A system for loading value into in-vehicle devices

NFC contactless smart cards facilitate rapid and secure value loading onto in-vehicle devices, addressing the inefficiencies of traditional methods by enabling one-tap transactions directly within vehicles.

JP7835670B2Active Publication Date: 2026-03-25CAPITAL ONE SERVICES LLC
View PDF 5 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-07-10
Publication Date
2026-03-25

AI Technical Summary

Technical Problem

Existing methods for loading value onto in-vehicle devices, such as toll transponders, are cumbersome and time-consuming, often requiring users to log into online accounts and enter payment information just before transactions, especially in time-constrained situations.

Method used

The use of near-field communication (NFC) contactless cards for one-tap authentication and payment to quickly and securely load value onto in-vehicle devices, eliminating the need for online account access and enabling transactions directly within the vehicle.

Benefits of technology

Enables fast, efficient, and secure loading of value onto in-vehicle devices, allowing transactions to be completed quickly and simply even in time-constrained scenarios, such as approaching a toll booth, by using NFC-enabled contactless smart cards for authentication and payment.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007835670000001
    Figure 0007835670000001
  • Figure 0007835670000002
    Figure 0007835670000002
  • Figure 0007835670000003
    Figure 0007835670000003
Patent Text Reader

Abstract

Various embodiments are directed to conducting one or more transactions in a vehicle using a near field communication (NFC) contactless card. For example, a user can load value (money, funds, digital currency, etc.) onto an in-vehicle device (e.g., a transponder, badge, card, etc.) with one-tap authentication and / or one-tap payment via the contactless card. Thus, payments can be loaded onto the in-vehicle device quickly, efficiently, and securely, even under time-sensitive circumstances.
Need to check novelty before this filing date? Find Prior Art

Description

Cross-reference to Related Applications

[0001] This application claims priority to U.S. Patent Application No. 16 / 514,427, filed July 17, 2019, entitled "System for Loading Value onto an In-Vehicle Device". The entire contents of the aforementioned patent application are hereby incorporated by reference in their entirety. BACKGROUND OF THE INVENTION

[0002] Today, more and more transactions are being carried out inside vehicles. For example, a toll transponder placed inside a vehicle can be used to pay tolls when the vehicle passes through a toll booth or a transponder reader. In another example, a garage transponder or badge can be used to enter and park a vehicle in a parking garage. Other types of in-vehicle transactions may involve payments such as drive-thru services and event access parking passes.

[0003] Typically, a customer loads value onto a payment device such as the above-mentioned toll and garage transponders, badges, etc. by logging into an online account and entering payment information. However, in many cases, the customer needs to load payment onto the device in a time-constrained situation, such as just before approaching a toll booth.

[0004] Therefore, there is a need for a quick and efficient method for loading value onto an in-vehicle device. SUMMARY OF THE INVENTION

[0005] Various embodiments are intended to enable the execution of one or more transactions within a vehicle using near-field communication (NFC) contactless cards. For example, a user can load value (money, funds, digital currency, etc.) onto an in-vehicle device (transponder, badge, card, etc.) by performing one-tap authentication or one-tap payment, or both, via a contactless card. Thus, even in time-constrained situations, payments can be loaded onto the in-vehicle device in a fast, efficient, and secure manner. [Brief explanation of the drawing]

[0006] [Figure 1A] Figure 1A shows an exemplary data transmission system according to one or more embodiments. [Figure 1B] Figure 1B shows an exemplary sequence diagram for providing authenticated access by one or more embodiments. [Figure 2] Figure 2 shows an exemplary system using a contactless card according to one or more embodiments. [Figure 3A] Figure 3A shows examples of contactless cards according to one or more embodiments. [Figure 3B] Figure 3B shows examples of contact pads for contactless cards according to one or more embodiments. [Figure 4] Figure 4 shows an exemplary sequence diagram relating to secure password generation by one or more embodiments. [Figure 5] Figure 5 shows an example of password generation for a password manager application according to one or more embodiments. [Figure 6] Figure 6 shows another example of a sequence diagram relating to secure password generation by one or more embodiments. [Figure 7] Figure 7 shows another example of website password generation using one or more embodiments. [Modes for carrying out the invention]

[0007] Various embodiments generally relate to systems for loading value (e.g., money) into an in-vehicle device using at least a contactless near-field communication (NFC) smart card. In examples, the in-vehicle device may be any suitable device located within or inside a vehicle and may be used to perform various transactions. In some examples, the in-vehicle device may be integrated into the vehicle.

[0008] According to one embodiment, the in-vehicle device may be a toll transponder. If a user wishes to reload or add funds to an existing web-based account corresponding to the toll transponder, the user can tap a mobile computing device, such as a smartphone, on the toll transponder to read one or more types of account-related information so that the mobile computing device can access the account. Thus, for example, when a smartphone is tapped, the smartphone can read a Uniform Resource Locator (URL) from the toll transponder, which allows the smartphone to launch a toll-specific payment application or website. The user can then tap a contactless smart card on the smartphone to reload the account. In the example, the reload amount may be a predetermined value set by the user, for example, $20. It should be understood that the toll transponder is just one example of an in-vehicle device, and is not limited thereto. The in-vehicle device may be any type of transponder that enables the withdrawal of payments from the associated account.

[0009] According to another embodiment, a contactless card may be tapped directly onto an in-vehicle device without the use of a mobile computing device. For example, value (e.g., funds) can be loaded directly onto an in-vehicle transponder via "contactless" authentication and payment (e.g., using a contactless smart card) without the use of an external web-based account.

