Card issuance using restricted virtual numbers
One-tap contactless card authentication allows personalized and secure generation of virtual card numbers with flexible restrictions, addressing inflexibility and security issues in existing systems.
Patent Information
- Application Number
- JP2025081108
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2019-12-23
- Filing Date
- 2025-05-14
- Publication Date
- 2026-08-26
- Estimated Expiration
- 2040-11-23
Smart Images

Figure 0007911604000001 
Figure 0007911604000002 
Figure 0007911604000003
Abstract
Description
Technical Field
[0001] Related Applications This application claims priority to U.S. Patent Application No. 16 / 726,210, entitled "Card Issuance Using Limited Virtual Numbers," filed on December 23, 2019. The entire contents of the aforementioned application are incorporated herein by reference in their entirety.
Background Art
[0002] A virtual credit card is a virtual credit card number commonly used for online purchases and disposable transactions. The virtual card number can be a randomly generated number associated with an actual credit card. Some card-issuing companies may set an upper limit for the virtual number and, in some cases, an expiration date within one year from the creation of the virtual number. For online merchants, the virtual card number may appear no different from other credit cards.
[0003] Basic restrictions associated with the virtual card number, such as the maximum claim amount and expiration date, can be set by the issuer, but there is a need for specially personalized restrictions tailored to the recipient so that the issuing user can set them safely.
Summary of the Invention
[0004] Various embodiments are aimed at applying one or more restrictions to a virtual card number via contactless card authentication and generating a card number for use by the recipient. The one or more restrictions can be particularly personalized for the recipient and can include, for example, merchant restrictions, amount restrictions, time restrictions, or location restrictions. The generated virtual card number, along with the one or more applied restrictions, can be consumed in various ways, such as writing the number onto a blank card via near-field communication or directly transmitting the number to the recipient's computing device.
Brief Description of the Drawings
[0005] [Figure 1A] This shows an exemplary data transmission system in one or more embodiments. [Figure 1B] This shows an exemplary sequence diagram for providing authenticated access by one or more embodiments. [Figure 2] This illustrates an exemplary system using contactless cards according to one or more embodiments. [Figure 3A] This shows an exemplary contactless card according to one or more embodiments. [Figure 3B] This shows exemplary contact pads of a contactless card according to one or more embodiments. [Figure 4] This shows an exemplary flow for generating a virtual card number and associated restrictions using one or more embodiments. [Figure 5] This shows an exemplary flow of one-tap authentication in one or more embodiments. [Figure 6] This illustrates an exemplary flow in which a virtual card number is written to a blank card via a user computing device in one or more embodiments, and the card is used via a recipient computing device. [Figure 7] This illustrates an exemplary process for transferring a virtual card number between two computing devices according to one or more embodiments. [Figure 8] This shows exemplary card applets and applet communications in one or more embodiments. [Figure 9] This shows an exemplary flowchart of one or more embodiments. [Modes for carrying out the invention]
[0006] Various embodiments generally aim to generate a virtual card number and apply one or more restrictions to the card number in a personalized and secure manner. For example, the issuing user may set personalized restrictions tailored to the recipient of the virtual card number, such as vendor restrictions, amount restrictions, time restrictions, and location restrictions. For instance, a user (parent) might want to leave $30 for a babysitter for dinner, but that $30 must be spent at a specific pizza restaurant. In another example, a user (e.g., business owner) might want to offer an employee a $5,000 purchase of supplies, but the spending is limited to two hours and must be spent at a specific supplier.
[0007] To create a virtual card number with one or more restrictions, a user may open a software application (e.g., a banking app) and select an icon for generating a virtual card number. According to one embodiment, a user may use the software application to select one or more restrictions to apply to the card number. The user may then perform one-tap authentication (sometimes referred to herein as "one-tap contactless card authentication") via a contactless card belonging to the user to confirm and apply the selected restrictions and generate a virtual card number.
[0008] In the example, once a virtual card number is generated, that number (with one or more selected restrictions applied) may be written to a blank, unlocked card via a software application and activated for use with any point-of-sale (Point of Sale) management system. According to a further embodiment, the virtual card number may be transmitted from a first computing device to a second computing device, for example, from a user computing device to a recipient computing device. The first and second computing devices may be near-field communication (NFC) enabled devices, and the virtual card number may be transmitted via NFC.
[0009] As will be further explained below, one-tap contactless card authentication can be a very secure way to verify a user's identity, for example, to ensure that restrictions are actually set by the user and not by a fraudster. Furthermore, since contactless cards are often the payment method used to "load" or fund virtual card numbers, one-tap authentication ensures that the user is indeed the person authorized to create and fund the virtual card number.
[0010] According to one embodiment, one-tap contactless card authentication may involve a user placing, tapping, or bringing a contactless card close to a designated area of a user computing device (e.g., a smartphone). The user computing device may detect the contactless card via near-field communication (NFC) and receive one or more ciphertexts from the contactless card. Information contained in the ciphertexts that can identify the true owner of the contactless card may be compared or matched with authentication information associated with the user who is signed in to the banking app. If they match, it can be confirmed that the user's identity has been successfully verified.
[0011] As described above, previous solutions imposed limitations on virtual card numbers that were inflexible and impersonal. The embodiments and examples described herein overcome and are advantageous over previous solutions in that users can easily and conveniently personalize and adjust one or more limitations on virtual card numbers based on the recipient of the number. Furthermore, users can write virtual card numbers to a blank, unlocked card via their computing device and activate the card so that the recipient can use it with various point-of-sale management systems. In addition, users can conveniently transfer virtual card numbers from their computing device to the recipient's computing device via near-field communication. Overall, the application of one or more limitations and the generation of virtual card numbers can be performed in a highly secure and safe manner via one-tap contactless card authentication.
[0012] Drawings are referenced here. Similar reference numbers are used throughout to refer to similar elements. In the following description, many specific details are provided for illustrative purposes to fully understand them. However, it may be apparent that novel embodiments can be implemented without these specific details. In other examples, well-known structures and devices are shown in block diagram form to facilitate their description. The intent is to cover all modifications, equivalents, and alternatives within the scope of the claims.
[0013] Figure 1A shows an exemplary data transmission system according to one or more embodiments. As will be further discussed below, system 100 may include a contactless card 105, a client device 110, a network 115, and a server 120. Although Figure 1A shows a single instance of the components, system 100 may include any number of components.
[0014] The system 100 may include one or more contactless cards 105, which will be further described below with reference to Figures 3A and 3B. In some embodiments, the contactless card 105 may, in one example, use NFC to communicate wirelessly with a client device 110.
