Contactless Card Cryptogram Verification for Digital Transaction Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing digital transaction systems lack adequate security measures to prevent fraud, especially for transactions that satisfy predetermined risk factors such as high value or suspicious origins.

Innovation Solution

A method that solicits communication between a contactless card and a mobile device when a digital transaction satisfies certain risk factors, involving the receipt and verification of a cryptogram to authenticate the user account and confirm the contactless card association, as well as verifying the phone number associated with the mobile device.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures (user names and passwords) are used for digital transactions, then ease of operation is maintained, but security against fraud is insufficient for high-risk transactions

Engineering Contradiction:
Improvesecurity against fraudVSAvoidtransaction execution simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system applies different authentication methods based on the risk level of the transaction. Low-risk transactions use simple password authentication, while high-risk transactions trigger additional verification steps including contactless card authentication and biometric verification. This localized application of security measures ensures strong protection where needed without unnecessarily complicating routine transactions.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system performs risk assessment before authorizing the transaction to determine the appropriate authentication level. By evaluating transaction characteristics (amount, location, device, IP address) in advance, the system can prepare and request the necessary verification steps beforehand, preventing fraud while maintaining smooth processing for legitimate transactions.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If additional verification steps are added for high-risk transactions, then security is improved, but transaction processing time increases

Engineering Contradiction:
Improvefraud prevention capabilityVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system evaluates risk factors and determines the need for enhanced authentication before the transaction is fully processed. By identifying high-risk transactions early in the process, the system can prompt users to complete verification steps (contactless card tap, biometric scan) before authorization, rather than adding delays after the transaction is initiated. This allows legitimate users to complete verification quickly while preventing fraudulent transactions.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system replaces traditional manual verification methods with contactless card authentication and biometric verification. These automated verification methods are processed rapidly by the mobile device and server, reducing the time required for enhanced authentication compared to manual identity verification or multiple password confirmations.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If contactless card authentication is implemented, then user identification accuracy is improved, but device complexity increases

Engineering Contradiction:
Improveuser identification accuracyVSAvoidauthentication system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The mobile device serves as an intermediary that manages the contactless card authentication process. The mobile device contains the short-range communication antenna for receiving cryptograms from the contactless card and the processor for verifying authentication. This distributes the complexity across multiple components rather than requiring a single complex system, making the overall solution more manageable and scalable.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system replaces physical card insertion or manual data entry with contactless card authentication using short-range communication. The contactless card transmits a cryptogram that is rapidly verified by the mobile device processor, providing accurate user identification through automated cryptographic verification rather than manual processes.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances security for digital transactions by ensuring that only authorized users can execute high-risk or suspicious transactions, thereby reducing the risk of fraud.

Implementation Method 1

receiving, by a short-range communication antenna of the mobile device, a cryptogram from the contactless card

Methodology Applied
Scientific EffectElectromagnetic induction: Electromagnetic Induction

Data Source

PatentUS20250053983A1Systems and methods for increasing security for digital transactions with predetermined risk factors
Publication Date: 2025.02.13 CAPITAL ONE SERVICES LLC
  • US20250053983A1 patent drawing
  • US20250053983A1 patent drawing
  • US20250053983A1 patent drawing

AI summary

Systems and methods disclosed herein can determine when a digital transaction initiated in connection with a user account satisfies at least one predetermined risk factor. Responsive thereto, systems and methods disclosed herein can increase security to verify that the digital transaction is likely being initiated by an authorized user of the user account prior to executing the digital transaction in connection with the user account. To do so, a mobile device can communicate with a contactless card to receive a cryptogram therefrom, verify the cryptogram to identify the user account and to confirm that the contactless card is associated with the user account, and verify that a phone number of the mobile device is also associated with the user account.