Contactless Card Cryptographic Authentication via Diversified Keys

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic authentication methods for contactless cards are vulnerable to hacking and compromise, particularly in email and SMS-based verification systems, and require time-consuming manual processes for card activation and account access.

Innovation Solution

A data transmission system using cryptographic algorithms such as asymmetric encryption, digital signature algorithms, and elliptical curve algorithms to generate and manage diversified keys for secure authentication, enabling secure communication between contactless cards and devices, and allowing for secure activation and account access without the need for separate physical tokens.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If email or SMS-based verification is used for authentication, then card activation and account access can be achieved, but the system becomes vulnerable to hacking and unauthorized access

Engineering Contradiction:
Improvecard activation processVSAvoidauthentication security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent replaces traditional mechanical/authentication systems (email verification, SMS codes, manual credential entry) with a contactless cryptographic authentication system using NFC/RFID technology. The contactless card contains cryptographic keys and algorithms that enable secure authentication without exposing credentials through vulnerable channels like email or SMS.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The contactless card acts as an intermediary device between the user and the authentication system. It contains embedded cryptographic modules that perform secure key exchange and authentication operations, eliminating the need for users to directly handle sensitive credentials through vulnerable channels.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of manufacture

If manual card activation processes are used (calling telephone numbers or visiting websites), then card activation can be completed, but the process becomes time-consuming

Engineering Contradiction:
Improvecard activation capabilityVSAvoidactivation time
Core Design Contradiction:
Ease of manufactureVSLoss of time

Solution Approach 1:

The contactless card enables self-service activation by automatically performing cryptographic authentication operations when brought near a reader device. The card independently manages its own activation and authentication processes without requiring users to manually call centers or visit websites, significantly reducing activation time.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The cryptographic authentication data and keys are pre-configured in the contactless card during manufacturing. This preliminary setup enables immediate activation and authentication operations without requiring time-consuming manual configuration or verification steps during the activation process.

Inventive Principle:
Principle #10Preliminary action

3Ease of operation

If log-in credentials (username and password) are used for account access, then authentication can be performed, but the system becomes vulnerable to credential compromise

Engineering Contradiction:
Improveaccount access processVSAvoidcredential compromise risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent replaces traditional username/password credential systems with contactless cryptographic authentication. The contactless card contains secure cryptographic modules that perform key-based authentication, eliminating the need for users to remember and enter vulnerable text-based credentials.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system uses asymmetric cryptography with public and private keys stored in the contactless card. The private key remains securely stored in the card and never leaves the device, while the public key is used for authentication operations. This asymmetric approach ensures that even if communication channels are compromised, the private key cannot be extracted.

Inventive Principle:
Principle #4Asymmetry

4Reliability

If traditional cryptographic algorithms (such as triple DES) are used for data encryption, then data protection can be provided, but the algorithms have similar vulnerabilities to other authentication methods

Engineering Contradiction:
Improvedata encryption capabilityVSAvoidalgorithm vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent employs modern cryptographic algorithms with updated parameters and key management approaches. Instead of relying on older algorithms like triple DES, the system uses contemporary cryptographic standards with stronger key lengths and more secure mathematical foundations, making them resistant to modern cryptographic attacks.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The contactless card's secure element acts as an intermediary that isolates and protects cryptographic operations from external attacks. The cryptographic keys and algorithms are executed within the secure boundary of the card, preventing attackers from intercepting or manipulating the cryptographic processes even if they compromise the communication channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20240422002A1Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2024.12.19 CAPITAL ONE SERVICES LLC
  • US20240422002A1 patent drawing
  • US20240422002A1 patent drawing
  • US20240422002A1 patent drawing

AI summary

Example embodiments of systems and methods for data transmission between transmitting and receiving devices are provided. In an embodiment, each of the transmitting and receiving devices can contain a master key. The transmitting device can generate a diversified key using the master key, protect a counter value and encrypt data prior to transmitting to the receiving device. The receiving device can generate the diversified key based on the master key and can decrypt the data and validate the protected counter value using the diversified key.