[0010] In further embodiments, the in-vehicle device may be integrated into the vehicle and coupled to various electronic components of the vehicle. For example, the vehicle may have an interface point for reading a contactless smart card and loading its value. The interface point may be installed on the vehicle's dashboard or center console. In another example, a secure interface may be placed inside the vehicle to securely hold a contactless smart card in place while the user is in the vehicle, and further, to remove it when the user leaves the vehicle. In yet another example, the in-vehicle device integrated into the vehicle may be used as an authentication mechanism for authenticating the vehicle, for example, when entering a parking lot and parking.

[0011] In previous solutions, value loading was a cumbersome process. As mentioned above, users typically had to log in to their online accounts and enter payment information, all of which had to be done before driving the vehicle. And generally, previous solutions failed to effectively coordinate and facilitate transactions within the vehicle. The embodiments and examples described herein offer a breakthrough and advantage over conventional solutions by enabling the rapid loading of value into in-vehicle devices using NFC-enabled contactless smart cards, even in time-constrained situations (e.g., when a vehicle approaches a toll booth or transponder reader). Furthermore, because the contactless card itself is uniquely associated with the user, the card can be used to quickly authenticate the user within the vehicle, for example, in a parking lot.

[0012] Here, drawings are referenced. In the drawings, similar elements are referenced throughout, using similar reference numerals. In the following description, many specific details are given for illustrative purposes to provide a complete understanding. However, it will be clear that new embodiments can be implemented without these specific details. In other examples, well-known structures and devices are shown in block diagram form to facilitate their description. The intention is to cover all modifications, equivalents, and alternatives within the claims.

[0013] Figure 1A shows an exemplary data transmission system in one or more embodiments. As will be further described below, system 100 may include a contactless card 105, a client device 110, a network 115, and a server 120. Although Figure 1A shows a single instance of the components, system 100 may include any number of components.

[0014] The system 100 may include one or more contactless cards 105, which are described further below with reference to Figures 3A and 3B. In some embodiments, the contactless card 105 may communicate wirelessly with the client device 110, for example, by utilizing NFC.

[0015] System 100 may include a client device 110, which may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, computer devices or communication devices, including, for example, servers, network appliances, personal computers, workstations, telephones, smartphones, handheld PCs, personal digital assistants, thin clients, fat clients, internet browsers, or other devices. The client device 110 may also be a mobile computing device, for example, an Apple iPhone, iPod, iPad®, or other suitable device running Apple's iOS® operating system, a device running Microsoft's Windows® Mobile operating system, a device running Google's Android® operating system, and / or other suitable mobile computing devices such as a smartphone, tablet, or similar wearable mobile device.

[0016] The client device 110 includes a processor and memory, and the processing circuitry may include additional components necessary to perform the functions described herein, including a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware. The client device 110 may further include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input devices may include any device available and supported on the user's device for inputting information into the user's device, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, and camcorder. These devices can be used to input information and interact with the software and other devices described herein.

[0017] In some examples, a client device 110 of system 100 may run one or more applications, such as a software application, which enables network communication with one or more components of system 100 and transmits and / or receives data.

[0018] The client device 110 may communicate with one or more servers 120 via one or more networks 115, and each may operate with the server 120 as a front-end and back-end pair. The client device 110 may send one or more requests to the server 120, for example, from a mobile device application running on the client device 110. One or more requests may relate to retrieving data from the server 120. The server 120 may receive one or more requests from the client device 110. Based on one or more requests from the client device 110, the server 120 may be configured to retrieve the requested data from one or more databases (not shown). Based on the receipt of the requested data from one or more databases, the server 120 may be configured to send the received data to the client device 110, and the received data responds to one or more requests.

[0019] System 100 may include one or more networks 115. In some examples, network 115 may be one or more wireless networks, wired networks, or any combination of wireless and wired networks, and may be configured to connect client devices 110 to a server 120. For example, network 115 may include one or more such as optical fiber networks, passive optical networks, cable networks, Internet networks, satellite networks, wireless local area networks (LANs), global systems for mobile communications, personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplexing-based systems, code division multiplexing (CDMA)-based systems, D-AMPS, Wi-Fi®, fixed radio data, IEEE 802.11b, 802.15.1, 802.11n, 802.11g, Bluetooth®, NFC, radio automatic identification (RFID), and / or Wi-Fi.

[0020] Furthermore, network 115 may include, but is not limited to, a telephone line, optical fiber, IEEE Ethernet 802.3, a wide area network, a wireless personal area network, a LAN, or a global network such as the Internet. Further, network 115 may support an Internet network, a wireless communication network, a cellular network, etc., or any combination thereof. Network 115 may further include one network or any number of the above-exemplified types of networks operating as an independent network or cooperating with each other. Network 115 may utilize one or more protocols of one or more network elements that are communicatively coupled. Network 115 may convert from one or more protocols of other protocols to one or more protocols of a network device or from one or more protocols of other protocols to one or more protocols of a network device. Although network 115 is shown as a single network, according to one or more examples, network 115 may include a plurality of interconnected networks, such as, for example, the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, a home network, etc.

[0021] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to a memory. Server 120 may be configured as a central system, server, or platform that controls and invokes various data at different times to execute a plurality of workflow actions. Server 120 may be configured to connect to one or more databases. Server 120 may be connected to at least one client device 110.

[0022] Figure 1B shows an exemplary sequence diagram for providing authenticated access according to one or more embodiments. This figure includes a contactless card 105 and a client device 110, and the client device 110 may include an application 122 and a processor 124. Figure 1B may refer to components similar to those in Figure 1A.

