Contactless Card OTP Authentication With Risk-Based Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless card authentication methods are vulnerable to attacks and do not adequately verify the physical presence of the card owner, compromising transaction security and integrity.
Innovation Solution
A system that uses a physical token on the contactless card, requiring the card owner to authenticate transactions through a mobile application, incrementing a counter value on the token, and comparing it with a remote server to ensure the card's presence and authorize transactions, with adjustable authentication strength based on risk profiles.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional email or SMS verification is used for transaction authentication, then transaction verification can be performed, but the system is vulnerable to attacks and does not provide sufficient security
Solution Approach 1:
The patent introduces a one-time passcode (OTP) as an intermediary authentication mechanism between the user and the transaction system. The OTP is generated by a secure element in the contactless card and verified by the payment terminal, serving as a mediator that prevents direct exposure of sensitive authentication data while providing strong security against attacks
Solution Approach 2:
The patent creates a cryptographic copy of the card's secure authentication data in the form of a one-time passcode. This OTP is a temporary representation of the card's authentication credentials that can be transmitted and verified without exposing the actual card data, thereby providing security while enabling verification
2Ease of operation
If the card is kept with the mobile device for convenience, then ease of operation is improved, but fraudulent actors may possess the device used to authenticate transactions
Solution Approach 1:
The patent segments the authentication system into two distinct components: the contactless card containing a secure element that generates OTPs, and the mobile device that stores card information for convenience. This segmentation allows the card to be kept separate from the device, so even if the device is compromised, the secure authentication element remains protected in the physical card
Solution Approach 2:
The OTP serves as an intermediary that bridges the convenience of mobile device storage with the security of physical card possession. The OTP generated by the card's secure element acts as a mediator that can be used for authentication without requiring the physical card to be present, yet remains secure because it is generated by the card's protected environment
3Reliability
If risk-based authentication is implemented, then transaction security is enhanced, but system complexity increases
Solution Approach 1:
The patent changes the parameter of authentication strength based on risk assessment. The system dynamically adjusts whether to require OTP verification, use alternative authentication methods, or proceed with standard verification based on factors such as transaction amount, location, and user behavior patterns. This allows strong security for high-risk transactions while maintaining simplicity for low-risk transactions
Data Source
AI summary
Example embodiments provide systems and methods for validating an action using a physical token, such as a near-field-communications (NFC)-capable chip. A server may receive a request to perform the action, and may require validation from the holder of the physical token. The holder of the physical token may log into an application using their login credentials, providing a first tier of authentication. The holder may then scan the physical token with a reader on their mobile device, which provides a second tier of authentication. The scan may reveal a value for a counter on the physical token, which may be compared to a counter at the server in order to validate that the physical token has been used as expected. If the server deems it appropriate, a third (or further) tier may be required, such as scanning a photographic identification of the holder.


