Contactless Card Authentication for Secure Password Recovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing password recovery methods, such as using a card verification value (CVV), lack sufficient security and are vulnerable to fraud, necessitating a more secure alternative for password management.
Innovation Solution
Utilizing a contactless card as an authentication factor, where a user taps the card to generate a cryptogram that is verified against a stored cryptogram, allowing password retrieval or reset.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a card verification value (CVV) is used for password recovery, then the password management process is simple and familiar to users, but the security level is insufficient and vulnerable to fraud
Solution Approach 1:
The patent changes the authentication parameter from a static CVV code to a dynamic cryptogram that is generated through contactless communication between the card and device. This cryptogram changes with each transaction and incorporates encryption, thereby increasing security while maintaining ease of use through contactless tapping
Solution Approach 2:
The patent replaces the manual entry of CVV codes with an automated contactless communication system. The cryptographic authentication is performed automatically through NFC or similar contactless interfaces, eliminating the need for users to manually type or remember complex security codes
2Reliability
If traditional authentication methods are used, then the system is easy to implement, but it lacks fraud prevention capabilities
Solution Approach 1:
The patent implements preliminary action by pre-registering the contactless card with the user's account and pre-establishing the cryptographic verification protocol. During password recovery, the system already has the card's cryptographic credentials stored and ready for verification, enabling immediate fraud prevention without adding complex real-time processing
Solution Approach 2:
The patent introduces an intermediary cryptographic verification layer between the user and the password recovery process. The contactless card acts as a secure intermediary that generates and transmits cryptograms, which the server verifies against stored values. This intermediary mechanism provides fraud prevention without requiring the server to implement complex authentication logic
Data Source
AI summary
A method includes: receiving, by a server from a user device of a user, a message indicating a forgotten password of an online account of the user; verifying, by the server, at least one contactless card associated with the online account; transmitting, by the server to the user device, a first notification requesting the user to tap the at least one contactless card to the user device; receiving, by the server from the user device, a generated cryptogram, wherein the generated cryptogram is generated by the at least one contactless card; comparing, by the server, the generated cryptogram with a stored cryptogram associated with the at least one contactless card; and in response to a determination that the generated cryptogram matches the stored cryptogram, transmitting, by the server to the user device, a second notification indicating the user is authenticated to perform an action related to the forgotten password.


