Access to and use of multiple loyalty points accounts

The system uses steganographically encoded images and online authentication protocols with contactless cards and mobile devices to securely and efficiently access multiple loyalty accounts, addressing inefficiencies and security vulnerabilities in existing systems.

JP7839732B2Active Publication Date: 2026-04-02CAPITAL ONE SERVICES LLC
View PDF 4 Cites 0 Cited by

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Filing Date
2020-11-24
Publication Date
2026-04-02

AI Technical Summary

Technical Problem

Existing systems for accessing multiple loyalty accounts are inefficient and insecure, particularly when using chip-based financial cards, as they require time-consuming manual authentication and are vulnerable to security risks if login credentials are compromised.

Method used

A system utilizing steganographically encoded images and online authentication protocols to verify and authenticate users, involving contactless cards and mobile devices, with dynamic barcodes generated for single-use transactions to enhance security and efficiency.

Benefits of technology

Provides secure and efficient access to multiple loyalty accounts by leveraging dynamic authentication technologies, ensuring enhanced security and convenience across various applications, including payment and non-payment transactions.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007839732000001
    Figure 0007839732000001
  • Figure 0007839732000002
    Figure 0007839732000002
  • Figure 0007839732000003
    Figure 0007839732000003
Patent Text Reader

Abstract

Various embodiments are generally directed to accessing, redeeming, or otherwise utilizing a plurality of loyalty points and loyalty accounts utilizing offline and / or online verification or authentication protocols. A method for utilizing a plurality of loyalty points includes determining that a user requests access to a loyalty points account database, receiving encrypted data generated based on an encryption algorithm and a diversified key, receiving user verification, the verification including verification of a combination of data including the encrypted data, wherein a server associated with the issuer decrypts the combination of data based on the encryption algorithm and the diversified key, and, in response to receiving the user verification, accessing a database associated with the user's loyalty points account and authorizing redemption of a plurality of loyalty points associated with the loyalty points account.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Cross - Reference to Related Applications This application claims priority to U.S. Patent Application No. 16 / 727,294, titled "Access to and Use of Multiple Loyalty Point Accounts", filed on December 26, 2019. The content of the aforementioned patent application is hereby incorporated by reference in its entirety.

[0002] Technical Field Embodiments herein generally relate to computing platforms, and more specifically, to accessing multiple loyalty accounts using various authentication protocols.

Background Art

[0003] To activate many cards, more specifically financial cards (e.g., credit cards), a time - consuming process is required where the card owner makes a phone call to a phone number, accesses a website, or enters and provides card information. Further, with the increasing use of chip - based financial cards, a more secure function is provided in face - to - face purchases compared to previous technologies (e.g., magnetic stripe cards), but access to the account usually depends on login credentials (e.g., username and password) to verify the identity of the card owner and / or complete the transaction in other ways. However, if the login credentials are compromised, there is a possibility that other persons can access the user's account.

[0004] Regardless of whether account access is related to payment, repayment activities, or general access, if a single approval credential or mechanism is compromised, the security risk may deteriorate. Therefore, the security problem of the account worsens when trying to access multiple accounts efficiently.

[0005] Therefore, authentication mechanisms for competitive transactions, including account access and payment and redemption transactions, need to be improved. [Overview of the Initiative]

[0006] Embodiments disclosed herein provide systems, methods, products, and computer-readable media for verifying users and / or completing transactions, including but not limited to payment transactions, using steganographically encoded images. According to one or more examples, an online protocol is used to verify and / or authenticate a user in order to initiate an exchange of information that provides (or otherwise utilizes) access to one or more accounts associated with loyalty points.

[0007] For example, a computer implementation method utilizing an application running on a computer system may initiate a transaction, verify the user's identity, and / or authorize the transaction by utilizing a steganographically encoded image. (In various embodiments, the application may be launched by tapping a contactless card on a user device, e.g., a mobile device). This method, The application running on the processor circuitry determines that the user is requesting access to a loyalty points account database; the application receives encrypted data from the communication interface of a contactless card associated with the account, the encrypted data being generated based on an encryption algorithm and a diversified key, the diversified key being stored in the memory of the contactless card and generated based on a master key and counter values ​​stored in the memory of the contactless card; the application receives user verification from a server, the verification including verifying a combination of data including encrypted data, the server verifying the combination of data by decrypting the combination of data based on an encryption algorithm and a diversified key stored in the server's memory, the diversified key being stored in the server's memory and generated based on a master key and counter values ​​stored in the server's memory; and in response to receiving user verification, accessing the database associated with the user's loyalty points account and authorizing the redemption of multiple loyalty points associated with the loyalty points account.

[0008] As another example shows, a system using online and / or offline authentication and steganographically encoded images authenticates and / or verifies a user and / or authorizes a transaction. The system includes a processor circuit and a memory for storing instructions, which, when executed by the processor circuit, initiates a request to the processor circuit for an application running on the processor circuit to perform at least one operation related to multiple accounts associated with multiple loyalty points, the application receives encrypted data from the communication interface of a contactless card associated with the account, the encrypted data being generated based on an encryption algorithm and a diversified key, the diversified key being stored in the memory of the contactless card and generated based on a master key and counter value stored in the memory of the contactless card, and the application receives verification of the encrypted data from a server, the server being an encryption algorithm Based on the rhythm and the diversified keys stored in the server's memory, the encrypted data is decrypted and verified, the diversified keys stored in the server's memory are generated based on the master key and counter values ​​stored in the server's memory, and in response to receiving the verification, authorization is given to perform at least one operation, the at least one operation being at least one of i) accessing a database containing multiple loyalty identifiers associated with at least one user and at least two different accounts, each account being associated with a different set of loyalty points, and ii) storing at least one of the multiple loyalty identifiers for at least two different accounts in the database.

[0009] In yet another example, a host system associated with the issuer of a user-associated card, which includes a non-temporary computer-readable storage medium for storing computer-readable program code executable by a processor, generates a data combination which includes i) a loyalty identifier for at least one user account associated with multiple loyalty accounts, and ii) encrypted data generated based on an encryption algorithm and a diversified key, and decrypts the encrypted data based on the encryption algorithm and diversified key stored in the server's memory to verify the encrypted data, the diversified key stored in the server's memory is generated based on a master key and counter values ​​stored in the server's memory. [Brief explanation of the drawing]

[0010] [Figure 1] This illustrates an embodiment of a system for verifying or authenticating a user in accordance with a payment protocol. [Figure 2] This shows at least one embodiment of tapping for verifying users utilizing an authorization protocol. [Figure 3] Figure 2 shows at least one embodiment that generates a barcode based on tapping and verification. [Figure 4A] An example of a contactless card is shown. [Figure 4B] An example of a contactless card is shown. [Figure 5] This shows an embodiment of the first logic flow. [Figure 6] This shows a second embodiment of the logic flow. [Figure 7] This shows an embodiment of the computing architecture. [Modes for carrying out the invention]

[0011] Aspects of this disclosure include systems, methods, and / or techniques for providing authenticated cardholder access. Generally, various embodiments relate to accessing or otherwise using one or more loyalty points accounts by utilizing and generating barcodes using an online authentication protocol, where the barcodes may be used to complete one or more transactions, including payment transactions. In various embodiments, the barcodes are generated in accordance with an online authentication protocol, but for further security, they are valid for only a single transaction and thereafter expire to prevent improper use of the application associated with that single transaction. Consistent with the disclosed embodiments, the systems and methods may utilize one or more computing devices, processors, web servers, account servers, and / or contactless devices (e.g., radio frequency identification (RFID) cards).

[0012] Various embodiments of this disclosure provide one or more advantages, including the use of barcodes to complete transactions while leveraging the enhanced security provided by dynamic authentication technologies, such as online technologies, with respect to verifying users and completing transactions such as payment transactions (thereby providing both convenience and additional security). In various embodiments, leveraging online technologies improves the efficiency of computer devices, such as mobile phones, by providing a single method for authenticating or verifying users across one or more applications, even if one or more applications differ in their purposes, such as a transportation application related to an entertainment application. Thus, in various embodiments, an authorization protocol may be used to efficiently and more securely authenticate a user across different applications and purposes, and then a barcode generated as a result of verification may be used to complete transactions associated with one or more different applications, including transactions and operations that may or may not involve payment.

[0013] Figure 1 shows a schematic diagram of an exemplary system 100 consistent with the disclosed embodiments. As shown, system 100 includes one or more contactless cards 101, one or more mobile devices 110, and a server 120. Contactless card 101 represents any type of payment card, such as a credit card, debit card, ATM card, loyalty account card, or gift card. In various embodiments, contactless card 101 or card 101 is a virtual payment card. Contactless card 101 may comprise one or more chips (not shown), such as a radio frequency identification (RFID) chip, configured to communicate with mobile device 110 via NFC, EMV standards, or other short-range protocols in wireless communication. While NFC is used as an exemplary communication protocol, this disclosure is equally applicable to other types of wireless communication, such as EMV standards, Bluetooth®, and / or other suitable communication protocols compliant with Wi-Fi. Mobile device 110 represents any type of network-enabled computing device, such as a smartphone, tablet computer, wearable device, laptop, or portable gaming device. Server 120 represents all types of computing devices, including servers, workstations, computer clusters, cloud computing platforms, and virtualized computing systems.

