Dynamic Cryptogram Generation for Contactless Card Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cryptographic authentication methods for contactless cards are vulnerable to hacking and compromise, lacking robust security for data transmission and account access, especially with the increasing reliance on electronic transactions.

Innovation Solution

Implementing a system with a transmitting device that uses a counter value and multiple keys to create a cryptogram for secure data transmission, incorporating multifactor authentication to authorize sensitive data sharing, and integrating this into contactless cards for enhanced security and activation processes.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional authentication methods (email, SMS, log-in credentials) are used for contactless card verification, then the activation and access process is simple and user-friendly, but the system is vulnerable to hacking, compromise, and unauthorized access

Engineering Contradiction:
ImprovesecurityVSAvoidauthentication system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements dynamic authentication by continuously updating the counter value in memory and regenerating cryptograms for each transaction. This dynamic approach ensures that authentication data changes with each use, preventing replay attacks and significantly improving security compared to static authentication methods

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The authentication system is segmented into multiple independent components: counter value storage, key management, cryptogram generation, and multifactor authentication layers. This segmentation allows each component to be optimized independently and creates a more robust security architecture that is harder to compromise as a whole

Inventive Principle:
Principle #1Segmentation

2Reliability

If static authentication data is used for contactless transactions, then the system is simpler to implement, but it is vulnerable to replay attacks and side-channel data attacks

Engineering Contradiction:
Improveresistance to replay attacksVSAvoidcryptographic processing complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system employs periodic action by updating the counter value at regular intervals (e.g., after each transaction or at predetermined time intervals) and regenerating cryptographic keys and cryptograms accordingly. This periodic refresh of authentication data ensures that even if one instance is compromised, the system remains secure through subsequent periodic updates

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent changes critical parameters dynamically during operation - specifically the counter value in memory and the derived cryptographic keys. By changing these parameters with each transaction rather than using fixed values, the system becomes resistant to replay attacks and side-channel attacks that rely on analyzing static data patterns

Inventive Principle:
Principle #35Parameter changes

3Reliability

If multiple cryptographic keys are stored and processed for each transaction, then security against side-channel attacks is improved, but the processing time and computational overhead increase

Engineering Contradiction:
Improveprotection against side-channel attacksVSAvoidtransaction processing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-generating and storing multiple cryptographic keys in secure memory before transactions occur. The counter value and key set are prepared in advance and updated only when needed, allowing rapid authentication during actual transactions without the overhead of generating keys in real-time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cryptographic system dynamically selects and switches between multiple key sets during transactions. By having multiple pre-prepared keys and selectively using them based on the counter value, the system achieves both security through key diversity and efficiency by avoiding repeated key generation, thus reducing processing time

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20230396441A1Systems and methods for cryptographic authentication of contactless cards
Publication Date: 2023.12.07 CAPITAL ONE SERVICES LLC
  • US20230396441A1 patent drawing
  • US20230396441A1 patent drawing
  • US20230396441A1 patent drawing

AI summary

Example embodiments of systems and methods for data transmission system between transmitting and receiving devices are provided. These systems and methods may provide for the secure transmission of sensitive information, such personally-identifiable information. In some examples, the sensitive information may be requested and securely shared when cryptographically signed by the user, and the user may control the access of viewers to the personally identifiable information or end users.