve access.

[0084] By way of example, FIG. 9 illustrates exemplary web page data and control mechanisms for a web device 910 and a mobile device 920 configured according to aspects disclosed herein. The web device 910 is shown displaying a publicly accessible main web page 915 of an application service website. According to one aspect, a user may sign in to the application service using several mechanisms, which may be displayed as menu pull-down options 940 upon selection of a sign-in link 925. It may be understood that clients may generally customize the availability and selection of sign-in option types using web browser security settings according to personal preferences, and the present invention is not limited to any particular combination of sign-in options. Rather, a passwordless authentication system is included herein that provides a username and dynamic password pair using a contactless card or other mechanism.

[0085] 9 embodiment, the client selects contactless card sign-in option 905 to initiate the launch of the application. As described with respect to step 802, in response to the selection of contactless card sign-in option 905, the service provider application identifies the client that sent the request using one or more of a web cookie (i.e., information stored in the client device's web browser by the service provider application during the client's previous access to the application), an IP address, a MAC address, or other identifying aspects of the web device. The application service identifies the client's authorization device, i.e., the client's device configured to accept authentication information from the client. This authorization device may comprise, for example, a mobile phone, tablet, or other device with NFC capability that enables authentication using a cryptogram exchange comprising an encrypted username and dynamic password.

[0086] It will be appreciated that the group of client devices configured to approve application access requests may vary depending on the type of approval requested and the capabilities of the particular client device. For example, authentication using facial scanning may utilize an approval device with image processing capabilities, authentication using fingerprint scanning may utilize an approval device with fingerprint scanning capabilities, and authentication using contactless card authentication may utilize an approval device with NFC communication capabilities.

[0087] In the example of FIG. 9, mobile phone 920 is identified as an authorized client device, and the service provider application forwards notification 930 to the authorized device that an attempt has been made to access a service provider application registered to the client. Notification 930 appears as a pop-up alert displayed on the client's phone. The notification may also include a prompt 950 requesting further action by the client. For example, prompt 950 instructs the client to "tap their contactless card to authorize." An alternative prompt requiring only selection of link 955 may be used depending on a determined authentication level threshold for accessing the service provider application.

[0088] 8, if the service provider requests contactless card authentication in step 802, the client engages contactless card 840 with NFC-enabled device 830, for example, by bringing contactless card 840 into NFC proximity with device 830. Contactless card 840 and device 830 may then exchange cryptograms, as described with respect to FIG. 2, and the stored, encrypted username and dynamic password are transferred to the NFC-enabled device.

[0089] According to one embodiment, as described above, the authentication server 850 may be configured to store at least a username, master key information, and counter information for each client. The authentication server 850 may decrypt the encrypted username and compare it to a stored username known to correspond to the client to verify the client's identity. The authentication server 850 may further decrypt the ciphertext using a diversified key generated using the stored counter value and the client's master key and extract the password from the ciphertext. According to one embodiment, the password may comprise or be associated with a counter, so that it can be dynamically updated with each ciphertext exchange between the client and the application server. The authentication server 850 compares the password extracted from the ciphertext with a stored expected password for the client to approve or reject the application request. In step 805, the approval / rejection is forwarded to the client device 830 for communication with the web device 810.

[0090] In one embodiment, communication of the approval / denial of the access request may be provided to the web device 810 via a dedicated secure channel established by the service provider application between the application session established by the web device 810 and the client NFC-enabled device 830. Thus, approval received by the NFC-enabled device 830 may be broadcast over the channel to automatically update the application session of the web device and launch the application. In an alternative embodiment, the application session established by the web device may monitor the communication link established between the application and the NFC-enabled device for notification of approval. The web device may periodically poll the service provider application to determine whether it has received notification of authentication from the NFC-enabled device. Upon receiving approval in step 806, the service provider application grants access to the web device by launching the application in step 807.

