Contactless Card Cryptographic Authentication via Key Diversification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic authentication methods for contactless cards are vulnerable to hacking and compromise, lacking robust security measures for data protection and transaction verification, especially in electronic transactions.

Innovation Solution

A system and method for cryptographic authentication of contactless cards, utilizing a client device with a processor and card reader, and an authentication server, which enables secure transaction approval through NFC communication, key diversification, and message authentication codes (MAC) to ensure secure data exchange and prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (email, SMS, triple DES) are used, then transaction verification can be performed, but the system is vulnerable to hacking and unauthorized access

Engineering Contradiction:
Improvetransaction securityVSAvoidvulnerability to hacking
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The authentication process is segmented into multiple independent components: device-specific keys stored on the contactless card, server-side key management, and transaction-specific authentication tokens. This segmentation ensures that compromise of one component does not lead to complete system compromise, directly addressing the vulnerability to hacking while maintaining transaction verification capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Device-specific keys are pre-provisioned on the contactless card during card personalization, and the server is pre-configured with key derivation information before any transactions occur. This preliminary setup enables secure authentication from the first transaction without requiring real-time key exchange, enhancing both security and reliability.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If chip-based financial cards with log-in credentials are used, then account access security is improved, but the system still relies on vulnerable username and password authentication

Engineering Contradiction:
Improveaccount access securityVSAvoidcredential compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent replaces the mechanical username/password authentication system with a cryptographic key-based authentication system. The contactless card contains device-specific keys that are used to generate authentication tokens, eliminating the need for vulnerable log-in credentials while maintaining account access control. This substitution directly addresses the credential compromise vulnerability.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic tokens and key derivation functions as intermediaries between the contactless card and the server. Instead of directly transmitting or verifying usernames and passwords, the system uses these cryptographic intermediaries to authenticate identity, thereby eliminating the vulnerability associated with credential compromise while preserving account access security.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If cryptographic authentication with key diversification is implemented, then data security and transaction integrity are enhanced, but the system complexity increases

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal key derivation mechanism that can generate multiple diversified keys from a single master key stored on the contactless card. This master key serves multiple functions: it derives transaction-specific keys, authenticates the card to the server, and enables secure data exchange. This multi-functionality reduces the number of separate cryptographic components needed, thereby managing system complexity while enhancing data security through key diversification.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent uses key derivation functions that transform a single master key into multiple diversified keys by changing cryptographic parameters (such as using different derivation algorithms or incorporating transaction-specific data). This parameter-based key diversification enhances data security by ensuring that each transaction or data element is protected by a unique key, while the underlying uniform structure manages complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250021970A1Systems and methods for secure transaction approval
Publication Date: 2025.01.16 CAPITAL ONE SERVICES LLC
  • US20250021970A1 patent drawing
  • US20250021970A1 patent drawing
  • US20250021970A1 patent drawing

AI summary

System and methods of contactless card authentication systems include a contactless card and a client device having an application, a processor, and a card reader. An application on the client device receives a transaction lockdown request, sends a request to the server to begin to allow a transaction approval within a time period, receives the transaction approval via an authentication tap from the contactless card, sends the transaction approval to the server; and receive an allowance or disallowance response from the server.