Contactless Card Multi-Factor Authentication for Secure Messaging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional messaging services lack security, allowing for potential spoofing of phone numbers and identities, making it difficult to transmit sensitive information without fear of communicating with an imposter.

Innovation Solution

A method using a contactless card for multi-factor authentication in SMS sessions, where a one-time password and account identifier are hashed and encrypted, with geolocation as an additional authentication factor, to initiate a secure SMS session by verifying the validity of the password and phone number association.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If conventional messaging services are used, then ease of operation is improved, but security deteriorates

Engineering Contradiction:
Improveease of messagingVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The authentication process is segmented into multiple independent factors: possession of the contactless card, verification of the one-time password, and confirmation of phone number association. Each factor independently contributes to the overall security, allowing the system to maintain ease of operation through automated multi-factor verification while significantly improving security against spoofing and identity assumption.

Inventive Principle:
Principle #1Segmentation

2Reliability

If multi-factor authentication is implemented, then security is improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The contactless card acts as an intermediary authentication device that simplifies the complex multi-factor verification process. The card contains embedded security elements including the one-time password and phone number association data, allowing the authentication system to verify multiple factors through a single card presentation and decryption operation, thereby improving security while managing complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If one-time passwords are used, then security is improved, but loss of time increases

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The one-time password is generated and encrypted in advance during the account setup phase, with the encrypted password stored associatively with the account identifier. During authentication, the system retrieves the pre-stored encrypted password and verifies it against the provided one-time password, eliminating the need for real-time password generation and reducing authentication time while maintaining security through the time-limited nature of the one-time password.

Inventive Principle:
Principle #10Preliminary action

Applied Scientific Principles

This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.

Function Achieved in This Case

Enhances the confidence that communications are with an authenticated party, reducing the risk of imposters and making secure messaging suitable for sensitive information exchanges, such as financial or health information.

Implementation Method 1

A contactless card may be used in conjunction with a messaging-capable device to provide a credential for initiating a secure messaging service session. The contactless card may communicate with the messaging-capable device via near field communication.

Methodology Applied
Scientific EffectNear field communication: Electromagnetic Induction

Data Source

PatentUS20240397316A1Multi-factor authentication providing a credential via a contactless card for secure messaging
Publication Date: 2024.11.28 CAPITAL ONE SERVICES LLC
  • US20240397316A1 patent drawing
  • US20240397316A1 patent drawing
  • US20240397316A1 patent drawing

AI summary

Exemplary embodiments may use a contactless card as a secondary form of authentication in a multi-factor authentication for a secure messaging service. The recipient party of a request to initiate a messaging service session (such as a server computing device) may be programmed to use the phone number of the originating device to look up records regarding an identity of a party and their associated phone number as a primary credential and then may require an authentication credential originating from the contactless card as a secondary credential for the initiating party. In some instances, the credential originating from the contactless card is a onetime password that is valid only for a period of time. The recipient party determines whether the onetime password is valid. If both credentials are valid, a secure messaging session may be initiated with the initiating party.