[0014] As shown, the contactless card memory 102 includes a data store for card data 103, a counter 104, a master key 105, a diversified key 106, a unique customer identifier 107, and an account number 108. The card data 103 generally includes account-related information, such as information used to process payments using the contactless card 101. For example, the card data 103 may include an account number, expiration date, billing address, and a card verification value (CVV). The account number can be any type of account number, such as a primary account number (PAN), a virtual account number, and / or a token generated based on a PAN. Other types of account numbers are contemplated, and the use of account numbers or other types of card data 103 should not be considered limiting to disclosure. The card data 103 may further include a name, billing address, shipping address, and other account-related information. The account number 108 stores a one-time use virtual account number, along with its associated expiration date and CVV value. For example, the account number 108 may contain thousands of one-time use virtual account numbers, expiration dates, and CVV values.

[0015] As shown, the memory 112 of the mobile device 110 contains an instance of the operating system (OS) 112, and the processor 119 may perform one or more operations associated with applications of the operating system (OS) 112, and / or any other appropriate operations associated with processor activity, including comparison operations and the execution of instructions associated with memory 111. Examples of operating systems 112 include the Android® OS, iOS®, Linux®, and Windows® operating systems. As shown, the OS 112 contains one or more applications, including an account application 113, an authentication or verification application or service 114 (hereinafter referred to as the “authentication application” for convenience), one or more other applications 115, and / or one or more access applications 116. The account application 113 allows the user to perform various account-related operations, such as viewing account balances, purchasing items, and processing payments. First, the user may access the account application 113 by authenticating using authentication credentials. For example, authentication credentials may include a username and password, biometric credentials, etc.

[0016] The authentication application 114 is generally configured to determine when a user requires authentication for a transaction, service, or accessibility request, including completing a payment associated with the application. For example, the authentication application 114 may determine that a user requires access to a particular application and / or to complete a transaction or payment associated with it, such as an access application 116. The access application 116 may be or include an application configured to grant access to one or more features of a particular service associated with a user account, such as transportation services (e.g., public transport), a financial account or application containing bank accounts, health insurance accounts, account balances, intermediary information, or other appropriate financial data, a service application (e.g., retail services, delivery services, entertainment services, gaming services), and other appropriate applications that may require user authentication. In various embodiments, the access application 116 may be associated with a payment function, e.g., a credit or bank account for making or receiving payments, and / or authentication transactions may still relate to non-payment functions for authentication or verification, e.g., activating a credit or debit card. In various embodiments, the access application 116 is a retail or goods / services provision application, and one or more functions associated with the access application 116 include completing payments associated with the goods or services provided in connection with the access application 116, and the associated transactions or payments may be completed by scanning a barcode generated in accordance with an online authentication protocol, as described below. In various embodiments, the authentication application 114 may utilize a separate API interface to facilitate the authentication protocol and request access to the application 116.The authentication application 114 may be configured to verify the user by utilizing any appropriate protocol, including one or more verification processes that utilize encryption technology, the EMV standard, or an authentication protocol compliant with the EMV standard. In various embodiments, the authentication application 114 is configured to synchronize a counter 104 associated with the contactless card 101 with a server 120 associated with the issuer, which can communicate with the contactless card 101 and the mobile device when the user is authenticated.

[0017] In various embodiments, the authentication application 114 may coordinate with the server 120 and / or the contactless card 101 to record the approval of non-payment transactions associated with the counter 104. The log may be a counter log 101 located in the memory 122 of the server 120 or the memory 102 of the contactless card 101. The log may maintain separate transaction summaries of transactions that are payment transactions and non-payment transactions, regardless of the total summaries of the counter 104 and the server 120 or the contactless card 101. The server 120 and / or the authentication application 114 communicating with the contactless card may use the information contained therein for fraud prevention measures. For example, the authentication application 114 and / or the server 120 may reject a payment transaction if the threshold number of non-payment transactions between non-payment transactions and payment transactions is too low (or too high), or vice versa. In various embodiments, the counter log 212, which includes identification information between non-payment transactions and payment transactions, e.g., counts, may be used for any other appropriate purpose during the online verification protocol.

[0018] In various embodiments, the authentication application 114 is associated with the account application 113. For example, the authentication application 114 may be installed on a mobile device 110 using the account application 113, and the user is prompted to enable the authentication application 114 following the installation. More generally, each time the account application 113 is opened, the account application 113 may determine whether the authentication application 114 is enabled as the default authentication application for OS 112. If the authentication application 114 is not enabled as the default authentication application, the account application 113 may prompt the user to enable the authentication application 114 as the default authentication application for OS 112 and / or enable one or more functions of the authentication application 114. Once enabled as the default authentication application for OS 112, the authentication application 114 may programmatically identify when an authorization application requires authentication and enable verification using a payment protocol even if the payment is not associated with verification or authorization. In various embodiments, in order to initiate an authentication or verification protocol (e.g., at least one operation associated with an online verification technique or protocol), the authentication application 114 may prompt the user to tap the contactless card 101 on the mobile device 110 to initiate the authentication application 114 or one or more operations associated therewith.

[0019] In general, in the various embodiments described herein, an online verification or authentication protocol may include one or more of the following operations: An authentication application may initiate a transaction to verify the identity of a user, where the authentication application may initiate all or part of an application by prompting the user to tap a contactless card 101 on a computer device, for example, a mobile device 110, and may, for example, access an application 116 and / or generate a barcode that can be scanned to access the functions of application 116 and / or complete the associated transaction. A transaction may include NFC communication between a card reader 118 and a contactless card 101, the contactless card 101 may provide the mobile device 110 with one or more inputs, including the latest version of an Application Transaction Counter (ATC), the contactless card 101 or the mobile device 110 (including any appropriate components associated therewith) may generate a suitable ciphertext based on the multiple inputs, the contactless card 101 or the mobile device 110 (including any appropriate components associated therewith) may then send the ciphertext and ATC to the issuer of the contactless card 101 (e.g., a server 120 associated with the issuer). The user may then verify and receive access to one or more functions associated with the application 116 by receiving a response from the issuer verifying or authorizing the user, the received response being based on at least one cryptographic operation performed by the issuer (e.g., server 120) in response to the receipt of the ciphertext. For example, if server 120 can decrypt the ciphertext, the server may send an instruction to the mobile device 110 indicating that the ciphertext has been verified.

[0020] In various embodiments, upon a user being authenticated, server 120 may send an authentication token to barcode generation application 117b associated with either mobile device 110 or contactless card 101 (using any suitable token generation technique). Barcode generation application 117b may cause a barcode, which can be scanned by any suitable scanning device, to be displayed on display 140, 141 of either mobile device 110 and / or contactless card 101. The authentication token may be configured to permit access to one or more functions of access application 116, including completing a payment transaction associated with access application 116. In various embodiments, to enhance the security associated with the transaction, server 120 may configure the authentication token to approve a single transaction associated with access application 116 and then configure it to disable the authentication token / barcode from approving other operations associated with access application 116 without performing other verification (online or offline).

[0021] In various embodiments where contactless card 101 is a virtual payment card, authentication application 114 may obtain information associated with contactless card 101 by accessing a digital wallet implemented on mobile device 110, and the digital wallet includes the virtual payment card.

[0022] As shown, server 120 further includes a data store of account data 124a and memory 122. Account data 124a includes account-related data for a plurality of users and / or accounts. Account data 124a can include at least master key 105, counters 104 such as application transaction counter ("ATC") 104, customer ID 107, associated contactless card 101, account owner name, account billing address, one or more delivery addresses, one or more virtual card numbers, and historical information for each account. Memory 122 includes management application 123 and instances of diversified keys 106 for one or more accounts from card data 103, counters 104, master key 105, and account data 124a. The system can further include one or more loyalty accounts 124b.

[0023] System 100 is configured to perform key diversification to protect data. This may be referred to herein as key diversification technology. System 100 can implement an online authentication protocol.

[0024] In various embodiments, the authentication application 114 receives first application user credentials from the user, associated with the user profile. The first application user credentials may include biometric data, established gestures associated with user recognition, a username and password combination, etc. The processor 119 compares the first application user credentials with stored second application user credentials. The stored second application user credentials may be associated with the user's identity and may be stored in either the memory 111 of the mobile device 110 or the memory 122 of the server 120. In various embodiments, the stored second application user credentials are maintained on the server 120, and the first match is performed by the server 120. In various embodiments, once a first match is determined between the first application user credentials and the stored second application user credentials, the authentication application 114 may grant the user access to one or more first-level user account options of the user account associated with the access application 116. A user account may be a financial account, a health insurance account, and / or any other similar account associated with a service provider (e.g., a transit account, an entertainment account, etc.). Once a first match is determined, the user may access certain first-level user account options associated with the access application 116 without barcode generation occurring and without the completion of a transaction, e.g., payment completion. First-level user account options for a user account may include viewing the account balance, viewing recent transactions, etc. Second-level authentication may be required to perform more advanced access and / or certain account functions, namely second-level user account options, such as performing payment transactions.For example, the system fully completes an online authentication protocol, generates an authentication token in response to the successful completion of the protocol, generates a barcode for scanning (using the authentication token), and the scan completes a transaction associated with the access application 116, such as a payment.

[0025] Generally, the server 120 (or other computing device) and the contactless card 101 may be provisioned with the same master key 105 (also called a master symmetric key). More specifically, each contactless card 101 is programmed with a separate master key 105 having a corresponding pair within the server 120. For example, when a contactless card 101 is manufactured, a unique master key 105 may be programmed into the memory 102 of the contactless card 101. Similarly, the unique master key 105 may be stored (and / or stored in a different secure location) in the customer record associated with the contactless card 101 within the account data 124a of the server 120. The master key may be kept secret from all parties other than the contactless card 101 and the server 120, thereby enhancing the security of the system 100.

