Continuous authentication for digital services based on contactless card positioning

The system provides continuous authentication for digital services using a contactless card that maintains authorization as long as it is near the device, addressing the issue of frequent re-authentication and enhancing user experience.

JP7911563B2Active Publication Date: 2026-08-26CAPITAL ONE SERVICES LLC
View PDF 7 Cites 0 Cited by

Patent Information

Application Number
JP2024147139
Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
Priority Date
2019-07-18
Filing Date
2024-08-29
Publication Date
2026-08-26
Estimated Expiration
2040-07-10

AI Technical Summary

Technical Problem

Existing authentication methods for digital services require frequent re-authentication, degrading user experience due to excessive user effort and attention, which is undesirable for security reasons.

Method used

A system utilizing a contactless card to provide continuous authentication based on proximity to a computing device, where the card remains active and continuously provides periodic status messages to maintain authorization as long as it is near the device, terminating access when inactive.

Benefits of technology

Enhances user experience by reducing the need for frequent re-authentication while maintaining security through continuous card presence verification.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007911563000001
    Figure 0007911563000001
  • Figure 0007911563000002
    Figure 0007911563000002
  • Figure 0007911563000003
    Figure 0007911563000003
Patent Text Reader

Abstract

To provide continuous authentication for digital services based on positioning of a contactless card.SOLUTION: Various embodiments relate generally to continuous authentication of a user to digital services based on activity of a contactless card placed in proximity to a computing apparatus on which the digital service operates. For example, a series of periodic status messages between a client apparatus and the contactless card may be provided to verify whether or not the contactless card remains active. The authorization to access the digital services continues while the contactless card is active, and the authorization terminates if the contactless card is inactive.SELECTED DRAWING: Figure 2
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0004] , , ,

[0005] , ,

[0001] Cross - reference to related applications. This application claims priority to U.S. Patent Application Serial No. 16 / 516243, filed on July 18, 2019, entitled "CONTINUOUS AUTHENTICATION FOR DIGITAL SERVICES BASED ON CONTACTLESS CARD POSITIONING", the entire content of which is incorporated herein by reference.

[0002] Technical Field. Embodiments of the present application generally relate to a computing platform, and more specifically, to providing continuous authentication for digital services when a contactless card is located in the vicinity of a computing device.

Background Art

[0003] When accessing services such as digital wallets, websites, networks, applications, etc., typically user authentication is required. Commonly deployed authentication methods include password authentication, iris authentication, face authentication, voice authentication, fingerprint authentication, vein authentication, pre - determined gestures, etc.

Summary of the Invention

Problems to be Solved by the Invention

[0004] For security reasons, these authentication methods impose limitations on the length of time that an authenticated user may continue to log in to a service. However, requiring continuous re - authentication by the user to stay logged out of a service can cause excessive attention and effort on the part of the user, which can degrade the user experience.

Means for Solving the Problems

[0005] Embodiments disclosed herein provide a system, method, product, and computer-readable medium for providing continuous authentication to digital services based on the proximity of a contactless card to a computing device. For example, the system may include a processor circuit and a memory for storing instructions, which, when executed by the processor circuit, cause the processor circuit to: receive a request for access to a digital service by an application running in the processor circuit; receive a first authentication by the application based on verification of a first set of encrypted data associated with a user account; request a second authentication from a contactless card by the application; and receive a second set of encrypted data from the communication interface of a contactless card in response to activation of the contactless card by a card reader in a client device. The second set of encrypted data is generated based on an encryption algorithm and a derived key. The derived key is stored in the memory of the contactless card. The contactless card is activated by a client device when the contactless card is located near the client device. The second set of encrypted data is associated with a user account. The system further includes instructions that, when executed by the processor circuit, cause the processor circuit to perform the following actions: receive a second verification of the user account from the server based on a second set of encrypted data; authorize access to the digital service in response to the first and second verifications of the user account; and verify whether the contactless card remains active by continuously providing a series of periodic status messages between the client device and the contactless card. While the contactless card is active, authorization to access the digital service continues; and if the contactless card is inactive, authorization to access the digital service terminates.

[0006] In another embodiment, the method may include: receiving a request to access a digital service by an application running in a processor circuit; receiving a first authentication by the application based on verification of a first set of encrypted data associated with a user account; and requesting a second authentication from a contactless card by the application. The method may further include: receiving a second set of encrypted data from the communication interface of a contactless card by a card reader of a client device in response to the activation of the contactless card. The second set of encrypted data is generated based on an encryption algorithm and a derived key. The derived key is stored in the memory of the contactless card. The contactless card is activated by the client device when the contactless card is located near the client device. The second set of encrypted data is associated with a user account. The method may further include the application receiving a second verification of the user account from the server based on a second set of encrypted data, the application authorizing access to the digital service in response to the first and second verifications of the user account, and the application verifying whether the contactless card remains active by continuously providing a series of periodic status messages between the client device and the contactless card. While the contactless card is active, authorization to access the digital service continues, and if the contactless card is inactive, authorization to access the digital service terminates.

[0007] According to another embodiment, a non-temporary computer-readable storage medium having computer-readable program code, wherein the computer-readable program code executable by a processor circuit may cause the processor circuit to receive a request to access a digital service by an application running in the processor circuit, receive a first authentication by the application based on verification of a first set of encrypted data associated with a user account, and request a second authentication from a contactless card by the application. The computer-readable program code executable by the processor circuit may further cause the processor circuit to receive a second set of encrypted data from the communication interface of a contactless card in response to the activation of the contactless card by a card reader of a client device. The second set of encrypted data is generated based on an encryption algorithm and a derived key. The derived key is stored in the memory of the contactless card. The contactless card is activated by a client device when the contactless card is located near the client device. The second set of encrypted data is associated with a user account. The computer-readable program code executable by the processor circuit may further cause the processor circuit to perform the following actions: the application receives a second verification of the user account from the server based on a second set of encrypted data; the application authorizes access to the digital service in response to the first and second verifications of the user account; and the application verifies whether the contactless card remains active by continuously providing a series of periodic status messages between the client device and the contactless card. While the contactless card is active, authorization to access the digital service continues; and if the contactless card is inactive, authorization to access the digital service terminates. [Brief explanation of the drawing]

[0008] [Figure 1]This document illustrates an embodiment of a system for providing continuous authentication to digital services. [Figure 2] This document presents an embodiment for providing continuous authentication to digital services based on the approximation of a contactless card to a computing device. [Figure 3] This document presents an embodiment for providing continuous authentication to digital services based on the approximation of a contactless card to a computing device. [Figure 4A] An embodiment of a contactless card is shown. [Figure 4B] An embodiment of a contactless card is shown. [Figure 5A] A side view of an embodiment of a cover for a client device is shown. [Figure 5B] Figure 5A shows an end view of an embodiment of the cover for the client device. [Figure 6] This document presents an embodiment of a logical flow to provide continuous authentication for digital services. [Figure 7] An embodiment of the computing architecture is shown. [Modes for carrying out the invention]

[0009] The drawings are not necessarily to scale. The drawings are for illustrative purposes only and are not intended to depict any specific parameter of the disclosure. The drawings are intended to illustrate exemplary embodiments of the disclosure and should therefore not be considered to limit the scope. Certain components in some of the drawings may be omitted or illustrated at a different scale for clarity of illustration. Furthermore, some reference numerals may be omitted in certain drawings.

[0010] The present disclosure will be described more thoroughly below with reference to the accompanying drawings illustrating several embodiments. The subject matter of this disclosure may be carried out in numerous different forms and should not be construed as limiting to the embodiments described herein. These embodiments are provided so as to make the disclosure detailed and complete and to fully convey the scope of the subject matter to those skilled in the art. Throughout the drawings, similar numbers indicate similar components.