[0015] System 100 may include a client device 110, which may be a network-enabled computer. As referred to herein, a network-enabled computer may include, but is not limited to, a computer device, or a communication device, such as a server, network appliance, personal computer, workstation, telephone, smartphone, handheld PC, personal digital assistant, thin client, fat client, internet browser, or other device. The client device 110 may be a mobile computing device, such as Apple's iPhone®, iPod®, iPad®, or other suitable device running Apple's iOS® operating system, a device running Microsoft's Windows® mobile operating system, a device running Google's Android® operating system, and / or other suitable mobile computing devices such as a smartphone, tablet, or similar wearable mobile device.
[0016] The client device 110 may include a processor and memory, and the processing circuit may include additional components, such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitive, and tamper-proof hardware, as necessary to perform the functions described herein. The client device 110 may further include a display and input devices. The display may be any type of device for presenting visual information, such as a computer monitor, flat panel display, and mobile device screen, including liquid crystal displays, light-emitting diode displays, plasma panels, and cathode ray tube displays. The input device may include any device for inputting information available and supported on the user's device into the user's device, such as a touchscreen, keyboard, mouse, cursor control device, microphone, digital camera, video recorder, or camcorder. These devices may be used to input information and interact with the software and other devices described herein.
[0017] In some examples, a client device 110 of system 100 may run one or more applications, such as software applications, that enable network communication with one or more components of system 100 and transmit and / or receive data.
[0018] A client device 110 may communicate with one or more servers 120 via one or more networks 115 and may operate as a front-end to back-end pair with each of the servers 120. The client device 110 may send one or more requests to the server 120, for example, from a mobile device application running on the client device 110. One or more requests may be associated with the retrieval of data from the server 120. The server 120 may receive one or more requests from the client device 110. Based on one or more requests from the client device 110, the server 120 may be configured to retrieve the requested data from one or more databases (not shown). Based on the receipt of the requested data from one or more databases, the server 120 may be configured to send the received data to the client device 110, and the received data may respond to one or more requests.
[0019] System 100 may include one or more networks 115. In some examples, network 115 may be one or more wireless networks, wired networks, or any combination of wireless and wired networks, and may be configured to connect client devices 110 to a server 120. For example, network 115 may include one or more of the following: fiber optic networks, passive optical networks, cable networks, Internet networks, satellite networks, wireless local area networks (LANs), global systems for mobile communications, personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplex-based systems, code division multiple access-based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth®, NFC, radio frequency identification (RFID), Wi-Fi, etc.
[0020] Furthermore, network 115 may include, but is not limited to, a telephone line, optical fiber, IEEE Ethernet 802.3, wide area network, wireless personal area network, LAN, or global network such as the Internet. Further, network 115 may support an Internet network, wireless communication network, cellular network, etc., or any combination thereof. Network 115 may further include one network, or any number of the exemplary types of networks described above, operating as a stand-alone network or cooperating with each other. Network 115 may utilize one or more protocols of one or more network elements to which they are communicatively coupled. Network 115 may translate from other protocols to one or more protocols of network devices or from other protocols. Although network 115 is shown as a single network, according to one or more examples, network 115 may include, for example, multiple interconnected networks such as the Internet, a service provider's network, a cable television network, a corporate network such as a credit card association network, and a home network.
[0021] System 100 may include one or more servers 120. In some examples, server 120 may include one or more processors coupled to a memory. Server 120 may be configured as a central system, server, or platform for controlling and invoking various data at different times to execute multiple workflow actions. Server 120 may be configured to connect to one or more databases. Server 120 may be connected to at least one client device 110.
[0022] Figure 1B shows an exemplary sequence diagram for providing authenticated access according to one or more embodiments. This diagram may include a contactless card 105 and a client device 110, which may include an application 122 and a processor 124. Figure 1B may refer to components similar to those shown in Figure 1A.
[0023] In step 102, application 122 communicates with contactless card 105 (for example, after being brought close to contactless card 105). Communication between application 122 and contactless card 105 may include contactless card 105 being close enough to the card reader (not shown) of client device 110 to enable NFC data transfer between application 122 and contactless card 105.
[0024] In step 104, after communication is established between the client device 110 and the contactless card 105, the contactless card 105 generates a message authentication code (MAC) ciphertext. In some examples, this may occur when the contactless card 105 is read by the application 122. In particular, this may occur when reading, such as an NFC read, of a Near Field Radio Data Interchange (NDEF) tag, which may be created according to the NFC Data Interchange format.
[0025] For example, a reader such as application 122 may send messages, such as an applet selection message, using the applet ID of the NDEF generation applet. Once the selection is confirmed, a series of selection file messages followed by read file messages may be sent. For example, the sequence may include "Select function file", "Read function file", and "Select NDEF file". At this point, the counter value maintained by contactless card 105 may be updated or incremented, followed by "Read NDEF file". At this point, a message may be generated that may include a header and a shared secret. Subsequently, a session key may be generated. A MAC ciphertext may be created from the message, which may include a header and a shared secret. Next, the MAC ciphertext may be concatenated with one or more blocks of random data, and the MAC ciphertext and random numbers (RND) may be encrypted with the session key. Subsequently, the ciphertext and header may be concatenated, encoded as ASCII hexadecimal, and returned in NDEF message format (in response to the "Read NDEF file" message).
[0026] In some cases, the MAC ciphertext may be transmitted as an NDEF tag, while in other cases, the MAC ciphertext may be included with a uniform resource indicator (e.g., a formatted string).
[0027] In some examples, application 122 may be configured to send a request to contactless card 105, the request comprising instructions for generating a MAC ciphertext.
[0028] In step 106, the contactless card 105 transmits the MAC ciphertext to the application 122. In some examples, the transmission of the MAC ciphertext is performed via NFC, but this disclosure is not limited thereto. In other examples, this communication may be performed via Bluetooth®, Wi-Fi, or other wireless data communication means.
[0029] In step 108, application 122 communicates the MAC ciphertext to processor 124. In step 112, processor 124 verifies the MAC ciphertext according to instructions from application 122. For example, the MAC ciphertext may be verified as described below.
[0030] In some examples, MAC ciphertext verification may be performed by a device other than the client device 110, such as a server 120 communicating data with the client device 110 (as shown in Figure 1A). For example, processor 124 may output MAC ciphertext for transmission to server 120, which can then verify the MAC ciphertext.
[0031] In some cases, MAC ciphertext can function as a digital signature for verification purposes. To perform this verification, public-key asymmetric algorithms, such as the Digital Signature Algorithm and the RSA algorithm, or other digital signature algorithms such as zero-knowledge protocols, may be used.