[0026] The master key 105 may be used in combination with the counter 104 to enhance security using key diversification. The counter 104 has a value that is synchronized between the contactless card 101 and the server 120. The counter value 104 may have a number that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or between the contactless card 101 and the mobile device 110). To enable NFC data transfer between the contactless card 101 and the mobile device 110, the account application 113 may communicate with the contactless card 101 when it is close enough to the card reader 118 of the mobile device 110 (e.g., within NFC range). The card reader 118 may be a digital reader with NFC capabilities, e.g., an NFC reader, and may be configured to read from and / or communicate with the contactless card 101 (e.g., via NFC, Bluetooth®, RFID, etc.). Therefore, the exemplary card reader 118 includes an NFC communication module, a Bluetooth® communication module, and / or an RFID communication module.

[0027] For example, a user may request authorization or verification to access the access application 116. One or more components of the system 100, including the authentication application 114, may initiate communication with the access application 116 (e.g., an API call or other appropriate mechanism) to utilize one or more payment protocols to verify or authenticate the user, regardless of whether the access application 116 or any particular mode of access requested by a user of the access application 116 involves making a payment.

[0028] In various embodiments, one or more protocols may include online technologies as discussed elsewhere in this specification. The authentication application 114 prompts the user to tap the contactless card 101 to the mobile device 110, thereby bringing the contactless card 101 close enough to the card reader 118 of the mobile device 110 to enable NFC data transfer between the contactless card 101 and the card reader 118 of the mobile device 110. In various embodiments, the mobile device 110 may trigger the card reader 118 via an API call. Furthermore, and / or alternatively, the mobile device 110 may trigger the card reader 118 based on periodically polling the card reader 118. More generally, the mobile device 110 may trigger the card reader 118 to engage in communication using any viable method.

[0029] In various embodiments, before initiating communication with the contactless card 101, card reader 118, and mobile device 110, and / or immediately after establishing communication between the contactless card 101 and card reader 118, the authentication application 114 may receive first application user credentials as a prerequisite for activating the card and / or initiating the online authentication protocol. The user may provide first application user credentials after receiving a prompt from the authentication application to enter credentials. As described above, the first application user credentials may include biometric data, established gestures associated with user recognition, username and password combinations, facial recognition, etc. As described above, in various embodiments, the authentication application 114 communicates the first application user credentials to the processor 119. The processor 119 compares the first application user credentials with stored second application user credentials. The stored second application user credentials may be located in memory 111 associated with the mobile device 110, memory 102 associated with the contactless card 101, and / or memory 122 associated with the server 120. In various embodiments, the first application user credentials are provided to the server 120, which compares the first application user credentials with the stored second application user credentials. In various embodiments, as described above, the processor 119 communicates the comparison result to the authentication application 114 (for example, for a match).In various embodiments, the first match may initiate or function as a prerequisite for one or more of the following: i) initiating the remainder of an online verification protocol for verifying or authenticating a user to access the access application 116; and / or ii) granting the user access to first-level user account options for the user account associated with the access application 116 (e.g., viewing account balance and / or recent transactions); and / or iii) generating an authentication token to be provided to the barcode generation application 117b to generate a barcode that can be scanned to access one or more functions associated with the access application 116 and / or otherwise related transactions, e.g., payment transactions. Thus, in various embodiments, the verification and authentication application, in response to finding the first match, initiates additional operations (associated with the online verification process) to verify the user's identity.

[0030] In various embodiments, the system 100 includes a loyalty points application 117a that utilizes loyalty points associated with the access application 116 and / or the retailer 148, based on an online verification protocol that may or may not utilize the generated barcode associated with the barcode generation application 117b. The loyalty points application 117a may enable a user to perform any number and types of operations related to loyalty points, such as viewing the loyalty points balance, redeeming loyalty points for products, goods, and / or services, or transferring loyalty points to another account. When a user requests to perform an operation in the loyalty points application 117a, the user may be required to verify their identity using a contactless card 101. As described in more detail herein, the requested operation may be authorized based on a server 120 that verifies encrypted data generated by the contactless card 101, verifies application user credentials, and / or uses a barcode generated by the barcode generation application 117b.

[0031] In various embodiments, a first match between first application user credentials and stored second application user credentials may or may not grant first-level access to an application, e.g., access application 116, but in any case, the first match may serve as a prerequisite for initiating at least one online authorization protocol. In various embodiments where first-level access was not initially granted, first-level access is granted upon successful completion of at least one online and / or offline protocol. In various embodiments, second-level access to access application 116 is granted as soon as at least one online and / or offline verification protocol is completed and a barcode generated as a result of the completion of one of those protocols is scanned. Second-level access may refer to completing a payment transaction in relation to access application 116.

[0032] In various embodiments, regardless of other preconditions, a first tap of the contactless card 101 on the mobile device 110 initiates an online and offline verification protocol, and a second tap, a subsequent tap, initiates one of the other online and offline verification protocols.

[0033] In various embodiments, regardless of whether one or more prerequisites apply or are performed, after communication is established between the mobile device 110 and the contactless card 101, the contactless card 101 generates a Message Authentication Code (MAC) ciphertext. In various embodiments, this may occur when the contactless card 101 is read by the account application 113. In particular, this may occur during reading, such as an NFC read, of a Near Field Radio Data Exchange (NDEF) tag, which may be created according to the NFC Data Exchange format. For example, the account application 113 and / or a reader such as the card reader 118 may send a message, such as an applet selection message, using the applet ID of the NDEF generation applet. In various embodiments, the generated ciphertext may be an acknowledgment request ciphertext (ARQC) that conforms to the EMV standard.

[0034] In various embodiments, once a selection is confirmed, a sequence of selected file messages followed by a read file message may be sent. For example, the sequence may include “Selected Functional File,” “Read Functional File,” and “Selected NDEF File.” At this point, a counter value 104 maintained by the contactless card 101 may be updated or incremented, followed by “Read NDEF File.” At this point, a message containing a header and a shared secret may be generated. Subsequently, a session key may be generated. A MAC ciphertext may be constructed from the message. This may include a header and a shared secret. Next, the MAC ciphertext may be concatenated with one or more blocks of random data, and the MAC ciphertext and random numbers (RND) may be encrypted with the session key. Subsequently, the ciphertext and header may be concatenated, encoded as ASCII hexadecimal, and returned in NDEF message format (in response to the “Read NDEF File” message). In various embodiments, the MAC ciphertext may be sent as an NDEF tag, and in other examples, the MAC ciphertext may be included with a uniform resource indicator (e.g., as a formatted string). Next, the contactless card 101 may transmit the MAC ciphertext to the mobile device 110, which may then forward the MAC ciphertext to the server 120 for verification, as described below. (However, in various embodiments, the mobile device 110 may verify the MAC ciphertext.)

[0035] More generally, when preparing to transmit data (e.g., to a server 120 and / or mobile device 110), the contactless card 101 may increment a counter value 104. The contactless card 101 may then provide a master key 105 and the counter value 104 as input to an encryption algorithm, which generates a diversified key 106 as output. The encryption algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, crypto-based message authentication code (CMAC) algorithms, etc. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, symmetric CMAC algorithms such as AES-CMAC, and / or other algorithms or techniques that conform to applicable versions of ISO / IEC 1833 and / or ISO / IEC 7816. The contactless card 101 may then use the diversified key 106 to encrypt the data (e.g., customer identifier 107 and other arbitrary data). Next, the contactless card 101 may transmit encrypted data (e.g., encrypted customer ID 109) to the account application 113 on the mobile device 110 (e.g., via NFC connection, Bluetooth® connection, etc.). The account application 113 on the mobile device 110 may then transmit the encrypted data to the server 120 via the network 130. In at least various embodiments, the contactless card 101 transmits a counter value 104 along with the encrypted data. In such embodiments, the contactless card 101 may transmit an encrypted counter value 104 or an unencrypted counter value 104.

[0036] Upon receiving the encrypted customer ID 109, the management application 123 of the server 120 may perform the same symmetric encryption using the counter value 104 as input to encryption and the master key 105 as the key for encryption. As stated, the counter value 104 may be specified in the data received from the mobile device 110, or the counter value 104 may be maintained by the server 120 to perform key diversification for the contactless card 101. The output of the encryption may be the same diversified key value 106 created by the contactless card 101. The management application 123 may then decrypt the encrypted customer ID 109 received over the network 130 using the diversified key 106 that reveals the data transmitted by the contactless card 101 (e.g., at least the customer identifier 107). By doing so, the management application 123 can verify the data transmitted by the contactless card 101 over the mobile device 110, for example, by comparing the decrypted customer ID 107 with the customer ID in the account data 124a of the account. Once verified, the management application 123 may send an instruction to the mobile device 110 indicating that the verification was successful.

[0037] A counter 104, for example, ATC is used as an example, but other data may be used to secure communication between the contactless card 101, the mobile device 110, and / or the server 120. For example, the counter 104 may be replaced with a random nonce generated each time a new diversified key 106 is needed, the full value of the counter sent from the contactless card 101 and the server 120, a portion of the counter value sent from the contactless card 101 and the server 120, a counter maintained independently by the contactless card 101 and the server 120 but not transmitted between them, a one-time passcode exchanged between the contactless card 101 and the server 120, and a cryptographic hash of the data. In various embodiments, one or more portions of the diversified key 106 may be used by the parties to create multiple diversified keys 106.

