Cryptographic Authentication for Contactless Cards

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems for authenticating and activating contactless cards are vulnerable to hacking and require cumbersome processes, such as phone calls or website visits, which compromise data security and transaction integrity.

Innovation Solution

The implementation of a cryptographic authentication system for contactless cards, which includes a contactless card with processors and memory containing a diversified master key, transmission data, applets, and a counter, and a client application that generates authentication keys and decrypts encrypted data using cryptographic algorithms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (email, SMS, log-in credentials) are used for contactless card verification, then card activation and authentication can be performed, but the system is vulnerable to hacking, unauthorized access, and data security breaches

Engineering Contradiction:
Improvedata securityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional mechanical/authentication systems (email verification, SMS codes, username/password logins) with a cryptographic authentication system that uses cryptographic algorithms, diversified master keys, and applets embedded in the contactless card to perform secure authentication and card activation, thereby eliminating vulnerabilities associated with traditional methods

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces cryptographic applets as intermediary components within the contactless card that mediate between the cardholder and the authentication system. These applets execute cryptographic operations locally on the card, providing a secure intermediary layer that prevents direct exposure of sensitive authentication data

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If phone calls or website visits are required for card activation, then card activation can be performed, but the process becomes time-consuming and cumbersome

Engineering Contradiction:
Improvecard activation processVSAvoidactivation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The patent enables the contactless card to perform self-service authentication and activation by executing cryptographic operations locally using embedded applets and diversified master keys. The card autonomously generates cryptographic results and validates authentication without requiring the cardholder to manually contact external systems, thereby streamlining the activation process

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent pre-provisions the contactless card with cryptographic applets and diversified master keys during card issuance. This preliminary configuration enables the card to immediately perform cryptographic authentication operations without requiring time-consuming setup or external verification during the activation process

Inventive Principle:
Principle #10Preliminary action

3Reliability

If log-in credentials (username and password) are used for account access, then authentication can be performed, but the system remains vulnerable to credential compromise and unauthorized access

Engineering Contradiction:
Improveauthentication securityVSAvoidcryptographic system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional log-in credential systems with a cryptographic authentication mechanism that uses diversified master keys and cryptographic algorithms executed by applets on the contactless card. This substitution eliminates the vulnerability of transmitting or storing username/password pairs while providing equivalent or superior security

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent implements local cryptographic processing within the contactless card through embedded applets. The authentication operations are performed locally on the card using locally-stored diversified master keys, ensuring that sensitive cryptographic data never leaves the card, thereby providing localized security that prevents credential compromise

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20250055697A1Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2025.02.13 CAPITAL ONE SERVICES LLC
  • US20250055697A1 patent drawing
  • US20250055697A1 patent drawing
  • US20250055697A1 patent drawing

AI summary

Example embodiments of systems and methods for data transmission between a contactless card and a client application are provided. A card key may be generated using a master key and identification number. A first and second session key may be generated using the card key and portions of the. A cryptographic result including the counter may be generated using one or more cryptographic algorithms and the card key. A cryptogram may be generated using the first session key and encrypted using the second session key. The application may be transmit one or more messages to the first applet of the contactless card. The first applet may be configured to establish one or more communication paths to the second applet based on receipt of the one or more messages from the client device. The second applet may be deactivated by the first applet via the one or more communication paths.