Contactless Card Counter Resynchronization for Secure Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic authentication methods for contactless cards are vulnerable to attacks and lack efficient methods for secure activation and verification, particularly in electronic transactions, where email and SMS are susceptible to hacking, and traditional log-in credentials can be compromised.

Innovation Solution

A cryptographic authentication system for contactless cards using a counter resynchronization process, where a contactless card with processors and memory, including applets, synchronizes a counter value with servers through a client application, enabling secure authentication by comparing and resynchronizing the counter value, and utilizing NFC technology for communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional email or SMS is used for transaction verification, then the activation process is simple, but the system is vulnerable to hacking and unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication mechanism
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs preliminary cryptographic key establishment and counter initialization during card activation, before actual transactions occur. This preliminary setup creates secure authentication foundations that prevent hacking and unauthorized access during subsequent use.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

A cryptographic intermediary layer is introduced between the contactless card and the server, using counter-resynchronization mechanisms and cryptographic keys to mediate authentication. This intermediary prevents direct vulnerability to hacking while maintaining secure verification.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If log-in credentials are used for account access, then the authentication method is straightforward, but the credentials can be compromised

Engineering Contradiction:
Improveauthentication securityVSAvoidaccess method
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The contactless card performs self-service authentication by autonomously generating and managing cryptographic signatures and counter values. The card itself serves as the authentication mechanism, eliminating the need for separate log-in credentials that could be compromised.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

Traditional mechanical credential verification (username/password) is replaced with cryptographic mechanisms including counter-resynchronization and digital signatures. This substitution provides stronger security while maintaining ease of operation through contactless communication.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If magnetic strip cards are used for in-person purchases, then the technology is well-established, but they lack secure features compared to chip-based cards

Engineering Contradiction:
Improvesecurity featuresVSAvoidcard technology
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements dynamic authentication where counter values change with each transaction and cryptographic keys are refreshed periodically. This dynamic behavior provides superior security compared to static magnetic strip data, while the contactless chip technology enables these dynamic features.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The contactless card combines multiple security technologies including cryptographic applets, counter mechanisms, and secure element hardware in a composite structure. This composite approach integrates various security features into a single card that exceeds the security of magnetic strip cards.

Inventive Principle:
Principle #40Composite materials

4Productivity

If card activation requires calling or visiting a website, then traditional verification methods are used, but the process is time-consuming

Engineering Contradiction:
Improveactivation speedVSAvoidverification security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The manual activation process (calling or website visits) is replaced with automated cryptographic verification through contactless communication. The system uses NFC or similar contactless technology to rapidly exchange authentication data between the card and server, achieving both speed and security.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

Cryptographic verification is performed preliminarily during the activation process itself, rather than requiring separate verification steps. The counter-resynchronization and key establishment occur as part of the initial card activation, enabling rapid subsequent transactions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240356905A1Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2024.10.24 CAPITAL ONE SERVICES LLC
  • US20240356905A1 patent drawing
  • US20240356905A1 patent drawing
  • US20240356905A1 patent drawing

AI summary

Example embodiments of systems and methods for data transmission between a contactless card, a client device, and one or more servers are provided. The memory of the contactless card may include one or more applets and a counter. The client device may be in data communication with the contactless card and one or more servers, and the one or more servers may include an expected counter value. The client device may be configured to read the counter from the contactless card and transmit it to the one or more servers. The one or more servers may compare the counter to the expected counter value for synchronization. The contactless card and the one or more servers may resynchronize the counter, via one or more processes, based on one or more reads of the one or more applets. The one or more servers may authenticate the contactless card based on the resynchronization.