[0023] In step 102, the application 122 communicates with the contactless card 105 (e.g., after being brought close to the contactless card 105). The communication between the application 122 and the contactless card 105 may include the contactless card 105 being sufficiently close to a card reader (not shown) of the client device 110 to enable NFC data transfer between the application 122 and the contactless card 105.

[0024] In step 104, after communication is established between the client device 110 and the contactless card 105, the contactless card 105 generates a message authentication code (MAC) cipher. In some examples, this may occur when the contactless card 105 is read by the application 122. In particular, this may occur upon reading, such as NFC reading, of a Near Field Data Exchange (NDEF) tag generated according to the NFC data exchange format.

[0025] For example, a reader such as application 122 may send a message such as an applet selection message having the applet ID of the NDEF generation applet. Once the selection is confirmed, a sequence of file selection messages followed by file reading messages may be sent. For example, the sequence may include "Select function file", "Read function file", and "Select NDEF file". At this point, a counter value held by the contactless card 105 may be updated or incremented, followed by "Read NDEF file". At this point, a message may be generated that may include a header and a shared secret key. Subsequently, a session key may be generated. The MAC cipher may then be concatenated with one or more blocks of random data, and the MAC cipher and random numbers (RND) may be encrypted with the session key. The ciphertext and header may then be concatenated, encoded in ASCII hexadecimal, and returned in NDEF message format (in response to the "Read NDEF file" message).

[0026] In some examples, the MAC cipher may be transmitted as an NDEF tag, while in other examples, the MAC cipher may be included with the Uniform Resource Indicator (for example, as a formatted string).

[0027] In some examples, application 122 may be configured to send a request to contactless card 105, the request including an instruction to generate a MAC encryption.

[0028] In step 106, the contactless card 105 transmits the MAC encryption to the application 122. In some examples, the transmission of the MAC encryption is done via NFC. However, this disclosure is not limited to this. In other examples, this communication may be done via Bluetooth, Wi-Fi, or other means of wireless data communication.

[0029] In step 108, application 122 transmits the MAC cipher to processor 124. In step 112, processor 124 verifies the MAC cipher according to instructions from application 122. For example, the MAC cipher may be verified as described below.

[0030] In some examples, MAC encryption verification may be performed by a device other than the client device 110, such as a server 120 communicating data with the client device 110 (as shown in Figure 1A). For example, the processor 124 may output MAC encryption for transmission to the server 120, which can then verify the MAC encryption.

[0031] In some cases, MAC encryption can function as a digital signature for verification purposes. To perform this verification, a public-key asymmetric algorithm, such as the RSA algorithm or other digital signature algorithms like zero-knowledge protocols, may be used.

[0032] In some examples, it is understood that the contactless card 105 may initiate communication after the contactless card is brought close to the client device 110. For example, the contactless card 105 may send a message to the client device 110 indicating that the contactless card has established communication. The application 122 on the client device 110 may then proceed with communication with the contactless card in step 102, as described above.

[0033] Figure 2 shows an example of a system 200 using a contactless card. System 200 may include a contactless card 205, one or more client devices 210, a network 215, servers 220, 225, one or more hardware security modules 230, and a database 235. Although Figure 2 shows a single instance of the components, system 200 may include any number of components.

[0034] The system 200 may include one or more contactless cards 205, which are further described below with reference to Figures 3A and 3B. In some examples, the contactless card 205 may communicate wirelessly with the client device 210, for example, through NFC communication. For example, the contactless card 205 may include one or more chips, such as RFID chips, configured to communicate via NFC or other near-field protocols. In other embodiments, the contactless card 205 may communicate with the client device 210 via other means, including but not limited to Bluetooth, satellite, Wi-Fi, wired communication, and / or any combination of wireless and wired connections. According to some embodiments, the contactless card 205 may be configured to communicate with the card reader 213 of the client device 210 (hereinafter also referred to herein as an NFC reader, NFC card reader, or reader) via NFC when the contactless card 205 is within range of the card reader 213. In other examples, communication with the contactless card 205 may be achieved via a physical interface, such as a universal serial bus interface or a card swipe interface.

[0035] System 200 may include client devices 210, which may be network-enabled computers. As referred to herein, network-enabled computers may include, but are not limited to, computer devices or communication devices, including, for example, servers, network appliances, personal computers, workstations, mobile devices, telephones, handheld PCs, personal digital assistants, thin clients, fat clients, internet browsers, or other devices. One or more client devices 210 may also be mobile devices. For example, a mobile device may include Apple's iPhone, iPod, iPad, or other mobile devices running Apple's iOS operating system, any device running Microsoft's Windows Mobile operating system, any device running Google's Android operating system, and / or other smartphones or similar wearable mobile devices. In some examples, client device 210 may be identical or similar to client device 110 as described with reference to Figure 1A or Figure 1B.

[0036] A client device 210 can communicate with one or more servers 220 and 225 via one or more networks 215. For example, an application 211 running on the client device 210 may send one or more requests to one or more servers 220 and 225. One or more requests may relate to retrieving data from one or more servers 220 and 225. Servers 220 and 225 may receive one or more requests from the client device 210. Based on one or more requests from the client device 210, one or more servers 220 and 225 may be configured to retrieve the requested data from one or more databases 235. Based on the receipt of the requested data from one or more databases 235, one or more servers 220 and 225 may be configured to send the received data to the client device 210 in response to one or more requests.

[0037] System 200 may include one or more hardware security modules (HSMs) 230. For example, one or more HSMs 230 may be configured to perform one or more cryptographic operations disclosed herein. In some examples, one or more HSMs 230 may be configured as special-purpose security devices configured to perform one or more cryptographic operations. The HSMs 230 may be configured such that keys are not exposed outside the HSMs 230 but are instead maintained internally. For example, one or more HSMs 230 may be configured to perform at least one of key derivation, decryption, and MAC calculations. One or more HSMs 230 may be included in or communicate data with servers 220 and 225.