[0032] In some examples, it can be understood that the contactless card 105 may initiate communication after the contactless card is brought close to the client device 110. For example, the contactless card 105 may send a message to the client device 110 indicating that the contactless card has established communication. The application 122 on the client device 110 may then proceed to communicate with the contactless card in step 102, as described above.
[0033] Figure 2 shows an exemplary system 200 that uses a contactless card. System 200 may include a contactless card 205, one or more client devices 210, a network 215, servers 220, 225, one or more hardware security modules 230, and a database 235. Although Figure 2 shows a single instance of the components, system 200 may include any number of components.
[0034] The system 200 may include one or more contactless cards 205, which will be further described below with reference to Figures 3A and 3B. In some examples, the contactless card 205 may communicate wirelessly with the client device 210, for example, via NFC communication. For example, the contactless card 205 may include one or more chips, such as a radio frequency identification chip, configured to communicate via NFC or other short-range protocols. In other embodiments, the contactless card 205 may communicate with the client device 210 via other means, including but not limited to Bluetooth®, satellite, Wi-Fi, wired communication, and / or any combination of wireless and wired connections. According to some embodiments, the contactless card 205 may be configured to communicate with the card reader 213 of the client device 210 (which may be referred to herein as an NFC reader, NFC card reader, or reader) via NFC when the contactless card 205 is within range of the card reader 213. In other examples, communication with the contactless card 205 may be achieved via a physical interface, such as a universal serial bus interface or a card swipe interface.
[0035] System 200 may include client devices 210, which may be network-enabled computers. As referred to herein, network-enabled computers may include, but are not limited to, computer devices, or communication devices, such as servers, network appliances, personal computers, workstations, mobile devices, telephones, handheld PCs, personal digital assistants, thin clients, fat clients, internet browsers, or other devices. One or more client devices 210 may also be mobile devices. For example, a mobile device may include Apple's iPhone®, iPod®, iPad®, or other mobile devices running Apple's iOS® operating system, a device running Microsoft's Windows® mobile operating system, a device running Google's Android® operating system, and / or other smartphones or similar wearable mobile devices. In some examples, client device 210 may be the same as or similar to client device 110, as described with reference to Figure 1A or Figure 1B.
[0036] The client device 210 can communicate with one or more servers 220 and 225 via one or more networks 215. The client device 210 can, for example, send one or more requests to one or more servers 220 and 225 from an application 211 running on the client device 210. One or more requests may be associated with the retrieval of data from one or more servers 220 and 225. Servers 220 and 225 can receive one or more requests from the client device 210. Based on one or more requests from the client device 210, one or more servers 220 and 225 may be configured to retrieve the requested data from one or more databases 235. Based on the receipt of the requested data from one or more databases 235, one or more servers 220 and 225 may be configured to send the received data to the client device 210, and the received data responds to one or more requests.
[0037] System 200 may include one or more hardware security modules (HSMs) 230. For example, one or more HSMs 230 may be configured to perform one or more cryptographic operations as disclosed herein. In some examples, one or more HSMs 230 may be configured as special-purpose security devices configured to perform one or more cryptographic operations. The HSMs 230 may be configured such that keys are never exposed outside the HSMs 230 and are instead maintained within the HSMs 230. For example, one or more HSMs 230 may be configured to perform at least one of key derivation, decryption, and MAC operations. One or more HSMs 230 may be contained within or communicate with servers 220 and 225.
[0038] System 200 may include one or more networks 215. In some examples, network 215 may be one or more wireless networks, wired networks, or any combination of wireless and wired networks, and may be configured to connect client devices 210 to servers 220 and / or 225. For example, network 215 may include one or more of the following: fiber optic networks, passive optical networks, cable networks, cellular networks, Internet networks, satellite networks, wireless LANs, global systems for mobile communications, personal communication services, personal area networks, wireless application protocols, multimedia messaging services, enhanced messaging services, short message services, time division multiplex-based systems, code division multiple access-based systems, D-AMPS, Wi-Fi, fixed wireless data, IEEE 802.11b, 802.15.1, 802.11n and 802.11g, Bluetooth®, NFC, RFID, Wi-Fi, and / or any combination of those networks. As a non-limiting example, communication from the contactless card 205 and the client device 210 may include NFC communication, a cellular network between the client device 210 and the carrier, and the internet between the carrier and the backend.
[0039] Furthermore, network 215 may include, but is not limited to, telephone lines, optical fibers, IEEE Ethernet 802.3, wide area networks, wireless personal area networks, local area networks, or global networks such as the Internet. Additionally, network 215 may support Internet networks, wireless communication networks, cellular networks, or any combination thereof. Network 215 may further include one network or any number of the exemplary types described above, either as a standalone network or working in cooperation with one another. Network 215 may utilize one or more protocols of one or more network elements that are communicatively coupled together. Network 215 may convert from one or more protocols to one or more protocols of network devices, or from other protocols to one or more protocols. Although network 215 is presented as a single network, it should be understood that, according to one or more examples, network 215 may include multiple interconnected networks, such as the Internet, service provider networks, cable television networks, corporate networks such as credit card association networks, and home networks.
[0040] In various examples provided herein, a client device 210 of system 200 may include one or more applications 211, one or more processors 212, and one or more card readers 213. For example, one or more applications 211, such as software applications, may be configured to enable network communication with one or more components of system 200, for example, to transmit and / or receive data. Although only a single instance of the components of client device 210 is shown in Figure 2, it is understood that any number of devices 210 may be used. The card reader 213 may be configured to read from and / or communicate with a contactless card 205. In conjunction with one or more applications 211, the card reader 213 may communicate with the contactless card 205. In the example, the card reader 213 may include a circuit or circuit component, such as an NFC reader coil, that generates a magnetic field that enables communication between the client device 210 and the contactless card 205.
[0041] Any application 211 of the client device 210 may communicate with the contactless card 205 using short-range wireless communication (e.g., NFC). The application 211 may be configured to interface with a card reader 213 of the client device 210, which is configured to communicate with the contactless card 205. It should be noted that those skilled in the art will understand that a distance of less than 20 centimeters coincides with the NFC range.
[0042] In some embodiments, application 211 communicates with contactless card 205 via associated reader (e.g., card reader 213).
