Contactless Card Cryptographic Authentication via Applet Intermediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems for data security and authentication of contactless cards are vulnerable to attacks, particularly through email and SMS, and rely on insecure methods such as log-in credentials for account access.
Innovation Solution
The implementation of a contactless card system with a processor and memory containing applets and private keys, where communication between applets enables cryptographic services, including cryptogram generation and key management, to enhance security and authentication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If email or SMS is used for transaction verification, then communication convenience is improved, but security reliability deteriorates due to susceptibility to attacks and hacking
Solution Approach 1:
The patent introduces an intermediary cryptographic authentication system that mediates between the user and the transaction verification process. Instead of directly using vulnerable email/SMS channels, the system uses a contactless card with cryptographic applets that generate and verify authentication codes, making the communication channel secure while maintaining convenience.
Solution Approach 2:
The patent replaces the mechanical/vulnerable system of email and SMS verification with a cryptographic system based on mathematical principles. The contactless card uses cryptographic algorithms to generate authentication codes, substituting the insecure mechanical communication channels with a mathematically secure system.
2Quantity of substance
If triple DES encryption algorithms are used, then data encryption capability is improved, but security reliability deteriorates due to similar vulnerabilities to other encryption methods
Solution Approach 1:
The patent uses a composite cryptographic approach combining multiple algorithms including triple DES, AES, and SHA-256 hashing. The system employs a hybrid encryption scheme where symmetric encryption (AES) and asymmetric encryption (RSA) are combined, creating a more secure system that leverages the strengths of multiple cryptographic methods rather than relying on a single algorithm.
3Adaptability or versatility
If log-in credentials are used for account access, then authentication capability is improved, but security reliability deteriorates when credentials are compromised
Solution Approach 1:
The patent extracts the authentication capability from the vulnerable log-in credential system and relocates it to the contactless card. The card contains cryptographic applets that perform authentication independently, removing the dependency on transmittable credentials that can be compromised and stolen.
Solution Approach 2:
The contactless card performs self-service authentication by generating and verifying cryptographic codes locally within the card itself. The card autonomously authenticates transactions without requiring external credential verification, making the system more secure and reliable.
4Reliability
If card activation requires telephone or website verification, then account security is improved, but productivity deteriorates due to time-consuming processes
Solution Approach 1:
The patent performs preliminary cryptographic setup and key generation during card manufacturing, so that the card is pre-configured with security credentials. This eliminates the need for time-consuming post-activation verification processes, as the security infrastructure is already in place before the card reaches the user.
Data Source
AI summary
Example embodiments of systems and methods for data transmission in a contactless card are provided. The contactless card may include a processor, and a memory. The memory may contain a first applet, a second applet, and a plurality of keys. The first applet and the second applet may be stored within a shared security domain. The second applet may be configured to communicate with the first applet to perform one or more cryptographic services. The second applet may be configured to transmit one or more requests to the first applet to encode one or more payload strings based on the plurality of keys to perform the one or more cryptographic services. The first applet may be configured to perform the one or more cryptographic services on behalf of the second applet based on the one or more requests.