[0038] As shown, the server 120 may include one or more hardware security modules (HSMs) 125. For example, one or more HSMs 125 may be configured to perform one or more cryptographic operations, as disclosed herein. In various embodiments, one or more HSMs 125 may be configured as special-purpose security devices configured to perform one or more cryptographic operations. The HSMs 125 may be configured such that keys are never exposed outside the HSMs 125 and are instead maintained within the HSMs 125. For example, one or more HSMs 125 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 125 may be contained within the server 120 or may communicate with the server 120 for data.

[0039] As stated, key diversification technology can be used to perform secure operations using a contactless card 101. For example, if the management application 123 verifies the encrypted customer ID 109 using key diversification, the management application 123 may send a message to the authentication application 114 (or other components of the device 110 such as the account application 113, points application 117A, or application 116) indicating that the user has been verified and / or authenticated, and the authentication application 114 may, as a result, grant the user access to the access application 116. In various embodiments, the output sent may include an acknowledgment response ciphertext (ARPC). Generally, upon receiving a message indicating that the user has been verified and / or authenticated based on the verification of the encrypted customer ID 109, the receiving component of the mobile device 110 may grant any number of operations. For example, the points application 117A may grant access to the loyalty account, for example, to view loyalty points, to redeem loyalty points, or to redeem loyalty points.

[0040] As is specific to one or more embodiments described herein, including the above discussion, the server 120 which may be used for online authentication or verification may be configured to operate in accordance with the EMV standard, including performing operations that utilize the EMV payment protocol for non-payment purposes. The host server (or system) 120 may be associated with the issuer of a card associated with a user, and the host system includes a non-temporary computer-readable storage medium that stores computer-readable program code executable by a processor, and the processor and storage medium may include one or more hardware or software components, including those generally described in Figure 8. The host system may be configured to receive transaction data associated with the access application 116 and / or the contactless card 101. The receipt of transaction data may be facilitated, for example, by an authentication application 114 (or other appropriate component or application of the mobile device 110) associated with a mobile device 110 and a user (or other appropriate computer device), as described herein. The authentication application 114 may initiate an authentication or verification transaction using one or more other components, for example, the contactless card 101 and a card reader 118. The server 120 receives the transaction data from the authentication application 114. Transaction data may include i) a counter (e.g., ATC) and ciphertext based on one or more inputs of the transaction, as well as a symmetric key associated with the card. In various embodiments, the ciphertext is an arbitrage ciphertext (ARQC).

[0041] In various embodiments, when the server 120 receives transaction data, the management application 123 may send a response (e.g., from the issuer) verifying the user's identity based on the received ciphertext to the appropriate component of the mobile device 110, such as the authentication application 114, the account application 113, the points application 117a, etc. In response to receiving the verification response, the authentication application 114 may, as a result, facilitate the generation of a barcode useful for granting access to the relevant part or function of the access application 116 and / or completing the transaction associated with the access application 116. In various embodiments, the response may include an authentication token provided to the contactless card 101 and / or the barcode generation application 117b associated with the mobile device 110, which can be used by the barcode generation application 117b to display a barcode on either the display 140 and / or the display 141. The barcode may be scanned by an appropriate scanning device capable of decrypting the authentication token in order to complete the transaction associated with the access application 116, such as a payment transaction, and / or otherwise provide access to the function associated with the access application 116. Furthermore, the access application 116 may grant access to relevant parts or functions of other applications on the mobile device 110, such as the account application 113 and / or the points application 117a. Similarly, the account application 113 and / or the points application 117a may receive a verification response and grant access to relevant parts or functions of the application, such as access to the loyalty points account of the points application 117a and authorization of transactions using loyalty points.

[0042] In various embodiments, the management component 123 may be configured to invalidate the authentication token upon a single scan of the barcode, which grants access to a function associated with the access application 116 and / or otherwise completes the associated transaction. The management component 123 may then prohibit unauthorized subsequent use of the barcode to access aspects of the access application 116. In various embodiments, the generated barcode may be used for multiple applications, e.g., multiple access applications 116, depending on which choices the user decides to make, provided that the authentication protocol has been performed. In various embodiments, the management application 123 may receive instructions from the user or the authentication application 114, as part of the overall transaction data, to impose restrictions on transactions associated with the access application 116, e.g., monetary limits on payment transactions. The management application 123 configures an authorization token (and, by extension, a subsequently generated barcode) to enforce the restrictions. In various embodiments, the authorization token may be a payment token that authorizes a payment transaction in relation to the access application 116, with or without predefined user limits regarding the amount available.

[0043] Accordingly, in various embodiments, the generated barcode as outlined herein may be a dynamic barcode displayed on either a mobile device 110 or the surface of a contactless card 101 having at least one of the following features: i) The barcode may be configured to become invalid after one use. ii) The barcode may be utilized by multiple access applications 116, including one or more use cases (provided that an authentication protocol associated with an authentication token is performed), for example, in a single use case, once the barcode is generated, but before scanning is performed, the authentication application 114 may utilize the barcode without requiring any protocol for the user to access and perform other access applications 116 again. (For example, a counter log 112 may be utilized by the authentication application 114 to verify that no subsequent transactions have taken place after the barcode was generated, and as a result, the user may be able to switch the use of the barcode to another access application 116 and / or access other functions of the originally selected access application 116 that are different from the one originally selected.) iii) The barcode may be configured to remain active for multiple scans and different access applications 116 after a verification protocol has been performed. and / or iv) the authorization token (and, by extension, the barcode) may be configured to be associated with predefined restrictions (by the user or otherwise) in relation to transactions associated with the access application 116, for example, by imposing monetary restrictions on payment transactions to be completed in relation to the access application 116. It should be noted that in various embodiments, the features described in this paragraph apply not only to barcodes generated in relation to the online protocols described above, but also to any other protocols described herein.

[0044] In various embodiments, server 120 may utilize counter log 212 to implement fraud prevention measures. In various embodiments, counter log 212 may include timestamps associated with counter values ​​associated with one or more non-payment transactions. In various embodiments, counter log 212 may include timestamps associated with counter values ​​associated with one or more payment transactions. In various embodiments, ATC counter values ​​associated with a particular transaction, such as whether it is a payment transaction or a non-payment transaction, may also be recorded. Management application 123 may be configured to compare the general number of payment transactions performed between non-payment transactions. If the number of payment transactions after a non-payment transaction exceeds a certain threshold, management application 123 may reject the payment transaction even if the transaction otherwise completes (for example, an excessive number of payment transactions after a non-payment transaction may be considered fraudulent, as it is assumed that a user may use a payment protocol for non-payment and payment protocols). In various embodiments, the opposite may be done. For example, a large number of non-payment transactions performed after a threshold of payment transactions may cause management application 123 to reject a particular non-payment transaction when verification or authentication is performed. In various embodiments, the management application 123 may cause an authentication or verification operation to be rejected if any transaction, for example, exceeds a minimum or maximum threshold relating to the time between payment or non-payment. The counter log 121 may be used to perform other appropriate operations, including performing fraud prevention measures in other appropriate ways. In various embodiments, fraud prevention measures may invalidate a valid authorization token by instructing an appropriate component of the mobile device, for example, the authentication application 114, to reject the application, even if the authentication token associated with the barcode is valid.

[0045] Figure 2 is a schematic diagram 200 illustrating an exemplary embodiment of tapping to initiate an online verification and / or authentication protocol for generating a barcode to access a function and / or complete a transaction in relation to the access application 116. The graphical user interface (GUI) of the authentication application 114 on the mobile device 110 may include a prompt 206 for tapping a contactless card 101 to initiate authentication or verification of another application, e.g., the access application 116. A separate API interface may be provided for the authentication application 114 to communicate verification or authentication (once completed) to the access application 116. In various embodiments, the access application 116 provides a prompt 202 for entering user credentials for comparison (e.g., as described with reference to Figure 1) for a first and / or second level of information access related to the access application 116, as a prerequisite for receiving the tap prompt 206, or after the tap has been made, but before any additional online verification operation. In various embodiments, the authentication application 114 provides an interface for prompts 202 to enter user credentials with respect to the access application 116 and / or other applications, such as other applications 115.

[0046] In various embodiments, when the contactless card 101 is tapped to the mobile device 110, the authentication application 114 sends instructions to the contactless card 101 via the card reader 118 (e.g., via NFC, Bluetooth®, RFID, etc.). In various embodiments, the instructions may specify that one or more encryption techniques be performed, as described with respect to Figure 1. In various embodiments, online authentication techniques are used, and the authentication application 114 receives transaction data from the server 120. In various embodiments, the prompt to send data between the contactless card 101 and the mobile device 110 may specify that the authentication application 114 send data via the EMV protocol or any suitable protocol that conforms to the standard. Or, any suitable data may be received directly from the contactless card 101 via the EMV protocol or a protocol that conforms to the standard.

[0047] Figure 3 is a schematic diagram 300 showing an exemplary embodiment of a barcode generated after a tap (to generate a barcode) to initiate an online verification and / or authentication protocol, which is performed, for example, to access a function in relation to an access application 116 and / or to complete a transaction. In various embodiments, the barcode 307 is generated on the display of a mobile device suitable for scanning by any suitable scanning device. In various embodiments, the server's management application 123 and / or the authentication application 114 of the mobile device 110 may provide an authentication token to a barcode generation application 117b associated with either the mobile device 110 (shown in Figure 3) and / or a contactless card 101. The barcode generation application 117b may use the authentication token to generate a single-use barcode 307 for repeated use to grant access to one or more functions of the access application 116 (and / or to complete a transaction associated therewith) and / or to grant access to one or more functions of the access application 116 (and / or to complete a transaction associated therewith). As another example, barcode 307 may be used to authorize access to the loyalty account in points application 117a and / or to perform operations associated with the loyalty account in points application 117a.

