Contactless Magnetic Stripe Card Authentication With Diversified Keys
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless legacy magnetic stripe cards lack secure data transmission and user authentication mechanisms, making them vulnerable to security breaches during interactions with client devices like smartphones.
Innovation Solution
A contactless legacy magnetic stripe card equipped with processing circuitry, memory zones, and cryptographic capabilities generates diversified keys using user-provided input or counter values, encrypts data, and transmits it to a server via a client device for secure authentication and transaction authorization.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If contactless legacy magnetic stripe cards are used for transactions, then compatibility with existing merchant systems is maintained, but security and authentication are insufficient
Solution Approach 1:
The patent combines the legacy magnetic stripe card with contactless NFC technology and cryptographic processing capabilities. The card integrates a processor and memory that can perform cryptographic operations, while maintaining compatibility with both contactless readers and traditional magnetic stripe readers. This merging allows the card to secure transactions through encryption and authentication mechanisms while preserving backward compatibility with existing merchant systems.
Solution Approach 2:
The patent changes the security parameters of the card by implementing dynamic key generation and cryptographic algorithms. Instead of static magnetic stripe data, the system generates diversified keys based on master keys and counter values, and uses encryption algorithms to protect transaction data. This parameter change transforms the card from a simple magnetic stripe to a secure cryptographic device while maintaining transaction functionality.
2Reliability
If cryptographic processing capabilities are added to the card, then transaction security is enhanced, but device complexity increases
Solution Approach 1:
The patent extracts the cryptographic processing functionality from the card reader and places it within the card itself. The card contains an integrated processor and memory that can generate diversified keys, encrypt data, and perform authentication operations independently. This extraction reduces the complexity burden on the reader system while enhancing the security of the transaction, as the card becomes self-sufficient in cryptographic operations.
Solution Approach 2:
The patent uses the concept of key copying and diversification. A master key is used to generate multiple diversified keys through cryptographic algorithms, allowing the system to maintain security without requiring a unique complex key for each transaction. The card stores and manages these copied and diversified keys, simplifying the overall system architecture while maintaining strong security through key replication and variation.
3Reliability
If diversified keys are generated using counter values, then data integrity is maintained, but processing time increases
Solution Approach 1:
The patent implements preliminary action by pre-storing counter values and master keys in the card's memory before transactions occur. The card maintains a counter that increments with each transaction, and these pre-stored values are used immediately during authentication without requiring external lookup or generation. This preliminary preparation reduces processing time during actual transactions while maintaining data integrity through the use of pre-configured cryptographic parameters.
Solution Approach 2:
The patent uses periodic action through the counter value mechanism, where the counter increments periodically with each transaction. This periodic increment creates a diversified key for each transaction using the master key and current counter value. The periodic nature of this action ensures that keys are refreshed regularly to maintain integrity, while the algorithmic efficiency of the diversification process minimizes processing time overhead.
Data Source
AI summary
A technique for generating a diversified encryption key for a contactless legacy magnetic stripe card is disclosed. The diversified key can be generated using a master key, a key diversification value and an encryption algorithm. In one example embodiment, the key diversification value can be provided by the user as a fingerprint, numeric code or photo. The user can provide the key diversification value to the card or a cellphone. The card can generate the diversified key using the user provided key diversification value. The card or the cellphone can transmit the user provided diversification value to the server and the server can regenerate the diversified key using the user provided diversification value.


