Authentication Server for Contactless Card Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Contactless card communications are vulnerable to interception and unauthorized access due to the lack of effective encryption and authentication measures, leading to increased security risks and operational inefficiencies.

Innovation Solution

An authentication server and method that utilize multi-factor authentication, including first, second, and third factor authentications, to protect communications by converting card-not-present transactions to card-present transactions, thereby reducing fraud and enhancing security through encrypted data exchanges and customized queries.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If contactless card communication is implemented without encryption or protection measures, then operational efficiency and ease of use are improved, but security reliability deteriorates due to vulnerability to interception and unauthorized access

Engineering Contradiction:
Improvecontactless card communicationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple distinct factors (something the user has - card, something the user knows - PIN/password, and biometric verification). Each factor operates as a separate authentication layer, ensuring that no single point of failure compromises the entire security system while maintaining the convenience of contactless initiation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces an intermediary authentication server that mediates between the contactless card and the transaction system. This intermediary verifies the card's authenticity, performs multi-factor authentication, and validates transaction requests, thereby securing the communication channel without affecting the user-friendly contactless interface.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If multi-factor authentication and encryption measures are implemented, then security reliability is improved, but device complexity and processing time increase

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary authentication actions by pre-verifying the card's validity and establishing secure communication channels before actual transactions occur. The authentication server pre-processes card verification and maintains session security, reducing the complexity burden during live transaction processing.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The contactless card itself performs self-verification functions by containing embedded security credentials and authentication logic. The card autonomously generates cryptographic proofs and validates its own authenticity, reducing the burden on external systems and simplifying the overall authentication architecture.

Inventive Principle:
Principle #25Self-service

3Reliability

If multi-factor authentication is performed for each transaction, then security against fraud is improved, but transaction speed and productivity decrease

Engineering Contradiction:
Improvefraud protectionVSAvoidtransaction speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system implements periodic authentication where full multi-factor verification occurs at scheduled intervals or when anomaly detection triggers re-authentication. Between these periodic checks, transactions can proceed with lighter verification, maintaining both security and speed for routine operations.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The system applies partial authentication for low-risk transactions, performing only essential verification steps. Full multi-factor authentication is reserved for high-value or suspicious transactions, ensuring that security measures are proportional to the risk level rather than uniformly applied to all transactions.

Inventive Principle:
Principle #16Partial or excessive action

4Reliability

If cryptographic authentication and encrypted data transmission are implemented, then security reliability is improved, but system resource consumption increases

Engineering Contradiction:
Improvecommunication securityVSAvoidsystem resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system replaces heavy cryptographic operations with lighter verification mechanisms. Instead of performing full cryptographic authentication for every transaction, the system uses pre-computed cryptographic proofs stored on the card and lighter validation algorithms on the server, reducing computational overhead while maintaining security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system dynamically adjusts cryptographic parameters based on transaction requirements. For low-value transactions, weaker but faster encryption algorithms are used, while high-value transactions employ stronger cryptography. This parameter adaptation balances security requirements with resource consumption constraints.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240289792A1Systems and methods for near field contactless card communication and cryptographic authentication
Publication Date: 2024.08.29 CAPITAL ONE SERVICES LLC
  • US20240289792A1 patent drawing
  • US20240289792A1 patent drawing
  • US20240289792A1 patent drawing

AI summary

Systems and methods for authentication may include an authentication server. The authentication server may include a processor and a memory. The processor may be configured to receive a cryptogram associated with a first near field communication data exchange format (NDEF) read. The processor may be configured to perform a first factor authentication of the cryptogram. The processor may be configured to receive a first data set, wherein the first data set is associated with a second NDEF read. The processor may be configured to extract metadata from the first data set. The processor may be configured to perform, after the first factor authentication, a second factor authentication based on the metadata. The processor may be configured to generate a message indicative of an outcome of the second factor authentication. The processor may be configured to transmit the message that instructs the processor to effectuate one or more actions.