Contactless Card Biometric Authentication and Key Diversification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cryptographic authentication methods for contactless cards are vulnerable to attacks and lack secure activation processes, relying on insecure methods like email, SMS, and log-in credentials, which compromise data security and transaction integrity.
Innovation Solution
A system and method utilizing a data transmission system with a transmitting and receiving device, employing cryptographic algorithms to generate and manage diversified keys for secure data transmission, and enabling authentication through user credentials via gestures, ensuring secure activation and usage of contactless cards.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If email or SMS is used to verify transactions, then transaction verification can be performed, but the system becomes vulnerable to hacking and unauthorized access
Solution Approach 1:
The patent replaces traditional mechanical authentication methods (email, SMS, passwords) with biometric authentication using fingerprint sensors. The fingerprint sensor captures unique physiological characteristics of the user's finger, providing secure authentication without relying on vulnerable communication channels or easily compromised credentials.
2Ease of operation
If log-in credentials are used for account access, then authentication can be performed, but the system becomes vulnerable to compromise and unauthorized access
Solution Approach 1:
The patent replaces logical authentication credentials (usernames and passwords) with physiological biometric authentication. The fingerprint sensor captures the user's fingerprint pattern, and the processor compares it against stored templates, providing secure authentication that cannot be easily compromised like traditional credentials.
3Productivity
If magnetic strip cards are used for in-person purchases, then transactions can be processed, but the security features are insufficient compared to chip-based cards
Solution Approach 1:
The patent combines multiple security technologies into a single card system: magnetic strip for backward compatibility, EMV chip for enhanced security, and contactless NFC capability for convenient transactions. This composite approach allows the card to provide robust security features while maintaining broad interoperability across different transaction systems.
4Reliability
If card activation requires calling or visiting a website, then card security can be verified, but the process becomes time-consuming
Solution Approach 1:
The patent enables card activation through self-service using the cardholder's own biometric data. The fingerprint sensor on the card reader captures the cardholder's fingerprint, and the processor automatically verifies it against stored biometric templates, activating the card without requiring external verification through phone calls or website visits.
5Ease of operation
If contactless card technology is implemented, then transaction convenience is improved, but authentication security may be compromised
Solution Approach 1:
The patent merges contactless NFC technology with biometric authentication in a unified system. The contactless card contains both NFC communication capability and embedded biometric data, allowing users to perform contactless transactions with enhanced security through fingerprint verification, combining the convenience of contactless payment with robust authentication.
Data Source
AI summary
Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device, which can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.