[0043] In some embodiments, card activation may occur without user authentication. For example, a contactless card 205 may communicate with an application 211 via NFC through a card reader 213 on a client device 210. Communication (e.g., tapping the card in close proximity to the card reader 213 on the client device 210) allows the application 211 to read the data associated with the card and perform activation. In some cases, the tap may activate or launch the application 211 and then initiate one or more actions or communication with an account server 225 to activate the card for subsequent use. In some cases, if the application 211 is not installed on the client device 210, tapping the card against the card reader 213 may initiate the download of the application 211 (e.g., navigation to an application download page). Following installation, tapping the card may activate or launch the application 211 and then initiate the activation of the card (e.g., via the application or other backend communication). After activation, the card may be used in a variety of transactions, including commercial transactions.
[0044] According to some embodiments, the contactless card 205 may include a virtual payment card. In those embodiments, the application 211 may obtain information associated with the contactless card 205 by accessing a digital wallet implemented on the client device 210, the digital wallet including the virtual payment card. In some examples, the virtual payment card data may include one or more statically or dynamically generated virtual card numbers.
[0045] Server 220 may include a web server that communicates with database 235. Server 225 may include an account server. In some examples, server 220 may be configured to validate one or more credentials from contactless card 205 and / or client device 210 by comparing them with one or more credentials in database 235. Server 225 may be configured to approve one or more requests, such as payments and transactions, from contactless card 205 and / or client device 210.
[0046] Figure 3A shows one or more contactless cards 300, which may include payment cards such as credit cards, debit cards, or gift cards issued by a service provider 305, as indicated on the front or back of the card 300. In some examples, the contactless card 300 may include, but is not limited to, an identification card unrelated to a payment card. In some examples, the payment card may include a dual-interface contactless payment card. The contactless card 300 may include a substrate 310 which may include a single layer or one or more laminated layers made of plastic, metal, and other materials. Exemplary substrate materials include polyvinyl chloride, polyvinyl chloride acetate, acrylonitrile butadiene styrene, polycarbonate, polyester, titanium anodized oxide, palladium, gold, carbon, paper, and biodegradable materials. In some examples, the contactless card 300 may have physical properties conforming to the ID-1 format of the ISO / IEC 7810 standard, or otherwise, the contactless card may conform to the ISO / IEC 14443 standard. However, the contactless card 300 relating to this disclosure may have different characteristics, and it should be understood that this disclosure does not require the contactless card to be implemented as a payment card.
[0047] The contactless card 300 may also include identification information 315 displayed on the front and / or back of the card, and a contact pad 320. The contact pad 320 may be configured to establish contact with a user device, a smartphone, a laptop, a desktop, or a tablet computer or other communication device. The contactless card 300 may also include processing circuits, an antenna, and other components not shown in Figure 3A. These components may be located behind the contact pad 320 or elsewhere on the substrate 310. The contactless card 300 may also include a magnetic strip or tape (not shown in Figure 3A) that may be located on the back of the card.
[0048] As shown in Figure 3B, the contact pad 320 in Figure 3A may include a processing circuit 325 for storing and processing information, including a microprocessor 330 and memory 335. It is understood that the processing circuit 325 may include additional components, such as a processor, memory, error and parity / CRC checker, data encoder, collision avoidance algorithm, controller, command decoder, security primitives, and tamper-proof hardware, as necessary to perform the functions described herein.
[0049] Memory 335 can be read-only memory, write-once read-multiple memory, or read / write memory, such as RAM, ROM, and EEPROM, and contactless card 300 may include one or more of these memories. Read-only memory may be programmable at the factory as read-only or one-time programmable. One-time programming allows it to be written once and read multiple times. Write-once / read-multiple memory may be programmed at some point after the memory chip leaves the factory. Once programmed, the memory may not be rewritable but can be read multiple times. Read / write memory can be programmed and reprogrammed multiple times after leaving the factory. It can also be read multiple times.
[0050] Memory 335 may be configured to store one or more applets 340, one or more counters 345, one or more diversified keys 347, and a customer identifier 350. One or more applets 340 may include one or more software applications configured to run on one or more contactless cards, for example, Java Card applets. However, it is understood that applet 340 is not limited to Java Card applets, but could instead be any software application capable of running on a contactless card or other device with limited memory. One or more counters 345 may include numeric counters sufficient to store integers. One or more diversified keys 347 may be used to generate ciphertext that can be encrypted, for example, information about a user or customer (e.g., a customer identifier 450) and transmitted to a mobile device, at least for authentication purposes, by encrypting various information. The customer identifier 350 may include a unique alphanumeric identifier assigned to a user of a contactless card 300, the identifier being able to distinguish a user of a contactless card from a user of another contactless card. In some examples, the customer identifier 350 may identify both the customer and the account assigned to that customer, and further, the contactless card associated with the customer's account.
[0051] The processor and memory elements of the exemplary embodiments described above are described with reference to the contact pad, but the disclosure is not limited thereto. These elements may be implemented outside of the pad 320, or completely separated from it, or as additional elements in addition to the processor 330 and memory 335 elements located within the contact pad 320.
[0052] In some examples, the contactless card 300 may include one or more antennas 355. These antennas 355 may be positioned within the contactless card 300, around the processing circuit 325 of the contact pads 320. For example, one or more antennas 355 may be integrated with the processing circuit 325, or they may be used in conjunction with an external booster coil. In other examples, one or more antennas 355 may be located outside the contact pads 320 and the processing circuit 325.
[0053] In one embodiment, the coil of the contactless card 300 may function as the secondary side of an air-core transformer. A terminal may communicate with the contactless card 300 by blocking power or amplitude modulation. The contactless card 300 may infer data transmitted from the terminal using a gap in the contactless card's power connection, which may be functionally maintained via one or more capacitors. The contactless card 300 may reciprocate communication by switching the load on the contactless card's coil or by load modulation. Load modulation may be detected in the terminal's coil by interference.
[0054] As described above, the contactless card 300 may be built on a software platform that can run on other devices with limited memory, such as a smart card or JavaCard, and one or more applications or applets may run securely. Applets can be added to the contactless card to provide one-time passwords (OTPs) for multi-factor authentication (MFA) in a variety of mobile application-based use cases. The applet may be configured to respond to one or more requests, such as a near-field wireless data exchange request from a reader, such as a mobile NFC reader, and generate an NDEF message containing a cryptographically secure OTP encoded as an NDEF text tag.