[0011] Embodiments disclosed herein provide continuous authentication of a contactless card based on its proximity to a client device, such as a mobile device or a personal computer. In some embodiments, continuous activation may enable the contactless card to provide authentication with digital services as long as the contactless card is located near the client device's card reader. For example, the presence or absence of the contactless card may be verified by providing a series of periodic "heartbeats" or status messages between the client device and the contactless card. While the contactless card is active, authorization to access digital services continues; if the contactless card is inactive, authorization terminates.

[0012] In some embodiments, a device or cover on the client device may be used to house and position the contactless card relative to the client device. In particular, the cover may include a slot or receptacle located near the card reader of the mobile device. The contactless card may be continuously activated by the electromagnetic field of the client device while it is held inside the cover. This continuous activation may then enable the contactless card to provide authentication with digital services, as long as the contactless card remains inside the cover. Removing the contactless card from the cover may result in a loss of the electromagnetic field, thereby terminating authentication with digital services.

[0013] One advantage is that providing continuous authentication using "heartbeat" or state messaging improves the ease with which users interact with digital services. For example, once authenticated, a user can remain logged into digital services based on authentication as long as their contactless card remains active. By reducing the number of times users must enter their authentication information, the security of card data can be improved.

[0014] Referring generally to the notation and nomenclature used in this application, one or more parts of the detailed descriptions that follow may be presented in relation to program procedures executed on a computer or computer network. The descriptions and expressions of these procedures are used by those skilled in the art to most effectively communicate the content of their work to others skilled in the art. In this application, also generally, a procedure is considered to be a consistent series of actions to produce a desired result. These actions require the physical manipulation of physical quantities. These quantities usually, though not necessarily, take the form of electrical, magnetic, or optical signals that can be stored, transferred, combined, compared, and otherwise manipulated. It is sometimes convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc., mainly for reasons of common usage. However, it should be noted that all these terms and similar terms should be associated with the appropriate physical quantities and are merely convenient labels applied to those quantities.

[0015] Furthermore, these operations are often expressed in terms such as addition or comparison, which are generally associated with mental activity performed by a human operator. However, in any of the operations described herein, which form part of one or more embodiments, such ability of a human operator is unnecessary or, in most cases, undesirable. Rather, these operations are machine operations. Useful machines for performing the operations of the various embodiments include digital computers, and / or devices or digital computers, which are selectively invoked or configured by computer programs described and stored internally in accordance with the disclosures herein, and / or which are specifically configured for the required purpose. The various embodiments also relate to devices or systems for performing these operations. These devices may be specifically configured for the required purpose. The necessary structures for various of these machines will become apparent from the description provided.

[0016] Referring here to the drawings, similar reference numerals are used throughout the drawings to indicate similar components. In the following description, for illustrative purposes, numerous specific details are described to provide a more detailed understanding of them. However, it may become apparent that novel embodiments may be carried out without these specific details. In other examples, known structures and devices are shown in block diagram form to facilitate their description. All modifications, equivalents, and substitutions are intended to be covered within the claims.

[0017] Figure 1 shows a schematic diagram of an exemplary system 100 according to the disclosed embodiment. As shown, the system 100 includes one or more contactless cards 101, one or more client devices 110, and one or more servers 120. The contactless card 101 represents any type of identification and / or payment card, such as a credit card, debit card, ATM card, or gift card. The contactless card 101 may include one or more chips (not shown), such as a radio frequency identification (RFID) chip, configured to communicate with the client device 110 via NFC, the EMV standard, or other short-range protocols in wireless communication. Although NFC is used as an exemplary communication protocol, this disclosure is equally applicable to other types of wireless communication, such as the EMV standard, Bluetooth®, and / or Wi-Fi®. The client device 110 represents any type of computing device with network capabilities, such as a smartphone, tablet computer, wearable device, laptop, or portable game console. Server 120 represents any type of computing device, such as a server, workstation, computing cluster, cloud computing platform, or virtualized computing system.

[0018] As shown, the memory 102 of the contactless card may include card data 103, a counter 104, a master key 105, a diversified key 106, a unique customer identifier 107, and a data storage device 108 for account numbers. The card data 103 generally includes account-related information, such as information used to process payments using the contactless card 101. For example, the card data 103 may include an account number, an expiration date, a billing address, and a card verification value (CVV). The account number may be any type of account number, such as a primary account number (PAN), a virtual account number, and / or a token generated based on the PAN. Other types of account numbers are also contemplated, and the use of the account number or other types of card data 103 should not be considered as limiting the present disclosure. The card data 103 may further include a name, a billing address, a shipping address, and other account-related information. As will be described in more detail in the present application, the contactless card 101 may provide authentication / access to the digital service 114 by providing records from the card data 103 and / or the account number 108 to the account application 113.

[0019] As illustrated, the memory 111 of the client device 110 contains an instance of an operating system (OS) 112. Exemplary operating systems 112 include Android® OS, iOS®, Linux®, and Windows® operating systems. As illustrated, the OS 112 may include an account application 113, digital services 114, one or more other applications 115, and a clipboard 116. In embodiments, the digital services are banking applications or websites, and the account application 113 may allow the user to perform various account-related operations, such as viewing account balances, purchasing goods, and processing payments. Initially, the user must authenticate using authentication credentials to access the account application 113. For example, authentication credentials may include a username and password, biometric credentials, etc. As will be described in detail later, in order to access the account application 113 and / or digital services 114, the user must also satisfy secondary authentication based on data exchanged between the client device 110 and the contactless card 101.

[0020] The digital service 114 may include, but is not limited to, one or more services, including, client device applications (e.g., banking, social media, music streaming, gaming, etc.), websites, messaging services (e.g., email, text, etc.), and many others. Embodiments of the present application are not limited to this context. In some embodiments, the digital service 114 is associated with an account application 113. For example, the digital service 114 is installed on a client device 110 and is operable with the account application 113.

[0021] As shown, server 120 includes data storage device 124 for account data and memory 122. Account data 124 may include account-related data for one or more users and / or accounts. Account data 124 may include at least master key 105, counter 104, customer ID 107, associated contactless card 101, account holder name, account billing address, one or more shipping addresses, one or more card numbers, and history information for each account. Memory 122 may include management application 123 and instances of card data 103, counter 104, master key 105, and derived key 106 related to one or more accounts from account data 124.

[0022] System 100 is configured to perform key diversification to ensure data security. This may also be referred to in this application as key diversification technology. Generally, the same master key 105 (also referred to as a master symmetric key) may be provided to server 120 (or another computing device) and contactless card 101. More specifically, a separate master key 105 having a corresponding pair in server 120 is programmed into each contactless card 101. For example, when contactless card 101 is manufactured, a unique master key 105 may be programmed into memory 102 of contactless card 101. Similarly, the unique master key 105 may be stored in the customer record associated with contactless card 101 in account data 124 of server 120 (and / or may be stored in a different secure location). Master key 105 is kept secret from all parties other than contactless card 101 and server 120, thereby improving the security of system 100.

[0023] The master key 105 may be used in conjunction with the counter 104 to enhance security using key derivation. The counter 104 contains a value synchronized between the contactless card 101 and the server 120. The counter 104 value may contain a number that changes each time data is exchanged between the contactless card 101 and the server 120 (and / or between the contactless card 101 and the client device 110). To enable NFC data transfer between the contactless card 101 and the client device 110, the account application 113 may communicate with the contactless card 101 if the contactless card 101 is close enough to the card reader 118 of the client device 110. The card reader 118 may be configured to read from (and / or communicate with) the contactless card 101 (e.g., via NFC, Bluetooth, RFID, etc.). Thus, the exemplary card reader 118 may include an NFC communication module, a Bluetooth communication module, and / or an RFID communication module.

[0024] For example, the user may move the contactless card 101 to the location of the client device 110, thereby bringing the contactless card 101 close enough to the card reader 118 of the client device 110 to enable NFC data transfer between the contactless card 101 and the card reader 118 of the client device 110. In some embodiments, the client device 110 may trigger the card reader 118 via an application programming interface (API) call. As an addition or alternative, the client device 110 may trigger the card reader 118 based on periodically polling it. More generally, the client device 110 may trigger the card reader 118 to engage in communication using any feasible method. In some embodiments, the contactless card 101 may be powered / activated in response to the magnetic field of the client device 110.