[0091] FIG. 10 is a time diagram illustrating the evolution of various displays and controls provided on / by the display interfaces of a web device 1010 and a mobile phone 1020 over time during the passwordless login technique disclosed herein. Web page 1010A shows a public login page of an application service running on the web device 1010. Display 1020A shows the mobile phone 1020 in an initial, quiescent state. As described with respect to FIG. 8, when a client attempts to access a service provider application, the access request is converted into an authentication request that is forwarded to the mobile phone device 1020 identified in step 1004, and a notification 1025 is displayed as a mobile phone display 1020B. As described above, the notification may include a prompt, such as asking the client to approve the request using an input mechanism such as link selection 1026. In some embodiments, while the application service is communicating with the client device 1020 / contactless card / authentication server, in step 1002, the web device 1010 display 1010B includes a notification that the application is awaiting client authentication.

[0092] In some embodiments, following an initial authentication establishing possession (i.e., the client possesses a known mobile device), the application service may further prompt for alternative forms of authentication, including those establishing identity and / or knowledge. Such a configuration enables at least two-factor authentication with passwordless login. Such forms of authentication include, but are not limited to, a facial scan, a fingerprint scan, a query / response challenge, a cryptogram username / dynamic password exchange, etc. In such an embodiment, at step 1006, the mobile phone display 1020C may include an additional prompt 1027 requesting a second factor of authentication, such as a facial scan, biometric authentication, or a contactless card cryptogram exchange. Following receipt and verification of the second factor of authentication, at step 1008, approval is conditionally forwarded to the application service, and at step 1009, the application service website display 1010C is updated to allow access by the client.

[0093] 11A and 11B are time diagrams illustrating the evolution of various displays and controls provided on / by a display interface of a mobile phone 1120 over time, configured to implement the passwordless login techniques disclosed herein. Web page 1110 shows a public login page for an application service running on the web device 1120. When a client attempts to access a service provider application from a mobile phone device, a first factor authentication menu 1125 may be displayed to the user, including the selection option of a “contactless card login” option 1105. The user may tap a contactless card 1115 to the mobile device's NFC reader to satisfy the first factor authentication. Authentication using the above process proceeds with the mobile phone 1120 exchanging cryptographic authentication information with an authentication server.

[0094] After successful contactless card authentication, a second factor authentication may be required before granting access to the application service, as shown in FIG. 11B. In FIG. 11B, the second factor authentication is shown to include biometric thumbprint authentication, although other technologies such as facial scanning, voice recognition, eye scanning, etc. may be substituted. In some embodiments, the user may select the form of second factor authentication to use. In other embodiments, the application may select the form of second factor authentication. In any case, successful biometric authentication enables client access to the application service.

[0095] Thus, a system and method for secure, passwordless authentication using a cryptographic exchange including a username and a dynamic password for purposes of multi-factor authentication has been shown and described. Such an arrangement advantageously enhances application security by using unpredictable, dynamically encoded username-password pairs and a protocol that provides multi-factor authentication prior to application access.

[0096] As used in this application, the terms "system," "component," and "unit" are intended to refer to a computer-related entity that is either hardware, a combination of hardware and software, software, or software in execution, examples of which are described herein. For example, a component may be, but is not limited to, a process running on a processor, a processor, a hard disk drive, multiple storage drives, a non-transitory computer-readable medium (either optical and / or magnetic storage media), an object, an executable, a thread of execution, a program, and / or a computer. Illustratively, both an application running on a server and the server may be a component. One or more components may reside within a process and / or thread of execution, and a component may be localized on one computer and / or distributed across two or more computers.

[0097] Additionally, components may be communicatively coupled to one another by various types of communication media to coordinate operations. Coordination may include one-way or two-way information exchange. For example, components may communicate information in the form of signals communicated over the communication media. This information may be embodied as signals assigned to various signal lines. In such an assignment, each message is a signal. However, further embodiments may alternatively use data messages. Such data messages may be transmitted over various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0098] Some embodiments may be described using the phrase "in one embodiment" or "embodiment," along with derivatives thereof. These terms mean that a particular feature, structure, or characteristic described in connection with an embodiment is included in at least one embodiment. The appearances of the phrase "in one embodiment" in various places in this specification do not necessarily all refer to the same embodiment. Furthermore, unless otherwise noted, it is recognized that the above features can be used together in any combination. Thus, any features discussed separately can be used in combination with each other unless it is noted that the features are not compatible with each other.