[0055] In the example, when preparing to transmit data (e.g., a mobile device, server, etc.), the contactless card 300 may increment the counter value of one or more counters 345. The contactless card 300 may then provide a master key, which may be a distinct key stored in the card 300, and the counter value as input to an encryption algorithm that generates a diversified key, which may be one of the diversified keys 347 as output. It is understood that the memory of a device or component receiving data from the contactless card 300 also stores the master key and the counter value, and that it decrypts the data using the diversified key that the card used to encrypt the transmitted data. The encryption algorithm may include encryption algorithms, hash-based message authentication code (HMAC) algorithms, cryptographic-based message authentication code (CMAC) algorithms, etc. Non-limiting examples of encryption algorithms may include symmetric encryption algorithms such as 3DES or AES128, symmetric HMAC algorithms such as HMAC-SHA-256, and symmetric CMAC algorithms such as AES-CMAC. Next, the contactless card 300 may encrypt data (e.g., customer identifier 350 and other data) using a diversified key in the form of one or more ciphertexts, which can be sent to a mobile device, for example, as an NFC Data Exchange Format (NDEF) message. The contactless card 300 may then send the encrypted data (e.g., ciphertext) to a mobile device, which can then decrypt the ciphertext using a diversified key (e.g., a diversified key generated by the mobile device using a counter value and master key stored in its memory).
[0056] Figure 4 shows an example of a flow 400 that generates a virtual card number and associated restrictions according to one or more embodiments. A user may open a banking application 402 (sometimes referred to herein as the “banking app”) using a mobile computing device. As shown, the banking app 402 may display at least a welcome screen and an icon 406 for sign-in. A user may sign in to their account by entering a username and password, or access their account by other appropriate means, such as tapping their contactless card to the mobile computing device. It may be understood that tapping the user’s contactless card to sign in is performed and operated in a manner similar to the one-tap authentication process described further below. It may also be understood that the banking app may be a mobile-based application, a native application, a web application, or any software application such as a web browser.
[0057] Upon signing in to a user's account, the banking app 402 may display and allow the user to select various account-related tasks, such as checking account balances, transferring funds between accounts, paying bills, and generating virtual card numbers, as indicated by icon 408. The user may select icon 408, as indicated by the highlighted box, to generate a virtual card number and one or more associated restrictions. In some examples, the user may also enter and identify the recipient of the virtual card number, where the recipient may also be a customer of the bank. It may be understood that the virtual card number may be funded, loaded, or linked to a user account that may be associated with the user's contactless card. In the example, the user account may be a money account, check account, credit card account, debit card account, digital wallet account, cryptocurrency account, etc.
[0058] As further shown, the bank app 402 may display possible restriction options 410. For example, the user may select the “Time” icon to set various types of time-related restrictions on the virtual card number, such as an expiration date, a period during which the virtual card number can be used, or a specific date range during which the number is active. The user may also select the “Vendor” icon, which can be used to set any type of vendor-related restrictions, such as restricting the use of the virtual card number to specific stores, restaurants, suppliers, etc. Furthermore, the user may select the “Location” icon, which may restrict the use of the virtual card number to a specific geographical location, such as a specific zip code, city, town, or state. Furthermore, as shown by the bottom icon, the user may select the “Amount” icon to set amount-related restrictions, such as reducing the amount to an exact dollar and cent (or other currency) value. Once the user selects any of the displayed restriction options 410, it is understood that the user may manually enter the restrictions and / or select pre-selected or pre-chosen restrictions. Advantageously, in this way, the one or more restrictions that a user can set are more personalized, flexible, and specific to the recipient, thereby giving the user more control over their virtual card number.
[0059] In some cases, the bank app 402 may make limit suggestions to the user based on data related to the user and, where applicable, data related to the recipient. For example, if the user only has a specific amount in their account that they want to use to fund or load a virtual card number, a limit of not exceeding the amount available in the user's account may be suggested. In other cases, if the recipient is also a customer of the bank, financial data associated with the recipient may be analyzed to determine, for example, the type of food the recipient likes, or restaurants the user frequently visits to suggest vendor or location limits.
[0060] In one example of restrictions, a user might generate a virtual card number for their daughter going out to dinner with friends at a Main Street restaurant. The user could set various restrictions on the virtual card number, such as a vendor restriction set at least for the Main Street restaurant, a $40 spending limit, and a 3-hour usage limit. As shown in the dashed box, the banking app 402 may display all selected restrictions and ask the user to confirm that the information is correct. If changes are necessary, the user can modify the restrictions. Once the user has confirmed that the restrictions are correct, they can select icon 412 to perform one-tap contactless card authentication and generate a virtual card number. In some examples, the one-tap authentication process may start automatically once the user confirms the restrictions.
[0061] Figure 5 shows an example of a one-tap contactless card authentication flow 500 according to one or more embodiments. As described above, the exemplary one-tap authentication flow 600 may begin, for example, when the user selects or presses icon 412 to generate a virtual card number with the selected restrictions shown in Figure 4.
[0062] As shown in the diagram, the banking app 502 (which may be similar to or identical to the banking app 402) may display a one-tap introduction screen 512 and related background information to position the user for one-tap authentication. For example, the background information may indicate that the user's contactless card has technology that can be used for actions requiring higher security, and further indicate that the card can be placed flat on the computing device screen to proceed with the authentication process. The user may then proceed by selecting or pressing the "Yes, I understand" icon.
[0063] In the example, when the user selects or presses the "Yes, I understand" icon, the banking app 502 may display a designated area enclosed by a dashed box where the user can place or tap a contactless card. It can be understood that the contactless card may be similar to or identical to the contactless card 300 described above. Furthermore, as described above, the user's contactless card used to perform one-tap authentication may be a financial instrument used to "fund" or "load" a virtual card number.
[0064] Furthermore, a one-tap authentication instruction 514 may be displayed, or an icon or link to the one-tap instruction 514 may be provided. The instruction 514 may include at least step-by-step instructions for performing one-tap authentication. For example, the user may be instructed to select or press a “Read Card” icon and then place or tap the contactless card within the dashed guide lines of a “Place Card Here” box. Once the “Read Card” icon is pressed, the banking app 502 may further display an indication that the user’s contactless card is ready to be scanned. In some examples, if the computing device is unable to read the contactless card via NFC, the banking app 502 may instruct the user to retry scanning the card. It may be understood that the contactless card may be placed anywhere on the user’s computing device, including not only the front of the device but also the back or any location near the NFC reader.
[0065] According to one embodiment, when a user computing device detects a contactless card via NFC, the computing device may receive one or more ciphertexts from the contactless card. It can be understood that a ciphertext can broadly refer to encrypted text, data, or information. Furthermore, it can be understood that one or more ciphertexts may be received as NFC Data Interchange Format (NDEF) messages.