[0038] System 200 may include one or more networks 215. In some examples, network 215 may be one or more wireless networks, wired networks, or any combination of wireless and wired networks, and may be configured to connect client devices 210 to servers 220 and / or 225. For example, network 215 may include one or more fiber optic networks, passive optical networks, cable networks, cellular networks, Internet networks, satellite networks, wireless LANs, Global System for Mobile Communications (GSM), personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplexing-based systems, code division multiple access (CDMA)-based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth, NFC, RFID, Wi-Fi, and / or any combination of those networks. As a non-limiting example, communication between the contactless card 205 and the client device 210 may include NFC communication, a cellular network between the client device 210 and the carrier, and the internet between the carrier and the backend.

[0039] Furthermore, network 215 may include, but is not limited to, telephone lines, fiber optics, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, local area networks, or global networks such as the Internet. In addition, network 215 may support Internet networks, wireless communication networks, cellular networks, or any combination thereof. Network 215 may further include one network or any number of the exemplary types described above, operating as independent networks or in cooperation with one another. Network 215 may utilize one or more protocols of one or more network elements that are communicably coupled. Network 215 may convert from one or more protocols of network devices to one or more protocols of network devices, or from one or more protocols of network devices to another protocol. Although network 215 is shown as a single network, according to one or more examples, network 215 may include multiple interconnected networks, such as the Internet, service provider networks, cable television networks, corporate networks such as credit card association networks, and home networks.

[0040] In various examples provided herein, a client device 210 of system 200 may include one or more applications 211, one or more processors 212, and one or more card readers 213. For example, one or more applications 211, such as software applications, may be configured to enable network communication with one or more components of system 200, for example, to transmit and / or receive data. Although only a single instance of the components of the client device 210 is illustrated in Figure 2, it is understood that any number of devices 210 may be used. The card reader 213 may be configured to read from and / or communicate with a contactless card 205. In conjunction with one or more applications 211, the card reader 213 may communicate with a contactless card 205. In the examples, the card reader 213 may include a circuit or circuit component, such as an NFC reader coil, that generates a magnetic field to enable communication between the client device 210 and the contactless card 205.

[0041] Any application 211 of the client device 210 may communicate with the contactless card 205 using near-field communication (e.g., NFC). The application 211 may be configured to interact with a card reader 213 of the client device 210, which is configured to communicate with the contactless card 205. Those skilled in the art will understand that distances of less than 20 cm are consistent with the range of NFC.

[0042] In some embodiments, application 211 communicates with contactless card 205 via an associated reader (e.g., card reader 213).

[0043] In some embodiments, card activation may be performed without user authentication. For example, a contactless card 205 may communicate with an application 211 via NFC through a card reader 213 on a client device 210. This communication (e.g., tapping the card in close proximity to the card reader 213 on the client device 210) allows the application 211 to read data associated with the card and perform activation. In some cases, the tap may activate or launch the application 211 and then initiate one or more actions or communications with the account server 225 to activate the card for subsequent use. In some cases, if the application 211 is not installed on the client device 210, tapping the card to the card reader 213 may initiate the download of the application 211 (e.g., navigation to the application download page). Following installation, tapping the card may activate or launch the application 211 and then initiate card activation (e.g., via the application or other backend communications). After activation, the card can be used for a variety of transactions, including commercial transactions.

[0044] According to some embodiments, the contactless card 205 may include a virtual payment card. In those embodiments, the application 211 may obtain information related to the contactless card 205 by accessing a digital wallet implemented on the client device 210, the digital wallet including a virtual payment card. In some examples, the virtual payment card data may include one or more statically or dynamically generated virtual card numbers.

[0045] Server 220 may include a web server that communicates with database 235. Server 225 may include an account server. In some examples, server 220 may be configured to verify one or more credentials from contactless card 205 and / or client device 210 by comparing them with one or more credentials in database 235. Server 225 may be configured to authorize one or more requests from contactless card 205 and / or client device 210, such as payments and transactions.

[0046] Figure 3A shows one or more contactless cards 300, which may include payment cards such as credit cards, debit cards, or gift cards issued by a service provider 305, as indicated on the front or back of the card 300. In some examples, the contactless card 300 may include, but is not limited to, an ID card, regardless of whether it is a payment card. In some examples, the payment card may include a dual-interface contactless payment card. The contactless card 300 includes a substrate 310, which may include a single layer or one or more layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 300 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, or the contactless card may conform to the ISO / IEC 14443 standard. However, the contactless card 300 according to this disclosure may have different characteristics, and it should be understood that this disclosure does not require the contactless card to be implemented as a payment card.

[0047] The contactless card 300 may include identification information 315 displayed on the front and / or back of the card, and a contact pad 320. The contact pad 320 may be configured to establish contact with another communication device, such as a user device, smartphone, laptop, desktop, or tablet computer. The contactless card 300 may include processing circuits, antennas, and other components not shown in Figure 3A. These components may be located behind the contact pad 320 or elsewhere on the substrate 310. The contactless card 300 may include a magnetic strip or tape that may be located on the back of the card (not shown in Figure 3A).

[0048] As shown in Figure 3B, the contact pad 320 in Figure 3A may include a processing circuit 325 for storing and processing information, which includes a microprocessor 330 and memory 335. It is understood that the processing circuit 325 may include additional components, as necessary to perform the functions described herein, including a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware.

