Contactless Card Identity Data for Interception-Resistant Authentication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional identity verification methods for computing systems are vulnerable to security breaches and impractical due to the need for different types of additional information, and one-time passcodes can be intercepted for unauthorized access.

Innovation Solution

A contactless card stores identity data such as passport and driver's license information, using cryptographic algorithms and key diversification to generate encrypted data for authentication, which is verified by an authentication server before authorizing operations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If one-time passcode (OTP) is used for identity verification, then authentication can be performed, but security vulnerabilities exist as OTP may be intercepted and used for unauthorized access

Engineering Contradiction:
Improveauthentication securityVSAvoidinterception vulnerability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the authentication data from the mobile device and stores it securely in a contactless card. The contactless card becomes a separate, secure credential holder that can be presented to the authentication server without exposing the authentication data to interception risks in the mobile device environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The contactless card acts as an intermediary between the user and the authentication server. It holds and presents authentication credentials in a secure, controlled manner, eliminating the need for vulnerable OTP transmission through the mobile device while maintaining the authentication process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If different types of additional information are required for identity verification across different systems, then each system can have its own security requirements, but the solution becomes impractical for users

Engineering Contradiction:
Improvesystem-specific securityVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The contactless card is designed as a universal credential holder that can store multiple types of authentication data (passport information, driver's license data, etc.). This single card can satisfy the identity verification requirements of different systems, eliminating the need for users to manage multiple forms of additional information across different platforms.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If encrypted data from contactless card is validated through authentication server, then security is enhanced, but the process requires additional verification steps

Engineering Contradiction:
Improveauthentication securityVSAvoidverification time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The authentication credentials are pre-loaded into the contactless card during card issuance. When authentication is needed, the card can immediately present the pre-prepared encrypted data to the authentication server, eliminating the time-consuming process of generating or retrieving authentication information during the verification step.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4082167B1Secure authentication based on identity data stored in a contactless card
Publication Date: 2025.10.22 CAPITAL ONE SERVICES LLC
  • EP4082167B1 patent drawingFigure 1A
  • EP4082167B1 patent drawingFigure 1B
  • EP4082167B1 patent drawingFigure 2A~2B

AI summary

Systems, methods, articles of manufacture, and computer-readable media for secure authentication based on identity data stored in a contactless card associated with an account. An application may receive an indication specifying to perform an operation. The application may receive encrypted data from the card, the encrypted data based on a cryptographic algorithm, a customer identifier, and a private key. The application may receive an indication that the authentication server verified the encrypted data based on the private key for the card. The application may determine a type of data required to authorize the operation. The application may receive data comprising passport data or driver license data from the card. The application may determine that the data satisfies a rule for authorizing the operation and authorize performance of the operation based on the authentication server verifying the encrypted data and the data satisfying the at least one rule.