Contactless Chip Card Two-Factor Authentication via Mobile Intermediary
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing contactless payment systems face challenges in authenticating transactions without a physical terminal, particularly in non-face-to-face transactions, as they lack secure methods to validate Personal Identification Numbers (PINs) and prevent fraudulent use of lost or stolen payment devices.
Innovation Solution
A method utilizing contactless chip cards and mobile devices for two-factor authentication, where a PIN or challenge is input into the mobile device, communicated to the contactless chip card, and converted into dynamic authentication data, ensuring secure transaction validation without exposing the PIN.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If contactless payment devices are used for non-face-to-face transactions, then transaction convenience is improved, but fraud risk increases due to inability to validate PIN at the time of transaction
Solution Approach 1:
The system performs preliminary PIN validation by having the user enter their PIN into the mobile device before the contactless transaction occurs. The mobile device then communicates this PIN to the contactless payment device, which validates it against stored credentials. This preliminary action ensures authentication happens before the actual payment, preventing fraud while maintaining contactless convenience.
Solution Approach 2:
The mobile device serves as an intermediary between the user and the contactless payment device. It captures the PIN input, communicates it to the payment device via contactless interface, and receives the authentication result. This intermediary role enables PIN validation in non-face-to-face transactions without requiring a traditional terminal, resolving the contradiction between convenience and security.
2Ease of operation
If cell phone memory is used to store secret data, then device accessibility is improved, but security decreases due to potential extraction of secret keys
Solution Approach 1:
The contactless payment device acts as a secure intermediary that stores the actual secret key in its protected memory, not in the mobile device. The mobile device only handles transient data like PIN input and authentication results. This separation ensures that even if the mobile device is compromised, the secret key remains protected in the contactless device's secure element.
Solution Approach 2:
The system extracts the secret key storage function from the mobile device and places it in the contactless payment device's protected memory. The mobile device retains only the user interface and communication functions, while the critical security function of key storage is separated into a more secure environment, reducing the risk of key extraction.
3Reliability
If traditional intelligent payment devices with PIN validation are used, then transaction security is improved, but transaction speed decreases due to physical terminal requirements
Solution Approach 1:
The system replaces the mechanical requirement of a physical terminal with a contactless communication interface. The PIN validation process that traditionally required a physical card reader is substituted with wireless communication between the mobile device and contactless payment device, maintaining security while enabling faster, contactless transactions.
Solution Approach 2:
The contactless payment device is designed to perform multiple functions: storing secret credentials, validating PINs, and enabling contactless communication. This multi-functionality allows it to provide traditional secure PIN validation while also enabling rapid contactless transactions, eliminating the trade-off between security and speed.
Data Source
AI summary
Generating authentication data for use in a transaction by providing a contactless payment device or smart card configured to communicate with a mobile device, placing the contactless chip card in a proximity to the mobile device to instantiate communication between the contactless chip card and the mobile device, inputting a first input value into the mobile device, communicating data derived from the first input value from the mobile device to the contactless chip card, the contactless chip card converting a set of conversion data, including the first input value, into at least one dynamic value based at least in part on a secret value, communicating the dynamic value from the contactless chip card to the mobile device, and communicating authentication data based at least in part on the dynamic value to a user. In some embodiments the first input value is a Personal Identification Number (PIN), a challenge, or both a PIN and a challenge.