[0066] In the example, one or more received ciphertexts may contain at least information that identifies a user, or other relevant information indicating that the card belongs to a particular user. For example, card user information could be any type of data or information that associates a contactless card with a user (e.g., ID number, customer number, etc.), which may be created or established in the backend system when the contactless card is created for the user and / or when the user signs up for or applies for a contactless card. The information contained in one or more received ciphertexts can then be matched or compared with the authentication information associated with the user to verify the user's identity. Authentication information is any type of data or information that identifies the user who is signed in to the banking app (e.g., ID number, customer number, etc.).
[0067] For example, the banking app 502 may be configured to decrypt one or more ciphertexts received from a contactless card using at least one key (e.g., a private key, a decryption key, a key corresponding to a particular encryption-decryption scheme). The banking app 502 may securely access or receive user-related credentials from one or more remote computing devices, such as a backend server. The credentials may include at least an identifier or any information that identifies the user who logged into the banking app 502. The banking app 502 may then determine whether the received credentials match the decrypted ciphertext information received from the contactless card to verify that the contactless card actually belongs to the user and / or verify that the user is indeed claiming to be the user.
[0068] In another example, the banking app 502 may receive one or more ciphertexts from a contactless card, decrypt the ciphertexts, and send them to one or more remote computing devices, which may be secure backend servers, to determine whether the information contained in the one or more ciphertexts matches authentication information associated with the user. The one or more remote computing devices may then send instructions or confirmations to the banking app 502 to verify the user's identity. At least in that respect, most (but not all) of the identity verification process may be performed on one or more secure remote computing devices, which may be advantageous in certain applications or use cases.
[0069] Once the user's identity has been verified and authenticated, the banking app 502 may display instructions indicating that the contactless card has been read and the user's identity has been successfully verified. The user may then select or press the "Continue" icon, which allows the banking app 502 to generate a virtual card number with one or more restrictions selected above.
[0070] In some examples, the bank app 502 may ask the user for permission to share user-related data with third-party services, such as a third-party wallet, if, for example, the virtual card number is being sent to a third-party wallet (e.g., the recipient's third-party wallet). User-related data may include the user's first name, middle name, last name, billing address, email address, phone number, card number, and card expiration information. In additional examples, the user may be prompted to agree to one or more terms and / or conditions related to transferring the virtual card number to the third-party wallet. The user may proceed by selecting or pressing the “Agree” icon as shown. The bank app 502 may then generate a virtual card number with one or more applied restrictions, which may be ready for use by the recipient.
[0071] Figures 4 and 5 illustrate one-tap contactless card authentication performed after the user has selected one or more restrictions to apply to the virtual card number; however, in further embodiments, the one-tap authentication process may be performed before the user selects any restrictions. For example, the user may open a banking app and select an icon to generate a virtual card number. At this point, before selecting any restrictions and generating the virtual card number, the user may be prompted to perform one-tap authentication.
[0072] Figure 6 shows an example of a flow 600 in which a virtual card number is written to a blank card via a user computing device 601 according to one or more embodiments, and the card is used via a recipient computing device 611. It can be understood that the user computing device 601 and the recipient computing device 611 may be any type of NFC-enabled or NFC-compatible device. After a virtual card number with one or more restrictions is generated by the user computing device 601 according to the above flow and / or process, the user may write the virtual card number (with the associated restrictions) to a blank, unlocked NFC-enabled card.
[0073] As shown, the banking app 602 (which may also be similar to or identical to the banking apps 402 and 502 described above) may display an introductory screen and instructions or information regarding the writing process. For example, app 602 may indicate that the generated virtual card number can be written to a blank card by placing the blank card within the dashed guide lines of the following screen. It can be understood that the blank card may be a blank, unlocked NFC-enabled card that allows the virtual card number and information related to associated restrictions to be securely received from the user computing device 601 via near-field communication.
[0074] As further shown, the banking app 602 may display dashed guide lines so that the user can place a blank card near or on the screen (or anywhere near the NFC reader of the user computing device 601, e.g., on the back or side of the device) and press or select icon 606 to write a virtual card number. When icon 606 is pressed or selected, the computing device 601 may detect the blank card via the NFC reader and associated NFC circuitry, and the virtual card number may be written to the blank card as an NFC Data Exchange Format (NDEF) tag. After the virtual card number has been written to the blank card, the card may be activated for use in any point-of-sale management system or any NFC-enabled device, the details of which are further described below, at least with respect to Figure 8. It may be understood that an activated card may be referred to as an “active” card.
[0075] On the recipient computing device 611, the recipient may open the banking app 622 and tap the active card to receive, process, and use or consume the virtual card number, as illustrated. For example, after receiving the virtual card number after tapping the active card, the recipient computing device 611 may copy and paste, type, or autofill the associated payment information on any web-based application or website, such as the vendor website 642. It can be understood that purchases or transactions made on website 642 are still subject to user-set limitations, as described above. In another example, the virtual card number may be added and provisioned to a third-party digital wallet. In yet another example, the user may physically use the active card at numerous point-of-sale management systems and NFC-enabled devices, such as in physical stores.
[0076] Figure 7 shows an exemplary process 700 for transferring a virtual card number from a user computing device 702 to a recipient computing device 704 according to one or more embodiments. The user and recipient computing devices 702 and 704 may be NFC-enabled or NFC-compatible devices. As shown, the user device 702 may be tapped to (or vice versa) the recipient device 704 to transfer the virtual card number from the user device 702 to the recipient device 704 via near-field communication. Similar to the process of writing a virtual card number to a blank card, the virtual card number may be transferred between at least two devices via their respective banking applications.
[0077] Once a virtual card number is transferred, the recipient device 704 can consume that number in various ways. For example, as shown, a banking app 722 may process the virtual card number and be used by the recipient to copy and paste or enter it into payment fields in a merchant's web-based application or website, subject to user-set limits. In another example, as further shown, the recipient may use a third-party wallet app 742 to provision the virtual card number into a third-party virtual wallet.
[0078] For example, the virtual card number may be encrypted with a Personal Identification Number (PIN) before sending the number to the recipient device 704. Therefore, in order to use the virtual card number in a banking app 722 scenario, a third-party wallet app 742 scenario, or other scenario, the recipient may need to enter a PIN.
[0079] Figure 8 shows examples of card applets stored in the memory 802 of one or more embodiments of a contactless card and the communication between them. The contactless card may be the blank, unlocked NFC-enabled card described above that receives a virtual card number via an NDEF tag transmitted from a user computing device. In addition to the memory 802, the contactless card may also include one or more processors or processing circuits (not shown), as well as the contactless card 300 and its contact pads shown in Figures 3A and 3B.
