Contactless Card Cryptographic Authentication with Preliminary Challenges
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Card-based transactions are vulnerable to phishing and replay attacks due to the lack of secure encryption, leading to increased security risks and inefficiencies in resource consumption and transaction performance.
Innovation Solution
An authentication server and method that utilize a processor to transmit and encrypt challenges with symmetric keys, generating and authenticating cryptograms to enhance security and efficiency in contactless card transactions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If encryption and authentication measures are implemented to protect contactless card transactions, then security against phishing and replay attacks is improved, but system resource consumption increases and transaction efficiency decreases
Solution Approach 1:
The system performs preliminary authentication by obtaining a first cryptogram from the card before the actual transaction occurs. This advance authentication establishes security credentials that can be reused, avoiding the need to perform full authentication ceremonies for each subsequent transaction, thereby maintaining security while improving transaction efficiency
Solution Approach 2:
The authentication process is segmented into distinct phases: initial authentication to obtain a first cryptogram, and subsequent transactions using a second cryptogram. This segmentation allows the system to perform heavy authentication operations only when necessary, reducing resource consumption during regular transactions while maintaining security
2Productivity
If traditional authentication methods are used without scalable cryptographic protocols, then implementation is simpler, but the system cannot handle large numbers of transactions efficiently
Solution Approach 1:
The system changes cryptographic parameters dynamically by using different cryptogram types (first cryptogram for initial authentication, second cryptogram for subsequent transactions) and updating authentication states. This allows the system to maintain security while optimizing for scalability and handling large transaction volumes efficiently
Data Source
AI summary
Systems and methods for authentication may include an authentication server. The authentication server may include a processor and a memory. The processor may be configured to transmit an authentication request. The processor may be configured to receive a first response that is responsive to the authentication request, the first response comprising a first cryptogram. The processor may be configured to generate a first challenge based on the first response. The processor may be configured to encrypt the first challenge with a symmetric key. The processor may be configured to transmit the first challenge receive a second response that is responsive to the first challenge, the second response comprising a second cryptogram. The processor may be configured to authenticate the second response.