[0025] After communication is established between the client device 110 and the contactless card 101, the contactless card 101 may generate a message authentication code (MAC) ciphertext. In some embodiments, this may be done when the contactless card 101 is read by the account application 113. In particular, this may be done when a near-field data exchange (NDEF) tag is read, for example, an NFC read, which may be generated according to an NFC data compatible format. For example, the account application 113 and / or a reader such as the card reader 118 may send a message having the applet ID of an NDEF generating applet, for example, an applet selection message. When the selection is confirmed, a sequence may be sent in which a file selection message is followed by a file read message. For example, the sequence may include "Function File Selection", "Function File Read", and "NDEF File Selection". In this regard, the counter value 104 held by the contactless card 101 may be updated or incremented, followed by "NDEF File Read". In this regard, a message may be generated which may include a header and a shared secret. A session key may then be generated. The MAC ciphertext may be generated from the message, which may include a header and a shared secret. The MAC ciphertext may then be concatenated with random data spanning one or more blocks, and the MAC ciphertext and random numbers (RNDs) may be encrypted with the session key. The ciphertext and header may then be concatenated, encoded as ASCII hexadecimal, and returned in NDEF message format (in response to the “NDEF file read” message). In some embodiments, the MAC ciphertext may be sent as an NDEF tag, and in other embodiments, the MAC ciphertext may be included with a uniform resource indicator (e.g., as a formatted string).The contactless card 101 may then transmit the MAC ciphertext to the client device 110, which may then forward the MAC ciphertext to the verification server 120, as described below. However, in some embodiments, the client device 110 may verify the MAC ciphertext. Embodiments of the present application are not limited to this context.

[0026] More generally, when preparing to transmit data (for example, to a server 120 and / or client device 110), the contactless card 101 may increment the value of counter 104. The contactless card 101 may then provide the master key 105 and the value of counter 104 as input to a cryptographic algorithm, which generates a derived key 106 as output. The cryptographic algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cipher-based message authentication code (CMAC) algorithms, and the like. Examples of non-restrictive cryptographic algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. The contactless card 101 may then encrypt the data (for example, customer identifier 107 and other arbitrary data) using the derived key 106. Next, the contactless card 101 may transmit encrypted data (e.g., encrypted customer ID 109) to the account application 113 of the client device 110 (e.g., via NFC connection, Bluetooth connection, etc.). The account application 113 of the client device 110 may then transmit the encrypted data to the server 120 via the network 130. In at least one embodiment, the contactless card 101 transmits the counter 104 value along with the encrypted data. In such an embodiment, the contactless card 101 may transmit either an encrypted or unencrypted counter 104 value.

[0027] When the encrypted customer ID 109 is received, the management application 123 of the server 120 may perform the same symmetric encryption using the counter 104 value as the input for encryption and the master key 105 as the key for encryption. As described above, the counter 104 value may be specified in the data received from the client device 110, or the counter 104 value may be held by the server 120 to perform key derivation for the contactless card 101. The output of the encryption may be the same derived key value 106 generated by the contactless card 101. The management application 123 may then decrypt the encrypted customer ID 109 received via the network 130 using the derived key 106. This reveals the data transmitted by the contactless card 101 (e.g., at least the customer identifier 107). In doing so, the management application 123 can verify the data transmitted by the contactless card 101 via the client device 110 (e.g., by comparing the decrypted customer ID 107 with the customer ID in the account data 124 for the account).

[0028] While counter 104 is used as an example, other data may be used to ensure the security of communication between the contactless card 101, the client device 110, and / or the server 120. For example, counter 104 may be replaced with a random nonce, generated whenever a new derived key 106 is needed, the entire counter value may be sent from the contactless card 101 and the server 120, a portion of the counter value may be sent from the contactless card 101 and the server 120, the counter may be held independently by the contactless card 101 and the server 120 but not sent between them, a one-time passcode may be exchanged between the contactless card 101 and the server 120, or it may be a cryptographic hash of the data. In some embodiments, one or more portions of the derived key 106 may be used by the parties to generate multiple derived keys 106.

[0029] As shown in the figures, the server 120 may include one or more hardware security modules (HSMs) 125. For example, one or more HSMs 125 may be configured to perform one or more cryptographic operations as disclosed herein. In some embodiments, one or more HSMs 125 may be configured as special-purpose security devices configured to perform one or more cryptographic operations. The HSMs 125 may be configured such that keys are never revealed outside the HSMs 125, but instead held inside the HSMs 125. For example, one or more HSMs 125 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 125 may be included inside the server 120 or may communicate with the server 120 for data.

[0030] As described above, key derivation techniques may be used to perform secure operations using the contactless card 101. For example, once the management application 123 verifies the encrypted customer ID 109 by key derivation, the management application 123 may send the account number, expiration date, and / or the CVV associated with the account to the account application 113 on the client device 110. The management application 123 may also include other information (e.g., first name, last name, mailing address, invoice issuing address, and other account information). The account number may be a PAN, a virtual account number, and / or a token generated based on the PAN. The account application 113 may decrypt the received data (if encrypted) and provide the account number, expiration date, invoice issuing address, and / or CVV to the API of the digital service 114.

[0031] In another embodiment, the card data 103 is read directly from the contactless card 101. This can be useful when the client device 110 does not have a connection to the server 120. For example, the account application 113 and / or digital service 114 may output an indication prompting the contactless card 101 to move closer to the client device 110. In one embodiment, once the contactless card 101 is moved close to the client device 110, the contactless card 101 transmits the card data 103 to the client device 110. In another embodiment, once the contactless card 101 is moved close to the client device 110, the account application 113 may instruct the contactless card 101 to transmit the card data 103 to the client device 110. In one embodiment, the contactless card 101 transmits card data 103 (including one or more of the account number, expiration date, CVV value, and account holder's name) to the client device 110 as an NDEF file (e.g., via NFC, Bluetooth, and / or RFID). In another embodiment, the contactless card 101 transmits the card data 103 using the EMV protocol. In embodiments where the EMV protocol is used, the card data 103 transmitted using the EMV protocol includes the account number, expiration date, and account holder's name. The contactless card 101 may then transmit the card data 103 to the account application 113 using the EMV protocol. In embodiments where the EMV protocol is used, the account application 113 may receive from the contactless card 101 (e.g., by receiving the CVV in the NDEF file via NFC reading) and / or from the management application 123 on the server 120. However, in some embodiments, the EMV protocol may be used to directly transmit the CVV value from the contactless card 101. The account application 113 may then provide the card data 103 (e.g., account number, expiration date, and / or CVV) to the API of the digital service 114.

[0032] Regardless of the technology used to provide card data 103 and / or account number 108 to the digital service 114, the account application 113 and / or OS 112 may manage the data provided to the digital service 114. For example, as long as the contactless card 101 is active, for example, when located adjacent to the client device 110, the card data 103 and / or account number 108 may be retained in the digital service 114. Thus, access / authentication to the digital service 114 is maintained. In another embodiment, after the card data 103 and / or account number 108 have been used to make a purchase, the card data 103 and / or account number 108 may be retained in the digital service 114.

[0033] Furthermore, the account application 113 and / or the digital service 114 may copy the account number to the OS clipboard 116. The clipboard 116 stores data that can be copied and / or pasted into the OS 112. For example, the clipboard 116 may store data locally for pasting into a field on the client device 110, and the user may input / paste the data stored in the clipboard 116 using commands and / or gestures available in the OS 112. For example, by copying the account number to the clipboard 116, the user can paste the account number into the corresponding form field using commands and / or gestures available in the OS 112. Furthermore, the digital service 114 may output a notification specifying the expiration date and CVV while the account number is being copied to the clipboard 116. This allows the user to manually input the expiration date and CVV into the corresponding form field while the notification is visible. In some embodiments, the account application 113 and / or digital service 114 may copy the expiration date, invoice address, and / or CVV to the clipboard 116, so that the expiration date, invoice address, and / or CVV can be pasted into the corresponding form fields.