[0048] Figure 4A shows a contactless card 101 which may include a payment card such as a credit card, debit card, and / or gift card. As shown, the contactless card 101 may be issued by a service provider 405 which is displayed on the front or back of the card 101. In various embodiments, the contactless card 101 may include an identification card which is not related to a payment card, but is not limited thereto. In various embodiments, the payment card may be a dual-interface contactless payment card. The contactless card 101 may include a substrate 410 which may include a single layer or one or more laminated layers composed of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In various embodiments, the contactless card 101 may have physical properties that conform to the ID-1 format of the ISO / IEC 7810 standard, or otherwise, the contactless card 101 may conform to the ISO / IEC 14443 standard. However, please understand that the contactless card 101 relating to this disclosure may have different characteristics, and this disclosure does not require that payment cards be contactless.

[0049] The contactless card 101 may also include identification information 415 displayed on the front and / or back of the card, and a contact pad 420. The contact pad 420 may be configured to establish contact with other communication devices such as a mobile device 110, a user device, a smartphone, a laptop, a desktop, or a tablet computer. The contactless card 101 may also include processing circuits, an antenna, and other components not shown in Figure 4A. These components may be located behind the contact pad 420 or elsewhere on the substrate 410. The contactless card 101 may also include a magnetic strip or tape (not shown in Figure 4A) that may be located on the back of the card. The contactless card 101 may include a display interface 416 capable of displaying a barcode 417 that may be generated as described with reference to Figures 1-3 and 5-7B, the barcode 417 which may be scanned and decoded by any suitable scanning device to allow access to application functions and / or to facilitate the completion of transactions associated with the application, such as payment transactions.

[0050] As shown in Figure 4B, the contact pads 420 of the contactless card 101 may include a processing circuit 425 for storing and processing information, which includes a microprocessor 430 and memory 102. It is understood that the processing circuit 425 may include additional components, as necessary to perform the functions described herein, including a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware.

[0051] Memory 102 may be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and contactless card 101 may include one or more of these memories. Read-only memory may be read-only or programmable once at the factory. One-time programming allows it to be written once and read multiple times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritable but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. Read / write memory can be read multiple times after leaving the factory.

[0052] Memory 102 may be configured to store one or more applets 440, one or more counters 104, a customer identifier 107, and a virtual account number 108. One or more applets 440 may comprise one or more software applications configured to run on one or more contactless cards, such as a Java® card applet. However, it is understood that applet 440 is not limited to a Java card applet, but could instead be any software application capable of running on a contactless card or other device with limited memory. One or more counters 104 may comprise numeric counters sufficient to store integers. The customer identifier 107 may comprise a unique alphanumeric identifier assigned to a user of a contactless card 101, the identifier being able to distinguish a user of a contactless card from other contactless card users. In various embodiments, the customer identifier 107 may identify both the customer and the account assigned to that customer, and further identify the contactless card associated with the customer's account. As stated, the account number 108 may comprise thousands of disposable virtual account numbers associated with the contactless card 101. The applet 440 of the contactless card 101 may be configured to manage account number 108. The memory 102 may be configured to include a barcode generation application 117b that can generate a barcode 417 which can be scanned and decoded by any suitable scanning device and for any suitable purpose described herein, as shown in Figure 4A.

[0053] While the processor and memory elements of the exemplary embodiments described above have been described with reference to the contact pads, this disclosure is not limited thereto. It is understood that these elements may be implemented as additional elements in addition to the processor 430 and memory 102 elements located outside or completely separated from the pads 420, or within the contact pads 420.

[0054] In various embodiments, the contactless card 101 may include one or more antennas 455. The one or more antennas 455 may be located within the contactless card 101 and around the processing circuit 425 of the contact pads 420. For example, one or more antennas 455 may be integrated with the processing circuit 425, or one or more antennas 455 may be used in conjunction with an external booster coil. In other examples, one or more antennas 455 may be located outside the contact pads 420 and the processing circuit 425.

[0055] In one embodiment, the coil of the contactless card 101 may function as the secondary side of an air-core transformer. A terminal may communicate with the contactless card 101 by disconnecting power or amplitude modulation. The contactless card 101 may infer data transmitted from the terminal by using a gap in the contactless card's power connection, which can be functionally maintained through one or more capacitors. The contactless card 101 may return communication by switching the load of the contactless card's coil or load modulation. Load modulation may be detected in the terminal's coil by interference. More generally, using an antenna 455, processing circuitry 425, and / or memory 102, the contactless card 101 provides a communication interface for communication via NFC, Bluetooth®, and / or Wi-Fi communication.

[0056] As described above, the contactless card 101 may be built on a software platform capable of running on memory-limited smart cards or other devices such as Java cards, and one or more applications or applets may be securely executed. The applet 440 may be added to the contactless card and provide a one-time password (OTP) for multi-factor authentication (MFA) in various mobile application-based use cases. The applet 440 may be configured to respond to one or more requests, such as a near-field wireless data exchange request from a reader such as a mobile NFC reader (e.g., mobile device 110), and generate an NDEF message with a cryptographically secure OTP encoded as an NDEF text tag.

[0057] One example of NDEFOTP is the NDEF short record layout (SR=1). In such an example, one or more applets 440 may be configured to encode the OTP as a well-known type of text tag of NDEF type 4. In various embodiments, an NDEF message may comprise one or more records. Applet 440 may be configured to add one or more static tag records in addition to the OTP record.

[0058] In various embodiments, one or more applets 440 may be configured to emulate an RFID tag. The RFID tag may include one or more polymorphic tags. In various embodiments, each time the tag is read, different encrypted data that may indicate the authenticity of the contactless card is presented. Based on one or more applications, the NFC reading of the tag may be processed, the data may be sent to a server such as server 120, and the data may be verified by the server.

[0059] In various embodiments, the contactless card 101 and the server 120 may contain specific data so that the card can be properly identified. The contactless card 101 may have one or more unique identifiers (not shown). Each time a read operation is performed, the counter 104 may be configured to increment. In various embodiments, each time data is read from the contactless card 101 (for example, by a mobile device 110), the counter 104 is sent to the server for verification to determine whether the counter value 104 is equal (as part of the verification).

[0060] One or more counters 104 may be configured to prevent replay attacks. For example, if a ciphertext is retrieved and replayed, and counter 104 is read, used, or otherwise passed, the ciphertext is immediately rejected. If counter 104 is not used, it can be replayed. In various embodiments, counters incremented on the card are different from counters incremented for transactions. The contactless card 101 cannot determine the application transaction counter 104 because there is no communication between applets 440 on the contactless card 101. In various embodiments, the contactless card 101 may comprise a first applet 440-1 and a second applet 440-2, which may be transaction applets. Each applet 440-1 and 440-2 may comprise its respective counter 104.

[0061] In various embodiments, counter 104 may become out of sync. In various embodiments, considering accidental reads that initiate a transaction, such as reads at a certain angle, counter 104 may be incremented, but the application does not process counter 104. In various embodiments, when the mobile device 110 is woken up, NFC may be enabled, and the device 110 may be configured to read available tags, but no action is taken in response to the read.

[0062] To maintain the synchronization of counter 104, an application such as a background application may be run that can be configured to detect when the mobile device 110 wakes up and synchronize with a server 120 indicating that the read resulting from the detection will next advance counter 104. In another example, a hashed one-time password may be used to accept a window of synchronization misses. For example, if it is within a threshold of 10, counter 104 may be configured to advance. However, if it is within a different threshold number, for example, 10 or 1000, the request to perform resynchronization may involve processing through one or more applications that requires the user to tap, gesture, or give other instructions through the user's device. If counter 104 is incrementing in the correct order, it is possible to know that the user is doing so.

[0063] The key diversification techniques described herein with reference to counter 104, master key 105, and diversified key 106 are examples of encryption and / or decryption of key diversification techniques. Since the disclosures are equally applicable to other types of key diversification techniques, these exemplary key diversification techniques should not be considered limiting to the disclosures.

[0064] During the creation process of the contactless card 101, two encryption keys may be uniquely assigned to each card. The encryption keys may be symmetric keys that can be used for both encrypting and decrypting data. The Triple DES (3DES) algorithm may be used with EMV and implemented by the hardware of the contactless card 101. By using a key diversification process, one or more keys may be derived from the master key based on uniquely identifiable information of each entity that requires a key.

[0065] In various embodiments, a session key (such as a unique key per session) can be derived to overcome the vulnerability of the 3DES algorithm, but instead of using a master key, a unique key and counters derived from the card can be used as diversification data. For example, each time contactless card 101 is used during an operation, a different key can be used to generate a message authentication code (MAC) and perform encryption. This results in three layers of encryption. The session key can be generated by one or more applets and derived using application transaction counters with one or more algorithms (defined in EMV 4.3 Book 2 A1.3.1 Common Session Key Derivation).

[0066] Furthermore, the increment of each card can be unique and may be assigned by personalization or by an algorithm based on some identifying information. For example, odd-numbered cards may increment by 2, and even-numbered cards may increment by 5. In various embodiments, the increment may also vary in sequential reading, resulting in a single card incrementing sequentially by 1, 3, 5, 2, 2, ... A specific sequence or algorithmic sequence may be defined during personalization or from one or more processes derived from a unique identifier. This can make it difficult for a replay attacker to generalize from a small number of card instances.

[0067] The authentication message may be delivered as the content of a text NDEF record in hexadecimal ASCII format. In other examples, the NDEF record may be encoded in hexadecimal format.

