Contactless Card Authentication for Secure Password Recovery

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing password recovery methods, such as using a card verification value (CVV), lack sufficient security and are vulnerable to fraud, necessitating a more secure alternative for password management.

Innovation Solution

Utilizing a contactless card as an authentication factor, where a user taps the card to generate a cryptogram that is verified against a stored cryptogram, allowing password retrieval or reset.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a card verification value (CVV) is used for password recovery, then the password management process is simple and familiar to users, but the security level is insufficient and vulnerable to fraud

Engineering Contradiction:
Improvesecurity levelVSAvoiduser convenience
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent changes the authentication parameter from a static CVV code to a dynamic cryptogram that is generated through contactless communication between the card and device. This cryptogram changes with each transaction and incorporates encryption, thereby increasing security while maintaining ease of use through contactless tapping

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces the manual entry of CVV codes with an automated contactless communication system. The cryptographic authentication is performed automatically through NFC or similar contactless interfaces, eliminating the need for users to manually type or remember complex security codes

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If traditional authentication methods are used, then the system is easy to implement, but it lacks fraud prevention capabilities

Engineering Contradiction:
Improvefraud preventionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary action by pre-registering the contactless card with the user's account and pre-establishing the cryptographic verification protocol. During password recovery, the system already has the card's cryptographic credentials stored and ready for verification, enabling immediate fraud prevention without adding complex real-time processing

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary cryptographic verification layer between the user and the password recovery process. The contactless card acts as a secure intermediary that generates and transmits cryptograms, which the server verifies against stored values. This intermediary mechanism provides fraud prevention without requiring the server to implement complex authentication logic

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12511640B2Systems and methods of managing password using contactless card
Publication Date: 2025.12.30 CAPITAL ONE SERVICES LLC
  • US12511640B2 patent drawing
  • US12511640B2 patent drawing
  • US12511640B2 patent drawing

AI summary

A method includes: receiving, by a server from a user device of a user, a message indicating a forgotten password of an online account of the user; verifying, by the server, at least one contactless card associated with the online account; transmitting, by the server to the user device, a first notification requesting the user to tap the at least one contactless card to the user device; receiving, by the server from the user device, a generated cryptogram, wherein the generated cryptogram is generated by the at least one contactless card; comparing, by the server, the generated cryptogram with a stored cryptogram associated with the at least one contactless card; and in response to a determination that the generated cryptogram matches the stored cryptogram, transmitting, by the server to the user device, a second notification indicating the user is authenticated to perform an action related to the forgotten password.