Contactless Card Counter Resynchronization for Cryptographic Authentication
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless cards face challenges in data security, authentication, and verification, with vulnerabilities in two-factor authentication systems and reliance on insecure login credentials, leading to potential unauthorized access and time-consuming activation processes.
Innovation Solution
Implementing a cryptographic authentication system for contactless cards using a counter resynchronization process, involving a contactless card with processors and memory, a client application, and servers, where the counter is synchronized and authenticated based on applet reads, ensuring secure communication and verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If email or SMS is used for transaction verification, then authentication can be performed, but the system becomes vulnerable to hacking and unauthorized access
Solution Approach 1:
The patent introduces a cryptographic authentication system that acts as an intermediary between the user and the transaction verification process. Instead of relying on vulnerable email or SMS channels, the system uses a contactless card with cryptographic applets that generate and verify authentication codes through secure near-field communication, eliminating the need for insecure external communication channels
Solution Approach 2:
The patent replaces the mechanical/system-dependent authentication methods (email servers, SMS networks) with a self-contained cryptographic system embedded in the contactless card. The card contains cryptographic applets that perform authentication operations locally using cryptographic keys and counters, substituting external communication infrastructure with onboard cryptographic processing
2Ease of manufacture
If traditional card activation processes are used, then cards can be activated, but the process is time-consuming and requires manual intervention
Solution Approach 1:
The patent enables self-service card activation through the contactless card system. When the card is presented to a reader, the cryptographic applet automatically performs authentication using the counter value and cryptographic keys, and the activation process completes without requiring the cardholder to manually call or visit a website. The system autonomously verifies the card's authenticity and activates it
Solution Approach 2:
The patent incorporates preliminary cryptographic setup during card personalization, where authentication applets and cryptographic keys are pre-configured in the card. This preliminary action ensures that when the card is first used, the authentication and activation processes can proceed immediately without requiring additional setup or manual intervention
3Ease of operation
If log-in credentials are used for account access, then authentication can be performed, but the system is vulnerable to credential compromise and unauthorized access
Solution Approach 1:
The patent extracts the authentication capability from vulnerable external credential storage (username/password databases) and embeds it directly in the contactless card through cryptographic applets. The authentication credentials are taken out of the online system and stored securely in the card's embedded memory, protected by cryptographic keys that never leave the card during normal operation
Solution Approach 2:
The patent creates a cryptographic copy of the authentication mechanism within the contactless card itself. Rather than relying on external credential verification, the card contains a replicated authentication system with its own cryptographic keys and counter-based authentication logic, allowing it to authenticate itself to the system without transmitting sensitive credentials
Data Source
Figure 1A
Figure 1B
Figure 2
AI summary
Example embodiments of systems and methods for data transmission between a contactless card, a client device, and one or more servers are provided. The memory of the contactless card may include one or more applets and a counter. The client device may be in data communication with the contactless card and one or more servers, and the one or more servers may include an expected counter value. The client device maybe configured to read the counter from the contactless card and transmit it to the one or more servers. The one or more servers may compare the counter to the expected counter value for synchronization. The contactless card and the one or more servers may resynchronize the counter, via one or more processes, based on one or more reads of the one or more applets. The one or more servers may authenticate the contactless card based on the resynchronization.