[0068] Figure 5 shows an embodiment of the logical flow 500. The logical flow 500 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 500 may include some or all of the operations of verifying or authenticating a user using online authentication technology to access one or more accounts associated with loyalty points, and / or utilizing loyalty points. Embodiments are not limited in this context.

[0069] As shown, the logical flow 500 begins in block 505, where at least one of the authentication application 114, OS 112, management application 123, and / or any other suitable application may initiate a transaction to verify the user's identity and generate a barcode for accessing the functionality associated with the access application 116. In various embodiments, verification may be initiated by tapping a contactless card 101 on the mobile device 110. In various embodiments, the access application 116 provides a prerequisite for receiving the tap prompt, or immediately after the tap has been made but before any additional online verification operation, for entering user credentials for comparison for a first and / or second level of information access associated with the access application 116, the nature of the first level of functionality is described elsewhere herein. In various embodiments, the user credentials are associated with a user profile and entered into an interface provided by the mobile device 110, where, as previously stated, the first application user credentials may include biometric data, established gestures associated with user recognition, a combination of username and password, and / or similar. The first application user credentials may be sent by the authentication application 114 to the management application 123 of the server 120, where the first application user credentials are compared with the stored second credentials.

[0070] In block 510, and according to various embodiments, communication is initiated between the mobile device 110 and the contactless card 101, utilizing the card reader 118, and the communication is based on the NFC protocol. In various embodiments, the communication is a condition for a first level of comparison that results in a match, and in various embodiments, instead of sending first application credentials for comparison at the server 120, a comparison is made between the mobile device 110 and the contactless card 101, where stored second credentials are stored in the contactless card's memory 102. In various embodiments, the comparison for user credentials is omitted, and a tap of the contactless card 101 on the mobile device 110 initiates a prompt to select which application requires authentication, for example, an access application 116, and the NFC communication between the contactless card 101 and the mobile device 110 initiates online verification or authentication of the user using a payment protocol that conforms to the EMV standard, but is initiated for purposes including verification or authentication for purposes other than simply completing a sale or purchase. In various embodiments, as described above, the user taps the contactless card 101 on the mobile device 110 to cause the contactless card 101 to generate and transmit encrypted data (e.g., encrypted customer ID 109). In response to receiving the instruction to generate encrypted data, the contactless card 101 may increment a counter value 104 in the memory 102.

[0071] In various embodiments, in block 515, the contactless card 101 generates a diversified key 106 using a counter value 104 in memory 102, a master key 105, and an encryption algorithm. In block 520, the contactless card 101 encrypts data (e.g., customer identifier 107) using the diversified key 106 and the encryption algorithm to generate encrypted data (e.g., encrypted customer ID 109).

[0072] In block 525, the contactless card 101 may transmit encrypted data to the account application 113 of the mobile device 110, for example, using NFC. In at least one embodiment, the contactless card 101 further includes an instruction for a counter value 104 along with the encrypted data. In block 530, the account application 113 of the mobile device 110 may transmit the data received from the contactless card 101 to the management application 123 of the server 120. In block 535, the management application 123 of the server 120 may generate a diversified key 106 using the master key 105 and the counter value 104 as input to an encryption algorithm. In one embodiment, the management application 123 uses the counter value 104 provided by the contactless card 101. In other embodiments, the management application 123 increments the counter value 104 in memory 122 to synchronize the state of the counter value 104 in memory 122 with the counter value 104 in memory 102 of the contactless card 101.

[0073] In block 540, the management application 123 decrypts the encrypted data received from the contactless card 101 via the mobile device 110 using the diversified key 106 and the encryption algorithm. In doing so, at least the customer identifier 107 can be obtained. By obtaining the customer identifier 107, the management application 123 can verify the data received from the contactless card 101 in block 545. For example, the management application 123 may compare the customer identifier 107 with the customer identifier of the relevant account in the account data 124a and verify the data based on the match. In doing so, the management application 123 may send a verification instruction to the mobile device 110.

[0074] In block 550, in response to the decryption and verification of blocks 540 and 545, the management application 123 may provide access to one or more loyalty points accounts 124b, and may allow the redemption of one or more loyalty points associated therewith, including loyalty points associated with the retailer 148. Although shown as being stored in server 120, the points application 117a may include instances of loyalty points account 124b. In various embodiments, prior to decryption, the management application 123 may generate an authorization token that can be sent to a barcode generation application 117b on either a contactless card 101 and / or a mobile device 110, the barcode which may then be displayed by displays 140 and / or 141, the authorization token which may impose one or more restrictions and conditions as outlined above with respect to the various components of Figure 1, and the barcode which may be scanned by any suitable scanning device to enable the decryption and redemption of loyalty points associated with loyalty points account 124b. In various embodiments, the barcode generation application 117 may generate barcodes using any suitable technique for barcode generation, and the generated barcodes may be displayed on the display 140 of a mobile device and / or on the display 141 of a contactless card 101.

[0075] Figure 6 shows an embodiment of the logical flow 600. The logical flow 600 may represent some or all of the operations performed by one or more embodiments described herein. For example, the logical flow 600 may include utilizing the generated barcode associated with Figure 5 to approve a transaction associated with the access application 116. Embodiments are not limited in this context.

[0076] As shown, the logical flow 600 begins after one or more operations in Figure 5 are completed, and in various embodiments, the flow begins in block 530 in Figure 5. In block 605, any suitable component of system 100 may determine, by an application running on the processor circuit, that a user is requesting access to the loyalty points account database. In block 610, any suitable component of system 100 may transmit first application user credentials by the application and from the computer device associated with the processing circuit to server 120 using any suitable technique as discussed herein. In block 615, any suitable component of system 100 may compare the first application user credentials with stored second application user credentials at the server, and the stored second application user credentials are stored at the server. In block 620, in response to a match of first and second credentials, any suitable component of system 100 may, by the application, receive encrypted data from the communication interface of the contactless card associated with the account, the encrypted data being generated based on an encryption algorithm and a diversified key, the diversified key being stored in the contactless card's memory and generated based on a master key and counter value stored in the contactless card's memory. In block 625, in response to a match of first and second credentials, any suitable component of system 100 may combine the loyalty identifier associated with the user with the encrypted data, the data combination including a combination of the loyalty identifier and the encrypted data. The combination (and / or any other combination operation described herein) may be based on a logical operation, the logical operation may be an exclusive OR operation. In block 630, any suitable component of system 100 may, at the server, perform an operation on the received encrypted data and the loyalty identifier.In block 635, any suitable component of system 100 may generate a barcode on either i) a contactless card or ii) a computer device, the generated barcode being based on a token that utilizes encrypted data and a loyalty identifier received from the server. In block 640, any suitable component of system 100 may display the generated barcode. In block 645, any suitable component of system 100 may receive verification of encrypted data from the application and from the server based on scanning the generated barcode, the server decrypting the encrypted data based on an encryption algorithm and verifying the encrypted data using a diversified key stored in the server's memory, the diversified key stored in the server's memory being generated based on a master key and counter values ​​stored in the server's memory. In block 650, any suitable component of system 100 may, in response to receiving a verification, grant authorization to perform at least one operation, the at least one operation including at least one of i) accessing a database containing multiple loyalty identifiers associated with at least one user and at least two different accounts, each account being associated with a different set of loyalty points, and ii) storing at least one of the multiple loyalty identifiers relating to at least two different accounts in the database.

[0077] In various embodiments, the contactless card 101 may be tapped on one or more devices, such as computer kiosks or terminals, to verify identity in order to receive transaction items in response to a purchase, such as coffee. By using the contactless card 101, a secure method of verifying identity can be established in a loyalty program. For example, securely verifying identity to obtain rewards, coupons, offers, etc., or to receive benefits, is established in a way different from simply scanning a bar card. For example, encrypted transactions may occur between the contactless card 101 and the device, which may be configured to handle one or more tap gestures. As described above, one or more applications may be configured to verify the user's identity and then prompt the user to act or respond, for example, via one or more tap gestures. In various embodiments, data, such as bonus points, loyalty points, reward points, healthcare information, etc., may be written back to the contactless card.

[0078] In various embodiments, the contactless card 101 can be tapped to a device such as a mobile device 110. As described above, the user's identity may be verified by one or more applications, and then, based on the verification of identity, the user may be given the desired benefit.

[0079] In various embodiments, the exemplary authentication communication protocol may, with some modifications, mimic an EMV-standard offline dynamic data authentication protocol commonly performed between transaction cards and point-of-sale (POS) devices. For example, since the exemplary authentication protocol is not used to complete payment transactions with the card issuer / payment processor itself, some data values ​​are unnecessary, and authentication can be performed without requiring a real-time online connection to the card issuer / payment processor. As is known in the art, a point-of-sale (POS) system submits a transaction containing transaction values ​​to the card issuer. Whether the issuer approves or rejects the transaction may be based on whether the card issuer is aware of the transaction values. On the other hand, in certain embodiments of this disclosure, transactions originating from a mobile device lack transaction values ​​associated with the POS system. Therefore, in various embodiments, a dummy transaction value (i.e., a value that is recognizable to the card issuer and sufficient to allow activation to occur) may be passed as part of the exemplary authentication communication protocol. POS-based transactions may also reject a transaction based on the number of attempts (e.g., a transaction counter). The number of attempts exceeding a buffer value may result in a soft decline. A soft decline requires further verification before accepting the transaction. In some implementations, the transaction counter buffer value may be modified to avoid a decrease in legitimate transactions.