[0034] Figure 2 is a schematic diagram 200 illustrating an exemplary embodiment that provides continuous authentication to a digital service 214 based on the proximity of a contactless card 201 to a client device such as a mobile device 210. The mobile device 210 may be a smartphone or a tablet computer, but is not limited to this embodiment. In other embodiments, the client device may be a laptop, desktop computer, or transaction kiosk. For example, the client device may be a laptop computer with an internal or external reader for communicating with the contactless card 201. Embodiments of the present application are not limited to this context.

[0035] In this non-limiting embodiment, the digital service 214 may be a banking application stored in the memory of the mobile device 210. The user may move the contactless card 201 closer to the physical vicinity of the mobile device 210. Power obtained from the electromagnetic field 227 of the mobile device 210 may then activate one or more chips and / or chip modules (not shown) of the contactless card 201. More specifically, the contactless card 201 is operable to receive the electromagnetic field 227 and convert it into a voltage suitable for powering other circuit components of the contactless card 201. For example, the electromagnetic field 227 may be converted to power an RFID chip configured to communicate with the mobile device 210 via, for example, NFC, EMV standards, or other short-range protocols of wireless communication.

[0036] When a user first attempts to log in to their account, the login credentials received by the API 221 of the digital service 214 are sent to the server 220 as a first set of encrypted data 216. The first set of encrypted data 216 may be associated with the user account 228, which is then associated with the data storage device of the account data 224.

[0037] Next, the server 220 may, for example, use a management application 123 (Figure 1) to compare the first set 216 of encrypted data with the customer identifier in the account data 224 related to the user account 228, and confirm whether the data is valid or invalid accordingly. If they match, the first authentication / verification 230 is provided to the mobile device 210.

[0038] Next, the digital service 214 may request a second authentication 232 from the contactless card 201. In some embodiments, the contactless card 201 may be pre-activated based on an electromagnetic field 227 received from the client device 201. In other embodiments, the contactless card 201 may be inactive, in which case it needs to be activated to complete the request for the second authentication 232. For example, the user may not have pre-positioned the contactless card 201 near the mobile device 210, or the position of the contactless card 201 relative to the card reader 218 of the mobile device 210 may result in an inappropriate strength of communication signal emanating from the contactless card 201. In any case, the mobile device 210 may prompt the user via a graphical user interface (GUI). For example, the notification may instruct the user to physically touch the contactless card 201 to the back of the mobile device 210. In other embodiments, the notification may provide feedback regarding the strength of the electromagnetic field 227 and / or the signal strength of the contactless card 201.

[0039] Once the contactless card 201 is activated, the card reader 218 of the mobile device 201 may receive a second set 234 of encrypted data from the communication interface 236 of the contactless card 201. In some embodiments, the second set 234 of encrypted data may be generated based on an encryption algorithm and a derived key stored in the memory of the contactless card 201. The second set 234 of encrypted data is associated with the user account 228.

[0040] Next, the server 220 may receive a second set 234 of encrypted data from the mobile device 210 and compare it with the customer identifier in the account data 224 relating to user account 228, and accordingly verify whether the data is valid or invalid. If they match, a second authentication / verification 238 is provided to the mobile device 210. Then, for example, in response to the first verification 230 and the second verification 238 of user account 228, the account application 213 may provide access to the digital service 214.

[0041] Once a user successfully logs into the digital service 214, authorization to access the digital service 214 continues as long as the contactless card 201 is active. To achieve this, the account application 213 may verify whether the contactless card 201 is still active by having a series of periodic heartbeats or status messages 250 exchanged between the mobile device 210 and the contactless card 201. In some embodiments, the status messages 250 may be a series of requests or "pings" to the contactless card 201, which result in a communication response via the antenna 229 of the contactless card 201. For example, the status messages 250 may trigger the card reader 218 of the contactless card 201 via an application programming interface (API) call. However, the status messages 250 may trigger the card reader to engage in communication using any feasible method. If it is determined that the contactless card 201 is inactive, for example, if no communication response is received by the contactless card 201, authorization to access the digital service 214 may be terminated.

[0042] While not limited to these, the status message 250 can be transmitted unencrypted, encrypted, signed, or otherwise securely. In some embodiments, the status message 250 may include one or more verification messages, which include, for example, reporting the active / inactive status of the contactless card 201. Furthermore, the status message 250 may relate to a first verification 230 and / or a second verification 238.

[0043] In some embodiments, the status message 250 may include sending any type of command or query that is transmitted securely or openly, receiving a response from the contactless card 201, and then evaluating the response to determine whether the response falls within the expected parameter range. In yet another embodiment, the mobile device 210 may include a timer 252 configured to periodically transmit the status message 250. Access to the digital service 214 may continue until the account application 213 determines that the signal strength of the contactless card 201 is below a predetermined threshold. This may occur, for example, when the contactless card 201 is moved from the mobile device 210 or when the mobile device 210 enters sleep mode. In some embodiments, the account application 213 may prevent the mobile device 210 from entering sleep mode while the contactless card 201 is active.

[0044] Figure 3 is a schematic diagram 300 illustrating an exemplary embodiment that provides continuous authentication to a digital service 314 based on the proximity of a contactless card 301 to a mobile device 310. Schematic diagram 300 may be similar to schematic diagram 200 described above. Thus, for the sake of brevity, only certain aspects of schematic diagram 300 will be described below.

[0045] As shown in the figure, schematic diagram 300 may include a second client device 311, such as a personal computer. In this non-limiting embodiment, the digital service 314 may be a banking website that operates on / is displayed on the second client device 311. The account application 313 may be located on the second client device 311. In other embodiments, the account application 313 may be part of the mobile device 310. In yet another embodiment, the account application 313 may be split between the mobile device 310 and the second client device 311.

[0046] When a user first attempts to log in to their account, the login credentials received by the digital service 314 are sent to the server 320 as a first set of encrypted data 316, which may be associated with the user's user account 328. The server 320 may then compare the first set of encrypted data 316 against the customer identifier in the account data 324 relating to the user account 328, for example, by a management application, and verify the validity or invalidity of the data accordingly. If they match, a first authentication / verification 330 is provided from the server 320 to the second client device 311.

[0047] Next, the digital service 314 may request a second authentication 332 from the contactless card 301. In some embodiments, the second authentication 332 request may be sent directly to the mobile device 310, or it may be sent to the server 320 for later transmission to the mobile device 310. The contactless card 301 may be pre-activated based on the magnetic field 327 received from the client device 301. In other embodiments, the contactless card 301 may be inactive, in which case it is necessary to activate the contactless card 301 to complete the request for the second authentication 332.

[0048] Once the contactless card 301 is activated, the card reader 318 of the mobile device 301 may receive a second set of encrypted data 334 from the communication interface 336 of the contactless card 301. In some embodiments, the second set of encrypted data 334 may be generated based on an encryption algorithm and a derived key stored in the memory of the contactless card 301. The second set of encrypted data 334 is associated with the user account 328.

[0049] Next, the server 320 may receive a second set 334 of encrypted data from the mobile device 310 and compare it with the customer identifier in the account data 324 relating to user account 328, and accordingly verify whether the data is valid or invalid. If they match, a second authentication / verification 338 is provided to the second client device 311. Then, for example, in response to the first verification 330 and the second verification 338 of user account 328, the account application 313 may provide access to the digital service 314.

[0050] Once a user successfully logs into the digital service 314, authorization to access the digital service 314 may continue as long as the contactless card 301 is active. To achieve this, the account application 313 may verify whether the contactless card 301 is still active by having a series of periodic heartbeats or status messages 350 provided between the mobile device 310 and the contactless card 301. In some embodiments, the status messages 350, or the output of the status messages (e.g., contactless card active / inactive), may be sent to the server 320 and then to the two client devices 311. In some embodiments, the status messages 350 may be transmitted directly to the second client device 311. If it is determined that the contactless card 301 is inactive, authorization to access the digital service 314 may be terminated.