[0049] Memory 335 may be read-only memory, write-once / read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 300 may include one or more of these memories. Read-only memory may be programmable as read-only at the factory, or it may be programmable only once. If it is programmable only once, it can be read multiple times after being written to once. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once the memory is programmed, it cannot be rewritten but can be read multiple times. Read / write memory may be programmed and reprogrammed multiple times after leaving the factory. Read / write memory may also be read multiple times after leaving the factory.

[0050] The memory 335 may be configured to store one or more applets 340, one or more counters 345, and one or more customer identifiers 350. The one or more applets 340 may include one or more software applications configured to run on one or more contactless cards, such as Java® card applets. However, it is understood that the applet 340 is not limited to Java card applets, but may instead be any software application capable of running on contactless cards or other devices with limited memory. The one or more counters 345 may include numeric counters sufficient to store integers. The customer identifiers 350 may include unique alphanumeric identifiers assigned to users of contactless cards 300, the identifiers which can distinguish users of contactless cards from users of other contactless cards. In some examples, the customer identifiers 350 may identify both the customer and the account assigned to that customer, and further, the contactless card associated with the customer's account.

[0051] The processor and memory elements of the exemplary embodiments described above are described with reference to the contact pads, but the disclosure is not limited thereto. These elements may be mounted outside the pads 320, completely separate from the pads 320, or as additional elements in addition to the elements of the processor 330 and memory 335 located within the contact pads 320.

[0052] In some examples, the contactless card 300 may include one or more antennas 355. The one or more antennas 355 may be located inside the contactless card 300 and around the processing circuit 325 of the contact pad 320. For example, the one or more antennas 355 may be integrated with the processing circuit 325, or the one or more antennas 355 may be used with an external booster coil. In another example, the one or more antennas 355 may be located outside the contact pad 320 and the processing circuit 325.

[0053] In one embodiment, the coil of the contactless card 300 may function as the secondary side of an air-core transformer. The terminal may communicate with the contactless card 300 by cutting power or amplitude modulation. The contactless card 300 may infer data transmitted from the terminal using a gap in the contactless card's power connection, which is functionally maintained through one or more capacitors. The contactless card 300 may communicate back by switching or load modulation of the coil of the contactless card. Load modulation may be detected in the terminal's coil by interference.

[0054] As described above, the contactless card 300 is built on a software platform capable of running on smart cards or other devices with limited memory, such as a smart card or JavaCard, and one or more applications or applets can be securely executed on it. Applets can be added to the contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in various mobile application-based use cases. An applet can be configured to generate an NDEF message containing a cryptographically secure OTP encoded as an NDEF text tag in response to one or more requests, such as a near-field data exchange request from a reader, such as a mobile NFC reader.

[0055] Figure 4 shows an exemplary sequence diagram 400 for loading value into an in-vehicle device 404 using a mobile computing device 402 and a contactless card 406, according to one or more embodiments. The mobile computing device 402 may be a client device such as a smartphone, laptop, tablet computer, or wearable computer, configured to send and receive information with the in-vehicle device 404 and the contactless card 406. As described above, the mobile computing device 402 may include at least an NFC card reader configured to establish NFC communication with the contactless card 406.

[0056] In step 412, the mobile computing device 402 may receive or obtain a unique identifier (ID) associated with the in-vehicle device 404. For example, the in-vehicle device 404 may be a toll transponder, a drive-through payment service device, a garage access transponder or badge, a parking pass, etc. The unique ID associated with the in-vehicle device 404 may be obtained from one or more barcodes displayed thereon, or from other appropriate identifiers such as an in-vehicle device number, name, transponder identification number, account number associated with a drive-through payment service, badge number associated with a garage access transponder or badge, or pass number corresponding to a parking pass. In another example, the in-vehicle device 404 may include one or more NFC tags or radio automatic identification (RFID) tags that can transmit unique ID information. Furthermore, the computing device 402 may receive or obtain information for accessing an account (online or otherwise) associated with the in-vehicle device 404. For example, the information may include at least a Uniform Resource Locator (URL) for accessing an online account.

[0057] Upon receiving the unique ID of the in-vehicle device 404 and information for accessing the account associated with the device, in step 414, the mobile computing device 402 may access the account associated with the device and load at least funds into the account.

[0058] In step 416, communication may be established between the mobile computing device 402 and the contactless card 406. In one example, communication may be established automatically when the contactless card enters the magnetic field generated by the NFC reader of the mobile computing device 402. In another example, the mobile computing device 402 may first establish communication by sending a signal to the contactless card 406 when the computing device 402 detects that the contactless card 406 has entered the magnetic field of the NFC reader. As described below, the user can use the contactless card 406 to perform one-tap authentication and one-tap payment on the mobile computing device 402, which, advantageously, allows for quick and simple value loading processing while the user is in the vehicle.

[0059] In step 418, value (e.g., funds, digital currency, entity or business-specific value) may be loaded into the account via a tap of the contactless card 406 on the mobile computing device 402. Once loaded into the account, in step 420, the account associated with the in-vehicle device 404 may be updated to reflect the added value. Then, in step 422, the in-vehicle device 404 may communicate with one or more readers to process or withdraw payments from the account.

[0060] It should be understood that the steps shown in sequence diagram 400 are for illustrative purposes only and are not intended to limit you in any way. Therefore, these steps do not need to be performed in any particular order.

[0061] Figure 5 shows an example of value load processing using one-tap authentication and one-tap payment in one or more embodiments. In Figure 5, view 500 is shown, which visually represents what a user (e.g., driver, passenger, etc.) would see inside the vehicle as they approach the toll booth 504 and transponder reader 506. In the example, as the user approaches the toll booth, the user may realize that their online toll payment account does not have enough funds to pay the toll.