[0099]

[0013] Generally, reference is made to the notation and nomenclature used herein, and the detailed descriptions herein may be presented in terms of functional blocks or units that can be implemented as program procedures executed on a computer or network of computers. These procedural descriptions and representations are used by those skilled in the art to most effectively convey the substance of their work to others skilled in the art.

[0100] A procedure is herein and generally conceived to be a self-consistent sequence of operations leading to a desired result. These operations are those requiring physical manipulation of physical quantities. Usually, though not necessarily, these quantities take the form of electrical, magnetic, or optical signals capable of being stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient, principally for reasons of common usage, to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, or the like. It should be borne in mind, however, that all of these and similar terms are to be associated with the appropriate physical quantities and are merely convenient labels applied to these quantities.

[0101] Further, the manipulations performed are often referred to in terms, such as adding or comparing, which are commonly associated with mental operations performed by a human operator. No such capability of a human operator is necessary, or desirable in most cases, in any of the operations described herein that form part of one or more embodiments. Rather, the operations are machine operations. Useful machines for performing the operations of various embodiments include general purpose digital computers or similar devices.

[0102] Some embodiments may be described using the terms "coupled" and "connected," along with derivatives thereof. These terms are not necessarily intended as synonyms for each other. For example, some embodiments may be described using the terms "connected" and / or "coupled" to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term "coupled" may also mean that two or more elements are not in direct contact with each other, but yet still cooperate or interact with each other.

[0103] It is emphasized that this Abstract of the Disclosure is provided to allow the reader to quickly ascertain the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Moreover, in the foregoing Detailed Description, various features are grouped together in a single embodiment to streamline the disclosure. This method of disclosure is not to be interpreted as reflecting an intention that the claimed embodiments require more features than are expressly recited in each claim. Rather, as the following claims reflect, inventive subject matter lies in fewer than all features of a single disclosed embodiment. Accordingly, the following claims are hereby incorporated into the Detailed Description, with each claim standing on its own as a separate embodiment. In the appended claims, the terms "comprising" and "wherein" are used as the plain-English equivalents of the respective terms "comprising" and "wherein." Furthermore, the terms "first," "second," "third," etc. are used merely as labels and are not intended to impose numerical requirements on their subject matter.

[0104] What has been described above includes examples of the disclosed architecture. Of course, it is not possible to describe every conceivable combination of components and / or methodologies, but one of ordinary skill in the art will recognize that many more combinations and permutations are possible. Accordingly, the novel architecture is intended to embrace all such alterations, modifications, and variations that fall within the spirit and scope of the appended claims.

Claims

1. A method of registering a contactless card by one or more servers storing a user name and a dynamic password in a database of each of the one or more servers; the one or more servers binding the client to the contactless card by storing the username and client identifier in the database as the client's digital identity; the one or more servers binding the client and the contactless card to one or more client devices by storing client device information and application information in the client's digital identity, the client device information including a device identifier unique to each of the one or more client devices, and the application information including an application identifier; at least one of the servers authenticating the contactless card based on receiving the username and the dynamic password from the contactless card via the client device, wherein at least the username is encoded using a hashing algorithm and the dynamic password is associated with a counter maintained for the client and a number of times the username is retrieved from the contactless card; A method comprising:

2. the one or more client devices include a first client device and a second client device; the first client device and the second client device are configured as different devices; the second client device is used to authenticate requests made by the first client device; The method of claim 1.

3. The method comprises: The client device further includes launching an application; launching the application includes establishing a communications link between a web session associated with the request and the second client device to enable the second client device to transfer authentication to the web session to launch the application on the client device. The method of claim 2.