[0080] In various embodiments, the contactless card 101 may selectively communicate information depending on the receiving device. When tapped, the contactless card 101 may recognize the device to which the tap is directed, and based on this recognition, the contactless card may provide appropriate data to that device. This advantageously allows the contactless card to transmit only the information necessary to complete an immediate action or transaction, such as payment or card authentication. By limiting the transmission of data and avoiding the transmission of unnecessary data, both efficiency and data security can be improved. Information recognition and selective communication can be applied to a variety of scenarios, including card activation, balance transfer, account access attempts, commercial transactions, and gradual fraud reduction.

[0081] If the tap of contactless card 101 is directed towards a device running Apple's iOS® operating system, such as an iPhone®, iPod®, or iPad®, the contactless card may recognize the iOS® operating system and transmit appropriate data to communicate with the device. For example, contactless card 101 may provide encrypted identity information necessary to authenticate the card using an NDEF tag via NFC. Similarly, if the tap of contactless card is directed towards a device running the Android® operating system, such as an Android® smartphone or tablet, the contactless card may recognize the Android® operating system and transmit appropriate data to communicate with the device (such as encrypted identity information necessary for authentication as described herein).

[0082] As another example, contactless card taps may be directed to POS devices including, but not limited to, kiosks, checkout registers, payment stations, or other terminals. When a tap is performed, the contactless card 101 may recognize the POS device and transmit only the information necessary for the action or transaction. For example, upon recognizing a POS device used to complete a commercial transaction, the contactless card 101 may communicate the payment information necessary to complete the transaction under the EMV standard.

[0083] In various embodiments, a POS device participating in a transaction may request or specify additional information provided by the contactless card, such as device-specific information, location-specific information, and transaction-specific information. For example, when a POS device receives data communication from a contactless card, the POS device may recognize the contactless card and request additional information necessary to complete an action or transaction.

[0084] In various embodiments, a POS device may partner with an authorized vendor or other entity that is familiar with or accustomed to performing certain contactless card transactions. However, it is understood that such partnerships are not required for the execution of the described method.

[0085] In various embodiments such as shopping stores, grocery stores, and convenience stores, the contactless card 101 can be tapped on a mobile device without opening an application to indicate a desire or intention to use one or more reward points, loyalty points, coupons, offers, etc., to cover one or more purchases. Thus, the intention behind the purchase is provided.

[0086] In various embodiments, one or more applications may be configured to determine, in order to verify the user's identity, that the activation occurred at 3:51 p.m., that the transaction was processed or performed at 3:56 p.m., and that it was activated via one or more tap gestures on the contactless card 101.

[0087] In various embodiments, one or more applications may be configured to control one or more actions in response to one or more tap gestures. For example, one or more actions may include collecting rewards, collecting points, deciding on the most important purchase, deciding on the least expensive purchase, and / or reconfiguring into other actions in real time.

[0088] In various embodiments, data may be collected in relation to tap actions as biometric / gesture authentication. For example, a cryptographically secure and intercept-resistant unique identifier may be sent to one or more backend services. The unique identifier may be configured to retrieve secondary information about the individual. The secondary information may consist of personally identifiable information about the user. In various embodiments, the secondary information may be stored within a contactless card.

[0089] In various embodiments, the device may include an application for splitting invoices or checking payments between multiple individuals. For example, each individual may, but not be required, own a contactless card and be a customer of the same issuing financial institution. Each of these individuals may receive a push notification on the device via the application and split a purchase. Instead of accepting only one card tap to indicate payment, other contactless cards may be used. In various embodiments, individuals with different financial institutions may own contactless cards 101 for providing information to initiate one or more payment requests from card-tapping individuals.

[0090] In various embodiments, this disclosure refers to tapping a contactless card. However, this disclosure is not limited to tapping, and it is understood that this disclosure includes other gestures (e.g., waving or other movements of the card).

[0091] Figure 7 shows an exemplary embodiment of the computing architecture 700, comprising a computing system 702 suitable for implementing the various embodiments described above. In various embodiments, the computing architecture 700 may be implemented with or as part of an electronic device. In various embodiments, the computing architecture 700 may represent, for example, a system implementing one or more components of system 100. In various embodiments, the computing system 702 may represent, for example, the mobile device 110 and the server 120 of system 100. Embodiments are not limited to this context. More generally, the computing architecture 700 is configured to implement all the logic, applications, systems, methods, apparatus, and functions described herein with reference to Figures 1 to 6.

[0092] The terms “system,” “component,” and “module” as used in this application are intended to refer to any computer-related entity, whether hardware, a combination of hardware and software, software, or running software, examples of which are provided by the exemplary computing architecture 700. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable, an execution thread, a program, and / or a computer. For example, both an application running on a server and the server itself may be components. One or more components may reside within a process and / or an execution thread, and components may be localized to one computer and / or distributed across two or more computers. Furthermore, components may be coupled together in a communicative manner by various types of communication media and their operation may be coordinated. Coordination may include the one-way or two-way exchange of information. For example, components may communicate information in the form of signals communicated over a communication medium. Information may be implemented as signals assigned to various signal lines. In such an assignment, each message is a signal. However, further embodiments may use data messages as an alternative. Such data messages can be transmitted over various connections. Examples of connections include parallel interfaces, serial interfaces, and bus interfaces.

[0093] The computing system 702 includes various common computing elements such as one or more processors, multicore processors, coprocessors, processing circuit memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, and power supplies. However, the embodiments are not limited to those implemented by the computing system 702.

[0094] As shown in Figure 7, the computing system 702 comprises a processor 704, system memory 706, and a system bus 708. The processor 704 may be any of a variety of commercially available computer processors or computer process circuits, including but not limited to AMD® Athlon®, Duron®, and Opteron® processors, ARM® application, embedded, and secure processors, IBM® and Motorola® DragonBall® and PowerPC® processors, IBM and Sony® Cell processors, Intel® Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors and similar processors. Dual microprocessors, multi-core processors, and other multiprocessor architectures may also be used as the processor 704. The processor 704 may be comprised of associated memory instructions contained in the system memory 706, and as a result, when the instructions are re-executed on the processor (e.g., the processor circuit) 704, the processor may perform one or more operations associated with any one of Figures 5 to 7B, and / or any other operations or techniques disclosed herein.

[0095] The system bus 708 provides an interface to system components, including but not limited to the system memory 706 and the processor 704. The system bus 708 can be one of several types of bus structures that can further interconnect to the memory bus (with or without a memory controller), peripheral buses, and local buses using any of various commercially available bus architectures. Interface adapters can connect to the system bus 708 via slot architectures. Examples of slot architectures include, but are not limited to, Accelerated Graphics Port (AGP), CardBus, Industry Standard Architecture ((E)ISA), Microchannel Architecture (MCA), NuBus, Peripheral Component Interconnect (Extensible) (PCI(X)), PCI Express, and Personal Computer Memory Card International Association (PCMCIA).

[0096] The system memory 706 may include various types of computer-readable storage media in the form of one or more high-speed memory units, such as read-only memory (ROM), random access memory (RAM), dynamic RAM (DRAM), double data rate DRAM (DDRAM), synchronous DRAM (SDRAM), static RAM (SRAM), programmable ROM (PROM), erasable programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, silicon oxide nitride (SONOS) memory, magnetic or optical cards, arrays of devices such as redundant array of independent disks (RAID) drives, solid-state memory devices (e.g., USB memory, solid-state drives (SSDs)), and other types of storage media suitable for storing information. In the illustrated embodiment shown in Figure 7, the system memory 706 may include non-volatile memory 710 and / or volatile memory 712. The non-volatile memory 710 may store the basic input / output system (BIOS).

[0097] The computing system 702 may include various types of computer-readable storage media in the form of one or more low-speed memory units, including an internal (or external) hard disk drive (HDD) 714, a magnetic floppy disk drive (FDD) 716 for reading from or writing to a removable magnetic disk 718, and an optical disk drive 720 for reading from or writing to a removable optical disk 722 (e.g., a CD-ROM or DVD). The HDD 714, FDD 716, and optical disk drive 720 may be connected to the system bus 708 by an HDD interface 724, an FDD interface 726, and an optical drive interface 728, respectively. The HDD interface 724 for external drive implementation may include at least one or both of the Universal Serial Bus (USB) and IEEE 1394 interface technologies. The computing system 702 is generally configured to implement all the logic, systems, methods, apparatus, and functions described herein with reference to Figures 1 to 6.

[0098] The drives and associated computer-readable media provide volatile and / or non-volatile storage of data, data structures, computer-executable instructions, etc. For example, a number of program modules may be stored in the drives and memory units 710, 712, including an operating system 730, one or more application programs 732, other program modules 734, and program data 736. In various embodiments, one or more application programs 732, other program modules 734, and program data 736 may include, for example, various applications and / or components of system 100, such as an operating system 112, an account application 113, an authentication application 114, other applications 115, an access application 116, and an administration application 123.

[0099] The user may input commands and information to the computing system 702 via one or more wired / wireless input devices, such as a keyboard 738 and a pointing device such as a mouse 740. Other input devices may include a microphone, infrared (IR) remote control, radio frequency (RF) remote control, gamepad, stylus pen, card reader, dongle, fingerprint reader, grab, graphics tablet, joystick, keyboard, retina reader, touchscreen (e.g., capacitive, resistive, etc.), trackball, trackpad, sensor, stylus, etc. These and other input devices are often connected to the processor 704 via an input device interface 742 coupled to the system bus 708, but may also be connected via other interfaces such as a parallel port, IEEE 1394 serial port, game port, USB port, or IR interface.

