Secure Card Reprovisioning With Cryptograms and Key Switching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Card-based transactions are susceptible to security risks such as phishing and replay attacks, especially with contactless cards, leading to increased interception and unauthorized access, and reissuance of cards can introduce further security concerns.
Innovation Solution
A secure reprovisioning system and method that includes creating a cryptogram using a counter value and transmission data, transmitting it, updating the counter value, receiving encrypted keys and parameters, decrypting them, and switching the association from a first account to a second account, using encrypted data communications and multifactor authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If contactless cards use NFC, Wi-Fi, or Bluetooth to transmit data, then convenience and speed of transactions are improved, but security is worsened due to increased risk of data interception and unauthorized access
Solution Approach 1:
The system performs preliminary authentication actions before allowing any data transmission. The card must first authenticate with the reader, establish a secure session, and exchange cryptographic keys before any actual transaction data can be transmitted. This preliminary security setup prevents interception attacks by ensuring that even if data is captured during transmission, it cannot be used without proper authentication.
Solution Approach 2:
The patent introduces cryptographic intermediaries (encryption keys and cryptograms) between the card and reader. Instead of transmitting raw data directly, the system uses encrypted data and authentication codes as intermediaries to verify identity and authorize transactions. This intermediary layer ensures that even though data travels over the wireless channel, it remains protected and unusable without the proper cryptographic credentials.
2Reliability
If cards are reissued to address security risks, then account security is improved, but security is worsened due to risks of card skimming, interception during mailing, and fraudulent address changes
Solution Approach 1:
Instead of physically reissuing cards, the system creates a digital copy of the card's authentication capabilities through reprovisioning. The original card remains with the user, but its cryptographic credentials are updated remotely. This digital copying approach eliminates the need for physical card mailing while still providing security updates and fraud protection.
Solution Approach 2:
The patent replaces the mechanical card reissuance process with an electronic reprovisioning system. Instead of physically sending new cards through the mail (which creates interception and skimming risks), the system uses wireless communication to electronically update the card's credentials. This substitution eliminates the physical handling step that introduced security vulnerabilities.
3Reliability
If traditional card reissuance is used, then security concerns are addressed, but device complexity and user inconvenience are increased due to mailing processes and potential address fraud
Solution Approach 1:
The card reprovisioning system performs self-service authentication and key exchange without requiring user intervention in the technical process. The card automatically authenticates with the reader, receives updated credentials, and stores them securely. This eliminates the need for users to manually update cards or provide new addresses, simplifying the process while maintaining security.
Solution Approach 2:
The system uses a universal communication interface that works with both contactless and contact-based cards, as well as with different types of readers. This multi-functional approach allows the same reprovisioning mechanism to serve multiple purposes: security updates, credential refresh, and fraud prevention, all through a single standardized process that reduces complexity.
Data Source
AI summary
Systems and methods for authentication may include a first device having an association with a first account, including a memory containing one or more applets, a counter value, and transmission data, a communication interface, and one or more processors in communication with the memory and communication interface. The first device may create a cryptogram based on the counter value, wherein the cryptogram includes the counter value and the transmission data. The first device may transmit, after entry of the communication interface into a communication field, the cryptogram, and update, after transmission of the cryptogram, the counter value. The first device may receive, via the communication interface, one or more encrypted keys and one or more parameters. The first device may decrypt the one or more encrypted keys and, after decryption of the one or more encrypted keys, switch an association from the first account to a second account.