4. The method comprises: and further comprising the client device launching an application. launching the application includes monitoring communications of the second client device to detect approval of the request, and selectively launching the application at the client device in response to detecting the approval. The method of claim 2.

5. The method comprises: further comprising prompting the client to retrieve the username and the dynamic password from a contactless card associated with the client. The method of claim 1.

6. the first client device and the second client device are configured as the same device; The method of claim 2.

7. one of the servers registers a username for the client and binds the contactless card to the client prior to communication with the one or more client devices; The method of claim 1.

8. one of the servers generates a username for the client; The method of claim 7.

9. one of the servers receiving the username from the client via one of the client devices; The method of claim 1.

10. the client identifier includes a user identifier (UID) and an application identifier; The method of claim 1.

11. 1. A system for controlling access to an application by a client, comprising: The system comprises: Memory and one or more processors; the one or more processors are coupled to the memory and execute program code stored in the memory to perform predetermined operations; The operation is storing a user name and a dynamic password for the contactless card in a database on a server; storing said username and client identifier in a client digital identity in said database; storing client device information and application information in the client's digital identity, the client device information including a device identifier unique to each of one or more client devices, and the application information including an application identifier; authenticating the contactless card based on receiving the username and the dynamic password from the contactless card via one of the client devices, wherein at least the username is encoded using a hashing algorithm and the dynamic password is associated with a counter maintained for the client and the number of times the username is retrieved from the contactless card; Including, the system.

12. the one or more client devices include a first client device and a second client device; the first client device and the second client device are configured as different devices; the second client device is used to authenticate requests made by the first client device to access applications; The system of claim 11.

13. further comprising launching the application; launching the application includes establishing a communications link between a web session associated with the request and the second client device to enable the second client device to transfer authentication to the web session for launching the application. The system of claim 12.

14. further comprising launching the application; launching the application includes monitoring communications of the second client device to detect approval of the request, and selectively launching the application in response to detecting the approval. The system of claim 12.

15. the one or more processors registering a username for the client and binding the contactless card to the client prior to communication with the one or more client devices; The system of claim 11.

16. 1. A non-transitory computer-readable storage medium, comprising: comprising instructions that, when executed by a computer, cause the computer to perform predetermined operations; The operation is registering the contactless card by storing a username and a dynamic password in a database; binding the client to the contactless card by storing the username and client identifier in a database as the client's digital identity; binding the client and the contactless card to one or more client devices by storing in the client's digital identity a device identifier and an application identifier unique to each of the one or more client devices; authenticating the contactless card based on receiving the username and the dynamic password from the contactless card via one of the client devices, wherein at least the username is encoded using a hashing algorithm and the dynamic password is associated with a counter maintained for the client and the number of times the username is retrieved from the contactless card; A non-transitory computer-readable storage medium.

17. the program code is further configured to prompt the client to retrieve the username and the dynamic password from the contactless card associated with the client.

17. The computer-readable storage medium of claim 16.

18. 17. The computer-readable storage medium of claim 16, wherein the program code is further configured to register a username for the client and bind the contactless card to the client prior to communication with the one or more client devices.

19. at least one entry in a client table of said database comprises a master key and a counter associated with said client; 17. The computer-readable storage medium of claim 16.

20. the client identifier includes a user identifier (UID); the application identifier includes an identifier of an instance of an application, a version of the application, a session identifier, or a combination thereof; 17. The computer-readable storage medium of claim 16.

Citation Information

Patent Citations

  • One-time password generator, authentication method and recording medium with one-time password generating program recorded therein

    JP2001352324A

  • Information management device, id tag, information management method and information management program

    JP2006209254A

  • Method for generating onetime password, IC card system, and IC card

    JP2009271836A

  • System and method for secure transaction processes using mobile devices

    JP2015519637A

  • Method and apparatus for dynamic authentication

    US20130318575A1