[0062] As shown in the diagram, to initiate one-tap value load processing, the user can tap their smartphone 506 on the toll transponder 508. Alternatively, the smartphone 506 may capture one or more images of the toll transponder. In either or both of these examples, the smartphone may receive at least two pieces of information, as described above. Firstly, the smartphone 506 may receive a unique identifier associated with the transponder, for example, so that the correct transponder is identified and loaded. This may be a transponder number, a barcode number, or any other type of information that specifically identifies the transponder 508. Secondly, the smartphone 506 may receive information about where and how to access the user's online toll payment account. In the example, the information may be in the form of a URL linking to an online account, a mobile application, etc. The information may also be physically displayed or placed on the transponder 508 itself. It is understood that the transponder ID and account-related information may be stored in the smartphone 506 for future use. Furthermore, it is understood that the aforementioned transponder ID and information may be received, accessed, or obtained wirelessly from transponder 508 via NFC and / or RFID communication.

[0063] Upon accessing the toll account corresponding to the user, user authentication and value loading (such as account loading or reloading, or one-time payment) can be performed with a single tap using the contactless card 510. It is understood that the contactless card 510 may be similar to or identical to the contactless card 300 described above. Furthermore, it is understood that the funds or money loaded into the toll payment account may be linked to one or more bank accounts corresponding to the contactless card 510.

[0064] As shown in the diagram, a website, mobile application, or any other suitable payment application or website for the toll payment account may be displayed on the graphical user interface (GUI) module 512 to perform one-tap authentication and one-tap payment. In the example, a notification (not shown) may instruct the user to tap the contactless card 510 on the smartphone 506 to authenticate to the user's toll account. When the user taps the contactless card 510 on the smartphone 506, the contactless card 510 may generate encrypted data and send it to the smartphone 506. Upon receipt, the one-tap GUI module 512 may send at least the encrypted data to one or more authentication servers. The authentication servers may decrypt the data and authenticate the data with a secret key stored in the server's memory. The authentication servers may then authenticate the user of the contactless card 510 and send confirmation to the smartphone 506.

[0065] Furthermore, one-tap authentication can also be used, for example, to authenticate a user and automatically log them into their toll account without requiring them to enter login information and a password. In one example, the authentication server may communicate with one or more account servers to verify or confirm such authentication, and in another example, the user may have previously identified or registered a contactless card 510 as an authentication tool in their toll account.

[0066] As illustrated, after the user is authenticated and logged into the toll payment account, the GUI module 512 can display various information such as the account's current balance and a pre-set load value, and as shown in Figure 5, the account's current balance may be $50. Furthermore, the GUI module 512 may display a notification 514 instructing the user to tap the contactless card 510 to make a payment to the account or to load or reload the account. In some examples, it may be understood that both authentication and value loading processes may be performed automatically based on a single tap of the contactless card 510, as opposed to separate taps for authentication and separate taps for payment. Furthermore, the one-tap authentication and payment function may be presented to the user audibly so that the user does not need to look at their smartphone 506 or be distracted while driving.

[0067] Furthermore, when the contactless card 506 is tapped to the smartphone 506, the merchant ID and transaction ID may be transmitted to one or more authentication servers. A virtual account number (VAN) generator may be used to generate virtual card data associated with the contactless card 510 (e.g., virtual card number, expiration date, and / or CVV). The VAN generator may then transmit the virtual card data, merchant ID, transaction ID, and any username and / or address corresponding to the user to one or more merchant servers (e.g., toll payment merchants or providers). The merchant servers may then process the transaction by using the data received from the VAN generator to generate a transaction record in the transaction database using, for example, at least the received virtual card number, expiration date, CVV, etc. The transaction record may further include the user's name, billing address, shipping address, and indications for each product and / or service purchased. The merchant servers may then transmit an order confirmation (e.g., value reload) to the mobile computing device 404.

[0068] One-tap authentication and payment via smartphone 506, transponder 508, and contactless card 510 may be used, performed, operated, completed, etc., within the vehicle, before the user passes through toll booth 504 and / or transponder reader 516, at which point the required toll may be deducted from the user's online account. Thus, the use of contactless card 510 and the user's mobile computing device advantageously enables value load processing to be fast, simple, and secure.

[0069] Figure 6 shows an example of direct loading between a contactless card 601 and an in-vehicle device 602 according to one or more embodiments. As described above, the in-vehicle device 602 may be a toll transponder, a garage access transponder or badge, a device for drive-through payment services, a parking pass, etc. As illustrated, the in-vehicle device 602 may include various components such as one or more processors 604, memory 606, an NFC reader 608, an insertion interface 610 (which may be optional in some examples), a power interface 612, and an amplifier 614. It will be understood that the contactless card 601 may be similar to or identical to the contactless card 300 described above.

[0070] In one embodiment, the user can directly tap the contactless card 601 onto the in-vehicle device 602 without using a mobile computing device. In an alternative embodiment, the contactless card 601 may be inserted into an insertion interface 610, which may be a card slot for accommodating the contactless card 601. The bank account associated with the contactless card 601 may be linked (e.g., at the time of contact or prior to contact) to an account associated with the in-vehicle device 602, or in another embodiment, funds in the bank account may be accessed by the in-vehicle device 602 in real time or near real time to load into the account associated with the in-vehicle device 602.

[0071] According to the embodiment, the in-vehicle device 602 may determine whether the contactless card 601 has established communication with the in-vehicle device via an NFC reader or insertion interface. Value load processing may be initiated if it is determined that communication has been established. Furthermore, the in-vehicle device 602 may determine whether communication has been established with an external in-vehicle device reader (not shown). When a user taps the contactless card 601 or inserts it into the insertion interface 610 to initiate value load processing, the in-vehicle device 602 may understand that it may "look for" communication with the external reader for a predetermined period of time (e.g., 10 minutes, 5 minutes, 1 minute, 30 seconds, etc.) if, for example, the user takes time to pass through or on the side of the external reader.