[0051] Figure 4A shows an exemplary contactless card 401. This may be a payment card such as a credit card, debit card, and / or gift card. As shown, the contactless card 401 may be issued by a service provider 405, which is displayed on the front or back of the card 401. In some embodiments, the contactless card 401 may include an identification card, which is not related to a payment card and is not limited thereto. In some embodiments, the payment card may include a dual-interface contactless payment card. The contactless card 401 may comprise a substrate 410, which may comprise a single layer or one or more laminated layers made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, anodized titanium, palladium, gold, carbon, paper, and biodegradable materials. In some embodiments, the contactless card 401 may have physical characteristics conforming to the ID-1 format of the ISO / IEC 7810 standard, or the contactless card may conform to the ISO / IEC 14443 standard. However, the contactless card 401 relating to this disclosure may have different characteristics, and it should be understood that this disclosure does not require the contactless card to be implemented as a payment card.

[0052] The contactless card 401 may include identification information 415 displayed on the front and / or back of the card, and a contact pad 420. The contact pad 420 may be configured to establish contact with one or more client devices 110 (Figure 1), user devices, smartphones, laptops, desktops, or tablet computers, or other communication devices. The contactless card 401 may include processing circuits, antennas, and other components not shown in Figure 4A. These components may be located on the back of the contact pad 420 or elsewhere on the substrate 410. The contactless card 401 may include a magnetic strip or tape, which may be located on the back of the card (not shown in Figure 4A).

[0053] As shown in Figure 4B, the contact pads 420 of the contactless card 401 may include a processing circuit 425, which includes a microprocessor 430 and memory 102 for storing and processing information. It is understood that the processing circuit 425 may include additional components, including a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitives, and tamper-proof hardware, which are necessary to perform the functions described herein.

[0054] Memory 102 may be read-only memory, one-write multiple-read memory, or read / write memory, such as RAM, ROM, and EEPROM, and the contactless card 401 may include one or more of these memories. Read-only memory is programmable to be read-only or one-time programmable, so that it is read only once or only once. One-time programmability provides the opportunity to be written only once and then read multiple times. One-write / multiple-read memory may be programmed after the memory chip leaves the factory. Once memory 102 is programmed, it will not be rewritten but will be read multiple times. Read / write memory may be programmed and reprogrammed multiple times after leaving the factory. Read / write memory may also be read multiple times after leaving the factory.

[0055] Memory 102 may be configured to store one or more applets 440, one or more counters 104, a customer identifier 107, and a virtual account number 108. One or more applets 440 may include one or more software applications configured to run on one or more contactless cards, such as a Java® card applet. However, it is understood that applet 440 is not limited to a Java card applet, but may instead be any software application capable of running on a contactless card or other device with limited memory. One or more counters 104 may comprise numeric counters sufficient to store integers. The customer identifier 107 may include a unique alphanumeric identifier assigned to a user of a contactless card 401, the identifier may distinguish the user of the contactless card from other contactless card users. In some embodiments, the customer identifier 107 may identify both the customer and the account assigned to that customer, and further may identify the contactless card 401 associated with the customer's account. In some embodiments, account number 108 may include thousands of one-time use virtual account numbers associated with the contactless card 401.

[0056] The processor and memory components of the exemplary embodiments described above are described with reference to the contact pads, but the disclosure is not limited thereto. These components may be mounted outside of the pads 420 or completely separate from them, or they may be mounted as additional components in addition to the processor 430 and memory 402 components provided within the contact pads 420.

[0057] In some embodiments, the contactless card 401 may include one or more antennas (not shown). Generally, using the antennas, processing circuitry 425, and / or memory 102, the contactless card 401 may provide a communication interface for communication via NFC, Bluetooth, and / or Wi-Fi communication. In some embodiments, the antennas may be located within the contactless card 401, around the processing circuitry 425 of the contact pads 420. For example, the antennas may be integrated with the processing circuitry 425, and one or more antennas may be used with external booster coils. In another embodiment, the antennas may be located outside the contact pads 420 and the processing circuitry 425. As described above, the antennas may transmit responses to status messages indicating whether the contactless card 401 is active or not. If no communication response is received from the antennas, authorization to access one or more digital services may be terminated.

[0058] As described above, the contactless card 401 may be configured on a software platform that can operate on other smart cards or devices with limited memory, such as JavaCard, and one or more applications or applets may be securely executed. An applet 440 may be added to the contactless card to provide a one-time password (OTP) for multifactor authentication (MFA) in various usage scenarios based on mobile applications. The applet 440 may be configured to respond to one or more requests, such as a Near Field Data Exchange request, from a reader (e.g., a mobile NFC reader on a client device 110) and generate an NDEF message containing a cryptographically secure OTP encoded as an NDEF text tag.

[0059] An example of an NDEF OTP is the NDEF short record layout (SR=1). In such embodiments, one or more applets 440 may be configured to encode the OTP as a well-known type of text tag of NDEF type 4. In some embodiments, an NDEF message may include one or more records. Applet 440 may be configured to add one or more static tag records in addition to the OTP records.

[0060] In some embodiments, one or more applets 440 may be configured to emulate RFID tags. The RFID tags may include one or more different forms of tags. In some embodiments, each time a tag is read, different cryptographic data that may indicate the authenticity of a contactless card is presented. Based on one or more applications, the NFC reading of the tag may be processed, and the data may be sent to a server such as server 120 (Figure 1), where the data may be verified.

[0061] In some embodiments, the contactless card 401 and the server 120 may include predetermined data so that the contactless card 401 can be properly identified. The contactless card 401 may include one or more unique identifiers. Each time a read operation is performed, the counter 104 may be configured to increment based on the recognition of one or more unique identifiers. In some embodiments, each time data is read from the contactless card 401 (e.g., by a client device 110), the counter 104 is sent to the server for verification to determine whether the counter value 104 is equal (e.g., as part of the verification).

[0062] In some embodiments, two encryption keys may be uniquely assigned to each card during the generation process of the contactless card 401. The encryption keys may include symmetric keys that can be used for both encryption and decryption of data. The triple DES (3DES) algorithm may be used by EMV, which is implemented in hardware in the contactless card 101. By using a key derivation process, one or more keys may be derived from a master key based on uniquely identifiable information relating to each entity that requires a key.

[0063] In some embodiments, to overcome the shortcomings of the 3DES algorithm, which may be susceptible to vulnerabilities, a session key (such as a unique key per session) may be derived, but instead of using a master key, a unique key and counter derived by the card may be used as derived data. For example, each time a contactless card 401 is used during operation, a different key may be used to generate and encrypt the message authentication code (MAC). This results in three layers of encryption. The session key may be generated by one or more applets and derived using an application transaction counter with one or more algorithms (such as those defined in "EMV 4.3 Book 2 A1.3.1 Common Session Key Derivation").

[0064] Furthermore, the increment for the contactless card 401 may be unique, assigned by personalization, or algorithmically assigned by some identifying information. For example, cards with odd numbers may be incremented by 2, and cards with even numbers may be incremented by 5. In some embodiments, the increment may vary in sequential reading, such that a single card may be incremented in a repeating order of 1, 3, 5, 2, 2, ... A particular sequence or algorithmic sequence may be defined at the time of personalization or from one or more processes derived from a unique identifier. This makes it more difficult for a replay attacker to generalize from the small numbers of card instances.

[0065] The authentication message may be sent as the content of a text NDEF record having a hexadecimal ASCII format. In another embodiment, the NDEF record may be encoded in hexadecimal format.