[0100] Monitor 744 or other types of display devices are also connected to the system bus 708 via interfaces such as the video adapter 746. Monitor 744 can be located inside or outside the computing system 702. In addition to Monitor 744, the computer typically includes other peripheral output devices such as speakers and printers.

[0101] The computing system 702 may operate in a network environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computers 748. The remote computers 748 could be workstations, server computers, routers, personal computers, portable computers, microprocessor-based entertainment devices, peer devices, or other common network nodes, typically including many or all of the elements described in relation to the computing system 702, but for brevity, only the memory / storage device 750 is shown. The logical connections shown include wired / wireless connections to a local area network (LAN) 752 and / or a larger network, such as a wide area network (WAN) 754. Such LAN and WAN network environments are common in offices and businesses and facilitate enterprise-scale computer networks such as intranets. All of these may connect to global communication networks, such as the Internet. In embodiments, the network 130 in Figure 1 is one or more of the LAN 752 and WAN 754.

[0102] When used in a LAN networking environment, the computing system 702 is connected to the LAN 752 via a wired and / or wireless network interface or adapter 756. The adapter 756 may facilitate wired and / or wireless communication to the LAN 752, which may include a wireless access point placed on it to communicate with the wireless capabilities of the adapter 756.

[0103] When used in a WAN networking environment, the computing system 702 may include a modem 758, or be connected to a communication server on the WAN 754, or have other means of establishing communication on the WAN 754, such as via the Internet. The modem 758 may be internal or external, wired and / or wireless, and connect to the system bus 708 via an input device interface 742. In a network environment, the program modules, or parts thereof, shown with respect to the computing system 702 may be stored in a remote memory / storage device 750. The shown network connections are illustrative, and it will be understood that other means of establishing communication links between computers may be used.

[0104] Computing system 702 is capable of communicating with wired and wireless devices or entities using the IEEE 802 standard family, such as wireless devices configured to operate wirelessly (e.g., IEEE 802.16 wireless modulation technology). This includes at least Wi-Fi (or Wireless Fidelity), WiMAX, and Bluetooth® wireless technologies. Thus, communication can be a predefined structure, similar to conventional networks, or simply ad-hoc communication between at least two devices. Wi-Fi networks provide secure, reliable, and high-speed wireless connectivity using wireless technologies known as IEEE 802.11x (a, b, g, n, etc.). Wi-Fi networks can be used to connect computers to each other, to connect to the Internet, or to wired networks (using IEEE 802.3 related media and functions).

[0105] Various embodiments may be implemented using hardware elements, software elements, or a combination of both. Examples of hardware elements may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field-programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, application programming interfaces (APIs), instruction sets, computing code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. The decision of whether an embodiment is implemented using hardware and / or software elements may vary depending on any number of factors, such as desired computing speed, power level, heat resistance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.

[0106] At least one or more aspects of various embodiments can be implemented by representative instructions stored in a machine-readable medium representing various logics within a processor, which, when read by a machine, produce logic that performs the techniques described herein. Such representations, known as "IP cores," are stored in tangible machine-readable medium and provided to various customers or manufacturing facilities for loading into manufacturing machines that create logic or processors. Various embodiments can be implemented, for example, using a machine-readable medium or article that can store instructions or sets of instructions that, when executed by a machine, can cause a machine to perform methods and / or operations according to the embodiment. Such machines can include, for example, any suitable processing platform, computing platform, computing device, processing device, computing system, processing system, computer, processor, etc., and can be implemented using any suitable combination of hardware and / or software. Machine-readable media or articles may include, for example, any suitable type of memory unit, memory device, memory article, memory medium, storage device, storage article, storage medium and / or storage unit, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disks, floppy disks, compact disk read-only memory (CD-ROM), compact disk recordable (CD-R), compact disk rewritable (CD-RW), optical disks, magnetic media, magneto-optical media, removable memory cards or disks, various digital versatile disks (DVDs), tapes, cassettes, etc. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, cryptographic code, etc., and may be implemented using any suitable high-level, low-level, object-oriented, visual, compiled and / or interpreted programming language.

[0107] The foregoing description of exemplary embodiments is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit this disclosure to the exact form disclosed. Many modifications and changes are possible in light of this disclosure. The scope of this disclosure is intended to be limited by the appended claims rather than by this detailed description. Future applications claiming priority to this application may assert the disclosed subject matter in different ways and may generally include any set of one or more limitations, as variously disclosed or demonstrated herein.

Claims

1. It is a method, The application running on the processor circuit determines the request for access to the loyalty points account, The aforementioned application receives encrypted data from the contactless card associated with the account, The application transmits the encrypted data to the server, The application receives the decryption result from the server, The application determines, based on the decryption result, that the server has decrypted the encrypted data. The application, based on its determination that the server has decrypted the encrypted data, displays multiple points in the loyalty points account. The aforementioned application processes redemption requests that include one or more loyalty points, The application approves the reimbursement request based on its determination that the server has decrypted the encrypted data. A method for providing this.

2. The aforementioned method, The application transmits the first application user credentials to the server. The server compares the first application user credentials with the second application user credentials. Furthermore, The comparison is performed to determine whether the application sends the encrypted data to the server. The method according to claim 1.

3. The aforementioned method, The server determines, based on the comparison, that the first application user credentials match the second application user credentials. The server combines the loyalty identifier with the encrypted data, Furthermore, The application, upon matching, sends the encrypted data to the server. The aforementioned combination is performed in order to show the decryption result on the server. The method according to claim 2.

4. Combining the aforementioned loyalty identifier with the encrypted data means The server performs an exclusive OR operation on the encrypted data and the loyalty identifier. The method according to claim 3, comprising:

5. The server stores the loyalty identifier, The method according to claim 4, further comprising:

6. The server generates a token based on the encrypted data and the loyalty identifier. Furthermore, The aforementioned token is transmitted from the server to the application as a result of the decryption. The method according to claim 3.

7. The aforementioned method, The application receives the token from the server, The aforementioned application generates a barcode based on the aforementioned token, Furthermore, The barcode is used by the application to determine, based on the decryption result, that the server has decrypted the encrypted data. The method according to claim 6.

8. The aforementioned method, The aforementioned application displays the barcode, The scanning device scans the barcode, Furthermore, The application determines, based on the scan results, that the server has decrypted the encrypted data. The method according to claim 7.

9. The aforementioned method, The scanning device decrypts the barcode to obtain the token. The method according to claim 8, further comprising:

10. It is a system, Processor and The system includes a memory for storing instructions, and when an instruction is executed by the processor, the processor receives the instruction. To determine the request for access to the loyalty points account, Receiving encrypted data from a contactless card associated with the account, The encrypted data is sent to the server, The decryption result is received from the server, Based on the decryption result, the server determines that the encrypted data has been decrypted. Based on the determination that the server has decrypted the encrypted data, the server displays multiple points in the loyalty points account. To process redemption requests involving one or more loyalty points, Based on the determination that the server has decrypted the encrypted data, the repayment request will be approved. A system that executes an action.

11. The aforementioned system, The memory stores instructions, and when an instruction is executed by the processor, the processor receives the following information: The first application user credentials are sent to the aforementioned server, Receiving the token as the decryption result from the server, The system according to claim 10, which causes the following to be performed.

12. The aforementioned system, The memory stores instructions, and when an instruction is executed by the processor, the processor receives the following information: To generate a barcode based on the aforementioned token. Make it run, The barcode is used to determine that the server has decrypted the encrypted data. The system according to claim 11.

13. The aforementioned system, The memory stores instructions, and when an instruction is executed by the processor, the processor receives the following information: Display the aforementioned barcode on the display. The system according to claim 12, which causes the execution of the following:

14. The token is based on a combination of the encrypted data and the loyalty identifier associated with the account. The system according to claim 12.

15. A computer-readable storage medium comprising computer-readable program code, wherein the program code, when executed by a processor, is transmitted to the processor. To determine the request for access to the loyalty points account, Receiving encrypted data from a contactless card associated with the account, The encrypted data is sent to the server, The decryption result is received from the server, Based on the decryption result, the server determines that the encrypted data has been decrypted. Based on the determination that the server has decrypted the encrypted data, the server displays multiple points in the loyalty points account. To process redemption requests involving one or more loyalty points, Based on the determination that the server has decrypted the encrypted data, the repayment request will be approved. A computer-readable storage medium that enables execution of [something].

16. A computer-readable storage medium comprising computer-readable program code, wherein the program code, when executed by the processor, is transmitted to the processor. The first application user credentials are sent to the aforementioned server, Receiving the token as the decryption result from the server, A computer-readable storage medium according to claim 15, which enables the execution of the above.

17. A computer-readable storage medium comprising computer-readable program code, wherein the program code, when executed by the processor, is transmitted to the processor. To generate a barcode based on the aforementioned token. Make it run, The barcode is used to determine that the server has decrypted the encrypted data. The computer-readable storage medium according to claim 16.

18. The token is based on the encrypted data and the loyalty identifier associated with the account. The computer-readable storage medium according to claim 16.

19. The token is based on an exclusive OR operation performed on the encrypted data and the loyalty identifier. The computer-readable storage medium according to claim 18.

20. A computer-readable storage medium comprising computer-readable program code, wherein the program code, when executed by the processor, is transmitted to the processor. Display the aforementioned barcode on the display. A computer-readable storage medium according to claim 17, which enables the execution of the following.

Citation Information

Patent Citations

  • Point management device and program

    JP2007257018A

  • Card settlement support method, card settlement support program, and card settlement support device

    JP2009093380A

  • Tap to copy data to clipboard via NFC

    US10438437B1

  • Personal point of sale

    US20160364717A1