Contactless Card Security via Switchable Antenna and Dynamic Password
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Contactless cards are vulnerable to unauthorized transactions due to susceptibility to data theft, which can lead to card cloning and other attacks, as the data transmitted during transactions is not adequately protected.
Innovation Solution
A contactless card with an encrypted memory component and a switchable antenna that communicates with a point of sale device only after user activation, using a dynamic password to decrypt the card data for secure transmission via near field communication.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If card data is transmitted during contactless transactions, then transaction convenience is improved, but data security deteriorates due to susceptibility to theft and card cloning
Solution Approach 1:
The system performs preliminary encryption of card data before transmission and requires preliminary authentication (PIN entry or biometric verification) before the antenna becomes active. This ensures that even if data is intercepted during transmission, it remains encrypted and inaccessible without proper authentication, thus maintaining both convenience and security
Solution Approach 2:
The patent introduces an intermediary authentication mechanism (PIN code entry or biometric sensor) that mediates between the user and the card data transmission. This intermediary layer verifies user identity before allowing the antenna to transmit data, preventing unauthorized access while maintaining legitimate transaction convenience
2Productivity
If card data is stored in memory for transaction processing, then transaction functionality is improved, but vulnerability to data theft increases
Solution Approach 1:
The system encrypts card data in memory before it can be accessed or stolen. The encryption is performed preliminarily, so that even if an attacker gains access to the memory, only encrypted data is available, which is useless without the decryption key stored securely in the authentication module
Solution Approach 2:
The patent applies different security qualities to different parts of the system: the card data in memory is encrypted, the authentication credentials are stored in a separate secure element, and the antenna is controlled by authentication status. This localized application of security measures protects the most vulnerable points while maintaining transaction functionality
3Speed
If the antenna is always active for contactless communication, then transaction speed is improved, but security against unauthorized payments deteriorates
Solution Approach 1:
The antenna's operational state is made dynamic rather than static. It transitions from an inactive state to an active state only after successful authentication, and remains controllable during transactions. This dynamic control prevents unauthorized use while allowing rapid legitimate transactions once authenticated
Solution Approach 2:
The system implements periodic authentication checks and antenna activation/deactivation cycles. The antenna is activated only during authorized transaction periods and deactivated afterward, creating a periodic pattern of activity that prevents continuous unauthorized access while maintaining transaction speed during authorized periods
Applied Scientific Principles
This section explains which scientific principles are used to turn an abstract innovation direction into a practical engineering solution.
Function Achieved in This Case
The solution effectively limits data transmission to secure encrypted data until a transaction is initiated, rendering stolen card data inaccessible without the decryption password, thus enhancing security and fraud protection for contactless payments.
Implementation Method 1
an antenna that communicates with a point of sale device and transmits the decrypted card data to the point of sale device via a near field communication network
Data Source
AI summary
An embodiment of the present invention is directed to systems and methods for securing contactless cards from unauthorized payments, including card cloning attacks. An embodiment of the present invention provides a password at the time of usage of the card to decrypt the data contained in the card at the time when the user is initiating a transaction. In this exemplary illustration, card data may be encrypted at rest, and decrypted at the time of use. Other variations may include a switchable antenna that is disabled at rest and enabled during a transaction.