[0066] Figures 5A and 5B show non-limiting embodiments of a cover 560 over a client device 510, such as a mobile device. The cover 560 may also be a case for the mobile device surrounding the client device 510. In some embodiments, the cover 560 may include an opening to allow user interaction with the screen 562 of the client device 510. As shown, the cover 560 may include a slot or receptacle 566 via an end wall 568 of the cover 560, the receptacle 566 being operable to accommodate a contactless card 501 therein. Once held in the receptacle 566, the contactless card 501 may be pre-positioned to allow communication with a card reader (not shown) of the client device 510. It will be recognized that the cover 560, including the size and position of the receptacle 566, may be modified depending on one or more characteristics of the client device 501 and / or the contactless card 501. As further illustrated, the receptacle 566 and the contactless card 501 may be arranged along the rear surface 570 of the client device 510. In some embodiments, the cover 560 may be transparent or opaque. Embodiments of the present application are not limited to this context.

[0067] Figure 6 shows an embodiment of the logical flow 600 for providing continuous authentication to a digital service. In block 601-600, the logical flow block 601-600 may include receiving a request to access the digital service by an application running in the processor circuit. In some embodiments, the digital service may include, but is not limited to, one or more services including, client device applications (e.g., banking, social media, music streaming, gaming, etc.), websites, or messaging services (e.g., email, text, etc.). In block 603, the logical flow 600 may include receiving a first authentication by the application based on verification of a first set of encrypted data associated with a user account. In some embodiments, the first set of encrypted data is generated based on login credentials supplied to the digital service by the user. In block 605, the logical flow 600 may include requesting a second authentication from a contactless card by the application.

[0068] In block 607, the logical flow 600 may include the client device's card reader receiving a second set of encrypted data from the contactless card's communication interface in response to the activation of the contactless card. The second set of encrypted data is generated based on an encryption algorithm and a derived key. The derived key is stored in the contactless card's memory. The contactless card is activated by the client device when the contactless card is located near the client device. The second set of encrypted data is associated with a user account.

[0069] In block 609, the logical flow 600 may include the application receiving a second verification of the user account from the server based on a second set of encrypted data. In block 611, the logical flow may include the application authorizing access to the digital service in response to the first and second verifications of the user account. In block 613, the logical flow may include the application verifying whether the contactless card remains active by continuously providing a series of periodic status messages between the client device and the contactless card. While the contactless card is active, authorization to access the digital service continues; if the contactless card is inactive, authorization to access the digital service terminates.

[0070] In some embodiments, the contactless cards described herein may be placed on one or more devices such as computer kiosks or terminals to verify identification information in order to receive transactional goods in response to purchases such as coffee. By using contactless cards, a secure method of verifying identification information can be established in loyalty programs. For example, securely verifying identification information to obtain rewards, coupons, offers, etc., or to receive benefits, can be established in a way different from simply scanning a bar card. For example, encrypted transactions may take place between the contactless card and the device, which may constitute processing one or more tap gestures. As described above, one or more applications may be configured to verify the user's identification information. In some embodiments, data, such as bonus points, loyalty points, reward points, or healthcare information, may be written back to the contactless card.

[0071] In some embodiments, the exemplary authentication communication protocol may mimic, with some modifications, an EMV standard offline dynamic data verification protocol commonly performed between transaction cards and point-of-sale (POS) devices. For example, since the exemplary authentication protocol is not used to complete payment transactions with the card issuer / payment processor itself, some data values ​​are unnecessary, and authentication can be performed without a real-time online connection to the card issuer / payment processor. As is known in the art, the point-of-sale (POS) system submits a transaction to the card issuer that includes transaction values. Whether the issuer approves or rejects the transaction may be based on whether the card issuer recognizes the transaction values. On the other hand, in certain embodiments of this disclosure, a transaction originating from a client device lacks transaction values ​​associated with the POS system. Therefore, in some embodiments, a dummy transaction value (i.e., a value that is recognizable to the card company and sufficient to trigger) may be passed as part of the exemplary authentication communication protocol. A POS-based transaction may be rejected based on the number of transaction attempts (e.g., a transaction counter). An attempt exceeding a buffer value may result in a soft rejection. Soft rejection requires further verification before accepting a transaction. In some implementations, the buffer value for the transaction counter may be modified to avoid rejecting legitimate transactions.

[0072] In some embodiments, contactless cards can selectively transmit information depending on the receiving device. Once moved to a nearby location, the contactless card can recognize the device it is directed to, and based on this recognition, it can provide the appropriate data for that device. The advantage of this is that it allows the contactless card to transmit only the information necessary to complete an immediate action or transaction, such as payment or card authentication. By limiting the transmission of data and avoiding the transmission of unnecessary data, both efficiency and data security can be improved. Information recognition and selective communication are applicable to a variety of scenarios, including card activation, balance transfers, account access attempts, commercial transactions, and reduction of step-up bias.

[0073] In another embodiment, continuous authentication may be directed to a POS device, including but not limited to a kiosk, checkout register, payment station, or other terminal. The contactless card can recognize the POS device and transmit only the information necessary for the operation or transaction. For example, upon recognizing a POS device used to complete a commercial transaction, the contactless card can transmit the payment information necessary to complete the transaction under the EMV standard.

[0074] In some embodiments, a POS device participating in a transaction may request or specify additional information to be provided by the contactless card, such as device-specific information, location-specific information, or transaction-specific information. For example, once a POS device receives data communication from a contactless card, it may request additional information necessary to recognize the contactless card and complete an operation or transaction.

[0075] In some embodiments, the POS device may be enrolled in an authorized commercial or other entity that is familiar with a given contactless card or accustomed to performing a given contactless card transaction. However, it should be understood that such enrollment is not required for the implementation of the described method.

[0076] In some embodiments, such as in shopping stores, grocery stores, and convenience stores, a contactless card may be placed in or near a client device without requiring the client to open an application, in order to indicate a request or intention to cover one or more purchases using one or more of the following: reward points, loyalty points, coupons, offers, etc. In this way, the intention behind the purchase is provided.

[0077] Figure 7 shows an exemplary embodiment of a computing architecture 800 comprising a computing system 802 which may be suitable for implementing the various embodiments described above. In various embodiments, the computing architecture 800 may include or be implemented as part of an electronic device. In some embodiments, the computing architecture 800 may represent, for example, a system 100 (Figure 1) that implements one or more components of the system. In some embodiments, the computing system 802 may represent, for example, a client device 110 and a server 120 of system 100. Embodiments of the present application are not limited to this context. More generally, the computing architecture 800 is configured to implement all the logic, applications, systems, methods, devices, and functions described herein with reference to Figures 1 to 6.

[0078] As used herein, the terms “system,” “component,” and “module” are intended to refer to computer-related entities, hardware, combinations of hardware and software, software, or running software, examples of which are provided by the exemplary computing architecture 800. For example, a component may be, but is not limited to, a process running on a computer processor, a computer processor, a hard disk drive, multiple storage drives (optical and / or magnetic storage media), an object, an executable file, an execution thread, a program, and / or a computer. Exemplarily, both an application running on a server and the server itself may be components. One or more components may reside within a single process / execution thread, a component may be localized in one computer, and / or distributed across two or more computers. Furthermore, multiple components may be connected communicatively to one another by various types of communication media to coordinate their operation. Coordinated operation may involve unidirectional or bidirectional exchange of information. For example, components may transmit information in the form of signals transmitted over a communication medium. Information may be implemented as signals assigned to various signal lines, where each message is a signal. However, in another embodiment, data messages may be used as an alternative. Such data messages may be transmitted over various connections. Exemplary connections include parallel interfaces, serial interfaces, and bus interfaces.

[0079] The computing system 802 includes a variety of common computing elements, such as one or more processors, multicore processors, coprocessors, memory units, chipsets, controllers, peripherals, interfaces, oscillators, timing devices, video cards, audio cards, multimedia input / output (I / O) components, power supplies, and so on. However, the embodiments are not limited to the implementation example using the computing system 802.