[0072] Once communication is established between the in-vehicle device 602 and the external reader, one or more payment values ​​may be loaded from the linked user bank account into the account associated with the in-vehicle device 602 so that the loaded value can be withdrawn by the external reader. For example, the presence of a communicable external reader may trigger the in-vehicle device 602 to send data to the external reader indicating at least that "the user has specified and allocated the required payment value from an authorized bank account, so load that payment value into the in-vehicle device account and withdraw the payment." Therefore, for example, if the toll is $5, the data sent to the toll transponder reader may be "the user has authorized a $5 toll payment from their contactless card, so load that amount and withdraw it." At least in this respect, the account associated with the in-vehicle device may not be a conventional web-based account as described above in Figures 4 and 5, but simply a "pass-through" account that passes the required payment value to an entity requesting payment from the contactless card's bank account.

[0073] In some examples, the loading and deduction of value may be facilitated by one or more server computers (which may be managed by entities requesting and receiving payments), at least in part on data transmitted from the in-vehicle device 602 to an external reader (which may be communicating with one or more servers).

[0074] As illustrated, the in-vehicle device 602 may include or incorporate a power interface 612 for drawing power from the vehicle, which may be done via the vehicle's power socket, or in other examples, power may be provided by one or more energy storage components such as a battery or capacitor. Furthermore, the amplifier 614 may be configured to amplify the signal from the in-vehicle device 602 to an external reader, for example, to improve or extend the communication capability between the in-vehicle device 602 and the external reader.

[0075] Figure 7 shows exemplary authentication and / or value-load processing using components integrated into a vehicle 700 according to one or more embodiments. As shown from view 702, the in-vehicle device 710 may be integrated into the driver's side of the center console in the vehicle 700. Although the device 710 is shown to have a generally elliptical shape, it can be understood that the reader may be rectangular, square, or any other suitable shape, design, or configuration. An NFC reader and / or RFID reader may be incorporated into the in-vehicle device 710. Furthermore, the vehicle 700 may include one or more vehicle computing devices (not shown) and other components for at least performing and facilitating transactions within the vehicle.

[0076] In one example, a user can authenticate by tapping a contactless card 720 on an in-vehicle device 710. For example, the in-vehicle device 710 may be used to authenticate a user by providing authentication information to an external reader when entering a parking lot. In another example, the vehicle 700 may include a secure storage area 712 in which the contactless card 720 can be locked in place. The storage area 712 may also include an NFC reader and / or an RFID reader.

[0077] In a further example, the in-vehicle device 710, the vehicle computing device, and the mobile computing device 722 may all separately include a Bluetooth interface (or any other suitable interface) for short-range wireless communication. Authentication information may be transmitted, for example, from the in-vehicle device 710 to the vehicle computing device via their respective short-range wireless communication interfaces. Furthermore, the mobile computing device 722 may communicate with the vehicle computing device and / or the in-vehicle device 710. For example, a user may use the mobile computing device 722 to control or manage the loading of value into an account associated with the in-vehicle device 710, such as by making a transfer from a contactless card 720 to the in-vehicle device 710 via the Bluetooth interface of the vehicle computing device. It is understood that the short-range wireless communication between the interfaces of the in-vehicle device 710, the vehicle computing device, and the mobile computing device 722 may be authenticated and secure.

[0078] Therefore, the user may optionally tap the contactless card 720 on either the in-vehicle device 710 or the mobile computing device 722 to perform authentication and / or value loading. Furthermore, in some examples, the user may control the authentication and value loading functions using the vehicle computing device (e.g., via an in-vehicle display device), and / or the user may control such functions using the mobile computing device 722 as described above.

[0079] The device components and functions described above can be implemented using any combination of discrete circuits, application-specific integrated circuits (ASICs), logic gates, and / or single-chip architectures. Furthermore, the device functions may preferably be implemented using microcontrollers, programmable logic arrays, and / or microprocessors, or any combination thereof. Note that hardware, firmware, and / or software elements may be referred to collectively or individually as “logic” or “circuit” in this specification.

[0080] At least one computer-readable storage medium may contain instructions that, when executed, cause a system to perform one of the computer implementation methods described herein.

[0081] Some embodiments, along with their derivatives, may be described using the expression “one embodiment” or “embodiment.” These terms mean that certain features, structures, or characteristics described in relation to an embodiment are included in at least one embodiment. The expression “in one embodiment” appears in various places in this specification, but not all of them necessarily refer to the same embodiment. Furthermore, unless otherwise noted, the features described above are recognized to be used together in any combination. Thus, features discussed separately can be adopted in combination with each other unless it is pointed out that the features are incompatible with each other.

[0082] With general reference to the notation and nomenclature used herein, the detailed descriptions herein may be presented in terms of program procedures executed on a computer or a network of computers. These descriptions and representations of procedures are intended to be used by those skilled in the art to most effectively communicate the substance of their work to others skilled in the art.

[0083] As used herein, a procedure is generally understood to be a self-consistent series of operations that produce a desired result. These operations require the physical manipulation of physical quantities. Typically, but not necessarily, these quantities take the form of electrical, magnetic, or optical signals that can be manipulated in ways such as storage, transfer, combination, comparison, and other methods. For reasons of common usage, it may be convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these and similar terms are associated with appropriate physical quantities and are merely convenient labels applied to those quantities.