[0080] As shown, the card's memory 802 may include a security domain 804. Within the security domain 804, there may be at least two separate applets 810 and 812, which are distinct from each other and both may reside in the same security domain 804. In the example, the contactless card may receive an NDEF tag from a user computing device, and the first applet 810 may consume or process the NDEF tag. Applet 810 may extract, derive, or otherwise obtain a virtual card number and other related information, such as expiration information, one or more limits set by the user, and a card verification value (CVV). Applet 810 may then transfer the virtual card number and related information to applet 812 so that the contactless card can be activated for use in a point-of-sale management system or other NFC-enabled device. In the example, a secure communication tunnel could be formed between two applets 810 and 812 to transfer or exchange a virtual card number, which, along with a new expiration date, CVV, one or more keys, would then become the primary account number for a contactless card that can be used for in-store purchases. It can be understood that applet 810 could be a banking applet, and applet 812 could be a payment applet.
[0081] In a further example, a virtual card number could be encrypted with a PIN, requiring the recipient to enter or use the PIN to perform a transaction with the virtual card number via a contactless card.
[0082] Figure 9 shows an exemplary flow diagram 900 according to one or more embodiments. Flow diagram 900 relates to generating a virtual card number and personalizing one or more restrictions associated with a virtual card number for the recipient. It can be understood that the blocks of flow diagram 900 and the features described therein do not need to be executed in a specific order. Furthermore, it can be understood that flow diagram 900 and the features described therein may be executed or supported by one or more processors.
[0083] In block 902, for example, a banking app may receive instructions or selections from the user to generate a virtual card number. In block 904, it may determine whether one or more restrictions are associated with the virtual card number. As described above, one or more restrictions may include merchant restrictions, amount restrictions, time or period restrictions, and / or location restrictions, and may be selected and set by the user in a manner personalized to the recipient. In some examples, the virtual card number may not have any restrictions set by the user.
[0084] One-tap contactless card authentication may be performed to generate a virtual card number with restrictions applied. Advantageously, this ensures that the user is actually generating the card number and applying restrictions to it. In block 906, the banking app may prompt the user to perform one-tap authentication. In the example, authentication is performed via the user's contactless card (which could be the payment method used to load or fund the virtual card number), and the user's identity may be verified based on the success of the authentication.
[0085] As described above, the NFC reader on the user computing device may detect the user's contactless card and receive one or more ciphertexts from it, which can be used to determine whether the contactless card actually belongs to or is associated with the user. The ciphertexts may be decrypted by the user computing device using a banking app via a diversified key (a diversified key derived from at least a counter value stored in memory and a master key) and matched against authentication information associated with the user, which may be received from one or more secure remote computing devices (e.g., a server computer). In another example, the ciphertexts may be sent to one or more secure remote computing devices, which may decrypt the ciphertexts and match the information contained therein against the user authentication information. Based on this decision, the verification of the user's identity may be confirmed.
[0086] If user identity verification via one-tap authentication is successful, block 908 may apply one or more restrictions selected and set by the user (if any) to the virtual card number. The banking app can then generate a virtual card number, which can be consumed in the different ways described above, such as writing it to a physical contactless card or sending it to the recipient's computing device. Also, as described above, one-tap authentication may be performed at any point in the number generation process, such as before the user selects and sets one or more restrictions.
[0087] While the embodiments and examples described above involve a reader coil implemented in a mobile computing device, it can be understood that power to any NFC reader installed in any type of device may be dynamically adjusted to improve NFC communication. Furthermore, the above NDEF messages and corresponding payloads may include message content or data related to various use cases of contactless cards, such as contactless card activation, user verification, user authentication, various transactions, sales, and purchases.
[0088] The components and functions of the devices described above may be implemented using discrete circuits, application-specific integrated circuits (ASICs), logic gates, and / or any combination of single-chip architectures. Furthermore, the functions of the devices may be implemented using microcontrollers, programmable logic arrays, and / or microprocessors, or any combination of the aforementioned, where appropriate. Note that hardware, firmware, and / or software elements may be referred to collectively or individually as “logic” or “circuit” in this specification.
[0089] At least one computer-readable storage medium may contain instructions that, when executed, cause a system to perform any of the computer implementation methods described herein.
[0090] Some embodiments may be described using the expression “one embodiment” or “embodiment” together with their derivatives. These terms mean that certain features, structures, or characteristics described in relation to an embodiment are included in at least one embodiment. The appearance of the phrase “in one embodiment” in various places in this specification does not necessarily all refer to the same embodiment. Furthermore, unless otherwise noted, the features described above are recognized to be usable together in any combination. Thus, any features discussed separately may be used together in combination with each other unless it is noted that the features are incompatible with each other.
[0091] With general reference to the notation and nomenclature used herein, the detailed descriptions herein may be presented relating to program procedures performed on a computer or a network of computers. These descriptions and representations of procedures are intended to be used by those skilled in the art to most effectively convey the nature of their work.
[0092] The procedures described herein are generally considered to be a self-consistent set of operations leading to a desired result. These operations require the physical manipulation of physical quantities. These quantities, though not always, take the form of electrical, magnetic, or optical signals that can be stored, transferred, combined, compared, and otherwise manipulated. For reasons of common usage, it may be convenient to refer to these signals as bits, values, elements, symbols, characters, terms, numbers, etc. However, it should be noted that all these and similar terms are associated with the appropriate physical quantities and are merely convenient labels applied to those quantities.
[0093] Furthermore, the operations performed are often referred to in terms such as addition or comparison, which are generally associated with intelligent calculations performed by human operators. In any of the calculations described herein, which form part of one or more embodiments, such ability of a human operator is not required, or in most cases, undesirable. Rather, the calculations are machine calculations.
[0094] Some embodiments, along with their derivatives, may be described using the expressions “joined” and “connected.” These terms are not necessarily intended to be synonyms of each other. For example, some embodiments may be described using the terms “connected” and / or “joined” to indicate that two or more elements are in direct physical or electrical contact with each other. However, the term “joined” can also mean that two or more elements are not in direct contact with each other but are still cooperating or interacting with each other.
[0095] Various embodiments also relate to apparatus or systems for performing these operations. Such apparatus may be specifically constructed for a required purpose and selectively activated or reconfigured by a computer program stored in a computer. The procedures presented herein are not inherently related to any particular computer or other apparatus. The necessary structures for these various machines will become apparent from the given description.