[0080] As shown in Figure 7, the computing system 802 comprises a processor 804, system memory 806, and a system bus 808. The processor 804 may be any of a variety of commercially available computer processors, including but not limited to AMD's Athlon®, Duron®, and Opteron® processors, ARM®'s Application, Embedded, and Secure Processors, IBM® and Motorola®'s DragonBall® and PowerPC® processors, IBM and Sony®'s Cell processors, and Intel®'s Celeron®, Core®, Core(2)Duo®, Itanium®, Pentium®, Xeon®, and XScale® processors, and similar processors. A dual microprocessor, a multi-core processor, and other multiprocessor architectures may be used as the processor 804.

[0081] The system bus 808 provides interfaces for system components, including but not limited to system memory 806 through processor 804. The system bus 808 may be one of several types of bus structures that can further interconnect to the memory bus (with or without the memory controller), peripheral bus, and local bus using any of various commercially available bus architectures. Interface adapters may be connected to the system bus 808 via slot architectures. Exemplary slot architectures may include, but are not limited to, AGP (Accelerated Graphics Port), CardBus, (E)ISA ((Extended) Industry Standard Architecture), MCA (Micro Channel Architecture), NuBus, PCI(X) (Peripheral Component Interconnect (Extended)), PCI Express, and PCMCIA (Personal Computer Memory Card International Association).

[0082] The system memory 806 may include various types of computer-readable storage media in the form of one or more faster memory units, such as ROM (read-only memory), RAM (random-access memory), DRAM (dynamic RAM), DDRAM (Double-Data-Rate DRAM), SDRAM (synchronous DRAM), SRAM (static RA), PROM (programmable ROM), EPROM (erasable programmable ROM), EEPROM (electrically erasable programmable ROM), flash memory (e.g., one or more flash arrays), polymer memory such as ferroelectric polymer memory, ovonic memory, phase-change or ferroelectric memory, SONOS (silicon-oxide-nitride-oxide-silicon) memory, magnetic or optical cards, RAID (array of devices such as Redundant Array of Independent Disks) drives, solid-state memory devices (e.g., USB memory, SSD (solid-state drive)), and any other type of storage medium suitable for storing information. In the embodiment shown in Figure 8, the system memory 806 may include a non-volatile memory 810 and / or a volatile memory 812. The BIOS (basic input / output system) may be stored in the non-volatile memory 810.

[0083] The computing system 802 may include various types of computer-readable storage media having one or more forms of slower memory units, including an internal (or external) HDD (hard disk drive) 814, a magnetic FDD (floppy disk drive) 816 for reading from or writing to a removable magnetic disk 818, and an optical disk drive 820 for reading from or writing to a removable optical disk 822 (e.g., a CD-ROM or DVD). The HDD 814, FDD 816, and optical disk drive 820 may be connected to the system bus 808 by an HDD interface 824, an FDD interface 826, and an optical drive interface 828, respectively. The HDD interface 824 for external drive implementation may include at least one or both of USB (Universal Serial Bus) and IEEE 1394 interface technologies. The computing system 802 is generally configured to implement all the logic, systems, methods, devices, and functions described herein with reference to Figures 1 to 6.

[0084] The drive and associated computer-readable media provide volatile and / or non-volatile storage devices such as data, data structures, and computer-executable instructions. For example, a number of program modules, including an operating system 830, one or more application programs 832, other program modules 834, and program data 836, may be stored in the drive and memory units 810, 812. In one embodiment, one or more application programs 832, other program modules 834, and program data 836 may include, for example, various applications and / or components of system 100, such as an operating system 112, an account application 113, a digital services application 114, other applications 115, a clipboard application 116, and a management application 123.

[0085] The user can input commands and information to the computing system 802 via one or more wired / wireless input devices, such as a keyboard 838 and a pointing device such as a mouse 840. Other input devices may include microphones, infrared (IR) remote controls, radio frequency (RF) remote controls, gamepads, stylus pens, card readers, dongles, fingerprint readers, gloves, graphics tablets, joysticks, keyboards, retina readers, touchscreens (e.g., capacitive, resistive, etc.), trackballs, trackpads, sensors, styluses, etc. These and other input devices are often connected to the processor 804 via an input device interface 842 connected to the system bus 808, but may also be connected via other interfaces such as a parallel port, an IEEE 1394 serial port, a game port, a USB port, or an IR interface.

[0086] Monitor 844 or other types of display devices are also connected to the system bus 808 via an interface such as video adapter 846. Monitor 844 may be located inside or outside the computing system 802. In addition to Monitor 844, the computer typically includes other peripheral output devices such as speakers and printers.

[0087] The computing system 802 may operate in a networked environment using logical connections via wired and / or wireless communication to one or more remote computers, such as remote computers 848. The remote computers 848 may be workstations, server computers, routers, personal computers, portable computers, microprocessor-based entertainment devices, peer devices, or other common network nodes, and while only memory / storage 850 is illustrated for brevity, they typically include many or all of the components described in relation to the computing system 802. The illustrated logical connections include wired / wireless connections to a LAN (local area network) 852 and / or a larger network, such as a WAN (wide area network) 854). Such LAN and WAN networking environments are common in offices and companies, facilitating enterprise-wide computer networks such as intranets, all of which may be connected to global communication networks, such as the Internet. In embodiments, the network 130 in Figure 1 is one or more of the LAN 852 and WAN 854.

[0088] When used in a LAN networking environment, the computing system 802 may be connected to the LAN 852 via a wired and / or wireless network interface or adapter 856. The adapter 856 can facilitate wired and / or wireless communication to the LAN 852 and may include a wireless access point placed on it to communicate with the wireless function of the adapter 856.

[0089] When used in a WAN network environment, the computing system 802 may include a modem 858, or be connected to a communication server in the WAN 854, or have other means for establishing communication via the WAN 854, for example, the Internet. The modem 858 is connected to the system bus 808 via an input device interface 842. The modem 858 may be internal or external, and may be wired and / or wireless. In a networked environment, the program module or part thereof illustrated in relation to the computing system 802 may be stored in a remote memory / storage device 850. The illustrated network connection is illustrative, and it will be recognized that other means for establishing communication links between computers may be available.

[0090] The computing system 802 is capable of communicating with wired and wireless devices or entities using the family of IEEE 802 standards, such as wireless devices configured to operate in wireless communication (e.g., IEEE 802.16 wireless modulation techniques). This includes, at least, Wi-Fi (Wireless Fidelity), WiMAX, and Bluetooth wireless technologies. Thus, the communication may be a predefined structure, such as a conventional network, or simply ad-hoc communication between at least two devices. Wi-Fi networks use wireless technologies called IEEE 802.11x (a, b, g, n, etc.) to provide secure, reliable, and high-speed wireless connectivity. Wi-Fi networks can be used to connect multiple computers to each other, to connect to the Internet, and to connect to wired networks (using media and functions associated with IEEE 802.3).

[0091] Various embodiments may be implemented using hardware components, software components, or a combination of both. Examples of hardware components may include processors, microprocessors, circuits, circuit elements (e.g., transistors, resistors, capacitors, inductors, etc.), integrated circuits, application-specific integrated circuits (ASICs), programmable logic devices (PLDs), digital signal processors (DSPs), field programmable gate arrays (FPGAs), logic gates, registers, semiconductor devices, chips, microchips, chipsets, etc. Examples of software may include software components, programs, applications, computer programs, application programs, system programs, machine programs, operating system software, middleware, firmware, software modules, routines, subroutines, functions, methods, procedures, software interfaces, APIs, instruction sets, computed code, computer code, code segments, computer code segments, words, values, symbols, or any combination thereof. Whether an embodiment is implemented using hardware and / or software components may vary depending on any number of factors, such as desired computation rate, power level, thermal tolerance, processing cycle budget, input data rate, output data rate, memory resources, data bus speed, and other design or performance constraints.