[0084] Furthermore, the operations performed are often referred to in terms such as addition or comparison, and these are generally associated with intellectual activities performed by human operators. However, in any of the operations described herein, which form part of one or more embodiments, such abilities of a human operator are not essential, and in most cases, undesirable. Rather, these operations are mechanical operations.

[0085] Some embodiments, along with their derivatives, may be described using the terms “joined” and “connected.” These terms are not necessarily intended to be synonymous with each other. For example, some embodiments may be described using the terms “connected” and / or “joined” to indicate that two or more elements are in direct physical or electrical contact with one another. However, the term “joined” may also mean that two or more elements are not in direct contact with one another but still cooperate or interact with one another.

[0086] Various embodiments relate to apparatus or systems for performing these operations. This apparatus may be specifically constructed for a required purpose and may be selectively activated or reconfigured by a computer program stored in a computer. The procedures presented herein are not inherently related to any particular computer or other apparatus. Various required structures of these machines will become apparent from the given description.

[0087] It is emphasized that this summary of the disclosure is provided to enable readers to quickly grasp the content of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the meaning of the claims. Furthermore, it is evident that in the preceding detailed description, various features are grouped into a single embodiment for the purpose of streamlining the disclosure. This method of disclosure should not be interpreted as reflecting an intention that the claimed embodiment requires more features than those explicitly stated in each claim. Rather, as reflected in the following claims, the subject matter of the invention lies in fewer features than all the features of the single disclosed embodiment combined. Accordingly, the following claims are incorporated into the detailed description, with each claim standing alone as an independent embodiment. In the attached claims, the terms "including" and "in which" are used as plain English equivalents of the terms "comprising" and "wherein," respectively. Also, terms such as "first," "second," and "third" are used simply as labels and are not intended to impose numerical requirements on their subject matter.

[0088] The above description includes examples of the disclosed architecture. Naturally, it is impossible to describe all conceivable combinations of components and / or methodologies, but those skilled in the art will recognize that many further combinations and permutations are possible. Therefore, novel architectures are intended to encompass all such changes, modifications, and variations that fall within the spirit and scope of the appended claims.

Claims

1. A computer implementation method, A contactless card establishing near-field communication (NFC) with an NFC-based device; The contactless card transmits user authentication information to the NFC-based device, where the user authentication information is associated with the user of the contactless card; This includes allowing the user to access or enter a physical space in response to the transmission of the user authentication information. The NFC-based device communicates with one or more remote computing devices to authenticate user authentication information received from the contactless card and to determine whether the user is authorized to access or enter the physical space. The contactless card has a counter value that is updated or incremented when the contactless card is read by the NFC-based device. The NFC-based device is further configured to provide access to or entry into the physical space by sending a control signal to the door or gate controller to open the door or gate of the physical space in response to the user being granted access to or entry into the physical space. Computer implementation method.

2. The contactless card includes generating encryption that contains authentication information to be transmitted to the NFC-based device. The computer implementation method according to claim 1.

3. The authentication information includes a counter value, an identification value, a random number, or any combination thereof. The computer implementation method according to claim 2.

4. The contactless card includes encrypting the encryption using a key and encryption function stored on the contactless card. The computer implementation method according to claim 2.

5. The encryption is generated by a Java card applet executed on the processing circuit of the contactless card. The computer implementation method according to claim 2.

6. The NFC-based device is an access transponder configured to process requests for access to the physical space. The computer implementation method according to claim 1.

7. It is a contactless card, Wireless interface and Memory configured to store instructions, The system includes a processing circuit configured to execute the aforementioned instruction, and when the instruction is executed, the processing circuit is instructed to do the following: Initiate short-range communication exchange with the receiving device via the aforementioned wireless interface; The wireless interface receives a request from the receiving device; The authentication information is transmitted to the receiving device via the wireless interface, and the authentication information is configured to authenticate the contactless card in order to access the physical space. The receiving device communicates with a system that performs one or more authentication operations on the authentication information received from the contactless card in order to determine whether to allow or deny access to the physical space. The contactless card has a counter value stored in the memory which is updated or incremented when the contactless card is read by the receiving device. The receiving device is further configured to provide access to or entry to the physical space by transmitting a control signal to the door or gate controller to open the door or gate of the physical space in response to the user of the contactless card being granted access to or entry to the physical space. Contactless card.

8. The instruction is configured to cause the processing circuit to generate encryption including authentication information for transmission to an NFC-based device. The contactless card according to claim 7.

9. The authentication information includes a counter value, an identification value, a random number, or any combination thereof. The contactless card according to claim 7.

10. The instruction is configured to cause the processing circuit to encrypt the data using the key and encryption function stored in the contactless card. The contactless card according to claim 8.

11. The encryption is generated by a Java card applet executed on the processing circuit of the contactless card. The contactless card according to claim 8.

12. The receiving device is an access transponder configured to process requests for access to the physical space by communicating the authentication information to one or more other systems in order to authenticate the contactless card. The contactless card according to claim 7.

13. The wireless interface includes a Near Field Communication (NFC) interface, a Bluetooth® interface, or a Wi-Fi® interface. The contactless card according to claim 7.

14. The authentication information includes a unique alphanumeric identifier assigned to the user of the contactless card, and the unique identifier is configured to distinguish the user from other users. The contactless card according to claim 7.

Citation Information

Patent Citations

  • Starter for carburetor

    JP1989032055A

  • Local Trusted Service Manager for Contactless Smart Cards

    JP2013546108A

  • Vehicle security and customization

    US20140240089A1

  • Systems and methods for managing an account

    US20150048159A1

  • Method and apparatus for providing a toll service and flexible toll device

    US20150088617A1