Contactless Card Authentication for Secure Messaging Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Financial institutions face challenges in securely providing confidential information to customers via SMS due to the insecure nature of SMS communication, which lacks authentication and may be intercepted by unwanted observers.

Innovation Solution

A method involving a programmatic intelligent agent that prompts users to authenticate via a contactless card, using Near Field Communication (NFC) capabilities, to establish an authenticated messaging session, ensuring secure communication and access to confidential information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If SMS messaging service is used for communication between customer and programmatic intelligent agent, then ease of operation is improved, but security and reliability deteriorate due to lack of authentication and potential interception

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent introduces an authentication intermediary system that mediates between the SMS messaging service and the programmatic intelligent agent. This intermediary verifies the identities of both parties through multi-factor authentication methods (SMS codes, biometric verification, device fingerprinting) before establishing an encrypted communication channel, thus maintaining ease of SMS operation while adding security through the intermediary authentication layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements preliminary authentication actions before the actual messaging begins. The system performs identity verification, device validation, and session token generation in advance of the communication exchange. This preliminary security setup ensures that only authenticated parties can access the messaging session, resolving the contradiction between easy operation and security by preparing security measures beforehand

Inventive Principle:
Principle #10Preliminary action

2Reliability

If authentication via contactless card is implemented, then security and reliability are improved, but device complexity increases due to NFC capabilities requirement

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The contactless card authentication system leverages the self-service capabilities of NFC technology. The user's mobile device automatically detects the contactless card when brought into proximity, retrieves authentication credentials, and completes the verification process without requiring manual intervention or complex device configuration. This self-service approach maintains security while minimizing the perceived complexity for the user

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent utilizes the universal NFC capability that exists in modern smartphones to perform multiple functions: contactless payment, identity authentication, and secure key storage. By leveraging this existing multi-functional technology, the system achieves enhanced security without requiring specialized or complex authentication hardware, thus resolving the contradiction between security improvement and device complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If authenticated messaging session is established with time limit, then security is improved through automatic session expiration, but loss of time increases due to need for re-authentication

Engineering Contradiction:
ImprovesecurityVSAvoidtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements periodic authentication through time-limited session tokens that automatically expire after a predetermined duration. This periodic re-authentication mechanism ensures that even if credentials are compromised, the window for unauthorized access is limited. The system balances security with user convenience by setting reasonable time limits that require re-authentication only periodically rather than continuously

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The authentication system provides feedback to users about session status, including remaining session time and re-authentication requirements. This feedback mechanism allows users to plan their communication activities within the authenticated session and understand when re-authentication will be needed, reducing the perceived time loss by making the authentication requirements transparent and predictable

Inventive Principle:
Principle #23Feedback

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

The solution provides a secure and authenticated messaging environment, protecting sensitive information and preventing unauthorized access, while also enabling secure financial transactions and account management.

Implementation Method 1

The device may include Near Field Communication (NFC) capabilities, and the information may be obtained by NFC with the contactless card

Methodology Applied
Scientific EffectNear Field Communication (NFC): Electromagnetic Induction

Data Source

PatentUS20250175461A1Authenticated messaging session with contactless card authentication
Publication Date: 2025.05.29 CAPITAL ONE SERVICES LLC
  • US20250175461A1 patent drawing
  • US20250175461A1 patent drawing
  • US20250175461A1 patent drawing

AI summary

The exemplary embodiments described herein overcome problems encountered by conventional systems by providing an authenticated messaging environment in which a user can securely message with a programmatic intelligent agent. The user may be authenticated at the prompting of the programmatic intelligent agent, such as the beginning of a messaging session or when the user submits a request that requires access to sensitive or confidential information or requires access to a secure account. The prompt may take the form of a message sent from the programmatic intelligent agent. The message may contain a link for launching code, such as an application, that facilitates authentication of the user's identity. The user may activate the link to launch the code and then perform the steps requested by the code to perform the authentication.