[0092] At least one or more aspects of each embodiment may be implemented by typical instructions stored on a machine-readable medium representing various logic within a processor that, when read by a machine, causes the machine to generate logic that performs the techniques described herein. Such representations, known as "IP cores," may be stored on a tangible machine-readable medium and supplied to various customers or manufacturing facilities to be loaded into manufacturing machines that produce logic or processors. Some embodiments may be implemented using, for example, a machine-readable medium or product that can store one or a set of instructions that, when executed by a machine, causes the machine to perform the methods and / or operations according to the embodiment. Such a machine may include, for example, any suitable processing platform, computing platform, computing device, processing unit, computing system, processing system, computer, processor, etc., and may be implemented using any suitable combination of hardware and / or software. Machine-readable media or products may include, for example, any suitable type of memory unit, memory device, memory product, memory medium, storage device, storage product, storage medium and / or storage device, such as memory, removable or non-removable media, erasable or non-erasable media, writable or rewritable media, digital or analog media, hard disks, floppy disks, CD-ROMs (Compact Disk Read Only Memory), recordable compact disks (Compact Disk Recordable: CD-R), rewritable compact disks (Compact Disk Rewriteable: CD-RW), optical disks, magnetic media, magneto-optical media, removable memory cards or disks, various types of digital versatile disks (DVDs), tapes, cassettes, and the like. Instructions may include any suitable type of code, such as source code, compiled code, interpreted code, executable code, static code, dynamic code, encrypted code, etc., implemented using any suitable high-level, low-level, object-oriented, visual, compiled, and / or interpreted programming language.

[0093] The preceding description of exemplary embodiments is provided for illustrative and explanatory purposes only. It is not intended to be exhaustive or to limit the disclosure to the forms disclosed herein. Many modifications and variations are possible in light of this disclosure. The scope of this disclosure is not intended to be limited by this detailed description, but rather by the claims attached herein. Future applications claiming priority to this application may assert rights to the disclosed subject matter in different ways and may generally include any set of one or more limitations as disclosed or otherwise illustrated herein.

Claims

1. The client device's processor receives requests to access digital services from applications running on it, The above application performs the first authentication by verifying that the first set of data is associated with a user account, The client device receives a second set of encrypted data from the contactless card associated with the user account. The above application performs a second authentication based on the second set of encrypted data, The above application authorizes access to the above digital service in response to the first authentication and the second authentication, The above application verifies that the contactless card is active in each of the above time intervals by sending each of the multiple status messages to the contactless card in each of the above time intervals. The above application determines that the signal strength of the wireless signal received by the above contactless card is below a threshold, The above application determines, at least in part, that a first response to a first state message among the multiple state messages is not received from the contactless card, based on the determination that the signal strength is below the threshold. The application may terminate access to the digital service based on the determination that the first response to the first status message is not received from the contactless card. method.

2. The above method determines, before deciding that no response has been received to the first status message, The above application receives a second response in response to the second status message among the multiple status messages, The above application further includes providing access to the above digital service without requiring re-authentication based on the above first response, The first response and the second response described above are each one of a plurality of responses. The method according to claim 1.

3. Each of the above multiple responses is received as one or more Near Field Communication (NFC) Data Interchange Format (NDEF) messages from the contactless card. The method according to claim 2.

4. The second set of encrypted data described above is generated based on the encryption algorithm and the derived key of the contactless card described above. The above derived key is based on the master key and counter value of the above contactless card. The method according to claim 1.

5. Performing the second authentication described above means The above application sends the second set of encrypted data to the server, The above application further includes receiving the above second authentication from the above server based on the above second set of encrypted data, The counter value of the above contactless card is synchronized with the counter value maintained on the above server. The method according to claim 4.

6. By supplying energy to the Near Field Communication (NFC) interface and antenna, the above-mentioned multiple status messages are transmitted to the contactless card, thereby verifying that the contactless card is active. The method according to claim 1.

7. A non-temporary computer-readable storage medium, wherein the computer-readable storage medium, when executed by a processor, The application receives requests to access digital services, The above application performs the first authentication by verifying that the first set of encrypted data is associated with the user account, The above application receives a second set of encrypted data from the contactless card associated with the above user account, The above application performs a second authentication based on the second set of encrypted data, The above application authorizes access to the above digital service in response to the first authentication and the second authentication, The above application verifies that the contactless card is active in each of the above time intervals by sending each of the multiple status messages to the contactless card in each of the above time intervals. The above application determines that the signal strength of the wireless signal received by the above contactless card is below a threshold, The above application determines, at least in part, that a first response to a first state message among the multiple state messages is not received from the contactless card, based on the determination that the signal strength is below the threshold. The above application includes an instruction that causes the processor to terminate access to the digital service based on the determination that the first response to the first status message is not received from the contactless card, A computer-readable storage medium.

8. The above command determines, before deciding that no response has been received to the first status message, The above application receives a second response in response to the second status message among the multiple status messages, The above application configures the processor to perform the following: providing access to the above digital service without requiring re-authentication based on the above first response, The first response and the second response described above are each one of a plurality of responses. The computer-readable storage medium according to claim 7.

9. Each of the above multiple responses is received as one or more Near Field Communication (NFC) Data Interchange Format (NDEF) messages from the contactless card. The computer-readable storage medium according to claim 8.

10. The second set of encrypted data described above is generated based on the encryption algorithm and the derived key of the contactless card described above. The above derived key is based on the master key and counter value of the above contactless card. The computer-readable storage medium according to claim 7.

11. The instruction to perform the second authentication described above is: The above application sends the second set of encrypted data to the server, The above application further includes instructions that cause the processor to receive the second authentication based on the second set of encrypted data from the above server, The counter value of the above contactless card is synchronized with the counter value maintained on the above server. The computer-readable storage medium according to claim 10.

12. By supplying energy to the Near Field Communication (NFC) interface and antenna, the above-mentioned multiple status messages are transmitted to the contactless card, thereby verifying that the contactless card is active. The computer-readable storage medium according to claim 7.

13. A computing device comprising a processor and memory, The above memory, when executed by the processor, The application receives requests to access digital services, The above application performs the first authentication by verifying that the first set of encrypted data is associated with the user account, The above application receives a second set of encrypted data from the contactless card associated with the above user account, The above application performs a second authentication based on the second set of encrypted data, The above application authorizes access to the above digital service in response to the first authentication and the second authentication, The above application verifies that the contactless card is active in each of the above time intervals by sending each of the multiple status messages to the contactless card in each of the above time intervals. The above application determines that the signal strength of the wireless signal received by the above contactless card is below a threshold, The above application determines, at least in part, that a first response to a first state message among the multiple state messages is not received from the contactless card, based on the determination that the signal strength is below the threshold. The above application stores an instruction that causes the processor to terminate access to the digital service based on the determination that no first response to the first status message is received from the contactless card. computing device.

14. The above command determines, before deciding that no response has been received to the first status message, The above application receives a second response in response to the second status message among the multiple status messages, The above application causes the processor to further perform the following actions based on the above first response: providing access to the above digital service without requiring re-authentication. The first response and the second response described above are each one of a plurality of responses. The computing device according to claim 13.

15. Each of the above multiple responses is received as one or more Near Field Communication (NFC) Data Interchange Format (NDEF) messages from the contactless card. The computing device according to claim 14.

16. The second set of encrypted data described above is generated based on the encryption algorithm and the derived key of the contactless card described above. The above derived key is based on the master key and counter value of the above contactless card. The computing device according to claim 13.

17. The instruction to perform the second authentication described above is: The above application sends the second set of encrypted data to the server, The above application includes an instruction that causes the processor to receive the second authentication based on the second set of encrypted data from the above server, The counter value of the above contactless card is synchronized with the counter value maintained on the above server. The computing device according to claim 16.

Citation Information

Patent Citations

  • Computer automatic recognition system by IC card

    JP2002157050A

  • Method for creating one-time password, method for authenticating one-time password, one-time password creation apparatus, IC card with function to create one-time password, one-time password authentication apparatus, IC card program, and computer program

    JP2008176383A

  • Charging system

    JP2015139038A

  • Settlement system, illegal acquisition prevention method, settlement method, information processor, server device, information processing program, and server program

    JP2016110462A

  • Multi-factor authentication using a smartcard

    US20070118745A1