[0096] It is emphasized that a summary of the disclosure is provided so that readers can quickly confirm the nature of the technical disclosure. It is submitted with the understanding that it will not be used to interpret or limit the scope or meaning of the claims. Furthermore, it is found that in the aforementioned detailed description, various features are grouped together into a single embodiment for the purpose of streamlining the disclosure. This method of disclosure should not be interpreted as reflecting an intention that the embodiments described in the claims require more features than are expressly described in each claim. Rather, as reflected in the following claims, the subject matter of the invention lies in fewer features than all the features of a single disclosed embodiment combined. Accordingly, the following claims are incorporated into the detailed description, and each claim stands independently as a separate embodiment. In the appended claims, the terms “including” and “in which” are used as plain English equivalents of the terms “equipment” and “here,” respectively. Furthermore, terms such as “first,” “second,” and “third” are used simply as labels and are not intended to impose numerical requirements on their subjects.
[0097] The above description includes examples of disclosed architectures. Of course, it is impossible to describe all possible combinations of components and / or methodologies, but those skilled in the art will recognize that many more combinations and permutations are possible. Therefore, novel architectures are intended to encompass all such changes, modifications, and variations that fall within the spirit and scope of the attached claims.
Claims
1. Display device and Near-field communication (NFC) circuit and Memory configured to store instructions, A device comprising the memory and a processing circuit connected to the NFC circuit, The aforementioned processing circuit is The system detects instructions to generate a virtual card number for a second device based on the personal identification number of a first contactless card, The display device displays a prompt to encourage the user to touch the first contactless card to the device and communicate via NFC, A first NFC communication is established with the first contactless card via the NFC circuit. After establishing the first NFC communication, the system receives encrypted data from the first contactless card, and the encrypted data includes identification information for authenticating the user. The aforementioned processing circuit is The encrypted data is sent to a remote device for authentication. Upon receiving notification from the aforementioned remote device that authentication was successful, Depending on the success of the authentication, the virtual card number is determined, A second NFC communication is established with the second device via the aforementioned NFC circuit. The NFC circuit performs an NFC operation to transmit the virtual card number to the second device as part of the second NFC communication. Device.
2. The processing circuit further, Determine one or more restrictions related to the virtual card number, The remote device transmits one or more restrictions to be applied to the virtual card number. The apparatus according to claim 1.
3. The processing circuit further receives one or more restrictions based on user input on the graphical user interface (GUI) displayed on the display device. The apparatus according to claim 2.
4. The one or more restrictions mentioned above include store restrictions, monetary restrictions, time restrictions, and / or location restrictions. The apparatus according to claim 2.
5. The processing circuit of the device is further configured to securely transmit the expiration date and card verification value (CVV) information to a second device via the NFC circuit. The apparatus according to claim 1.
6. The processing circuit further, Based on user input, the system receives modifications to one or more of the aforementioned restrictions. To transmit to the remote device changes to one or more restrictions applied to the virtual card number, The apparatus according to claim 2.
7. The aforementioned virtual card number is associated with the user account. The user account is a money account, check account, credit card account, debit card account, digital wallet account, or cryptocurrency account. The apparatus according to claim 1.
8. The aforementioned virtual card number is associated with a Personal Identification Number (PIN), The aforementioned PIN is required for the use of the virtual card number. The apparatus according to claim 1.
9. The processing circuit is further configured to transmit and provide the virtual card number to a third-party digital wallet of the computing device. The apparatus according to claim 1.
10. The apparatus further comprises a display connected to the processing circuit, and displays a prompt on a graphical user interface (GUI) prompting the user to place the second device on the surface of the display. The apparatus according to claim 1.
11. A computer implementation method, The aforementioned computer implementation method is: Detecting instructions to generate a virtual card number for a second device based on the personal identification number of a first contactless card, The display device shows a prompt, encouraging the user to tap the first contactless card on the device to communicate via Near Field Communication (NFC), Based on the fact that the first contactless card is tapped on the device, a first NFC communication is established with the first contactless card via the NFC circuit, After establishing the first NFC communication, the system receives encrypted data from the first contactless card, wherein the encrypted data includes information for authenticating the user. The encrypted data is transmitted to at least one remote device, the user is authenticated, and an instruction is received indicating that the user has been successfully authenticated. After receiving the aforementioned successful authentication, a virtual card number is generated, Establishing a second NFC communication with the second device via the NFC circuit, and performing an NFC operation to transmit the virtual card number to the second device via the NFC circuit, A computer implementation method, including
12. Determining one or more restrictions related to the virtual card number, Sending one or more restrictions to be applied to the virtual card number to the remote device, The computer implementation method according to claim 11, including the method described in claim 11.
13. This includes receiving one or more restrictions through user input on a graphical user interface (GUI) displayed on the display device of a computing device. The computer implementation method according to claim 12.
14. The one or more restrictions mentioned above include store restrictions, monetary restrictions, time restrictions, and / or location restrictions. The computer implementation method according to claim 12.
15. This includes securely transmitting the expiration date and card verification value (CVV) information to a second device via the aforementioned NFC circuit. The computer implementation method according to claim 11.
16. Based on user input, we receive one or more restrictions and To transmit to the remote device changes to one or more restrictions applied to the virtual card number, The computer implementation method according to claim 12.
17. A non-temporary computer-readable storage medium for storing computer-readable program code that can be read by a processor, The aforementioned readable program code is: The processor detects an instruction to generate a virtual card number for a second device based on the personal identification number of the first contactless card, The processor displays a prompt on the display device, prompting the user to touch the first contactless card to the device in order to communicate via NFC. The processor establishes a first NFC communication with the first contactless card via the NFC circuit based on the fact that the first contactless card has been touched to the device, The processor, after establishing the first NFC communication, receives encrypted data from the first contactless card, and the encrypted data includes information for authenticating the user. The processor transmits the encrypted data to the remote device and authenticates the user. The processor receives a notification of successful authentication from the remote device, The processor determines the virtual card number in response to the successful authentication, The processor establishes a second NFC communication with the second device via the NFC circuit, The processor performs an NFC operation via the NFC circuit and transmits the virtual card number to the second device. including, A non-temporary computer-readable storage medium.
18. The virtual card number is associated with a Personal Identification Number (PIN), and the PIN is required for the use of the virtual card number. The computer-readable storage medium according to claim 17.
19. The execution of the aforementioned code further causes the processor to send and provide the virtual card number to the computing device's third-party digital wallet. The computer-readable storage medium according to claim 17.
20. The execution of the code involves the processor prompting the display device to provide a first contactless card to the surface of the computing device or within distance of the computing device, and communicating encrypted data. The computer-readable storage medium according to claim 17.
Citation Information
Patent Citations
System for allowing secure access and use of a virtual credential
US20180337925A1
Systems and methods for processing mobile payments by provisioning credentials to mobile devices without secure elements
WO2013151797A1
Systems and methods for facilitating a transaction using a virtual card on a mobile device
WO2013155627A1